1
00:00:01,660 --> 00:00:04,520
This week's surveillance report covers Dashlane, the password manager,

2
00:00:04,800 --> 00:00:07,000
who has confirmed that hackers stole some customers'

3
00:00:07,220 --> 00:00:07,880
password vaults.

4
00:00:07,960 --> 00:00:09,040
We're going to talk about what's happened.

5
00:00:09,440 --> 00:00:14,240
The Pentagon has come forward and has admitted that U.S. troops are targeted with commercial location data,

6
00:00:14,380 --> 00:00:19,040
which is the same problems we talk about, hitting the people that supposedly don't have to deal with this.

7
00:00:19,140 --> 00:00:21,580
And there are some broader implications there I want to touch on.

8
00:00:21,900 --> 00:00:26,960
Europe is accelerating its move away from U.S. technology with Nextcloud's EuroOffice launching,

9
00:00:27,280 --> 00:00:29,860
as well as Tuda, the email provider joining as well.

10
00:00:30,140 --> 00:00:37,980
And then there's a wild meta AI account takeover story where hackers literally just asked AI chatbots to get access to Instagram accounts.

11
00:00:38,300 --> 00:00:39,480
And the AI said, sure,

12
00:00:39,740 --> 00:00:40,060
why not?

13
00:00:40,400 --> 00:00:40,520
Hello,

14
00:00:40,720 --> 00:00:40,840
everybody,

15
00:00:41,120 --> 00:00:44,100
and welcome to the Techlore Surveillance Report hosted by yours truly,

16
00:00:44,340 --> 00:00:44,540
Henry.

17
00:00:44,730 --> 00:00:49,560
And this is your essential weekly tech news delivering deep analysis on the latest threats to security,

18
00:00:49,720 --> 00:00:49,940
privacy,

19
00:00:50,260 --> 00:00:56,240
and digital freedom and empowering you to reclaim control and defend your rights.

20
00:00:56,640 --> 00:00:58,260
All right, we had some juicy,

21
00:00:58,660 --> 00:00:58,920
juicy,

22
00:00:59,740 --> 00:01:01,680
juicy stories this week,

23
00:01:02,200 --> 00:01:03,440
starting with what we never

24
00:01:03,600 --> 00:01:07,640
want to hear back here, right, which is a password manager that gets in some way potentially

25
00:01:08,080 --> 00:01:08,240
compromised.

26
00:01:08,840 --> 00:01:09,000
Now,

27
00:01:09,340 --> 00:01:14,540
this has a lot of asterisks on it, but it is quite reminiscent of that last pass

28
00:01:14,560 --> 00:01:16,500
data breach that we dealt with a few years ago.

29
00:01:17,040 --> 00:01:18,680
So Dashlane is a password manager.

30
00:01:18,980 --> 00:01:19,940
Theoretically on paper,

31
00:01:20,180 --> 00:01:21,260
one of the better ones,

32
00:01:21,420 --> 00:01:22,740
they actually started pivoting towards

33
00:01:22,760 --> 00:01:26,660
doing some more open source stuff, which I really liked when they started doing that.

34
00:01:27,060 --> 00:01:27,240
Now,

35
00:01:27,480 --> 00:01:31,260
pretty much they came forward yesterday at the time of recording and said that hackers

36
00:01:31,680 --> 00:01:35,900
obtained at least a dozen encrypted vaults used for storing customer passwords during

37
00:01:35,920 --> 00:01:36,960
a week in cyber attack.

38
00:01:37,300 --> 00:01:42,500
Now, if you're newer to the concept of password managers, the idea is you have a vault that

39
00:01:42,500 --> 00:01:44,540
is synced over the cloud with all of your passwords.

40
00:01:45,320 --> 00:01:46,000
But ideally,

41
00:01:46,700 --> 00:01:49,480
everything you do in that vault is encrypted on your device before it touches

42
00:01:49,520 --> 00:01:50,000
their servers.

43
00:01:50,240 --> 00:01:52,740
and so they can't actually see inside of the vault.

44
00:01:53,030 --> 00:01:55,740
Now, before we get into the repercussions of this

45
00:01:55,860 --> 00:01:56,540
and what it means,

46
00:01:56,950 --> 00:01:59,840
just to target what might have happened first,

47
00:02:00,080 --> 00:02:01,200
Dashlane came forward and said

48
00:02:01,200 --> 00:02:03,360
there was no evidence of compromise on its own systems,

49
00:02:03,880 --> 00:02:05,400
but it has not yet said how the hackers

50
00:02:05,580 --> 00:02:07,440
were able to defeat its two-factor protections

51
00:02:07,840 --> 00:02:09,399
in order to access customer accounts.

52
00:02:09,640 --> 00:02:12,320
You can read their original announcement if you want to,

53
00:02:12,500 --> 00:02:14,400
but it is very light on details.

54
00:02:14,700 --> 00:02:16,520
They say that they brute-forced

55
00:02:16,550 --> 00:02:18,800
the company's two-factor authentication system,

56
00:02:19,180 --> 00:02:22,420
and it granted the hackers access to about 20 customer accounts.

57
00:02:22,590 --> 00:02:25,760
So then they were able to download a copy of their encrypted vaults.

58
00:02:25,960 --> 00:02:29,240
They did say they've taken steps to mitigate the risk of future incidents.

59
00:02:29,920 --> 00:02:31,660
And like TechCrunch says here in the article,

60
00:02:31,860 --> 00:02:33,500
without saying what those were.

61
00:02:33,940 --> 00:02:35,360
The spokespeople for Dashlane,

62
00:02:35,530 --> 00:02:36,160
as of yesterday,

63
00:02:36,320 --> 00:02:37,940
did not respond to a request for comment.

64
00:02:38,260 --> 00:02:40,880
They did not say if it knows who targeted its customers

65
00:02:41,050 --> 00:02:43,920
or if the hackers contacted Dashlane with demands like a ransom.

66
00:02:44,320 --> 00:02:48,100
Now, there's an Ars Technica article that came out today with a few more details.

67
00:02:48,520 --> 00:02:53,860
And when I say few, I'm being a little bit generous there because there's still a lot that's not really clear.

68
00:02:54,280 --> 00:02:58,820
Now, the reason why there's confusion is because Dashlane isn't being very specific on what's going on.

69
00:02:58,950 --> 00:03:01,400
Pretty much the Ars Technica article speculates,

70
00:03:01,640 --> 00:03:01,860
you know,

71
00:03:02,090 --> 00:03:05,100
are they trying to brute force the accounts directly by trying different codes?

72
00:03:05,350 --> 00:03:07,220
Are they trying to do something called 2FA fatigue?

73
00:03:07,780 --> 00:03:09,700
When you spam somebody over and over,

74
00:03:09,920 --> 00:03:12,440
eventually they click approve and let the attacker in anyway.

75
00:03:12,800 --> 00:03:18,200
But it's also plausible that the attack exploited features that allow Dashlane users to enroll new devices in their accounts.

76
00:03:18,620 --> 00:03:21,280
pretty much we have no idea why there were all these prompts.

77
00:03:21,460 --> 00:03:23,000
These are just small little nuggets

78
00:03:23,200 --> 00:03:24,300
of information we have,

79
00:03:24,680 --> 00:03:26,820
and everything beyond that is a bit of speculation.

80
00:03:27,180 --> 00:03:28,240
Now, there are a few things

81
00:03:28,340 --> 00:03:34,540
that are confirmed that I think we can already start to form reasonable kind of takeaways about.

82
00:03:35,020 --> 00:03:35,840
So the first thing,

83
00:03:36,060 --> 00:03:38,620
you know, a lot of people are going to point to, and I know Dashlane is going to

84
00:03:38,740 --> 00:03:40,960
point to the fact, especially in marketing and PR,

85
00:03:41,580 --> 00:03:43,460
that these were encrypted vaults. Now,

86
00:03:43,880 --> 00:03:44,340
this is a

87
00:03:44,320 --> 00:03:44,740
good step,

88
00:03:44,960 --> 00:03:47,620
right? We saw this sort of as well with LastPass,

89
00:03:47,780 --> 00:03:49,360
where at least the most sensitive data

90
00:03:49,920 --> 00:03:51,440
was, you know, part of an encrypted vault.

91
00:03:51,640 --> 00:03:53,540
But what we learned is because of the security of

92
00:03:53,540 --> 00:03:57,320
their master password and the amount of iterations required to break into the vault, all this

93
00:03:57,560 --> 00:04:02,040
technical stuff, especially in combination with people using weak master passwords,

94
00:04:02,240 --> 00:04:02,980
we have seen

95
00:04:03,320 --> 00:04:07,320
millions of dollars that have been drained in things like cryptocurrencies tied to the LastPass

96
00:04:07,480 --> 00:04:07,840
data breach,

97
00:04:08,150 --> 00:04:10,400
all because originally encrypted vaults were taken.

98
00:04:10,840 --> 00:04:12,380
But to this day, there are

99
00:04:12,360 --> 00:04:15,660
people who are still trying to break into those vaults computationally.

100
00:04:15,910 --> 00:04:16,980
And so that is my concern

101
00:04:17,030 --> 00:04:17,940
with this one as well.

102
00:04:18,380 --> 00:04:19,540
Yes, hackers stole, let's say,

103
00:04:19,780 --> 00:04:21,620
20 encrypted vaults,

104
00:04:22,060 --> 00:04:22,700
but now they can start

105
00:04:22,850 --> 00:04:24,840
hitting that starting today and people with really,

106
00:04:25,020 --> 00:04:27,340
really weak master passwords may be at risk.

107
00:04:27,520 --> 00:04:27,780
So

108
00:04:28,200 --> 00:04:33,240
no matter what password manager you're using, this is a good takeaway for you to make sure your master

109
00:04:33,380 --> 00:04:35,920
password is as strong as it could possibly be.

