This Week in Privacy

Reddit is forcing users to login to view old.reddit.com, discontinuing it's RSS feeds and ending public API access killing privacy preserving third party clients. We'll be covering the latest in privacy & security news, so join us for This Week In Privacy #73!
  • (00:00) - Intro
  • (00:39) - Start of podcast
  • (01:41) - Reddit is putting more limits on old.reddit.com
  • (24:46) - Cops Can Bypass iPhone's Automatic Reboot to Get Into Locked Phones, Leaked Video Claims
  • (48:14) - Forum Discussion: Chat Control 2.0 Updates
  • (52:15) - Site Updates
  • (01:01:31) - This study looks at how and with whom connected cars share your data
  • (01:27:11) - Forum Discussion: How often are people sending encrypted emails?
  • (01:33:16) - New Attack Can Track You Across Operating Systems Without Elevated Privileges
  • (01:42:01) - Q&A
  • (01:46:47) - Outro
ā˜… Support this podcast ā˜…

Creators and Guests

Host
Jonah Aragon
Program Director
Host
Nate Bartram
Digital Producer

What is This Week in Privacy?

A weekly live podcast from Privacy Guides - We cover updates on what we’re working on, privacy news from around the industry, and anything our community wants to share.


Privacy Guides is a non-profit, impartial organization that is focused on delivering the best online privacy advice and building a strong privacy community.

Reddit further erodes anonymous usage,

cops can now bypass the iPhone's automatic

reboot,

and a new attack that can track you

across all operating systems.

All of this and more coming up on

This Week in Privacy number seventy-three,

so stay tuned.

Welcome back to This Week in Privacy,

our weekly series where we discuss the

latest updates with what we're working on

within the Privacy Guides community and

this week's top stories in data privacy

and cybersecurity while answering viewer

questions.

I'm Nate,

and joining me this week is Jonah.

Howdy, Jonah.

It's been a minute.

Yeah, it's good to be back.

And I've been having a good week with

the video stuff that's been going on.

That's been going well for you.

So I hope we could talk about that

later.

But how have you been doing?

Pretty good.

Yeah.

Just, uh, busy with the videos.

Um, like you said,

we'll talk about that later,

but we put out a couple of videos

in the last couple of weeks and we

got more on the way and, um, yeah,

so I mean, good week for sure,

but definitely keeping super busy.

Sweet.

All right.

Yeah, I think with that,

we'll go ahead and jump into the latest,

biggest news from privacy and security in

the past week.

As a reminder to any viewers,

if you have any thoughts or questions

while we're going over the story,

feel free to leave it in the chat

and we will address them at the end

of the story.

So first up,

we're going to talk about Reddit.

And this headline,

this comes from Ars Technica,

says Reddit is putting more limits on

old.reddit.com.

So back in July,

some of you may remember that Reddit

started requiring that users be logged in

to access old Reddit,

which real quick for anyone who doesn't

know for now,

we'll see how long this lasts.

You can literally go to old.reddit.com and

it's the old version of Reddit.

It definitely looks kind of dated these

days, but it's also a lot lighter.

I think there's like less JavaScript.

I think there might even be less trackers,

but don't quote me on that.

But most notably,

It's usually also a lot less strict about

requiring you to sign in.

Some of you may know that if you

try to go to Reddit right now and

you're not signed in,

and especially if you're using a VPN,

it's probably going to block you and force

you to sign in.

Old Reddit didn't do that.

So a lot of privacy people preferred old

Reddit because, again, it was lighter,

it was a little bit less of a

nightmare, and no sign-in required.

But now...

uh the article says today but this is

you know a few days old it says

that the social media platform announced

additional upcoming restrictions on old

reddit a reddit post from an employee said

that in the next few months will further

limit access for logged in users to only

those who have used old reddit in the

last six months which covers the majority

of all old reddit users so if you

want to be grandfathered in now is your

time to uh go log in they said

there will be an exception for moderators

who are still able to view old reddit

regardless of when they last log uh last

used it as long as they are logged

in

And they claim that this is basically to

help reduce scraping and automated abuse.

Yeah.

The article says that there's concerns

that they may completely shut down old

Reddit one day, which...

Yeah, well, let me see here.

Yeah, I mean,

I guess we're at that part of the

article.

It does say down here that in twenty

twenty five,

Huffman said the old Reddit would remain

online as long as people are using it.

But in August, he changed his tune,

saying in a post that the reality is

we're getting to a time where we need

to make some changes.

And those changes would probably include

limiting access,

migrating important uses and rebuilding

old Reddit on a modern tech stack.

So I guess technically it doesn't sound

like it's going anywhere,

but it may not survive in a noticeable

form.

And then.

This is the one that really pissed me

off.

They kind of threw this in here at

the end.

But Reddit is also going to stop

supporting RSS feeds on November,

because RSS is now a common surface for

large-scale scraping and automated abuse.

It will still be available for moderators

who use it for workflows through supported

alternatives,

which I think they said there's an app

called Discord Relay and some other stuff.

Yeah, that's super, super nifty.

I think that's kind of it as far

as stories go or as far as details.

Jonah,

I think I'll turn it over to you.

I know like you, for example, you say,

if I remember correctly,

you're not a super big Reddit user.

And I personally,

I kind of go through phases.

Like right now,

I've actually been on Reddit quite a bit,

but I'm probably going to stop using it

a little bit for a while.

So why does this matter for people like

you and soon to be me who may

not be heavy Reddit users?

Well, you know what?

I think I'm kind of in the same

boat where I use it kind of off

and on.

The reality is I've experienced this a lot

lately where a lot of just niche

information is still only available on

Reddit.

It's just been such a prolific form for

such a long time that

A lot of discussions are still taking

place there,

and especially if you can find older

discussions about things like from two

years ago or something,

instead of all of the AI slop that

is now kind of permeated the search

results.

I think that those Reddit results tend to

still be a bit better,

which is it's a shame that it's all

locked down into that one ecosystem.

But that is, of course,

the main business strategy of Reddit and

why they can make changes like this

because people are kind of stuck using it,

you know?

Yeah, for sure.

The RSS thing really pissed me off because

to me that is just such a

it feels like, um,

what's the word I'm looking for?

Uh, like,

like a canary in a coal mine of

like the direction that the web is headed

in where the web used to be this

open.

And it's funny cause like, I remember, um,

I'll be honest,

I don't know how old you are.

So you may or may not remember this,

but when I was about in high school,

so about like the mid two thousands, um,

RSS really popped off in the mainstream.

And it seemed like every single website

you went to had RSS.

And I didn't even know what it was.

It's almost like apps.

When apps popped off in every single

website, it was like, download our app.

And so every website I went to was

like, we have an RSS feed.

And now what's funny is a lot of

them still support RSS,

but they just don't broadcast it that same

way anymore.

So I don't know where I'm going with

this.

With them saying we're not going to do

RSS anymore, to me, it's just such a...

like it feels like they're just really um

like the whole web is turning into this

walled garden you know like twitter

requires logins now uh facebook and

instagram have required it for a long time

now reddit's doing it it's really sad to

see the internet getting increasingly

siloed and closed off like this and super

turning against what the web was supposed

to be especially considering who was

involved in the founding of reddit but

yeah

Yeah, social media definitely, I think,

played a big part in people moving away

from like personal websites and blogs and

that sort of thing.

It's funny,

I was just watching a video about it

was from I don't know when it was,

two thousand one or something.

It was a video of Steve Jobs kind

of announcing the first Apple store that

they opened and they were selling software

like create your own personal website.

Like at the time,

that was just the thing you would do

online.

And now that's kind of been

uh you know centralized onto all of these

platforms because people don't want to

people don't want to do that but that's

at the risk of um you know these

platforms being able to do whatever they

want with your content at at any time

um and obviously i think reddit is really

no different than a lot of other social

media platforms in the sense that they

have

just awful data practices.

They're doing all of this crazy stuff with

like tracking you across the site.

It's obviously an advertising supported

platform,

and then they're also using that content

on the back end to sell it to

AI companies for for training and stuff

like that.

So

Yeah,

that's kind of just not a fantastic

situation that they've created.

And this is just kind of another anti-user

approach to things.

It's unfortunate that everything just kind

of needs an account these days just to

access.

But we've talked about that with Twitter

or X switching to that as well.

Reddit is kind of no different.

And yeah,

I'm sure this is going to upset

some contingent of Reddit users.

But I think Reddit in general has just

been going downhill for some time.

And I don't know if old Reddit really

saves people from a lot of the stuff

that they're doing.

Fair.

Yeah, I'm glad you mentioned the AI thing.

That was something I wanted to make sure

we mentioned.

Reddit struck a deal with,

I think it's OpenAI,

and now they sell user data to OpenAI

to help train the models.

And

Yeah, real quick,

I do remember those days.

Like you were saying back then,

there were things like GeoCities that were

real plug and play.

And like you said,

everybody had a website.

I think MySpace was probably the first

time that really took off because they had

that ability to inject CSS code and

customize your page.

But even before that,

it was pretty common to run into people

who had a random, you know,

for whatever reason.

So...

Yeah.

I also just want to point out,

I know you kind of touched on this

at the beginning, but unfortunately,

there are still some privacy projects who

only or primarily use Reddit or sometimes

Discord.

Proton.

That's exactly who I'm thinking of.

They're not the only ones,

but they're probably the most prominent

one.

Yeah.

So even when we step back from the

privacy stuff, we think like, oh, well,

you know, we don't need Reddit.

Like, you're right.

We need them to get the memo, though.

It's really frustrating.

So I think that'll bring me to,

you know,

is there anything that we can do about

it?

Are there any alternative platforms?

Or do you think it would help to...

Is there any kind of protest or anything?

In some cases,

like the one you just mentioned with

Proton and these other companies who are

using Reddit as, like, their main...

news announcement form for whatever

reason.

I think it's kind of unfortunate.

Getting them to switch would be great.

But there are alternative ways to access

Reddit.

FoundDoug in the chat mentioned RedLib as

a good self-hosted frontend for Reddit.

We do recommend these frontends for

accessing a lot of social media sites on

a read-only basis.

I don't know if there's...

I haven't looked into...

red lips specifically too much.

I don't know if there's public instances,

but stuff like that that can kind of

abstract

the content of the site away from like

Reddit running a bunch of JavaScript in

your browser and tracking you,

I think is generally a good thing to

do if you're just trying to access Reddit.

But I would certainly just I mean,

because this is what we do and I've

been a big proponent of, you know,

websites and organizations kind of

starting their own forms,

running their own blogs and comment

sections and kind of having their own

communities separate from

these major platforms,

because if you do everything on your own

domain name and you kind of do it

yourself,

that as a as an organization or a

business that provides you with a lot of

safety because you're not just at the

whims of however the business that you're

trying to use operates.

And I think that a lot of people

don't realize that because from a short

term perspective,

you know, having all of this,

all of these tech resources available for

free and very easy to set up,

it's obviously appealing.

But at the same time,

Um, it's just,

it's just a way for you to basically

send all of your users or all of

your customers to these other platforms

who will eventually lock you away from,

from those users,

from your own users and customers.

We've seen it on like Facebook,

for example,

where everyone was like encouraged to make

Facebook pages.

And then all of a sudden,

now that everyone's on Facebook.

Now,

if you want to communicate with people on

Facebook effectively as a,

As a business, for example,

now you have to pay Facebook a bunch

of money for advertising, right?

That's the main goal of really

locking people in to these platforms,

I suppose.

So certainly there's some Fediverse

alternatives.

I'm not super familiar with a lot of

them.

I haven't used them recently,

but Lemmy's around and I know some

communities use that.

I'm a big proponent of Discourse,

the form software.

Thankfully,

I've seen a lot of open source

communities,

especially like Linux distros,

kind of adopt Discourse as the de facto

form software of choice for a lot of

these and for good reason.

