1
00:00:02,020 --> 00:00:07,500
This week's surveillance support covers OpenAI's rogue AI agent hacking far more than just

2
00:00:07,640 --> 00:00:12,420
hugging face and actually a similar thing now happening to Anthropic, Iran linked hackers

3
00:00:12,720 --> 00:00:17,500
burrowing into dozens of US water systems, an activist prosecuted for wiping his number

4
00:00:17,720 --> 00:00:22,120
at the border, and thousands of private claw chats exposed on Google.

5
00:00:22,240 --> 00:00:26,980
A bit of an AI heavy week this week, plus our normal data breaches, threats, FOS Plus

6
00:00:27,300 --> 00:00:28,260
updates, open source.

7
00:00:28,860 --> 00:00:32,259
Welcome to the Techlore Surveillance Report, everybody, your essential weekly tech news

8
00:00:32,380 --> 00:00:36,180
delivering the deep analysis on the latest threats to security, privacy, and digital freedom,

9
00:00:36,440 --> 00:00:41,000
and of course, empowering you to reclaim control and defend your rights as we go along.

10
00:00:41,880 --> 00:00:45,320
I'm excited this week, no announcements really, so let's just dive into the fun stories.

11
00:00:45,800 --> 00:00:50,620
Following this one has been a bit of a nightmare, actually, because the story and my analysis

12
00:00:50,770 --> 00:00:52,600
on it continues to change over time.

13
00:00:53,000 --> 00:00:57,940
OpenAI, the company behind ChatGPT, pretty much set up what was supposed to be sandboxed

14
00:00:57,960 --> 00:01:03,320
environment, which was not properly sandboxed and made it easy to escape. And then that model

15
00:01:03,660 --> 00:01:07,800
essentially started attacking different things around the internet. The main highlight being

16
00:01:08,480 --> 00:01:14,100
Hugging Face, which is another AI organization. The original story is that, oh my god, this rogue

17
00:01:14,220 --> 00:01:20,380
AI agent from OpenAI escaped its, you know, its boundaries from a testing environment and just

18
00:01:20,480 --> 00:01:24,560
started hacking the world. And it just kind of like snapped its fingers and made it happen.

19
00:01:24,680 --> 00:01:28,460
But as we learn more details, it looks less that way.

20
00:01:28,600 --> 00:01:32,820
And when we see these attacks, it's important to remind, especially the new listeners out there,

21
00:01:33,040 --> 00:01:39,280
a lot of people think that it's like the movies where, you know, you just put in a command into your terminal and boom, you hacked someone and that's done.

22
00:01:39,660 --> 00:01:41,240
I think a lot of people know it's not that simple.

23
00:01:41,540 --> 00:01:46,780
But for attacks like these, I think what people don't appreciate, like when I'm talking to people around me,

24
00:01:46,940 --> 00:01:50,500
is the amount of steps required to get to that final destination.

25
00:01:51,140 --> 00:01:59,820
Like let's say even if that one terminal line hack thing actually works that way, you would have to do that multiple times to finally get where you want to go.

26
00:01:59,980 --> 00:02:03,420
And of course, we all pretty much know it's not just a one command kind of thing.

27
00:02:03,860 --> 00:02:10,920
And so it's the kind of thing of scouring the internet for publicly available credentials for certain user accounts that have access to certain information.

28
00:02:11,220 --> 00:02:12,880
They then found some specific zero days.

29
00:02:12,930 --> 00:02:17,880
They found specific bugs and all these things piled on top of each other to finally give them access.

30
00:02:18,050 --> 00:02:20,000
And we've seen attacks like this from humans too.

31
00:02:20,480 --> 00:02:27,100
I think really what's new here is the fact, well, it wasn't done by a human, one, but also it was just faster.

32
00:02:27,500 --> 00:02:28,640
You know, it was more offensive.

33
00:02:29,220 --> 00:02:31,500
It might work a little bit faster than a human might.

34
00:02:31,780 --> 00:02:38,520
Ars Technica had this great article where they came forward making a pretty compelling argument that this isn't the triumph it was made out to be.

35
00:02:38,550 --> 00:02:47,220
When these headlines came out, you know, these AI companies, I think what's really hard to figure out when we're doing coverage for this,

36
00:02:47,420 --> 00:02:49,300
and when I say we, I mean just as a society,

37
00:02:49,740 --> 00:02:52,700
is what is hype and what is reality?

38
00:02:52,950 --> 00:02:54,460
And I think these AI companies,

39
00:02:54,730 --> 00:02:56,100
even when negative things happen,

40
00:02:56,280 --> 00:02:59,200
they're still incentivized to paint them in a positive way.

41
00:02:59,480 --> 00:03:02,360
So that's kind of the hidden dark side here.

42
00:03:02,600 --> 00:03:04,400
When OpenAI says, oops, we hacked someone,

43
00:03:04,520 --> 00:03:06,060
it's like, wait, we hacked someone.

44
00:03:06,300 --> 00:03:07,980
That's how good our models are, right?

45
00:03:08,060 --> 00:03:08,920
That's pretty cool.

46
00:03:09,520 --> 00:03:12,020
So it makes it really hard to actually analyze the coverage.

47
00:03:12,170 --> 00:03:13,580
And in this case specifically,

48
00:03:14,040 --> 00:03:16,579
both companies were actually incentivized by the same thing

49
00:03:16,600 --> 00:03:18,420
when you think about it from a PR perspective.

50
00:03:18,920 --> 00:03:20,840
Open AI is incentivized to say,

51
00:03:20,980 --> 00:03:22,740
wow, our model is just so good.

52
00:03:22,900 --> 00:03:23,780
Look at what it did.

53
00:03:24,120 --> 00:03:25,480
And it was just so out of control.

54
00:03:25,620 --> 00:03:27,640
It was so good that it wasn't even our fault.

55
00:03:28,180 --> 00:03:30,080
And then you have also Hugging Face,

56
00:03:30,640 --> 00:03:33,220
who actually made a lot of very simple mistakes

57
00:03:33,620 --> 00:03:34,840
that could have prevented this attack,

58
00:03:35,100 --> 00:03:36,640
which also a human could have exploited

59
00:03:37,000 --> 00:03:38,340
now that we know more of the details.

60
00:03:38,900 --> 00:03:41,140
And Hugging Face is also incentivized to say,

61
00:03:41,300 --> 00:03:43,740
oh yeah, dude, this is like some novel, crazy thing.

62
00:03:43,900 --> 00:03:44,760
Couldn't have been prevented.

63
00:03:45,120 --> 00:03:54,600
They tried to spin the entire incident as a success story at Hugging Face because the security team treated OpenAI's report with the urgency it deserved as a genuine zero-day unknown to the world and moved accordingly.

64
00:03:55,200 --> 00:04:07,060
Left out of the post is that five days passed until OpenAI revealed its role on the breach Hugging Face disclosed, and that at least another five days passed from the time OpenAI reported the zero-days and JFrog released patches for them.

65
00:04:07,640 --> 00:04:13,880
So the lesson here is that if OpenAI agents can gain a 10-day head start, so too can other models being used maliciously.

66
00:04:14,240 --> 00:04:17,980
This is hardly the success story Jfrog and OpenAI are trying to make it out to be.