110
00:04:36,160 --> 00:04:38,280
Now, I think the second very clear takeaway that

111
00:04:38,300 --> 00:04:41,440
is not polarizing is that Dashlane needs to step the hell up.

112
00:04:41,940 --> 00:04:43,860
If they want in any way to retain

113
00:04:43,980 --> 00:04:48,720
their reputation as being a trusted password manager, which is probably the most sensitive

114
00:04:48,860 --> 00:04:50,960
piece of software anybody can use.

115
00:04:51,120 --> 00:04:54,120
This is people's access to literally their life,

116
00:04:54,520 --> 00:04:55,320
everything in their life.

117
00:04:56,080 --> 00:04:58,520
Dashlane needs to step the hell up or else they're going to end up like

118
00:04:58,640 --> 00:05:02,780
LastPass and be a literal laughingstock of the password manager industry, which is a bummer because

119
00:05:02,800 --> 00:05:08,040
I think Dashlane has actually tried to really fix their reputation in the last several years.

120
00:05:08,520 --> 00:05:11,840
So I would love to see Dashleen step forward and at least say,

121
00:05:12,000 --> 00:05:12,060
hey,

122
00:05:12,310 --> 00:05:14,440
we don't know what's going on yet. We're doing investigations.

123
00:05:14,720 --> 00:05:15,560
Here's what we do know.

124
00:05:16,000 --> 00:05:16,740
And instead,

125
00:05:16,900 --> 00:05:18,320
they're kind of just ignoring everything.

126
00:05:18,850 --> 00:05:20,900
My optimistic side is saying,

127
00:05:21,060 --> 00:05:21,200
hey,

128
00:05:21,420 --> 00:05:27,280
you know, there's a lot going on. They probably need to investigate what's going on. It's going to take them a few days. They want to make sure they get all the details right.

129
00:05:27,600 --> 00:05:28,980
All those things can be true,

130
00:05:29,620 --> 00:05:31,940
but I still think even with that optimistic lens,

131
00:05:32,360 --> 00:05:41,560
there's no reason they can't be reaching out to people who are legitimately concerned about this if they're dashling customers and letting those customers know directly what they're doing,

132
00:05:41,800 --> 00:05:43,820
not just saying generic,

133
00:05:44,160 --> 00:05:47,920
vague stuff that doesn't really mean anything that's leaving everybody to have to guess what's going on.

134
00:05:47,920 --> 00:05:49,460
I think this is the worst case scenario.

135
00:05:49,760 --> 00:05:51,920
These are always quite juicy stories,

136
00:05:52,080 --> 00:05:54,100
and we see a lot develop really quickly.

137
00:05:54,620 --> 00:05:57,460
And so I'm watching this quite closely, so make sure to stay subscribed.

138
00:05:57,660 --> 00:05:59,260
I'm sure we'll have more updates on this one.

139
00:05:59,360 --> 00:06:00,400
It's a pretty big story,

140
00:06:00,880 --> 00:06:02,440
and I know it always gets people concerned

141
00:06:02,540 --> 00:06:04,700
when there's a new password manager data breach.

142
00:06:11,120 --> 00:06:12,820
All right, coming soon, we still have Europe,

143
00:06:13,040 --> 00:06:16,560
who's trying to pull away from U.S. big tech with some really interesting initiatives.

144
00:06:17,020 --> 00:06:19,740
We have hackers who hijacked Instagram celebrity accounts

145
00:06:19,840 --> 00:06:22,820
by just asking AI to do it, and it said sure.

146
00:06:23,480 --> 00:06:27,140
But before we get there, we have this really interesting story.

147
00:06:27,260 --> 00:06:30,060
So before I even touch on the story directly,

148
00:06:30,220 --> 00:06:31,400
a little bit of context.

149
00:06:31,960 --> 00:06:36,180
And this is a recurring pattern in the privacy digital rights space,

150
00:06:36,340 --> 00:06:40,900
which is you can't only give good things to good people.

151
00:06:41,180 --> 00:06:43,120
We need to make things universal,

152
00:06:43,620 --> 00:06:47,080
and that is just the reality of how this all works.

153
00:06:47,400 --> 00:06:50,060
If we want people to have access to encryption,

154
00:06:50,320 --> 00:06:52,020
everybody needs access to encryption.

155
00:06:52,540 --> 00:06:53,700
So if we want law enforcement,

156
00:06:53,960 --> 00:06:55,020
if we want military,

157
00:06:55,320 --> 00:06:57,480
etc., to have access to encryption,

158
00:06:57,870 --> 00:07:01,700
that also means regular people like you and I should also have access to encryption.

159
00:07:02,180 --> 00:07:05,580
This is something that I like to consider, oh, a basic human right, right?

160
00:07:05,610 --> 00:07:07,280
We think privacy is a basic human right.

161
00:07:07,640 --> 00:07:11,680
Access to security can in some ways be justified as a basic human right.

162
00:07:11,870 --> 00:07:14,480
And I would say digital rights are human rights,

163
00:07:14,720 --> 00:07:14,840
right?

164
00:07:15,220 --> 00:07:17,680
Now, a lot of times those in power like to fight this narrative.

165
00:07:17,980 --> 00:07:22,160
But then we have these fun moments where it actually switches and we actually can say,

166
00:07:22,400 --> 00:07:22,720
You see,

167
00:07:22,900 --> 00:07:27,340
look what happens when you don't take these problems seriously and it actually ends up impacting you.

168
00:07:28,020 --> 00:07:30,460
We had the Salt Typhoon hacks not too long ago,

169
00:07:30,860 --> 00:07:33,340
which pretty much was created because of a backdoor.

170
00:07:33,500 --> 00:07:40,000
Those same backdoors that they're trying to implement into everybody's messages and everybody's web traffic all around the world right now.

171
00:07:40,320 --> 00:07:42,040
People seem to be proposing backdoors,

172
00:07:42,300 --> 00:07:49,200
but then we see the big guys who have a backdoor and it gets exploited and they deal with one of the worst hacks ever.

173
00:07:49,980 --> 00:07:55,640
And now we continue this trend because U.S. troops were targeted with location data.

174
00:07:56,110 --> 00:08:00,340
Now, this came from Senator Ron Wyden, who has a history of covering a lot of these privacy-based

175
00:08:00,690 --> 00:08:00,820
problems.

176
00:08:01,660 --> 00:08:05,700
And he pretty much said that the U.S. Department of Defense has confirmed that adversaries

177
00:08:05,710 --> 00:08:10,900
have targeted and surveilled serving military personnel on the battlefield using commercial

178
00:08:11,120 --> 00:08:11,760
location data,

179
00:08:12,280 --> 00:08:15,500
the latest demonstration of how information collected from phones and

180
00:08:15,640 --> 00:08:18,260
computers can be abused to track and target individuals.

181
00:08:18,700 --> 00:08:21,220
We talk about this a lot on the podcast.

182
00:08:21,650 --> 00:08:22,600
Pretty much law enforcement,

183
00:08:22,780 --> 00:08:23,200
the FBI,

184
00:08:23,380 --> 00:08:26,040
and other government agencies in the U.S., they need

185
00:08:26,180 --> 00:08:29,940
to normally get a warrant to just, you know, access information about you.

186
00:08:29,950 --> 00:08:33,539
There needs to be a reasonable cause to have to investigate people.

187
00:08:33,919 --> 00:08:36,180
They need a judge to say that makes sense.

188
00:08:36,500 --> 00:08:38,039
Now you can go ahead and pursue them.

189
00:08:38,520 --> 00:08:40,120
I don't think many people who listen to this podcast,

190
00:08:40,400 --> 00:08:40,760
nor myself,

191
00:08:41,180 --> 00:08:42,680
think that law enforcement

192
00:08:42,940 --> 00:08:45,460
shouldn't be allowed to pursue people that they think are doing something wrong.

193
00:08:45,660 --> 00:08:48,340
But there should be some layer of accountability.

194
00:08:49,000 --> 00:08:53,200
Typically, they have to get a warrant to search things like your house or anything in your physical life.

195
00:08:53,290 --> 00:08:56,280
They can't just walk all over you without a judge saying that's okay.

196
00:08:56,960 --> 00:09:02,360
Now, the problem with the digital space is that even though those laws technically are kind of supposed to exist,

197
00:09:03,180 --> 00:09:06,980
they just get around them by purchasing data from other people who collected it legally.

198
00:09:07,420 --> 00:09:10,580
Because there is no privacy regulation in the U.S.

199
00:09:10,820 --> 00:09:11,260
especially,

200
00:09:11,660 --> 00:09:14,900
What happens is you download an app for a calculator,

201
00:09:15,140 --> 00:09:15,580
Duolingo,

202
00:09:15,880 --> 00:09:16,380
whatever.

203
00:09:16,680 --> 00:09:18,000
I'm just using random apps.

204
00:09:18,000 --> 00:09:21,640
I'm not saying these specific apps do this, but pretty much any app you download from the

205
00:09:21,640 --> 00:09:25,480
app store probably comes with third-party trackers and SDKs inside of that app.

206
00:09:25,500 --> 00:09:29,680
And what happens is that these actually secretly collect lots of data on your phones and your

207
00:09:29,780 --> 00:09:30,080
devices.

208
00:09:30,520 --> 00:09:32,520
It sends it to these weird industries,

209
00:09:32,820 --> 00:09:35,580
and these industries collect all of this data

210
00:09:35,940 --> 00:09:38,040
about you, this massive surveillance economy.

211
00:09:38,500 --> 00:09:40,640
And then the FBI and law enforcement,

212
00:09:40,810 --> 00:09:43,360
because they can't get data about individuals without a warrant,

213
00:09:43,510 --> 00:09:43,640
say,

214
00:09:43,840 --> 00:09:51,980
you know what, let's just skip the whole process and let's just purchase the data from these data brokers that are actually allowed to collect the data because there's nothing stopping them from collecting that data.

