1
00:00:01,260 --> 00:00:07,700
This week's surveillance report covers France's first in Europe ban on social media for under 15s.

2
00:00:07,920 --> 00:00:14,300
And fortunately, there is somewhat good news out of the UK and California to help balance that out.

3
00:00:14,720 --> 00:00:19,260
A hidden device leaving US cars open to hacking, statistics undercutting chat control,

4
00:00:19,620 --> 00:00:22,940
a wave of platform openness rulings against Apple and Google,

5
00:00:23,460 --> 00:00:26,980
plus the usual data breaches, threats, and open source updates,

6
00:00:27,640 --> 00:00:30,360
closing out with actually an update from ourselves as well.

7
00:00:30,920 --> 00:00:32,320
Welcome to the Techlore Surveillance Report,

8
00:00:32,400 --> 00:00:34,540
your weekly essential tech news,

9
00:00:34,740 --> 00:00:36,580
delivering deep analysis on the latest threats

10
00:00:36,860 --> 00:00:38,440
to security, privacy, and digital rights,

11
00:00:38,620 --> 00:00:42,240
and empowering you to reclaim control and defend your rights.

12
00:00:42,620 --> 00:00:43,080
Welcome, everybody.

13
00:00:43,220 --> 00:00:44,560
We got a pretty good week this week,

14
00:00:44,740 --> 00:00:46,160
and I'll do my best to give you all the news.

15
00:00:46,440 --> 00:00:46,900
Let's get into it.

16
00:00:47,060 --> 00:00:48,920
So today's episode is going to start in Europe,

17
00:00:49,240 --> 00:00:50,420
specifically in France.

18
00:00:50,720 --> 00:00:52,540
So Australia was the first country

19
00:00:52,640 --> 00:00:54,840
to try a social media ban for minors,

20
00:00:55,040 --> 00:00:56,100
and it's getting around it.

21
00:00:56,380 --> 00:00:57,600
It's calling into question

22
00:00:57,620 --> 00:01:02,180
the privacy implications. There's also this whole thing of having the companies who are the problems,

23
00:01:02,460 --> 00:01:07,420
having to collect more personal data about people, and now putting more trust in their hands to

24
00:01:07,660 --> 00:01:10,900
regulate themselves. And then we also have this whole thing of like, well, we're not actually

25
00:01:11,120 --> 00:01:15,260
changing these platforms. Once these kids turn whatever age they're allowed to use the platforms

26
00:01:15,580 --> 00:01:19,760
again, they're back on the same exploitive crappy platforms that have existed now for the last 10

27
00:01:19,940 --> 00:01:24,100
years or longer for some of them. But France has decided that this is what they want to do.

28
00:01:24,240 --> 00:01:29,500
So French lawmakers approved on Tuesday a ban on social media access for children under the age of 15.

29
00:01:29,900 --> 00:01:37,140
In terms of the reasoning, President Macron, who in April urged young people to switch off their phones and read in order to become better citizens,

30
00:01:37,400 --> 00:01:40,900
wants the law in place in time for the start of the next academic year.

31
00:01:40,920 --> 00:01:48,520
So if you're curious for the timing on how that works, children younger than 15 right now will not be allowed to open a new social media account from September 1st.

32
00:01:48,640 --> 00:01:52,660
And honestly, those are kind of the established facts of the story.

33
00:01:52,700 --> 00:01:53,940
There isn't too much yet.

34
00:01:54,260 --> 00:01:55,960
There aren't even that many quotes from it.

35
00:01:56,170 --> 00:01:59,660
It was a pretty wide majority of people who approved this in parliament.

36
00:02:00,240 --> 00:02:06,360
I get especially frustrated because I understand why people want to rein in these big tech companies and these social media platforms.

37
00:02:06,920 --> 00:02:17,400
I have massive problems with these platforms, but I also have massive problems in just banning them outright and just telling kids not to be on them, especially when we actually look at the technology required to do that.

38
00:02:17,660 --> 00:02:20,880
the privacy implications, whether or not they've actually been shown to work,

39
00:02:20,990 --> 00:02:24,500
which if you look at Australia, which is already past this in December of last year,

40
00:02:24,960 --> 00:02:28,940
it's not working very well. These kids are getting around it. They're using VPNs. And in

41
00:02:28,940 --> 00:02:34,180
the UK, they've also done similar things. And the UK continually teases this concept of banning VPNs

42
00:02:34,520 --> 00:02:39,140
and trying to go to the next downstream thing without actually fixing the real upstream issue.