I think it's a good.

setup for organizations and businesses.

And of course,

we use that for our form,

discuss that privacy guides.net.

So stuff like that, setting that up,

having going back to like a more

decentralized web,

I think benefits a lot of people,

I think it certainly benefits users.

But it also has a lot of benefits

for businesses to kind of get away from

these from the social media sites that are

shifting to more predatory practices,

I think.

Yeah, for sure.

I think, um, with like, uh,

like discourse,

that's probably not ideal for like a

Reddit replacement per se,

like from a user perspective.

But yeah,

especially when we think of like bigger

projects, like, uh, like Linux distros,

proton Tudor and like places to get help

and tech support.

Like, yeah.

Discourse is,

I think really good for that.

And I think, um,

I think we'll talk about this probably

more in the site updates,

but I left a comment last night on,

uh,

our latest video on the forum where the

comments, uh,

it felt, uh,

cause for those who don't know,

our last couple of videos have gone fairly

viral.

They've,

they've gotten a pretty good reach and

they've also been very polarizing.

And so I commented on the forum.

I'm like, man,

it's really nice to see like sane takes

and like people that even though they

might disagree with us,

they're not like calling me names or

anything.

And it's just, it's so refreshing.

And people kind of pointed out, it's like,

yeah,

this is kind of like the way the

web should be like the future of the

web,

these smaller communities where people can

get along a little easier.

So it's,

I almost wonder if it would be good

for the internet to be a little bit

more, uh,

I don't want to say fragmented,

like decentralized like that.

So yeah, I don't know.

I think I'll turn that one over to

a viewer.

Yeah.

Oh, one more thing.

Yeah.

I found dog said Libra or red lib

was previously called Libra.

I definitely,

I don't know if you mentioned this cause

I'm trying to troubleshoot something over

here,

but I do wonder if they're almost like

a, what was it called?

The knitter, like knitter.

I do wonder how long these things are

going to be able to function when Reddit

is increasingly cracking down on this

stuff and

if they're going to get a cease and

desist.

But in the meantime,

I am all for that kind of stuff.

So yeah,

I think we'll turn it over to viewers.

If you guys use Reddit,

what are you going to do?

What are your recommendations?

Do you have something to add?

Those frontends are definitely a

short-term solution.

I mean, in the long term,

we just got to switch away from platforms

like this.

I know we have an announcement post on

our forum for this live stream,

like we do every week.

We've gotten some comments on the forum

from people who have talked about this

Reddit story.

There's mixed opinions, for sure, on it.

Somebody said...

that that sites that archive like deleted

comments on Reddit and stuff might lose

access because of this.

And that might be a privacy win.

I think that that's a little the I

mean,

there is certainly an argument to be made

a lot of the time.

So I think when you put out content

publicly,

I think people in general need to be

more mindful of content that's put out

publicly because a lot of the time it

does just exist kind of forever.

And so if you're really worried about

that,

There might not be much you can do,

but yeah,

I thought that was an interesting

argument.

Yeah.

I had a thought on that one,

but I don't remember what it was now.

This one,

I think we touched on this one a

little bit, but somebody,

a new user asked,

do you think the anonymous internet access

is becoming impossible and what can users

realistically do to preserve it?

Do you want to weigh in on that

one or want me to start?

Because I do have some thoughts on that.

I don't think it's becoming impossible in

a lot of areas.

I think age verification is certainly

causing problems in that regard,

and we may start to see it becoming

more difficult.

But at the same time,

I don't think it's an unreasonable burden

to switch to these more decentralized

platforms.

I think that's ultimately the solution is

to find or start communities outside of

Reddit that aren't going to be subject to

these onerous restrictions or requirements

to create an account that can be used

for tracking you and what you're browsing.

I would imagine for a lot of the

kind of stuff that people are doing on

Reddit,

having all of that tied to a specific

profile is definitely going to...

tell Reddit, tell advertisers,

tell the people that they're selling data

to a lot of stuff about you and

then tied with your IP address and that

kind of thing.

It's probably trivial to tie a lot of

that information to your real to your real

information.

And so, yeah,

just decentralizing all of that, I think,

is the long term goal to definitely to

definitely work on for for people in

organizations.

Yeah,

and one thing I want to point out,

somebody else responded and basically said

that.

They said the end game of all this

is self-hosting and federation.

And I totally agree with you,

but I want to add to that.

I'm not disagreeing.

I'm always the person who's like, well,

think about the normies and the people who

aren't super tech savvy.

And I think this is one of those

situations where actually those of us who

are more tech savvy can be like the

–

was, I'm not good with words today.

Um, but the anchor point, I guess,

for our friends, you know,

like if you know how to host,

like my, my sister, for example,

has access to my, my, um,

jellyfin server and she can just text me

and be like, Hey, it's not working,

you know, or whatever.

And it's,

it's super easy and she doesn't have to

handle any of it.

And so I think, you know,

there's certain things that like, um,

like switching to graphene or switching to

Linux, like,

or switching to proton mail, you know,

we need, yeah,

the user has to do that.

But when it comes to things like hosting

Mastodon or peer tube or, um, next cloud,

like those are things that you can do

and then manage for your friends and

family.

And, you know,

you kind of need to like,

you need to be upfront with them.

Like, um,

Like we actually,

I actually just installed a pie hole on

my network yesterday.

And I told my wife, I'm like,

just FYI,

technically I can see all the websites you

go to.

I don't really care.

I'm just looking for trackers and stuff

like that,

but I just want you to know.

And she did not care.

So, um, you know,

but like letting people know, like, Hey,

I have this cloud.

You're welcome to use it.

And I mean,

some people will probably take advantage

of that and be super entitled and crappy

about it, but you know,

other people will just like, Oh,

this is really cool.

Thank you.

And

you know?

So, um, yeah,

I guess what I'm getting at is like,

this is one of those rare situations where

like,

it's not so much every single person needs

to host their own Mastodon or, uh,

I think there's, what is it?

Plymora Plymora is like the lightweight

version,

but like you could host a small instance

and just give a few family and friends

access and that helps them out.

And they don't necessarily have to be

super tech savvy.

So yeah, for sure.

As found dogs that we can all be

big tech.

Exactly.

Yeah.

And that's super true.

I think people forget, um,

that like hosting forums in communities,

you could do that on like really low

end content back in like two thousand five

or so low end hardware back in two

thousand five.

Right.

I mean,

it's not like computers are super

powerful.

You could certainly host it on pretty much

anything today.

It's really not very intensive to host a

lot of these to host a lot of

this software.

Not that everyone can do it,

but just like you said,

I think it

can be on some of the more technical

people in certain communities to create

these platforms for other people to join.

It would be great if instead of the

movies subreddit,

if a bunch of people got together to

discuss movies on some site like that.

But it does require a lot of collaboration

and I know that people find that

difficult.

Well, and also just to add onto that,

I was going to say,

if you're hosting a small community,

like again, for like a family,

next cloud instance,

the beauty of that is you probably don't

need to pay a ton in storage because

you're not providing like five gigs for

everybody.

It's just, you know, a handful of people,

I guess,

unless you come from a big family, but,

um,

Yeah.

I was just going to say real quick,

Ben said I use RSS feed regularly to

get the best post without doom scrolling.

It's yeah.

Like RSS is so useful.

I used to, um,

I used to use it to get like,

Oh,

click the wrong button to get like news

feeds.

And then, um, I could filter out like,

uh, right now I use next clouds RSS,

which admittedly is not great for this.

Um, but Thunderbird used to be amazing.

I could filter out like sponsored posts

and ads and like all kinds of cool

stuff.

So yeah, RSS going away really sucks.

Um,

people are chatty tonight uh do you think

they could still get around this like like

knitter yeah we were just talking about

that earlier um right now we do have

a few reddit front ends but it's really

a question of like with this access

closing off are they still going to be

technically feasible and then if they find

workarounds like knitter did are they

still going to be you know are they

going to get hit with a cease and

desist so we don't really know at this

time um we'll just have to wait and

see but um let's see here sorry i'm

trying to read a whole bunch of things

um

Yeah,

somebody in the forum thread pointed out

that apparently the social media

propaganda is much stronger than we

thought it was.

And they actually provided a source for

that.

So that was pretty interesting to read.

I kind of skimmed that because it was

pretty long.

But I was like, oh, lovely.

So yeah,

maybe we should all just get off

mainstream social media.

It's probably not great.

Let me ask or read a couple of

these questions here.

Yeah.

Well,

this kind of goes back to what we

were talking about.

The problem is that the quote unquote

normies are unaware or simply don't care,

outnumber the rest of us.

So the experience on a wide range of

topics ends up being very limited.

Yeah.

I think that's the problem we're all

struggling with is like even something

like Mastodon, in my opinion,

is very feature rich.

It's very mature.

It's, in my opinion,

a very nice experience.

And it's like, well,

how am I supposed to get people?

It's like the network effect, right?

It's like, yeah,

but you can't follow Taylor Swift and Mark

Ruffalo.

Actually, Mark Ruffalo is on Mastodon,

but he hasn't posted in like

a year um you know like all these

big names that you want to follow it's

you can't really find them on a lot

of these other social media it's it's a

problem i think everybody's trying to

figure out yeah uh torsten on the forum

who's a member thanks for your support uh

just left a comment agreeing that like the

small web type self-hosting is nice but

they find it really intimidating uh

because you need to do so much stuff

to protect them protect those servers um

like if you use tail scale, for example,

to kind of limit that,

that's a good way to keep your things

secure.

But then that kind of limits who can

access it by design,

which is hard for communities like larger

communities.

I mean,

it is a tough issue for for sure.

And I think I think a solution for

that is not just like for a lot

of techie people to spin up things on

their own,

but I think people

You know,

coming together and creating a small

community of people who have technical

skills who can kind of work together on

that kind of stuff is going to be

a lot more sustainable.

But that's kind of where the collaboration

stuff comes in again,

at least if we're talking about public

things like a Mastodon instance or a forum

or something like that.

Yeah, for sure.

Anonymous said they just joined.

Have we been talking about Reddit the

whole time?

We have,

but actually I was going to say,

unless you have anything to add or any

last thoughts,

there's one more question here in the

forum.

I wonder if you guys could discuss the

secure paste feature added to Graphene OS.

I think it's a great feature that everyone

should enable.

Do you have any thoughts about this one?

I thought it was still in beta.

I didn't know it was like out out.

I only know that it exists,

but I haven't looked into it myself,

so I don't know how it works.

Okay.

Yeah.

I, um, again,

I thought it was still in beta,

but apparently it is out out.

The only thing I can really say is

side of burritos, the YouTuber,

he does pretty much nothing but graphene

videos on YouTube.

And he did a video about this.

That was really interesting actually.

Um,

which remember for those of you watching

now,

remember when we talk about this later on,

cause I'm going to mention that video

again,

but he built his own little app that,

um,

reads your clipboard to illustrate what

the secure clipboard feature does and why

it's useful.

So, um,

Yeah, I'd say if you're curious about it,

go check it out because I thought that

was a really interesting video.

Yeah,

I think that's all I got on that.

Yeah,

I'm sure other people on the team have

used it and have more experience than me.

There's probably discussion about it on

the forum too.

I think that's a good place to find

out information about new stuff like that.

Probably, yeah.

There's always discussions on the forum,

especially about stuff like graphene.

Yeah,

I think for now it's probably a good

time to go ahead and move on to

the next story.

Yeah,

let's take a look at this one here.

This is by ForoForMedia.

The headline is,

Cops can bypass iPhone's automatic reboot

to get into locked phone's leaked videos.

Claim, Magnet Forensics,

the owner of the gray key phone unlocking

tool,

says it can bypass an iPhone reboot...

It can bypass an iPhone rebooting feature

that was locking cops out.