215
00:09:52,440 --> 00:09:53,520
So for years,

216
00:09:53,780 --> 00:09:59,560
all of us have been screaming that this needs to be fixed. This is a massive loophole,

217
00:10:00,000 --> 00:10:01,500
not only for basic democracy,

218
00:10:01,780 --> 00:10:02,300
but why?

219
00:10:02,800 --> 00:10:04,100
Why would anybody want this?

220
00:10:04,260 --> 00:10:13,160
Why is it okay for when you download an app for now everywhere you go throughout your life to be sent to some random data brokers who don't care about you or your privacy or your safety?

221
00:10:13,380 --> 00:10:16,820
And then from there, they can just give it to anyone who wants to pay them for it.

222
00:10:16,860 --> 00:10:17,860
That's pretty messed up.

223
00:10:18,140 --> 00:10:19,600
Politicians have ignored this problem.

224
00:10:19,960 --> 00:10:21,100
And you know what? Politicians

225
00:10:21,260 --> 00:10:24,440
themselves are now starting to finally deal with these consequences.

226
00:10:24,920 --> 00:10:26,200
The reality is that the

227
00:10:26,420 --> 00:10:32,120
Minnesota assassin who assassinated those politicians in Minnesota found their addresses

228
00:10:32,440 --> 00:10:35,220
from people searching websites that were free and accessible.

229
00:10:35,560 --> 00:10:37,800
It was on his notepad, and it's how he

230
00:10:38,040 --> 00:10:38,780
found those people.

231
00:10:39,120 --> 00:10:42,240
So I finally get to my point I'm trying to make here, which is we have this

232
00:10:42,260 --> 00:10:47,280
history of things just impacting us mere mortals who just want to live and exist and not be

233
00:10:47,620 --> 00:10:47,820
exploited.

234
00:10:48,220 --> 00:10:50,200
But now it's starting to hit those in power too.

235
00:10:50,480 --> 00:10:51,660
It hit politicians,

236
00:10:51,900 --> 00:10:52,760
it hit people like

237
00:10:52,840 --> 00:10:54,780
cellular companies as part of Salt Typhoon,

238
00:10:55,020 --> 00:10:56,720
and now it's hitting military personnel.

239
00:10:56,960 --> 00:10:57,100
Because

240
00:10:57,420 --> 00:10:59,200
military personnel are not immune to this problem,

241
00:10:59,380 --> 00:11:00,920
they're not able to opt out either.

242
00:11:01,100 --> 00:11:02,020
The reality is

243
00:11:02,200 --> 00:11:09,179
nobody is probably reasonably able to 100% opt out of this system because no one actually cares about

244
00:11:09,200 --> 00:11:10,540
dealing with the root system.

245
00:11:10,920 --> 00:11:13,920
So I wanted to shed light on this story because to me,

246
00:11:14,100 --> 00:11:20,040
it's a demonstration of how these problems are so out of control now in 2026 that even people that

247
00:11:20,040 --> 00:11:25,200
you think should get exceptions to it, which I don't agree with, but even the people you think

248
00:11:25,540 --> 00:11:28,320
should be exempted from these problems are not.

249
00:11:28,540 --> 00:11:29,760
They can't get around them either.

250
00:11:29,980 --> 00:11:30,620
I just really

251
00:11:30,760 --> 00:11:35,020
hope that this wakes people up. I'm really happy that Senator Ron Wyden is calling this out,

252
00:11:35,280 --> 00:11:38,680
and he constantly does these call-outs to try to draw attention to these problems.

253
00:11:38,960 --> 00:11:40,240
I'm really glad there's coverage for this.

254
00:11:40,780 --> 00:11:42,600
And those are at least my two cents on it.

255
00:11:42,860 --> 00:11:44,300
I'd love to hear what you guys think in the comments

256
00:11:44,560 --> 00:11:46,320
because I think this is ridiculous.

257
00:11:46,540 --> 00:11:47,240
It's getting out of control.

258
00:11:47,520 --> 00:11:49,800
Oh, and one more thing I forgot to mention about this story.

259
00:11:50,020 --> 00:11:52,660
Senator Ron Wyden actually called this whole location

260
00:11:53,400 --> 00:11:56,200
data tracking industry slash the whole data broker industry

261
00:11:56,400 --> 00:11:57,600
a national security threat.

262
00:11:57,740 --> 00:11:59,380
And for the first time in a long time,

263
00:11:59,900 --> 00:12:01,520
I actually agree with how that word is utilized.

264
00:12:02,000 --> 00:12:03,640
For context, we have platforms like TikTok

265
00:12:03,940 --> 00:12:05,740
that have been called a national security threat

266
00:12:05,900 --> 00:12:08,820
because they collect sensitive data and send it to China.

267
00:12:09,320 --> 00:12:11,420
But really what that was, in my view,

268
00:12:11,680 --> 00:12:15,080
is it's China that had a platform that was used by almost every American.

269
00:12:15,490 --> 00:12:18,680
And that was a huge power shift towards China big tech companies.

270
00:12:19,430 --> 00:12:20,860
But we don't care if Meta,

271
00:12:21,040 --> 00:12:21,500
if Google,

272
00:12:21,800 --> 00:12:24,720
if Facebook or Facebook is Meta, but you guys get what I'm saying.

273
00:12:24,990 --> 00:12:27,440
We don't care if US big tech companies collect that data.

274
00:12:27,920 --> 00:12:31,620
And I think that this is really more proof to that sentiment that I have,

275
00:12:31,780 --> 00:12:37,440
which is these data brokers that collect all this data and then they might sell it to Chinese companies anyway.

276
00:12:37,920 --> 00:12:39,880
Why is that not a national security risk?

277
00:12:40,120 --> 00:12:47,280
So I think that this word national security risk is being thrown around a lot in the digital space, but it's being used to justify really crappy things.

278
00:12:47,560 --> 00:12:55,800
And I actually really appreciate how Senator Ron Wyden used this specific threat as a truly genuine national security threat, which I think it is.

279
00:12:55,900 --> 00:12:58,860
All right, coming soon, we have a lot of European updates,

280
00:12:59,020 --> 00:13:05,520
and we also have Meta, who did something crazy with their AI agents that just granted people access to other people's accounts.

281
00:13:06,080 --> 00:13:10,880
Ridiculous, but nothing we wouldn't expect from Meta. But I quickly wanted to shout out our sponsor first,

282
00:13:11,140 --> 00:13:15,440
which today is Easy Opt-Out. If you haven't heard of Easy Opt-Out before,

283
00:13:15,620 --> 00:13:19,820
they are an automated service that tries to remove your information from people searching websites.

284
00:13:20,100 --> 00:13:22,720
It's actually quite related to that story that we just talked about.

285
00:13:22,880 --> 00:13:25,980
There's two main methods to remove your information from these people search websites.

286
00:13:26,260 --> 00:13:27,920
There's the manual one, which works very well,

287
00:13:28,100 --> 00:13:29,700
but you have to continually do it yourself.

288
00:13:30,220 --> 00:13:31,700
And it isn't just a one-time thing.

289
00:13:31,760 --> 00:13:32,960
You have to always do the maintenance,

290
00:13:33,500 --> 00:13:36,500
or you can just pay for an automated service to take care of it for you.

291
00:13:36,720 --> 00:13:38,680
And that's personally what I like to do as well.

292
00:13:38,800 --> 00:13:41,220
Because it's only $20 a year, it does the opt-outs for me.

293
00:13:41,340 --> 00:13:42,360
I don't have to think about it.

294
00:13:42,380 --> 00:13:46,840
I just get an email every few months that says they opted me out, and then I kind of just move on with my life.

295
00:13:46,960 --> 00:13:50,640
It's just run by a couple guys who realized that they could offer the same service for a lot cheaper.

296
00:13:51,060 --> 00:13:53,360
They were verified by Consumer Reports Independent Research,

297
00:13:53,720 --> 00:13:55,220
and they actually tied with Optory

298
00:13:55,580 --> 00:13:57,180
in terms of the best kind of performance,

299
00:13:57,440 --> 00:13:59,240
but Optory has a much higher price tag.

300
00:13:59,680 --> 00:14:02,720
And a lot of people in our community actually like combining the two tools.

301
00:14:02,900 --> 00:14:07,060
They use free Optory to scan to see which sites they're on, and then they just have easy

302
00:14:07,280 --> 00:14:09,500
opt-outs do the removals, and then they can compare the difference.

303
00:14:09,980 --> 00:14:12,040
When people in my life find their name, their home addresses,

304
00:14:12,280 --> 00:14:13,360
and information about themselves

305
00:14:13,500 --> 00:14:15,640
and their family online on these people-searching websites,

306
00:14:15,860 --> 00:14:17,280
and they ask me what to do about it,

307
00:14:17,360 --> 00:14:19,120
I just tell them to go with easy opt-outs.

308
00:14:19,280 --> 00:14:23,540
That is the number one recommendation I have, and it's who I still personally use to this day.

309
00:14:23,630 --> 00:14:26,240
I want to thank Easy Optouts for all of their support over the years.

310
00:14:26,330 --> 00:14:27,900
We couldn't do this podcast without them.

311
00:14:28,190 --> 00:14:30,880
So go check them out down in the description if you want to get started today.

312
00:14:31,440 --> 00:14:33,480
And now let's go back into the stories.

313
00:14:39,740 --> 00:14:41,300
All right, so now we're going to talk about Europe.

314
00:14:41,430 --> 00:14:43,800
And we have two core stories that are quite different,

315
00:14:44,160 --> 00:14:48,200
but the first story has a ton of stories within it, and it has to do with the Euro office.

