A weekly live podcast from Privacy Guides - We cover updates on what we’re working on, privacy news from around the industry, and anything our community wants to share.
Privacy Guides is a non-profit, impartial organization that is focused on delivering the best online privacy advice and building a strong privacy community.
Apple Watch's new features may be
listening at all times,
and so is your LG TV,
but at least we have some good news
from Graphene OS.
All this and more coming up on This
Week in Privacy, number seventy,
so stay tuned.
Hello, everyone,
and welcome back to This Week in Privacy.
This is our weekly series where we discuss
the latest updates with what we're working
on within the Privacy Guides community and
this week's top stories that we've seen in
data privacy and cybersecurity while
answering viewer questions.
Get in the chat, everyone.
I'm Jonah,
and with me this week is Nate.
How are you doing, Nate?
I'm pretty good.
It was a good week on my end.
How are you doing?
Oh, you know,
I was out for the first half of
the week,
but trying to get caught up now.
But yeah, otherwise doing great.
Got some got some good stuff and we
got some good stories to talk about today.
So I'm excited about that.
Awesome.
Yeah, let's jump right into it.
I think you got the first story here
about the new Apple release.
Yeah, so this was reported by Wired here.
Headline is,
Apple doesn't want you to worry about the
new Apple Watch's listening features.
Apple announced on Wednesday that the two
smartwatches that they make come with four
opt-in audio intelligence tools that are
powered by audio gathered by the watch's
microphones.
They include sound and music recognition,
a conversation recap feature,
and live rewind,
so a user can see a transcription of
anything that was said in their
environment in the previous
Apple claims that all of them are built
to prioritize privacy and security using
the extensive infrastructure the company
has developed to protect its other Apple
intelligence and Siri services.
So how this works and Apple makes a
strong point to emphasize this in all of
their marketing uh they have created new
chips in these apple watches s-eleven
chips and they include a special memory
protected space that apple calls the
secure exclave which is
designed specifically for sensor data.
It actually is a chip that has been
in many previous Apple watches,
hence S-Eleven.
But the chip in the past was mainly
used for Hey Siri detection,
and now they've expanded it to do more
things.
So
This chip, the exclave in the S-Eleven,
it's an isolated buffer that Apple says is
inaccessible to the rest of the operating
system where the Apple Watch can hold and
process audio data in a protected space.
So the first
new audio intelligence feature that we'll
talk about is called Siri Recap,
which is definitely the most concerning
one for privacy.
I've seen a lot of discussions about this
online so far.
Siri Recap is a feature you can set
to be on all the time or on
certain schedules,
and it will generate recaps of every
substantive conversation that you have.
If it
basically detects a conversation that
you're in or around you.
Your watch is going to detect that in
that secure exclave.
It's going to begin recording that
conversation and securing it in this
secure exploits separate from the
operating system.
And then when the conversation is
finished,
that that audio is transmitted to your
iPhone using Apple's special new secure
Bluetooth pairing that they are
introducing this year.
And then the audio is immediately deleted
from the Apple Watch itself.
When the iPhone gets that data,
it uses local speech recognition and
language models on device to transcribe
that audio and then generate a minimal
version of that transcript that removes
non-essential elements like extra words or
repeated phrases.
And then the raw audio is immediately
deleted from the iPhone as well.
The last step is a safety model that
they run, which, according to Apple,
screens the text to omit potentially
harmful terms.
And from there,
that transcript is sent to Apple's private
cloud compute,
which will then perform more intense
processing to to make that recap happen.
So that transcript
Yeah, it creates a title and a summary,
which is then encrypted and sent back to
the iPhone and Apple Watch.
Apple says that Siri recap is built to
remove sensitive information like
financial data,
ID numbers or other personal identifiers
from its summaries.
So
That's certainly something we'll have to
get into,
but I'll talk about one other feature
really quick.
They also have a feature called Live
Rewind,
and this is a feature that lets you
ask your watch for a text version of
the last fifteen seconds of what was said
in your environment.
It uses the secure exclave buffer to
continuously hold audio on a rolling
basis,
where old sound is replaced by new audio
it doesn't amass.
And that feature is actually used right
now for Hey Siri support.
Again,
what pretty much most of these smart
devices or IoT devices like your like your
HomePod or like Alexa or whatever,
they all work by continuously recording
your environment and then parsing it to
see if you've said like,
Hey Siri or Alexa or now I've probably
triggered everyone's devices,
so you're welcome.
But yeah, that's pretty standard.
What Apple is doing here is basically
giving you a button where you can actually
access that recording yourself on demand
instead of just using it for that Siri
functionality.
If you activate it,
the watch will send that buffered audio
from its secure exclave to the secure
exclave of the iPhone that you have
connected to.
If the iPhone is not available,
that transfer fails and the audio gets
deleted.
But if it goes through,
then the iPhone does on-device speech
recognition processing to make a
transcript of that,
and then it sends the text.
back to your Apple Watch where you can
read it or save it in the Siri
app for later.
So the article says it's hard to ignore
that in spite of all of these data
protections,
anyone wearing a new Apple Watch could be
seeking audio intelligence on, say,
your intimate event session,
private family update or accidental slip
up with a secret.
To try and mitigate blatant privacy
violations,
Apple says that the watch produces an
audible chime when a watch owner initiates
a live rewind transcript to alert other
people in the area,
even if it's in silent mode or paired
with headphones.
The features are built to omit or filter
out potentially identifying information
about speakers.
but the sheer scope and breadth of the
tools is extremely noteworthy.
I would also add that while that audio
indication happens when you use the
fifteen second live rewind feature,
there is no indication whether a user has
enabled Siri recap on their device.
A lot of stuff.
That's some of what's going on.
Let's talk about that.
Maybe I'll throw it over to you, Nate,
because I've talked for a while.
What do you think about these devices?
Can we trust any of this?
Oh, man, that's a good question.
So, I mean, a lot of this,
I mean,
I'm pretty open about the fact that I'm
probably the least technically qualified
person on the team.
So a lot of this stuff, I mean,
it sounds to me
Apple has at least made some effort to
not ever have direct access to the raw
data.
But I know that there are people who
have concerns about things like the – not
secure enclave, the private cloud compute.
That's it.
It's just – I'm sure there are loopholes
in it I guess is what I'm getting
at.
Yeah.
I do feel compelled to point out that
Apple has been caught lying in the past.
They said that like no person would ever
hear your Siri recordings,
but then they found out that there were
contractors who would like review Siri
recordings to like improve accuracy and
stuff.
And it's like, so what is it?
And so it's, I don't know.
I think I don't know how much I
would trust it,
but I think you really hit the nail
on the head with that last part there
is this is turning everything into like,
The world is becoming increasingly...
I watched a video earlier today where he
called it ambient surveillance.
And the world is increasingly becoming
that.
You just drive down the road or walk
down the sidewalk and six houses in a
row have a ring doorbell, right?
Or now people have the meta glasses and
they're walking around with them and...
you know,
you may not know who they are,
where they are.
And now this that like you pointed out,
it's like they might have the little
transcription thing turned on all day long
and you don't know that or, you know,
it's like, OK,
it makes a little chime when they do
the rewind.
That doesn't take back what I said,
though.
Like, thanks for telling me, but.
i don't know it's it's scary because it's
hitting a point where you know in the
past i i used to tell people like
uh because of all the data breaches i'd
be like don't write down anything that you
don't want to become public like don't put
it in a digital format and now we're
hitting a point where it's like you can't
even say anything that you don't want to
become public it's and that's not good for
me because i'm very talkative so i don't
know this this worries me for sure
Yeah, I mean, it's crazy stuff.
And I've definitely seen a lot of people
talking about this because it seems,
I think, uncharacteristic of Apple.
We've talked about similar features in the
past, like from Microsoft.
I think Microsoft Recall comes to mind
when you think about a recap situation
like this.
Apple would claim that their version is a
bit more privacy respecting because with
the always-on feature,
you can't get an actual transcript and you
can't access the recordings yourself,
unlike Microsoft Recall,
which would just record you typing in your
passwords and your bank account
information to be stored in some database
forever.
So there's changes like that, but...
at the end of the day,
it is placing a lot of trust in
Apple.
And it's also now requiring you to have
a lot of trust in the people,
people around you,
because you're really even if like
I mean,
there's just a lot going on with this
because I would have to wonder how this
even works with like two party consent
laws in different states or like it
catching or picking up conversations like
in the area that you're not even involved
in.
I'd be concerned about that from a legal
perspective.
It doesn't really make a lot of sense
to me how Apple can get around that.
Of course,
they have an army of lawyers to figure
that out.
