This GrapheneOS Feature Can Get You Arrested
An activist has officially been charged
for using the Graphene OS duress pin
feature to destroy evidence.
Facial recognition is running rampant in
private companies and inside Germany's
free speech crackdowns.
We are covering all of this and more
coming up on this episode of This Week
in Privacy number sixty four.
So stay tuned.
Hello everyone and welcome back to This
Week in Privacy,
our weekly series where we discuss the
latest updates with what we're working on
within the Privacy Guides community and
this week's top stories in data privacy
and cybersecurity.
I'm Nate and with me this week again
is Jonah.
Jonah, how was your week?
You know, it's been pretty great.
Lots of stuff going on.
I think lots of good stories to talk
about.
I was ordering some stickers that I could
hand out at DEFCON when I'm there next
week.
Unfortunately, those haven't arrived yet.
They're arriving in a few hours.
I wanted to maybe show people what they
would look like on the stream today.
Don't have them yet,
but they are pretty cool.
And I sent a picture in our supporters
chat.
And if anyone will be at DEF CON
next week again,
come say hi and I'll give you one.
That's the only place to get them.
We don't have them on the store.
Yeah,
I showed the picture you sent in the
supporter chat to my wife and she was
like, oh, those are so cool.
So yeah, they look awesome.
Hopefully I have some extras that I can
mail out to people afterwards,
but we'll see.
We'll see.
How have you been, Nate?
Good, good.
It's been a busy week,
but I guess we'll talk more in the
site updates,
but we got a lot done this week
and
Um, yeah, I mean,
not too much exciting over on my end.
Just, uh, yeah, all good.
Well, those updates should be exciting.
Um, with that, let's talk about.
Our first story today,
this was reported by Ars Technica.
An activist was charged with a felony
after giving border agent duress code that
wiped his phone.
So they say in early twenty twenty five,
Atlanta resident Samuel Tunick was on his
way home following a trip abroad after
landing in the U.S.
Customs agents demanded access to his
Google Pixel phone.
You probably see where that's going.
It was running an alternative version of
Android called Graphene OS.
And we talked about some of this on
This Week in Privacy episode number thirty
one.
Security features.
Government attorneys and agents claim that
Tunick was subjected to a standard
secondary interrogation at an
international airport.
During that encounter,
agents were looking for anything that's
prohibited.
However,
Tunick's legal team alleges he was
targeted for his activism.
This is because Tunick was involved with a
group called Defend the Atlanta Forest,
which opposed the construction of an
enormous law enforcement training facility
in the area often known as Cop City.
What Tunick didn't know,
according to his lawyers,
was that he'd been placed on a watch
list for his actions and that Customs and
Border Protection had discussed over email
plans to detain him upon his arrival back
in the U.S.
for suspected terrorism activities.
So, during this investigation,
these Border Patrol agents basically said
they wanted to search his phone for
evidence of child sexual abuse material.
We talked a bit about that sort of
thing in another story last week.
And if he didn't unlock the device,
it would be confiscated.
So what comes into this story and how
it relates to Graphene OS is the duress
code is an optional feature of Graphene OS
that allows a user to set up a
secondary pin number that when it's
entered,
if you're worried about it falling into
the wrong
hands,
or if you're in a situation like this,
you can basically enter that code on the
lock screen instead of your regular PIN
number,
and it immediately irreversibly wipes the
eSIM, it wipes the entire device,
so none of that
data can be restored.
The article says that Tunick provided this
code to an agent who entered it on
the phone,
after which the screen went blank,
flashed several times,
and the phone appeared to restart.
All of the data on the phone was
gone,
but authorities confiscated it anyways.
Tunick was allowed to leave at that time.
But in late twenty twenty five, the U.S.
Department of Justice opted to file
criminal charges against him,
citing a little used statute,
Title eighteen U.S.
Code Section two to three to eight.
That makes it illegal to knowingly destroy
or damage property to prevent it from
being seized.
TechCrunch noted that this appears to be a
new legal strategy for the government.
EFF experts who spoke to TechCrunch note
that they've never seen the law applied in
this way before.
So the Department of Justice will need to
argue that even though Tunick was told
this was a routine border check,
he ran afoul of the law by tricking
an agent into deleting his data.
If convicted,
Tunick could face up to five years in
prison.
Um,
four or four media also interviewed Tunick
and his lawyer,
and his lawyer said that he only found
one other case using the same law,
which was a drug trafficking
investigation.
In other posts and outlets,
I think we have an article from PCMag
here,
Graphene OS discussed the case from a
technical perspective,
noting that none of their features are
illegal and that based on current
evidence,
Graphene OS phones can withstand forensic
investigation without requiring the use of
a duress pin.
So that is quite a story that I
think will have a lot of people using
Graphene OS and maybe the Stores pin
feature interested.
Nate,
I'm really curious what you think about
all of this first of all.
Why don't you share your thoughts?
Yeah, so this is a,
This is a complicated story in the sense
that when we first covered this story back
in – what did we say it was
there?
This week in Privacy at Thirty-One,
I reached out to a friend of mine
who's a lawyer and asked their expertise.
And veteran viewers know that right now,
the entire state of the Fourth Amendment
as it relates to electronic devices is
really, really up in the air.
And –
The courts are kind of really shy to
make a ruling and lay down some precedent
either way.
So right now – let's see.
I asked my friend to send me that
paper she wrote again.
So basically right now –
Searches normally require a warrant,
but at the border, there's an exception,
and within a hundred miles from land
borders and coastlines,
as well as airports,
international airports,
and it's worth noting that about
two-thirds of Americans live in this area.
So they can do a routine search, which,
again,
has not been legally defined by the
Supreme Court.
And it just says one that does not
seriously invade a traveler's privacy.
And let's see.
CBP guidance requires reasonable suspicion
only for advanced searches.
And a reasonable let's see a search is
considered advanced if an officer connects
external equipment through a wired or
wireless connection to an electronic
device,
not merely to gain access to the device,
but to review,
copy and or analyze its contents.
So this, I think,
would have counted as a routine search.
I also spoke to,
let me pull up my notes here.
I spoke to a friend of mine who
works in law enforcement to get his take.
He's very knowledgeable.
He knows about graphene.
He knows that it's not something that just
criminals use.
He said that he checked the court records
for federal cases using that section,
to and he said the only ones that
he found involved physical property and a
criminal investigation,
which he notes based on the information we
have right now,
this was not a criminal investigation.
This was a routine search.
He said,
I can't tell you the likelihood of this
charge sticking because that's beyond the
scope of my legal knowledge.
But in his opinion,
it's kind of a stretch.
Let me see here.
I'm trying to make sure I didn't miss
anything with his take.
Yeah, so it's very –
I think what this is ultimately going to
come down to – and for the record,
I'm not a lawyer either.
I don't have any legal training.
I got really busy,
and I forgot to send my lawyer friend
the actual legal paperwork,
which I think the TechCrunch article links
to.
Oh, this one does too actually.
So there is a link in there if
you want to read the actual charges.
I think it's only like two pages.
It's not that long.
But from what I'm reading and what I'm
seeing from other people –
Trying to charge him under this specific
statue is kind of weird,
and it may not stick,
but I think what might come back to
bite him is the fact that he gave
the officer the wrong pin.
And he knowingly did so,
although I would like to note that the
mayor of New York claimed that he forgot
his phone's password and never faced any
consequences,
which I don't think any of us buy
that.
But it'd be one thing – like I've
seen some people say online.
I think they've even said in our forum
thread about this that –
It'd be one thing if, like,
he wrote down the duress pin in his
phone and made it look like the actual
pin,
or if he made it something easily
guessable, like, you know, his birth year,
one, one, one, one, zero, zero, whatever.
If he had done that and the cop
just guessed and assumed,
I think he'd be in a much stronger
legal position.
If anything's going to come back to bite
him,
I think it's going to be the fact
that he knowingly gave them a duress pin.
But it... Yeah, I mean, it's definitely...
I think it's – I mean all this
is kind of beating around the bush of
saying that like I think we all know
this whole like, oh,
we think there's CSAM on your phone.
Like really?
Why do you think that?
Like where did that accusation come from?
Like this – I think any – what's
the word I'm looking for?
I think most people can see right through
it that this was clearly related to his
activism with the whole StopCopCity thing,
which, for the record,
I do want to point out there that
the last time we talked about a story
about StopCopCity and Proton turned over
information to the FBI,
that person was accused of throwing
firebombs and being violently aggressive,
which –
I advocate for peaceful protest,
so I don't know what this dude's story
is.
I don't know if he was out there
throwing Molotov cocktails or if he was
just out holding signs.
But either way,
I think there's clearly a link here.
And yeah,
I think this is probably going to be
one of those really big cases that we
have to keep our eye on and hope
for the best.
For sure.
I mean,
and Dag Overhull in the chat said exactly
the same thing.
I mean,
the government used three different
excuses in this Ars Technica article.
They said they were investigating him for
terrorism.
They talked about using CSAM as a
pretense,
which is exactly in line with what I
was talking about last week,
which is that the government uses these as
an excuse to search random people,
often without any evidence
at all,
and this is just yet more proof of
that happening.
There probably wasn't
any sort of probable cause whatsoever for
the things that the government was
claiming was on his phone,
which I think is a huge problem for
their legal case.
I'm obviously not a lawyer either,
but I totally agree with what your friend
was saying too about this specific law.
When I read this article,
I think it was posted by Zach Whitaker
on TechCrunch,
who is an excellent reporter.
My immediate reaction was that this is a
very strange law to charge him with
because I do think it clearly relates to
physical property.
The law says that you can't knowingly
destroy your damaged property to prevent
it from being seized by the government.
However,
The government did seize his phone,
and his phone is still fully functional as
a phone,
so in what way was the property destroyed
in a way that
prevented them from seizing it.
Obviously,
the government is after the data,
they're not after the phone itself,
but I don't think that this law applies
at all to this data case.
There's been a lot of court cases that
we've seen actually where,
unrelated to criminal charges whatsoever,
but it's generally understood that data is
not
property in the first place.
And this US code specifically relates to
property.
I think if data was property,
there'd be a lot more arguments about
like, oh, these data brokers,
they're illegally possessing my property,
right?
So I can sue them.
It's basically theft if they're sharing it
and selling it and whatever.
But that isn't how the law works.
Obviously,
I'm not really sure that's how the law
works.
I don't really subscribe to the fact that
personal data is property,
I think that would open up a whole
can of worms that we don't have to
get into right now.
But at least at the moment,
that isn't how it works.