In November, twenty twenty four,

four or four media revealed that Apple

quietly introduced a new feature in iOS

that automatically reboots an iPhone that

has not been unlocked for seventy two

hours.

And the idea behind this so-called

inactivity reboot

is to revert the phone to a state

that makes it harder for police to break

into the device and thus extract sensitive

data from it with forensics technology.

If you're in the Graphene OS community,

you've certainly heard about this like

before first unlock or after first unlock

state for encryption.

And in a

a phone that's in a before first unlocked

state, whether it's Android or iOS,

is going to be more secure than after

you unlock it for the first time.

So that's where rebooting your phone may

come in,

especially if it hasn't been used in quite

some time.

However,

this new technology to get around the

inactivity reboot on iOS was developed by

Magnet Forensics,

the company behind Gray Key,

a popular tool sold to law enforcement

agencies that allows them to

unlock and access data stored in iPhones

and Android smartphones.

Magnet has developed a new device called

GrayKey Preserve and a feature for its

regular GrayKey devices called Evidence

Preservation Mode,

according to the leaked video.

This is an educational and tutorial video,

which was made exclusively for law

enforcement agents and appears to be dated

early twenty twenty five.

The video does not explain the technical

details behind the new product and

feature,

but it gives some strong hints as to

how it works.

Taking a look here, it says, yeah,

in a quote, now,

one of the many things that the gray

key preserve is going to do is it's

going to enable airplane mode or more

specifically,

it's going to disable our radio

transmissions like Bluetooth,

Wi-Fi and cellular.

In doing this,

that's not only going to allow you to

preserve the data in the field,

but also isolate the data in the field,

as an employee explains.

even if that device doesn't have the

ability to turn on airplane mode or to

turn off the transmitters through the

control center of iOS.

Once initial access is gained and the

device is in a preserved state,

we also disable all of those radios to

make sure the data cannot reach that

device.

Um,

so it says that the after first unlock

state is captured by gray key preserve and

evidence preservation mode.

So that even if that device does reboot

for any number of reasons,

memory maintenance or the power is lost or

whatever the after first unlock state is

not lost.

Um,

So, yeah,

it says when using the new solution,

law enforcement agents only see the iPhone

software version and device model rather

than any data within,

according to the employee in a screenshot

of great keys customer interface that's

included in the video that allows the cops

to preserve the data they care about

without actually seeing it before they're

authorized to do so.

So a researcher who has looked into this

thinks that Magnet has found a way to

manipulate the iPhone clock,

effectively slowing down time or even

stopping the clock from ticking even after

a reboot.

Most likely, according to this researcher,

the Great Key may disable the iPhone tasks

that set data to expire.

So lots of stuff to unpack here.

What does this mean for iPhone users?

What do you think, Nate?

Yeah, I mean, I don't know.

The best I could come up with is,

I mean,

the automatic reboot is designed to be

there as a safety net, right?

And in my opinion,

seventy two hours is a crazy long safety

net anyways.

But I would say my first thought is

don't rely on the automatic reboot if

possible.

Like something I think I mentioned this on

previous episodes.

I don't think my threat model is

particularly high,

but just to be safe when I go

through airports now and, you know,

you have to put everything to go through

the X-ray machine,

I go ahead and reboot my phone.

And by the time it gets through the

x-ray machine,

it's fully rebooted and ready for me to

log back in.

And that way,

in the off chance that I do get

pulled aside and they're like, oh,

we're gonna take your phone into this

other room and do whatever weird stuff

with it.

Well, it's in BFU.

That is literally the best case I can

do.

And I won't have time to like,

oh wait, let me see it real quick.

And obviously they're not gonna let me do

that.

And then I know this is actually a

video that you and I have talked about

making for some time,

but digital minimalism is a bit of a

luxury.

It's not always like,

just don't have anything on your phone,

obviously.

That's one thing people talk about a lot

is if they're traveling internationally,

they're like, oh, bring a burner phone.

And it's like, yeah,

that's cool if you can afford a burner

phone.

But still, just being mindful.

Are there things that you can take off

of your phone,

especially if you do know you're going to

be going to a protest or somewhere where

you might get pulled over or something?

And so, yeah, just kind of,

keeping that kind of stuff in mind,

I think is at least the best I

could come up with.

I don't know if you have any additional

thoughts.

Yeah, for sure.

It's it's tricky to rely on a lot

of these software defenses.

I would think that I mean,

this video is from early twenty twenty

five,

so I don't know if this is like

already been patched.

I would imagine that if it hasn't yet,

Apple will probably look into it now that

this capability is is known.

But yeah,

all of this privacy and security stuff,

it's really just a game of cat and

mouse.

We see all these vulnerabilities come out

all the time and then they get patched

by these companies.

And then the people who are developing

these vulnerabilities for a variety of

reasons will just find new ones because

none of this software is, you know,

it's not going to be perfectly secure by

any means,

especially like if it's Internet

connected,

you're going to have

you're going to potentially run into

problems.

I guess there's a lot of effort being

made in terms of securing new software by

default, or there's things like on iOS,

memory integrity enforcement,

or on Android MTE,

which are going to

keep software more safe and prevent a lot

of these vulnerabilities from happening in

the first place.

But even even with those vulnerabilities

are found in them and the amount of

just old legacy code in all of these

operating systems and apps that we use is

like that's not going to be replaced with

with safer code for quite a while.

So yeah,

I think this kind of stuff will continue

cropping up as an issue.

But of course,

to minimize your risk as much as possible,

uh,

keeping your devices up to date and making

sure you have the very latest security

patches is super important because new

vulnerabilities like this are found, uh,

just constantly.

Yeah, for sure.

Definitely.

Um,

Penguin had a comment here that as far

as we know, graphene is not hackable, um,

especially because graphene comes with,

I think it's enabled by default.

Um, or no,

it's so they have a feature where the

USB port, uh,

you can basically turn it off if you

want to, where it doesn't do anything,

or you can set it to only charge

and not transfer any data.

I think the default is that while the

phone is locked,

it does not transfer any data,

but then when you unlock it,

it can do Android Auto or whatever,

which actually,

it's funny you mentioned that.

We didn't put it in here,

but literally an hour before we went live,

I think it was Jordan posted an article

about how somebody in Canada, yeah,

there's...

I'm not going to share it yet,

but yeah,

somebody in Canada was arrested for a

shooting, I guess.

And the police are currently unable to get

in there,

get into their phone because they're using

graphene.

So please don't use graphene for illegal

things.

But, you know,

these are the kind of articles we look

at and we're like, oh, OK,

like graphene is doing what it says it's

supposed to do.

And.

Yeah.

Username is nice.

It reminds me of when people used to

set their set the date to January first,

nineteen seventy to break their phones.

I didn't know about that.

That's funny.

Nick Spice here said that they thought if

people had the accessory blocking enabled,

that would help combat this.

I know that's not enabled by default,

so it's possible that that would have

combated it,

but it's just not a common thing for

people to have.

I know that in the past,

ways around that have been discovered as

well.

It's why even graphing OS, for example,

when you can disable the USB-C port,

there's varying levels of how much you can

disable it.

I have it disabled

to where the USB-C port only works if

the phone is off,

and then it's only used for charging when

the device is off.

But if it's on,

you can't use it at all,

even for charging.

I know they have a charging-only feature,

and then they have the feature like Nate

was talking about where it's just

restricted when it's locked.

iOS obviously doesn't have quite that

granular of an approach, but it...

Yeah,

I don't know if this would have prevented

this specific case,

but enabling features like that is

probably good.

I know that a lot of these

vulnerabilities,

especially when the phone is locked on

iOS,

can also come from having a lot of

features enabled on the lock screen.

If you go to your Face ID and

password settings,

there's a lot of switches for like,

do you want to allow Siri when the

device is locked?

Do you want to allow Control Center?

And in this case,

I think they mentioned even if Control

Center is disabled,

they can get around some of that stuff.

like as a general rule disabling all of

that stuff and locking down your phone

when it's locked is going to any little

bit helps when it comes to security like

this

Yeah, for sure.

And I was going to say like one

thing that stood out to me that I,

the moments I always feel kind of mixed

is it talks about how like,

I wonder if this is a technical limitation

or like a pinky promise like flock,

but it says that like when they use

this thing,

they can only see the phone software

version and device model.

So in theory,

it's designed to just like prevent the

phone from BFU.

Cause I don't know if I copied it

in the notes here,

but they mentioned that a lot of the

time when they, they get these phones.

Yeah.

You know,

Oh,

I don't think I put it in the

notes here.

A lot of the time...

when they get these phones,

they don't break into them right away

because they have to get a warrant or

they have to get approval from a judge.

And so I, I kind of like that,

like, um,

like you still can't see the data.

You still have to wait and get legal

approval, but I don't know.

It's, I mean, it's the same with anything,

right?

Like, sure.

In theory, it's great.

The celebrate can be used to hack phones

that are being used by, you know,

violent cartel members and pedophiles and

stuff like that.

But also it can just as easily,

easily be used by authoritarian

governments to spy on journalists and

stuff.

So,

Yeah, it's definitely an interesting case.

I mean,

this is that's more of a case of

like gray key policy kind of coming into

play and preventing police officers from

like going rogue and using this for

personal purposes, which, of course,

is a big issue.

You know,

we've talked about it in numerous videos

in the past of like law enforcement agents

kind of abusing these powers for their own

personal gain.

And maybe this prevents that.

But it doesn't.

I mean, at the end of the day,

they still have the data,

even if it's not accessible to an

individual officer before it goes through

like this approval process.

And it kind of calls into question we

talked about this with flock cameras,

for example,

which are kind of collecting all of this

data all the time and storing it in

a database.

And even though you're only supposed to

access that database with a warrant,

in some cases,

you know,

the fact that the data exists in the

database in the first place,

I think is is an issue and in

a Fourth Amendment violation,

like just on its own without regardless of

whether that data was queried by a

government agent.

I don't think that I think the data

collection in the first place is kind of

the bar where a warrant should be

required.

It's not just when a government agent

later tries to access and view that data

should a warrant be required.

So I think that stronger laws need to

be in place

for a variety for something like this,

because my dog is being loud.

I don't know where I was going with

that.

The point is,

I think stronger warrant requirements

should be in place just for this data

collection to be happening in the first

place.

And we're not really seeing that right

now.

Yeah, no, totally agree.

I just, like I said,

I don't know if, you know, that,

that thing,

like they can only see the software

version and device model.

That's why I'm like,

I don't know if that's a literal technical

limitation.

Like, no, no matter what,

they can only see that with this tool.

Or if it's like you said,

is it a,

a policy thing like flock where it's like,

well,

they're only supposed to look at that

tool,

but in theory they can access other stuff

too.

So I don't know.

It's either way.

I have mixed feelings about it.

Not a fan.

I'll be looking forward to Apple to patch

it.

Yeah, I'm looking for a comment here.

I think it was, yeah, FoundDog said,

I'm surprised Apple hasn't ditched the

USB-C port entirely.

I don't think that that...

is going to well,

the way that it's implemented is probably

not going to help because I know Apple

is going to want some sort of diagnostic

way to access these devices,

and that'll be just as useful as a

USB-C port,

especially to these well-funded companies

like like Magnet and Craykey and

Celebrate, for example.

I know like on the Apple Watch,

for example,

There isn't a USB-C port, obviously,

but they can still do some diagnostics in

an Apple Store or if you send it

in.

On the original Apple Watches,

it used to be like there was a

hidden port you would need a special

connector for.

Nowadays, there isn't a hidden port.

It's all wireless, but it's like a...

They have like a sixty gigahertz wireless

connection that they can do in the store

to basically establish the same thing as a

as a wired connection.

And I would imagine that Apple would leave

something like that in the iPhones that

can be, in theory, accessed by only,

you know, tools that Apple has.