So I'm sure that they've come up with
a reason,
but it doesn't seem to be the intent
of the law at all um so there's
there's that aspect of it and i am
concerned about that but also it's it's a
lot of reliance on all of the software
that apple makes in every step of this
to to work properly because there's a lot
of like theoretical features like it
should get rid of sensitive personal
information and it should only send um
like non-sensitive information to these
servers
and everything should be inaccessible to
people but at every step of the way
it's all apple designed software and it's
very hard to verify what's going on even
with um the the private compute cloud or
private cloud compute i always get those
words mixed up but whatever um
I recently found out that,
because I don't pay a lot of attention
to Apple intelligence,
but apparently private cloud compute is
not even using Apple Silicon anymore.
I remember they made a big deal about
that,
but now most of it runs in Google
Cloud on NVIDIA hardware.
Now you're trusting those trusted
execution environments,
which I think I've talked about in a
previous episode.
I don't really like those either.
But Apple's implementation, in my opinion,
is even worse than a lot of the
open source trusted execution environment
setups that we've seen in the past.
Like the founder of Signal, Moxie,
has a service, doesn't he?
I don't remember what it's called.
Yeah,
was it Concave or something like that?
It's got to be something like that.
Yeah, I know what you're talking about.
Maybe you can look it up and let
me know.
But there's something like that.
There's some open source solutions where
you can kind of verify what's going on.
Apple has pushed this idea very heavily in
their marketing of private cloud compute
that independent security researchers can
do the same thing with their service.
It isn't really the case in practice
because Apple doesn't release the source
code for any of these things and they
don't really help out any security
researchers who are trying to inspect the
images.
So while they do publish the software
images and you can verify that their
hardware is running those images somehow,
I don't actually know technically how to
do that, but apparently,
Yeah,
some somebody smarter than me would be
able to do that.
But somebody smarter than me who does that
would still have a very hard time checking
whether those images themselves are
running trustworthy code,
which I think is a big problem in
the in the trusted compute space.
And also,
Apple can kind of update these at any
time,
much like
you know,
their own operating system updates.
So there is still a lot of trust
in Apple in what is going on here.
And there's also a lot of trust in
now other parties besides Apple,
like like Nvidia and Google,
that they don't have some vulnerability in
like Nvidia's trusted execution
environment setup that could allow this
information to be leaked.
So
I don't know,
it's it all seems to be built on
a lot of pinky promises.
And I don't really like this trend that
we have where a lot of data is
being sent to like cloud AI models and
GPUs where everything is processed off
device because it isn't as strong as like
the end to end encrypted features that we
expect from other cloud services.
And it's definitely not as strong as just
keeping everything local.
So
Yeah,
any of these features that integrate with
private cloud compute,
I'm not a huge fan of,
and this seems no different.
Yeah, totally fair.
Real quick for audio listeners,
Carrie jumped in in the chat.
It's Confer is the name of the one
from Signal.
But yeah, I'm with you.
And even like the thing that jumped out
at me when you were saying all that
is towards the beginning,
you kept saying the word should.
And it's like, even if we...
Even if we assume good faith on
everybody's part,
which I don't think any of us would,
to be totally honest,
because we tend to be a little bit
skeptical.
But even if we assume that Apple really
is doing their best and Google really is
doing their best,
and even if it was open source,
like you said,
there's just so many moving parts here
that anybody who's had any sort of a
technical job,
like I come from an audio background.
I know you've done a lot of networking
in the past.
like people like you and me are like
anathema to like, Oh,
let's just add a cable extender or let's
add this other thing.
Cause it's like, no,
that's another point of failure.
That's another opportunity for something
to go wrong.
I want in a perfect world.
I want one cable that goes straight from
a to B, nothing in between it.
And you know, in this case,
we've got like five hundred different
points between a and B and it's like,
Oh man, all it takes is one bug.
Some one thing that didn't get configured.
Right.
One, you know, it's the whole like, uh,
what's the saying?
Like,
the attacker,
the defender needs to get it right every
single time.
The attacker only needs to get lucky once.
And yeah, so it's just, it's, oh man,
it sucks.
Cause I, I appreciate that again,
if we assume good faith,
I appreciate that they are trying to make
this private and keep the hands out of
it,
but there's just so many moving pieces
that all it takes is one bug or
one mistake.
And now your data could be out there.
So yeah, I don't know.
And it's really interesting.
I was just going to say that the
video I watched earlier was from all
things secured and he made,
he made a really good point in the,
I guess I didn't watch the Apple release
myself,
but he had like a clip of it.
And the example they used for the,
what is it?
The instant replay feature or whatever is
like they were at a restaurant and the
server was,
listed off the like specials of the day
super fast so the guy like hit the
button and it brought up the transcript
and he pointed out he's like is it
really that hard just to ask the server
to be like i'm sorry could you say
that again could you slow that down a
little bit you know it's i don't know
it's weird it's like solving a problem
that doesn't exist
Yeah, I can see that argument for sure.
And that is kind of a weird use
case that they've been pushing a lot.
And I think that that was a strange
move.
I will say I was talking about this
on Mastodon with some people,
specifically the live rewind,
fifteen second thing.
And I think
that probably a more relevant use case to
people is gonna be like saving things in
conversations for later.
So like if you told me, hey,
you should check out Silo,
it's a super great TV show.
And then I would be like, oh yeah,
I should do that.
And I hit a button on my watch
and I tell Siri to save it for
later.
Otherwise,
people are taking out the notes app on
their phone to write something down and
that does interrupt conversations more.
Does that justify the feature?
I don't know.
But just to play devil's advocate,
I think there's at least one potential use
case that may be pro-social instead of
anti-social,
like all of these other use cases seem
to be.
Yeah,
everything else seems to be kind of
features that...
take away from having conversations with
people,
because I don't think it's that hard to
just ask people to repeat themselves or
remind you of what you had talked about
a while ago or anything like that.
Yeah,
just having AI kind of do all of
that for you is definitely the antisocial
approach to all of this stuff.
I'm really interested
in hearing from people in the chat,
if you have any opinions,
whether this is something or I guess
whether you understand how both of these
features work and if you're more concerned
about one of them or both of them.
I kind of feel neutral about live rewind
that fifteen second thing,
but the serial recap stuff is crazy,
crazy to me.
Yeah, I agree.
That one worries me a lot more.
It's just because like,
don't get me wrong.
I've been in like Zoom meetings where they
do the AI transcribe thing and it's really
great and it's really useful.
But that's also within a very limited,
you know,
one hour meeting or whatever to have that
thing just going all day.
And I actually thought of a story while
you were you were talking before.
I have a friend in Asia.
who sent a story to our group chat
about how, I think this was in Korea,
but I could be wrong.
Um,
I guess in a lot of those countries,
uh, some of their apps,
they've like really integrated facial
recognition.
And so there's a bank or, um, no,
it's like a coffee shop that had like
a little booth where you can order and
it scans your face and charges you.
And it,
it was so sensitive that it was
accidentally charging people in the
And so like people would go home and
check their bank account.
It's like you bought a seven dollar coffee
and they're like, no, I didn't.
Why?
It's so.
Yeah,
it's that's that's what worries me is the
people that are just like walking by
having a conversation or in the area.
And it's just I don't know, man, that's.
Not a fan.
Yeah.
It's really unfortunate, I think,
that Apple is doing this.
It seems to be very just against their
marketing ethos, right?
Because they try and position themselves
as the privacy company all the time,
and I'm not sure how they're going to
spin this.
But I...
can't see a lot of people not at
least acknowledging that this is a privacy
problem and that even if it's a privacy
problem that some people are willing to
put up with,
I think that erodes against their brand a
bit.
So it seems like a bad decision on
their end.
I hope you're right.
We'll see.
For audio listeners,
Kerry said here in the chat,
you know me, I'm an Apple guy,
but I agree with basically all the points
you made,
especially that we shouldn't normalize
recording other people.
Yeah, like Jonah said,
I guess drop your thoughts in the chat
and we'll circle back around in between
stories.
But we also still have the forum post,
which I think went out a little late
today.
Apologies for that.
But if you're a forum member and you'd
rather leave a question there,
I'm keeping an eye on that.
And speaking of the forum,
in the meantime,
we'll go to our first forum update here,
which is talking about an exciting feature
that Android is rolling out passkey
transfers between password managers.
And this did have a forum discussion,
but it also came with an article that
I will throw up on screen real quick.
This comes from nine to five Google.