And I think that because of all these
things,
I think these charges are pretty tenuous
at best.
This is obviously, to me,
a case of the government just trying to
use the court system as a punitive tool
attack against him because
It's expensive to go through all of these
legal proceedings.
He had to get a lawyer now.
There's all of these... I mean,
he has to deal with this lawsuit, right?
It's annoying.
And even if you're completely innocent of
anything you're being...
or everything you're being accused of,
it's a whole process.
And that is the goal of the government
in these cases.
It's an intimidation tactic, I think,
against protesters or activists like Tunic
here.
And...
it is really not a great story um
the government basically has unlimited
money resources power in the courts to
make your life terrible forever until you
give in so um yeah it's it's a
very scary and concerning story and
It's very problematic that this continues
to be a thing at the border,
especially with border control agents and
US citizens.
So...
Yeah,
I think that sort of sums up what
I was saying.
Let me see if we had anything else
in the notes here I didn't talk about.
I'll add real quick while you're checking
that,
that I think you made a really good
point about data as property.
This almost feels like a double-edged
sword where the government either has to
say, no, he didn't destroy property,
therefore he didn't do anything wrong.
Or B, they have to say, okay,
data is property, which I would imagine,
again, not a lawyer.
Now the Fourth Amendment applies a little
bit more rigidly,
and they have to stop doing things like
buying data from data brokers to get
around a warrant requirement.
I feel like the government kind of put
themselves in a corner here with that one
when you brought that up.
Yeah, yeah.
Yeah, the whole data as property thing,
that's been debated a lot in terms of
advantages or disadvantages it would have.
But I mean, in this case,
like the property itself was not
destroyed.
And the article literally says like,
and I think they say in their documents
that they did, they seized the device,
they use that word.
So like,
what part of the law was even violated
in the first place?
I don't know.
It's probably a case for like,
this is a law that's not on the
books.
And so they're just they're grasping at
straws, basically.
Yeah, I don't know.
I had a few thoughts,
if that's all you had.
Yeah,
I think the main thing I'll just point
out again is that, like,
as Graphene OS said,
there's probably no good reason to use
this in the first place because they can't
get into your phone.
So I would keep that in mind if
you're thinking about that feature.
Anyways, what are you thinking?
No,
that's actually very similar to what I was
going to say is like, I think, like,
I think the dress pin thing is really
cool.
And I think.
I think it makes sense.
Like,
obviously we don't know what was deleted
from this person's phone and maybe there
was some really sensitive stuff on there.
Like not in the sense of CSAM,
but I mean, maybe there was,
who knows not, but you know,
maybe there were like names of other
protesters and like upcoming plans and,
you know,
access into Google docs and like things
that it's, he's like,
I don't want the cops to have this.
And so maybe the lesser evil for him
was like,
I need to make damn sure the cops
don't get into this.
Like, even though as far as we know,
they can't get into graphene.
Like,
what if that one percent chance they can
and he decided it wasn't worth it for
him um so i'm glad this feature does
exist but i i think that we see
a lot of people in the privacy space
set up tools like this um
I'm just going to say,
I think sometimes we think we're Mr.
Robot and we like really get into these
tools.
And if you want to set them up,
that's fine.
But like, keep in mind,
there can be consequences for this.
And, you know,
when I was twenty and I didn't have
a family and like, you know,
I had a dead end job at Walmart,
like, OK, fine,
I'll set up the duress pin like I'll.
Why not?
I have nowhere to be, but you know,
if you have people that rely on you
going to work to keep a roof over
your head, or, you know,
like you pointed out,
uncle Sam has unlimited resources.
Like that was that whole issue with the,
what was it?
The tornado cash developer that recently
went to jail.
Like he said that in his interviews is
he's like, yeah,
I couldn't keep litigating this case.
We were already tens of thousands of
dollars in debt.
And just digging deeper.
And the government has infinite pockets,
thanks to our taxpayer dollars.
That's a different rant.
To just keep charging these people
endlessly and dragging this out in court.
And so it's just something to keep in
mind.
It's a threat modeling thing.
Like, again,
some people really do have data where it's
like,
I can't risk that one percent chance.
But, you know,
I think most of us are probably not
in that boat.
And you've got to keep in mind the
consequences that could rise here.
Yeah.
I'll take a look at some chats here
really quick.
Yeah, definitely.
Hello, welcome to the stream.
Hello, world.
Peaceboy John, yeah, yeah, Graphene OS.
Yeah, I mean, it's a great tool.
I think it's important to note what Deg
Overholtz said again here in the chat.
They can't get into Graphene OS as far
as we know.
That's certainly true,
but I think Graphene OS also has a
lot of features that don't involve
completely destroying the data.
Something like,
I think disabling the USB port is a
pretty great feature that they have.
And that comes enabled by default for the
record.
Yep, when it's locked.
I mean,
and you can take it even further.
Like, on my Pixel right now,
I have it completely disabled when the
phone is on, so it only charges when,
like, the phone is powered off, basically.
And that has been fine,
because I just charge things overnight
anyways.
And there's stuff like that.
They have features, like,
you can disable Wi-Fi and Bluetooth after
a certain amount of time, or, like,
when the phone locks, so that they can't,
like,
connect it to a malicious Wi-Fi network or
something like that.
So, of course...
It's not as foolproof as completely
destroying the data, I'll give you that.
But exactly like you were saying,
I think you don't have to do this
Mr.
Robot Edward Snowden LARPing thing unless
you have a really good reason to.
But I think even in this case,
even if you know you're being targeted
because of your activism or something,
it's pretty unlikely that...
They're going to use all of these
resources to get into your phone,
maybe secret ones.
If you stole a ton of national secrets
like Edward Snowden,
maybe they would take it a bit more
seriously.
But even situations like this,
it's probably overkill.
uh unredacted said one can say they
entered the pin and destroyed the data
themselves um and yeah one could
definitely say that um this I mean you
could definitely argue like they should
have known about this possibility and not
just done whatever he said but also at
the same time you know him saying it
is like um
probably like that's probably the worst
thing for his case I still think that
this case is pretty weak despite that but
it is a thing I also wonder about
like writing down the pin on like a
piece of tape on the back of the
phone I don't know um but I don't
know if that would be considered like
telling them as well but that would be
a bit like even more of a gray
area that I think would would have
benefited him so that's a possibility but
Yeah, it's – Yeah.
I just wanted to say in regards to
that one,
like I don't think that argument is going
to fly.
Like again, not a lawyer,
but that whole like, well,
he's the one that entered the pin.
Yeah,
but you gave him the wrong pin knowing
what would happen.
Like that would be like – I know
this would –
I would say this would never happen,
but I've read crazier stories.
If the cops raided your home and they
say, we think you've kidnapped somebody.
Where are they?
And you're like, oh,
they're through that door over there.
But you booby trap that door.
You're still going to be held responsible
for the cop getting injured or killed
because you knew there was a booby trap
behind that door.
And I think it's the same thing here.
Like, I don't think that argument of like,
well,
he's the one that entered it is going
to fly away.
Yeah,
the booby trap thing was crossing my mind
too.
I'm glad you brought that up.
Great minds think alike.
I remember someone saying your PIN number
is protected by the First Amendment,
just not your biometrics.
That's generally considered to be true.
That hasn't been tested in courts,
but pretty much all legal experts agree it
would be because it's something in your
mind.
That being said,
there have been cases where the government
just detained some people forever because
they didn't give up their PIN or because
they forgot their PIN,
which is pretty rare,
but it just goes to show.
Some of the bad behavior in some cases.
Yeah,
I'm glad you highlighted that one because,
yeah,
it's – I guess it hasn't been tested
in court.
But generally,
it's – your First Amendment protects – you
don't have to give up the pin because
that's a violation of your free speech.
And I would imagine a violation of your
right against self-incrimination.
And we didn't mention it in these show
notes, but he claims,
this Samuel Tunick guy,
he claims that he repeatedly asked for a
lawyer and was denied.
So if that's true and they can prove
that,
I feel like that's a really strong
argument that all this stuff is going to
get thrown out because a lawyer would have
told him don't give them any pin,
even if it's a fake pin.
You know, I think.
Yeah.
Yeah.
I mean,
that but that is a critical component.
that was probably like the right move is
to just shut up don't don't give a
pin um at all uh sb ass is
powering off the phone before handing it
over also illegal powering off important
to delete the encryption key and and yeah
getting your phone to like up before first
unlock state is definitely more secure
without wiping any of that data
um that gives you more possibilities for
for defense in the future um you still
shouldn't you know give them any pin at
all like we like we just said but
i i don't actually know how this would
work i suspect it would
not be illegal in the same way at
all.
I mean,
the government can stretch any law to make
whatever claims they want,
and maybe they would claim, you know,
you deleted the encryption key by powering
it off,
and that destroyed the evidence or
whatever.
Who knows, right?
But I certainly don't think it would be
illegal to power off your device before
you've been informed of the investigation,
at the very least.
And I think this is something to consider
when you're going through...
these border checkpoints or if you're in a
situation where you reasonably expect you
might have an interaction like this with
some overreaching law enforcement,
it's probably a good idea to just have
your device powered off in the first
place.
is also probably a good idea to back
up your devices to the cloud and just
wipe them before you go through.
Only keep minimal data on your phone for
what you need for traveling, basically.
I think that that's probably one of the
strongest moves you can do.
So yeah,
there's a lot of options that would
definitely clearly be legal.
Much more legal compared to the gray area
that...
that this case is in.
But again,
I think that this case is a pretty
light gray.
I think that their case is pretty weak.
Newlywitch said,
if the CSAM turns out to be fabricated,
the privacy community needs to rally
behind this activist.
I think it's pretty clear that the CSAM
accusations are...
because the government is claiming that
this is sort of a suspected terrorism
activity in their behind-the-scenes
emails, which is not what they told him,
but that seems to be what they actually
believed.
So I think, in my opinion,
this is just...
total proof that it's probably like in
their training or something to just accuse
people of possessing CSIM wherever they
can because it's such a I mean it's
it's difficult to prove it's something you
could easily plant on people's devices
it's something that people really don't
like so it makes all of these headline
stories but since they're discussing you
know suspected terrorism activities behind
the scenes and not and not you know
investigating him for CSIM before they
told him that I
I think it's very clearly a total farce
basically.
Yeah, I would imagine the the CSAM thing,
too,
is like that is such a horrible thing
to be charged with that most people would
probably instinctively just want to clear
their name right there before those
accusations get out of control.
Like, oh, God, no, here,
please take my phone.
See, there's nothing on there.
So I wonder if that's part of why
they do it, too.
