This GrapheneOS Feature Can Get You Arrested
E64

This GrapheneOS Feature Can Get You Arrested

An activist has officially been charged

for using the Graphene OS duress pin

feature to destroy evidence.

Facial recognition is running rampant in

private companies and inside Germany's

free speech crackdowns.

We are covering all of this and more

coming up on this episode of This Week

in Privacy number sixty four.

So stay tuned.

Hello everyone and welcome back to This

Week in Privacy,

our weekly series where we discuss the

latest updates with what we're working on

within the Privacy Guides community and

this week's top stories in data privacy

and cybersecurity.

I'm Nate and with me this week again

is Jonah.

Jonah, how was your week?

You know, it's been pretty great.

Lots of stuff going on.

I think lots of good stories to talk

about.

I was ordering some stickers that I could

hand out at DEFCON when I'm there next

week.

Unfortunately, those haven't arrived yet.

They're arriving in a few hours.

I wanted to maybe show people what they

would look like on the stream today.

Don't have them yet,

but they are pretty cool.

And I sent a picture in our supporters

chat.

And if anyone will be at DEF CON

next week again,

come say hi and I'll give you one.

That's the only place to get them.

We don't have them on the store.

Yeah,

I showed the picture you sent in the

supporter chat to my wife and she was

like, oh, those are so cool.

So yeah, they look awesome.

Hopefully I have some extras that I can

mail out to people afterwards,

but we'll see.

We'll see.

How have you been, Nate?

Good, good.

It's been a busy week,

but I guess we'll talk more in the

site updates,

but we got a lot done this week

and

Um, yeah, I mean,

not too much exciting over on my end.

Just, uh, yeah, all good.

Well, those updates should be exciting.

Um, with that, let's talk about.

Our first story today,

this was reported by Ars Technica.

An activist was charged with a felony

after giving border agent duress code that

wiped his phone.

So they say in early twenty twenty five,

Atlanta resident Samuel Tunick was on his

way home following a trip abroad after

landing in the U.S.

Customs agents demanded access to his

Google Pixel phone.

You probably see where that's going.

It was running an alternative version of

Android called Graphene OS.

And we talked about some of this on

This Week in Privacy episode number thirty

one.

Security features.

Government attorneys and agents claim that

Tunick was subjected to a standard

secondary interrogation at an

international airport.

During that encounter,

agents were looking for anything that's

prohibited.

However,

Tunick's legal team alleges he was

targeted for his activism.

This is because Tunick was involved with a

group called Defend the Atlanta Forest,

which opposed the construction of an

enormous law enforcement training facility

in the area often known as Cop City.

What Tunick didn't know,

according to his lawyers,

was that he'd been placed on a watch

list for his actions and that Customs and

Border Protection had discussed over email

plans to detain him upon his arrival back

in the U.S.

for suspected terrorism activities.

So, during this investigation,

these Border Patrol agents basically said

they wanted to search his phone for

evidence of child sexual abuse material.

We talked a bit about that sort of

thing in another story last week.

And if he didn't unlock the device,

it would be confiscated.

So what comes into this story and how

it relates to Graphene OS is the duress

code is an optional feature of Graphene OS

that allows a user to set up a

secondary pin number that when it's

entered,

if you're worried about it falling into

the wrong

hands,

or if you're in a situation like this,

you can basically enter that code on the

lock screen instead of your regular PIN

number,

and it immediately irreversibly wipes the

eSIM, it wipes the entire device,

so none of that

data can be restored.

The article says that Tunick provided this

code to an agent who entered it on

the phone,

after which the screen went blank,

flashed several times,

and the phone appeared to restart.

All of the data on the phone was

gone,

but authorities confiscated it anyways.

Tunick was allowed to leave at that time.

But in late twenty twenty five, the U.S.

Department of Justice opted to file

criminal charges against him,

citing a little used statute,

Title eighteen U.S.

Code Section two to three to eight.

That makes it illegal to knowingly destroy

or damage property to prevent it from

being seized.

TechCrunch noted that this appears to be a

new legal strategy for the government.

EFF experts who spoke to TechCrunch note

that they've never seen the law applied in

this way before.

So the Department of Justice will need to

argue that even though Tunick was told

this was a routine border check,

he ran afoul of the law by tricking

an agent into deleting his data.

If convicted,

Tunick could face up to five years in

prison.

Um,

four or four media also interviewed Tunick

and his lawyer,

and his lawyer said that he only found

one other case using the same law,

which was a drug trafficking

investigation.

In other posts and outlets,

I think we have an article from PCMag

here,

Graphene OS discussed the case from a

technical perspective,

noting that none of their features are

illegal and that based on current

evidence,

Graphene OS phones can withstand forensic

investigation without requiring the use of

a duress pin.

So that is quite a story that I

think will have a lot of people using

Graphene OS and maybe the Stores pin

feature interested.

Nate,

I'm really curious what you think about

all of this first of all.

Why don't you share your thoughts?

Yeah, so this is a,

This is a complicated story in the sense

that when we first covered this story back

in – what did we say it was

there?

This week in Privacy at Thirty-One,

I reached out to a friend of mine

who's a lawyer and asked their expertise.

And veteran viewers know that right now,

the entire state of the Fourth Amendment

as it relates to electronic devices is

really, really up in the air.

And –

The courts are kind of really shy to

make a ruling and lay down some precedent

either way.

So right now – let's see.

I asked my friend to send me that

paper she wrote again.

So basically right now –

Searches normally require a warrant,

but at the border, there's an exception,

and within a hundred miles from land

borders and coastlines,

as well as airports,

international airports,

and it's worth noting that about

two-thirds of Americans live in this area.

So they can do a routine search, which,

again,

has not been legally defined by the

Supreme Court.

And it just says one that does not

seriously invade a traveler's privacy.

And let's see.

CBP guidance requires reasonable suspicion

only for advanced searches.

And a reasonable let's see a search is

considered advanced if an officer connects

external equipment through a wired or

wireless connection to an electronic

device,

not merely to gain access to the device,

but to review,

copy and or analyze its contents.

So this, I think,

would have counted as a routine search.

I also spoke to,

let me pull up my notes here.

I spoke to a friend of mine who

works in law enforcement to get his take.

He's very knowledgeable.

He knows about graphene.

He knows that it's not something that just

criminals use.

He said that he checked the court records

for federal cases using that section,

to and he said the only ones that

he found involved physical property and a

criminal investigation,

which he notes based on the information we

have right now,

this was not a criminal investigation.

This was a routine search.

He said,

I can't tell you the likelihood of this

charge sticking because that's beyond the

scope of my legal knowledge.

But in his opinion,

it's kind of a stretch.

Let me see here.

I'm trying to make sure I didn't miss

anything with his take.

Yeah, so it's very –

I think what this is ultimately going to

come down to – and for the record,

I'm not a lawyer either.

I don't have any legal training.

I got really busy,

and I forgot to send my lawyer friend

the actual legal paperwork,

which I think the TechCrunch article links

to.

Oh, this one does too actually.

So there is a link in there if

you want to read the actual charges.

I think it's only like two pages.

It's not that long.

But from what I'm reading and what I'm

seeing from other people –

Trying to charge him under this specific

statue is kind of weird,

and it may not stick,

but I think what might come back to

bite him is the fact that he gave

the officer the wrong pin.

And he knowingly did so,

although I would like to note that the

mayor of New York claimed that he forgot

his phone's password and never faced any

consequences,

which I don't think any of us buy

that.

But it'd be one thing – like I've

seen some people say online.

I think they've even said in our forum

thread about this that –

It'd be one thing if, like,

he wrote down the duress pin in his

phone and made it look like the actual

pin,

or if he made it something easily

guessable, like, you know, his birth year,

one, one, one, one, zero, zero, whatever.

If he had done that and the cop

just guessed and assumed,

I think he'd be in a much stronger

legal position.

If anything's going to come back to bite

him,

I think it's going to be the fact

that he knowingly gave them a duress pin.

But it... Yeah, I mean, it's definitely...

I think it's – I mean all this

is kind of beating around the bush of

saying that like I think we all know

this whole like, oh,

we think there's CSAM on your phone.

Like really?

Why do you think that?

Like where did that accusation come from?

Like this – I think any – what's

the word I'm looking for?

I think most people can see right through

it that this was clearly related to his

activism with the whole StopCopCity thing,

which, for the record,

I do want to point out there that

the last time we talked about a story

about StopCopCity and Proton turned over

information to the FBI,

that person was accused of throwing

firebombs and being violently aggressive,

which –

I advocate for peaceful protest,

so I don't know what this dude's story

is.

I don't know if he was out there

throwing Molotov cocktails or if he was

just out holding signs.

But either way,

I think there's clearly a link here.

And yeah,

I think this is probably going to be

one of those really big cases that we

have to keep our eye on and hope

for the best.

For sure.

I mean,

and Dag Overhull in the chat said exactly

the same thing.

I mean,

the government used three different

excuses in this Ars Technica article.

They said they were investigating him for

terrorism.

They talked about using CSAM as a

pretense,

which is exactly in line with what I

was talking about last week,

which is that the government uses these as

an excuse to search random people,

often without any evidence

at all,

and this is just yet more proof of

that happening.

There probably wasn't

any sort of probable cause whatsoever for

the things that the government was

claiming was on his phone,

which I think is a huge problem for

their legal case.

I'm obviously not a lawyer either,

but I totally agree with what your friend

was saying too about this specific law.

When I read this article,

I think it was posted by Zach Whitaker

on TechCrunch,

who is an excellent reporter.

My immediate reaction was that this is a

very strange law to charge him with

because I do think it clearly relates to

physical property.

The law says that you can't knowingly

destroy your damaged property to prevent

it from being seized by the government.

However,

The government did seize his phone,

and his phone is still fully functional as

a phone,

so in what way was the property destroyed

in a way that

prevented them from seizing it.

Obviously,

the government is after the data,

they're not after the phone itself,

but I don't think that this law applies

at all to this data case.

There's been a lot of court cases that

we've seen actually where,

unrelated to criminal charges whatsoever,

but it's generally understood that data is

not

property in the first place.

And this US code specifically relates to

property.

I think if data was property,

there'd be a lot more arguments about

like, oh, these data brokers,

they're illegally possessing my property,

right?

So I can sue them.

It's basically theft if they're sharing it

and selling it and whatever.

But that isn't how the law works.

Obviously,

I'm not really sure that's how the law

works.

I don't really subscribe to the fact that

personal data is property,

I think that would open up a whole

can of worms that we don't have to

get into right now.

But at least at the moment,

that isn't how it works.