So they said in the past transferring
credentials between password managers
involved downloading them into a usually
unencrypted file like a text or CSV,
which left them unprotected on your device
and pass keys in particular did not
originally offer a transfer method of thus
requiring you to manually recreate them
across multiple sites and apps.
I can confirm actually recently.
Myself and my wife were thinking about
switching password managers just as a
money saving thing.
And we quickly abandoned that because I'm
told there was a way to do the
passkey transfer,
but it's not very intuitive.
So I didn't know you could do it.
And it was just like, well,
I'm not going to ask her to recreate
all those passkeys.
But anyways, going back to the article,
it says Android wants to solve these
issues by offering an operating system
back transfer method.
And it works by you open your password
manager app.
You choose the option to either import or
copy your passwords and passkeys.
Somebody in the comments here on nine to
five Google pointed out that potentially
means you could have them in two places.
So that could be an easy way to
make a backup, for example.
They said the password manager will then
hand the task over to Android.
Android will automatically detect existing
password managers on your device and show
you which ones you can import from and
to.
And then once you tap continue,
Android will bring you to your existing
password manager to select, review,
and authorize the transfer.
Your data will be quickly and securely
transferred to your apps in just a few
seconds.
And there are screenshots here for video
listeners,
or you can go check out the newsletter
where we have all these links.
And it says that right now,
the transfer experience is supported by
Google Password Manager, One Password,
Bitwarden, and Dashlane.
Other partners can participate by
supporting the credential manager's
credential transfer API.
So hopefully we will see that roll out
to more people here pretty soon.
And we did have a few comments in
the forum thread discussing this.
So one user did point out it's pretty
limited right now because it's only got
like four password managers.
Jordan, our producer, added for now.
So hopefully it'll add more.
Another user pointed out,
let me actually pull up the link here
and see what's going on.
They said somebody quoted that...
The credential exchange format doesn't
appear to depend on Google services,
but they said they're not a hundred
percent sure about that.
And the question was,
how will it be rolled out on devices
that are no longer getting updates?
So there's definitely still a few
questions here, but I mean, overall,
I think this is,
Exciting news for sure.
As you all know from a recent video,
I am a huge fan of portability and
being able to very easily leave one
program,
move to another for any particular reason
that you want.
And I think this is a huge step
forward towards that.
I hope other password managers will adapt
it.
Before I hop into the questions,
did you have any thoughts on this story?
No, I think this is awesome news.
Like Kerry just asked,
is this using the credential exchange
protocol?
Yes, it is.
And that's been, you know,
been hoping to see something like that for
a while.
It was crazy to me that like in
this day and age, our best...
method of transferring all this stuff
between password managers beforehand was
just getting a CSV file with all of
your data in it unencrypted and moving
that around.
So I think anything that reduces that
lock-in, the better.
And it's great that
There are tools that are being built that
aren't just like,
import all of your data from your other
password manager and give it to us at
Google.
It's an interoperable thing where people
can use that to switch around more easily.
It kind of promotes good competition,
which I always think is a good thing.
So yeah, it's sweet.
It's good to have a standard way to
transport all this stuff,
especially with passkeys,
because I I'm a noted passkey fan.
I think people should be using them,
and this makes it much easier to use.
It also is like I've been concerned about
passkeys for a very long time that using
them, at least especially at first,
but even recently,
it really locks you into certain
ecosystems,
usually whatever your browser or operating
system comes with.
And now, like, even if you've been
stuck with like Apple passwords or Google
passwords or whatever for this all of this
time because it's very hard to transfer
all that stuff.
Now there's an escape hatch where you can
make a better choice than using your
browser's password manager.
So yeah, it's sweet.
I don't really have anything bad to say
about this.
I don't know how this works.
in like, um, Android though,
because I believe this is,
I actually don't know if this is built
into Android or if it's a Google play
services enabled feature.
Um, I'd have to look,
but I I'd wonder how this will work
on graph.
You know,
I think that's the main point I'm getting
to, and I guess we'll, we'll see.
Time will tell.
Yeah.
Hopefully it's not, uh,
it doesn't require Google services to,
like you were saying to avoid that lock
in and keep things a little more open.
Yeah.
Sound Dog left a couple of comments here.
He said,
I recently did one password to Vault
Warden on iOS and it was so painless.
And that is awesome.
And that's what we're hoping for is that
it will bring that same painless
transition to every system.
And you also said store your pass keys
on a physical hardware token.
That's not always an option for a lot
of reasons.
I mean,
there is like the cost of physical tokens.
There's, you know,
you might need an adapter possibly
depending on what kind of hardware you're
working with.
And yeah, I mean,
that's definitely the most secure way for
the record.
I'm not saying it's a bad idea.
I'm just saying it's good to have that
flexibility for everybody, for sure.
Maybe someday we can use this to move
them to a physical token.
That would be pretty cool.
Yeah.
And hello, Oddbite, who said,
I bet it's going to be GMS.
I hope you're wrong.
No offense, but I hope you're wrong.
I mean, Android,
I believe Health Connect is kind of a
similar feature for health apps,
and I believe that's built into Android
and not Google.
But I could be wrong about that, too.
I want to say you're correct.
Yeah, I think Android has,
for some of these interoperability things,
there is precedent for them to at least
do something.
But I don't know.
At least since it is a standard, I...
believe someone like Graphene OS in that
position would be able to build their own
implementation even if it's not supported
by Android itself rather than it being
locked down.
But it's not going to be a Google
Play Services API specifically.
But I don't know.
I guess we'll see.
On the topic of Android,
we do have some exciting news from
Graphene OS,
but we're going to get to that a
little bit later in the show.
And first,
we're going to jump into site updates and
what we have been working on behind the
scenes here at Privacy Guides this week.
So once again,
remember to leave your questions and
comments in the live chat or on the
forum.
I also have Signal open for our
supporters.
Keep an eye on that.
We'll get to those in just a moment.
But first,
I think one of our big pieces of
news this week is that we have a
new video out.
We got to interview someone really
awesome,
a name you may not be familiar with.
Her name is Melania Ensign.
And she's the founder and CEO of
Discernible.
And she used to do communications lead at
Facebook, Uber, AT&T.
And she ran the press department at DEF
CON for like a decade,
I think it was.
And I was really excited to do this
interview.
And it's actually, I think on YouTube,
it's already got like one point six
thousand or probably even more than that
by now,
because that was earlier in the day I
checked.
But yeah,
I was really excited to do this interview
because we got to talk about
Kind of a lot of the corporate stuff
that we don't usually get to talk about.
Like for example, you know,
proton will put out a blog or actually
I'll use a real example.
When proton got in trouble for,
or got a lot of heat,
I should say for there was a situation
where they were required to hand over
somebody's IP address that they use to log
into proton mail and
And people felt like their website was
really misleading,
like the marketing on their website,
kind of lulled users into a false sense
of security.
And I remember there was a big debate
over like, well, you know, it's a company,
they're going to do marketing,
like that stuff's going to happen.
And other people were like, yeah,
but this wasn't really worded well.
And so we have a lot of these
discussions all the time in the privacy
space.
And I thought it was really cool to
get to talk to someone who works in
a more the more corporate side of things
who's
not like a coder, not like a developer.
I love that we get to talk to
those people too,
but we kind of got to get this
other perspective and talk about like,
okay, well,
how do companies think about this stuff?
How do we align privacy incentives with,
you know, words?
How do we align privacy incentives and the
profit motive?
How do we bring those into alignment?
This was a really cool interview.
I'm really glad we got to get to
do.
I think it was awesome.
Like I said,
it's already got a ton of views.
If you guys have missed that one,
definitely, definitely check that out.
I think it was really good.
As a reminder,
we are currently working on a video about
the Apple versus the FBI back in
Maybe like me,
we're not fully paying attention at the
time because I was right on the cusp
of when I got into privacy,
and it was a lot.
And Jordan's putting a lot of work into
that video.
There's a lot of stuff to go through,
but that will be out soon,
and I'm very excited for that.
And now we'll turn it over to Jonah
to explain some of the other updates that
have been going on.
You are muted, amigo.
Oh, no.
Okay.
Yeah,
I just said I'm excited about that video,
too.
In other news, some news for this show,
this week in privacy,
we offer video podcasts on supported
podcast clients, including Apple Podcasts.
So if you listen to this show after
the fact or use a podcast client...
check it out and let us know if
it works uh if your client is supported
or whether it's working or not um but
that should be cool it's a good way
to distribute these videos outside of
youtube hopefully and maybe somebody will
find that helpful i don't know how popular
video podcasts are but it was a neat
feature that they introduced so i'm glad
we have the option now um
Yeah, in other news,
I've been working on more verified app
stuff now that I'm back,
so there's some cool stuff happening
there.