I wanted to go back real quick to
the question about powering off your
phone.
I've started doing that, actually,
because my logic is, again,
I don't have anything that sensitive that
I would
I've had my phone blow up.
So those of you who follow me know
that.
And like trying to get back into like
things like Signal and all my accounts,
it's like it wasn't really the end of
the world,
but it was still kind of a pain
in the ass.
So I would rather not factory reset my
phone if I don't have to.
So when I go through the airport, yeah,
I've started just rebooting my phone right
before I throw it in the thing to
go through the –
the x-ray because i actually have had
computers not like forensically searched
but i remember one of my it was
actually my cubes computer um because it's
literally from like two thousand twelve it
did go through the airport one time and
they were like hey we pinged is like
there's residue on here i'm gonna swab it
with a cotton swab it never left my
site she did everything right in front of
me she never turned it on or opened
it or anything but she like swabbed it
with a cotton swab and like okay you
came back clean everything's good go about
your way and so i've kind of had
that that
walk through my head of like, well,
I don't want to delete my phone,
but I also want to keep people out
before first unlock.
So yeah, as far as I know,
that's not illegal because like Jonah was
saying,
like nobody came up to me and was
like, Hey, let me search your phone.
It's me preemptively getting ahead of
that.
Like I am about to give up control
of my phone.
Let me go ahead and reboot it.
And that way,
if I end up in this situation where
they say, Hey, we pinged your phone,
I'm going to take it to a back
room, have fun.
It's before first unlock.
And also real quick,
Dag Overhaul said have a separate innocent
profile.
I mean, yeah,
that would work except if they do the
forensic thing because at that point the
phone's unlocked.
If they just do like a quick visual
search, then yeah,
what are they going to – they're not
going to find anything there.
But I don't know.
That's my thought process.
I just want to do this.
Oh,
the last thing I'll say real quick is
to definitely go ahead and check out this
four or four interview with him because
like it does require a subscription.
And I mean, it's like what?
Five bucks a month, ten bucks a month.
Just get like a one month subscription.
But it's totally worth reading because
apparently the cops like had a hidden
camera on him.
They had like a tracker on his car
and he didn't know this at the time
for the record.
He had no idea he was this targeted.
It's just it's so wild.
That's crazy.
Just another comment from DakeOverhaul.
Another YouTuber says he resets his phone
every time he's flying.
I mean, yeah,
that's not really a bad strategy,
especially if you can back it up and
restore it easily at your destination.
Honestly, when I fly to Vegas next week,
I'll be bringing a wiped...
macbook that doesn't have any data on it
um not necessarily for this reason mostly
because i don't need to bring all of
my all of the stuff on my laptop
to defcon but um you know it's typically
not a bad idea to travel with like
the minimum uh information you can so
Yeah, I'm not dedicated enough to do that.
But if my threat model was high enough
or if I was flying somewhere where like
I knew I'm almost certainly going to get
searched,
like if I was going to China for
whatever reason,
like maybe I would do that.
But.
It's definitely more of a concern like
international borders.
I don't know how much power TSA has
in this regard,
but I don't think they can do full
law enforcement investigations.
I'd have to look.
But border control in the U.S.
definitely can.
There's definitely a lot of power that
border control in other countries would
have as well,
no matter where you're traveling.
So all of those international borders,
for sure, you should keep that in mind.
Yeah, agreed.
I don't have anything else on that story.
Do you?
I think we pretty much got it covered.
Cool.
I was just going to look really quick
if we had any comments about this story
in the forum thread since this was our
kind of title story.
But we may have covered a lot of
the questions here that were answered
today.
by or asked by people in the live
stream um and maybe bob's your uncle said
i wonder if having an almost bare fake
android profile with a completely
different pin is enough for border control
um yeah i guess it depends on how
knowledgeable they are like if they're
only gonna search one profile you could
just have that one open but um that's
probably not a path i would
try to go down necessarily,
but it could be better than nothing.
I know that they can get kind of
mad about you having a blank phone.
They're like, where's your social media?
Is this legitimate?
That sort of thing.
But it's challenging to defend against the
government and law enforcement agencies in
this case because
They can kind of do whatever they want
and it gets sorted out later by the
courts.
So it's not a super fantastic system,
unfortunately.
Yeah, it looks like in the forum thread,
there was some discussion about this,
but not really a lot of questions,
just people kind of talking about all the
stuff we said,
somebody linked to that four or four
article,
somebody else linked to a Gizmodo article.
so yeah um just there's one post in
the forum i'd just highlight a sentence
from that was from trustee rock nate i'm
hopeful this case sets a precedent in
favor of dress pins i think that that
could be um one of the best outcomes
of this so we'll we'll see if that
happens um i guess it depends on how
tenuous the government thinks that their
case will be because there's there's also
cases where you see like things like this
and then to avoid uh setting a precedent
the government will very quickly drop it
but after a lot of time after you
have to spend a lot of money that
sort of thing so yeah you never really
you never really know
So real quick,
wanted to mention SB here brought up the
idea of a password strength checker,
and somebody else also said something
about using a strong password.
I mean, your mileage may vary,
but I remember Naomi Brockwell did a video
where she argued that a six-digit PIN is
probably going to be enough for most
people.
I mean, again,
if you're in a situation where you'd
rather just wipe the phone completely,
then you probably shouldn't trust a
six-digit PIN, but...
I don't know.
I it doesn't I guess what I'm getting
at is like,
I don't think it necessarily has to be
this like super crazy,
like twenty eight character randomly
generated letter, uppercase, lowercase.
Like,
I think there's a middle ground for most
people.
But I mean,
certainly if you want to do that,
go for it.
thing with that um is that the length
of this pin does directly improve like the
strength of the encryption if somebody is
able to brute force that data without any
limits um the reason you can do like
a six digit pin is because of the
brute forcing protections
in a phone,
and those are generally considered to be
fairly good,
especially with modern ones like latest
iPhones or especially like the Google
Pixel and the Titan chip on Graphene OS.
There should be enough rate limiting or
wiping it after a certain amount of time
enforced by the operating system that the
complexity of your pin,
as long as it's not super simple,
is not going to be a huge problem.
But
we have seen in the past, definitely,
definitely a good number of cases where
like we find out celebrate or gray key
or some of these other tools that these
agencies are using,
they can bypass the the rate limiting.
So
It is something definitely to consider,
especially if you're going to be in this
situation.
The other thing you could do is have
a six-digit pin on your profile and have
a separate,
longer password on a private space in your
profile.
Because private spaces,
at least on Graphene OS,
they're fully separate profiles with their
own encryption keys.
You can set up a second password for
them and...
you could sort out most of your apps
that might have sensitive information like
your banking app or your email or whatever
into a private space like that and just
keep
basic things like social media or whatever
you consider less sensitive in your main
profile.
I think that that's one legitimate thing
you can do as well.
And Dag Overhaal basically said the same
thing.
Like,
if you can get the keys out of
it,
you can brute force those short pins super
easily.
So there is that to consider.
But in theory,
they can't get the keys out of it,
and so it should be fine.
It's not as provenly foolproof as using a
longer pin.
So there's trade-offs for sure, for sure.
Gotcha.
I think we kind of got it.
Why don't you take our next story here?
All right.
I think I'm back.
I hope I'm back.
I don't know what's going on with my
internet.
I think you're back.
I didn't know you left,
but I can hear you now.
My internet keeps freezing up.
Yeah.
Interesting.
Weird.
Before we move on to the next story,
we did have one question in our forum
thread that's not related to this story.
It said,
are there any privacy alternatives to ring
cameras?
I did not do any research on this
one, but...
I don't know.
I mean,
I'm definitely not a fan of Ring for
so, so, so many reasons.
But the one thing I will give Ring
is that they've got an end-to-end
encryption that you can enable,
and I think that's a good start.
Is it true, though?
I mean, Anchor had those cameras.
Was it Eufy or whatever that were supposed
to be end-to-end encrypted?
Obviously, they were not.
Ring has a lot of other privacy problems
because they have those programs where,
like,
you can opt in to share all of
your camera footage with law enforcement
or like other programs to search for lost
dogs or something silly like that.
So, yeah, it's...
It's not a great setup.
There's certainly self-hosted setups you
can do.
There's a lot of video recording threads
on the forum you could look at with
a lot of different recommended tools.
There's some sort of cloud-based ones that
I think are better than others,
but they're gonna be unsafe if they use
the internet as an authentication later.
I'm thinking of like,
unify unify protect for example they have
good cameras but there's some like
reliance on like cloud authentication kind
of similar to like plex for example which
isn't like amazing um but there's always a
trade-off between like features because
with a lot of like self-hosted ones you
don't get a lot of useful things like
notifications uh on your phone when when
the doorbell rings or something like that
that you would get from
bigger tech company apps.
But yeah,
I don't have any specific recommendations.
I would take a look at all of
the home camera related threats on the
forum because they are probably more
knowledgeable than I am right now.
Yeah, I'm still renting,
so I haven't had much of an incentive
to look into home security that deeply.
But I'm looking here.
I know...
I know there was one that one of
our associates recommended,
and I passed that along a long time
ago,
but I can't remember what episode that
was.
AI summary,
so take it with a grain of salt.
But according to Brave's AI summary,
I looked up private doorbell camera.
It says things like Reolink and Eufy are
highly recommended because they allow
local storage without a monthly
subscription on a micro SD card.
There's also a TP-Link Taipo, Aquara,
who I've never heard of.
And then they said there's actually some
cameras that work with Home Assistant.
They're a Chinese company.
I didn't know they made the cameras they
make.
I know they make Z-Wave sensors for Home
Assistant and stuff.
I wanted to bring up really quick.
Sorry,
I'm trying to bring up a sharing screen
situation, which I don't know how to.
How do I?
I got you.
How do I share?
Thanks.
You can share my screen.
I have to remove mine.
That's why.
uh there we go uh somebody in our
signal group for supporters which you can
join by donating at privacyguides.org
donate um mentioned secluso uh this is a
raspberry pi based camera setup uh it's
end-to-end encrypted
The the secluso people are on our forum
I believe and there's a thread about it
and you can even ask them questions there
and stuff I think that's definitely one to
look into if you're in more of a
self hosting state of mind There's also
frigate and scripted as John points out in
the YouTube chat I've used
Ooh, I don't know which one I used.
I looked at both of them,
and I used one of them to get
some of my self-hosted cameras into Apple
HomeKit,
which is end-to-end encrypted and provides
some of those notifications.
And they integrate with Home Assistant as
well.
If only I remembered which one.