67
00:04:18,359 --> 00:04:20,820
Combined with Jfrog's opaqueness surrounding the zero days,

68
00:04:21,019 --> 00:04:23,160
because they never actually shared what all the zero days were,

69
00:04:23,440 --> 00:04:24,720
the incident looks even worse.

70
00:04:25,060 --> 00:04:26,780
Given the speed at which AI companies are moving,

71
00:04:27,320 --> 00:04:28,620
there may still be worse to come.

72
00:04:28,740 --> 00:04:32,180
As the title promises, this is the story that keeps on giving.

73
00:04:32,620 --> 00:04:34,760
Because right when you think, you know, that's it, you know,

74
00:04:35,100 --> 00:04:36,860
this is still unfolding, we're getting more details,

75
00:04:37,100 --> 00:04:40,540
we're maybe trying to figure out what this actually looks like,

76
00:04:40,660 --> 00:04:41,300
what does it mean,

77
00:04:42,180 --> 00:04:46,280
Anthropic now comes forward, who runs Claude and says,

78
00:04:46,300 --> 00:04:49,540
oh, hey, by the way, RAI also hacked three companies during our tests.

79
00:04:49,900 --> 00:04:50,400
Oh, my gosh.

80
00:04:51,200 --> 00:04:53,360
This one's also a little bit more embarrassing in some ways

81
00:04:53,620 --> 00:04:56,480
because two of the three organizations didn't even know

82
00:04:56,560 --> 00:04:59,340
they were already accessed until Anthropic had to tell them.

83
00:04:59,880 --> 00:05:02,280
So it's not the, like, we caught it fast story

84
00:05:02,660 --> 00:05:04,340
that we kind of got on the other end of things.

85
00:05:04,860 --> 00:05:09,519
And also, Mythos literally uploaded a malicious Python package

86
00:05:09,540 --> 00:05:13,100
to a public registry, which compromised 15 machines in the process.

87
00:05:13,460 --> 00:05:18,340
So, of course, I always like to look at, well, what's the intent behind, you know, publicizing

88
00:05:18,560 --> 00:05:18,680
this?

89
00:05:18,760 --> 00:05:20,920
And I guess it's for me, it's a 50-50 thing.

90
00:05:21,020 --> 00:05:24,740
I think this could be the kind of thing where it's like, oh, my God, OpenAI is getting a

91
00:05:24,740 --> 00:05:28,180
lot of both good and bad press about how their models are so good.

92
00:05:28,240 --> 00:05:31,040
And they just hack things and it might look Claude not look as good.

93
00:05:31,140 --> 00:05:33,880
So Claude's going to say, yeah, we can hack things, too.

94
00:05:34,480 --> 00:05:39,500
I also think it's equally likely, though, that they and this is actually what they reported

95
00:05:39,520 --> 00:05:44,240
themselves, this whole incident with open AI forced them to start looking at their own logs,

96
00:05:44,290 --> 00:05:47,980
and they actually discovered that their models are doing the same thing. I don't know what the truth

97
00:05:48,100 --> 00:05:53,000
is, guys. That's why, again, it's very frustrating covering these AI companies because they oftentimes

98
00:05:53,260 --> 00:05:57,460
aren't grounded in reality. And this is kind of my thoughts on these AI companies as a whole.

99
00:05:57,860 --> 00:06:02,080
They themselves claim that AI is out to end humanity while they're building the AI themselves.

100
00:06:02,920 --> 00:06:08,880
And so for me, I think that there's actually a lot of weird incentives for these AI companies to

101
00:06:08,900 --> 00:06:14,140
create fear, to create this idea of how powerful these things really are that actually go beyond

102
00:06:14,580 --> 00:06:17,800
what they realistically are, which is pattern recognition machines. I'm not saying these

103
00:06:17,940 --> 00:06:21,480
aren't powerful machines. We use some of them back here too for some of our content and like

104
00:06:21,940 --> 00:06:25,980
fact checking our scripts and helping us with transcripts. So we do use them back here. But

105
00:06:26,320 --> 00:06:31,720
I think it's really important to understand that these things are so far from what I've been able

106
00:06:31,720 --> 00:06:36,120
to tell, just doing things that humans can do much faster and much more efficiently, right?

107
00:06:36,240 --> 00:06:42,180
One of the stories last week covering this even made the claim, I believe it was from TechCrunch, that this was not at all an AI problem.

108
00:06:42,350 --> 00:06:46,660
It was a human problem because the humans didn't even put proper safeguards in place for this tool.

109
00:06:46,800 --> 00:06:51,600
I see this as blaming construction equipment for just doing what it's designed to do.

110
00:06:51,900 --> 00:06:54,160
But, you know, you are bulldozing the wrong building.

111
00:06:54,330 --> 00:06:58,180
And it's like, well, maybe the human shouldn't have put that next to the wrong building.

112
00:06:59,400 --> 00:07:01,800
So I have a lot of complicated feelings about this.

113
00:07:02,020 --> 00:07:02,780
This is still unfolding.

114
00:07:02,980 --> 00:07:04,500
I'm not an AI expert or anything.

115
00:07:04,540 --> 00:07:07,620
This is just me doing my best to try to make sense of these stories.

116
00:07:07,860 --> 00:07:12,600
So let me know what you guys think if you're on Spotify or YouTube, I suppose, or PeerTube,

117
00:07:13,100 --> 00:07:13,640
Techlore.tv.

118
00:07:19,960 --> 00:07:24,720
Coming soon, we have an activist who is facing a felony for wiping his graphene phone at the

119
00:07:24,980 --> 00:07:25,100
border.

120
00:07:25,560 --> 00:07:30,140
And then we also have thousands of private clod chats and artifacts getting indexed by

121
00:07:30,260 --> 00:07:30,400
Google.

122
00:07:30,520 --> 00:07:33,480
So we will touch on AI again for just a brief second.

123
00:07:33,560 --> 00:07:37,760
But before we get there, the U.S. government says that Iran-linked hackers are disrupting

124
00:07:37,900 --> 00:07:39,300
American water and energy providers.

125
00:07:39,580 --> 00:07:45,120
Now, I like to share this story with people in any story like this because it's very common

126
00:07:45,150 --> 00:07:48,960
for us to cover things that are a little bit more hypothetical and more, let's just say,

127
00:07:49,020 --> 00:07:53,100
in the cloud and not as, you know, in your hands, something you can feel.

128
00:07:53,740 --> 00:07:57,800
And that is kind of the inherent downside of covering security issues, right?

129
00:07:57,900 --> 00:08:01,620
When you say something was caught in a data breach, it just feels a bit nebulous to a

130
00:08:01,740 --> 00:08:02,200
lot of people.

131
00:08:02,700 --> 00:08:14,860
But I love stories like this, obviously not because it's good for people, like this is an awful story, but it reminds people in a very healthy way that these systems do eventually reach the real world, right?

132
00:08:15,080 --> 00:08:32,840
There was an advisory updated Wednesday that the FBI and the NSA, the Department of Energy and SISA, said that Iranian hackers were targeting programmable logic controllers on Internet-connected operational networks, allowing them to manipulate data on their displays, causing outages and disruption, specifically really looking at water and energy providers.