Otherwise,
I think there haven't been too many
updates to the...
to this site on GitHub.
But of course,
we always have these news briefs that we
publish to the website at
privacyguides.org slash news.
Freeride stays in the kind of cover news
stories that we don't really get a chance
to talk about.
here on the show.
So there's some stories like Microsoft
shattering another record,
patching nine hundred seventy three
vulnerabilities in September.
Alternate X dot com front end knitter
announces it will continue despite the
cease and desist order.
And of course,
every week Nate publishes these data
breach roundups where he goes through and
lists all of
All of the companies that have had data
breaches,
and there are always a surprising number
of them every single week.
You never run out of content, Nate.
Yeah,
that's a newsletter you can get subscribed
to if you want to just be aware
of all of that happening all the time.
Yeah,
I think I've been doing data breaches
since like twenty twenty one,
and I think there's been two,
maybe three weeks where nothing came
across my feed.
It's wild.
Pretty rare.
All the stuff that we work on,
it's made possible by our supporters.
You can sign up for a membership or
you can donate at privacyguides.org slash
donate,
or you can pick up some swag at
shop.privacyguides.org if that's what you
prefer.
Privacy Guides,
we're a nonprofit and we research and
share privacy related information and we
facilitate a community on our forum and
matrix and here on these live streams
where people can ask questions and get
advice about staying private online and
preserving your digital rights.
So with that out of the way,
let's talk about how LG TVs are spying
on you even when they're off.
And before we start that story, remember,
if you have a question about any of
these stories, even past ones,
or if you have questions unrelated to what
we're talking about,
feel free to leave them in the chat
because we will get to questions in
between all of this stuff as we can.
Anyways, Nate,
why don't you tell us more about what's
going on here?
Yeah, so this is fun.
I have an LG TV,
but at least it's an older one.
We'll talk about that in a little bit.
So I'm going to quote parts of the
article here, not the whole thing.
But basically,
LG smart TVs are almost constantly logging
and uploading data about owners and their
homes,
even when offline or in standby mode.
This comes from a YouTube channel called
Gamers Nexus, which...
I don't really follow,
but I will say I did go to
watch this video because I knew this was
a big story.
And I was like, all right,
I should probably go straight to the
source.
And it is a two-hour video,
but I will say they are very entertaining.
So if you have the time,
I would recommend checking it out because
it's...
It is not a dry watch,
and they really dig into their method
really deep.
So the company's TV sets scan Wi-Fi
networks from nearby devices,
record audio logs through their
microphones,
and use audio and video sampling to
recognize exactly what you're watching on
the TV from across inputs.
So basically, again,
they went down to Best Buy.
This is all in the video.
They went down to Best Buy.
They literally bought some TVs off the
shelf.
They hooked them up to Wireshark and did
some packet capture.
i don't think they did any man in
the middle um i think they mentioned
actually that they would love for someone
to help them with that uh but they
they did some detailed packet capture and
they said they saw that the tv was
scanning the local area network for nearby
hardware such as phones smart watches uh
they mentioned like printers tablets uh
like literally everything that was on
their network there in the office they're
like oh look there it is popping up
on the list um
And details of nearby Wi-Fi networks as
well, so like neighboring buildings.
And of course,
feeding that all back to LG's ad
solutions.
They say, perhaps more concerningly,
the TVs were capable of recording
microphone audio when in standby.
This continued even after the TV was
disconnected from the internet,
with audio files stored offline and
uploaded once a connection was restored.
And then the article says here,
the final piece of the puzzle is the
automatic content recognition,
which many of you may be familiar with.
This is actually pretty standard on as far
as I know, all smart TVs,
if not all of them, the vast majority,
I'm sure.
It's basically this thing where as you're
watching,
the TV will kind of
I'm oversimplifying here,
but they'll basically like take a snapshot
of a single frame of what you're watching
or sometimes even just a few pixels.
And they'll match that with their library
of known content.
So they can be like, oh,
you're watching Lord of the Rings.
And they can do it with like streaming
services.
They can do it with HDMI connections.
So it's not just like streaming stuff.
It's anything that's on that TV.
And they can snapshot it and be like,
oh, okay,
you're watching this and whatever.
Which I think is probably the purpose of
the audio recording.
Because then they can also match up the
audio with it.
Maybe to know what language you're
watching it in.
But I don't know.
Either way,
I think we can all agree that's super,
super creepy.
So, I mean, yeah.
That's kind of the bulk of the story,
I'll say.
It's one of those stories that there's a
lot to it.
But it's also very simple at the same
time.
Because it's very straightforward.
But I'm going to ask Jonah.
Do you think...
So I know,
like the most obvious answer would be
like,
we'll just unplug it from the internet
forever.
But for those people who do like
streaming, I mean,
are there any defenses against this?
Or is that kind of our only choice?
yeah it's it's really tough um none of
these smart tvs have really shown
themselves to be trustworthy i know we've
seen this acr stuff in in the past
with like vizio and other manufacturers
for example so it's not exactly new
although the scope of what lg is doing
is is pretty crazy but
really the only like the best solution to
this is to not use these smart TV
features and use a dedicated device that
you have plugged into your TV to watch
this media.
The problem with that
that I have is that there aren't a
lot of good devices you can plug in
either.
If you happen to trust Apple,
which maybe a lot fewer people do after
our first story we talked about today,
you can use an Apple TV and that
tends to have less tracking than most of
these other devices.
But if you're in like...
The only it's like with the smartphone
situation,
the only mainstream things you can get are
either Apple or Android TVs or Roku's,
neither of which are privacy respecting at
all.
So
Yeah, there's not a lot of options.
There's certainly open source options.
I actually just bought some hardware after
this story to test out a Linux-based
solution.
I think that there are do-it-yourself
options out there,
but unfortunately on the market,
I don't really know of a lot of...
great options for people to just buy off
the shelf at the moment,
which is a which is a shame.
I think I will highlight this comment in
the chat really quick.
What found said it would be great if
we could get some custom firmware for TVs.
That would be the the most ideal solution.
It would also be great if other,
you know, smart streaming boxes existed.
But oh, well.
Yeah,
can't wait until we have a Linux version
of a Roku stick or something.
Actually, yeah,
a couple questions on that.
Foundog said here further down,
even a cheap Fire TV or Roku stick
is better than something you can record.
Do you know by any chance?
Because I don't know.
Are the Roku sticks and stuff like that,
they wouldn't have the ACR capability?
They definitely would have the capability
to do ACR.
And also...
With that integration,
ACR is mostly a concern on smart TVs,
for example,
because you could just be watching normal
TV over the air,
and the TV would have no idea what
you're watching because it doesn't have
that metadata.
With something like Roku,
Roku's going to know what you're watching
because you're using the system to stream
something,
and so they have all of that metadata
themselves.
But they could also be doing ACR,
whether their lower-end devices are
capable of it.
Maybe not.
I actually don't know how resource
intensive ACR is.
I'd have to look into that.
But I wouldn't.
I would not.
Roku has a lot of its own privacy
issues.
So and if I actually
I feel like we talked about Roku recently,
how they were like there was a pop
up saying they were enabling ACR on all
of their devices.
So I think they actually did do that
recently.
I'd have to look at this news,
but I feel like it was just sometime
this year there was Roku news that we
talked about.
So I think they are literally doing this.
That would not surprise me because I have
a Roku.
Those are the only two TVs I have
for the record.
And one of them was free from my
last job.
It was a TV we took down that
it was like, well, if nobody takes it,
we're going to throw it out.
So anyways, yeah,
I was poking around the Roku the other
day and I'm like,
when the hell did they turn ACR back
on?
I was kind of pissed about it.
So.
Yeah, that could have been it.
Yeah, what Kerry just said.
ACR is exactly that.
It just is a way to figure out
what you're watching from what's on your
screen.
And it's definitely being used mainly for
marketing purposes.
They're just trying to sell your data,
get your habits about what you're doing
for advertising reasons.
not fantastic,
definitely not pro-consumer.
There's not really a lot of reasons for
ACR to exist that would benefit you.
I can't imagine anything because for you,
you know what you're watching,
so why would you need ACR?
It's just one of those bad business
practices.
No,
but it's so convenient because then they
can try to get you to watch other
movies to waste your time with.
Yeah.
Um,
here's something I've actually been
wondering since I read the story is,
do you know, I know they're very,
very imperfect,
especially the ones that are widely
available because they,
they want to cause as little breakage as
possible.
But do you think like DNS block lists,
like the kinds you can put on your
router would do anything,
or is this probably immune to that?