But I think people use both of them,
and that could be some other self-hosted
options to look into,
especially because they work...
with pretty much any LAN-only cameras.
Unredacted says, Unify Protect is decent.
Yeah,
and there are ways to use Unify products
without their cloud stuff.
If you don't connect it to the cloud,
they have a local web interface that you
can access everything on.
It's not open source,
so you can maybe take that with a
grain of salt, but...
Yeah, because something to consider.
John said scripted as a functional.
I think I did use scripted.
I think that is right.
So yeah, it is pretty, pretty neat.
I probably wouldn't integrate it with
Google and Amazon,
even though it can do that.
But Apple should be.
Apple handles that all through the Apple
TV to encrypt it locally.
So you do need to have a home
hub like that,
but it should be a bit better than
those products.
But again, that's not open source either,
so then you have to trust Apple.
There's all that stuff.
If you want a fully local sub-hosted NVR,
I would look at this Seclusa thing.
I would look at Frigate because I think
those are all good options as well.
I just wanted to say another vote for
X Protect is, again, AI summary,
take it with a grain of salt.
But it did say,
the last thing it says,
while local storage enhances privacy,
note that some manufactured data
collection may still occur for device
connectivity.
For absolute security,
consider air gap systems like X Protect or
Unify setups,
though these are more complex and
expensive to install.
So, yeah.
That's all I got on that one.
Sweet.
I think you're up for the next story
here if you want to.
I am.
All right.
Let's talk about Pokemon.
My childhood here.
We're actually going to combine these next
couple of stories because they're...
Let me throw this up here real quick.
These next couple stories are kind of all
about the rise of how private companies
are increasingly using surveillance
technology,
specifically facial recognition
technology,
uh, surveillance technology.
So this one's pretty quick.
Uh, this comes from PC or PC gamer,
excuse me.
And basically it says that Nintendo
stores, uh, it says specifically in Japan.
I don't know if it's worldwide,
but I think it's just in Japan for
now.
They say that basically they're having a
real problem with scalpers coming in and,
uh,
buying up all the cards and then reselling
them.
And then there's no, uh,
cards left over for normal,
legitimate people.
Um,
So they are going to start rolling out
facial recognition systems to verify that
customers are only coming in once per day,
which is apparently the limit.
They say the exception to this will be
children under elementary school age,
so preschoolers up to six years old.
Let me see here.
Yeah,
so this is the once a day to
ensure that players get more access to the
stock.
If the system detects that the same person
has entered the store more than one a
day or received more than one entry
ticket,
a notification to that effect is displayed
on the screen.
Entry will be denied to that person based
on the system's judgment.
Yeah,
the article kind of points out that
there's really nothing you can do about
this.
And they did go on to...
They're a little more generous than I
would have been.
This author basically said,
I've had loads of issues with the online
Pokemon Center.
It's never ending queues and insistence
that I'm in fact a bot whenever I
try to try multiple times to get a
pre-order through because the site keeps
bugging out.
While facial recognition systems seem like
it would be harder to mess up,
there is always room for error with these
things.
And unfortunately,
they say that facial recognition scans for
entering stores in Japan are not exactly
new.
Gundam stores employ the same system to
ensure people only buy one exclusive item
a day.
It seems like it's currently the best way
to combat scalpers and get popular stock
out to more people.
So I don't know that I agree that
it's the best way, but yeah,
I do appreciate them pointing out.
It's like, yeah, it's a cool idea,
assuming it works.
And I also feel the need to point
out that like,
these systems have to scan everybody.
It says like, oh,
it's not going to work on children up
to six years old.
Okay.
Maybe it's because I'm not a parent and
I don't really spend a lot of time
around kids.
I can't tell how old a kid is.
I mean,
pretty much everyone younger than me,
if they're not a teenager,
they're like six.
So I don't know.
The older you get, at least again,
for me,
it's harder to differentiate age brackets.
Again,
I can tell it's like you're adolescent,
you're
Oh no.
You're a teenager.
You're probably a young adult.
Like, but I don't understand that.
Like, did I cut out again?
Yeah, just a bit.
But yeah, my point is like, you know,
it's,
it's age verification is always like so
bad at doing things and like,
And I'm also annoyed by the part that
it says it's based on the system's
judgment.
Like,
I think I'd be a little more comfortable
if it's like a person will intervene and
double check the system, but whatever.
The only other thing I'll add is it
says that a Pokemon does explain that this
data will not be held indefinitely and
will be promptly deleted after a certain
period of time.
But this article did not specify what that
period of time is.
And then the other story that we're going
to group in with this one is about
Madison Square Garden.
And this is a summary that comes from
Bruce Schneier,
but I really liked his summary.
I think it was really well done.
So he shared a link to a story
about how Madison Square Garden is using
facial recognition software on everyone
that enters,
and they flag activists that oppose –
Using facial recognition,
they also – I think when this story
first started breaking,
it was about a woman who worked for
a law firm that was involved with suing
Madison Square Garden.
Like she wasn't even involved,
but she worked for the company,
so they wouldn't let her in in her
free time to go see a Christmas thing
with her kids.
And it turns out that last week the
system was shut off for Taylor Swift's
wedding.
And they said – well,
I'll read the ending here,
and then I'll go back and read this
quote from Evan Greer.
Bruce said that whatever privacy measures
Swift had in place for the wedding seemed
to have worked.
No photos have leaked online.
So Evan Greer,
who is one of the people that Madison
Square Garden alerts on,
says that ironically Swift herself has
reportedly used facial recognition at her
own concerts to identify stalkers.
This privacy-for-me surveillance-for-the
attitude feels like a perfect
encapsulation of the future we're already
living in.
one where wealthy elites can afford
privacy while the rest of us are forced
to live in a corporate surveillance
panopticon.
Yeah,
I don't have too much to add to
that, I don't think.
I think, Jonah,
if I can throw it back to you,
how do you feel about this idea?
Because a private company, theoretically,
has a right to do whatever they want,
right?
But it feels like there's not a lot
of regulation over this technology.
I don't know.
How do you think we should navigate this?
Yeah, there's really not.
Looking at the chat here, unredacted said,
many U.S.
states and cities outlaw or restrict
facial recognition without consent.
First of all,
least the first story about the pokemon
company that that's only in japan as far
as i know so wouldn't apply here in
the first place um but also typically you
can get this consent by basically posting
signs and i would imagine that they'll do
that because it's not really like you know
they they don't have a reason to do
this secretively they probably will post
signs to just say hey you know we're
we're on to you scalpers and and use
that as a as a deterrent basically so
I don't think that this is super regulated
at all, basically, like you were saying,
Nate.
And yeah,
there's nothing you can really...
do about some of these cases it's just
gonna be a growing issue I think
especially in this isn't like the case as
far as I know with at least the
Pokemon store story for example but a lot
of these systems will like link up with
with law enforcement I know that the
Madison Square Garden system
does connect to law enforcement databases.
The the people who work at Madison Square
Garden,
anybody like involved in the with the
business that they don't get,
they don't get information,
unless like a law enforcement agency comes
back and like, tells them, hey,
we flagged this person on your cameras,
but all of that data is basically streamed
to some law enforcement databases,
and it's all interconnected.
The other thing
yeah i i mean the other thing is
basically that comment where like when
businesses are implementing these and
they're not applying them to everyone like
you can they're not applying them to
taylor swift because she demanded privacy
at her wedding for example which i think
is reasonable obviously but it is a
situation where like the wealthy elites uh
as
as Evan Greer said,
can afford privacy while the rest of us
are forced to live in that corporate
surveillance panopticon.
Just like you said,
I think that is a perfectly apt summary
of the situation.
I just wanted to highlight again there.
It's... Yeah,
it's just not a great situation.
It really ties into...
The whole surveillance camera thing,
we're being attacked kind of from both
angles, basically.
We got cities and law enforcement setting
up plot cameras.
We got businesses setting up all of these
really advanced surveillance systems that
they're not only, like,
recording things for a limited period of
time to, like...
see who stole something off the shelf or
something like that.
But now they're like tracking people in
real time.
And they're like,
doing behavioral analysis.
And they're like making these huge
databases of people's data,
personal information,
they're linking it all up to to these
larger systems.
And this is where it really becomes a
much larger privacy concern than it was
before.
I think now would actually be a good
time to address.
We got a question in the supporters signal
chat right before we started streaming.
And they said,
what can everyday people do if they want
to travel without being tracked by ALPRs
or other mass surveillance tools?
And can the ALPRs or other cameras already
in use track people outside of cars using
facial recognition or other biometric
identifiers?
I think we're actually about to talk about
that in a minute.
But yeah, I mean,
I know there's no easy answers to that
one.
do you think there is anything we can
do as this surveillance?
Because I actually,
earlier this year when I was in New
York,
I walked right past Madison Square Garden.
I've actually been in that neighborhood
for my previous job as well.
And I remember just walking right past it
and you look around and they're not even
subtle,
like not even just Madison Square Garden,
but NYPD, like they're not even subtle.
You look at a light post and you
see like,
it looks like one of those stock photos.
There's like six different cameras pointed
out in every which way.
And there's a sign that's like,
NYPD is surveilling this area or whatever.
And it's like,
what is happening?
Other than moving out of New York and
never going back?
Like,
what do you do you think there's any
options here?
Yeah, it's,
it's really tough to do anything about it
on like an individual level.
It's, it's really the thing that it's,
it's a thing that we have to push
back against at a larger scale, I think,
and we just can't find it acceptable.
I think
I don't know what point we will reach
before we finally decide that this stuff
isn't okay.
I don't know what it'll take to make
that happen.
But yeah, it's a huge problem.
And I think it's just going unnoticed and
like, like just by the general population.
And
Yeah, it's really hard to, you know,
you're basically fighting back against
somebody with the resources of the
government, because it is the government.
And they can really, I mean,
we talk about this all the time,
you know, if the government is after you,
right,
there's not a lot you can do about
it.
And that applies even to these situations.
there's probably like things you could do
that would be wildly inconvenient like map
out routes that don't have these cameras
for example but it's not realistic i think
to avoid the you know the entire mass
surveillance system at this time uh
unfortunately because it's just very um
just very what's the word i'm thinking of
it's it's invasive and it's
pervasive pervasive it's everywhere um
somebody on our supporters chat said wear
ir blasters yeah you know blast in with
lasers i don't know i don't know what
you can do this is not you know
advice ir blasters is probably fine i
don't know how these uh cameras work so
i can't tell you if that would actually
work but that would be kind of a
funny setup
I almost sent it to our production chat
the other day since I was working on
a video.