133
00:08:33,240 --> 00:08:39,140
Now, originally, this was sent to a group which shares cybersecurity information called the Water Information Sharing and Analysis Center.

134
00:08:39,320 --> 00:08:40,099
There's something for everything.

135
00:08:40,800 --> 00:08:51,000
And they note that the Minnesota Fusion Center, which is a state-level intelligence sharing entity, issued an alert regarding ongoing malicious cyber activity impacting public drinking water systems across Minnesota.

136
00:08:51,440 --> 00:08:53,360
This disrupted over 30 communities.

137
00:08:53,700 --> 00:08:55,400
It's pretty scary stuff when you think about it.

138
00:08:55,400 --> 00:09:01,200
And again, I like these stories because it grounds a lot of the stuff we talk about on this podcast in reality.

139
00:09:01,200 --> 00:09:06,140
Now this clearly has some intense geopolitical ties right now with what's going on in Iran,

140
00:09:06,260 --> 00:09:10,440
and that could explain why there could be some targets happening on U.S. soil with things that

141
00:09:10,440 --> 00:09:15,600
are cyber attacks. So there's a lot going on here, and I'm not going to get too much into that side

142
00:09:15,600 --> 00:09:19,940
of the story. So I like to remind people about what does prepping look like? What would it look

143
00:09:20,040 --> 00:09:24,000
like if someone took out your power for a few days? What would it look like if you lost water access

144
00:09:24,220 --> 00:09:29,760
for a couple days? Do you have backup water at home? These are the things I like to ask, and it's a

145
00:09:29,780 --> 00:09:31,940
good thing for you to think about because you never know what's going to happen.

146
00:09:38,180 --> 00:09:42,360
This is going to be an especially challenging one. You know, in the Signal group, I kind of

147
00:09:42,600 --> 00:09:46,920
exchanged some messages with some of you guys, which is good because then I got some of your

148
00:09:47,460 --> 00:09:52,500
feedback and thoughts, which helped me kind of form my thoughts on this one. So, you know,

149
00:09:52,620 --> 00:09:57,840
the story itself before I dive into any analysis. So there's an individual here. His name is Samuel

150
00:09:57,860 --> 00:10:03,200
tunic, tunic, tunic. And he runs graphene on his Pixel, and it's something that he uses.

151
00:10:03,740 --> 00:10:07,940
He's an activist, part of a group called Defend the Atlanta Forest, which opposed the construction

152
00:10:08,220 --> 00:10:13,520
of an enormous law enforcement training facility in the area often known as Cop City. What he didn't

153
00:10:13,620 --> 00:10:17,480
know, according to his lawyers, was that he'd been placed on a watch list for his actions and that

154
00:10:17,740 --> 00:10:22,380
Customs and Border Protection had discussed over email plans to detain him upon his arrival

155
00:10:22,380 --> 00:10:25,240
back in the U.S. for suspected terrorism activities.

156
00:10:25,600 --> 00:10:27,900
And ours here actually kind of downplays

157
00:10:28,000 --> 00:10:29,280
what that looks like.

158
00:10:29,420 --> 00:10:31,000
So they had a hidden camera that was placed

159
00:10:31,260 --> 00:10:32,700
outside the house that he lived in.

160
00:10:33,040 --> 00:10:34,980
They also had a tracker placed on his car.

161
00:10:35,460 --> 00:10:38,080
They learned that his cell phone records were subpoenaed,

162
00:10:38,120 --> 00:10:39,700
and he said he got an email from Google

163
00:10:39,920 --> 00:10:42,800
saying his Gmail account had also been subpoenaed.

164
00:10:43,080 --> 00:10:44,680
Apparently, he also tried to get a job

165
00:10:44,900 --> 00:10:46,520
at a Christmas tree lot,

166
00:10:46,760 --> 00:10:48,620
which required a background check.

167
00:10:49,500 --> 00:10:52,140
But because it was going to be near public schools,

168
00:10:53,660 --> 00:10:55,660
for some reason he failed the background check

169
00:10:56,260 --> 00:11:00,000
so there's a lot of weird things happening here with very few details

170
00:11:00,500 --> 00:11:04,560
and I just it makes it difficult to cover the story because we can't know

171
00:11:04,630 --> 00:11:09,160
I know a couple other people have done coverage for the story say that oh those things are made up to make him look bad

172
00:11:09,500 --> 00:11:12,640
and other people have said oh this guy's clearly up to something no good

173
00:11:12,820 --> 00:11:16,100
that's why he's being investigated we don't know that's the reality

174
00:11:16,190 --> 00:11:20,000
and so I wanted to at least share those details and so that way

175
00:11:20,020 --> 00:11:24,200
you guys at least have all the facts of the story. Now, I also want to step back here a little bit

176
00:11:24,300 --> 00:11:29,100
because I think there was a piece of news last week that actually fits into this one, and it has to do

177
00:11:29,200 --> 00:11:35,640
with a case called U.S. v. Belmont Cardozo. Cardozo, I believe is how you say that. The Fourth Amendment

178
00:11:35,900 --> 00:11:39,780
requires that government searches of persons or property be reasonable, which usually means

179
00:11:40,020 --> 00:11:44,760
obtaining a warrant based on probable cause from a judge. But a warrantless search can still be

180
00:11:45,000 --> 00:11:49,240
reasonable if it falls within an exception to the warrant requirement, including the exception that

181
00:11:49,260 --> 00:11:53,460
allows officers to search your belongings at the border. The border search exception allows

182
00:11:53,760 --> 00:11:57,420
warrantless searches of persons and property crossing the U.S. border, including the functional

183
00:11:57,620 --> 00:12:01,360
equivalent of the border, such as international airports, given the government's interest in

184
00:12:01,540 --> 00:12:05,600
controlling who or what may enter the country. And it says right here, until a clear line is drawn,

185
00:12:05,840 --> 00:12:09,720
border officers within the Fourth Circuit's jurisdiction can use manual searches to sidestep

186
00:12:10,000 --> 00:12:13,500
heightened Fourth Amendment standards that would authorize apply. And that is kind of the gap that

187
00:12:13,480 --> 00:12:19,200
the EFF disagrees with existing. But that whole story I just shared with you is eerily similar

188
00:12:19,600 --> 00:12:24,340
to what actually happened to this individual. So this individual was being watched by the FBI for

189
00:12:24,360 --> 00:12:29,160
the year, just like I told you, Samuel Tunick. And he traveled outside of the US. And when he was

190
00:12:29,300 --> 00:12:34,760
coming home, he had his graphene phone. They started asking him to unlock it. And they used

191
00:12:34,920 --> 00:12:38,800
the duress password for graphene, which means they typed in a password, which reset the device.

192
00:12:39,140 --> 00:12:41,560
And when I say reset, I mean wipe the device.

193
00:12:42,020 --> 00:12:49,940
Now, his attorneys accused the government of demanding access to his phone under the pretext of searching for CSAM, but without providing evidence to justify its suspicion.

194
00:12:50,380 --> 00:13:03,180
His motion to suppress argued that the government was instead investigating him over his association with a long-running environmental movement called Defend the Atlanta Forest, which opposes the development of a sprawling training campus for law enforcement in Atlanta dubbed Cop City.