Um, I mean,
I mean,
the DNS block lists aren't foolproof.
I don't know how these connections are
being made with LG,
like if they require this DNS resolution.
But obviously, DNS block lists,
they're not blocking actual connections.
They just block this directory that tells
the device where the connection has to go.
So if LG has hard-coded in IP addresses
or anything like that,
or if they've even hard-coded in their own
DNS servers,
unless you block all other DNS traffic on
your network...
It's it's not foolproof.
And these block lists,
while they're great,
I think people should try it using a
pie hole on their network if if they
can and see how it works for them,
because it's better than nothing.
And you should always have like
multiple layers of defense,
like a browser ad block and DNS blocking
and all that stuff.
It is still taking a blacklist approach to
all of these networks.
And if it's not on the blacklist for
some reason,
these connections that they're using,
then it's not going to work.
And I would imagine a lot of these
default lists probably aren't going to
block all LG connections because
They probably don't want to block like TV
updates.
I think people would probably complain to
the blacklist manufacturer manufacturers
to block list writers if it if it
blocked a lot of functionality like that.
And so if LG is using the same
channels to
to perform all of this as they are
for updates,
then it's not going to block that at
all.
So it's really hard to block, I think,
first party connections with a DNS block
list like that.
I think the safer option is to just
not connect it to the internet again.
Yeah,
but I know in my house that's not
an option.
My wife would be very mad.
Yeah,
and one other thing I had written down
in the notes here is I mentioned I
do have an LG.
It's an older one.
It definitely does not have a microphone
or a camera.
But even then,
I have no doubt in my mind that
it's still doing the network scanning and
the ACR.
So I just wanted to remind everybody,
check your settings.
It's obviously not foolproof, but...
Oh no, we lost Nate's camera somehow.
We'll wait for him to figure that out.
In the meantime,
Foundog KDE Big Screen is out now.
Yeah, I'll have to check that out.
The one that I was going to look
at was OpenELEC.
It looks...
pretty cool.
I'm definitely someone who I have an LG,
OLED TV, little break,
but that that I don't connect to the
internet,
but I would want to have a device
that supports like Dolby Vision and some
other stuff for my Plex server because I
have high quality media on there.
And
open elect supposedly supports all of that
proprietary stuff somehow i don't know how
they're doing it but that's something i
want to check out but i'll have to
check out these other linux solutions as
well um if there are other like home
media pc solutions that people know of um
definitely let me know if you want me
to check it out too because i'm getting
some well i got some different hardware uh
open elect runs on like
Android devices, basically,
which is very convenient.
You can just kind of flash it on
a lot of different devices,
whereas some other solutions require a
whole PC,
which has less support from some like
streaming services and stuff.
But
But yeah,
I don't know if Nate's going to make
it back here.
Nate says he forgot to plug in the
fan on his camera and it overheated,
so it's going to cool off and he'll
be back.
He says he can do audio,
but I don't have any audio from him.
Maybe he's muted or it's not working.
Oh, Nate's here.
Okay.
It's not great audio, but it's there.
You're back.
All right.
Maybe you could turn off your camera so
we can see a profile picture instead of
these color bars.
Hi.
Yeah,
I'm not sure if there was anything else
that I wanted to talk about with this
LG story.
Oh, there you are.
Changing my microphone back to the good
one.
Um, yeah, no, I'm,
I'm glad you called out the, uh,
the plasma thing.
I definitely want to check that out.
Thank you for mentioning that.
Whoever that was.
Um, did you, sorry,
I was running around looking at the
camera.
Did you mention found dogs thing here
about using a fire stick would make the
ACR not work on other inputs?
yeah i guess uh that's certainly true i'm
not a gamer so i forget about that
sort of use case but i mean even
so um it's tough when i think you
know the majority of things that people
are doing on these tvs is streaming these
days and streaming services themselves are
not like amazing and it'd be nice if
there were more private options or if
Yeah,
I don't know what to do about that.
There's a lot of problems in the media
space.
Just in terms of licensing more than
anything else,
it's it's hard to have a good solution.
But all of this incessant marketing stuff
and advertising stuff on top of it is
super not great.
Yeah,
that was kind of one of my thoughts
early on when we were talking about even
even things like this,
this plasma big screen, which, again,
I do want to check out.
But I remember at one point I was
using a Raspberry Pi and I had the
Kodi app set up,
but I could not get it to sync
with Jellyfin properly.
So I still couldn't really do anything.
And even then, it's like, you know,
my wife still wants to watch like
Crunchyroll sometimes.
And it's like, yeah,
it's just it's hard to find a good
solution that works in general.
But.
Streaming is such a crap show right now.
Yeah.
Um, Cody, Cody was always tough.
I mean, for,
it was never really built for like
streaming stuff in mind.
So I'm hopeful that all of this other
stuff might be better.
I haven't tried out a lot of Linux
stuff lately.
Um, since switching to Plex pretty much,
but it'll be good to try it out
again.
Uh,
Carrie just said something that I think
I've seen a lot of people say,
I'm worried that TV makers are going to
start including modems built right in.
So even if you don't hook it up
to the wifi, yeah, for sure.
That's a,
that is a concern I have seen.
Yeah.
I can certainly see a lot of IOT
devices doing that in the name of
convenience, which is unfortunate.
Before we jump into the next forum update,
Jan Modal,
sorry if I pronounced your name wrong,
asked if there's any noteworthy
developments about the developer
verification program from Google.
Have you heard anything about that?
I haven't heard anything in like months.
I have not.
I don't think anything's going on.
I keep seeing the banners on websites that
come across lately,
but it doesn't seem like Google is going
to make any,
or they haven't made any moves there so
far, which is tough.
Yeah, unfortunately.
I agree.
Let me check the signal chat real quick.
Okay.
So next up,
we're going to jump into another forum
update,
and this one actually came from Kerry
Parker.
Uh, there's another, uh,
website associated with this one that I'm
going to throw up real quick.
So Carrie posted in the forum mentioning
the Commodore callback,
and this is a flip phone, uh,
which as you can see on this,
this scrolling banner here is very
nineties looking, but, uh,
it runs Android.
And it's basically designed to
specifically block like social media and
distracting like doom scroll apps.
So it's designed to give you the
flexibility of Android, you know,
for things that you actually, um,
I would argue you might conceivably need
like, you know, Uber or your banking app,
but it's designed to be a roadblock here.
So for example,
it says it's got a T nine style
texting, so it's not easy to text, um,
But it does still support music and
camera.
It blocks social media.
It says it runs Sailfish OS,
which I believe is a type of custom
Android operating system.
So yeah, less pop-ups.
When you have it closed,
only certain pop-ups will show up on the
little front screen there that you can see
on that picture.
But yeah,
it's a interesting little concept.
And I kind of wanted to bring this
one up.
So Kerry said that he pre-ordered this
mostly because he thinks it's a cool
concept and there seems to be a growing
market for dumb phones or at least less
smartphones.
Another user did point out kind of the
pros and cons.
They said like, you know,
it costs five times the price of other
four G dumb phones,
but it does include better memory and a
way better camera.
They said that they would probably just
get an offline digital camera and a sixty
dollar dumb phone.
They also pointed out there's light phone,
the punk phone,
which I remember the punk phone is
basically a dumb phone,
but it does come with signal.
And basically they asked Kerry to keep us
updated once he gets his.
And yeah,
I guess I'm interested in this because I
think I agree that I see a lot
of people from all ages, me personally,
at least.
I feel like I'm running into more and
more people who are like,
very dissatisfied with the technology the
state of technology um you know i just
saw a couple weeks ago apparently last
year cds had like a rise in sales
like a record like people are more and
more going back to analog but at the
same time like me knowing what i know
about privacy and stuff it's like yeah but
i don't want to fully go back to
like sms for example and not have signal
um
Um, and, and there are, like I said,
there's a handful of apps that I do
still genuine.
Like my wife and I went somewhere new
just yesterday that we'd never been
before.
And I needed a map,
a navigation to get there.
And, you know,
but we do that so rarely.
It's like,
do I really want to invest in like
a, you know,
an offline garment or something?
So I don't know.
It's just, it's really interesting,
I guess, for me to, um,
kind of think about what is that right
balance.
And, uh, you know,
I'm also admittedly interested in like,
I have, they're not my kids,
but you know,
I have nieces and nephews that I want
to be able to help their parents.
Like, Hey, you know,
when they're old enough,
like here's a phone that won't necessarily
give the internet access to them.
As somebody once said,
I forget where I got that from,
but so yeah, I guess just a,
an interesting,
interesting to think about like where,
where you try to draw the line between
privacy, but still being accessible,
but still having some of those security
benefits.