316
00:14:48,580 --> 00:14:53,460
The idea is that Microsoft Office is a centralized big tech company,

317
00:14:54,500 --> 00:14:55,580
in addition to all these

318
00:14:55,650 --> 00:14:58,980
other ecosystems that exist as Microsoft Office alternatives,

319
00:14:59,180 --> 00:15:01,100
also being from big tech companies.

320
00:15:01,660 --> 00:15:04,440
Many of those big tech companies happen to be US-based.

321
00:15:05,140 --> 00:15:08,420
And so as you can tell, there's a bit of a geopolitical angle to this as well.

322
00:15:08,450 --> 00:15:11,600
But pretty much Europe has come forward and said, we don't want big tech companies running

323
00:15:11,690 --> 00:15:12,540
our entire tech stack,

324
00:15:12,840 --> 00:15:14,440
especially from a government perspective.

325
00:15:15,000 --> 00:15:15,540
But also,

326
00:15:15,990 --> 00:15:22,040
we don't really want all of our businesses and all the things that are happening in Europe to be running through U.S. big tech companies.

327
00:15:22,480 --> 00:15:23,700
I'm sure this is a privacy thing.

328
00:15:23,820 --> 00:15:24,940
It's a digital sovereignty thing.

329
00:15:24,940 --> 00:15:26,880
They want data to be flowing through their own channels.

330
00:15:27,170 --> 00:15:30,080
The idea behind EuroOffice is exactly what it sounds like.

331
00:15:30,300 --> 00:15:34,780
They are coming forward and saying we want a European-based alternative to Microsoft,

332
00:15:35,080 --> 00:15:35,320
Google,

333
00:15:35,660 --> 00:15:36,020
big tech,

334
00:15:36,440 --> 00:15:36,580
etc.

335
00:15:36,900 --> 00:15:41,780
Now, the people who are making this happen is essentially a collaboration between tons of different projects.

336
00:15:42,100 --> 00:15:46,940
I'm not even going to get into the whole drama because there was a ton of drama around OnlyOffice

337
00:15:47,100 --> 00:15:50,420
because OnlyOffice has a license that they didn't agree with.

338
00:15:51,080 --> 00:15:52,560
I'm just, I'm not going to get into it.

339
00:15:52,780 --> 00:15:53,700
I'm about to explain it.

340
00:15:54,080 --> 00:15:57,480
I'm not going to explain it because I'm just not going to get into it.

341
00:15:57,540 --> 00:16:01,660
If you care about reading about licenses and open source drama, you can do that.

342
00:16:01,960 --> 00:16:03,500
All those resources exist online.

343
00:16:03,720 --> 00:16:05,660
So I'm at least making you aware of them.

344
00:16:05,920 --> 00:16:06,640
So if adopted,

345
00:16:06,860 --> 00:16:10,259
the package will direct money towards products that contribute to Europe's

346
00:16:10,280 --> 00:16:10,500
economy,

347
00:16:10,800 --> 00:16:12,500
and independence from foreign firms,

348
00:16:12,680 --> 00:16:14,440
cut red tape for data transfers,

349
00:16:14,940 --> 00:16:15,920
beef up research and

350
00:16:16,230 --> 00:16:17,560
innovation through leadership initiatives,

351
00:16:17,740 --> 00:16:19,600
incentivize countries to share digital capacities

352
00:16:19,690 --> 00:16:20,980
in new Euro Cloud Forum,

353
00:16:21,410 --> 00:16:24,760
and require EU governments to come up with national strategies to boost the

354
00:16:24,900 --> 00:16:26,160
adoption of cutting-edge tech,

355
00:16:26,480 --> 00:16:27,060
including AI.

356
00:16:27,360 --> 00:16:29,880
The package will also seek to ramp up the bloc's

357
00:16:29,910 --> 00:16:31,080
demand for advanced chips,

358
00:16:31,350 --> 00:16:34,700
a response to criticism by the industry with a series of industrial

359
00:16:35,000 --> 00:16:37,060
initiatives to revise the 2023 CHIPS law.

360
00:16:37,240 --> 00:16:39,940
The Commission's President Ursula von der Leyen,

361
00:16:40,140 --> 00:16:41,680
I hope I said that correctly, said,

362
00:16:41,690 --> 00:16:45,340
we cannot afford to depend on others for the technologies that keep our hospitals running,

363
00:16:45,650 --> 00:16:46,740
our energy grids stable,

364
00:16:47,000 --> 00:16:47,960
and our services secure.

365
00:16:48,480 --> 00:16:49,800
This is about protecting our citizens,

366
00:16:50,080 --> 00:16:50,840
defending our interests,

367
00:16:51,100 --> 00:16:52,140
and making our own choices.

368
00:16:53,200 --> 00:16:55,980
So yeah, they've replaced Google with French search engine Quant,

369
00:16:56,340 --> 00:16:58,880
which I know a lot of you in the audience actually know about.

370
00:16:59,580 --> 00:17:00,500
We have Nextcloud,

371
00:17:00,700 --> 00:17:03,760
who has pretty much come forward and has embraced this as well.

372
00:17:04,199 --> 00:17:04,959
And then we have Tuda,

373
00:17:05,140 --> 00:17:07,199
the email provider who's also a part of this.

374
00:17:07,560 --> 00:17:09,439
A lot of people might be wondering, Proton.

375
00:17:09,740 --> 00:17:13,319
Now, my understanding is that Proton is Swiss-based,

376
00:17:13,520 --> 00:17:15,300
so they're not technically in the EU.

377
00:17:16,000 --> 00:17:17,560
That's my assumption on why that's happening.

378
00:17:18,339 --> 00:17:20,420
But again, this is all kind of unfolding.

379
00:17:20,600 --> 00:17:22,680
It's kind of hard to make sense of what's going on here.

380
00:17:22,780 --> 00:17:24,420
This is a bit messy to read about,

381
00:17:24,600 --> 00:17:27,560
and I'm kind of waiting for a more formal united front

382
00:17:27,819 --> 00:17:29,680
on this because it seems like day by day,

383
00:17:29,860 --> 00:17:30,960
this is looking a little bit different.

384
00:17:31,340 --> 00:17:32,920
So I'll keep you all updated.

385
00:17:33,200 --> 00:17:34,200
Stay subscribed to the podcast,

386
00:17:34,460 --> 00:17:36,880
and I'll try my best to update you all as more information

387
00:17:37,140 --> 00:17:37,700
comes to light.

388
00:17:38,220 --> 00:17:39,960
All right, now there's a second story from Europe,

389
00:17:40,120 --> 00:17:41,500
which is France-specific.

390
00:17:41,940 --> 00:17:47,320
And this is a French article translated into English, which has, I don't think, any English

391
00:17:47,600 --> 00:17:48,940
article written on the internet about it.

392
00:17:49,140 --> 00:17:50,480
Actually, it's even paywalled.

393
00:17:51,240 --> 00:17:55,840
So I don't have the full primary information, which normally doesn't mean I cover it on

394
00:17:55,840 --> 00:17:56,260
this podcast.

395
00:17:56,860 --> 00:18:01,620
The only reason I'm going to cover it on this podcast with all of those asterisks is because

396
00:18:02,160 --> 00:18:06,580
there's a person named Nelian who's on the podcast called Comfort Zone, and they actually

397
00:18:06,780 --> 00:18:07,640
talked about this problem.

398
00:18:07,960 --> 00:18:11,120
And I have a lot of trust in how they communicated the problem.

399
00:18:11,720 --> 00:18:14,340
And so I'm going to relay more or less what they shared.

400
00:18:14,450 --> 00:18:17,640
And so if anything is wrong, blame them.

401
00:18:18,220 --> 00:18:19,700
But pretty much.

402
00:18:19,810 --> 00:18:20,800
So a bit of context.

403
00:18:20,870 --> 00:18:25,860
We talked recently about how RCS is now getting end-to-end encryption between iOS and Android devices.

404
00:18:26,320 --> 00:18:32,000
This means that those green messages between iOS and Android can now be supported with end-to-end encryption.

405
00:18:32,360 --> 00:18:35,440
It's not going to have signal level protections on metadata or anything like that.

406
00:18:35,580 --> 00:18:38,960
But this is huge for keeping out just basic people from your messages.

407
00:18:39,680 --> 00:18:39,760
Now,

408
00:18:40,340 --> 00:18:41,300
the technology is there.

409
00:18:41,420 --> 00:18:42,160
It's fully supported.

410
00:18:42,360 --> 00:18:43,620
It's available in tons of countries.

411
00:18:43,760 --> 00:18:45,320
I think it's still technically in beta,

412
00:18:45,800 --> 00:18:46,340
but this works.

413
00:18:47,180 --> 00:18:47,920
But not in France.

414
00:18:48,400 --> 00:18:48,800
So,

415
00:18:49,420 --> 00:18:50,540
Neil Leon in the podcast,

416
00:18:50,820 --> 00:18:51,180
not me,

417
00:18:51,380 --> 00:18:53,900
I believe what this article goes on to claim,

418
00:18:55,200 --> 00:18:57,200
but I have to relay through what I heard,

419
00:18:57,680 --> 00:19:00,200
was that the technology is actually fully there

420
00:19:00,360 --> 00:19:02,000
and embraced by cellular companies,

421
00:19:02,420 --> 00:19:05,080
or at least it's possible to be embraced by the cellular companies in France,

422
00:19:05,420 --> 00:19:07,680
But they aren't doing it because of government pressure.

423
00:19:08,040 --> 00:19:16,740
And this is another weird political situation because apparently there are some cell carriers in France right now that want to do certain mergers and they want to stay on the good side of the government.

424
00:19:17,060 --> 00:19:27,140
But the government doesn't really want RCS to be rolled out yet because they still want to continue looking at everybody's messages via SMS without end-to-end encryption.