But if that is available,

it wouldn't be that hard for a specialized

company to develop a way to connect to

that, even if, you know,

that that connection point isn't available

to Apple.

mere mortals like us who just want to

connect to our phone anymore.

So I don't think that just going to

a portless design is really going to help

when it comes to when it comes to

this problem, unfortunately.

Yeah, what's funny,

Apple seems to like I shouldn't be

surprised by this,

but they seem to be one of those

companies that like when it when it

benefits them, they're OK with it.

I used to know somebody who worked for

Apple for the the Genius Bar,

and they said that they've actually used

celebrate tools before.

like in their job officially,

like Apple has had celebrate tools in the

past.

I don't know how long ago this was.

It was a while ago from what they

told me,

but like they used to use celebrate tools

as part of their job to like,

you know,

help people recover data if they brought

it into the genius bar or something.

So it's, you know, I mean,

fortunately they were doing it with

consent, you know, like this is my iPhone,

I'm broke, it's broken, whatever.

But yeah, it's like, it's weird how like,

okay,

you're willing to use this when it

benefits you and your employees.

But I don't know, it's Apple's weird.

They're a weird company.

I did have a couple of questions I

flagged while we were talking.

One of them,

I think this went back to our first

story.

Nick said,

for those of us who are more tech

savvy and wanna be more private online,

where do we draw the line between

self-hosting and self-creation?

I think they're talking about making your

own tools, but I'm not too sure.

Do you have any thoughts on that one?

I mean,

certainly that's going to be more and more

of a thing with AI.

I think anyone can make their own tools

these days.

Yeah,

I don't know exactly what you're asking.

To be honest,

I would need more clarification on what

that means.

But I think doing anything yourself is

going to be an improvement over...

again, using those centralized platforms.

I think that that is kind of what

has caused a lot of the issues with

the Internet that we've now run into more

than anything else.

For sure.

And username is Nye here said we should

write an article about privacy fatigue.

I feel like have we done that?

I feel like we have in the past.

um we certainly have we have some videos

about that um i don't remember the exact

title of it right now i could look

but sometimes we change titles on things

and yeah that's fun lose track of it

okay because um i know i've written about

it a little bit at my old blog

on the new oil i've talked about burnout

um not specifically privacy related but

i've i've definitely talked about burnout

for sure um i'm looking through some of

our past articles here privacy washing

Mastodon tutorial, dating apps.

In the meantime,

mixed by said self-dev work.

I think in the self-hosting space,

if there is something you can self-host

that already does what you want it to

do, I think standardizing on certain...

Maybe not standardizing,

but supporting existing implementations of

things tends to be the better way to

go.

It's just easier for other people.

You benefit from a community of software

just as much as you benefit from a

community using these self-hosted

platforms to host discussions and stuff.

And so if you're all on a similar

platform, like Discourse, for example,

there's a wide variety of plugins that you

can install on the forum that make

community management easier.

And so using self-hosted tools like that,

if you're trying to start a community that

other people would use, is very helpful.

And it's the same with

like Mastodon, for example,

I think a reason like a lot of

the big public instances of these

Fediverse platforms use Mastodon because

it is really geared more towards larger

public communities.

And it has the largest ecosystem on the

Fediverse, for example.

And so you can get more support from

it from other people if things are going

wrong.

And I think that that's important when

you're when you're self hosting things.

I used the search button and I did

not find anything on our website.

So yeah,

we may have to add an article about

that because that is definitely an

important topic.

I think we all get burned out from

time to time.

We definitely do have a video about

privacy being like what if privacy feels

overwhelming to you,

strategies that you can do.

For example, it's one of our first videos.

So if you go back to the older

ones, I think it's...

Oh yeah, here it is on the list.

It's just how privacy can stop being

overwhelming.

If you're looking for strategies on how to

secure your digital life,

if you're facing kind of burnout and

stuff,

it's a good place to start for sure.

Yeah.

And I think, um,

I do actually really want to write this

as an article now, so I'm not,

I'm not going to dig too deep into

it, but, um, I mean,

just basic burnout strategies.

Like, you know, we talked to Cindy Cohen,

um, about how does she,

cause she's been fighting for privacy in

some form or another for like years.

And I remember asking her, I'm like,

how do you stay motivated?

And she's like,

I celebrate the little wins I have.

Um,

this is a big one personally is like,

I have spaces that are not privacy spaces,

like, especially, um,

I don't wanna sound full of myself and

I promise I'm not, but being Nate,

I know I'm a bit of a well-known

figure in the space,

but outside of privacy, I'm nobody.

Privacy is a very small space.

And honestly, I love that.

I love the fact that there are other

spaces that I can step outside and I'm

not this expert anymore that people are

like, well, what's your opinion on this?

It's like,

I can have an opinion and nobody cares.

because i'm just another normal person

like everybody else and i think just

having those spaces where you can go you

know whether it's video games whether it's

music whether it's um you know whatever it

is camping i don't know like having things

you can do where you can unplug and

disconnect is really fantastic uh at least

it is for me so anyways odd bite

one of our biggest supporters welcome to

the stream hello

Yeah, as username is nice,

I think calibrating one's threat model

step by step is one way to stop

being bored.

I think that's definitely a good strategy

because

You do have to have a plan going

into it of what's most important to you,

where you have to start out.

I think if you don't have a plan

and it's just kind of an unstructured,

try to secure everything,

try to make everything as private as

possible approach,

you're just going to have way too much

to deal with from the start.

like on our website, the knowledge base,

for example,

we do have a list of like common

threats that people face,

and maybe those aren't the things that

you're concerned about.

Maybe they are,

but it could give you a starting off

point or an idea of like, oh,

I never thought about this issue before,

but maybe I'm concerned about it.

Or it could help you narrow down like

which of these things on the list you're

most concerned about,

and then you can focus on it from

from there.

I think that definitely makes things a lot

easier,

which is why we talk about

threat modeling all the time instead of

just doing everything you can because you

can um it's just a more sustainable way

to to do things and i think you

can also it helps you be a lot

more thorough uh because you can kind of

set goals for yourself and evaluate how

you're doing and stuff like that which i

think helps a lot of people as well

Yeah, I was going to say,

I think a lot of the burnout I

see,

like there's definitely the burnout of

just like, you know,

I've been in the privacy space for years

and it feels like we're always losing,

which is not true,

but it can feel that way sometimes.

I think there's a difference between that.

The one I see most often is what

you were just saying is like somebody is

trying to do everything and they're just

overwhelmed by like, oh, cool.

Now there's this new my neighbor's Wi-Fi

can sense my position because of this new

attack or whatever.

And it's like.

Like you said,

like stepping back and being like, OK,

what's my actual threat model?

What am I really trying to defend against?

What don't I care about?

And what's like realistic, you know,

like it's yeah, I think personally,

I do think people should go as far

as they can to protect their privacy.

But there does hit a point where,

you know,

it starts to become a lot of work

and you have to ask yourself, like,

what am I getting?

What am I gaining?

What am I losing?

Like,

is this really worth it once I'm going

beyond the minimum?

And but you don't know that if you

don't know where the minimum is,

which is the threat model.

So

Yeah, it's important.

I'm going to have to briefly remind

Oddbite that if you opt into sharing your

membership status on the forum,

that's going to be publicly available on

our website.

I think we have a list of members.

And if you opt into sharing that publicly,

we include the list of members at the

end of videos now to thank people.

Definitely want to highlight all the

people supporting us.

Of course, this could be an impersonator.

Who knows if you're the real Oddbite,

but...

Um, again,

we won't spend too long on this,

but yeah, one person said, uh,

doing things in phases and set a cap

for how much is on my plate.

Um, yeah, doing things in steps for sure.

Um, not trying to do everything at once.

Uh,

what's this one compartmentalization with

identities for sure.

So, yeah, I mean,

there's a lot of stuff out there.

Maybe, uh,

Yeah,

I think there's some interest in this.

We should talk about this some more in

the future.

But for now,

I think I'm going to turn it over

to you to go over our first forum

post here that we wanted to highlight,

which I think is just kind of a

signal boost about Chat Control

Yeah, just an update.

Somebody posted here.

There's always chat control stuff going

on, I feel like.

Patrick Breyer,

who's a former MEP with the Pirate Party

and current, of course,

digital freedom activist,

posted about the upcoming sixth...

Trilog on ChatControl.

The Trilog negotiates extent of the later

proposal, which,

according to a leaked document,

is said to now include a workaround to

deploy a mass scanning by allowing

scanning of parts of a service in search

plans,

which Breyer calls mass surveillance by

another name.

The council's own legal service says such

framing would not hold up in judicial

review.

This is likely due to targeted

targeted being reframed as parts of a

service instead of a person.

So what information do we have here?

Of course,

you can always go to fightchatcontrol.eu.

You can go to fightchatcontrol.eu

hound sign, delegates,

or find the delegates section on that

site.

You can set the filter to EP Trilog

Shadows and you can see all eight

responsible MEPs.

If you're in the EU and you are

represented by these people at all,

definitely worth voicing your support.

I mean,

this is the kind of thing where for

some reason,

all of these track control measures are

just a constant fight in the EU.

Seemingly, it'll never end and hopefully

all of you in the EU can get

your act together and pass some law that

prevents this from happening.

So it doesn't just have to come up

all the time.

But that's really going to come down to

getting your representatives to do what

you want, which is always challenging.

So yeah,

were there any replies to this post that

you wanted to highlight, Nate?

Yeah,

Chat Control is definitely like a terrible

movie franchise that just will not die.

Yeah,

there was one here somewhere from another

user said,

don't forget that Canada has its own chat

control in the form of Bill C-Twenty-Two.

So if you're Canadian,

definitely keep that on your radar.

This other person actually commented

about,

I know there's been some talk about Canada

becoming an EU associate member,

which is not a thing that currently

exists.

So nobody even really knows what that

means.

But they did point out that if that

does go through,

that it might like pressure Canada to,

Play by similar, what'd they say?

More like an obligation to play by rules

by similar demand or by popular demand.

So yeah,

definitely stuff to keep an eye on.

And there was actually a video down here.

I think Freya shared it in the chat

where it's not chat controlled directly,

but apparently there's this similar

proposal called the EU Kids Act.

And the Stop Killing Games movement posted

a video where they basically talked about

how, like,

there's a whole bunch of things to it.

But one of the things I remembered is

it would basically make it illegal to

self-host games.

Like,

if you self-host your own Minecraft

server,

that would effectively become illegal.

And it's just, it's wild.

So, yeah, things are...

in a tough spot right now.

I will end by saying this person updated

their post and said that for now,

the plan to work around the targeting

limitation has been blocked.

But again,

there may be a seventh trial log in

November, possibly.

So, yeah, if you're in Canada,

if you're in the EU,

I would say go ahead and follow this

this forum post so that you get updates

and just, yeah,

try to keep updated with this stuff.

I know it's a lot.

We were just talking about burnout.

It's a lot, but unfortunately,

it's important stuff.

Username is Nye.

I want to know more details about this

Jonah act.

That's what I was going to say.

I saw that.

What is the Jonah act?

Two chat, two control.

Love it.

Yeah,

so I think that's all we got on

that one.

I think now we can move on to

the

site updates.

I guess I'll kick this one off.

In a little bit,

we're going to be talking about a new

attack that can track you regardless of

what operating system you use and does not

require administrative privileges,

by the way.

But first, like I said,

we're going to do some site updates.

Yeah, like I mentioned, we did, well,

we put out a video last week about

My brain is blanking.

The twenty sixteen San Bernardino shooting

and the fight that followed between Apple

and the FBI,

with the FBI trying to pressure Apple to

unlock it and Apple saying no.