And I think that because of all these

things,

I think these charges are pretty tenuous

at best.

This is obviously, to me,

a case of the government just trying to

use the court system as a punitive tool

attack against him because

It's expensive to go through all of these

legal proceedings.

He had to get a lawyer now.

There's all of these... I mean,

he has to deal with this lawsuit, right?

It's annoying.

And even if you're completely innocent of

anything you're being...

or everything you're being accused of,

it's a whole process.

And that is the goal of the government

in these cases.

It's an intimidation tactic, I think,

against protesters or activists like Tunic

here.

And...

it is really not a great story um

the government basically has unlimited

money resources power in the courts to

make your life terrible forever until you

give in so um yeah it's it's a

very scary and concerning story and

It's very problematic that this continues

to be a thing at the border,

especially with border control agents and

US citizens.

So...

Yeah,

I think that sort of sums up what

I was saying.

Let me see if we had anything else

in the notes here I didn't talk about.

I'll add real quick while you're checking

that,

that I think you made a really good

point about data as property.

This almost feels like a double-edged

sword where the government either has to

say, no, he didn't destroy property,

therefore he didn't do anything wrong.

Or B, they have to say, okay,

data is property, which I would imagine,

again, not a lawyer.

Now the Fourth Amendment applies a little

bit more rigidly,

and they have to stop doing things like

buying data from data brokers to get

around a warrant requirement.

I feel like the government kind of put

themselves in a corner here with that one

when you brought that up.

Yeah, yeah.

Yeah, the whole data as property thing,

that's been debated a lot in terms of

advantages or disadvantages it would have.

But I mean, in this case,

like the property itself was not

destroyed.

And the article literally says like,

and I think they say in their documents

that they did, they seized the device,

they use that word.

So like,

what part of the law was even violated

in the first place?

I don't know.

It's probably a case for like,

this is a law that's not on the

books.

And so they're just they're grasping at

straws, basically.

Yeah, I don't know.

I had a few thoughts,

if that's all you had.

Yeah,

I think the main thing I'll just point

out again is that, like,

as Graphene OS said,

there's probably no good reason to use

this in the first place because they can't

get into your phone.

So I would keep that in mind if

you're thinking about that feature.

Anyways, what are you thinking?

No,

that's actually very similar to what I was

going to say is like, I think, like,

I think the dress pin thing is really

cool.

And I think.

I think it makes sense.

Like,

obviously we don't know what was deleted

from this person's phone and maybe there

was some really sensitive stuff on there.

Like not in the sense of CSAM,

but I mean, maybe there was,

who knows not, but you know,

maybe there were like names of other

protesters and like upcoming plans and,

you know,

access into Google docs and like things

that it's, he's like,

I don't want the cops to have this.

And so maybe the lesser evil for him

was like,

I need to make damn sure the cops

don't get into this.

Like, even though as far as we know,

they can't get into graphene.

Like,

what if that one percent chance they can

and he decided it wasn't worth it for

him um so i'm glad this feature does

exist but i i think that we see

a lot of people in the privacy space

set up tools like this um

I'm just going to say,

I think sometimes we think we're Mr.

Robot and we like really get into these

tools.

And if you want to set them up,

that's fine.

But like, keep in mind,

there can be consequences for this.

And, you know,

when I was twenty and I didn't have

a family and like, you know,

I had a dead end job at Walmart,

like, OK, fine,

I'll set up the duress pin like I'll.

Why not?

I have nowhere to be, but you know,

if you have people that rely on you

going to work to keep a roof over

your head, or, you know,

like you pointed out,

uncle Sam has unlimited resources.

Like that was that whole issue with the,

what was it?

The tornado cash developer that recently

went to jail.

Like he said that in his interviews is

he's like, yeah,

I couldn't keep litigating this case.

We were already tens of thousands of

dollars in debt.

And just digging deeper.

And the government has infinite pockets,

thanks to our taxpayer dollars.

That's a different rant.

To just keep charging these people

endlessly and dragging this out in court.

And so it's just something to keep in

mind.

It's a threat modeling thing.

Like, again,

some people really do have data where it's

like,

I can't risk that one percent chance.

But, you know,

I think most of us are probably not

in that boat.

And you've got to keep in mind the

consequences that could rise here.

Yeah.

I'll take a look at some chats here

really quick.

Yeah, definitely.

Hello, welcome to the stream.

Hello, world.

Peaceboy John, yeah, yeah, Graphene OS.

Yeah, I mean, it's a great tool.

I think it's important to note what Deg

Overholtz said again here in the chat.

They can't get into Graphene OS as far

as we know.

That's certainly true,

but I think Graphene OS also has a

lot of features that don't involve

completely destroying the data.

Something like,

I think disabling the USB port is a

pretty great feature that they have.

And that comes enabled by default for the

record.

Yep, when it's locked.

I mean,

and you can take it even further.

Like, on my Pixel right now,

I have it completely disabled when the

phone is on, so it only charges when,

like, the phone is powered off, basically.

And that has been fine,

because I just charge things overnight

anyways.

And there's stuff like that.

They have features, like,

you can disable Wi-Fi and Bluetooth after

a certain amount of time, or, like,

when the phone locks, so that they can't,

like,

connect it to a malicious Wi-Fi network or

something like that.

So, of course...

It's not as foolproof as completely

destroying the data, I'll give you that.

But exactly like you were saying,

I think you don't have to do this

Mr.

Robot Edward Snowden LARPing thing unless

you have a really good reason to.

But I think even in this case,

even if you know you're being targeted

because of your activism or something,

it's pretty unlikely that...

They're going to use all of these

resources to get into your phone,

maybe secret ones.

If you stole a ton of national secrets

like Edward Snowden,

maybe they would take it a bit more

seriously.

But even situations like this,

it's probably overkill.

uh unredacted said one can say they

entered the pin and destroyed the data

themselves um and yeah one could

definitely say that um this I mean you

could definitely argue like they should

have known about this possibility and not

just done whatever he said but also at

the same time you know him saying it

is like um

probably like that's probably the worst

thing for his case I still think that

this case is pretty weak despite that but

it is a thing I also wonder about

like writing down the pin on like a

piece of tape on the back of the

phone I don't know um but I don't

know if that would be considered like

telling them as well but that would be

a bit like even more of a gray

area that I think would would have

benefited him so that's a possibility but

Yeah, it's – Yeah.

I just wanted to say in regards to

that one,

like I don't think that argument is going

to fly.

Like again, not a lawyer,

but that whole like, well,

he's the one that entered the pin.

Yeah,

but you gave him the wrong pin knowing

what would happen.

Like that would be like – I know

this would –

I would say this would never happen,

but I've read crazier stories.

If the cops raided your home and they

say, we think you've kidnapped somebody.

Where are they?

And you're like, oh,

they're through that door over there.

But you booby trap that door.

You're still going to be held responsible

for the cop getting injured or killed

because you knew there was a booby trap

behind that door.

And I think it's the same thing here.

Like, I don't think that argument of like,

well,

he's the one that entered it is going

to fly away.

Yeah,

the booby trap thing was crossing my mind

too.

I'm glad you brought that up.

Great minds think alike.

I remember someone saying your PIN number

is protected by the First Amendment,

just not your biometrics.

That's generally considered to be true.

That hasn't been tested in courts,

but pretty much all legal experts agree it

would be because it's something in your

mind.

That being said,

there have been cases where the government

just detained some people forever because

they didn't give up their PIN or because

they forgot their PIN,

which is pretty rare,

but it just goes to show.

Some of the bad behavior in some cases.

Yeah,

I'm glad you highlighted that one because,

yeah,

it's – I guess it hasn't been tested

in court.

But generally,

it's – your First Amendment protects – you

don't have to give up the pin because

that's a violation of your free speech.

And I would imagine a violation of your

right against self-incrimination.

And we didn't mention it in these show

notes, but he claims,

this Samuel Tunick guy,

he claims that he repeatedly asked for a

lawyer and was denied.

So if that's true and they can prove

that,

I feel like that's a really strong

argument that all this stuff is going to

get thrown out because a lawyer would have

told him don't give them any pin,

even if it's a fake pin.

You know, I think.

Yeah.

Yeah.

I mean,

that but that is a critical component.

that was probably like the right move is

to just shut up don't don't give a

pin um at all uh sb ass is

powering off the phone before handing it

over also illegal powering off important

to delete the encryption key and and yeah

getting your phone to like up before first

unlock state is definitely more secure

without wiping any of that data

um that gives you more possibilities for

for defense in the future um you still

shouldn't you know give them any pin at

all like we like we just said but

i i don't actually know how this would

work i suspect it would

not be illegal in the same way at

all.

I mean,

the government can stretch any law to make

whatever claims they want,

and maybe they would claim, you know,

you deleted the encryption key by powering

it off,

and that destroyed the evidence or

whatever.

Who knows, right?

But I certainly don't think it would be

illegal to power off your device before

you've been informed of the investigation,

at the very least.

And I think this is something to consider

when you're going through...

these border checkpoints or if you're in a

situation where you reasonably expect you

might have an interaction like this with

some overreaching law enforcement,

it's probably a good idea to just have

your device powered off in the first

place.

is also probably a good idea to back

up your devices to the cloud and just

wipe them before you go through.

Only keep minimal data on your phone for

what you need for traveling, basically.

I think that that's probably one of the

strongest moves you can do.

So yeah,

there's a lot of options that would

definitely clearly be legal.

Much more legal compared to the gray area

that...

that this case is in.

But again,

I think that this case is a pretty

light gray.

I think that their case is pretty weak.

Newlywitch said,

if the CSAM turns out to be fabricated,

the privacy community needs to rally

behind this activist.

I think it's pretty clear that the CSAM

accusations are...

because the government is claiming that

this is sort of a suspected terrorism

activity in their behind-the-scenes

emails, which is not what they told him,

but that seems to be what they actually

believed.

So I think, in my opinion,

this is just...

total proof that it's probably like in

their training or something to just accuse

people of possessing CSIM wherever they

can because it's such a I mean it's

it's difficult to prove it's something you

could easily plant on people's devices

it's something that people really don't

like so it makes all of these headline

stories but since they're discussing you

know suspected terrorism activities behind

the scenes and not and not you know

investigating him for CSIM before they

told him that I

I think it's very clearly a total farce

basically.

Yeah, I would imagine the the CSAM thing,

too,

is like that is such a horrible thing

to be charged with that most people would

probably instinctively just want to clear

their name right there before those

accusations get out of control.

Like, oh, God, no, here,

please take my phone.

See, there's nothing on there.