425
00:19:27,720 --> 00:19:35,040
So we have this really interesting dynamic in France right now where we have politics getting in the way of basic security going out to every single French citizen.

426
00:19:35,140 --> 00:19:37,240
So I wanted to at least put this on your radar.

427
00:19:37,400 --> 00:19:38,980
I'm not even going to add commentary on it yet.

428
00:19:39,140 --> 00:19:41,080
I'm mostly reeling what they said on their podcast.

429
00:19:42,280 --> 00:19:43,960
So at least it puts it on our radar.

430
00:19:44,260 --> 00:19:48,260
And I'll try to update you guys as I learn more about this. And there's more primary sources.

431
00:19:48,720 --> 00:19:52,100
If you are French and you do have better resources to share with me regarding that,

432
00:19:52,420 --> 00:19:56,180
I always appreciate those. A lot of stories actually come from you all who submit them.

433
00:19:56,360 --> 00:19:57,480
So I really appreciate it.

434
00:20:03,280 --> 00:20:03,720
All right,

435
00:20:03,980 --> 00:20:08,480
and now we continue the series of Meta just doing Meta things.

436
00:20:09,260 --> 00:20:10,340
I can't stand Meta.

437
00:20:11,090 --> 00:20:12,060
I can't stand Facebook.

438
00:20:12,270 --> 00:20:13,980
I can't stand Mark Zuckerberg.

439
00:20:14,240 --> 00:20:17,660
So I'm going to do my best not to get too angry at this.

440
00:20:17,960 --> 00:20:19,160
But this is just embarrassing.

441
00:20:19,290 --> 00:20:19,680
I mean,

442
00:20:20,170 --> 00:20:23,500
so Meta has AI support chatbots now.

443
00:20:25,220 --> 00:20:32,220
And apparently hackers literally just asked it for the ability to access different accounts.

444
00:20:32,660 --> 00:20:38,400
This hacked the Barack Obama White House account and the chief master sergeant of Space Force's account.

445
00:20:38,860 --> 00:20:48,500
Literally all the attackers had to do to break into these accounts was they used a VPN to approximately match the location to their target Instagram accounts region.

446
00:20:49,120 --> 00:20:55,980
They began a password reset process and then they asked Meta AI support chatbot to change the email address associated with the account.

447
00:20:56,400 --> 00:20:57,040
That is it.

448
00:20:57,300 --> 00:20:57,700
Now, Henry,

449
00:20:57,900 --> 00:21:00,380
luckily this wasn't available to the public for very long.

450
00:21:00,560 --> 00:21:00,660
Oh,

451
00:21:00,920 --> 00:21:01,940
no, you're wrong about that.

452
00:21:02,100 --> 00:21:03,800
It was active in the wild for months,

453
00:21:04,000 --> 00:21:06,420
going as far back as February of this year with

454
00:21:06,560 --> 00:21:09,180
hackers compromising thousands of accounts.

455
00:21:09,650 --> 00:21:13,600
The only difference is that they finally compromised high profile accounts.

456
00:21:13,670 --> 00:21:16,060
So people actually figured out what was going on.

457
00:21:16,200 --> 00:21:20,780
This is the same company that's trying to install, you know, tracking software on all

458
00:21:20,780 --> 00:21:21,360
their employees'

459
00:21:21,760 --> 00:21:22,020
cursors.

460
00:21:22,240 --> 00:21:25,400
This is the same person who doesn't want their own children on their platforms.

461
00:21:25,760 --> 00:21:28,640
Mark Zuckerberg doesn't let his children go on these platforms.

462
00:21:29,180 --> 00:21:34,360
This is the same platform that's been investing heavily in trying to duplicate their CEO as an AI clone.

463
00:21:34,500 --> 00:21:37,140
This is the same company that tried that whole metaverse thing.

464
00:21:37,140 --> 00:21:48,860
This is the same company that is coming forward and trying to get everybody to use meta Ray-Bans so that they can start enabling facial recognition software and be able to easily find people all around them.

465
00:21:49,660 --> 00:21:55,100
It's unbelievable just how freaking dystopian this company tries to be, like,

466
00:21:55,380 --> 00:21:55,760
intentionally.

467
00:21:57,160 --> 00:21:58,400
I cannot stand them.

468
00:21:58,500 --> 00:21:58,620
Now,

469
00:21:59,100 --> 00:21:59,260
you know,

470
00:21:59,460 --> 00:22:00,660
get away from that.

471
00:22:00,820 --> 00:22:02,940
Pretty much some actionable things.

472
00:22:03,100 --> 00:22:03,420
Luckily,

473
00:22:03,600 --> 00:22:08,100
people who had stronger MFA methods enabled weren't actually impacted by this.

474
00:22:08,260 --> 00:22:12,760
So this also means that all these people that were hit by this literally didn't have basic 2FA enabled,

475
00:22:13,020 --> 00:22:15,540
which is also a problem. And that's equally embarrassing,

476
00:22:15,760 --> 00:22:19,560
especially for something as, you know, mainstream as some of these people,

477
00:22:19,760 --> 00:22:19,840
right?

478
00:22:19,940 --> 00:22:24,380
these people you think would have proper security on their social media accounts like Barack Obama

479
00:22:24,620 --> 00:22:25,520
and the Space Force,

480
00:22:25,760 --> 00:22:27,420
you know, Chief Master Sergeant.

481
00:22:27,680 --> 00:22:28,980
I don't know how high that is, but that

482
00:22:29,240 --> 00:22:34,500
sounds high to me. When I zoom out, I just think about all the work that I put into my digital

483
00:22:34,640 --> 00:22:37,120
safety as well as probably a lot of you who listen to this podcast.

484
00:22:37,760 --> 00:22:39,220
And then I remember how much Meta

485
00:22:39,440 --> 00:22:43,560
actually cares about keeping you safe and how they're willing to just throw that away just for

486
00:22:43,920 --> 00:22:44,040
whatever,

487
00:22:44,380 --> 00:22:48,839
whatever they're prioritizing next to try to keep investors interested and not realize

488
00:22:48,860 --> 00:22:51,520
that everything that Meta's done the last 10 years isn't original,

489
00:22:51,740 --> 00:22:52,780
nor does it probably deserve

490
00:22:53,280 --> 00:22:56,760
the massive amount of money that they generate based on just exploiting people.

491
00:22:57,200 --> 00:22:58,160
Those are my

492
00:22:58,320 --> 00:23:00,640
strong opinions that are really leaking here.

493
00:23:00,860 --> 00:23:01,520
I'm getting carried away.

494
00:23:01,720 --> 00:23:02,760
My point that I'm trying to

495
00:23:02,880 --> 00:23:06,960
make here is that we put a lot of effort into this and some people clearly don't. And I think

496
00:23:07,060 --> 00:23:12,400
it's a good reminder that as long as you're doing quite a bit more than maybe what the regular worst

497
00:23:12,600 --> 00:23:13,500
case scenario is doing,

498
00:23:13,900 --> 00:23:16,720
you're probably going to stay pretty far ahead of most of these attacks.

499
00:23:16,920 --> 00:23:20,460
So even if you enabled SMS 2FA or email 2FA,

500
00:23:20,710 --> 00:23:28,380
if you just did some more basic stuff and you maybe weren't trusting Facebook along the way, you're probably going to avoid most privacy and security problems on the internet.

501
00:23:28,430 --> 00:23:33,420
So I think it's always a good reminder that even when we go far and beyond with these things,

502
00:23:33,700 --> 00:23:36,260
a lot of times it's the basics that can really keep us safe.

503
00:23:36,620 --> 00:23:38,620
So I saw this as a good reminder of that.

504
00:23:38,910 --> 00:23:46,660
One final update is that Instagram is actually starting to alert users who were targeted by those hackers during those AI chatbot attacks.

505
00:23:47,260 --> 00:23:52,680
so ideally you're going to be alerted if this hits you and you can see screenshots in the video as

506
00:23:52,800 --> 00:23:57,360
well of what that looks like and you can learn more by checking out the show notes in the description

507
00:24:03,300 --> 00:24:08,380
all right everybody we are now going to get into the defense bulletin this is split up into three

508
00:24:08,600 --> 00:24:12,979
sections the first section is the data breaches we're just going to rip through these and these are

509
00:24:13,420 --> 00:24:13,960
the data breaches.

510
00:24:14,400 --> 00:24:15,420
The next thing is the threats,

511
00:24:15,740 --> 00:24:17,460
which is the things that you should be watching

512
00:24:17,680 --> 00:24:21,320
out for because they could hit you or they maybe already did hit you and what you can do about them.

513
00:24:21,720 --> 00:24:25,000
And then we have the open source updates. To start with data breaches, we have the Carnival

514
00:24:25,360 --> 00:24:25,500
Cruise.

515
00:24:26,020 --> 00:24:28,880
That's confirmed a data breach affecting nearly 6 million people.

516
00:24:29,360 --> 00:24:30,360
And so if you have used

517
00:24:30,540 --> 00:24:31,960
them or you intend to use them,

518
00:24:32,120 --> 00:24:34,600
this is a good thing to look into and you can find more information

519
00:24:34,880 --> 00:24:35,680
in the show notes.

520
00:24:36,000 --> 00:24:39,719
We also have Charter Communications that had a data breach affecting

521
00:24:39,740 --> 00:24:44,000
almost 5 million accounts. The thing that kind of upsets me about this is that it actually happened

522
00:24:44,010 --> 00:24:44,780
in early April,

523
00:24:46,020 --> 00:24:48,640
but they only confirmed the breach earlier this week.