And that one got I think it's now

got over a million views on YouTube,

which

i don't want to downplay it but i

will say um youtube changed the way they

count views now so it's more like a

million clicks than a million views but

even so it's got i think half a

million what they call engaged views which

is what we used to know as views

so um like half a million real views

which is pretty amazing um definitely the

most viral i've ever any video i've ever

worked on so super proud of that but

yeah this week um

Lewis Rossman,

a lot of you guys probably saw,

posted a video where he revoked his

endorsement of Privacy.com.

And for any of you who haven't seen

this video, I've met Lewis.

I consider him a friend.

He's a really cool guy.

And I didn't disagree with him,

but I remember sitting here and thinking,

like, while I'm watching his video,

I'm like, okay, so what's...

What's the alternative?

Every service is going to KYC you.

And I just thought it was part of

a bigger discussion.

And so I kind of pitched it to

Jonah.

I kind of expected Jonah to say no,

to be honest.

But I was like, hey,

what if we make this video?

And he was like, yeah, let's do it.

So we whipped that up pretty quick and

posted that.

And that is now available.

And it has not gone as viral,

but it's definitely gotten a ton of

discussion in the comments.

I feel like that's an issue that comes

up a lot with maybe idealists in the

privacy space.

We see it especially in cybersecurity

where I think people can let perfect be

the enemy of the good.

As long as you know the downsides of

things,

a lot of tools do have

aspects of them that can help your privacy

in meaningful ways.

And I think Privacy.com is one of them.

Of course, there are alternatives to that.

And so if you disagree with the specific

provider that Privacy.com is using,

you can switch to my pseudo or another

provider that's similar,

or you can switch to prepaid debit cards.

There's a lot of those which you can

obtain completely anonymously.

Right now, all the virtual card services,

they do KYC in a similar manner.

They just use different companies, but

But those prepaid cards can or gift cards

could be obtained with cryptocurrency or

cash.

And so that's always an option.

But I think

Yeah,

as long as you understand you're giving up

some privacy in some respect when you're

using privacy.com, which is unfortunate.

I've never liked the name of this

privacy.com service because I think that

is a little misleading.

But at the same time,

being able to use a different card number

on every site that you use,

it has security benefits for sure because

you can disable those cards.

And it also has privacy benefits

because...

uh merchants can't track you based on your

billing information or like two websites

can't collaborate and share their

databases and link your accounts because

you can use not only different card

numbers but you can use different billing

addresses or whatever you want with

privacy.com it doesn't get checked on

those cards so they're like it sucks that

they're doing this uh it's very annoying

but at the same time if you want

those privacy benefits

in a different respect,

you also don't have a lot of options.

But I do think privacy.com should stop

doing that.

And I think that if you do use

privacy.com right now,

you should write to them and complain.

I don't use privacy.com.

Personally,

I use virtual cards from my bank,

which I think is the more convenient

option if you have that option.

But yeah,

Yeah, for sure.

And for the record, again,

if anybody hasn't seen the video,

we said all this in the video.

Like I even said at one point,

I'm like, look, I think at bare minimum,

Privacy.com could have gone with a

different provider that's not funded by

Peter Thiel.

Did you see the comment that said I

was defending Peter Thiel somehow?

I stared at that one for a minute.

I'm like, what?

Where?

But yeah, anyways.

Yeah.

So, I mean, we, we said that like,

look, they, they should do better.

There's probably providers who are

slightly better, but they're not all like,

there is no provider that's like, oh,

this one's great.

And they should have gone with them.

It's like, yeah, there's a lesser evil,

but not by much.

And yeah,

we did go over some of the alternatives,

like you mentioned.

And yeah, I don't know.

Anyways, that's,

that's a video that's out there.

If y'all want to check that out.

I think on that note,

I will turn it over to Jonah to

discuss any site changes that are coming

up.

Yeah, there's some minor updates.

As usual,

people keep plugging away at pull requests

on the site.

And if you have any suggestions or want

to add new content,

we always accept that stuff on on GitHub.

We have some changes revising the guidance

we have for Android app installation.

We have some changes to

We have some improvements to our Tor

interview and how we changed that,

and we changed our custom domain

requirement for email services again.

This is all based on forum discussions

that we have,

so if you want to get involved,

you can either create a pull request based

on discussions that you've seen on the

forum that people generally agree on,

or if you want to make a change,

you can open a discussion on the forum

at discuss.privacyguides.net.

That's the best way to contribute to our

shared knowledge base,

and we can hopefully get

the best privacy information we can out

there.

Of course,

Freya and others constantly work on news

briefs that we post to privacyguides.org

slash news.

These come up very regularly and they

cover a lot of news topics,

especially ones that we can't cover on the

show because we do a lot of discussion

on the show.

Of course, we can't

We can't cover every news story.

Some of the headlines from this week.

Critical Tor vulnerabilities were patched

across all Tor components from the LLM

report firehose.

New technique was discovered for breaking

RSA faster than ever before.

Meta promises to upgrade Ray-Ban smart

glasses with private processing.

Whatever that means,

you'll have to read the article to find

out.

um highly sensitive data of three million

people in the pentagon system were

accessed by unauthorized users and german

police are using linked devices to read

messages from messaging apps without

cracking the encryption which i believe

we've talked about a similar story on the

show before um of course every week nate

also publishes the data breach roundup to

this same page privacyguides.org news you

can also subscribe to it as a newsletter

but there's just constantly

data breaches happening all the time.

And it's kind of just a way to

show how often it happens,

because I think people wouldn't believe

how often these companies get hacked.

So yeah,

if you want to either be aware of

that,

or if you just want to see how

often it happens,

that's a good resource to check out.

Yeah, all of the stuff that we publish,

all the stuff that I talked about and

the videos that Nate talked about,

all of it's made possible by our

supporters.

You can sign up for a membership or

you can donate at privacyguides.org slash

donate.

You can also pick up some swag at

shop.privacyguides.org if you like.

At Privacy Guides, we are a nonprofit.

We research and share privacy-related

information,

and we facilitate a community on our forum

and matrix and these other platforms like

here on YouTube where people can ask

questions and get advice about staying

private online and preserving your digital

rights.

So yeah,

with my spiel out of the way, Nate,

let's talk about some new research on car

privacy or the lack thereof.

And everyone, remember...

The chat's been pretty active,

which is fantastic.

But if you do have questions,

either about what we're talking about or

just questions in general,

we will get to all those questions in

between stories.

So definitely feel free to leave them.

Now you don't have to wait.

Yeah, real quick,

I'll jump into a couple of those

questions.

First of all,

apparently the Jonah Act is the just open

nothing and hide act.

So if you were curious about that.

Username is Naya said,

where's Tudor encryption wise?

They receive government funding to

post-quantum cryptography.

I think either they're still rolling it

out or it might be done.

I know Tudor Drive uses post-quantum

encryption.

Yeah, I, I know it's,

it's in progress at very least if it's

not already fully rolled out.

I believe they fully rolled it out and

it should protect all that data.

Um, yeah, yeah.

Proton still is not rolled it out

annoyingly,

even though they have it supposedly.

Um, but yeah,

I've complained about that on the Reddit

and hopefully we,

hopefully we see that soon.

You know,

I really want to add a soundboard on

my little stream deck here for the clip

from Letter Kenny,

where he just says allegedly,

because I feel like I use that a

lot.

But anyways, I digress.

We'll move on to the next story,

which is a study about cars.

And I do apologize.

I'm going to read pretty much all of

this article.

It's not very long for the record.

And I read fast,

but it's one of those articles where

there's really not a lot of fluff and

it's very dense.

So it's one of those times I found

myself taking notes and I'm like,

I literally just copied the whole article.

So the headline says,

this study looks at how and with whom

connected cars share your data.

So I can actually summarize the first

couple of paragraphs.

Back in twenty twenty three,

Mozilla published a report that actually

broke all the way into the mainstream.

And what they did was they looked at

the privacy policies of more than two

dozen automakers.

And they said, quote,

cars are the worst product category we

have ever reviewed for privacy.

But this article notes like, yeah,

that was conducted by reading the privacy

policies.

But now we have actual research.

Northeastern University and Consumer

Reports tested twenty one cars from

nineteen different brands.

And let's see two attempts to actually see

what was in the data packets using

modified certificates failed in every

case.

But the network traces still yielded

valuable information,

including the domains contacted via DNS

traffic.

uh server name indication in tls

handshakes the volume and timing of

transmissions and differences in behavior

across experimental scenarios so all of

the cars contacted a first party domain uh

you know honda.com mercedes.com whatever

um uh where did they say

A few left it there,

such as the Buick Invista and the

Mercedes-Benz EQS didn't appear to reach

out anywhere else, for example.

Others were far more promiscuous,

with Tesla topping the chart.

The Model Three contacted thirty-four

advertising, tracking,

and analytics domains,

as well as thirty-seven domains from apps

integrated into the infotainment system.

Alphabet's domains were most frequently

contacted,

which is not enormously surprising given

the penetration of Android Automotive OS

into the sector.

They said,

but there were many second level domains

that were not necessary for core services

like DoubleClick.net and

GoogleSyndication.com,

which are used for advertising.

Media streaming like Spotify, SiriusXM,

and so on are also there,

as well as mapping companies like Here,

TomTom, and Mapbox.

They said using a car's infotainment

system resulted in contacting the most

domains versus just sitting idle or

driving for all the cars tested,

which would make sense,

apart from the Cybertruck,

which instead contacts twenty six more

third party domains while driving than

stationary, which is.

What?

I digress.

So with the EVs,

they were able to put them in a

Faraday tent and actually test.

They couldn't do that with the internal

combustion engine cars because of fumes,

but they were able to put them in

a tent and see would they try a

different way to phone home.

And they said some of the EVs,

including the Cadillac Lyric,

Chevy Blazer, Honda Prologue,

and Rivian R-I simply stopped using those

connected subsystems.

But some of the cars redirected their

traffic to Wi-Fi,

allowing the researchers to see traffic

flows that were previously unobservable.

And then they tested thirty different

connected car apps.

So I'm not gonna lie.

I tried one of these one time just

because I was hoping that we would be

able to remote start our car in the

winter and let it like warm up.

It did not do that.

So I deleted the app because in our

case, you know,

you download an app for like Honda,

Toyota, whoever,

and

in my opinion they're pretty useless it

like tells you it tells you things the

car already tells you like you know oh

you've driven this far oh it's time to

get an oil change and it's like what

do i need an app for that but

anyways um they said in some cases uh

this exposed users to more than twenty new

advertising tracking and analytics

companies from general motors toyota and

nissan were the worst offenders

um the authors reached out to seventeen of

the automakers and heard back from

fourteen the replies are not entirely

encouraging all of the oems told

researchers that data sharing with with

third parties was covered by contracts

prohibiting the use of pii outside the

scope of their privacy agreements the same

privacy agreements that horrified bozilla

in uh some of the automakers deflected

blame onto the embedded browser running

inside the infotainment system and said it

was up to the users to select the

right prompt or reject a cookie uh seven

said it's the consumer's responsibility to

read and accept all the terms and

conditions

even though in many cases the software is

already installed and the author's note

that declining a data sharing agreement

can result in loss of services and

functionality not a great solution if it

means losing useful features you expect to

work when you bought the car they said

there was at least one positive outcome

after being contacted Honda changed its

data practices and no longer shares

precise location data with at least one

tracking company so yeah that was a lot

but

i don't know the the fun thing about

cars is i feel like right now there's

not a lot of defenses i mean are

you aware of any any uh defenses against

car privacy invasions jonah it's

definitely a field that could use a lot

more research unfortunately um i don't

know maybe that's an opportunity for us to

look into that but it's it's tricky as

these

Yeah,

cars just become even more connected and

they're all kind of doing their own thing,

of course,

because like all of these companies,

they just want to monetize that data.

I'm sure very soon we'll see information

like the LG TV information that just came

out, except without with cars.