So, um,
Yeah.
Real quick, Nate.
Did you say it runs Android or did
you say it runs Android apps?
Because people are saying in the chat that
it runs Sailfish OS, which is true.
But I didn't catch what you said.
I mentioned that Sailfish is a,
if I understand correctly,
it's a type of Android.
No, no.
Sailfish is a Linux OS, actually.
They've been around a while.
There's like a...
It's big in Europe.
I've talked about it on a previous episode
because I'm kind of annoyed with them that
you can't.
It's not very accessible in the US.
It's kind of an EU specific thing.
Although, can you buy this in the US?
Maybe this will be the first time it's
kind of officially coming to the US.
I mean, you must be able to.
Kerry said he pre-ordered it.
Oh, yeah, I guess.
My first question when I saw this product
was, what is this a callback to?
Because I don't think Commodore made
phones,
but I guess it was the callback to
the general feeling of in earlier time.
I guess, yeah.
That's a really good point for sure.
Oh, you're right.
Linux-based,
encrypted and no hidden data sharing.
Oh, whoops.
Okay.
I apologize.
Thank you for correcting me.
Yeah.
Sailfish has always had...
like this Android emulation layer,
basically.
I remember Blackberry tried to get into
that too before they went away,
and I don't know if any of that
emulation stuff has really worked super
well, but I don't know.
Anyone who uses Sailfish OS on a different
device, let me know.
Yeah, for sure.
Yeah, it's interesting.
Like I said, I don't know.
I'm...
Me personally,
I'm fairly confident in my tech use and
I'll admit, you know, it's, it's a swing.
Sometimes I do find myself like, okay,
I'm on Mastodon a little too much.
I need to dial back, but it's, uh,
I I'm more interested in for other people.
Like it's, it's very helpful to have, um,
you know,
not to dig too much into pop psychology
right now, but they,
they call it commitment devices where a
popular one is like for personal finance.
I'm sure you've heard this one, Jonah,
that like,
if you use your credit card too much
freeze it like literally like stick it in
a Tupperware container with water and
freeze it and then next time you want
to use your credit card like you have
to thaw it out so it slows you
down to think and I think it's cool
that we're getting more devices like this
but yeah um
Yeah,
I guess if that is something that is
helpful for you,
then then more power to you.
It's something that has never really made
a lot of sense to me.
I know there's like a huge campaign.
I've talked about this with with some
people,
but like in the in the security space
against like scammers online and there
there's a campaign,
it's called like Take Nine, I think,
or something like that.
And it's like,
just read something and take nine seconds
to figure it out.
I'm like, I don't think
just waiting nine seconds is really going
to stop a lot of scammers.
And in a similar way,
I don't know if freezing your credit card
will stop you from spending a bunch of
money on random stuff.
But if that helps you,
if making life more difficult
intentionally with something like a
Commodore callback will help you use your
phone less and you want to use your
phone less, I guess...
I guess this is the phone for you,
I don't know.
It's probably not something that I would
be buying personally,
so I don't have much more to say
about it.
Yeah, same here.
I'm with Kerry.
I think it's really interesting,
but I can't justify it myself either.
I'm just kind of like, I don't know.
But anyways, yeah,
I just thought it was interesting and
worth talking about.
But I guess if we want,
we can go ahead and head into the
next story.
I guess I did have written down here,
if anybody has any comments about how you
approach phone privacy while still being
accessible, definitely let us know.
Kerry did say real quick, for the record,
this will not be replacing my main phone.
Foundog said,
I've recently made the switch to Graphene.
I've been really enjoying the positive
friction it's introduced.
No constant notifications,
less access to apps that encourage doom
scrolling.
Yeah, for sure.
Graphene's very,
very minimal when you first install it,
for sure.
And that's a good starting point.
I will say to Carrie's point there about
it not replacing the main phone,
this is a big reason that I have
not really been into any of these minimal
light
lightweight phones because this seems very
inconvenient to me to be switching between
things all the time and also like then
you have to keep messages in sync between
devices which is crazy it's funny because
we're talking about apple earlier at their
event they introduced a feature called
iphone handoff which basically lets you
share a sim and a number and messages
between two different iphones i don't know
how many people were clamoring to buy two
iphones but
That would be a cool model if something
like that could happen between an Android
phone and a minimal phone like this,
if they're able to replicate that in a
more open way on the Android side of
things.
And work with carriers,
because Apple has kind of put in the
work to get this going on the eSIM
side of things.
now Android is It's it's more possible for
somebody to build a feature like this
since that back-end technology is going to
exist at least with T-Mobile I think
there's interesting opportunities there
because I think For one reason or another
it could just be wanting a minimal phone.
I think more people are using two phones
these days and so Yeah,
that's just that sort of handoff in
automatic synchronization between devices
would be would be pretty cool to have
and
FoundDog said to Kerry Parker,
sounds like a fun day challenge for the
podcast.
That would be funny.
But actually, yeah, speaking of phones,
I'm going to turn it over to you
to give us the latest on this new
graphene story.
Yeah,
I'll look at an article that Freya wrote
about this based on some
Social media posts from Graphene OS.
Graphene OS will overhaul default apps and
implement a secure keyboard.
AOSP right now includes some basic apps
such as the gallery app that technically
function but have mostly been abandoned.
google themselves use their own
proprietary apps for photos messaging etc
on the operating system for their pixel
devices even even the dialer android is
not a real phone anymore on its own
but graphene os says that they're
overhauling or fully replacing the rest of
the aosp apps in the near future one
of the sticking points that they plan on
addressing is rcs messaging support in
their default messaging app
Previously, if users wanted to use RCS,
they would have to install Google messages
and give it potentially sensitive
permissions.
Despite RCS not being a, quote,
open platform in practice,
Grafina OS says that they plan to
implement it along with end-to-end
encryption support.
RCS is...
you know,
I'm not a huge fan of RCS,
but it is absolutely a huge usability
improvement over SMS and end-to-end
encrypted messaging support would let you
have secure cross-platform messaging by
default,
which would be an improvement certainly
over the status quo.
Graphene OS is also scaling up
improvements to the base operating system
as well.
Of particular note is their new secure
clipboard that will prevent apps from
being able to see other apps' clipboard
content without permission,
which is great because that is a huge,
risk factor when using like a password
manager or any other sensitive stuff.
So Graphene OS is always doing very cool
things on the Android side of things.
So yeah, this announcement,
it's all very early on.
I don't think we don't have a lot
of details about how they're doing this.
I know I signed the chat on byte.
I don't know where this message was,
but was talking about
There we go.
These claims are interesting because right
now RCS is very locked down to Google's
kind of closed ecosystem.
I believe to this day the only approved
messaging apps that can interact with RCS
at all are Google Messenger and Samsung's
messaging app.
As opposed to SMS,
which the Android platform has always let
other apps replace your default SMS app
since the beginning of Android.
Basically,
they really locked that down with RCS this
time around because they want to be a
monopoly.
So how Graphene OS is going to get
around that exactly?
Not incredibly clear to me.
Samsung shut down their messenger.
Okay, so that was originally,
but I guess it's just only Google now.
Yeah.
I'm sad to say currently my brother has
a Samsung phone,
and I remember when they shut down their
messenger, he texted me, and he's like,
what should I use?
And I'm like, I hate to say it,
but the Google app.
He's not a heavy signal user,
so I'm like, yeah,
at least you'll get some RCS encryption
and stuff,
but
Yeah.
It's really annoying.
The Google app on Stock Android is
annoying because it kind of opts you into
all the Google account stuff by default,
at least if you install it on Graphene
OS.
Since Google Play Services isn't there,
it's not there.
Because you're signed into your Google
account automatically in all Google apps
on Android normally,
and that app is no exception.
You have to go and follow the prompt
first.
Yeah.
unfortunate stuff which sucks because i
remember years ago uh on surveillance
report we covered a story about how it
doesn't see your content but it basically
records all the metadata so they know
exactly what messages you're sending to
who and when and it like hashes the
message so it again it doesn't see the
content but it hashes the message and then
it sees that same hash on both recipients
and it's just like come on guys really
this is ridiculous but
So actually, on that note,
I had it written down as a question,
but I guess I just answered it.
I said here,
is RCS better than a dedicated app such
as Signal or SimpleX?
Which the answer is no,
because Signal and SimpleX don't do that
kind of crap.
So it is cool that people are getting
a little bit better protection, I think,
with the proliferation of encrypted RCS.
But it's definitely no replacement for
these kind of things.
I will say, though,
and I'll ask you this.