524
00:24:49,060 --> 00:24:51,920
So very lame of them to not have

525
00:24:52,140 --> 00:24:55,720
very much discussion about this. And they just started revealing formal details now,

526
00:24:56,340 --> 00:24:57,220
but there

527
00:24:57,280 --> 00:24:58,980
are details now. So you can see if you're affected,

528
00:24:59,310 --> 00:25:00,660
you can learn more in the show notes.

529
00:25:00,940 --> 00:25:01,100
All right,

530
00:25:01,200 --> 00:25:02,880
this next story is just a quick update.

531
00:25:03,120 --> 00:25:04,820
It's not quite a data breach.

532
00:25:05,160 --> 00:25:06,120
It's an update to one,

533
00:25:06,220 --> 00:25:11,340
But California Attorney General is suing 23andMe over that 2023 breach exposing health data.

534
00:25:12,120 --> 00:25:15,560
If you were listening to the podcast back then, it's something we covered extensively,

535
00:25:16,110 --> 00:25:18,100
but they are now trying to hold them a bit more accountable.

536
00:25:18,540 --> 00:25:21,660
I don't want to do too much coverage for it because there's still a lot to be

537
00:25:22,460 --> 00:25:25,260
seen as to what this is going to look like.

538
00:25:25,470 --> 00:25:26,200
But if you stay subscribed,

539
00:25:26,580 --> 00:25:29,140
I'm sure we're going to cover updates once this finally comes to fruition.

540
00:25:29,480 --> 00:25:32,820
All right, this is a wearable health tech startup called UltraHuman.

541
00:25:32,860 --> 00:25:36,400
I have not heard of this company before, but they said that hackers access customers'

542
00:25:36,660 --> 00:25:38,720
wellness data via an internal tool.

543
00:25:39,120 --> 00:25:40,540
And so if you use this tool,

544
00:25:40,700 --> 00:25:42,620
look into this in the show notes.

545
00:25:42,940 --> 00:25:44,120
It's pretty important stuff.

546
00:25:44,500 --> 00:25:49,780
Next up, we have a prison calling service called Paytel, P-A-Y space T-E-L.

547
00:25:50,280 --> 00:25:59,220
And they have finally secured a publicly exposed cloud server that stored hundreds of thousands of driver's licenses and other sensitive information about people who used its service.

548
00:25:59,540 --> 00:26:05,660
This is really geared towards devices in prisons across much of the U.S. for inmates to receive calls.

549
00:26:05,900 --> 00:26:10,940
I don't know how many of our listeners this directly applies to, but if you know anyone who might have used this service,

550
00:26:11,200 --> 00:26:14,280
I suppose that's something to dig into if you want to learn more.

551
00:26:14,560 --> 00:26:15,600
This one was fascinating.

552
00:26:15,760 --> 00:26:20,860
So Grand Theft Auto V has a cheat service that got hacked exposing thousands of gamers.

553
00:26:21,120 --> 00:26:22,460
So it's called Atlas Menu.

554
00:26:23,060 --> 00:26:25,420
And if you think I know what the hell any of this is,

555
00:26:26,480 --> 00:26:28,760
that would be quite an assumption on your end

556
00:26:28,760 --> 00:26:29,940
because I've never heard of these things.

557
00:26:30,340 --> 00:26:32,440
So if you're a pro gamer like me,

558
00:26:33,280 --> 00:26:34,900
you're going to know what Atlas Menu is.

559
00:26:35,160 --> 00:26:36,860
So the stolen data included users'

560
00:26:37,080 --> 00:26:37,580
email addresses,

561
00:26:37,860 --> 00:26:39,120
usernames, scrambled passwords,

562
00:26:39,300 --> 00:26:39,920
IP addresses,

563
00:26:40,140 --> 00:26:40,800
and support tickets.

564
00:26:41,400 --> 00:26:42,940
And that's all on how I've been pwned.

565
00:26:42,940 --> 00:26:44,600
And you can read a lot more about this

566
00:26:44,820 --> 00:26:46,240
and you'll probably learn more from it

567
00:26:46,320 --> 00:26:48,580
than you will from me in the show notes.

568
00:26:48,900 --> 00:26:49,880
This isn't really a data breach,

569
00:26:50,040 --> 00:26:51,440
but I still wanted to put it on your radar.

570
00:26:51,780 --> 00:26:54,620
just a quick little recap story on TechCrunch.

571
00:26:55,000 --> 00:26:57,860
That's the worst hacks and breaches of 2026 so far.

572
00:26:58,190 --> 00:27:00,240
And it kind of just recaps all the main ones.

573
00:27:01,120 --> 00:27:03,120
I'm not going to get into it too much in this episode.

574
00:27:03,920 --> 00:27:04,600
We don't have enough time,

575
00:27:04,840 --> 00:27:06,520
but I wanted to at least put it on your radar.

576
00:27:06,860 --> 00:27:08,820
All right, now we're going to get into the threats.

577
00:27:08,930 --> 00:27:11,920
These are things that may impact the software you use on a daily basis

578
00:27:12,170 --> 00:27:13,520
that you should be very aware of.

579
00:27:13,800 --> 00:27:15,800
The only thing is we have a lot of stories this week.

580
00:27:15,890 --> 00:27:17,640
And so I do want to go through them pretty quickly

581
00:27:17,840 --> 00:27:19,560
so I don't waste too much of your time.

582
00:27:19,720 --> 00:27:24,020
So the first one is that Google has fixed one actively exploited Android zero-day flaw.

583
00:27:24,460 --> 00:27:28,100
So make sure you're getting up to date and you're still ideally getting software updates

584
00:27:28,270 --> 00:27:31,260
at minimum on your Android devices so you get these kind of patches.

585
00:27:31,720 --> 00:27:34,980
And if you want to learn more about the zero-day, you can check it out in the show notes.

586
00:27:35,360 --> 00:27:39,540
We also have Google Chrome that's adding session cookie theft protection for all users.

587
00:27:40,040 --> 00:27:44,080
Now, this is a very common attack that impacts especially people like YouTubers and people

588
00:27:44,130 --> 00:27:45,000
in public positions,

589
00:27:45,700 --> 00:27:46,300
where essentially,

590
00:27:46,580 --> 00:27:48,960
you know, you have a logged in browser that you're

591
00:27:48,960 --> 00:27:51,140
logged into your YouTube account with, your Twitter,

592
00:27:51,350 --> 00:27:51,500
etc.

593
00:27:51,900 --> 00:27:53,560
And someone hacks your computer and they

594
00:27:53,780 --> 00:27:54,840
steal the cookies from your browser.

595
00:27:55,080 --> 00:27:58,520
Google has rolled something out as a way to cryptographically

596
00:27:58,780 --> 00:28:00,680
bind session cookies to a specific device,

597
00:28:00,910 --> 00:28:02,660
which would prevent hackers from just stealing your

598
00:28:02,750 --> 00:28:02,880
cookies.

599
00:28:03,160 --> 00:28:05,540
This is rolling out to Google Workspace customers,

600
00:28:05,940 --> 00:28:07,240
Workspace individual subscribers,

601
00:28:07,500 --> 00:28:09,220
and users with personal Google accounts.

602
00:28:09,510 --> 00:28:11,560
And it will be enabled by default for all Google

603
00:28:11,720 --> 00:28:12,440
Workspace customers.

604
00:28:13,090 --> 00:28:15,060
This is built into at minimum Chrome.

605
00:28:15,930 --> 00:28:17,560
And I guess it's to be seen,

606
00:28:17,740 --> 00:28:22,100
I haven't heard yet how this applies to other Chromium-based browsers, and so I need to do

607
00:28:22,160 --> 00:28:22,960
more research on this,

608
00:28:23,190 --> 00:28:25,460
and I'll try to report those updates in future episodes.

609
00:28:26,220 --> 00:28:31,260
Acer has confirmed that they are looking to address two maximum severity zero-day vulnerabilities

610
00:28:31,800 --> 00:28:37,420
affecting their Wave 7 mesh routers, and so if you have this router, this is a strong story to

611
00:28:37,590 --> 00:28:39,540
follow to see if you're impacted by this.

612
00:28:40,020 --> 00:28:43,339
There's a service called GOGS, which is a self-hosted

613
00:28:43,360 --> 00:28:43,840
Git service,

614
00:28:44,130 --> 00:28:47,920
and there was a zero-day flaw that let hackers get remote code execution. And so if

615
00:28:47,920 --> 00:28:49,000
you use this service,

616
00:28:49,560 --> 00:28:51,040
definitely look into this story.

617
00:28:51,240 --> 00:28:52,940
There's a new denial-of-service attack

618
00:28:53,380 --> 00:28:56,320
called HTTP2 bomb,

619
00:28:56,580 --> 00:28:59,920
which can be launched from a single machine to take down web servers within

620
00:29:00,600 --> 00:29:01,040
seconds.

621
00:29:01,520 --> 00:29:04,520
The attack is actually quite interesting, and I think it was actually discovered. Yes,

622
00:29:04,610 --> 00:29:07,680
it was discovered by OpenAI's Codex software agent,

623
00:29:07,860 --> 00:29:08,620
which is fascinating.

624
00:29:08,830 --> 00:29:09,220
Now, the really

625
00:29:09,360 --> 00:29:13,320
important thing here is that systems running behind CDNs or reverse proxies do not expose

626
00:29:13,340 --> 00:29:17,380
vulnerable HTTP 2 endpoint and are a lot more difficult to target.

627
00:29:18,310 --> 00:29:18,640
And actually,

628
00:29:18,820 --> 00:29:19,100
this problem

629
00:29:19,220 --> 00:29:22,920
was already fixed in Nginx version 1.29.8.

630
00:29:23,510 --> 00:29:25,200
And if you want to read more about this to see if you

631
00:29:25,300 --> 00:29:27,760
have properly patched it, I would check it out in the show notes.

632
00:29:27,940 --> 00:29:29,020
It's a fascinating attack.