Certainly we know of a lot of privacy

invasions that cars have even today,

and it's only kind of getting worse.

what exactly we can do about it i

don't know though i don't have specific

car advice unfortunately um but it would

be great if there was was an option

yeah for sure i know one thing that

gets thrown around a lot is like just

drive an older car um you know australis

actually said we're cooked when all the

old cars break down that's not always a

feasible um solution because i know i used

to have a that was my last car

was a

and I got rid of that just a

couple years ago,

so I had it about thirteen years or

so, ten years, something like that,

and it was a very common car,

I'm not gonna say what it was for

obvious reasons,

but it was a very common car,

and yet,

I remember the last time I went into

an AutoZone, and I was like, yeah,

I need a headlight, and they're like, oh,

we don't have any headlights for that car,

and I'm like,

What do you mean you don't have any

headlights for that car?

I passed six other ones on the way

here.

This is not an unusual car.

And you know, especially like my new car,

one of our AC fan broke,

which was just wonderful when we lived in

Texas.

Our AC fan broke and I jumped online

and I spent days scouring,

not just YouTube, but like forums,

like multiple search engines.

I was like,

there has to be tutorials on how to

swap out this fan.

And I could not find any tutorials.

I could find,

I found that repair for a different make

and model, the right make and model,

but different repairs.

But we are no longer living in the

glory days of YouTube where it's like

anything you can think of,

there's a tutorial on YouTube for it.

So my point being is we're hitting a

point where

just drive an older car it's only going

to work if you have the money to

like get parts custom ordered and

fabricated and go to a mechanic every time

it breaks down because it's just becoming

impossible to like maintain these cars

anymore so i don't know personal rant on

that one but um anonymous one shared uh

a link about rivians um this has come

out

come up a few times when we talked

about car privacy and EVs.

I haven't looked into it.

Rivian claims that you can disable a lot

of the stuff, which is cool.

You do lose some features.

It is sort of like

very similar to trusting Apple with like,

is it truly disabled?

Are they collecting all of this stuff?

If you want to.

Yeah,

if you want to trust that that's

happening,

it could be it could be an option.

And it's cool that, you know,

they at least recognize that this is a

privacy problem.

But I think I don't know if people

have evaluated that yet.

um another comment i saw was from username

isn't high grok helps me drive this

comment is how i just found out that

tesla's integrate grok now i was just

looking this up um and that is very

sad knowledge for me to have so thank

you for sharing that with me um that

is that is terrible

Um, I'd buy said it here.

Thank you so much.

I was trying to remember the name of

the company.

Carrie Parker mentioned them a couple

months ago on firewalls.

Don't stop dragons.

Apparently slate alleges that you can turn

off all the tracking.

Same thing with Rivian.

It's like, how much do you trust it?

I will say, um, in my opinion,

what's up?

Sorry,

I was just going to say Slate might

be a better option than Rivian because my

understanding is there's not even a

computer unless you buy one.

Everything is kind of modular with the

Slate truck.

That's what it is.

Yeah, the Slate's all modular.

I remember looking at Slade and kind of

configuring one on their website.

I don't have the thirty grand to buy

a slate truck,

but I think even like the speaker system

they recommend is basically a Bluetooth

speaker that you mount there and then a

phone holder.

So

I mean,

that is kind of the ideal way to

do it in some in some sense,

because I think it makes a lot of

sense to kind of have everything on your

phone and kind of only trust this one

computer instead of this whole system that

you're using.

But I also don't know anything about the

slate truck or how nice it is the

drive or how many people will buy it.

But it's an interesting concept for sure.

a little bit off topic, but you said,

I don't have the thirty grand to buy

it.

I remember one time just purely for

laughs,

I went to system seventy six's website.

This was years ago before the ramp

apocalypse.

And just for laughs, I was like,

what is the most powerful computer they

sell?

So I got like the best,

like the most RAM,

the biggest hard drives,

like multiple GPUs.

And it came out to like seventy thousand

dollars.

I mean, to be fair,

it had like nine I-Nines in it or

something crazy.

So it's, yeah, but I just,

just for fun,

I like to do that every now and

then just how bad does it get?

But yeah,

we actually have quite a few here.

Oh,

I remember I was going to say like

with the

whole like Rivian, you know,

you can go to this link thing.

Yeah, we're kind of trusting them.

Like you said, it's like Apple.

We're kind of trusting them to turn it

off.

But it's one of those things,

in my opinion,

where it can't hurt to do it because

worst case scenario,

you're in the same boat you started in.

Best case scenario,

they do actually shut off at least some

of the telemetry.

Worst case scenario,

literally nothing has changed.

So it's not like you're going to be

worse off for doing it, in my opinion.

But...

Yeah,

what about a start a farm life when

the digital world is too much?

Seems like a lot of people are retiring

to the farm life.

Oh, what do we have here?

Jonah, it's different from Apple.

They say you can disable all cellular

connectivity.

It's a simple on off.

So but, you know,

it's like a proprietary system, right?

Just like Apple.

You just have to trust other switches

work.

I mean,

there's got to be a way to like

check and see if there's anything coming

off of it.

I would feel like I don't know.

I'm really curious.

I remember when we looked at the review

and stuff last time,

it does disable things like active lane

centering, which isn't great.

It disables navigation,

which might make sense.

But I mean,

even even in like two thousand eight to

twenty ten,

we had cars that just had maps in

them.

Could we just could we just have offline

maps for a fan?

Maybe I'm curious whether

I don't know anything about Rivian,

honestly.

I don't know if it supports CarPlay.

I wonder if you could disable this but

still use CarPlay for music streaming.

Or Android Auto.

Either one,

depending on the phone you have.

Yeah, it's interesting.

This article does say that they can

disable the eSIM entirely through a

service appointment,

which maybe would be even better.

But yeah,

it all depends on how well they've

implemented this.

But I would certainly hope it works as

advertised.

Yeah.

Yeah.

Um,

the last thing I'll add before we move

on is, uh,

I know there's services out there.

The two I know of is privacy for

cars and vehicle privacy report.

Um,

they basically submit opt-outs on your

behalf,

or you can do it yourself if you're

a masochist.

Um, it's,

it's one of those things where you're

trusting another party.

Uh,

this is not an official privacy guides

recommendation, but, um,

you are trusting a third party because you

have to,

and I think you even have to like

check a box that basically says like,

I am giving you legal authorization to act

on my behalf in this instance.

And even then, it's not really,

it's very limited.

It's like a lot of websites where it's

like, oh, opt out of targeted advertising.

And it's like, okay,

but opting out of targeted advertising is

not the same as opting out of collecting

the data for targeted advertising.

So it's definitely not,

I'm not trying to say it's foolproof and

like, oh,

you sign up for one of these and

they'll delete everything or whatever.

But again,

it's one of those things where I think

I would argue you're probably not worse

off.

Like I've done it.

I haven't had any downsides other than I

got a bunch of letters that are like,

we received your request and we'll process

and blah, blah, blah, blah, blah, blah.

And then, you know,

at very least it sends a message.

You know,

if they get tens of thousands of these

requests,

then maybe they might just be like, hmm,

people feel strongly about this.

So I don't know if it would be

enough to change, but yeah.

So I just wanted to throw that out

there.

I think you have a forum post to

pull up, but right before that,

I want to do one more comment here.

Foundog said,

I think I'd want the ability to remove

the five G modem.

I think that that would be like that's

that's the main thing.

If I was going to look into this

vehicle stuff more,

which maybe we should do, to be honest,

because nobody else seems to be doing it

these days since Mozilla stopped updating

that.

But I think that that would be probably

the best solution is just

there's probably going to be some vehicles

where you can just pull out this module

or make make a change to like force

it to no longer be connected and then

see like what functionality remains.

I think looking into that would be would

be cool.

I know that

Henry from Teklor suggested something

similar because at one point,

I think he got like a Nissan Leaf

or something,

but it was like an older EV that

only had two G connectivity.

So then when all of the towers stopped

supporting two G,

he said that that would that would make

it private.

know that's certainly an approach i think

removing it entirely would be uh certainly

a lot better um but i don't know

of any cars that make that super easy

to do but i feel like there might

be some out there where you could just

like remove a fuse or like disconnect a

module and and lose that functionality and

they they might be options to explore and

i think doing more research into that

would be pretty useful.

So we should think about that.

Username is not what's bad about five G

exactly.

I think just any connectivity,

like if you could remove the connectivity

features of your,

of your vehicle pretty easily,

no cellular, no, no wifi.

That would,

that would stop a lot of these privacy

problems.

You'd lose functionality.

So I think looking into like what

functionality you,

you would lose if you disconnected,

that would be something to, to look into,

but it would be good for privacy.

If that's a possibility.

Yeah, I don't know if it's true.

I've heard some claims that that could

potentially be like a warranty voiding

thing,

but also if you're buying a car

secondhand, usually there is no warranty,

so.

yeah another thing we'd have to look into

like can you easily reconnect it when you

bring it in for servicing maybe and that's

what i was about to say i feel

like a good mechanic could probably like

you said like there's probably just one

cable they just pull out and you know

but also a lot of the time i

no offense to mechanics a lot of you

guys seem to like talk down to

non-mechanics well you know you're gonna

lose this this and this yeah i i

know just please unplug it i i did

my research so

I don't know, but yeah, anyways,

actually we did have a couple of questions

before I dive into the forum post.

We had one basically, okay, sorry,

I closed it out.

Now I can't see it.

It's basically, they found on our forum,

there were some recommendations for

Venadium and one of them was to turn

off, do not track,

but since it's on by default,

wouldn't that make Venadium users stand

out more?

What do you think of that?

That's definitely true that it could.

In theory,

the reality is Vanadium doesn't have

billions or millions or even probably no

more than like a handful of thousand

users.

Right.

So fingerprinting is kind of already going

to be an issue for a lot of

people.

It's not really

geared to prevent fingerprinting.

I think that Graphene OS has said they

want to focus more on that in the

future.

I believe that they've said in regards to

fingerprinting,

it'd be cool to release Vanadium on the

Play Store so other people kind of blend

in with it.

But the reality is with a lot of

these mobile devices,

it's almost impossible to prevent a lot of

browser fingerprinting.

And even Tor Browser on Android is not

as good at preventing fingerprinting as...

as it is on like desktop with mobile

browser or Tor browser, for example.

It's just there's too many variables.

We talk about this all the time with

cellular devices.

They're machines that are basically built

for tracking.

So

There's only so much that can be done

with the current operating systems,

unfortunately.

Yeah,

Jordan just said in the chat that Graphene

OS has said they have around a half

a million users.

So yeah, in the grand scheme of things,

as far as browser fingerprinting goes,

that's a pretty insignificant number of

users who are browsing the web.

So you're going to stand out if you

use Vanadium either way.

I think the idea...

You said this was advice from a...

community wiki posts,

those are obviously maybe not obviously,

but those are submitted by people in our

community and they're kind of collaborated

on by other forum users,

but they haven't been like added to our

website.

So this isn't a post that I've read,

but I would imagine changing some of these

settings may help Vanadium users blend in

more with like Google Chrome users,

which may be a bit more beneficial.

But again, even Google Chrome users,

despite there being a ton of them,

because the browser is

sharing so much unique information,

you're still going to be fingerprintable.

So it's just not a thing that really

any browser on Android, to my knowledge,

tackles.

Tor browser might be doing the best,

but there's so few Tor browser users on

Android that you run into exactly the same

issue.

So that's not really a protection either.

You're just not going to be protected from

this on Android at the end of the

day.

That's what I would say.

Another thing Jordan said that I know you

kind of touched on is not everyone that

uses Graphene OS uses Vanadium either,

which is true.

I use Brave, so yeah.

Yeah,

I use Brave on mobile just because I

think they're the best at what they do.

Yeah, Oddbyte said Brave.

I use it because it syncs, you know.

I don't use the sync.

Oh, no?