195
00:13:03,460 --> 00:13:11,720
So the prosecutor has charged him under a federal statute that makes it unlawful to knowingly destroy or damage property to prevent authorities from seizing it.

196
00:13:11,750 --> 00:13:13,140
And he has pleaded not guilty.

197
00:13:13,430 --> 00:13:18,400
There is this kind of expectation that when you are going over borders, you have less rights.

198
00:13:18,800 --> 00:13:28,960
Now, I do think the duress thing is a very good lesson here because it is something that has been kind of discussed unofficially and kind of just communities online.

199
00:13:29,360 --> 00:13:33,480
and I think it really represents how there's a lot of times a gap between kind of speculation

200
00:13:33,860 --> 00:13:38,940
online and what the real world looks like. Now there is a quote here from somebody named Runa

201
00:13:39,220 --> 00:13:43,520
Sanvik, who is a security expert who works to protect at-risk people. And she said,

202
00:13:43,580 --> 00:13:47,340
I have not seen this before, though I've discussed this potential scenario with activists and

203
00:13:47,560 --> 00:13:51,920
journalists over the years. I think this case serves as a reminder that authorities may argue

204
00:13:52,140 --> 00:13:56,700
you knowingly destroyed data, so it's better to not have that data on you when you cross certain

205
00:13:56,720 --> 00:14:01,100
borders. With a little planning ahead of time, you can always download the data you need once you get

206
00:14:01,220 --> 00:14:05,760
where you're going. And this actually is pretty much what the advice has been that is a little bit

207
00:14:05,880 --> 00:14:10,120
more applicable to more of you. And that's kind of the good news here. If you are really concerned

208
00:14:10,300 --> 00:14:15,360
about border searches, you shouldn't be carrying a phone with your private data on it and travel

209
00:14:15,470 --> 00:14:19,820
should be treated as its own thing. Get a burner phone, just get something with signal on it and

210
00:14:19,920 --> 00:14:23,860
just add a few contacts to it. That way, if you're searched, you just give them your phone, let them

211
00:14:23,860 --> 00:14:28,180
scan whatever they want. It's not a huge deal and you move on. But if you're traveling with all of

212
00:14:28,180 --> 00:14:33,220
your normal data and you don't want to be, you know, victim to this, I would really recommend

213
00:14:33,620 --> 00:14:38,000
just not bringing those devices before I would ever tell someone like, oh yeah, set up a duress

214
00:14:38,300 --> 00:14:42,020
password. So just be very careful with that feature. Do your research. Make sure it actually

215
00:14:42,300 --> 00:14:46,880
fits into your threat model and would actually help you when you try to imagine a very stressed

216
00:14:47,200 --> 00:14:52,180
scenario inside of your workflow and your lifestyle. But this is a very interesting story.

217
00:14:52,280 --> 00:14:55,860
This is still unfolding, and it should be interesting to see what happens here, because

218
00:14:55,950 --> 00:14:59,020
this could set some precedent down the road for something else.

219
00:14:59,540 --> 00:15:03,020
All right, everybody, coming soon, we have how thousands of private cloud chats and artifacts

220
00:15:03,360 --> 00:15:04,320
got indexed by Google.

221
00:15:04,550 --> 00:15:10,300
I wish I could somehow get some of my new tools properly indexed by Google, so maybe I could

222
00:15:10,300 --> 00:15:11,420
get some of that magic sauce.

223
00:15:11,580 --> 00:15:15,720
But before I get there, I want to share with you a bit about our sponsor today, which is

224
00:15:15,960 --> 00:15:18,900
Dava Itch, D-A-W-A-R-I-C-H.

225
00:15:19,160 --> 00:15:23,280
Half of today's episode is a story about someone else holding your data when it goes wrong,

226
00:15:23,560 --> 00:15:28,360
like a rogue AI agent breaking into companies, hackers quietly sitting inside water systems,

227
00:15:28,720 --> 00:15:31,200
a guy facing a felony over what was on his phone at the border.

228
00:15:31,580 --> 00:15:35,480
The through line is one that we come back to literally every week on almost every story.

229
00:15:35,660 --> 00:15:39,720
The danger wasn't the data itself, it's who's holding it and whether you're the one in control

230
00:15:40,000 --> 00:15:44,220
and actually consenting to whatever's happening, which is the whole point of Dava Itch.

231
00:15:44,440 --> 00:15:48,120
It's open source, optionally self-hosted location history app.

232
00:15:48,420 --> 00:15:51,760
Basically, Google Timeline, except the map, actually belongs to you.

233
00:15:52,460 --> 00:15:56,160
Import your existing Google data, and you can actually enjoy it, and then delete Google when you're done.

234
00:15:56,480 --> 00:15:59,980
This is how you can track your cool rides, if you're going on rides, or your runs.

235
00:16:00,420 --> 00:16:05,080
Really, anything. The sky's the limit, and the best part is you don't have to think about the privacy implications,

236
00:16:05,500 --> 00:16:10,480
because, again, they're open source, and you can even self-host it yourself if you really want to trust only yourself.

237
00:16:11,160 --> 00:16:14,020
Dava Itch really flips everything we see in these stories on its head,

238
00:16:14,040 --> 00:16:16,600
because it gives you a superpower that only you own

239
00:16:17,080 --> 00:16:18,380
and it puts you in the driver's seat.

240
00:16:18,650 --> 00:16:21,000
So whether you're an athlete saving your favorite runs,

241
00:16:21,260 --> 00:16:23,760
logging office days versus working from home for taxes,

242
00:16:24,260 --> 00:16:25,240
documenting that road trip,

243
00:16:25,310 --> 00:16:26,660
or you just want a year of your life

244
00:16:27,020 --> 00:16:28,400
on a map that nobody else owns

245
00:16:28,500 --> 00:16:29,880
that you can share with your friends and family,

246
00:16:30,220 --> 00:16:31,660
you can self-host Dava Itch for free

247
00:16:31,820 --> 00:16:36,740
or grab the hosted version at d-a-w-a-r-i-c-h.app

248
00:16:37,080 --> 00:16:37,740
slash techlore.

249
00:16:37,890 --> 00:16:42,780
Again, that's d-a-w-a-r-i-c-h.app slash techlore.

250
00:16:43,200 --> 00:16:46,120
where the code Techlore gets you 20% off your first year.

251
00:16:46,520 --> 00:16:47,800
All right, everybody, back to the show,

252
00:16:47,840 --> 00:16:49,680
and thank you, Dava Itch, for sponsoring us.

253
00:16:55,700 --> 00:16:57,160
Before we get into the Defense Bulletin,

254
00:16:57,240 --> 00:17:00,780
we have one just very quick story also from AI companies,

255
00:17:01,040 --> 00:17:01,960
specifically Claude.

256
00:17:02,120 --> 00:17:05,319
Now, there's apparently an untold number of Claude chats and artifacts,

257
00:17:05,560 --> 00:17:07,100
which is those mini apps and documents

258
00:17:07,640 --> 00:17:10,380
that were found publicly searchable on Google over the weekend

259
00:17:10,400 --> 00:17:18,439
And after a Reddit user discovered that a typing search operator like siteclaw.ai slash share into Google surfaced a long list of shared conversations.