So I wonder if that's part of why

they do it, too.

I wanted to go back real quick to

the question about powering off your

phone.

I've started doing that, actually,

because my logic is, again,

I don't have anything that sensitive that

I would

I've had my phone blow up.

So those of you who follow me know

that.

And like trying to get back into like

things like Signal and all my accounts,

it's like it wasn't really the end of

the world,

but it was still kind of a pain

in the ass.

So I would rather not factory reset my

phone if I don't have to.

So when I go through the airport, yeah,

I've started just rebooting my phone right

before I throw it in the thing to

go through the –

the x-ray because i actually have had

computers not like forensically searched

but i remember one of my it was

actually my cubes computer um because it's

literally from like two thousand twelve it

did go through the airport one time and

they were like hey we pinged is like

there's residue on here i'm gonna swab it

with a cotton swab it never left my

site she did everything right in front of

me she never turned it on or opened

it or anything but she like swabbed it

with a cotton swab and like okay you

came back clean everything's good go about

your way and so i've kind of had

that that

walk through my head of like, well,

I don't want to delete my phone,

but I also want to keep people out

before first unlock.

So yeah, as far as I know,

that's not illegal because like Jonah was

saying,

like nobody came up to me and was

like, Hey, let me search your phone.

It's me preemptively getting ahead of

that.

Like I am about to give up control

of my phone.

Let me go ahead and reboot it.

And that way,

if I end up in this situation where

they say, Hey, we pinged your phone,

I'm going to take it to a back

room, have fun.

It's before first unlock.

And also real quick,

Dag Overhaul said have a separate innocent

profile.

I mean, yeah,

that would work except if they do the

forensic thing because at that point the

phone's unlocked.

If they just do like a quick visual

search, then yeah,

what are they going to – they're not

going to find anything there.

But I don't know.

That's my thought process.

I just want to do this.

Oh,

the last thing I'll say real quick is

to definitely go ahead and check out this

four or four interview with him because

like it does require a subscription.

And I mean, it's like what?

Five bucks a month, ten bucks a month.

Just get like a one month subscription.

But it's totally worth reading because

apparently the cops like had a hidden

camera on him.

They had like a tracker on his car

and he didn't know this at the time

for the record.

He had no idea he was this targeted.

It's just it's so wild.

That's crazy.

Just another comment from DakeOverhaul.

Another YouTuber says he resets his phone

every time he's flying.

I mean, yeah,

that's not really a bad strategy,

especially if you can back it up and

restore it easily at your destination.

Honestly, when I fly to Vegas next week,

I'll be bringing a wiped...

macbook that doesn't have any data on it

um not necessarily for this reason mostly

because i don't need to bring all of

my all of the stuff on my laptop

to defcon but um you know it's typically

not a bad idea to travel with like

the minimum uh information you can so

Yeah, I'm not dedicated enough to do that.

But if my threat model was high enough

or if I was flying somewhere where like

I knew I'm almost certainly going to get

searched,

like if I was going to China for

whatever reason,

like maybe I would do that.

But.

It's definitely more of a concern like

international borders.

I don't know how much power TSA has

in this regard,

but I don't think they can do full

law enforcement investigations.

I'd have to look.

But border control in the U.S.

definitely can.

There's definitely a lot of power that

border control in other countries would

have as well,

no matter where you're traveling.

So all of those international borders,

for sure, you should keep that in mind.

Yeah, agreed.

I don't have anything else on that story.

Do you?

I think we pretty much got it covered.

Cool.

I was just going to look really quick

if we had any comments about this story

in the forum thread since this was our

kind of title story.

But we may have covered a lot of

the questions here that were answered

today.

by or asked by people in the live

stream um and maybe bob's your uncle said

i wonder if having an almost bare fake

android profile with a completely

different pin is enough for border control

um yeah i guess it depends on how

knowledgeable they are like if they're

only gonna search one profile you could

just have that one open but um that's

probably not a path i would

try to go down necessarily,

but it could be better than nothing.

I know that they can get kind of

mad about you having a blank phone.

They're like, where's your social media?

Is this legitimate?

That sort of thing.

But it's challenging to defend against the

government and law enforcement agencies in

this case because

They can kind of do whatever they want

and it gets sorted out later by the

courts.

So it's not a super fantastic system,

unfortunately.

Yeah, it looks like in the forum thread,

there was some discussion about this,

but not really a lot of questions,

just people kind of talking about all the

stuff we said,

somebody linked to that four or four

article,

somebody else linked to a Gizmodo article.

so yeah um just there's one post in

the forum i'd just highlight a sentence

from that was from trustee rock nate i'm

hopeful this case sets a precedent in

favor of dress pins i think that that

could be um one of the best outcomes

of this so we'll we'll see if that

happens um i guess it depends on how

tenuous the government thinks that their

case will be because there's there's also

cases where you see like things like this

and then to avoid uh setting a precedent

the government will very quickly drop it

but after a lot of time after you

have to spend a lot of money that

sort of thing so yeah you never really

you never really know

So real quick,

wanted to mention SB here brought up the

idea of a password strength checker,

and somebody else also said something

about using a strong password.

I mean, your mileage may vary,

but I remember Naomi Brockwell did a video

where she argued that a six-digit PIN is

probably going to be enough for most

people.

I mean, again,

if you're in a situation where you'd

rather just wipe the phone completely,

then you probably shouldn't trust a

six-digit PIN, but...

I don't know.

I it doesn't I guess what I'm getting

at is like,

I don't think it necessarily has to be

this like super crazy,

like twenty eight character randomly

generated letter, uppercase, lowercase.

Like,

I think there's a middle ground for most

people.

But I mean,

certainly if you want to do that,

go for it.

thing with that um is that the length

of this pin does directly improve like the

strength of the encryption if somebody is

able to brute force that data without any

limits um the reason you can do like

a six digit pin is because of the

brute forcing protections

in a phone,

and those are generally considered to be

fairly good,

especially with modern ones like latest

iPhones or especially like the Google

Pixel and the Titan chip on Graphene OS.

There should be enough rate limiting or

wiping it after a certain amount of time

enforced by the operating system that the

complexity of your pin,

as long as it's not super simple,

is not going to be a huge problem.

But

we have seen in the past, definitely,

definitely a good number of cases where

like we find out celebrate or gray key

or some of these other tools that these

agencies are using,

they can bypass the the rate limiting.

So

It is something definitely to consider,

especially if you're going to be in this

situation.

The other thing you could do is have

a six-digit pin on your profile and have

a separate,

longer password on a private space in your

profile.

Because private spaces,

at least on Graphene OS,

they're fully separate profiles with their

own encryption keys.

You can set up a second password for

them and...

you could sort out most of your apps

that might have sensitive information like

your banking app or your email or whatever

into a private space like that and just

keep

basic things like social media or whatever

you consider less sensitive in your main

profile.

I think that that's one legitimate thing

you can do as well.

And Dag Overhaal basically said the same

thing.

Like,

if you can get the keys out of

it,

you can brute force those short pins super

easily.

So there is that to consider.

But in theory,

they can't get the keys out of it,

and so it should be fine.

It's not as provenly foolproof as using a

longer pin.

So there's trade-offs for sure, for sure.

Gotcha.

I think we kind of got it.

Why don't you take our next story here?

All right.

I think I'm back.

I hope I'm back.

I don't know what's going on with my

internet.

I think you're back.

I didn't know you left,

but I can hear you now.

My internet keeps freezing up.

Yeah.

Interesting.

Weird.

Before we move on to the next story,

we did have one question in our forum

thread that's not related to this story.

It said,

are there any privacy alternatives to ring

cameras?

I did not do any research on this

one, but...

I don't know.

I mean,

I'm definitely not a fan of Ring for

so, so, so many reasons.

But the one thing I will give Ring

is that they've got an end-to-end

encryption that you can enable,

and I think that's a good start.

Is it true, though?

I mean, Anchor had those cameras.

Was it Eufy or whatever that were supposed

to be end-to-end encrypted?

Obviously, they were not.

Ring has a lot of other privacy problems

because they have those programs where,

like,

you can opt in to share all of

your camera footage with law enforcement

or like other programs to search for lost

dogs or something silly like that.

So, yeah, it's...

It's not a great setup.

There's certainly self-hosted setups you

can do.

There's a lot of video recording threads

on the forum you could look at with

a lot of different recommended tools.

There's some sort of cloud-based ones that

I think are better than others,

but they're gonna be unsafe if they use

the internet as an authentication later.

I'm thinking of like,

unify unify protect for example they have

good cameras but there's some like

reliance on like cloud authentication kind

of similar to like plex for example which

isn't like amazing um but there's always a

trade-off between like features because

with a lot of like self-hosted ones you

don't get a lot of useful things like

notifications uh on your phone when when

the doorbell rings or something like that

that you would get from

bigger tech company apps.

But yeah,

I don't have any specific recommendations.

I would take a look at all of

the home camera related threats on the

forum because they are probably more

knowledgeable than I am right now.

Yeah, I'm still renting,

so I haven't had much of an incentive

to look into home security that deeply.

But I'm looking here.

I know...

I know there was one that one of

our associates recommended,

and I passed that along a long time

ago,

but I can't remember what episode that

was.

AI summary,

so take it with a grain of salt.

But according to Brave's AI summary,

I looked up private doorbell camera.

It says things like Reolink and Eufy are

highly recommended because they allow

local storage without a monthly

subscription on a micro SD card.

There's also a TP-Link Taipo, Aquara,

who I've never heard of.

And then they said there's actually some

cameras that work with Home Assistant.

They're a Chinese company.

I didn't know they made the cameras they

make.

I know they make Z-Wave sensors for Home

Assistant and stuff.

I wanted to bring up really quick.

Sorry,

I'm trying to bring up a sharing screen

situation, which I don't know how to.

How do I?

I got you.

How do I share?

Thanks.

You can share my screen.

I have to remove mine.

That's why.

uh there we go uh somebody in our

signal group for supporters which you can

join by donating at privacyguides.org

donate um mentioned secluso uh this is a

raspberry pi based camera setup uh it's

end-to-end encrypted

The the secluso people are on our forum

I believe and there's a thread about it

and you can even ask them questions there

and stuff I think that's definitely one to

look into if you're in more of a

self hosting state of mind There's also

frigate and scripted as John points out in

the YouTube chat I've used

Ooh, I don't know which one I used.

I looked at both of them,

and I used one of them to get

some of my self-hosted cameras into Apple

HomeKit,

which is end-to-end encrypted and provides

some of those notifications.

And they integrate with Home Assistant as

well.