I just, I like that it has,

I feel like it has the best

anti-fingerprinting for an Android

browser, but, you know.

It's good ad blocking, too, yeah.

Oh, yeah, ad blocking.

I don't remember what the ad blocking

situation is on Finadium, but...

I heard they were going to make a

change list built in,

but it's not really robust.

That sounds like it might be right.

Um, yeah,

username is nice that some websites can

ignore and bypass do not track requests.

And I also know that, um,

there is a. Uh,

I don't know if this necessarily, like,

I don't know how this compares versus, um,

like the idea of trying to make everybody

blend in on vanadium,

but do not track can also be used

ironically to track people because of the

way it works and the headers.

And so that's typically why it is

disabled.

Yeah.

Yeah.

I was going to say that's,

that's probably why we re uh,

or that forum post recommended.

You wouldn't want to disable it.

I think it's a good point.

Like in general,

if the other people who use your browsers

have it enabled by default,

you probably wouldn't want to disable it.

But I think in this case,

it probably doesn't matter too much in the

grand scheme of things.

So as

Yeah, who said that?

Where did that chat go?

Well, it doesn't matter.

The do not track setting is ignored by

sites because, yeah, that one.

Because it's not a legal requirement.

I mean,

it's just kind of a request that you

make.

There is a new standard,

I think it's called GPC,

Global Privacy Control,

but I could be wrong about that.

But the nice thing about that one,

in theory,

is that in states like California,

for example,

in other regions where there are stronger

privacy laws,

they've decided that this setting is...

considered a legally binding request,

whereas Do Not Track isn't because there's

some like requirements on how GPC is used.

It can't be like enabled by default on

standard browsers.

People have to opt into it.

So that's more like an affirmative choice.

I think a big problem with Do Not

Track is that like it just got enabled

on Firefox, for example, by default,

and then everyone was using it and then

Nobody really respected that request or

checked it because they wanted to track a

bunch of Firefox users.

Probably back in the day when a lot

of people use Firefox.

Now Firefox would probably get away with

enabling it by default,

arguing that most Firefox users care about

privacy.

But there was a time where people used

Firefox for non-privacy reasons back in

the day.

But I think those people are few and

far between now, unfortunately.

Well,

what's funny is I think Brave enables GPC

by default, but yeah,

that's another video idea I've submitted

but we haven't gotten around to.

Because if you market your browser as

specifically for privacy,

everywhere on Brave it's the privacy

browser.

So people are opting into it because they

downloaded a privacy browser.

But even Firefox probably couldn't justify

enabling it by default and Chrome

certainly couldn't.

you can't say this person specifically

requested privacy.

Would it be nice if we just had

data privacy laws that you don't have to

opt into?

Yes, that would be awesome.

But yeah, we don't.

Fair.

Yeah.

Somebody said Vanadium uses easy list and-

Yeah, I think that's about it.

There was another question from that

person real quick.

We'll just run through these.

Basically,

if I enable some hardening exploit

protection on Graphene OS,

when should I enable it for specific apps?

In my experience,

you should enable it by default.

I've only ever had to,

I kind of bounce around between a lot

of different operating systems to keep

testing them.

In my experience,

I've only ever had to disable exploit

protection once and it was with Apple

Music because it was,

for some reason it started giving me a

lot of trouble about like,

it wouldn't let me sign in and then

when I did sign in,

it like wouldn't find my library and then

like,

It wouldn't download music.

It was giving me all kinds of errors.

And finally,

when I disabled exploit protection,

suddenly it worked perfectly.

So, I don't know.

I would use a whitelist approach,

personally.

Every other app I've ever tried has worked

just fine.

Yeah.

I enabled all of them by default,

and I have not run into any issues

on my Pixel.

I would say...

If you can deal with that pop-up,

there are definitely a few apps where I

open them and I get that pop-up,

but nothing really seems to change.

I think that gallery app,

Avis Gallery or whatever it's called,

has this issue where sometimes I open it,

that pops up, but it's perfectly fine.

And if you can kind of just deal

with that pop-up, then it's...

whatever.

But also,

if you get that pop-up and functionality

is clearly impacted,

you can consider disabling it.

It just depends on how much you trust

that app, right?

It's just a sign.

I wouldn't disable these features every

time an app breaks or crashes because I

think it's a good...

point in time to evaluate whether you need

this app in the first place or whether

you can find an alternative that's not

going to break because of security

features.

But if you really do need this app,

then the whitelist approach,

like you said, Nate,

is the way to go,

where you just have everything enabled by

default and just disable it very

selectively.

Oddbite also read my mind.

Oddbite said you can disable the pop up,

which honestly is what I do, because,

yeah, it shows up all the time.

And then but there's like never a

functionality issue.

It's so yeah,

you just had at least one if you

have.

I was going to say,

I think I have at least one functionality

issue.

I don't remember what it was, though.

But yeah,

like I also just said that that's usually

used by tracking SDKs.

I think that that's most of the reason

that it pops up.

Can you disable that pop up?

for a specific app or can you just

disable the pop-up from the system in

general?

Because that's what I would wonder.

I would still want the pop-up for some

apps,

but if it was an issue with a

specific app, I'd want to turn it off.

But I've never looked into disabling it.

I can't remember.

They're saying per app.

They're saying per app in the chat.

So great.

That's a great option.

All right, and then last one,

this one's really quick.

Is there a difference between wired and

wireless headphones security-wise?

Generally speaking,

wired is going to be more secure.

We did, I think last week, actually,

we did cover an attack that also works

on wired headphones because it targets the

actual analog components.

But yeah,

usually when there's security issues,

it has to do with the Bluetooth of

wireless headphones.

Yeah, I mean, Bluetooth is just not a...

very private standard.

And anytime you're like, I mean,

it's radio waves,

this can be picked up by somebody if

they have the equipment.

Yeah.

for sure.

All right.

On that note, uh,

we'll get into the forum post here, which,

uh, this is a forum discussion.

It was actually,

I think our most popular forum discussion

this week is how often are people sending

encrypted emails?

Um,

so I'm not going to read any specific

messages here because basically the whole

thread of it was somebody was like,

I feel like a lot of the people

I email are using like Gmail or outlook

or Yahoo and everybody else kind of just,

uh, um, agreeing like, yeah, everyone I,

I email is, is, uh,

using one of these mainstream providers

there was some discussion about like you

know should you like teaching people how

to use mail envelope or how it comes

built in with like firefox or uh not

firefox um thunderbird and uh i saw some

people said that they've actually stopped

using encrypted email providers for that

reason specifically but i don't know i uh

i also wanted to talk about this because

i have opinions about this and uh i

actually don't know

I'm assuming you are probably on the same

page as me with this one,

but in your opinion,

is there a point to using an encrypted

email provider even if nobody else is?

Yeah.

I think we hammered this down pretty hard

on our website actually,

but the main reason we recommend these

providers is their protection at rest,

and especially if you can prevent the

provider from having the keys to open

that, that would be great.

A lot of people will say, well,

your data is encrypted by email.

Google and their servers because they use

disk encryption.

But Google has the keys to unlock it.

So how secure is that really?

Whereas with Proton,

you have the key to unlock it and

they can't do it.

And I think that in terms of long

term storage of emails,

you might be emailed a lot of sensitive

information.

You're certainly emailed like a lot of

account related stuff.

But like I almost never

use email for communication because

there's no point to it.

And we really, I think,

discourage people from using email for

communication in general.

And so

I think we're not really pushing for a

lot of end-to-end encryption for email

just because there are much better

platforms to use if you want to

communicate securely.

Whereas I just use it as an inbox

for all the accounts that I have.

And having that data encrypted at rest is

very important to me.

And that has nothing to do with the

end-to-end encrypted stuff.

Anyways,

what I would say is it's probably a

good thing that we're not focusing so much

on end-to-end encryption in email because

I think everyone should spend their time

switching to better instant messengers

like Signal instead of working on that.

Yeah, for sure.

I feel kind of the same way.

It's to me,

I think of it in terms of like

a data breach.

Like, okay,

if I'm using Proton or Tudor and I'm

communicating with people who are using

Gmail and Outlook and whatnot,

if that person has a data breach, yes,

my correspondence with them is going to be

leaked,

But it's not gonna be my whole inbox.

Like you said,

it's not gonna be my doctor's office,

my bank, all these different things.

That's not gonna be in there.

It's going to be my communication with

them, which may still be bad,

but it's not as bad.

And to me,

it's also cutting the risk in half

because, like you said,

my inbox is still encrypted at rest.

And that can't be as easily breached as

something like Gmail or Outlook,

especially Outlook.

So it's again, yeah,

it's not a perfect solution,

but it's a it's a risk reduction solution.

So I still think it's worth it.

Also, again, you know,

these providers are not like farming your

your email for marketing information,

which I think Google said they stopped

doing that, but whatever.

And yeah, I had that in the notes,

too,

that email is a legacy tech to begin

with.

And all these things like PGP,

even like Tudor,

I know Tudor like has their own version

of PGP where they encrypt even more

metadata.

But even that is still just like adding

band aids on top of email.

And there are better things like Signal or

SimpleX or whatever.

So but unfortunately,

we are at a point where, you know,

my bank is not going to signal me

a login code.

So we do still need email from time

to time for sure.

Yeah.

Jordan just said that,

but it would be nice if we could

use something else,

but I don't see that happening anytime

soon.

Yeah, Intel just said it's the standard,

and it is.

And it's just so entrenched in everything

that it's very unlikely that we'll switch

away from using it.

But protecting as much as you can,

I think...

I think the risk of,

just from a security perspective,

the risk of a data breach impacting your

email provider is much higher than the

risk of your emails being intercepted

live.

That all depends on your threat model,

of course,

but end-to-end encryption is a huge

benefit just for that data at rest against

data breaches,

even if it doesn't stop active attackers.

Switching to something like Proton,

even if you can't convince anyone else to

switch, and I think somebody even said,

yeah, anonymous once,

I'm not going to spend time on convincing

people to change email for writers.

Yeah,

I think that's not the best use of

anyone's time, but...

It would be great if people switch because

it would secure their own emails.

And just from a personal perspective,

it's one of those things where if you

switch, you benefit a lot,

even if nobody else uses it.

I think that's a problem that we have

with instant messengers when we think

about Signal or SimpleX.

like you don't get a lot of benefit

from Signal if nobody else is using

Signal.

So there's more of that problem,

but there's a clear benefit to switching

to a more private, secure email provider.

So yeah, highly recommend.

Yeah,

that's something I think about that I'm

probably gonna write a blog post at some

point about is like there's certain

privacy actions that do require you to get

other people to change, like you said,

like using Signal or something.

But then there's a lot of things that

you can do yourself that don't depend on

anybody else.

Like you can switch to Brave or Firefox.

You can switch to Linux if you can

afford to do that.

Yeah,

you can switch to a private email

provider.

Like there's a lot of privacy stuff you

can do on your own for sure, so.

Anyways, on that note,

I'm going to turn things over to you

now and you can tell us all about

this new attack.

This is actually our last story of the

day.

So if anybody has been holding on to

any questions that you haven't asked yet,

please do drop those in the chat and

Jonah will tell us all about this new

attack.

Yeah, Fria wrote this article,

new attack can track you across operating

systems without elevated privileges.

Fria, sorry,

researchers at the Graz University of

Technology Austria demonstrated a new

attack that can track you via file change

events on all systems allowing for various

data leaks.

They say that modern operating systems

like Linux,

Windows and Mac OS provide built in

subsystems to monitor file system events.

I notify redirectory changes to view NFS

events.

User processes,

programs on your computer can subscribe to

receive file operation notifications when

actions like accessing, writing,

opening and closing are performed on a

monitored file or directory.

And so the research paper that was

published essentially points out that

these tools can be used by programs to

read information about

large number of operating system files and

other files on your computer.