260
00:17:19,060 --> 00:17:23,720
Some reportedly contained health records, private company documents, and the names and phone numbers of children.

261
00:17:23,800 --> 00:17:25,420
So let's use this story as a reminder.

262
00:17:25,500 --> 00:17:30,080
If you're listening to this, just check through anything that you use that can implement sharing.

263
00:17:30,120 --> 00:17:34,040
And just double check that what's shared is something that you still want to be shared.

264
00:17:34,440 --> 00:17:36,840
It's these more obvious things that sometimes get skipped over.

265
00:17:37,000 --> 00:17:40,640
when we look at all the technical stuff, we forget just the most obvious stuff sometimes.

266
00:17:41,340 --> 00:17:45,240
Now, Anthropic has come forward and said, yeah, this is kind of the user's fault here.

267
00:17:45,820 --> 00:17:49,020
The company said that shared links only appear in search results when they've been posted

268
00:17:49,260 --> 00:17:52,520
somewhere search engines can see, like a forum or a social media post.

269
00:17:52,960 --> 00:17:56,620
It added that a link sent privately to someone stays out of search, which honestly, I think

270
00:17:56,660 --> 00:17:57,160
is pretty fair.

271
00:17:57,340 --> 00:17:58,800
Like, it's a very fair take.

272
00:17:58,960 --> 00:18:00,080
Like, this is a public link.

273
00:18:00,520 --> 00:18:02,280
Klon is giving them the ability to go public.

274
00:18:02,800 --> 00:18:04,820
Gosh, these autoplaying videos are so obnoxious.

275
00:18:04,960 --> 00:18:06,060
So thank you, TechCrunch.

276
00:18:06,360 --> 00:18:10,980
Again, I really think that what it seems like happened is it's a user error for the most part.

277
00:18:10,980 --> 00:18:14,620
I'm not saying neither of these companies couldn't have done more to introduce safeguards here.

278
00:18:15,120 --> 00:18:20,000
But I think a lot of users created this public link, maybe posted it online, forgot about it,

279
00:18:20,160 --> 00:18:24,920
and now those are being indexed by Google because they were just found in public places.

280
00:18:25,260 --> 00:18:27,700
Now, I use public links all the time, but only for things that I'm like,

281
00:18:27,760 --> 00:18:29,400
okay, if this ends up in public hands, that's fine.

282
00:18:29,580 --> 00:18:32,780
So just a reminder, and now let's get into the Defense Bulletin.

283
00:18:38,800 --> 00:18:43,540
now the defense bulletin is broken up into three subsections the first is the data breaches the

284
00:18:43,740 --> 00:18:48,300
second is the threats of the week so things to flag and the third one is the open source updates

285
00:18:48,480 --> 00:18:52,980
so we're going to start here with data breaches starting with care cloud who's started to notify

286
00:18:53,280 --> 00:18:59,999
hundreds of thousands after hackers stole medical records care cloud is a u.s health tech giant and

287
00:19:00,020 --> 00:19:05,180
they said very little about the breach since March. Yes, this literally happened earlier this year

288
00:19:05,640 --> 00:19:09,340
when it first admitted that hackers had raided one of its six stores of patient data.

289
00:19:10,180 --> 00:19:14,940
But new disclosures seen by TechCrunch, though, offer the clearest picture of the breach so far,

290
00:19:15,360 --> 00:19:20,580
including that nearly 350,000 people have been impacted. If anyone works for CareCloud,

291
00:19:20,800 --> 00:19:26,599
do you just not give a damn? Like, guys, I just want to zoom out. Like, if you know this company

292
00:19:26,640 --> 00:19:28,140
or you know someone involved with this company,

293
00:19:28,860 --> 00:19:30,460
please check in with them.

294
00:19:30,560 --> 00:19:33,660
They disclosed this in March with almost no information.

295
00:19:34,240 --> 00:19:36,320
They have had no communication since then.

296
00:19:36,660 --> 00:19:38,340
te reached out for comment

297
00:19:38,460 --> 00:19:39,980
and they didn't respond for comment.

298
00:19:40,500 --> 00:19:42,700
And we still have very limited information

299
00:19:43,060 --> 00:19:44,440
on anybody who's impacted.

300
00:19:44,860 --> 00:19:46,780
And might I remind you this impacts names,

301
00:19:47,280 --> 00:19:49,060
home addresses, social security numbers,

302
00:19:49,380 --> 00:19:51,120
government issued identification numbers

303
00:19:51,640 --> 00:19:53,100
like passports and driver's licenses.

304
00:19:53,860 --> 00:19:55,540
Notices also say that the stolen data

305
00:19:55,540 --> 00:19:59,020
included financial information such as bank account information and payment card numbers

306
00:19:59,520 --> 00:20:03,640
alongside a wealth of medical and health related information. I'm pretty pissed about this story

307
00:20:03,690 --> 00:20:07,120
just reading it. So I'm going to move on. But check out the show notes if you want to learn more

308
00:20:07,460 --> 00:20:12,840
to see what we do know about the story. Now South Korea has fined a telecom giant KT $39 million

309
00:20:13,230 --> 00:20:16,940
for a customer data breach. And I believe we already covered this one if I'm not mistaken.

310
00:20:17,090 --> 00:20:24,039
So the update here is the fine. So make sure to dig into this if you do or have used KT to make

311
00:20:24,060 --> 00:20:29,700
sure you already dealt with that. But otherwise, just know that they were fined. Shiny Hunters has

312
00:20:29,900 --> 00:20:34,640
claimed a Brinks home breach threatening to leak stolen data. Brinks is a home security company,

313
00:20:34,780 --> 00:20:39,400
which has it looks like cameras and some kind of home ecosystem. We were seeing a lot of these

314
00:20:39,560 --> 00:20:43,440
nowadays. But they have disclosed that hackers breached some of its systems and are threatening

315
00:20:43,440 --> 00:20:54,020
to leak allegedly stolen data. They exfiltrated more than a million rows of customer data. They

316
00:20:54,040 --> 00:20:59,660
support chat requests. So this is still unfolding. It's not looking great so far. So if you use

317
00:21:00,300 --> 00:21:04,660
Brinks Home Security, check out the story and also make sure you're keeping up with any news

318
00:21:04,720 --> 00:21:08,780
because they're going to start putting things out. Hopefully, if they're not the last company we

319
00:21:08,940 --> 00:21:12,880
talked about, the first one I should say, because we talked about K, yeah, if they're not CareCloud,

320
00:21:13,060 --> 00:21:17,080
they might actually communicate and actually care a little bit about their users. Obviously,

321
00:21:17,220 --> 00:21:21,440
these are always ironic because this is a home security company and now they could jeopardize

322
00:21:21,460 --> 00:21:27,520
your home safety a little bit, right? So I always like to point people as often as they can towards

323
00:21:27,780 --> 00:21:31,520
things that are as close to zero knowledge as possible. Guys, when it's something this sensitive,

324
00:21:31,800 --> 00:21:36,260
like I actually had a family member recently who just didn't think about it, right? Like they had

325
00:21:36,260 --> 00:21:41,380
a home security camera that was an indoor security camera. And they started getting weird messages

326
00:21:41,550 --> 00:21:45,740
from the local company about like things that were happening around the house. And it just didn't

327
00:21:46,020 --> 00:21:50,840
click that, yeah, it's not zero knowledge. It's not end-to-end encrypted. So any employee can go

328
00:21:50,860 --> 00:21:52,120
and watch that camera.