633
00:29:29,460 --> 00:29:33,340
This one is a pretty big story. It almost was a main story this week, but I had some other things

634
00:29:33,370 --> 00:29:35,640
I wanted to focus on a bit more to put on your radar.

635
00:29:35,960 --> 00:29:37,980
But there were dozens of Red Hat packages

636
00:29:38,070 --> 00:29:40,720
that were backdoored through its official NPM channel.

637
00:29:41,260 --> 00:29:41,620
Fortunately,

638
00:29:41,940 --> 00:29:43,300
Red Hat did say they removed

639
00:29:43,320 --> 00:29:44,020
malicious packages.

640
00:29:44,180 --> 00:29:46,940
They said the packages are strictly limited to internal development,

641
00:29:47,340 --> 00:29:52,200
and the malicious code was never published for customer consumption via the console.redhat.com

642
00:29:52,600 --> 00:29:52,740
system.

643
00:29:52,920 --> 00:29:56,600
All right, we have our new weekly tradition of some WordPress plugin attacks.

644
00:29:56,820 --> 00:29:59,600
So the newest one is WPMapsPro,

645
00:30:00,100 --> 00:30:01,040
which is a WordPress plugin,

646
00:30:01,300 --> 00:30:02,740
has a bug that was exploited

647
00:30:02,880 --> 00:30:05,040
to create admin accounts on WordPress websites.

648
00:30:05,240 --> 00:30:07,400
So if you use that plugin, you need to look into this.

649
00:30:07,700 --> 00:30:11,920
And up next, we have the next WordPress plugin, which is a critical kirky flaw,

650
00:30:12,320 --> 00:30:14,960
K-I-R-K-I, kirky.

651
00:30:16,360 --> 00:30:22,600
And there was a critical privilege escalation vulnerability that impacted that plugin so that you could take over any user account,

652
00:30:22,860 --> 00:30:24,440
including those belonging to admins.

653
00:30:24,520 --> 00:30:25,620
So if you use this plugin,

654
00:30:25,780 --> 00:30:27,120
you need to look into that.

655
00:30:27,740 --> 00:30:32,480
WordPress malware also had a campaign that hides payloads in Steam profiles.

656
00:30:33,040 --> 00:30:40,240
So nearly 2,000 WordPress websites were infected with malware that relies on Steam community profile comments to hide command and control data.

657
00:30:40,480 --> 00:30:43,820
You can defend against this by checking for references to Steam community URLs,

658
00:30:44,180 --> 00:30:46,260
suspicious external JavaScript injections,

659
00:30:46,620 --> 00:30:48,900
outbound connections from WordPress service to Steam,

660
00:30:49,440 --> 00:30:53,760
and unexpected scripts loading from domains like hellomyworld.info.

661
00:30:54,060 --> 00:30:55,460
There's other indicators as well.

662
00:30:56,160 --> 00:30:58,600
So if you are a WordPress admin, this is a story to look into.

663
00:30:59,000 --> 00:31:02,180
Okay, there were over 116,000 Minecraft systems

664
00:31:02,700 --> 00:31:04,760
infected in Weed Hack malware campaign.

665
00:31:05,620 --> 00:31:07,300
This is targeting Minecraft players

666
00:31:07,500 --> 00:31:11,220
and has infected more than 116,000 systems since January.

667
00:31:11,840 --> 00:31:14,400
It's distributed through Microsoft-related malicious mods,

668
00:31:14,600 --> 00:31:14,820
clients,

669
00:31:15,100 --> 00:31:15,900
cheats, and utilities

670
00:31:16,140 --> 00:31:19,160
that are promoted all over YouTube and SEO poisoning.

671
00:31:20,040 --> 00:31:21,360
So if you're a Minecraft player,

672
00:31:21,600 --> 00:31:22,360
look into this

673
00:31:22,440 --> 00:31:24,260
because it seems like this impacts a ton of things

674
00:31:24,300 --> 00:31:25,120
in that ecosystem,

675
00:31:25,320 --> 00:31:26,860
and I couldn't even begin to tell you

676
00:31:26,960 --> 00:31:27,960
what some of these things are.

677
00:31:28,360 --> 00:31:29,200
Like Donut Duper,

678
00:31:29,360 --> 00:31:32,580
oh God, if you use Donut Duper, you got to check this out.

679
00:31:32,940 --> 00:31:33,780
I don't know what it is,

680
00:31:34,240 --> 00:31:34,860
but it's in the screenshot.

681
00:31:35,200 --> 00:31:38,640
I'm not going to put too much time into this story as I'm doing for the others,

682
00:31:38,980 --> 00:31:42,640
but this is just a PSA that hackers are trying to steal Signal users'

683
00:31:42,900 --> 00:31:43,060
backups

684
00:31:43,300 --> 00:31:44,820
in a new wave of widespread attacks.

685
00:31:45,060 --> 00:31:46,640
The article covers more about this.

686
00:31:46,680 --> 00:31:49,220
I would really recommend reading it if you are a Signal user,

687
00:31:49,540 --> 00:31:52,360
but if you're not going to read the article and you're a Signal user,

688
00:31:52,900 --> 00:31:55,960
just make sure you're aware that there are phishing attacks on Signal.

689
00:31:56,180 --> 00:32:00,320
Signal has actually recently added a lot more warnings and confirmations to try to combat this

690
00:32:00,620 --> 00:32:00,680
problem.

691
00:32:01,080 --> 00:32:05,760
Another super quick PSA, the FBI's warning of fake FIFA websites running World Cup fraud

692
00:32:05,940 --> 00:32:06,040
schemes.

693
00:32:06,320 --> 00:32:06,380
Again,

694
00:32:06,540 --> 00:32:08,800
this all just falls into the same bucket of phishing attacks.

695
00:32:09,400 --> 00:32:10,300
So these are the

696
00:32:10,680 --> 00:32:14,300
current things that are being targeted to try to trick people into thinking they're on real websites.

697
00:32:14,500 --> 00:32:16,440
So if you're in any way engaging with the World Cup,

698
00:32:16,640 --> 00:32:17,860
just make sure you're accessing official

699
00:32:18,040 --> 00:32:22,060
websites and you can always read more by going to the show notes to see what these attacks actually

700
00:32:22,240 --> 00:32:22,620
look like.

701
00:32:22,840 --> 00:32:25,920
This is another story that we just don't have very much time to cover this week.

702
00:32:26,080 --> 00:32:26,900
There's too many stories.

703
00:32:27,000 --> 00:32:28,460
I think there was over 50 this week,

704
00:32:28,740 --> 00:32:30,940
but websites can now spy on you through your hard drive.

705
00:32:31,520 --> 00:32:34,560
We used to have a research section on surveillance report,

706
00:32:34,760 --> 00:32:37,100
which is the perfect category for stories like this,

707
00:32:37,240 --> 00:32:39,720
which is researchers find a really interesting way

708
00:32:39,940 --> 00:32:43,840
to be able to spy on you in a very weird side channel attack

709
00:32:44,140 --> 00:32:47,800
kind of movie-esque style of tracking people.

710
00:32:48,360 --> 00:32:50,540
But rarely does that really directly translate

711
00:32:50,640 --> 00:32:52,080
into what's possible on the internet.

712
00:32:52,500 --> 00:32:54,600
And that's probably a pretty similar situation here.

713
00:32:54,700 --> 00:33:01,840
Now, there is a full research paper that details this, but it actually does fingerprinting remotely using OFPS-based SSD timing.

714
00:33:02,180 --> 00:33:04,580
So you can read this whole research article if you want.

715
00:33:04,900 --> 00:33:07,540
There's no indications of these being performed in the wild.

716
00:33:07,860 --> 00:33:09,140
And if you are super,

717
00:33:09,360 --> 00:33:09,600
super,

718
00:33:10,000 --> 00:33:15,300
I guess, concerned about this, you pretty much just have to close your tabs when you're done with them.

719
00:33:15,400 --> 00:33:19,760
So this rewards all of you people like me who like to keep their browsers very neat and tidy.

720
00:33:19,860 --> 00:33:21,060
And this is probably the real solution.

721
00:33:21,120 --> 00:33:24,080
They propose ways for browsers to shut down all of these side channels.

722
00:33:24,440 --> 00:33:26,780
So it's very likely if this is a serious enough problem,

723
00:33:27,000 --> 00:33:29,080
browsers are going to patch it before it ever impacts you.

724
00:33:29,300 --> 00:33:30,780
This is another update.

725
00:33:32,020 --> 00:33:34,720
My gosh, this is a person we've been talking about the last several weeks now.

726
00:33:35,020 --> 00:33:35,800
Nightmare Eclipse.

727
00:33:36,270 --> 00:33:42,160
Pretty much Microsoft started making some vague legal threats against Nightmare Eclipse.

728
00:33:42,880 --> 00:33:45,180
And the cybersecurity community has kind of stepped up

729
00:33:45,300 --> 00:33:47,400
and for the most part has backed up Nightmare Eclipse

730
00:33:47,620 --> 00:33:49,740
and is saying that Microsoft is being really unprofessional.

731
00:33:50,220 --> 00:33:53,519
So if you want to learn more about this and learn more about Nightmare Eclipse

732
00:33:53,520 --> 00:33:55,940
and this whole drama between Microsoft and Nightmare Eclipse,

733
00:33:56,480 --> 00:33:56,820
check it out.

734
00:33:57,100 --> 00:34:00,900
I think overall the InfoSec and cybersecurity community is leaning.

735
00:34:01,580 --> 00:34:04,040
I don't know if they necessarily like Nightmare Eclipse,

736
00:34:04,120 --> 00:34:06,740
but they disagree on how Microsoft is approaching all of this.

737
00:34:06,880 --> 00:34:08,460
So check out the show notes if you want to learn more.