A lot of these files that can be

read or that you can monitor events for

can be read by any program without any

special privileges.

I saw people talking about this story on

Reddit on the r slash privacy subreddit.

And I think people were like, well,

this attack can only be,

it only matters if you're like locally

running software.

It's not like an attack you can get

over the internet.

But I didn't really understand that

argument because malware exists.

People are downloading software on their

computers all the times and this,

I think it gives any malware a large

amount of insight into your system and

what's running on it without that malware

needing any special permissions other than

just running on your device.

So it's not something that would need to

escalate to admin privileges.

And according to the researchers in this

paper,

it leaks a lot of information that

like more information than you would

think.

So it says on Linux,

they were able to achieve a keystroke

timing attack,

which is a type of side channel attack

that measures the timing between key

presses in order to infer information

about the text being typed,

including the actual text.

That attack could potentially leak

passwords or sensitive text being typed,

such as private messages.

They were also able to perform a

fingerprinting attack on the top one

hundred websites,

since visiting certain websites would

trigger specific access patterns for fonts

in the fonts directory.

So from just this alone,

an attacker can figure out what websites

you're visiting,

basically

malware running on your computer without

any access to your browser at all,

because it's sandbox,

can see whether you're accessing a certain

site, like a major one,

or at least guess and potentially track

you based on just files in the operating

system that can be read by pretty much

any software running on your device.

So I think it is a concerning problem.

And the paper also goes into

similar attacks to that on on Android,

on Windows, on Mac OS.

So, yeah, if you read this article,

you can read some specific attacks in the

paper is is linked.

But I think that that is kind of

the the situation there.

So, yeah.

Do you have any thoughts about like the

malware running on your computer side of

things or anything like that?

Well, I do want to answer,

username is Nye, said,

is this article peer-reviewed?

I don't think so,

but it is kind of confirmed.

The last sentence of the article says,

in particular,

Microsoft stated that the private data

leakage was actually there by design,

which is a pretty insane thing to say,

but whatever.

Yeah, I think, to me,

the thing that stuck out to me, so,

okay,

I know this was an hour and a

half ago,

but at the beginning of the live stream,

I talked about

that video from Side of Burritos where he

demonstrated how the secure clipboard

works on graphene.

And one thing he pointed out is that

there are certain apps that as soon as

you copy something to the clipboard,

as soon as you open the app,

before you even hit paste,

they already read what's on the clipboard.

So if you've got,

let's say you've got three apps open,

and you're trying to copy from app A

to app C,

but you accidentally open app B along the

way for whatever reason,

and it's one of those apps that does

that, even though you never hit paste,

it can read what's on your clipboard.

So to me, and for the record,

I don't think all apps do that,

I'm just saying some have that capability,

which is why the secure clipboard exists.

So to me,

that kind of reminds me of this thing,

where when we talk about malware,

we talk about malware, right?

Like whether it's bundled in a cracked

game or a phishing link or something,

but I'm also thinking of just really

shady, unethically acting apps,

like a game you download or anything from

Meta that is not technically malware,

like it is not actually malware in the

literal sense,

But it basically behaves like malware.

And now it's probing your system and doing

all this stuff.

And now it could potentially be picking

up,

even if it's hopefully not picking up your

actual passwords and the messages you're

texting,

it could still be tracking what websites

you visit.

Like you said,

even though the browser is sandbox,

it can still use these other side channels

to track what you're doing and pick up

information that it's not supposed to

have.

And it's not a virus.

It's not actual malware.

It's just behaving like it.

And yeah, it just...

To me,

that's the big thing that stuck out to

me.

It's like, this is a problem,

and this is actually why I wanted to

include it on this stream,

is because it's like,

this isn't strictly malware.

This could be...

Sorry, I know I'm rambling a little bit,

but that whole thing with Signal a year

ago where Signal was storing the

encryption keys unencrypted on Windows

devices on the desktop,

and everybody was like, dude,

what the heck?

And they're like, well,

if you have malware on your computer,

you're already screwed anyways.

Okay, what if I don't have malware?

What if I have this?

So, yeah, I don't know.

To me,

this is just a really important thing,

and Microsoft is completely insane for

saying, yeah, we know.

I digress.

Let's see.

This sounds like a thing that does not

sound bad until more research is done and

then a real world targeted attack gets

done to show us an actual example.

Yeah, that too.

Now that it's out there,

how many tech bros,

this will be a quick rant, I promise.

How many tech bros watched Black Mirror

and then went, hey,

that's a good idea for a business?

How many other tech bros do you think

are gonna read this article and be like,

ooh, build this functionality in?

So yeah, pretty bad.

It's a situation like this malware can't

in a lot of cases,

read the files involved.

But if you can read all this metadata,

we talk about metadata,

revealing all sorts of sensitive

information all the time,

just in so in this case,

like just the idea that software can see

when you open the file,

even if it knows nothing about the file

itself,

that can reveal a lot of information.

So yeah, all of this metadata protection,

I think needs to be,

like always taken taken more seriously

than it than it often is.

I just want to say,

I think I might go back and read

the actual paper itself because I want to

see if Microsoft justifies why this is

there by design.

Like, what do you, why?

What purpose?

I don't know.

But yeah,

I don't really know if there's any,

because again, this doesn't necessarily,

this isn't taking advantage of any

vulnerabilities.

This doesn't,

um this isn't uh like actual malware so

i don't know if there's any defenses

against this other than don't use windows

um but yeah just being careful what you

download and run uh hopefully apple and

linux will roll out some some fixes for

this but yeah you got any additional

thoughts uh yeah i don't think so just

just goes to show that you know any

any local software you run just like you

said can

running anything locally will give will

give programs a lot of information about

you,

regardless of like privileges in a lot of

cases,

just because the operating system is so

vast, right?

There's so many potential things that

software can access that it just isn't

locked down.

So being aware of that is important.

Yeah, yeah, if you need further examples,

y'all should look up what's going on with

Meadows Muse AI on Mac.

That is the gift that keeps on giving.

Username is Nye said,

did you watch the Hotel Reverie episode?

No,

I haven't watched anything since the

season with Miley Cyrus doing Nine Inch

Nails songs.

I want to, I just,

I'm not gonna lie,

This is going to sound completely

deranged.

I miss the old Black Mirror where I

would watch an episode and be like, wow,

that was really good.

That was also really intense and soul

crushing.

And I can't watch another episode for at

least a week.

And I miss that version of Black Mirror.

Now it's more just like sci-fi,

like occasionally a little bit bleak.

And I'm like,

like that season I mentioned,

I binged that entire season in two days,

which at the time I was still working

like my super long hour job.

So two days is really fast for me,

was really fast for me.

So it's like,

What happened to that Black Mirror where

it's like every episode crushed me

internally?

Yeah,

I'm sure the creator of Black Mirror has

definitely said this in numerous

interviews.

But with this type of show,

you can't outpace reality at this point.

It's hard to think of things that wouldn't

already be done.

And I think some of the most recent

seasons of Black Mirror were absolutely

all about that.

Like that one where they made a parody

of Netflix.

But Netflix basically does...

They're working on all the stuff in that

episode.

They're working on AI content.

They're working on content specifically

tailored to you.

Yeah,

I just think that we've seen a lot

of the Black Mirror stuff come true.

It's real products.

I will say I did watch Hotel Reverie.

That was a great episode.

Yeah.

I mean,

I'm definitely planning to catch up.

I've actually been the last six months or

so,

I've really been putting a dent in my

to watch list and I've been catching up

on stuff.

So it's on my list.

It's just not very high on my list

because there's so many other things that

like, you know,

It's like,

I've been meaning to watch this forever.

I was really excited about this and I

just never had time.

And so, yeah,

and I'll get to it eventually for sure.

But yeah, I get what you mean.

Like the onion is like that too.

Like they have to go so ridiculously over

the top now because politics has gotten so

ridiculous.

It's the only way they can,

which that's a different thing.

But Jordan said,

is it really a stream if Nate doesn't

talk about sci-fi?

Yeah.

I was actually going to throw it out

there.

Since it's October,

I know a lot of people are doing

that thirty one for thirty one thing.

If you all have any horror movies you

think I should check out, definitely.

I don't think you can message me on

the forum.

I think I shut that off,

but I don't know.

We need to start a forum thread for

this.

I'm down.

Yeah, leave it in this forum thread.

I don't know, ping me.

I don't even know what Thirty One for

Thirty One is, should I?

Am I missing out?

I mean,

I'm not going to do actual Thirty One

for Thirty One because I'm just not that

committed.

It's basically every day of October you

watch a different horror movie.

And I mean,

I guess the good news is you can

circle back.

It can be movies you've seen before.

Good excuse to watch The Invisible Man

again.

I love that movie.

That is a, oh my God,

that is such a good movie.

Yeah, I love that one.

I don't know.

I've been on kind of a horror movie

kick.

I finally watched Weapons.

I finally watched Fall of House of Usher.

I've got like,

twenty minutes left on the black phone,

too, because I'm just, like I said,

I'm not that invested.

I mean,

I'm invested enough that I'm gonna finish

it, but it's like, you know,

I started watching it last night,

and it was like,

it got to be about bedtime and it

was still like an hour left in the

movie.

And I'm like, yeah, no,

I'm not that invested.

I'm going to bed.

And then today,

Fridays are always my busy day because of

the show.

So username is not,

the onion has no more material left.

How can anybody really, I think, I mean,

we definitely see that in black mirror.

I think the last season of black mirror,

uh,

unless there's been a more recent one that

i am unaware of i don't i don't

know how often they make these but the

last one that i saw it kind of

ended on like a werewolf note like we're

just getting out of sci-fi now you're kind

of you're trying to spin off into a

new franchise it seems like because you

just can't come up with any more any

more bleak tech stuff anymore i think the

the tech space is just bleak as is

so it's not not it's no longer

groundbreaking

I wonder if he's just afraid to inspire

more people.

Like I have a ton of ideas,

but I know that they keep watching this

and every time, because I'm telling you,

I've seen so many news articles and it's

like, oh,

there's this new startup that does this.

And I'm like,

that is literally a Black Mirror episode.

Why?

So I digress.

Yeah, I'm looking in the forum.

I'm looking in Signal.

I'm not seeing any more questions.

So unless you or anybody else has

anything, I think we can wrap this up.

Yeah, probably can wrap it up.

I mean,

we've asked for questions this whole time.

So if you haven't sent it in yet,

I think that's on you,

but you can save it for the next

stream.

For sure.

Yeah.

Do you want to wrap this up, Nate?

Sure.

I got this.

All right.

So all the updates from this week in

privacy will be shared on the blog every

week.

So sign up for the newsletter or subscribe

with your favorite RSS reader.

If you want to stay tuned as a

reminder,

that newsletter actually goes out right at

the same time that we start streaming.

So that works as a good notification as

well.

And there's a link to the stream in

the newsletter.

So super convenient, super easy.

We also offer a podcast available on all

podcast platforms and RSS,

which now includes video on supported

platforms, if you prefer that.

And this video will also be synced to

PeerTube.

PrivacyGuides is an impartial nonprofit

organization that is focused on building a

strong privacy advocacy community and

delivering the best digital privacy and

consumer technology rights advice on the

internet.

If you want to support our mission,

you can make a donation on our website

at privacyguides.org slash donate.

You can also make a donation on any

page of the website by clicking the red

heart icon located in the top right corner

of the page.

You can contribute using standard fiat

currency via debit or credit card,

or you can donate anonymously using Monero

or your favorite cryptocurrency.

Becoming a paid member unlocks exclusive

perks like early access to video content,

exclusive video content,

and priority during the Q&A.

You'll also get a cool badge on your

profile in the Privacy Guides forum and

the warm,

fuzzy feeling of supporting independent

media.

Thank you everyone who watched.

It was awesome to have you guys in

the chat and we will be back next

week.

Thanks everyone.