329
00:21:52,250 --> 00:21:53,800
And so this is something people forget.

330
00:21:54,000 --> 00:21:55,640
We hear companies like Google,

331
00:21:55,920 --> 00:21:57,220
we hear companies like OpenAI,

332
00:21:57,480 --> 00:21:59,120
we think of them as companies,

333
00:21:59,400 --> 00:22:01,120
but they're made up by thousands of employees.

334
00:22:01,660 --> 00:22:05,040
And those employees can have a lot of access to your data

335
00:22:05,280 --> 00:22:06,840
depending on how the company is doing things.

336
00:22:06,910 --> 00:22:09,020
And that's why it's always important to chase after

337
00:22:09,260 --> 00:22:10,780
as close to zero knowledge as possible,

338
00:22:11,220 --> 00:22:13,080
because why would you want to trust random people

339
00:22:13,370 --> 00:22:14,860
behind companies with your information?

340
00:22:15,050 --> 00:22:17,160
Or why would you trust a data breach

341
00:22:17,520 --> 00:22:19,720
doesn't lead to something really sensitive coming up?

342
00:22:20,180 --> 00:22:22,900
It's a good talking point, I think, that I've had a lot of luck with.

343
00:22:23,300 --> 00:22:26,860
There's a semiconductor company named Analog Devices that disclosed a data breach.

344
00:22:27,000 --> 00:22:30,360
They say their operations were unaffected, but if you want to learn more, check out the show notes.

345
00:22:30,720 --> 00:22:35,180
We also have a small update to Fairlife, which I had no idea was a Coca-Cola company.

346
00:22:36,200 --> 00:22:41,800
And they just have a small update here that they confirmed that data was stolen as part of that attack.

347
00:22:42,320 --> 00:22:45,360
So you can learn more about that if you want to learn more in the show notes.

348
00:22:45,620 --> 00:22:49,440
Australian energy provider Origin says a data breach exposed client data.

349
00:22:49,780 --> 00:22:55,880
And so this impacted things like full names, physical addresses, date of births, and it's impacted quite a lot of people, 4.8 million.

350
00:22:56,000 --> 00:23:00,080
And so if you have any sort of relationship with Origin, make sure to look into that story.

351
00:23:00,840 --> 00:23:04,260
OnTrack has also started notifying customers of a data breach after a network hack.

352
00:23:04,280 --> 00:23:05,760
This is a parcel delivery company.

353
00:23:05,860 --> 00:23:10,220
And so if you were impacted by this, ideally, you got a quick notice about that.

354
00:23:10,660 --> 00:23:13,200
Chick-fil-A also has come out with a few more details.

355
00:23:13,420 --> 00:23:14,780
I believe we covered this last week.

356
00:23:14,920 --> 00:23:19,860
So if any of you like eating chickens, they have a data breach that impacted more than 13,000 customers.

357
00:23:20,140 --> 00:23:22,080
So it was a bit of a smaller scale breach here.

358
00:23:22,820 --> 00:23:24,980
And they got it from a third party source, apparently.

359
00:23:25,420 --> 00:23:29,960
And so if you do want to see if you were impacted, check out the show notes down in the description.

360
00:23:30,460 --> 00:23:32,120
All right, now we're going to get into the threats.

361
00:23:32,600 --> 00:23:35,620
And, you know, we're running a little bit short on time here, so I'll do my best.

362
00:23:35,730 --> 00:23:43,040
But Patrick Brayer, who's been kind of the main politician who is helping lead this whole movement against chat control,

363
00:23:44,060 --> 00:23:46,220
He just put out a quick blog.

364
00:23:46,520 --> 00:23:47,720
I'm not going to talk too much about it

365
00:23:47,900 --> 00:23:49,880
because it's quite similar to other things he shared.

366
00:23:49,960 --> 00:23:52,040
And we even talked about it, I think, last week or the week before.

367
00:23:52,620 --> 00:23:54,760
But it's just a quick blog post that is very well written

368
00:23:55,080 --> 00:23:58,640
about how the true losers of Chat Control 1.0 coming back are children

369
00:23:58,780 --> 00:24:00,220
and why he feels that way about it

370
00:24:00,680 --> 00:24:02,380
and kind of the stats behind Chat Control

371
00:24:02,600 --> 00:24:05,580
and why they overwhelmingly actually can sometimes harm children as well.

372
00:24:05,920 --> 00:24:08,040
So if you want to read a little bit more about it,

373
00:24:08,360 --> 00:24:09,200
definitely check out the show notes.

374
00:24:09,340 --> 00:24:11,140
This next one is a quick update.

375
00:24:11,340 --> 00:24:13,880
I'm still wrapping my head around it and how I feel about this one.

376
00:24:14,000 --> 00:24:17,500
but Google has a privacy-preserving age verification system

377
00:24:17,640 --> 00:24:18,940
that's coming to the Play Store,

378
00:24:19,120 --> 00:24:21,960
and this relies on an API that ties to parents.

379
00:24:22,220 --> 00:24:23,520
This doesn't require an ID.

380
00:24:23,670 --> 00:24:25,180
It doesn't require selfie verification.

381
00:24:25,360 --> 00:24:27,280
It's just connected to the Family Link app.

382
00:24:27,350 --> 00:24:29,660
The idea is that parents will set age ranges

383
00:24:30,040 --> 00:24:31,300
for their kids' managed accounts.

384
00:24:31,700 --> 00:24:34,180
Of what I've seen, this is a slightly better system, right?

385
00:24:34,460 --> 00:24:36,840
But again, the real root concern here, guys,

386
00:24:36,980 --> 00:24:39,940
I have no doubt that we can solve the technology problem

387
00:24:40,050 --> 00:24:41,780
of doing this in a privacy-respecting way.

388
00:24:41,920 --> 00:24:42,600
I think that's possible.

389
00:24:43,080 --> 00:24:44,140
I've seen the zero knowledge proofs.

390
00:24:44,370 --> 00:24:45,980
It still hasn't really been done on a mass scale,

391
00:24:46,130 --> 00:24:47,220
so I think it's not even there yet,

392
00:24:47,330 --> 00:24:48,860
but let's just assume we figure that out.

393
00:24:49,360 --> 00:24:50,840
I still have an issue with the idea

394
00:24:51,210 --> 00:24:53,460
of changing what the internet looks like

395
00:24:53,700 --> 00:24:54,800
depending on who you are.

396
00:24:54,860 --> 00:24:56,540
I think that's really at the core now

397
00:24:56,780 --> 00:24:58,060
of what I'm truly concerned about

398
00:24:58,380 --> 00:25:00,460
because if we're starting to decide,

399
00:25:00,680 --> 00:25:02,440
oh, for these people, the internet looks like this.

400
00:25:02,450 --> 00:25:04,380
For these people, the internet looks like this.