If only I remembered which one.

But I think people use both of them,

and that could be some other self-hosted

options to look into,

especially because they work...

with pretty much any LAN-only cameras.

Unredacted says, Unify Protect is decent.

Yeah,

and there are ways to use Unify products

without their cloud stuff.

If you don't connect it to the cloud,

they have a local web interface that you

can access everything on.

It's not open source,

so you can maybe take that with a

grain of salt, but...

Yeah, because something to consider.

John said scripted as a functional.

I think I did use scripted.

I think that is right.

So yeah, it is pretty, pretty neat.

I probably wouldn't integrate it with

Google and Amazon,

even though it can do that.

But Apple should be.

Apple handles that all through the Apple

TV to encrypt it locally.

So you do need to have a home

hub like that,

but it should be a bit better than

those products.

But again, that's not open source either,

so then you have to trust Apple.

There's all that stuff.

If you want a fully local sub-hosted NVR,

I would look at this Seclusa thing.

I would look at Frigate because I think

those are all good options as well.

I just wanted to say another vote for

X Protect is, again, AI summary,

take it with a grain of salt.

But it did say,

the last thing it says,

while local storage enhances privacy,

note that some manufactured data

collection may still occur for device

connectivity.

For absolute security,

consider air gap systems like X Protect or

Unify setups,

though these are more complex and

expensive to install.

So, yeah.

That's all I got on that one.

Sweet.

I think you're up for the next story

here if you want to.

I am.

All right.

Let's talk about Pokemon.

My childhood here.

We're actually going to combine these next

couple of stories because they're...

Let me throw this up here real quick.

These next couple stories are kind of all

about the rise of how private companies

are increasingly using surveillance

technology,

specifically facial recognition

technology,

uh, surveillance technology.

So this one's pretty quick.

Uh, this comes from PC or PC gamer,

excuse me.

And basically it says that Nintendo

stores, uh, it says specifically in Japan.

I don't know if it's worldwide,

but I think it's just in Japan for

now.

They say that basically they're having a

real problem with scalpers coming in and,

uh,

buying up all the cards and then reselling

them.

And then there's no, uh,

cards left over for normal,

legitimate people.

Um,

So they are going to start rolling out

facial recognition systems to verify that

customers are only coming in once per day,

which is apparently the limit.

They say the exception to this will be

children under elementary school age,

so preschoolers up to six years old.

Let me see here.

Yeah,

so this is the once a day to

ensure that players get more access to the

stock.

If the system detects that the same person

has entered the store more than one a

day or received more than one entry

ticket,

a notification to that effect is displayed

on the screen.

Entry will be denied to that person based

on the system's judgment.

Yeah,

the article kind of points out that

there's really nothing you can do about

this.

And they did go on to...

They're a little more generous than I

would have been.

This author basically said,

I've had loads of issues with the online

Pokemon Center.

It's never ending queues and insistence

that I'm in fact a bot whenever I

try to try multiple times to get a

pre-order through because the site keeps

bugging out.

While facial recognition systems seem like

it would be harder to mess up,

there is always room for error with these

things.

And unfortunately,

they say that facial recognition scans for

entering stores in Japan are not exactly

new.

Gundam stores employ the same system to

ensure people only buy one exclusive item

a day.

It seems like it's currently the best way

to combat scalpers and get popular stock

out to more people.

So I don't know that I agree that

it's the best way, but yeah,

I do appreciate them pointing out.

It's like, yeah, it's a cool idea,

assuming it works.

And I also feel the need to point

out that like,

these systems have to scan everybody.

It says like, oh,

it's not going to work on children up

to six years old.

Okay.

Maybe it's because I'm not a parent and

I don't really spend a lot of time

around kids.

I can't tell how old a kid is.

I mean,

pretty much everyone younger than me,

if they're not a teenager,

they're like six.

So I don't know.

The older you get, at least again,

for me,

it's harder to differentiate age brackets.

Again,

I can tell it's like you're adolescent,

you're

Oh no.

You're a teenager.

You're probably a young adult.

Like, but I don't understand that.

Like, did I cut out again?

Yeah, just a bit.

But yeah, my point is like, you know,

it's,

it's age verification is always like so

bad at doing things and like,

And I'm also annoyed by the part that

it says it's based on the system's

judgment.

Like,

I think I'd be a little more comfortable

if it's like a person will intervene and

double check the system, but whatever.

The only other thing I'll add is it

says that a Pokemon does explain that this

data will not be held indefinitely and

will be promptly deleted after a certain

period of time.

But this article did not specify what that

period of time is.

And then the other story that we're going

to group in with this one is about

Madison Square Garden.

And this is a summary that comes from

Bruce Schneier,

but I really liked his summary.

I think it was really well done.

So he shared a link to a story

about how Madison Square Garden is using

facial recognition software on everyone

that enters,

and they flag activists that oppose –

Using facial recognition,

they also – I think when this story

first started breaking,

it was about a woman who worked for

a law firm that was involved with suing

Madison Square Garden.

Like she wasn't even involved,

but she worked for the company,

so they wouldn't let her in in her

free time to go see a Christmas thing

with her kids.

And it turns out that last week the

system was shut off for Taylor Swift's

wedding.

And they said – well,

I'll read the ending here,

and then I'll go back and read this

quote from Evan Greer.

Bruce said that whatever privacy measures

Swift had in place for the wedding seemed

to have worked.

No photos have leaked online.

So Evan Greer,

who is one of the people that Madison

Square Garden alerts on,

says that ironically Swift herself has

reportedly used facial recognition at her

own concerts to identify stalkers.

This privacy-for-me surveillance-for-the

attitude feels like a perfect

encapsulation of the future we're already

living in.

one where wealthy elites can afford

privacy while the rest of us are forced

to live in a corporate surveillance

panopticon.

Yeah,

I don't have too much to add to

that, I don't think.

I think, Jonah,

if I can throw it back to you,

how do you feel about this idea?

Because a private company, theoretically,

has a right to do whatever they want,

right?

But it feels like there's not a lot

of regulation over this technology.

I don't know.

How do you think we should navigate this?

Yeah, there's really not.

Looking at the chat here, unredacted said,

many U.S.

states and cities outlaw or restrict

facial recognition without consent.

First of all,

least the first story about the pokemon

company that that's only in japan as far

as i know so wouldn't apply here in

the first place um but also typically you

can get this consent by basically posting

signs and i would imagine that they'll do

that because it's not really like you know

they they don't have a reason to do

this secretively they probably will post

signs to just say hey you know we're

we're on to you scalpers and and use

that as a as a deterrent basically so

I don't think that this is super regulated

at all, basically, like you were saying,

Nate.

And yeah,

there's nothing you can really...

do about some of these cases it's just

gonna be a growing issue I think

especially in this isn't like the case as

far as I know with at least the

Pokemon store story for example but a lot

of these systems will like link up with

with law enforcement I know that the

Madison Square Garden system

does connect to law enforcement databases.

The the people who work at Madison Square

Garden,

anybody like involved in the with the

business that they don't get,

they don't get information,

unless like a law enforcement agency comes

back and like, tells them, hey,

we flagged this person on your cameras,

but all of that data is basically streamed

to some law enforcement databases,

and it's all interconnected.

The other thing

yeah i i mean the other thing is

basically that comment where like when

businesses are implementing these and

they're not applying them to everyone like

you can they're not applying them to

taylor swift because she demanded privacy

at her wedding for example which i think

is reasonable obviously but it is a

situation where like the wealthy elites uh

as

as Evan Greer said,

can afford privacy while the rest of us

are forced to live in that corporate

surveillance panopticon.

Just like you said,

I think that is a perfectly apt summary

of the situation.

I just wanted to highlight again there.

It's... Yeah,

it's just not a great situation.

It really ties into...

The whole surveillance camera thing,

we're being attacked kind of from both

angles, basically.

We got cities and law enforcement setting

up plot cameras.

We got businesses setting up all of these

really advanced surveillance systems that

they're not only, like,

recording things for a limited period of

time to, like...

see who stole something off the shelf or

something like that.

But now they're like tracking people in

real time.

And they're like,

doing behavioral analysis.

And they're like making these huge

databases of people's data,

personal information,

they're linking it all up to to these

larger systems.

And this is where it really becomes a

much larger privacy concern than it was

before.

I think now would actually be a good

time to address.

We got a question in the supporters signal

chat right before we started streaming.

And they said,

what can everyday people do if they want

to travel without being tracked by ALPRs

or other mass surveillance tools?

And can the ALPRs or other cameras already

in use track people outside of cars using

facial recognition or other biometric

identifiers?

I think we're actually about to talk about

that in a minute.

But yeah, I mean,

I know there's no easy answers to that

one.

do you think there is anything we can

do as this surveillance?

Because I actually,

earlier this year when I was in New

York,

I walked right past Madison Square Garden.

I've actually been in that neighborhood

for my previous job as well.

And I remember just walking right past it

and you look around and they're not even

subtle,

like not even just Madison Square Garden,

but NYPD, like they're not even subtle.

You look at a light post and you

see like,

it looks like one of those stock photos.

There's like six different cameras pointed

out in every which way.

And there's a sign that's like,

NYPD is surveilling this area or whatever.

And it's like,

what is happening?

Other than moving out of New York and

never going back?

Like,

what do you do you think there's any

options here?

Yeah, it's,

it's really tough to do anything about it

on like an individual level.

It's, it's really the thing that it's,

it's a thing that we have to push

back against at a larger scale, I think,

and we just can't find it acceptable.

I think

I don't know what point we will reach

before we finally decide that this stuff

isn't okay.

I don't know what it'll take to make

that happen.

But yeah, it's a huge problem.

And I think it's just going unnoticed and

like, like just by the general population.

And

Yeah, it's really hard to, you know,

you're basically fighting back against

somebody with the resources of the

government, because it is the government.

And they can really, I mean,

we talk about this all the time,

you know, if the government is after you,

right,

there's not a lot you can do about

it.

And that applies even to these situations.

there's probably like things you could do

that would be wildly inconvenient like map

out routes that don't have these cameras

for example but it's not realistic i think

to avoid the you know the entire mass

surveillance system at this time uh

unfortunately because it's just very um

just very what's the word i'm thinking of

it's it's invasive and it's

pervasive pervasive it's everywhere um

somebody on our supporters chat said wear

ir blasters yeah you know blast in with

lasers i don't know i don't know what

you can do this is not you know

advice ir blasters is probably fine i

don't know how these uh cameras work so

i can't tell you if that would actually

work but that would be kind of a

funny setup

I almost sent it to our production chat

the other day since I was working on

a video.