I tend to be a very not picky
person most of the time.
So what is wrong with the existing AOSP
apps other than being apparently
abandoned, which is definitely not good.
And I think that should be fixed.
But like, I don't know,
is there going to be like a UI
design that like when it drops,
I'm going to be like, oh, wow,
I didn't know what I was missing.
I mean,
the stock gallery on Graphene OS is
insanely bad, in my opinion.
I downloaded, I think it's in a Crescent,
but it's somewhere.
I think it's like Avis Gallery or
something like that.
I don't know.
It starts with an A.
You should just download that and compare
it to the gallery app and then see
if the UI is a game-changing experience to
you.
But I had to do that because navigating
the normal gallery app was just painful.
I mean, it's definitely not great.
I don't know if I'd go so far
as to say it's painful,
but it's definitely nothing about it makes
me like, oh, this is cool.
It's just like, okay, it's a gallery app.
It's whatever.
Yeah.
It says they dropped it today.
I must have missed that.
Did you see that?
I'm going to have to download it.
Yeah, I didn't know.
I'll have to... What was this?
Yeah, where was that?
I think it's today.
I mean, same.
My Fridays are always dedicated to
prepping for the podcast,
but I'll poke around.
I'll see what I can find.
Oh, it's in alpha.
Okay.
I tend not to do alpha software.
I might wait.
I'll probably wait.
At least until beta.
I wish I had my pixel on my
desk here,
but I don't have it within arm's reach,
so I can't take a look.
But people are saying it's good in the
chat, so that is a very good sign,
I think.
Does it support RCS?
It better.
That's the whole point.
Well, I didn't know.
Maybe it's coming in a future update.
I didn't know if they figured it out
already.
Oh, that's a good point.
Yeah.
Oddbyte said earlier it kind of works with
the UIs from, like, O five.
You're right, no RCS, not yet.
Interesting.
We will see how they do it.
Indeed, indeed.
Most indeededly.
They are all, like,
I'm trying to think of what the gallery
app even is.
It literally would be, like,
Android three or something.
Not two thousand five.
Oddbyte is not old enough to remember.
iPhones, smartphones coming out, probably.
I was going to say,
how would you remember that?
I mean, the first smartphone,
the iPhone came out in two thousand seven.
So, you know,
you got to add a few years to
that.
But yeah, it's it's all old stuff.
It's those the stock apps are not great.
I fun fact,
I had a first gen iPhone.
Really?
I did.
I was my buddy.
Like first day.
Oh no, no, no.
I see.
Okay.
This is why my buddy talked me into
it because I was in bootcamp when it
came out.
And my, my,
my friend pointed out that like,
cause he also went into the military,
same branch.
And he,
he has actually the one that convinced me
to join.
But he pointed out that like,
that's the perfect thing because it
dropped like right as I went into
bootcamp.
And then he's like,
by the time you get out,
they'll have like worked out all the bugs
and everything.
And of course, when you're in boot camp,
you're just making straight money with
nothing to spend it on.
So you get out with like a few
thousand dollars and you're eighteen and
stupid.
So like I got out of boot camp
and I was like, you know,
and I knew I was going to be
moving around a whole bunch for a while.
So at the time,
it was right on that cusp where like
landlines weren't fully gone yet.
But I was like, well,
I'm not going to have a landline anytime
soon.
I'm going to need a cell phone.
And so I was like, yeah, why not?
I have the money.
The bugs should be worked out by now.
So I bought myself a first gen iPhone
with
unlimited data through at&t because that
was the only choice of carrier back then
crazy to have carrier exclusive phones
well the funny thing to me is that
it was unlimited data they don't even do
that anymore i mean now they do they
throttle it now but you know back then
it was like that was the only plan
it was
It was expensive.
But, you know, I was a TV single.
You probably couldn't milk a lot of data
out of that two G three G connection
at the time.
So probably find an offer.
That's a good point.
It was mostly my space back then.
Anyways, that's all I got.
Yeah.
I don't, uh,
I I'm,
I'm really curious to check out the
messaging app.
Um, is it,
when you say who said that it's very
good,
found dogs said it's very good in the
chat.
Is it just because it like matches current
design, like the Google messages app?
Like how, how is it better?
What did they do?
Jonah, we should do a,
a first look video.
First look at the Messenger app.
Yeah!
Maybe when RCS comes out,
they should figure it out.
But yeah,
if they expose an API for third-party apps
on Graphene OS to use it... Yeah,
I mean...
I don't understand RCS at all,
so I can't really weigh in on this.
I don't know why GrapheneOS can do this
and nobody else seems to be able to.
But maybe it's just a skill issue on
Cape's part.
Oddbyte works at Cape doing something.
Sending messages on Signal, I think,
is Oddbyte's job.
Chilling Cape.
Yeah.
The thing that bugs me about this kind
of stuff is I'm,
I'm into the whole V a voiceover IP
thing where like, I've got a number for,
well, it used to be work, you know,
back when I did like audio video stuff.
And then I've got like a number set
aside specifically for like my bank and my
doctor and all the like super important
stuff.
And then I've got like, you know,
I've got a couple of numbers.
I don't have as many as I used
to, but so for me, it's like, okay,
I could use something like this,
but then I'm going to go back to
using a SIM number,
which I don't want to do.
So yeah.
Yeah.
It's tough.
I don't know what I want.
I want both.
I want voice over IP that has RCS.
Yeah.
It is...
I've always thought it was crazy that they
don't add support for it in Google Voice.
I mean,
that feels like an obvious place to do
it.
But whatever.
Google is inexplicable to me.
Oddbite said it's because DroidGuard is
why...
Because that's why they can't do RCS.
Yeah, DroidGuard is...
I don't know,
Google has a million names for the Play
Integrity stuff,
so whatever component it is.
But Graphene OS has its own problems with
Play Integrity and Droid Guard and
everything,
so they have still figured it out.
So I think if they can do it,
other people can too.
Maybe not, I don't know.
I'm very interested to see how they do
it,
and hopefully they publish more about how
they're doing it.
And hopefully it's not like a hacky
workaround that Google can block
instantly.
I feel like it might be.
Beeper had this problem with iMessage
support on Android where, yeah,
it worked until Apple figured it out,
right?
It's not a very reliable setup.
I mean,
the one nice thing I will say about
beeper is I remember that incident.
Basically they have to man in the middle
of your messages to make it work.
They like convert it to an iPhone
basically.
And I appreciate that.
Uh, I never used it myself,
but I heard multiple people say that like,
it does straight up warn you when you
go to sign up for it.
It's like, Hey, just FYI,
technically we can see all your messages.
So make sure you trust it.
Like AdGuard does the same thing.
They, um,
if you have an ad guard license and
you install it on like an,
I think it's an Android only.
I don't think iPhones can do this,
but they're basically like, Hey, you know,
if you want to like really kill all
the ads, like including in app and stuff,
you need to like enable this feature.
And then when you go to enable it,
it's like just FYI,
you're basically turning us into a man in
the middle and we can see all your
traffic.
And we just want to make sure you
know that I'm like, all right,
at least I respect the transparency.
So yeah, I digress.
Yeah.
I got nothing else.
Take a look at the form really quick
here.
See if there's any questions.
Anyone else have any questions in the chat
that you want us to get to before
we wrap things up?
I don't know if we have another don't
think we have another story after this
kind of a slow news week except for
some big stuff.
Yeah,
I was gonna say it's a little shorter
of a week.
So I'm sad there's no silo tonight.
I was just thinking that yesterday.
That's been my ritual for the past ten
weeks is I do the podcast and then
I go watch Silo and I'm like, well,
now what do I do?
Oddbite's sharing some more stuff about
RCS.
Yeah, I mean,
it does seem like Graffianos will have to
spoof things.
I don't know.
if there's precedent for that,
it seems like an approach that they
wouldn't normally like to do.
But I don't know,
I feel like they're somewhat doing that
with like the place and sandboxing
already.
So it makes sense.
It just,
I don't see how it'll be reliable.
But graphene OS thinks it is and they
are very talented.
And they've been doing this for a lot
longer.
And I'm just kind of speculating.
I'm not an RCS expert.
So
Should be cool.
Should be cool to see.
Fair enough.
Precedent is Micro-G.
Yeah.
Hopefully they implemented better than
Micro-G, though.
I mean,
precedent in terms of Graphene OS doing
something.
Graphene OS famously,
not a fan of Micro-G either.
Oh, Micro-G had an RCS implementation?
Interesting.
I did not know that.
I probably never went anywhere.
Yeah,
they said it was just in a PR,
not merged.
I feel like that makes a lot of
sense.