401
00:25:04,590 --> 00:25:06,840
And in this region, the internet is allowed to have this.

402
00:25:06,870 --> 00:25:07,860
In this region, it's not.

403
00:25:08,180 --> 00:25:10,120
We're going to start seeing a lot less

404
00:25:10,310 --> 00:25:11,500
of a free open internet.

405
00:25:11,780 --> 00:25:23,800
It's like if we have these different libraries spread around the city and, you know, one library doesn't allow people under this age to get in and this one doesn't allow people above this age to get in and all of them have different pieces of content.

406
00:25:24,020 --> 00:25:30,920
We're going to start seeing curated content for specific groups of people and they might not get the full picture, right?

407
00:25:31,160 --> 00:25:32,680
So those are my concerns.

408
00:25:32,940 --> 00:25:34,060
It's a concern of censorship.

409
00:25:34,300 --> 00:25:38,000
It's a concern of freedom of expression, freedom of information, all those things.

410
00:25:38,050 --> 00:25:41,520
And I think that's really my long-term concern looking at these stories.

411
00:25:41,660 --> 00:25:45,280
JetBrains has warned of a critical TeamCity remote code execution flaw.

412
00:25:45,430 --> 00:25:48,440
And so if you want to learn about this, again, it affects TeamCity.

413
00:25:48,800 --> 00:25:52,040
And if you use that, you should look into it to make sure that you're not impacted and

414
00:25:52,050 --> 00:25:53,080
what you can do to prevent it.

415
00:25:53,340 --> 00:25:54,140
This one's just interesting.

416
00:25:54,250 --> 00:25:55,960
And so if you're more technical, you might like this.

417
00:25:56,200 --> 00:26:01,720
But Mythos, Claude's, you know, crazy, you know, offensive cybersecurity model actually

418
00:26:02,040 --> 00:26:06,580
found an issue with an algorithm candidate for post-quantum encryption.

419
00:26:06,930 --> 00:26:08,540
But it killed the algorithm called Hawk.

420
00:26:09,020 --> 00:26:14,700
like the quote here is basically with this paper hawk is dead um and so pretty interesting stuff

421
00:26:14,960 --> 00:26:20,080
it's good that it was found and so um i do think genuinely that these ai models do have really good

422
00:26:20,300 --> 00:26:25,480
potential to do really positive things and so um i'm trying to be optimistic about them um but i

423
00:26:25,480 --> 00:26:30,240
know that that also comes with a lot of the negatives with them as well so um i know that

424
00:26:30,240 --> 00:26:34,960
this kind of contradicts the earlier stories from earlier so um yeah i'm just doing my best to stay

425
00:26:34,860 --> 00:26:36,700
optimistic, guys. The next story comes from

426
00:26:36,840 --> 00:26:38,680
Misk, who are some security researchers,

427
00:26:39,240 --> 00:26:40,440
especially in the Apple ecosystem

428
00:26:40,700 --> 00:26:42,600
side of things, and they found a way to replace

429
00:26:42,860 --> 00:26:44,240
trusted macOS app

430
00:26:44,900 --> 00:26:46,640
executables, and they actually demoed this with Signal.

431
00:26:46,840 --> 00:26:48,600
Let's say you download Signal onto your machine

432
00:26:48,640 --> 00:26:50,020
or anything. Again, this isn't a

433
00:26:50,940 --> 00:26:52,420
knock-on signal. This can impact any

434
00:26:53,140 --> 00:26:53,960
executable with this

435
00:26:54,520 --> 00:26:55,500
kind of flaw.

436
00:26:56,300 --> 00:26:58,380
And so if you run a malicious app or script

437
00:26:58,520 --> 00:27:00,300
on your Mac, and it'll replace them

438
00:27:00,640 --> 00:27:02,380
with malicious versions. This doesn't

439
00:27:02,520 --> 00:27:04,279
require your Mac's password or any special

440
00:27:04,300 --> 00:27:08,060
approval, and it can happen entirely in the background. Accessing protected data still

441
00:27:08,240 --> 00:27:11,800
requires your approval, but the macOS system prompts show the trusted app's name and icon,

442
00:27:12,260 --> 00:27:16,240
making the requests appear to come from the real app. It's a lot more interesting than that if you

443
00:27:16,240 --> 00:27:20,180
want to get into the technical details. Again, it's a very well-written blog that I do recommend

444
00:27:20,420 --> 00:27:24,300
checking out, especially if you're more technical. But Apple has concluded that the

445
00:27:24,560 --> 00:27:28,280
behavior does not constitute a security issue for the following reasons. One,

446
00:27:28,350 --> 00:27:32,200
the proof of concept replaces the entire application bundle rather than modifying an existing

447
00:27:32,220 --> 00:27:36,180
signed executable. The attack requires code execution as the current user and only affects

448
00:27:36,440 --> 00:27:40,920
applications opened by that user. The replacement executable does not inherit the original application's

449
00:27:41,060 --> 00:27:44,660
entitlements, and Apple considers convincing a user to approve these prompts to be a matter of

450
00:27:44,800 --> 00:27:49,180
social engineering rather than a bypass of their security mechanisms, and Gatekeeper is designed

451
00:27:49,180 --> 00:27:53,360
to evaluate downloaded applications before their first launch. So there's kind of an ongoing debate

452
00:27:53,560 --> 00:27:57,700
of whether or not this is something that Apple should patch or not. Okay, everybody, and now we're

453
00:27:57,700 --> 00:28:04,540
going to get into the open source updates starting with proton pass and this one is quite interesting

454
00:28:04,820 --> 00:28:10,000
and it's an autofill improvement here so it can autofill on sites where it previously couldn't

455
00:28:10,200 --> 00:28:15,780
including shopping platforms social media sites forums and banking websites and it just they

456
00:28:15,980 --> 00:28:20,440
improved the way that they detect forms on the websites you're visiting what i really want to

457
00:28:20,480 --> 00:28:24,780
know is if it's going to work with apple if you guys know there's like a very notorious thing where

458
00:28:24,820 --> 00:28:28,340
logging into an iCloud account only works with Autofill and Safari.

459
00:28:29,440 --> 00:28:32,520
So let me see if I can actually test it myself right now.

460
00:28:32,800 --> 00:28:35,060
Oh my gosh, dude, guys, no way.

461
00:28:35,220 --> 00:28:36,760
I'm literally on Apple's site.

462
00:28:36,920 --> 00:28:39,700
I'm obviously not going to show you because I don't want to reveal my credentials.

463
00:28:40,240 --> 00:28:41,320
It's in a different browser window.

464
00:28:42,320 --> 00:28:45,240
But Autofill now works on iCloud.com.

465
00:28:45,360 --> 00:28:48,980
So for any of you Apple users out there who have kind of caught that Apple doesn't really

466
00:28:49,200 --> 00:28:54,060
agree with much Autofill, ProtonPass, I just confirmed, now works with iCloud.

467
00:28:54,140 --> 00:28:58,500
They also have a liquid glass animations and some other updates there, which I think are

468
00:28:59,080 --> 00:29:01,260
not the highlight changes, but pretty good stuff overall.

469
00:29:01,760 --> 00:29:04,640
Tails 7.1 got a new shutdown procedure.