We'll go into detail about this later,

but I'm working on a video about flock

right now, and I've checked dflock.org.

I live about a block away from a

major intersection.

There are thirteen flock cameras just at

that intersection.

Thankfully, most of them,

I actually don't think any of them are

pointed at the road,

except there is one that's pointed.

It's like, oh,

that's an intersection that I almost can't

avoid to get on that main road to

go anywhere.

There's one camera.

I'm like, man,

that thing has probably caught me so many

times just going to the store,

going to the gas station.

It's ridiculous.

It's insane.

That's just in the block around my place.

It's nuts.

I feel like we've seen reports of a

lot of cases where

Some of these flock cameras are not even

pointed at roads at all,

despite ostensibly being license plate

readers.

But they're just being used as general

surveillance cameras in general,

and they do have a lot of capabilities

beyond just license plate detection.

I think that brings us pretty well into

our next story I want to talk about

here, which was just the form post.

was a news report that was written up

by freya on our team so it's on

our website but there were some uh good

comments on there uh from the article

freya said flock styles license plate

reader vendor leonardo announced a new

system called signal trace which somebody

is talking about in the chat here too

so we can get into that but it

can fingerprint your wireless devices when

you drive by and track you around without

needing to see your license plate

When you travel in your car,

your smartphone, your smartwatch,

wireless headphones,

and even your car's infotainment system

are usually outputting a constant stream

of RF emissions.

When all of these individual devices are

traveling together,

it's likely to be the same person.

So the new devices

for tracking can be retrofitted onto

pre-existing license plate reader cameras,

and they're meant to work alongside them,

storing your device fingerprint alongside

your license plate number in a centralized

database that police can access at any

time.

One of the most terrifying things about

this, Freya says,

is that it not only identifies your car,

but it tries to identify individual people

inside the car.

For example,

if two people are riding together,

it can detect each person's individual

fingerprint separately.

It also means that the readers work if

you're not driving.

Simply walking around,

biking close enough,

will likely mean that your unique RF

fingerprint is now stored in some

database,

and your movements can be tracked.

Kind of ridiculously,

Leonardo tries to advertise that their

system, quote,

respects individuals' privacy rights,

end quote,

because the actual data itself isn't

decrypted or read.

but as Freya points out,

this is definitely an example of the

metadata being more useful than the

content, even if, you know,

police can't see what your actual, like,

MAC address or other device identifier,

I-M-E-I-I-M-S, M-Z, uh, what have you, um,

even if they can't read, like,

the actual numbers,

this system that Leonardo has built

basically, uh,

has already tied all of those identifiers

to other things that identify you.

So the content doesn't actually matter.

It's still a huge privacy concern.

Yeah, so again,

it is really a question of what can

you do to defend yourself against this?

And it's very tricky because these systems

are already in place.

Yeah,

scarecrows in the chat says surveillance

cameras respect your privacy because they

can't see through your clothes or inside

your bags.

That's exactly the same sort of argument,

right?

If you're tracking all of this metadata,

you're tracking people exactly where they

are, what they're doing.

It's not a privacy-respecting situation

just because you can't later look up what

exact device identifier was being tracked

at that time.

It's...

It's a huge privacy problem.

It's completely ridiculous that they would

claim otherwise.

Scarecrows also said that it looked like

the Texas Department of Transportation has

antennas on all their camera poles now,

so they're probably adding that in.

They haven't seen anything officially

saying they're Leonardo's signal trace,

but they look the same.

So, very, very concerning stuff,

and I think... I don't know, like...

how prevalent uh leonardo is compared to

flock but i'd be concerned about that i

also wouldn't be surprised if flock um if

they don't have a product like this

already is working on something like this

because as as terracotta pie in the chat

said uh why the world is just becoming

so surveilling and intrusive that's that's

so true and it is a huge it's

a huge problem

I mean, that means we fixed crime, right?

Like, you know,

there's no place in the world right now

that an ant can't pass gas,

that it's not caught on some kind of

camera.

So clearly we've solved crime.

Yeah, we've solved it.

Nobody has ever done anything bad since we

added these systems.

So I guess it's totally worth it.

Yeah,

I think – I know it's kind of

a rhetorical question,

but I think things like this go –

I think –

I know this comes from CalixOS,

and Henry and I talked about it at

Surveillance Report,

but I feel like they really have the

best model in the sense that privacy is

a three-pronged approach.

There's the technical side,

the legislative side,

and the education side.

And

You know, we've talked about this before,

like the people who just think like, oh,

well,

I'll just use Linux and like all this

this, you know,

age verification stuff won't affect me.

Yeah.

Until the person you're messaging is using

Windows and all your stuff is getting

scraped up in Windows recall and all that

kind of crap.

And then, you know, or until like.

Canada bans encrypted messaging and signal

says,

we're not going to service that place

anymore.

Like, what are you going to do then?

And, uh, but you know,

at the same time, it's like, yeah,

obviously companies break the law.

We can't just solely rely on these

laughably low fines.

And I think this is a case of

like the education one where like people

don't understand.

And I think a lot of it is,

um, a lack of,

I don't want to sound mean when I

say this,

but like a lack of empathy in the

What was her name?

Shoshana Zuboff in Surveillance

Capitalism,

The Age of Surveillance Capitalism.

She tells a story at the very beginning

how her house literally exploded.

It burned down and exploded.

And she talked about when the house first

caught fire,

she was trying to gather up all her

notes and stuff because she had no frame

of reference for –

what was about to happen.

Like,

it's just one of those things where like,

when you don't have a frame of reference,

you don't even think about it.

It's, it's the whole, sorry.

I know I'm rambling a little bit here,

but I'm, I'm going somewhere with this.

It's the whole, like, you know,

when people think like, Oh, well,

why would anyone want to hack me?

Like, I'm not interesting.

Or like, I have nothing to hide.

It's like, yeah, it's,

Because you're a decent person whose brain

doesn't immediately think of all the

horrible things you could do with

somebody's data.

And I think it's the same thing here

where like normal,

not crazy people think about surveillance

cameras and they're like, oh yeah,

we can find like stolen cars and Amber

alerts and like deter a crime.

And like, yeah, this is great.

And because they're not completely insane,

they don't stop and think about the cops

we talked about a couple of weeks ago

who are like stalking,

not even their girlfriend,

a girl who turned them down.

you know the all the hacked cameras that

allow pedophiles to look at playgrounds

that i think we covered one story about

a camera that was or maybe i wrote

about it in like a data breach or

something but like a um flock cameras that

were like placed inside a gym at a

community center and rightfully people

were like why was there even a camera

in there in the first place like you

know normal people don't think about all

the bad things that can happen because

they're not bad people

And yeah,

I think that's really what it is,

is it's a lack of education where people

don't.

And furthermore,

it's like this is one of the reasons

I post the data breach thing every week

is because it's one thing to say this

could happen.

It's another thing to show articles and go

like this does happen all the time.

Here's the twenty pages of search results

of all the times this has happened.

And I think that's when it'll really start

not not to try and scare people because

that doesn't work,

but to just make people realize like this

is not hypothetical.

This is not theoretical.

This is happening.

And we have to factor that into the

math.

Thank you for coming to my TED Talk.

Tip your service.

Scarecrow's in the chat here.

about those cameras you should post a

picture of these if you can to the

to the form uh have people take a

look at them because i think we can

we can try and track them down yeah

it is i mean of course these are

going to go brandless at this point

because they don't want to get any

backlash of course um but yeah it's a

huge huge problem post it on the forum

discuss dot privacyguides.net it's a great

great place

Yeah,

tag me in that because I'm on the

board of EFF Austin,

and I think I know what you're talking

about, but it's been so long.

I no longer live in Texas,

and even at the time,

I never really stopped and stood on the

street corner and like,

let me get a good look at this.

But yeah,

tag me because I can share it around

with the other board members,

and maybe we can identify what those are

and figure something out.

Or maybe somebody already knows for all I

know.

I've never asked about them before.

Yeah.

Okay.

Oh,

the one last thing I wanted to share

on this topic is somebody left a comment

on this story,

which is why I included it as a

forum post and not an actual story,

where they said the part about this

Leonardo thing can track RFID devices such

as credit cards.

They said, I cast suspicion on this claim.

Even if we pretend they aren't –

trying to scan RFID through the metal

panels of your car,

which should normally neutralize RFID.

I have no idea how they can even

pretend to scan a passive RFID signal,

such as that of a credit card,

from several meters away.

Its range is a few centimeters.

The signal-to-noise ratio is going to

render the signal as unreadable noise at

any large range.

They make a really good point because I

do use Apple Pay sometimes.

And like, depending on the terminal,

sometimes like if I'm just a few

centimeters or inches off,

it won't read the and I know that's

like NFC, not RFID.

But yeah, these things are so low powered.

It's like,

how are you going to read that from

ten feet away?

That doesn't even make sense.

So big, if true,

if they've mastered that technology,

that's impressive.

Alrighty.

I think that'll bring us into the site

updates if we don't have anything more to

add to that.

All right.

So yeah, in a little bit,

we're going to give you guys an update

on a story about some eBay executives.

If any of you remember that story,

they threatened and harassed some people

who left some negative reviews.

And we're not just talking about like

legal letters.

But before we get to that,

we're going to give you some quick updates

about what we've been working on at

Privacy Guides this week.

So I mentioned I've did some work on

a flock video.

That's because our video about Bull Run

and the NSA's

It's not the latest attack on encryption,

but the next chapter in our series is

done.

It looks great.

Thank you to Jordan for all of that.

And it should be going out to members.

I think we're trying to release it this

weekend.

So if you are not a member,

definitely sign up,

get early access to that.

This is my first time filming a

storytelling video like that.

And I'm really excited with how it turned

out.

And I think you guys are going to

enjoy it.

And then, yeah, just a little teaser.

Our next video that we're already working

on is about flock and, uh,

D flocks national day of action.

And, um, I believe it was Jonah that,

that did some digging and realized like,

man, other than Ben Jordan,

there's not really a lot of privacy people

talking about flock.

And so we thought it would be really

cool for us to step in and, uh,

hopefully this will be a really good video

that.

Explains what Flock is,

explains what are all the problems with

it,

gives that list of twenty pages of search

results that I mentioned earlier,

and is hopefully something you guys can

share with friends and family to be like,

hey, go talk to your city councilors,

email your politicians,

and tell them you don't want this.

So,

that's what we've got going on on the

video side.

Sweet.

On the website community side of things...

Some stuff I'm working on,

there's an upcoming kind of redesign of

the site to make it a bit easier

to maintain.