738
00:34:08,560 --> 00:34:09,080
All right, everybody.

739
00:34:09,220 --> 00:34:11,879
And now we're going to get into the open source news

740
00:34:12,200 --> 00:34:15,020
where we just cover open source and open source adjacent news.

741
00:34:15,080 --> 00:34:18,980
But I actually think this week we are 100% completely open source.

742
00:34:19,260 --> 00:34:20,879
No debates, no questions asked.

743
00:34:21,320 --> 00:34:25,240
So we're going to start with Tor browser with version 15.0.15,

744
00:34:25,419 --> 00:34:25,899
which was released.

745
00:34:26,080 --> 00:34:28,560
It seems like a pretty, pretty minor update.

746
00:34:28,740 --> 00:34:32,300
It just updated some of the extensions and it fixed a few bugs.

747
00:34:32,500 --> 00:34:35,580
So nothing too serious there, but make sure you get up to date if you're using the Tor

748
00:34:35,740 --> 00:34:35,940
browser.

749
00:34:36,680 --> 00:34:39,419
Mullvad had a security assessment of their Android app.

750
00:34:39,540 --> 00:34:41,520
Mullvad is an open source VPN provider.

751
00:34:41,740 --> 00:34:43,460
They're very well respected in the community.

752
00:34:43,960 --> 00:34:45,460
It's pretty much like an audit.

753
00:34:45,840 --> 00:34:47,740
So you can read the audit and see what they found.

754
00:34:47,960 --> 00:34:49,240
They have an overview of findings.

755
00:34:49,899 --> 00:34:51,639
And it's always good to see audits.

756
00:34:51,639 --> 00:34:55,440
The reason why you want to do audits over time is that audits are a snapshot in time.

757
00:34:55,540 --> 00:34:56,600
And so as of today,

758
00:34:56,820 --> 00:34:58,120
this is what Mullvad might look like.

759
00:34:58,280 --> 00:35:00,880
But starting next week, they're going to start pushing out more code.

760
00:35:00,980 --> 00:35:02,440
And maybe it's not the same thing.

761
00:35:02,480 --> 00:35:07,420
And so it's really cool how providers like Mullvad continually do more audits over time.

762
00:35:07,580 --> 00:35:08,640
This one is really interesting.

763
00:35:08,900 --> 00:35:09,040
Now,

764
00:35:09,260 --> 00:35:11,740
I'm pretty far removed from Gmail.

765
00:35:12,780 --> 00:35:14,880
I've been using Proton for a long time.

766
00:35:15,140 --> 00:35:20,640
So I don't really quite envision exactly how this works, but I think I get the picture.

767
00:35:20,920 --> 00:35:23,160
So Proton released this new feature,

768
00:35:23,480 --> 00:35:28,380
which they're kind of marketing as a way to use Gmail a bit more privately.

769
00:35:29,080 --> 00:35:33,180
So what you can do now is you can connect Gmail into your Proton account.

770
00:35:33,720 --> 00:35:34,820
You connect them.

771
00:35:35,400 --> 00:35:38,300
Connecting your Gmail does not give Google access to your Proton Mail inbox.

772
00:35:38,440 --> 00:35:39,480
They make that very clear.

773
00:35:39,860 --> 00:35:44,480
So this is supposed to be like a transition for people who aren't ready to leave Gmail overnight.

774
00:35:44,640 --> 00:35:47,980
but they want to start using a privacy-first email provider.

775
00:35:48,370 --> 00:35:51,740
So now you can actually send emails from your Gmail address

776
00:35:52,410 --> 00:35:54,500
from directly inside of Proton.

777
00:35:54,800 --> 00:35:56,340
This also includes importing your emails.

778
00:35:56,410 --> 00:35:58,680
The idea here is if you're a Gmail customer,

779
00:35:58,800 --> 00:36:00,020
you've been using Gmail for 10 years,

780
00:36:00,240 --> 00:36:02,240
and you want to start dipping your toes in Proton,

781
00:36:02,300 --> 00:36:03,920
it'll import all of your Gmail emails.

782
00:36:03,950 --> 00:36:08,200
You can even still send emails through your Gmail address from Proton,

783
00:36:08,940 --> 00:36:11,200
but you can kind of start transitioning things slowly.

784
00:36:11,760 --> 00:36:14,099
Really, I think what this is doing is it's making it easier

785
00:36:14,120 --> 00:36:16,280
for people to move to a privacy-first email provider.

786
00:36:16,480 --> 00:36:17,760
And I think they're well aware of that.

787
00:36:17,820 --> 00:36:19,920
They know that if they get people starting to use them,

788
00:36:20,280 --> 00:36:22,280
it's probably likely that they'll move to it

789
00:36:22,540 --> 00:36:23,460
permanently down the road.

790
00:36:23,860 --> 00:36:24,940
I think this is great.

791
00:36:25,260 --> 00:36:26,680
Obviously, it's great for Proton,

792
00:36:26,900 --> 00:36:28,700
but I think really this is great

793
00:36:28,840 --> 00:36:30,100
for just people who are new to this.

794
00:36:30,280 --> 00:36:31,860
I know a lot of people have been using Gmail

795
00:36:32,100 --> 00:36:33,040
for like 10 plus years,

796
00:36:33,420 --> 00:36:34,440
and that is actually the main reason

797
00:36:34,520 --> 00:36:36,360
they never are going to switch to a different provider.

798
00:36:36,480 --> 00:36:38,040
The friction point is just too high.

799
00:36:38,320 --> 00:36:39,700
And so the more that we can reduce

800
00:36:40,000 --> 00:36:40,960
that friction point, the better.

801
00:36:41,460 --> 00:36:43,299
And this is a place where I think I'd love to see

802
00:36:43,340 --> 00:36:48,940
to also be able to step up and offer similar ability for people to quickly migrate from old

803
00:36:49,200 --> 00:36:49,340
services.

804
00:36:49,600 --> 00:36:52,040
I can't say I'm going to use this, and I'm sure a lot of you in our audience probably

805
00:36:52,220 --> 00:36:56,040
won't use this either. But this is a good thing to recommend to friends and family in your life

806
00:36:56,200 --> 00:36:58,180
that are already thinking about maybe leaving Gmail.

807
00:36:58,440 --> 00:37:00,700
Now it's one less reason for them not to

808
00:37:00,700 --> 00:37:00,980
do it.

809
00:37:01,200 --> 00:37:03,920
Now we have just a few more Linux stories here.

810
00:37:04,100 --> 00:37:06,340
Rocky Linux hit version 10.2, which brings

811
00:37:06,520 --> 00:37:09,200
post-quantum cryptography and Flatpak default,

812
00:37:09,500 --> 00:37:10,460
which is really awesome.

813
00:37:10,680 --> 00:37:11,559
And that actually comes

814
00:37:11,580 --> 00:37:13,620
right off of another big update from Rocky Linux

815
00:37:14,280 --> 00:37:16,000
just a few days ago, which was 9.8,

816
00:37:16,200 --> 00:37:17,620
which had major software updates

817
00:37:17,720 --> 00:37:19,000
and a new image builder feature.

818
00:37:19,420 --> 00:37:21,760
OpenSUSE Tumbleweed has updated their desktop environments,

819
00:37:21,980 --> 00:37:22,460
their kernel,

820
00:37:22,780 --> 00:37:24,280
and security fixes as well.

821
00:37:24,330 --> 00:37:26,980
So you can learn more about that in the show notes.

822
00:37:26,990 --> 00:37:30,420
And we also have NixOS that hit version 26.05.

823
00:37:31,160 --> 00:37:32,560
So if you want to learn more about that,

824
00:37:32,820 --> 00:37:35,480
there's also more information about that in the show notes.

825
00:37:35,900 --> 00:37:37,440
And that, my friends, is going to conclude

826
00:37:37,580 --> 00:37:39,180
this week's Techlore Surveillance Report.

827
00:37:39,680 --> 00:37:41,420
If this analysis helped you reclaim control,

828
00:37:41,460 --> 00:37:44,140
you can become a Techlorian by visiting the link in the show notes.

829
00:37:44,380 --> 00:37:46,020
I absolutely love doing this,

830
00:37:46,140 --> 00:37:48,540
and I couldn't do it without all of our community support.

831
00:37:49,000 --> 00:37:51,000
And you'll also gain access to exclusive communities

832
00:37:51,280 --> 00:37:52,340
like the private signal group.

833
00:37:52,780 --> 00:37:55,140
You'll also get some perks like my private RSS feed,

834
00:37:55,220 --> 00:37:56,420
which I'm updating throughout the week

835
00:37:56,580 --> 00:37:58,040
to keep track of all these stories.

836
00:37:58,160 --> 00:38:01,320
And so if you want to access my RSS feed as I'm collecting them,

837
00:38:01,780 --> 00:38:02,820
that's how you can do it.

838
00:38:03,180 --> 00:38:05,380
And if you don't want to support us via the paid method,

839
00:38:05,400 --> 00:38:07,620
you can still do it for free by just leaving a rating.

840
00:38:08,100 --> 00:38:09,640
You can also share the episode with people

841
00:38:09,640 --> 00:38:11,480
in your life to help keep them safer as well.

842
00:38:12,200 --> 00:38:14,060
Other than that, just keep enjoying the episodes

843
00:38:14,600 --> 00:38:17,060
and I'll be happy to keep delivering them each week.

844
00:38:17,580 --> 00:38:18,260
Thank you all for listening

845
00:38:18,560 --> 00:38:20,260
and I'll see you in the next episode of Surveillance Support.

846
00:38:20,360 --> 00:38:22,380
And also don't forget to check out Easy Opt Outs,

847
00:38:22,440 --> 00:38:24,960
our sponsor from this week's episode in the description.

848
00:38:25,400 --> 00:38:26,020
See you next week.