The Electronic Frontier Foundation (EFF) is urging California Governor Gavin Newsom to veto Assembly Bill 1709, which would impose a sweeping ban on social media use for individuals under 16. The EFF argues that the bill, by restricting recommendation algorithms and other essential online tools, infringes on free speech, privacy, and access to information, while also potentially forcing invasive age-verification methods.
This article is the first part of a two-part series on doxxing safety, focusing on prevention and managing one's digital footprint. It explains doxxing as the deliberate disclosure of personal information for harassment and highlights the need for individual protection due to a lack of comprehensive data privacy legislation. The article introduces Open Source Intelligence (OSINT) as a methodology central to doxxing, but also valuable for prevention, and suggests various OSINT tools and resources.
This article, the second part of a series on doxxing safety, focuses on incident response after personal information has been deliberately shared to harass or endanger someone. It emphasizes the importance of maintaining an incident log to track suspicious online activity and assigning team roles for a coordinated response.
Several US states, including Connecticut, Maryland, New Jersey, Oregon, and Virginia, have enacted new laws to restrict commercial location tracking, addressing concerns about pervasive surveillance. Despite this progress, significant gaps remain in these laws, highlighting the need for broader action from other states and Congress to ensure comprehensive location data protection.
This article, adapted from a video by EFF and the Trevor Project, offers advice for LGBTQ+ individuals to improve their online safety and security. It emphasizes taking control of personal information shared with online services and platforms to prevent doxxing and unwanted outing.
A recent poll indicates that two-thirds of British citizens do not trust their current government, nor any future administration, with access to their encrypted private messages. This sentiment highlights a significant public concern regarding government access to personal communications.
The latest version of the Brave browser, 1.94, has introduced a new feature called 'Email Aliases'. This feature allows users to generate disposable email addresses for signing up to new services, aiming to help users evade tracking.
Android 17 will introduce new network security features, including support for Encrypted Client Hello (ECH). ECH is a privacy standard designed to prevent network providers from monitoring which websites users visit. These updates aim to improve connection privacy and protect user data on home networks.
Building customer trust in digital systems requires more than just compliance; it hinges on how data is handled daily. Key areas for security leaders include ensuring consistency of customer intent across all systems, treating privacy as a distributed-systems challenge, minimizing unnecessary data, designing for potential failures, and understanding AI's impact on trust boundaries.
EFF and allies are advocating for stronger privacy and data protection measures in Brazil's elections, arguing that violations of these rights enable the spread of misinformation and manipulation. Their recommendations aim to foster better collaboration between oversight bodies, civil society, and digital platforms to ensure electoral integrity, especially in the age of AI-generated disinformation.
Immigration and Customs Enforcement (ICE) has used administrative subpoenas to request user data from technology companies for investigations into individuals, including social media users critical of the government and international students. The EFF is compiling a list of these subpoenas, highlighting instances where they have been challenged for exceeding authority and violating First Amendment rights.
The Electronic Frontier Foundation (EFF) argues that Automated License Plate Readers (ALPRs) enable mass surveillance and are inherently harmful. They advocate for the complete elimination of ALPR mass surveillance and, failing that, for strict legal restrictions like warrant requirements and data deletion deadlines.
The Electronic Frontier Foundation (EFF) has released a statement regarding a settlement with Meta, arguing that it will restrict young users' access to Meta products and negatively impact their rights to expression and association. The EFF also contends that the settlement mandates increased personal data collection for age assurance, further embedding Meta's surveillance practices and potentially compromising user privacy and anonymity.
France's top court has struck down a law that would have banned social media use for individuals under 15 years old, ruling it an infringement on freedom of expression. The decision noted that the ban did not distinguish between different online services or individual user circumstances, and highlighted the negative impact such laws can have on all users' free speech.
Microsoft is testing new privacy features for Windows 11 that will give users more control over which desktop applications can access their camera, microphone, and location. These controls are designed to enhance user privacy by allowing them to make explicit choices about data access for installed applications.