We'll go into detail about this later,
but I'm working on a video about flock
right now, and I've checked dflock.org.
I live about a block away from a
major intersection.
There are thirteen flock cameras just at
that intersection.
Thankfully, most of them,
I actually don't think any of them are
pointed at the road,
except there is one that's pointed.
It's like, oh,
that's an intersection that I almost can't
avoid to get on that main road to
go anywhere.
There's one camera.
I'm like, man,
that thing has probably caught me so many
times just going to the store,
going to the gas station.
It's ridiculous.
It's insane.
That's just in the block around my place.
It's nuts.
I feel like we've seen reports of a
lot of cases where
Some of these flock cameras are not even
pointed at roads at all,
despite ostensibly being license plate
readers.
But they're just being used as general
surveillance cameras in general,
and they do have a lot of capabilities
beyond just license plate detection.
I think that brings us pretty well into
our next story I want to talk about
here, which was just the form post.
was a news report that was written up
by freya on our team so it's on
our website but there were some uh good
comments on there uh from the article
freya said flock styles license plate
reader vendor leonardo announced a new
system called signal trace which somebody
is talking about in the chat here too
so we can get into that but it
can fingerprint your wireless devices when
you drive by and track you around without
needing to see your license plate
When you travel in your car,
your smartphone, your smartwatch,
wireless headphones,
and even your car's infotainment system
are usually outputting a constant stream
of RF emissions.
When all of these individual devices are
traveling together,
it's likely to be the same person.
So the new devices
for tracking can be retrofitted onto
pre-existing license plate reader cameras,
and they're meant to work alongside them,
storing your device fingerprint alongside
your license plate number in a centralized
database that police can access at any
time.
One of the most terrifying things about
this, Freya says,
is that it not only identifies your car,
but it tries to identify individual people
inside the car.
For example,
if two people are riding together,
it can detect each person's individual
fingerprint separately.
It also means that the readers work if
you're not driving.
Simply walking around,
biking close enough,
will likely mean that your unique RF
fingerprint is now stored in some
database,
and your movements can be tracked.
Kind of ridiculously,
Leonardo tries to advertise that their
system, quote,
respects individuals' privacy rights,
end quote,
because the actual data itself isn't
decrypted or read.
but as Freya points out,
this is definitely an example of the
metadata being more useful than the
content, even if, you know,
police can't see what your actual, like,
MAC address or other device identifier,
I-M-E-I-I-M-S, M-Z, uh, what have you, um,
even if they can't read, like,
the actual numbers,
this system that Leonardo has built
basically, uh,
has already tied all of those identifiers
to other things that identify you.
So the content doesn't actually matter.
It's still a huge privacy concern.
Yeah, so again,
it is really a question of what can
you do to defend yourself against this?
And it's very tricky because these systems
are already in place.
Yeah,
scarecrows in the chat says surveillance
cameras respect your privacy because they
can't see through your clothes or inside
your bags.
That's exactly the same sort of argument,
right?
If you're tracking all of this metadata,
you're tracking people exactly where they
are, what they're doing.
It's not a privacy-respecting situation
just because you can't later look up what
exact device identifier was being tracked
at that time.
It's...
It's a huge privacy problem.
It's completely ridiculous that they would
claim otherwise.
Scarecrows also said that it looked like
the Texas Department of Transportation has
antennas on all their camera poles now,
so they're probably adding that in.
They haven't seen anything officially
saying they're Leonardo's signal trace,
but they look the same.
So, very, very concerning stuff,
and I think... I don't know, like...
how prevalent uh leonardo is compared to
flock but i'd be concerned about that i
also wouldn't be surprised if flock um if
they don't have a product like this
already is working on something like this
because as as terracotta pie in the chat
said uh why the world is just becoming
so surveilling and intrusive that's that's
so true and it is a huge it's
a huge problem
I mean, that means we fixed crime, right?
Like, you know,
there's no place in the world right now
that an ant can't pass gas,
that it's not caught on some kind of
camera.
So clearly we've solved crime.
Yeah, we've solved it.
Nobody has ever done anything bad since we
added these systems.
So I guess it's totally worth it.
Yeah,
I think – I know it's kind of
a rhetorical question,
but I think things like this go –
I think –
I know this comes from CalixOS,
and Henry and I talked about it at
Surveillance Report,
but I feel like they really have the
best model in the sense that privacy is
a three-pronged approach.
There's the technical side,
the legislative side,
and the education side.
And
You know, we've talked about this before,
like the people who just think like, oh,
well,
I'll just use Linux and like all this
this, you know,
age verification stuff won't affect me.
Yeah.
Until the person you're messaging is using
Windows and all your stuff is getting
scraped up in Windows recall and all that
kind of crap.
And then, you know, or until like.
Canada bans encrypted messaging and signal
says,
we're not going to service that place
anymore.
Like, what are you going to do then?
And, uh, but you know,
at the same time, it's like, yeah,
obviously companies break the law.
We can't just solely rely on these
laughably low fines.
And I think this is a case of
like the education one where like people
don't understand.
And I think a lot of it is,
um, a lack of,
I don't want to sound mean when I
say this,
but like a lack of empathy in the
What was her name?
Shoshana Zuboff in Surveillance
Capitalism,
The Age of Surveillance Capitalism.
She tells a story at the very beginning
how her house literally exploded.
It burned down and exploded.
And she talked about when the house first
caught fire,
she was trying to gather up all her
notes and stuff because she had no frame
of reference for –
what was about to happen.
Like,
it's just one of those things where like,
when you don't have a frame of reference,
you don't even think about it.
It's, it's the whole, sorry.
I know I'm rambling a little bit here,
but I'm, I'm going somewhere with this.
It's the whole, like, you know,
when people think like, Oh, well,
why would anyone want to hack me?
Like, I'm not interesting.
Or like, I have nothing to hide.
It's like, yeah, it's,
Because you're a decent person whose brain
doesn't immediately think of all the
horrible things you could do with
somebody's data.
And I think it's the same thing here
where like normal,
not crazy people think about surveillance
cameras and they're like, oh yeah,
we can find like stolen cars and Amber
alerts and like deter a crime.
And like, yeah, this is great.
And because they're not completely insane,
they don't stop and think about the cops
we talked about a couple of weeks ago
who are like stalking,
not even their girlfriend,
a girl who turned them down.
you know the all the hacked cameras that
allow pedophiles to look at playgrounds
that i think we covered one story about
a camera that was or maybe i wrote
about it in like a data breach or
something but like a um flock cameras that
were like placed inside a gym at a
community center and rightfully people
were like why was there even a camera
in there in the first place like you
know normal people don't think about all
the bad things that can happen because
they're not bad people
And yeah,
I think that's really what it is,
is it's a lack of education where people
don't.
And furthermore,
it's like this is one of the reasons
I post the data breach thing every week
is because it's one thing to say this
could happen.
It's another thing to show articles and go
like this does happen all the time.
Here's the twenty pages of search results
of all the times this has happened.
And I think that's when it'll really start
not not to try and scare people because
that doesn't work,
but to just make people realize like this
is not hypothetical.
This is not theoretical.
This is happening.
And we have to factor that into the
math.
Thank you for coming to my TED Talk.
Tip your service.
Scarecrow's in the chat here.
about those cameras you should post a
picture of these if you can to the
to the form uh have people take a
look at them because i think we can
we can try and track them down yeah
it is i mean of course these are
going to go brandless at this point
because they don't want to get any
backlash of course um but yeah it's a
huge huge problem post it on the forum
discuss dot privacyguides.net it's a great
great place
Yeah,
tag me in that because I'm on the
board of EFF Austin,
and I think I know what you're talking
about, but it's been so long.
I no longer live in Texas,
and even at the time,
I never really stopped and stood on the
street corner and like,
let me get a good look at this.
But yeah,
tag me because I can share it around
with the other board members,
and maybe we can identify what those are
and figure something out.
Or maybe somebody already knows for all I
know.
I've never asked about them before.
Yeah.
Okay.
Oh,
the one last thing I wanted to share
on this topic is somebody left a comment
on this story,
which is why I included it as a
forum post and not an actual story,
where they said the part about this
Leonardo thing can track RFID devices such
as credit cards.
They said, I cast suspicion on this claim.
Even if we pretend they aren't –
trying to scan RFID through the metal
panels of your car,
which should normally neutralize RFID.
I have no idea how they can even
pretend to scan a passive RFID signal,
such as that of a credit card,
from several meters away.
Its range is a few centimeters.
The signal-to-noise ratio is going to
render the signal as unreadable noise at
any large range.
They make a really good point because I
do use Apple Pay sometimes.
And like, depending on the terminal,
sometimes like if I'm just a few
centimeters or inches off,
it won't read the and I know that's
like NFC, not RFID.
But yeah, these things are so low powered.
It's like,
how are you going to read that from
ten feet away?
That doesn't even make sense.
So big, if true,
if they've mastered that technology,
that's impressive.
Alrighty.
I think that'll bring us into the site
updates if we don't have anything more to
add to that.
All right.
So yeah, in a little bit,
we're going to give you guys an update
on a story about some eBay executives.
If any of you remember that story,
they threatened and harassed some people
who left some negative reviews.
And we're not just talking about like
legal letters.
But before we get to that,
we're going to give you some quick updates
about what we've been working on at
Privacy Guides this week.
So I mentioned I've did some work on
a flock video.
That's because our video about Bull Run
and the NSA's
It's not the latest attack on encryption,
but the next chapter in our series is
done.
It looks great.
Thank you to Jordan for all of that.
And it should be going out to members.
I think we're trying to release it this
weekend.
So if you are not a member,
definitely sign up,
get early access to that.
This is my first time filming a
storytelling video like that.
And I'm really excited with how it turned
out.
And I think you guys are going to
enjoy it.
And then, yeah, just a little teaser.
Our next video that we're already working
on is about flock and, uh,
D flocks national day of action.
And, um, I believe it was Jonah that,
that did some digging and realized like,
man, other than Ben Jordan,
there's not really a lot of privacy people
talking about flock.
And so we thought it would be really
cool for us to step in and, uh,
hopefully this will be a really good video
that.
Explains what Flock is,
explains what are all the problems with
it,
gives that list of twenty pages of search
results that I mentioned earlier,
and is hopefully something you guys can
share with friends and family to be like,
hey, go talk to your city councilors,
email your politicians,
and tell them you don't want this.
So,
that's what we've got going on on the
video side.
Sweet.
On the website community side of things...
Some stuff I'm working on,
there's an upcoming kind of redesign of
the site to make it a bit easier
to maintain.