There's always age verification stuff.
Yeah.
Oh, you know what?
Oh,
I think it just came in today and
it didn't even occur to me,
but we should have mentioned California
signed their stupid age verification law.
Yeah.
Recently I saw they also exempted, um,
open source operating systems from it.
I don't talk about that last week.
Yeah.
Did you, I missed the actual story,
so I don't know.
Did,
did they list out actual software licenses
in the law?
Cause that seemed kinda,
that's what I read in like a,
an article about it,
but it seems like a weird approach.
Um, I mean,
I didn't read the law itself,
but that's what I read too.
Yeah.
I guess there's just some chosen because a
lot of people in the in the open
source community are using some weird
licenses.
And now we're kind of just going to
be stuck on a few.
I don't I mean,
I don't really have a problem with these
open source licenses.
So I think it's fine.
But it's an interesting choice for sure.
Well, it's, I think it's any,
any license that like,
I don't think they listed specific like
MIT three point Oh, a GPL, whatever.
I think they just listed like anything
that's, um, licensed to be like reused,
uh, freely distributed.
So I mean,
there's a significant number of like
pretty much any open source license as far
as I know would fall under that.
But yeah, I would hope that's true.
That's probably true.
What I had read was that they did
list it out,
but I think I didn't get that from,
I did not get that from a reliable
source.
I mean, again, you could be right.
I didn't look at the law itself,
so who knows?
And now I'm reading the news.
That seems like a bad idea.
Anyways.
I'm really trying to.
Yeah,
I'm just looking it up to see if
I could find it anything with that
California law.
I'm like control F.
Nothing about licenses is coming up.
Oh,
so I guess I'll have to look into
it later.
Oh, it does.
Okay.
It does just say it doesn't refer to
entities that distribute an operating
system or application under license terms
that permit a recipient to copy,
redistribute, and modify the software.
So, good.
Yeah.
Will privacy guys recommend HaloCard on
the wiki?
Great question.
I have not looked into HaloCard too much
myself.
I would have to check in on the
forum thread about that because typically
our recommendations are at the whim of the
community consensus.
But we'll have to take a look at
that again and see what people think.
But yeah, I just wanted to be noted.
Yeah.
I looked up HaloCard in BraveSearch
because I'm like, oh,
I don't know if I've heard of this.
The second result is TrustPilot and the
preview.
Setting up HaloCard on GrapheneOS was
easy,
although it required JIT enabled in
Vanadium and affordable.
I've definitely seen HaloCard.
That's one of the first things that pops
up.
It's been mentioned quite a bit in
GrapheneOS chats, I think.
I don't think it has special support for
GrapheneOS,
but they've talked about being a
tap-to-pay provider for GrapheneOS in the
future,
which obviously GrapheneOS doesn't have
right now.
So people are certainly into that idea.
I think a lot of GrapheneOS users would
like to see a tap-to-pay payment option
from someone.
I mean, I'm already seeing, if it's legit,
I see advantages over privacy.com.
Physical cards, a shared balance,
spending limit of up to a million dollars
a day.
Yeah,
that's definitely a problem that I have.
Let's see.
Apple and Google Pay,
privacy has that now.
Three D secure and refunds.
I don't know about that,
but four more features.
What are we missing?
Custom billing address, custom card name,
top up cards, crypto, bank transfer.
Interesting.
This is very, very interesting.
I'm going to look into this myself.
I got to turn over my passport.
I can't do it.
Yeah,
there is identity verification fault.
I have not heard of Walt,
but I'm looking at it right now.
Somebody is developing a tap to pay
wallet.
Well, I know there's that.
Oh, I was about to say,
I know there's a European-based one that's
supposed to be like an open standard.
I think this is this.
They have exploration of U.S.
product fit in their twenty twenty seven
roadmap, but they haven't launched yet.
And it looks like it'll be.
eu only at least i don't know if
it's every eu country but some of them
um they do say they're going to market
to all eos graphene and sailfish os users
so i guess they are really getting in
on the on the privacy focused operating
system side of things but that'll be cool
that will be great i don't think this
is the one i was thinking of just
because launch that does not seem like
I was thinking the one that it's like
a collaboration between like Mirena and I
think like Fairphone and Jolla or Joya or
whatever.
So I don't think this is them.
But I mean, hey, I welcome competition.
I think it's cool.
Ain't no need for a cookie banner.
We ain't tracking you.
Launch that shit.
Yeah, Oddbite,
is this your tap-to-fay app?
That would be cool.
I don't understand how they're doing it on
iOS.
Oh, I suppose...
Yeah,
the EU has made them open it up.
True, true.
I love that.
Ain't no need for a cookie banner.
We're not tracking you.
No, I was joking.
Real quick,
Foundog did say that Curve works in the
UK for a Graphene OS tap to pay.
So not an official endorsement,
but if you're in the UK,
you might want to look into that.
Yeah, there's some other...
I don't know what they are because I'm
not into EU,
but I know some specific banks have built
Tap to Pay into their apps in their
specific countries.
But not something you can just use with
any card.
Whereas Walt apparently looks like...
I don't know if they're going to offer
cards or you can use any card.
I guess it's not very clear from their
website.
Oh,
it says you can add some cards too.
Looks like they have both anyways.
Um, yeah,
I'll have to keep an eye on that.
It looks like they don't really have
anything right now,
so there's nothing to really check out,
but odd bite and found dog both said
that curve is not really great for
privacy, but it's more of a,
it's just an option for digital.
Yeah, I digress.
Does Curve,
are they the ones that let you do
virtual cards in the EU too?
Or is that a different company?
I don't know if Curve does,
but I know Revolut does.
Revolut is what I was thinking of, yeah.
They're not very privacy respecting
either,
but there's some benefit to that anyways.
I mean, to be fair,
I think there's valid arguments that
privacy.com is not super privacy
respecting,
but they claim not to sell your data.
And it's, it's about,
it's a different threat model.
You know,
that's what I always tell people.
It's like,
my goal is not necessarily to be private
from them.
My goal is to like,
not have my card numbers sold.
Cause I've actually had.
Yeah.
Years and years ago,
I bought tickets to a concert and I
used a privacy card,
I used a simple login alias,
and then I think I used a fake
address too.
And sure enough, six months later,
I got an email that's like,
so we had a data breach.
And I'm just like, whatever, I don't care.
Turn off card, turn off email.
And it's not only that risk,
but also we talk about this a lot
on our website with these virtual card
providers.
It's also just a matter of marketing.
You don't want...
the data to be linked between accounts if
there's multiple data breaches and your
card is in both of them,
or if they're using that for marketing
purposes or whatever,
like a hash of your credit card number
or something.
So anything you can do,
it's just like using an email aliasing
service, which themselves,
there's the trade-off where now they can
see all of your incoming email,
but also the benefits of not...
you know,
needing to use the same exact email
address,
use the same exact credit card with all
of these different things that you sign up
with is very useful.
I've been using a new credit card lately
because I don't use privacy.com because I
like using credit cards instead of debit
cards.
I think they have better consumer
protections.
Anyways,
the new one that I'm using lets me
create unlimited virtual cards, though,
and it's been super helpful.
I think I have like fifty already.
Nice.
Well, I think that's all we got.
I'm not seeing any questions in the forum,
not seeing anything on Signal.
Well,
then I guess we can wrap things up.
As usual,
all of the updates that we talked about
on this week in privacy,
we share them on the blog every week.
So you can sign up for the newsletter
or subscribe with your favorite RSS reader
if you want to stay tuned and read
the sources for everything we talked
about.
We also offer a podcast available on all
podcast platforms and RSS,
which now includes video on supported
platforms.
Again, check it out,
let us know if that works for you.
And we sync the video
to PeerTube for anyone else who wants to
catch the recording and doesn't have a
supported podcast client.
Privacy Guides, again,
we're an impartial nonprofit organization.
We're focused on building a strong privacy
advocacy community and delivering the best
digital privacy and consumer technology
rights advice on the internet.
If you want to support our mission then
you can make a donation on our website
at privacyguides.org slash donate.
You can also make a donation on any
page on the website by clicking the red
heart icon located in the top right corner
of the page.
You can contribute using standard fiat
currency via debit or credit card or you
can opt to donate anonymously using Monero
or with your other favorite
cryptocurrency.
Becoming a paid member unlocks exclusive
perks like early access to video content,
exclusive video content,
and priority during the This Week in
Privacy livestream Q&A.
You also get a cool badge on your
profile in the Privacy Guides form,
and the warm,
fuzzy feeling of supporting independent
media.
Thank you all for watching,
and we will see you next week!