We were using this software called

MakeDocsMKDocs,

which is basically being discontinued.

There's a whole...

don't know a lot going on with it

uh so we're working on kind of a

new yeah that's kind of the driving force

behind this so we're switching to uh

should be switching to hugo uh for that

which should make contributing a little

easier hopefully and uh we're gonna

redesign our blog make it a bit easier

to navigate um besides that i've been

looking into security keys lately uh

that's been

mostly what I'm doing this week.

There's a lot of stuff going on that

makes them really annoying to come up with

good recommendations and criteria.

A lot of cases where security keys aren't

certified or they are certified,

but they don't report themselves as

certified in some cases,

so then websites can't tell if they are

or not and stuff like that.

There's varying...

Varying security practices with all of

these,

and it's hard to find one super great

solution.

Because of course,

YubiKeys have been traditionally the top

recommendation,

but there are drawbacks to them for sure.

You can't back them up,

which people find very inconvenient.

If you switch them out or update,

you have to...

switch them out on every single website

you visit, which is really annoying to do.

So yeah,

a lot of a lot of stuff like

that.

So continuing to look into those pretty

much there's a thread on our form at

discuss the privacy guides.net.

Again,

talking about there's like multiple

threads, basically,

there's some tool specific ones,

there's comparison ones where people are

sharing kind of opinions about all of that

stuff.

So if you have any thoughts about

security keys for some reason,

you can chime in there.

Otherwise,

Free has been working on articles.

We talked about

that one earlier,

but there's been other ones throughout the

week.

They get posted to privacyguides.org slash

news,

and it's a great way to stay up

to date with some other stories that we

don't talk about on this weekly show.

Some of the stories include over a hundred

vulnerabilities being found in the IRS's

contractor handling Americans' tax

information.

New dynamic patching in Chrome is going to

allow updates without restarting the

browser.

And then, of course,

those stories that we talked about today.

All of the stuff that we just talked

about in this section,

it's made possible by our supporters.

You can sign up for a membership or

donate at privacyguides.org.

Or you can pick up some swag merch

at shop.privacyguides.org.

Hopefully,

I can expand some of that stuff with

new sticker designs in the future,

but we'll see.

Privacy Guides, all of us here, of course,

we are a nonprofit.

We research and share privacy-related

information.

We host communities like our forum,

for example.

We have chats on Matrix where people can

get advice and stay up to date about

digital privacy and preserving your

digital rights.

So yeah,

with all of that out of the way,

let's...

We're going to talk about an update to

the FCC router ban that we discussed a

few episodes ago.

I don't remember exactly when that was.

First,

I'll check the chat really quick for some

stuff.

Derek, twenty three fifty eight.

Looking forward to the vlog video.

Yeah, I hope it'll be good.

And it's been working on that for a

bit.

So hopefully we can get that out pretty

soon.

Tony Mojo said the same thing.

Yeah, I think it should be.

It should be fun.

It's definitely a little bit more entry

level.

It doesn't dive in super deep.

But again,

there's so little content out there as it

is that I think we kind of wanted

to start very surface level and give

people kind of an on-ramp to understand

the problem.

At least that's what I was going for.

Yeah.

I also just wanted to say real quick.

Yeah.

The, the security keys do have drawbacks.

Like right now I'm trying to get back

into using the Tor browser a lot more

and it's like, oh, cool.

I can't even log into Tudor because I

added the security key and remove TOTP.

So yeah, that, that is a bummer.

I hope Tor can figure that out at

some point.

I don't remember if mall that browser has

enabled it.

I know they were looking into it at

one point,

but I was going to say they haven't

yet, but I, yeah,

I know they're trying to,

so hopefully soon fingers crossed.

This story was reported by Ars Technica.

The Trump administration exempts SpaceX's

Starlink from the FCC ban on foreign-made

routers.

A public notice issued by the FCC said

Starlink routers received approval from

the Department of Defense.

SpaceX's exemption is good until February

first, twenty twenty eight.

Netgear's exemption,

which we're going to talk about next,

is only good until October of twenty

twenty seven.

Netgear was the first major vendor to get

an exception to this rule on April

fourteenth.

Amazon then received an exemption for its

Aero routers and the routers to be used

for its Leo satellite service.

I would remind people we talked about this

in the episode where we first discussed

this FCC router ban,

but like there are pretty much

no routers made in America.

And it's not like super easy to just

spin up router factories overnight.

So of course,

there would have to be all sorts of

exemptions to these laws.

I do think

We'll get back to this in a second,

but I do think it's kind of arbitrary

how these are being applied.

The article says SpaceX has a factory in

Texas and some of its routers have the

words made in the USA printed on them,

leading some to believe that it might be

the only major router maker to escape the

FCC's wide-ranging ban.

Yeah, exactly.

But other Starlink routers are made in

Vietnam.

So, some discussion topics here.

The FCC hasn't publicly shared what

criteria these companies meet to get

exemptions.

And this is the main problem that I

have with all of this stuff.

It seems to be kind of arbitrary whoever's

in the Trump administration's favor at any

given point in time.

It seems like they are often...

kind of coerced or threatened into making

whatever changes the government wants in

order to preserve their business.

I am really annoyed right now,

not because of...

routers but because of some stuff that's

happening with the company that makes my

car i have a pull star too and

they've been banned from selling new

models in the us because they're a chinese

company it's a strange situation because

like their sister company volvo is owned

by the same parent company and they

received an exemption um it seems like

other car manufacturers are receiving

exemptions

as well,

but that kind of relates to a similar

thing as these routers where it's

computers from foreign countries that the

Trump administration doesn't want in the

USA.

It's very strange because all of the

computers in Polestar's cars as well as

Volvo's run

android automotive so like it's it's all

designed by a by a american company

basically uh so why they are concerned

about those computers it's not very clear

to me but it's just it kind of

seems to be whoever is putting in the

effort to basically convince the trump

administration

that they should keep their business

around is getting exemptions.

And in that case,

Polestar just didn't really bother with

it.

But it's annoying that all that stuff is

happening in the first place.

Anyways, I think that was my main thought.

Nate,

what were you thinking about this article?

Did you have any thoughts or questions

about it?

Um, not really too much.

Uh, I mean, you,

you kind of nailed everything, you know,

it's like, even from the beginning,

the government hasn't really said like,

what exactly is their criteria here?

What is the threat they're trying to

defend against just some vague national

security, which, you know,

the government's always done like, Oh,

national security.

But now they're like really kicking that

into overdrive.

And, um,

I think the article also noted that it's

interesting that these are all temporary

exemptions.

But once they're up, it's like, okay,

what happens?

They can reapply,

but I guess they're also supposed to show

progress that they're moving manufacturing

to the U.S., which, like you said,

just does not happen overnight.

So, okay, this is an extreme example,

but –

I checked on it the other day out

of sheer boredom.

Samsung semiconductor factory that they're

building in Texas.

That sucker's been under construction.

I think they broke ground in like twenty

twenty one or something like that.

And every year they've been saying we're

going to start putting out chips in the

spring.

We're going to start putting out chips in

the fall.

They're still not putting out chips.

I don't know what they're doing.

That's happening, I think,

with a lot of these companies in America.

There's one in Arizona I know of.

I don't remember if it's TSMC or Intel,

but somebody's building a plant out there.

I think it's TSMC.

Yeah, and that's been a similar situation.

Routers might be an easier one to make

in the U.S.

I know that they really want chip

companies to move manufacturing to the

U.S.,

but that is such a specialized tool that

even TSMC...

is gonna have a very hard time moving

that manufacturing capacity to the US if

they want to because it's not just a

matter of like getting the plans in the

machines and like making it here some of

these products require like real experts

in the field and like pretty much all

of them in that case are in Taiwan

so where are they in America who can

even do this stuff you you actually need

the people involved in it actually just is

true that

there aren't enough people in America who

know about that stuff to implement these

things.

So I think that that's going to cause

delays.

I think it's just the thing where like,

clearly favors Elon Musk, basically.

That's kind of the favoritism we've seen

with Tesla and his other companies.

We've seen it with like OpenAI and Sam

Altman.

There's just some companies that the

government really likes.

I think we talked about that when

anthropics fable models where were banned

by the us government for some period of

time and that was an american company you

know there weren't even like chinese

concerns which is usually the excuse that

they use um so yeah i i don't

think anyone's really safe from these

sorts of restrictions unfortunately yeah

honestly i was surprised it took starlink

this long to get the the exception i

wonder if they just didn't bother to

to apply for it or something.

But yeah, it's, it's like you said,

there's so many like with these, I mean,

I don't know about routers,

but with semiconductor factories,

it's like in some cases there's like very

specific niche equipment that's made by

like, I'm not even making this up.

There's some stuff that's only made by

like a single company in Germany that has

like ten people.

So they're back ordered by like six to

eighteen months on this equipment.

And then that's not including the facility

itself,

which granted the Samsung semiconductors,

the conductor factory is like one of the

biggest in the world.

So that's probably a bit of an exception,

but yeah, it's,

it's not like you just rent an office

space,

throw in a few cubicles and start printing

out stuff.

Like even with these routers, it's like,

this doesn't just happen overnight.

It's.

Yeah, and it's going to be,

it's kind of a situation,

I think a lot of these businesses who

are affected are going to have to face

the question of like,

is it even worth sticking around in the

US?

And I think probably more businesses may

opt out of that than the Trump

administration probably expects.

Going back to the whole Polestar thing,

I know that like,

it's only five percent of their US sales

or something like that were in the US.

They're big in like Europe, for example.

And in I assume the reason that they

didn't really pursue an exemption in that

case was because it'd be way cheaper to

just drop that five percent of sales than,

you know,

try and meet all of these demands that

the government has.

And I don't know if that'll be the

case with like Netgear, for example,

but spinning up this this manufacturing

capability is not.

cheap so giving up on us sales for

a lot of these companies might actually be

the more cost-effective way to go even

even for american companies like like

netgear is an american company for example

they just manufacture overseas like pretty

much every other company in the us does

so it'll be a weird time in tech

i think it'll be bad for americans overall

because

Americans have gotten really used to tech

being very cheap.

If you ask anybody from any other country,

even like nearby countries like Canada,

but especially Europe,

especially like far away from everything

countries like Australia.

tech is way more expensive to buy pretty

much everything in those countries

compared to the US.

And I think that changes like this are

just going to really push up the price

to...

like not exorbitant but basically it's

going to be meeting the the prices of

other of all these other countries and

we're just kind of going to be in

the same boat um we're just not going

to have the advantages that we've enjoyed

for for quite a while and that'll be

probably a shock to a lot of people

i don't have much more to add to

that i agree

Tough times are coming.