We were using this software called
MakeDocsMKDocs,
which is basically being discontinued.
There's a whole...
don't know a lot going on with it
uh so we're working on kind of a
new yeah that's kind of the driving force
behind this so we're switching to uh
should be switching to hugo uh for that
which should make contributing a little
easier hopefully and uh we're gonna
redesign our blog make it a bit easier
to navigate um besides that i've been
looking into security keys lately uh
that's been
mostly what I'm doing this week.
There's a lot of stuff going on that
makes them really annoying to come up with
good recommendations and criteria.
A lot of cases where security keys aren't
certified or they are certified,
but they don't report themselves as
certified in some cases,
so then websites can't tell if they are
or not and stuff like that.
There's varying...
Varying security practices with all of
these,
and it's hard to find one super great
solution.
Because of course,
YubiKeys have been traditionally the top
recommendation,
but there are drawbacks to them for sure.
You can't back them up,
which people find very inconvenient.
If you switch them out or update,
you have to...
switch them out on every single website
you visit, which is really annoying to do.
So yeah,
a lot of a lot of stuff like
that.
So continuing to look into those pretty
much there's a thread on our form at
discuss the privacy guides.net.
Again,
talking about there's like multiple
threads, basically,
there's some tool specific ones,
there's comparison ones where people are
sharing kind of opinions about all of that
stuff.
So if you have any thoughts about
security keys for some reason,
you can chime in there.
Otherwise,
Free has been working on articles.
We talked about
that one earlier,
but there's been other ones throughout the
week.
They get posted to privacyguides.org slash
news,
and it's a great way to stay up
to date with some other stories that we
don't talk about on this weekly show.
Some of the stories include over a hundred
vulnerabilities being found in the IRS's
contractor handling Americans' tax
information.
New dynamic patching in Chrome is going to
allow updates without restarting the
browser.
And then, of course,
those stories that we talked about today.
All of the stuff that we just talked
about in this section,
it's made possible by our supporters.
You can sign up for a membership or
donate at privacyguides.org.
Or you can pick up some swag merch
at shop.privacyguides.org.
Hopefully,
I can expand some of that stuff with
new sticker designs in the future,
but we'll see.
Privacy Guides, all of us here, of course,
we are a nonprofit.
We research and share privacy-related
information.
We host communities like our forum,
for example.
We have chats on Matrix where people can
get advice and stay up to date about
digital privacy and preserving your
digital rights.
So yeah,
with all of that out of the way,
let's...
We're going to talk about an update to
the FCC router ban that we discussed a
few episodes ago.
I don't remember exactly when that was.
First,
I'll check the chat really quick for some
stuff.
Derek, twenty three fifty eight.
Looking forward to the vlog video.
Yeah, I hope it'll be good.
And it's been working on that for a
bit.
So hopefully we can get that out pretty
soon.
Tony Mojo said the same thing.
Yeah, I think it should be.
It should be fun.
It's definitely a little bit more entry
level.
It doesn't dive in super deep.
But again,
there's so little content out there as it
is that I think we kind of wanted
to start very surface level and give
people kind of an on-ramp to understand
the problem.
At least that's what I was going for.
Yeah.
I also just wanted to say real quick.
Yeah.
The, the security keys do have drawbacks.
Like right now I'm trying to get back
into using the Tor browser a lot more
and it's like, oh, cool.
I can't even log into Tudor because I
added the security key and remove TOTP.
So yeah, that, that is a bummer.
I hope Tor can figure that out at
some point.
I don't remember if mall that browser has
enabled it.
I know they were looking into it at
one point,
but I was going to say they haven't
yet, but I, yeah,
I know they're trying to,
so hopefully soon fingers crossed.
This story was reported by Ars Technica.
The Trump administration exempts SpaceX's
Starlink from the FCC ban on foreign-made
routers.
A public notice issued by the FCC said
Starlink routers received approval from
the Department of Defense.
SpaceX's exemption is good until February
first, twenty twenty eight.
Netgear's exemption,
which we're going to talk about next,
is only good until October of twenty
twenty seven.
Netgear was the first major vendor to get
an exception to this rule on April
fourteenth.
Amazon then received an exemption for its
Aero routers and the routers to be used
for its Leo satellite service.
I would remind people we talked about this
in the episode where we first discussed
this FCC router ban,
but like there are pretty much
no routers made in America.
And it's not like super easy to just
spin up router factories overnight.
So of course,
there would have to be all sorts of
exemptions to these laws.
I do think
We'll get back to this in a second,
but I do think it's kind of arbitrary
how these are being applied.
The article says SpaceX has a factory in
Texas and some of its routers have the
words made in the USA printed on them,
leading some to believe that it might be
the only major router maker to escape the
FCC's wide-ranging ban.
Yeah, exactly.
But other Starlink routers are made in
Vietnam.
So, some discussion topics here.
The FCC hasn't publicly shared what
criteria these companies meet to get
exemptions.
And this is the main problem that I
have with all of this stuff.
It seems to be kind of arbitrary whoever's
in the Trump administration's favor at any
given point in time.
It seems like they are often...
kind of coerced or threatened into making
whatever changes the government wants in
order to preserve their business.
I am really annoyed right now,
not because of...
routers but because of some stuff that's
happening with the company that makes my
car i have a pull star too and
they've been banned from selling new
models in the us because they're a chinese
company it's a strange situation because
like their sister company volvo is owned
by the same parent company and they
received an exemption um it seems like
other car manufacturers are receiving
exemptions
as well,
but that kind of relates to a similar
thing as these routers where it's
computers from foreign countries that the
Trump administration doesn't want in the
USA.
It's very strange because all of the
computers in Polestar's cars as well as
Volvo's run
android automotive so like it's it's all
designed by a by a american company
basically uh so why they are concerned
about those computers it's not very clear
to me but it's just it kind of
seems to be whoever is putting in the
effort to basically convince the trump
administration
that they should keep their business
around is getting exemptions.
And in that case,
Polestar just didn't really bother with
it.
But it's annoying that all that stuff is
happening in the first place.
Anyways, I think that was my main thought.
Nate,
what were you thinking about this article?
Did you have any thoughts or questions
about it?
Um, not really too much.
Uh, I mean, you,
you kind of nailed everything, you know,
it's like, even from the beginning,
the government hasn't really said like,
what exactly is their criteria here?
What is the threat they're trying to
defend against just some vague national
security, which, you know,
the government's always done like, Oh,
national security.
But now they're like really kicking that
into overdrive.
And, um,
I think the article also noted that it's
interesting that these are all temporary
exemptions.
But once they're up, it's like, okay,
what happens?
They can reapply,
but I guess they're also supposed to show
progress that they're moving manufacturing
to the U.S., which, like you said,
just does not happen overnight.
So, okay, this is an extreme example,
but –
I checked on it the other day out
of sheer boredom.
Samsung semiconductor factory that they're
building in Texas.
That sucker's been under construction.
I think they broke ground in like twenty
twenty one or something like that.
And every year they've been saying we're
going to start putting out chips in the
spring.
We're going to start putting out chips in
the fall.
They're still not putting out chips.
I don't know what they're doing.
That's happening, I think,
with a lot of these companies in America.
There's one in Arizona I know of.
I don't remember if it's TSMC or Intel,
but somebody's building a plant out there.
I think it's TSMC.
Yeah, and that's been a similar situation.
Routers might be an easier one to make
in the U.S.
I know that they really want chip
companies to move manufacturing to the
U.S.,
but that is such a specialized tool that
even TSMC...
is gonna have a very hard time moving
that manufacturing capacity to the US if
they want to because it's not just a
matter of like getting the plans in the
machines and like making it here some of
these products require like real experts
in the field and like pretty much all
of them in that case are in Taiwan
so where are they in America who can
even do this stuff you you actually need
the people involved in it actually just is
true that
there aren't enough people in America who
know about that stuff to implement these
things.
So I think that that's going to cause
delays.
I think it's just the thing where like,
clearly favors Elon Musk, basically.
That's kind of the favoritism we've seen
with Tesla and his other companies.
We've seen it with like OpenAI and Sam
Altman.
There's just some companies that the
government really likes.
I think we talked about that when
anthropics fable models where were banned
by the us government for some period of
time and that was an american company you
know there weren't even like chinese
concerns which is usually the excuse that
they use um so yeah i i don't
think anyone's really safe from these
sorts of restrictions unfortunately yeah
honestly i was surprised it took starlink
this long to get the the exception i
wonder if they just didn't bother to
to apply for it or something.
But yeah, it's, it's like you said,
there's so many like with these, I mean,
I don't know about routers,
but with semiconductor factories,
it's like in some cases there's like very
specific niche equipment that's made by
like, I'm not even making this up.
There's some stuff that's only made by
like a single company in Germany that has
like ten people.
So they're back ordered by like six to
eighteen months on this equipment.
And then that's not including the facility
itself,
which granted the Samsung semiconductors,
the conductor factory is like one of the
biggest in the world.
So that's probably a bit of an exception,
but yeah, it's,
it's not like you just rent an office
space,
throw in a few cubicles and start printing
out stuff.
Like even with these routers, it's like,
this doesn't just happen overnight.
It's.
Yeah, and it's going to be,
it's kind of a situation,
I think a lot of these businesses who
are affected are going to have to face
the question of like,
is it even worth sticking around in the
US?
And I think probably more businesses may
opt out of that than the Trump
administration probably expects.
Going back to the whole Polestar thing,
I know that like,
it's only five percent of their US sales
or something like that were in the US.
They're big in like Europe, for example.
And in I assume the reason that they
didn't really pursue an exemption in that
case was because it'd be way cheaper to
just drop that five percent of sales than,
you know,
try and meet all of these demands that
the government has.
And I don't know if that'll be the
case with like Netgear, for example,
but spinning up this this manufacturing
capability is not.
cheap so giving up on us sales for
a lot of these companies might actually be
the more cost-effective way to go even
even for american companies like like
netgear is an american company for example
they just manufacture overseas like pretty
much every other company in the us does
so it'll be a weird time in tech
i think it'll be bad for americans overall
because
Americans have gotten really used to tech
being very cheap.
If you ask anybody from any other country,
even like nearby countries like Canada,
but especially Europe,
especially like far away from everything
countries like Australia.
tech is way more expensive to buy pretty
much everything in those countries
compared to the US.
And I think that changes like this are
just going to really push up the price
to...
like not exorbitant but basically it's
going to be meeting the the prices of
other of all these other countries and
we're just kind of going to be in
the same boat um we're just not going
to have the advantages that we've enjoyed
for for quite a while and that'll be
probably a shock to a lot of people
i don't have much more to add to
that i agree
Tough times are coming.