The New York Times reports on the increasing use of AI-powered surveillance systems for babies, with companies like Nanit collecting extensive data on infant development. These systems are expanding their data collection capabilities and aiming to monitor children into early adolescence.
The article argues that humans must take action to regulate autonomous lethal AI drones, highlighting the potential dangers of AI agents operating in the digital realm. It calls for immediate intervention to rein in the development and deployment of such technologies.
A developer has created a browser fingerprinting tool that demonstrates how easily users can be tracked online using advanced techniques. The tool, built with assistance from Claude, runs locally to show users their own susceptibility to various tracking methods.
A technique that uses inaudible sounds to fingerprint browsers has reportedly been used to track users visiting AliExpress. This method, though considered outdated, is still effective and raises privacy concerns.
TikTok, ByteDance, and affiliated companies have reached a $400 million settlement with the U.S. Department of Justice. The settlement resolves allegations that the companies violated the Children's Online Privacy Protection Act (COPPA). This agreement addresses concerns regarding the handling of children's data and online privacy practices.
Uber has been fined nearly $1 billion by Dutch regulators for violating the EU's General Data Protection Regulation. The fine stems from the company's automated suspension of driver accounts, which the Dutch Data Protection Authority deemed a breach of data protection rules.
AliExpress is reportedly using ultrasonic audio signals embedded in its website and app to fingerprint shoppers. These signals, undetectable by humans, can be picked up by devices and used for tracking, even potentially interfering with Bluetooth devices. Both Firefox and Brave browsers have announced measures to block these ultrasonic tracking techniques.
TikTok has reached a $400 million settlement with the US Justice Department concerning violations of children's privacy laws. The settlement includes an immediate payment of $300 million, with an additional $100 million contingent on the vacating of a previous consent decree against Musical.ly.
TikTok has agreed to a $400 million settlement to resolve a U.S. lawsuit alleging violations of child privacy laws. The settlement requires ByteDance-owned TikTok to pay $300 million immediately and an additional $100 million later.
The EFF and several civil society groups have urged Nottinghamshire Police to halt the deployment of live facial recognition (LFR) technology. They argue that LFR constitutes mass surveillance, treats everyone as a suspect by default, and raises concerns about disproportionate targeting, particularly of young people for low-level offenses.
The article discusses how using consistent online identifiers like email and phone numbers facilitates profiling by data brokers and attackers. Anonyome Labs proposes the use of separate digital personas to reduce activity correlation, thereby limiting the impact of breaches, spam, and identity theft.
This article explores the pervasive nature of surveillance, acknowledging that individuals are aware of being watched but often lack knowledge about who is conducting the surveillance, their motivations, and the methods employed.
EPIC and the Consumer Federation of America have released a new guide explaining how personal data influences pricing in today's economy. The resource defines terms related to data-driven pricing, illustrates how surveillance pricing operates, and provides examples of predatory pricing strategies.
A usage policy for Flock license plate reader cameras instructs police to conceal their use of the technology from individuals whose vehicles are scanned. This directive mirrors past tactics employed by law enforcement to hide the use of IMSI-catchers, commonly known as Stingrays.
Tech companies have privately challenged some ICE subpoenas seeking user data, particularly when the data was requested for investigating individuals criticizing the government or tracking immigration activities. EFF encourages these companies to do more by publicly challenging unlawful subpoenas and taking legal action against them to protect user privacy and deter future misuse.
U.S. Immigration and Customs Enforcement (ICE) has issued a directive prohibiting agents from using personally owned body-worn cameras, specifically mentioning Meta's Ray-Ban Stories smart glasses. This move is intended to prevent potential misconduct and avoid further scrutiny of agent behavior.
This article discusses how ad libraries in mobile apps can leak user location data, potentially without developers' knowledge. It highlights the multi-billion dollar location data industry and mentions recent reforms by Flock, privacy-invasive legislation in the Senate, and an EFF investigation into mobile ad software.
A CEO has apologized for the misuse of police surveillance technology, while activists are calling for vandalism against license plate cameras. This backlash is occurring as concerns about Halloween surveillance plans circulate.