Yeah.

Well,

why don't you take us away with our

next question?

Speaking of Europe.

Yeah.

Speaking of Europe and tough times are

coming.

So this next story comes from Telegraph.

It says inside the dystopian world of

Germany's free speech crackdown.

I'm going to read off the notes that

I made here because this is a very

long article.

Definitely worth a read.

Lots of good stuff in there.

But I'm going to read off my notes

just to keep it short.

to the relevant parts.

So Berlin police told Dr.

Ziedelman he had been accused of violating

a post-Second World War law that bans the

display of Nazi symbols, slogans,

and imagery and could now face three years

in prison if found guilty.

The sixty-nine-year-old found out the

offending social media post was a meme

about Adolf Hitler,

but it was one in which he criticized

the Nazi dictator and compared his

invasion of Czechoslovakia to Vladimir

Putin's invasion of Ukraine.

So basically, like,

I'm saying Hitler is bad.

Why is this

Yeah.

Dr.

Z is one of thousands of Germans who

have been threatened with fines or prison

sentences for social media posts that fall

afoul of the country's political speech

laws,

which are unusually stringent for an EU

member state.

One German had his home raided for calling

a minister a –

Schwachkopf,

which I guess is German for dummy.

And I'm sure all the Germans are laughing

at my pronunciation right now.

Another was fined two thousand euros or

about seventeen hundred pounds for calling

Friedrich Merz a lying fritz under a law

that critics claim makes it effectively

illegal to make fun of politicians.

The number of investigations under Section

eighty six a the Nazi symbol band that

Dr.

Z was investigated for has more than

doubled over the past decade,

according to official police statistics.

Investigate investigations into the

political insult law also reached a record

level in twenty twenty five.

The surge in cases is so vast that

the U.N.

has launched an investigation into free

speech violations in Germany,

a step typically reserved for

dictatorships and banana republics.

German free speech activists on the left

and right,

as well as the Trump administration,

have also raised the alarm,

and there are growing calls from some of

the country's stricter laws to be

scrapped.

The fur bears some similarities to the

speech debate in Britain,

where citizens have a knock on the door

from police over opinions posted online.

Uh,

this part blew my mind in the case

of Dr. Z,

the rise of online portals in Germany,

which allows citizens to report each other

for illegal comments seems to be what

alerted police to a social media post.

So they literally have like Stasi style

snitch on your neighbor because something

he said hurt my feelings.

Which is pretty insane.

Another controversial law in Germany's

free speech debate is section one eighty

eight of the criminal code,

which imposes a de facto ban on publicly

insulting or defaming elected officials.

In one recent case,

a pensioner was investigated under Section

one eighty eight for posting Pinocchio is

coming on Facebook.

After he learned that Frederick Mertz,

the chancellor, was visiting his hometown.

In November,

twenty twenty four police in Bavaria

raided the home of another pensioner

because he called Robert Habeck,

the then vice chancellor of Germany,

again, a dummy.

The raid was reportedly launched after Mr.

Habeck personally filed a criminal

complaint against the pensioner.

In twenty twenty one,

police raided a man's apartment in Hamburg

after he told a senator,

you're such a D. I'm assuming it's dick.

I don't know.

And this year,

a resident was fined two thousand euros

for calling Mr. Mertz a lying fritz.

Officials show a record four thousand

seven hundred and ninety two section one

eighty eight cases were filed in Germany

in twenty twenty five,

with the numbers rising by nearly eighty

five percent between twenty twenty three

and twenty twenty five.

So, um.

Yeah, I mean, this is...

This kind of goes back to the thing

that I said with the graphene thing,

where it's like...

Some people are totally comfortable...

painting a target on their back because

it's the principle of the matter, right?

Like you should be allowed to call your

politicians names.

I'm sorry,

but no matter what politician it is,

as long as you're not like threatening

them,

you should be allowed to say that they're

stupid.

You should be allowed to say that they're

corrupt.

You should be allowed to say that they're

not doing a good job.

Like you should be allowed to criticize

them.

And I think if you're,

It's one of those things where like we're

seeing this all over the West,

unfortunately,

where this kind of stuff is being

monitored.

We know that the feds here in the

U.S.

at least are monitoring social media.

That's what services like Palantir do is

they just scrape social media,

even the really fringe niche ones that

only have like one hundred thousand people

using them.

So just remember that what you post,

even if it's like friends only or

something,

anything you put in a digital format,

you should kind of assume it's public.

And just be aware if you're one of

those people who's like,

I'm going to go ahead and stand up

for my right for free speech.

Like, that's totally cool.

I applaud that.

I do that, too.

I'm very critical of all levels of

government on Mastodon.

But at the same time,

just you need to be aware of the

risk you're taking.

So and Germany needs to figure out what

they're doing if they're getting

investigated by the UN.

I think that's pretty wild.

I don't know if I have much more

to add to that.

Did anything jump out at you that I

missed?

No.

No, I don't think so.

I think you pretty much covered it.

Yeah,

it's just like we talked about earlier in

terms of government overreach, basically.

Are you willing to take the risk of

being targeted by these governments,

even if you're not doing anything wrong?

It's a pain.

It's a hassle that they can really put

you through,

and I think that that's a big problem

we have to face right now.

Good times.

I have not heard of this Gulag Archipelago

that Scarecrow recommends.

So I don't know.

I can add that to my reading list.

I haven't heard of that one before.

Sounds like something that somebody in

Russia may have written.

I'm not seeing any other questions right

now.

So I think we can probably jump into

our story about eBay that I know you

were interested in.

Yeah, that's a crazy one.

Yeah, just checking the chat here,

but we'll look at this TechCrunch article.

eBay reaches a fifty six million dollar

settlement with e-commerce newsletter

writers it terrorized in twenty nineteen.

I remember reading about this in twenty

nineteen.

Well,

I guess I didn't remember I read it

in twenty nineteen, though.

I thought it was an older story.

It's a lot more recent than I thought.

The article says the settlement this week

resolves a twenty twenty one civil case

that was brought by the couple against

eBay.

The couple is a married couple,

Ina and David Steiner,

who were the co-authors of eCommerce

Bytes.

They inspired the ire of high-level eBay

executives, said TechCrunch,

after occasionally criticizing the company

in their newsletter.

uh executives from ebay used sock puppet

social media accounts to harass the couple

while also sending them anonymous

threatening letters and bizarre items in

the mail including live spiders and

cockroaches pornographic magazines a

bloody pig mask a funeral wreath and a

book about surviving the death of a spouse

so this is not just the typical legal

harassment you might see from a company's

lawyers this is an actual

criminal harassment and stalking from

top-level executives at eBay.

According to previously released court

documents,

a plan that was attempted but never

successfully carried out involved affixing

a GPS tracking device to the couple's car.

Yet another internally broached plan at

eBay involved sending a, quote,

Samoan gang to the Steiner's home.

In a statement published Tuesday,

eBay disavowed its former employees'

behavior as, quote,

not representative of eBay's culture.

So that is a crazy story.

I know that eBay made that statement.

statement obviously but uh people up to

the ceo of the of ebay uh devin

uh weinig and uh multiple board members

were involved in this uh the ceo settled

for two million dollars as part of the

settlement uh was directly from him uh

half a million dollars will be paid out

from uh another ebay executive wendy

Jones and seven former eBay employees were

criminally charged and pled guilty in

relation to this plot,

including the company's former security

chief, James Bout,

who was sentenced to nearly five years in

prison for this.

So it's wild.

eBay is crazy apparently.

And I believe a lot of the people

like, um,

A lot of the people involved are still

on the, at least the board, I believe.

I know that the CEO is the former

CEO.

I don't know who's involved now,

but not all of them were, like,

very punished, basically.

So... I guess, um...

Getting fifty six million dollars is not

the worst outcome for these people.

They're probably happy about that because

they settled.

But it is absolutely crazy that they had

to go through that in the first place.

You know,

a targeted harassment campaign like that

is not exactly typical of a company like

eBay.

So, yeah.

Was there anything you wanted to discuss

about this article or any other thoughts

that you had, Nate?

No,

I think partially I wanted to cover it

because one, like, yeah, it's so wild.

It's like, these are executives, right?

And it's funny because I've noticed I've

worked around every level of employee you

can imagine from like the entry level

cashier at the grocery store to like I

have stood ten feet away from someone

who's in the top twenty on the Forbes

billionaire list.

Like I have worked around everybody you

can imagine.

And I've noticed a curve of like.

I don't want to drop an F-bomb of

like how many craps they give where like

the lowest level people don't care.

Like they're never stressed.

They don't care.

Well, I mean, they're stressed,

but like they don't care because they

don't get paid enough to care.

And then on the other end of the

spectrum is like all the higher executives

that don't care because they pay someone

else to care.

And then right in the middle are all,

like,

the middle managers that are just

constantly stressed and high-strung about

everything.

And so it's just weird to me that

there's, like,

all these C-suites and executives that

it's just, like,

why are you wasting your time because

somebody, like,

left you a negative review in their

personal substack?

Like, seriously.

Truly, like,

when we were talking about this article

earlier today,

if you had asked me about this story,

because I knew of this story.

I remember reading the original, like,

story about it.

But I would have told you,

I remember this happening in like,

two thousand eight or two thousand ten or

like some sometime like early eBay,

basically,

where it's maybe it's a small company and

they're like personally invested.

But this started in early twenty nineteen,

this whole thing like eBay is a massive

company at this point.

And you're concerned about some couple's

newsletter on on a blog online.

It doesn't even make any sense at all.

It is the wildest story I have ever

seen.

And, yeah,

I guess I don't even know what else

to say about that.

It's crazy.

Yeah, it really is.

Also, just, you know, privacy.

Be careful what information you put out

there, who has access to it,

all that kind of stuff.

Yeah,

you never know who's going to stalk you,

apparently.

Seriously, that's so wild.

You would think they'd have better things

to do.

I sure would if I was being paid

that much.

Just to backtrack,

Scarecrow was talking about that book.

He said, yeah,

it's about someone's arrest in nineteen

forty five for private letters to a friend

about Stalin.

Imagine your letters from seven years ago

came back to smack you in this way.

Eight years of hard labor.

Yeah,

I kind of want to point that out

that not not to fear monger,

but this is something I hear smart people

point out all the time is like.

Again,

why privacy matters is a lot of the

time.

in an authoritarian or repressive regime,

when the new guys take over,

they will retroactively punish people for

things that happened before.