Yeah.
Well,
why don't you take us away with our
next question?
Speaking of Europe.
Yeah.
Speaking of Europe and tough times are
coming.
So this next story comes from Telegraph.
It says inside the dystopian world of
Germany's free speech crackdown.
I'm going to read off the notes that
I made here because this is a very
long article.
Definitely worth a read.
Lots of good stuff in there.
But I'm going to read off my notes
just to keep it short.
to the relevant parts.
So Berlin police told Dr.
Ziedelman he had been accused of violating
a post-Second World War law that bans the
display of Nazi symbols, slogans,
and imagery and could now face three years
in prison if found guilty.
The sixty-nine-year-old found out the
offending social media post was a meme
about Adolf Hitler,
but it was one in which he criticized
the Nazi dictator and compared his
invasion of Czechoslovakia to Vladimir
Putin's invasion of Ukraine.
So basically, like,
I'm saying Hitler is bad.
Why is this
Yeah.
Dr.
Z is one of thousands of Germans who
have been threatened with fines or prison
sentences for social media posts that fall
afoul of the country's political speech
laws,
which are unusually stringent for an EU
member state.
One German had his home raided for calling
a minister a –
Schwachkopf,
which I guess is German for dummy.
And I'm sure all the Germans are laughing
at my pronunciation right now.
Another was fined two thousand euros or
about seventeen hundred pounds for calling
Friedrich Merz a lying fritz under a law
that critics claim makes it effectively
illegal to make fun of politicians.
The number of investigations under Section
eighty six a the Nazi symbol band that
Dr.
Z was investigated for has more than
doubled over the past decade,
according to official police statistics.
Investigate investigations into the
political insult law also reached a record
level in twenty twenty five.
The surge in cases is so vast that
the U.N.
has launched an investigation into free
speech violations in Germany,
a step typically reserved for
dictatorships and banana republics.
German free speech activists on the left
and right,
as well as the Trump administration,
have also raised the alarm,
and there are growing calls from some of
the country's stricter laws to be
scrapped.
The fur bears some similarities to the
speech debate in Britain,
where citizens have a knock on the door
from police over opinions posted online.
Uh,
this part blew my mind in the case
of Dr. Z,
the rise of online portals in Germany,
which allows citizens to report each other
for illegal comments seems to be what
alerted police to a social media post.
So they literally have like Stasi style
snitch on your neighbor because something
he said hurt my feelings.
Which is pretty insane.
Another controversial law in Germany's
free speech debate is section one eighty
eight of the criminal code,
which imposes a de facto ban on publicly
insulting or defaming elected officials.
In one recent case,
a pensioner was investigated under Section
one eighty eight for posting Pinocchio is
coming on Facebook.
After he learned that Frederick Mertz,
the chancellor, was visiting his hometown.
In November,
twenty twenty four police in Bavaria
raided the home of another pensioner
because he called Robert Habeck,
the then vice chancellor of Germany,
again, a dummy.
The raid was reportedly launched after Mr.
Habeck personally filed a criminal
complaint against the pensioner.
In twenty twenty one,
police raided a man's apartment in Hamburg
after he told a senator,
you're such a D. I'm assuming it's dick.
I don't know.
And this year,
a resident was fined two thousand euros
for calling Mr. Mertz a lying fritz.
Officials show a record four thousand
seven hundred and ninety two section one
eighty eight cases were filed in Germany
in twenty twenty five,
with the numbers rising by nearly eighty
five percent between twenty twenty three
and twenty twenty five.
So, um.
Yeah, I mean, this is...
This kind of goes back to the thing
that I said with the graphene thing,
where it's like...
Some people are totally comfortable...
painting a target on their back because
it's the principle of the matter, right?
Like you should be allowed to call your
politicians names.
I'm sorry,
but no matter what politician it is,
as long as you're not like threatening
them,
you should be allowed to say that they're
stupid.
You should be allowed to say that they're
corrupt.
You should be allowed to say that they're
not doing a good job.
Like you should be allowed to criticize
them.
And I think if you're,
It's one of those things where like we're
seeing this all over the West,
unfortunately,
where this kind of stuff is being
monitored.
We know that the feds here in the
U.S.
at least are monitoring social media.
That's what services like Palantir do is
they just scrape social media,
even the really fringe niche ones that
only have like one hundred thousand people
using them.
So just remember that what you post,
even if it's like friends only or
something,
anything you put in a digital format,
you should kind of assume it's public.
And just be aware if you're one of
those people who's like,
I'm going to go ahead and stand up
for my right for free speech.
Like, that's totally cool.
I applaud that.
I do that, too.
I'm very critical of all levels of
government on Mastodon.
But at the same time,
just you need to be aware of the
risk you're taking.
So and Germany needs to figure out what
they're doing if they're getting
investigated by the UN.
I think that's pretty wild.
I don't know if I have much more
to add to that.
Did anything jump out at you that I
missed?
No.
No, I don't think so.
I think you pretty much covered it.
Yeah,
it's just like we talked about earlier in
terms of government overreach, basically.
Are you willing to take the risk of
being targeted by these governments,
even if you're not doing anything wrong?
It's a pain.
It's a hassle that they can really put
you through,
and I think that that's a big problem
we have to face right now.
Good times.
I have not heard of this Gulag Archipelago
that Scarecrow recommends.
So I don't know.
I can add that to my reading list.
I haven't heard of that one before.
Sounds like something that somebody in
Russia may have written.
I'm not seeing any other questions right
now.
So I think we can probably jump into
our story about eBay that I know you
were interested in.
Yeah, that's a crazy one.
Yeah, just checking the chat here,
but we'll look at this TechCrunch article.
eBay reaches a fifty six million dollar
settlement with e-commerce newsletter
writers it terrorized in twenty nineteen.
I remember reading about this in twenty
nineteen.
Well,
I guess I didn't remember I read it
in twenty nineteen, though.
I thought it was an older story.
It's a lot more recent than I thought.
The article says the settlement this week
resolves a twenty twenty one civil case
that was brought by the couple against
eBay.
The couple is a married couple,
Ina and David Steiner,
who were the co-authors of eCommerce
Bytes.
They inspired the ire of high-level eBay
executives, said TechCrunch,
after occasionally criticizing the company
in their newsletter.
uh executives from ebay used sock puppet
social media accounts to harass the couple
while also sending them anonymous
threatening letters and bizarre items in
the mail including live spiders and
cockroaches pornographic magazines a
bloody pig mask a funeral wreath and a
book about surviving the death of a spouse
so this is not just the typical legal
harassment you might see from a company's
lawyers this is an actual
criminal harassment and stalking from
top-level executives at eBay.
According to previously released court
documents,
a plan that was attempted but never
successfully carried out involved affixing
a GPS tracking device to the couple's car.
Yet another internally broached plan at
eBay involved sending a, quote,
Samoan gang to the Steiner's home.
In a statement published Tuesday,
eBay disavowed its former employees'
behavior as, quote,
not representative of eBay's culture.
So that is a crazy story.
I know that eBay made that statement.
statement obviously but uh people up to
the ceo of the of ebay uh devin
uh weinig and uh multiple board members
were involved in this uh the ceo settled
for two million dollars as part of the
settlement uh was directly from him uh
half a million dollars will be paid out
from uh another ebay executive wendy
Jones and seven former eBay employees were
criminally charged and pled guilty in
relation to this plot,
including the company's former security
chief, James Bout,
who was sentenced to nearly five years in
prison for this.
So it's wild.
eBay is crazy apparently.
And I believe a lot of the people
like, um,
A lot of the people involved are still
on the, at least the board, I believe.
I know that the CEO is the former
CEO.
I don't know who's involved now,
but not all of them were, like,
very punished, basically.
So... I guess, um...
Getting fifty six million dollars is not
the worst outcome for these people.
They're probably happy about that because
they settled.
But it is absolutely crazy that they had
to go through that in the first place.
You know,
a targeted harassment campaign like that
is not exactly typical of a company like
eBay.
So, yeah.
Was there anything you wanted to discuss
about this article or any other thoughts
that you had, Nate?
No,
I think partially I wanted to cover it
because one, like, yeah, it's so wild.
It's like, these are executives, right?
And it's funny because I've noticed I've
worked around every level of employee you
can imagine from like the entry level
cashier at the grocery store to like I
have stood ten feet away from someone
who's in the top twenty on the Forbes
billionaire list.
Like I have worked around everybody you
can imagine.
And I've noticed a curve of like.
I don't want to drop an F-bomb of
like how many craps they give where like
the lowest level people don't care.
Like they're never stressed.
They don't care.
Well, I mean, they're stressed,
but like they don't care because they
don't get paid enough to care.
And then on the other end of the
spectrum is like all the higher executives
that don't care because they pay someone
else to care.
And then right in the middle are all,
like,
the middle managers that are just
constantly stressed and high-strung about
everything.
And so it's just weird to me that
there's, like,
all these C-suites and executives that
it's just, like,
why are you wasting your time because
somebody, like,
left you a negative review in their
personal substack?
Like, seriously.
Truly, like,
when we were talking about this article
earlier today,
if you had asked me about this story,
because I knew of this story.
I remember reading the original, like,
story about it.
But I would have told you,
I remember this happening in like,
two thousand eight or two thousand ten or
like some sometime like early eBay,
basically,
where it's maybe it's a small company and
they're like personally invested.
But this started in early twenty nineteen,
this whole thing like eBay is a massive
company at this point.
And you're concerned about some couple's
newsletter on on a blog online.
It doesn't even make any sense at all.
It is the wildest story I have ever
seen.
And, yeah,
I guess I don't even know what else
to say about that.
It's crazy.
Yeah, it really is.
Also, just, you know, privacy.
Be careful what information you put out
there, who has access to it,
all that kind of stuff.
Yeah,
you never know who's going to stalk you,
apparently.
Seriously, that's so wild.
You would think they'd have better things
to do.
I sure would if I was being paid
that much.
Just to backtrack,
Scarecrow was talking about that book.
He said, yeah,
it's about someone's arrest in nineteen
forty five for private letters to a friend
about Stalin.
Imagine your letters from seven years ago
came back to smack you in this way.
Eight years of hard labor.
Yeah,
I kind of want to point that out
that not not to fear monger,
but this is something I hear smart people
point out all the time is like.
Again,
why privacy matters is a lot of the
time.
in an authoritarian or repressive regime,
when the new guys take over,
they will retroactively punish people for
things that happened before.