470
00:29:04,880 --> 00:29:09,360
Tails is the anonymous operating system that is ephemeral, and it's a bit slower, but it

471
00:29:09,440 --> 00:29:10,120
prevents data loss.

472
00:29:10,340 --> 00:29:13,960
So the power off confirmation dialogue informs you an application needs to be closed or an

473
00:29:13,980 --> 00:29:15,320
open document needs to be saved.

474
00:29:15,640 --> 00:29:19,260
Even if you don't confirm, Tails will still shut down after 60 seconds, which is what my

475
00:29:19,460 --> 00:29:20,020
first thought was.

476
00:29:20,520 --> 00:29:23,020
Tails is theoretically used in emergency situations.

477
00:29:23,140 --> 00:29:24,340
So how does that play along?

478
00:29:24,860 --> 00:29:27,040
They replaced Gnome Videos with Celluloid,

479
00:29:27,140 --> 00:29:29,160
which is a more modern and reliable video player.

480
00:29:29,580 --> 00:29:33,040
It looks like they have some other just minor updates that go along with that.

481
00:29:33,320 --> 00:29:36,240
Thunderbird hit version 153, which they're titling Meadow,

482
00:29:36,440 --> 00:29:37,720
and it launches with a smoother setup,

483
00:29:38,340 --> 00:29:40,240
Thundermail integration, and more.

484
00:29:40,540 --> 00:29:42,600
Seems like they have some nice appearance updates.

485
00:29:43,420 --> 00:29:46,340
They now work with native support from Microsoft Exchange email servers.

486
00:29:46,820 --> 00:29:47,740
There's quite a few other changes.

487
00:29:48,000 --> 00:29:49,860
So if you use Thundermail or Thunderbird,

488
00:29:50,020 --> 00:29:51,120
I would definitely check this one out.

489
00:29:51,200 --> 00:29:56,840
This is a quick signal boost that there's a new Firefox Nova UI with the return of compact mode.

490
00:29:57,070 --> 00:29:59,980
I actually made a whole video on the main Techlore channel.

491
00:30:00,150 --> 00:30:02,960
So if you're on YouTube, I'll leave a card for it.

492
00:30:03,160 --> 00:30:06,860
Or if you're on the podcast, I'll leave it in the show notes.

493
00:30:07,520 --> 00:30:10,880
But I did a whole first look at this new Nova UI in the nightly version.

494
00:30:10,950 --> 00:30:14,680
And I kind of walked through what it looks like, what the differences are, and compare it to regular Firefox.

495
00:30:14,890 --> 00:30:19,520
And I do want to remind people that most likely this is going to eventually be a downstream thing, right?

496
00:30:19,720 --> 00:30:21,800
like Mullvad browser will eventually inherit some of this,

497
00:30:21,980 --> 00:30:22,760
Tor browser, et cetera.

498
00:30:22,900 --> 00:30:25,380
And so this is kind of the new direction for Firefox.

499
00:30:25,760 --> 00:30:28,680
So I kind of detail what I like and don't like about it.

500
00:30:28,980 --> 00:30:30,080
So I would check out that video

501
00:30:30,080 --> 00:30:31,240
if you want to learn more about this.

502
00:30:31,600 --> 00:30:32,460
Collabora Online,

503
00:30:32,800 --> 00:30:35,020
which is an online collaboration document thing,

504
00:30:35,160 --> 00:30:36,540
think like Microsoft Office,

505
00:30:37,100 --> 00:30:39,500
but in the cloud and open source,

506
00:30:39,840 --> 00:30:41,080
adds optional AI assistant

507
00:30:41,240 --> 00:30:43,200
and smarter document comparison and review.

508
00:30:43,260 --> 00:30:44,420
And so if you use Collabora,

509
00:30:45,060 --> 00:30:45,920
definitely go check that out.

510
00:30:46,360 --> 00:30:49,920
Now we also have Wine that hit version 11.14.

511
00:30:50,620 --> 00:30:52,740
You can find a changelog down in the show notes.

512
00:30:53,100 --> 00:30:54,740
And that everybody is going to wrap up

513
00:30:54,960 --> 00:30:56,140
this week of surveillance.

514
00:30:56,310 --> 00:30:58,620
A lot of interesting stories, a lot of AI stuff.

515
00:30:58,890 --> 00:31:01,320
We had other interesting things outside of the AI stuff.

516
00:31:01,640 --> 00:31:03,740
So thank you all for tagging along on this journey.

517
00:31:04,090 --> 00:31:05,860
If this analysis helped you reclaim control,

518
00:31:05,930 --> 00:31:07,000
you can become a Techlorian

519
00:31:07,030 --> 00:31:08,400
by visiting a link in the show notes.

520
00:31:08,430 --> 00:31:10,220
You'll gain access to our private signal group.

521
00:31:10,220 --> 00:31:11,780
You'll get some other perks in our community.

522
00:31:12,280 --> 00:31:14,640
And regardless, if you want a newsletter version of this,

523
00:31:14,880 --> 00:31:17,020
like you just want something quick in your email inbox

524
00:31:17,260 --> 00:31:19,220
that's maybe quicker to forward to your friends and family,

525
00:31:19,340 --> 00:31:20,800
or honestly, it's just really good

526
00:31:21,240 --> 00:31:22,040
for your friends and family

527
00:31:22,100 --> 00:31:23,740
if you know they're not gonna listen to a whole podcast.

528
00:31:24,180 --> 00:31:27,540
I do like a TLDR five-minute read of this podcast

529
00:31:27,960 --> 00:31:30,240
on our website every single week that's a newsletter.

530
00:31:30,520 --> 00:31:31,320
And it's free to access.

531
00:31:31,800 --> 00:31:32,880
It's not spammy or anything.

532
00:31:33,220 --> 00:31:34,020
So if you want that,

533
00:31:34,240 --> 00:31:35,620
I would really recommend checking that out

534
00:31:35,660 --> 00:31:36,980
and signing up down in the description.

535
00:31:37,140 --> 00:31:37,940
If you haven't already too,

536
00:31:37,980 --> 00:31:38,820
make sure to leave a rating.

537
00:31:38,980 --> 00:31:40,660
I know Spotify, if you're listening on Spotify,

538
00:31:40,900 --> 00:31:43,240
just click however many stars you like this podcast.

539
00:31:44,060 --> 00:31:45,720
And if you're on Apple, same thing.

540
00:31:45,940 --> 00:31:46,680
Just leave the rating.

541
00:31:47,540 --> 00:31:48,360
It really helps a lot.

542
00:31:48,360 --> 00:31:51,260
It helps for discovery and it helps me reach more and more people with this news.

543
00:31:51,590 --> 00:31:53,740
And I want to thank you all for listening, being here this week,

544
00:31:54,020 --> 00:31:58,160
taking your privacy and security and your digital freedom seriously for one other week.

545
00:31:58,460 --> 00:32:00,560
And I'll see you in the next episode of Surveillance Support.

546
00:32:00,740 --> 00:32:01,340
You're all awesome.

547
00:32:02,080 --> 00:32:03,120
And I can't wait to be back next week.

548
00:32:03,600 --> 00:32:03,820
See you soon.