So in a functioning democracy,

usually a law will be passed and they'll

say, okay, from this point going forward,

this thing is illegal.

But like when the Taliban took over,

I distinctly remember this story because I

remember thinking how sad it was.

When the Taliban took over in Afghanistan,

when the US pulled out,

Afghans were rushing to like delete their

online presence because for years,

a lot of them had been like kind

of slowly westernizing.

And now they knew that some of the

stuff they did that was like totally

innocent, like, you know,

maybe women wearing blue jeans could get

them killed now.

And they were trying so hard to scrub

their social media presence and stuff like

that because now what they did in the

past is yeah.

And like, I don't,

I don't think we should all be living

in fear, but it's just, again,

be mindful of it's yeah.

Privacy matters.

It's very unfortunate.

But yeah, that's all I had, I think.

I think those were all our stories.

So I think we can check around,

see if we have any more final questions

before we wrap up here.

I think we only had one forum post.

Send them in the chat if you have

any.

I did see a forum post I wanted

to look at, actually.

Sure.

One of the top stories from the last

week.

Somebody posted on the forum,

does your privacy setup actually make you

stand out more?

They said for the past month and a

half,

they've been trying out some VPN services

on their phone,

trying to see which one works better.

So they talked about different VPN

providers that they used.

But they said that they received a message

from their IT department basically saying

they connected,

they detected a connection to their work

email account from an IP address

associated with Malved VPN and they wanted

to confirm that it was them and why

they were using a VPN service for that

connection,

which of course did not make them feel

very private.

It is.

So like,

it is a concern with some of these

tools.

Absolutely.

Uh, we,

we talk about this a lot more in

like the browser fingerprinting context

where it's like using something like

Mulvet browser, for example,

or even brave, uh,

might make you more fingerprintable to

people who are specifically looking out

for it.

A lot of these privacy tools that we

recommend are really geared towards, um,

thwarting mass surveillance tools.

They're effective at blocking like,

ninety-nine percent of the general things

that you'll see on sites,

whether that's like Facebook tracking or

ad networks or that sort of broad

surveillance,

whether that's by companies or otherwise.

When it comes to like,

individualized privacy advice,

it is more of a

There's a lot of threat modeling you have

to take into account.

You have to decide who you're trying to

defend against from a privacy perspective

and how you want to stand out.

Because if people are looking at you

specifically,

they can detect that you're using these

privacy tools and that can be a red

flag in some cases, like this one,

for example.

There are certainly ways to work around

this.

One way, like on phones,

at least Android phones, for example,

I see people use private spaces or work

profiles in their main profile because you

can set a VPN connection for only that

profile and the apps inside that.

And then you can have like a private

space with a VPN for most of your

general apps and then keep like...

work stuff for local stuff like your bank

in a in a profile that doesn't use

a VPN.

But yeah,

it really depends on your individual

situation in that case,

which is why

If you have any questions about that sort

of thing,

it'd be great to ask on the forum.

There were a lot of good responses in

that thread.

I won't go through all of them,

but that was kind of my two cents

on that, and I wanted to highlight,

I think,

a related question here in the chat from,

and maybe Bob's your uncle.

If you obfuscate a connection to a VPN

like you can with Tor Bridges,

does the ISP still know you're connecting

to a VPN?

That is the sort of thing where it's

also...

suspicious, or it can be.

There are different obfuscation methods

that are less fingerprintable.

So like web tunnels with Tor, for example,

are supposed to be less identifiable,

which is why they can get around

censorship in some countries.

I don't know what specific tools you would

use with a VPN,

although some of that Tor bridge software

is kind of generic and could be used

in theory for that sort of thing.

But even in that case,

I think it's a little suspicious if you're

just sending like a large amount of

traffic every day to one specific IP

address and there aren't a ton of ways

around that so I guess I don't know

off the top of my head if there's

any like VPN clients that will rotate

different connections between different

IPs or VPNs or whatever I'd have to

look into that but um I think I

think either way typically

Your ISP definitely can detect whether

you're using a VPN.

They can also detect whether you're using

Tor.

The Tor network,

maybe that's a common misconception people

have,

but it doesn't hide the fact that you're

using these things or like you're

devices or whatever from the ISP

specifically.

The only thing that it will hide is

a lot of metadata about that traffic,

like the domain names you're connecting to

and IP addresses, etc.

How much you're sending to like one

particular source.

But that's why we say VPNs are,

they're not like a foolproof solution.

They're

Just shifting trust from your ISP to that

VPN provider in most cases,

but they're not like the perfect privacy

tools and they can be detected.

So it is something that you have to

keep in mind.

Yep,

I don't really have anything to add to

that.

I did see that question.

I thought it was really interesting

because, yeah, I thought about,

like you said,

we usually see it talked about in the

browser space where if everybody's using

Movad browser and you've got all the

shields and uBlock turned on,

then you stand out.

But it's definitely a lot different when

you're talking about very specific use

cases like at work or they talked here

about trying to access their bank and

stuff like that.

So it's a good thread, though.

Lots of good info there.

Check our signal donors chat again real

quick here.

Yeah, I've been kind of bouncing around,

checking the forum thread,

not seeing anything new.

Scarecrows in the chat said,

Zuma?

I'm not familiar with who that is,

but they made a video about the government

vandal events.

Maybe that's worth checking out.

I'll have to add it to my list

of videos.

I assume there probably are ways of

obfuscating some of that information,

but typically with VPN companies also,

the IP address that you're connecting to

is visible and known to be a VPN,

so they can just know that way.

A lot of the deep packet inspection stuff

that I've seen is like,

claims that your ISP could use that to

detect what specific sites that you're

connecting to even when you're using a VPN

and people say the same thing about the

Tor network that they can use that to

see to kind of gain more information about

what you're doing on Tor in addition to

just the fact that you're connecting to

it.

I haven't seen any evidence that that can

be reliably applied in the real world.

I know that

It's all just theoretical,

and I think that some VPN providers like

MOLVAD with their data, D-A-I-T-A program,

they claim to defend against that sort of

thing,

but also I've never seen any proof that

that sort of thing can be reliably used

outside of lab academic settings,

basically, with small groups.

At an ISP scale,

I don't think that deep packet inspection

is going to be a huge issue.

But there are,

if you are concerned about that,

there are, of course,

obfuscation techniques.

As Unrejected said,

there's also advanced protocols like

X-Ray.

Reality, that's sort of a similar thing.

Spoof the TLS signatures of other sites.

I'm not totally for sure with how that

works.

I think...

Similar to web tunnels if I remember

correctly that Tor has but I could be

I could be wrong I know a lot

of these tools Especially ones that

unredacted org works with you should

definitely check out their site by the way

because you're doing a lot of cool stuff

with like the Tor network and stuff but

a Lot of those for like anti-censorship

purposes can get around that sort of thing

I Would

I will have to look more into how

this works because I'm not sure.

I feel like, like I said before,

I think sending a lot of traffic to

one specific server is probably suspicious

in itself.

But yeah,

some of these tools can add more plausible

deniability.

But maybe there's other things that it

does that I don't know or remember off

the top of my head.

So I'll have to look into that later.

I wanted to mention scarecrow said here

that, um,

several politicians have suggested that

this sort of stuff may earn you extra

scrutiny.

I remember we covered that story a little

bit,

and I think what they were actually saying

was that it's not so much that using

a VPN will make you extra interesting.

It's more that, um,

so the way that section seven Oh two

works is any electronic signal that

crosses international borders becomes a

fair game for the NSA and

With a VPN, since they can't, in theory,

since they can't tell where it's coming

from originally,

there's a lot of questions about like,

does that count as crossing international

borders?

Can you collect VPN traffic?

Because is it somebody from the UK

connecting here to try and evade age

verification on Discord?

Is it, you know,

somebody from a repressive country?

Is it somebody in the US who's just

connected to a nearby server and it didn't

cross international lines or something

like that?

So, or, you know,

if you use like Proton Secure Core,

those route through servers that are

actually owned by Proton.

So there's like,

There's a handful in Iceland.

There's a handful in Switzerland.

I think there's another country that they

have a few.

But so like those would,

for a US user like myself,

those would bounce out of the country and

then back in.

So I think that's more what it was

referring to.

Not so much like, hey,

let's watch everybody that uses a VPN,

but more like, hey,

how do we know if these people are

supposed to be protected by law?

Which I would argue the NSA doesn't care

about anyways, but I digress.

Sorry,

I was trying to get something to go

away.

I was just going to say,

Zach from Unredacted also said,

they take into account how much traffic is

sent to different IPs.

I guess there's some VPN clients designed

for sensory countries that can load

balance connections.

Yeah,

that would be what I'm interested in

looking into more because I think that

could be a cool solution,

but I don't know what they are.

Again,

I'll have to look into this after the

show.

I don't think I have much else.

I'm not seeing anything in the signal

chat.

Kind of wraps things up.

I think I just want to share really

quick.

Right before this stream,

I was reading a story,

and I caught some of Henry from TechLore's

livestream like an hour before this one,

where he talked about some stuff about

Texas...

getting a court order for Verisign to

basically revoke another Coventry's .com

domain.

I had a lot of thoughts,

both about that story and also about

Henry's take on the whole thing,

so I think I'm going to talk about

that in a livestream on my channel right

after this one.

So if anyone's interested in continuing to

listen to me talk about stuff,

you could go over there if you want

to, but just throwing that out there.

Otherwise, yeah, Nate,

you want to wrap things up,

do you think?

Yeah, sure.

I'll let you get to that.

So all the updates from this week in

privacy will be shared on the blog every

week.

So sign up for the newsletter or subscribe

with your favorite RSS reader if you want

to stay tuned.

For people who prefer audio,

we also offer a podcast available on all

podcast platforms and RSS,

and this video will be synced to PeerTube.

Privacy Guides is an impartial nonprofit

organization that is focused on building a

strong privacy advocacy community and

delivering the best digital privacy and

consumer technology rights advice on the

internet.

If you want to support our mission,

you can make a donation on our website,

privacyguides.org.

To make a donation,

you can click the red heart icon located

in the top right corner of the page.

You could also go straight to

privacyguides.org slash donate.

You can contribute using standard fiat

currency via debit or credit card or opt

to donate anonymously using Monero or your

favorite cryptocurrency.

Becoming a paid member unlocks exclusive

perks like early access to video content

and priority during the live stream Q&A.

You'll also get a cool badge on your

profile in the Privacy Guides forum and

the warm fuzzy feeling of supporting

independent media.

So thank you everyone who watched and

stuck around and we will see you next

week.