So in a functioning democracy,
usually a law will be passed and they'll
say, okay, from this point going forward,
this thing is illegal.
But like when the Taliban took over,
I distinctly remember this story because I
remember thinking how sad it was.
When the Taliban took over in Afghanistan,
when the US pulled out,
Afghans were rushing to like delete their
online presence because for years,
a lot of them had been like kind
of slowly westernizing.
And now they knew that some of the
stuff they did that was like totally
innocent, like, you know,
maybe women wearing blue jeans could get
them killed now.
And they were trying so hard to scrub
their social media presence and stuff like
that because now what they did in the
past is yeah.
And like, I don't,
I don't think we should all be living
in fear, but it's just, again,
be mindful of it's yeah.
Privacy matters.
It's very unfortunate.
But yeah, that's all I had, I think.
I think those were all our stories.
So I think we can check around,
see if we have any more final questions
before we wrap up here.
I think we only had one forum post.
Send them in the chat if you have
any.
I did see a forum post I wanted
to look at, actually.
Sure.
One of the top stories from the last
week.
Somebody posted on the forum,
does your privacy setup actually make you
stand out more?
They said for the past month and a
half,
they've been trying out some VPN services
on their phone,
trying to see which one works better.
So they talked about different VPN
providers that they used.
But they said that they received a message
from their IT department basically saying
they connected,
they detected a connection to their work
email account from an IP address
associated with Malved VPN and they wanted
to confirm that it was them and why
they were using a VPN service for that
connection,
which of course did not make them feel
very private.
It is.
So like,
it is a concern with some of these
tools.
Absolutely.
Uh, we,
we talk about this a lot more in
like the browser fingerprinting context
where it's like using something like
Mulvet browser, for example,
or even brave, uh,
might make you more fingerprintable to
people who are specifically looking out
for it.
A lot of these privacy tools that we
recommend are really geared towards, um,
thwarting mass surveillance tools.
They're effective at blocking like,
ninety-nine percent of the general things
that you'll see on sites,
whether that's like Facebook tracking or
ad networks or that sort of broad
surveillance,
whether that's by companies or otherwise.
When it comes to like,
individualized privacy advice,
it is more of a
There's a lot of threat modeling you have
to take into account.
You have to decide who you're trying to
defend against from a privacy perspective
and how you want to stand out.
Because if people are looking at you
specifically,
they can detect that you're using these
privacy tools and that can be a red
flag in some cases, like this one,
for example.
There are certainly ways to work around
this.
One way, like on phones,
at least Android phones, for example,
I see people use private spaces or work
profiles in their main profile because you
can set a VPN connection for only that
profile and the apps inside that.
And then you can have like a private
space with a VPN for most of your
general apps and then keep like...
work stuff for local stuff like your bank
in a in a profile that doesn't use
a VPN.
But yeah,
it really depends on your individual
situation in that case,
which is why
If you have any questions about that sort
of thing,
it'd be great to ask on the forum.
There were a lot of good responses in
that thread.
I won't go through all of them,
but that was kind of my two cents
on that, and I wanted to highlight,
I think,
a related question here in the chat from,
and maybe Bob's your uncle.
If you obfuscate a connection to a VPN
like you can with Tor Bridges,
does the ISP still know you're connecting
to a VPN?
That is the sort of thing where it's
also...
suspicious, or it can be.
There are different obfuscation methods
that are less fingerprintable.
So like web tunnels with Tor, for example,
are supposed to be less identifiable,
which is why they can get around
censorship in some countries.
I don't know what specific tools you would
use with a VPN,
although some of that Tor bridge software
is kind of generic and could be used
in theory for that sort of thing.
But even in that case,
I think it's a little suspicious if you're
just sending like a large amount of
traffic every day to one specific IP
address and there aren't a ton of ways
around that so I guess I don't know
off the top of my head if there's
any like VPN clients that will rotate
different connections between different
IPs or VPNs or whatever I'd have to
look into that but um I think I
think either way typically
Your ISP definitely can detect whether
you're using a VPN.
They can also detect whether you're using
Tor.
The Tor network,
maybe that's a common misconception people
have,
but it doesn't hide the fact that you're
using these things or like you're
devices or whatever from the ISP
specifically.
The only thing that it will hide is
a lot of metadata about that traffic,
like the domain names you're connecting to
and IP addresses, etc.
How much you're sending to like one
particular source.
But that's why we say VPNs are,
they're not like a foolproof solution.
They're
Just shifting trust from your ISP to that
VPN provider in most cases,
but they're not like the perfect privacy
tools and they can be detected.
So it is something that you have to
keep in mind.
Yep,
I don't really have anything to add to
that.
I did see that question.
I thought it was really interesting
because, yeah, I thought about,
like you said,
we usually see it talked about in the
browser space where if everybody's using
Movad browser and you've got all the
shields and uBlock turned on,
then you stand out.
But it's definitely a lot different when
you're talking about very specific use
cases like at work or they talked here
about trying to access their bank and
stuff like that.
So it's a good thread, though.
Lots of good info there.
Check our signal donors chat again real
quick here.
Yeah, I've been kind of bouncing around,
checking the forum thread,
not seeing anything new.
Scarecrows in the chat said,
Zuma?
I'm not familiar with who that is,
but they made a video about the government
vandal events.
Maybe that's worth checking out.
I'll have to add it to my list
of videos.
I assume there probably are ways of
obfuscating some of that information,
but typically with VPN companies also,
the IP address that you're connecting to
is visible and known to be a VPN,
so they can just know that way.
A lot of the deep packet inspection stuff
that I've seen is like,
claims that your ISP could use that to
detect what specific sites that you're
connecting to even when you're using a VPN
and people say the same thing about the
Tor network that they can use that to
see to kind of gain more information about
what you're doing on Tor in addition to
just the fact that you're connecting to
it.
I haven't seen any evidence that that can
be reliably applied in the real world.
I know that
It's all just theoretical,
and I think that some VPN providers like
MOLVAD with their data, D-A-I-T-A program,
they claim to defend against that sort of
thing,
but also I've never seen any proof that
that sort of thing can be reliably used
outside of lab academic settings,
basically, with small groups.
At an ISP scale,
I don't think that deep packet inspection
is going to be a huge issue.
But there are,
if you are concerned about that,
there are, of course,
obfuscation techniques.
As Unrejected said,
there's also advanced protocols like
X-Ray.
Reality, that's sort of a similar thing.
Spoof the TLS signatures of other sites.
I'm not totally for sure with how that
works.
I think...
Similar to web tunnels if I remember
correctly that Tor has but I could be
I could be wrong I know a lot
of these tools Especially ones that
unredacted org works with you should
definitely check out their site by the way
because you're doing a lot of cool stuff
with like the Tor network and stuff but
a Lot of those for like anti-censorship
purposes can get around that sort of thing
I Would
I will have to look more into how
this works because I'm not sure.
I feel like, like I said before,
I think sending a lot of traffic to
one specific server is probably suspicious
in itself.
But yeah,
some of these tools can add more plausible
deniability.
But maybe there's other things that it
does that I don't know or remember off
the top of my head.
So I'll have to look into that later.
I wanted to mention scarecrow said here
that, um,
several politicians have suggested that
this sort of stuff may earn you extra
scrutiny.
I remember we covered that story a little
bit,
and I think what they were actually saying
was that it's not so much that using
a VPN will make you extra interesting.
It's more that, um,
so the way that section seven Oh two
works is any electronic signal that
crosses international borders becomes a
fair game for the NSA and
With a VPN, since they can't, in theory,
since they can't tell where it's coming
from originally,
there's a lot of questions about like,
does that count as crossing international
borders?
Can you collect VPN traffic?
Because is it somebody from the UK
connecting here to try and evade age
verification on Discord?
Is it, you know,
somebody from a repressive country?
Is it somebody in the US who's just
connected to a nearby server and it didn't
cross international lines or something
like that?
So, or, you know,
if you use like Proton Secure Core,
those route through servers that are
actually owned by Proton.
So there's like,
There's a handful in Iceland.
There's a handful in Switzerland.
I think there's another country that they
have a few.
But so like those would,
for a US user like myself,
those would bounce out of the country and
then back in.
So I think that's more what it was
referring to.
Not so much like, hey,
let's watch everybody that uses a VPN,
but more like, hey,
how do we know if these people are
supposed to be protected by law?
Which I would argue the NSA doesn't care
about anyways, but I digress.
Sorry,
I was trying to get something to go
away.
I was just going to say,
Zach from Unredacted also said,
they take into account how much traffic is
sent to different IPs.
I guess there's some VPN clients designed
for sensory countries that can load
balance connections.
Yeah,
that would be what I'm interested in
looking into more because I think that
could be a cool solution,
but I don't know what they are.
Again,
I'll have to look into this after the
show.
I don't think I have much else.
I'm not seeing anything in the signal
chat.
Kind of wraps things up.
I think I just want to share really
quick.
Right before this stream,
I was reading a story,
and I caught some of Henry from TechLore's
livestream like an hour before this one,
where he talked about some stuff about
Texas...
getting a court order for Verisign to
basically revoke another Coventry's .com
domain.
I had a lot of thoughts,
both about that story and also about
Henry's take on the whole thing,
so I think I'm going to talk about
that in a livestream on my channel right
after this one.
So if anyone's interested in continuing to
listen to me talk about stuff,
you could go over there if you want
to, but just throwing that out there.
Otherwise, yeah, Nate,
you want to wrap things up,
do you think?
Yeah, sure.
I'll let you get to that.
So all the updates from this week in
privacy will be shared on the blog every
week.
So sign up for the newsletter or subscribe
with your favorite RSS reader if you want
to stay tuned.
For people who prefer audio,
we also offer a podcast available on all
podcast platforms and RSS,
and this video will be synced to PeerTube.
Privacy Guides is an impartial nonprofit
organization that is focused on building a
strong privacy advocacy community and
delivering the best digital privacy and
consumer technology rights advice on the
internet.
If you want to support our mission,
you can make a donation on our website,
privacyguides.org.
To make a donation,
you can click the red heart icon located
in the top right corner of the page.
You could also go straight to
privacyguides.org slash donate.
You can contribute using standard fiat
currency via debit or credit card or opt
to donate anonymously using Monero or your
favorite cryptocurrency.
Becoming a paid member unlocks exclusive
perks like early access to video content
and priority during the live stream Q&A.
You'll also get a cool badge on your
profile in the Privacy Guides forum and
the warm fuzzy feeling of supporting
independent media.
So thank you everyone who watched and
stuck around and we will see you next
week.