EPIC, alongside a coalition of civil rights and privacy organizations, has sent a letter to Congressional leaders advocating for reforms to FISA Section 702. The letter specifically calls for closing the "backdoor search" and "data broker" loopholes, which critics argue allow warrantless access to Americans' communications.
The article discusses the increasing implementation of age verification laws globally, noting that many of these laws are ineffective and pose significant privacy risks. It specifically addresses the promotion of Zero-Knowledge Proofs (ZKPs) as a solution, arguing that ZKP-based age verification schemes are gameable, hackable, and could centralize power while creating further harms.
Documents reveal an ICE agent allegedly attempted to encourage confrontational tactics among Minneapolis activists, specifically targeting the Sunrise Movement. The agent reportedly offered to develop tools for 'direct-action' protests, raising concerns about potential entrapment and misuse of surveillance.
DecryptAds is a new, free service that simplifies the process of identifying entities tracking users through online ads and mobile apps. It scrapes and correlates adtech data, making previously hard-to-access information readily available to the public.
Apple has issued a new wave of warnings to users in 110 countries, indicating they may have been targeted by mercenary spyware. This latest notification follows previous alerts sent to users in over 150 countries since late 2021.
New Zealand's intelligence service alleges that China has attempted to use its space investments as a means to spy on domestic affairs. The agency also notes that identifying internal threats has become more challenging due to the widespread availability of harmful content online.
OpenAI is reportedly replacing its controversial Recall-style screenshot surveillance feature for ChatGPT with a new method that records user clicks and keystrokes. This change aims to build richer conversational memories for the AI by analyzing user interactions without capturing full screen data.
Flock Safety has introduced reforms to its mass surveillance technology, including reducing the default data retention period for automated license plate readers (ALPRs) from 30 days to 7 days. The company also implemented offense filtering for data access and claims to have enhanced audit features and officer lockout capabilities. However, critics argue these changes are insufficient to address the fundamental privacy risks associated with the technology.
EPIC and a coalition of over two dozen civil rights and privacy organizations have sent letters to the Senate and Thompson Reuters. These letters urge action to protect Americans' Fourth Amendment rights against commercial surveillance.
The Fourth Circuit ruled that a school's warrantless search of a student's cellphone did not violate the student's Fourth Amendment rights. This decision occurred despite the student facing criminal charges, raising concerns about privacy in educational settings. The ruling implies that schools may not need warrants for cellphone searches under certain circumstances.
Francesca Hong, who opposed the construction of new data centers in Wisconsin, has lost her election bid. While her loss may be seen as a short-term win for proponents of AI data centers, the broader fight against their expansion is ongoing.
EPIC has urged the U.S. Court of Appeals for the Seventh Circuit to apply the Wiretap Act's crime-tort exception in a case involving Edward-Elmhurst Health. The health system is accused of disclosing patient MyChart portal information to Meta, as it embedded Meta Pixel and other tracking technologies into its webpages, which collected and disclosed visitor information to unknown companies.
A large number of 737 free VPN and proxy extensions, primarily targeting Russian-speaking users, have been discovered to intercept browser traffic and reroute it through proxy infrastructure. These extensions, installed over 75,000 times across numerous Chrome Web Store accounts, were found to be impersonating legitimate services.
The Electronic Privacy Information Center (EPIC) highlights a Duke University study demonstrating vulnerabilities in data broker practices. This comes as 33 data brokers have disclosed under California's Delete Act that they sell or share data, raising concerns about bulk data security programs.
A coalition of advocacy groups has sent a letter to Senate committees warning about a deal that grants ICE access to private profiles of tens of millions of Americans via Thomson Reuters. The groups express concern about the implications of this data access for privacy and civil liberties.
Signal has implemented a new security feature called Automatic Key Verification to help users protect their encrypted chats from man-in-the-middle attacks. This feature provides an additional layer of assurance that conversations have not been intercepted.
British Transport Police are deploying live facial recognition technology on the London Underground, starting at Victoria station. Privacy advocates are concerned that this technology is becoming increasingly common and less scrutinized.