43
00:02:39,210 --> 00:02:43,959
And I think that's really what I'm trying to target here. Banning social media is a potential

44
00:02:43,960 --> 00:02:48,040
solution, but it's going to create so many more downstream impacts like the ones I've covered.

45
00:02:48,460 --> 00:02:52,900
Whereas if we look a little bit more upstream of this issue, we see the real problem with these

46
00:02:53,080 --> 00:02:56,920
platforms and how universal they are. It's the fact that they are collecting such data in the

47
00:02:57,120 --> 00:03:01,400
first place and they're using that data to exploit you as an individual. It's the fact that they have

48
00:03:01,520 --> 00:03:05,660
algorithms that are designed to be addictive. They implement dark patterns. These are tech companies

49
00:03:05,860 --> 00:03:10,980
that are literally hacking human biology and just banning it from people under 15, I think sends the

50
00:03:11,000 --> 00:03:15,620
wrong message. I also know that the reality is the internet is how people are doing things.

51
00:03:16,140 --> 00:03:20,740
Really radical response to try to do something people have neglected for over 10 years.

52
00:03:21,260 --> 00:03:25,300
This has been happening this whole time, and it's just taken too long for anyone to do anything

53
00:03:25,540 --> 00:03:29,820
about it. And I think this is the radical approach, which frustrates me, but that's why I'm here to at

54
00:03:29,840 --> 00:03:33,560
least give you my take. And also, if you're in France, you can still contact your politicians,

55
00:03:33,720 --> 00:03:38,419
but especially if you're outside of France and the rest of Europe, and also any region at this point

56
00:03:38,440 --> 00:03:42,000
in the world. It's important to contact your politicians about this stuff because, again,

57
00:03:42,360 --> 00:03:47,740
it seems like and sounds like it's very popular to people because the overall premise sounds good,

58
00:03:48,020 --> 00:03:52,840
but the actual implementation and we see countries that integrate this, it is not good. And so it's

59
00:03:52,920 --> 00:03:56,880
important to educate people accordingly. If you're listening to this podcast, I think it's the number

60
00:03:56,960 --> 00:04:03,260
one thing you can do this week. Now, it is not all bad news. There is a bit of good news here. Now,

61
00:04:03,520 --> 00:04:09,320
The UK actually got a new prime minister, Andy Burnham, and he is planning digital ID scheme.

62
00:04:09,640 --> 00:04:13,260
He's pretty much come forward and said, hey, this is all a distraction.

63
00:04:13,560 --> 00:04:14,980
We want to focus on the cost of living.

64
00:04:15,580 --> 00:04:17,120
This isn't something we want to focus on.

65
00:04:17,140 --> 00:04:19,700
So let's focus on the economy and what really matters to people.

66
00:04:19,780 --> 00:04:22,180
And so he's pretty much saying we're not going to do this anymore.

67
00:04:22,420 --> 00:04:25,880
Now, I do want to be clear here because there's a lot of stuff going on in the UK,

68
00:04:26,180 --> 00:04:29,260
and a lot of them actually function quite independently of one another.

69
00:04:29,720 --> 00:04:32,640
So we have the UK going after these social media bans.

70
00:04:32,780 --> 00:04:34,240
They also tease VPN bans.

71
00:04:34,440 --> 00:04:35,520
This has nothing to do with that.

72
00:04:35,800 --> 00:04:39,460
They're also targeting many other things right now in the space, like age verification.

73
00:04:39,960 --> 00:04:42,500
I don't think this even necessarily touches on that.

74
00:04:42,900 --> 00:04:46,840
What this is specifically is, and this was covered on the podcast, but it was from a long

75
00:04:46,960 --> 00:04:50,540
time ago, it's this scheme to tackle illegal immigration.

76
00:04:50,900 --> 00:04:55,340
So think of this more as like a digital passport and a way to just verify your identity on the

77
00:04:55,520 --> 00:04:55,640
internet.

78
00:04:55,780 --> 00:04:59,780
So this is actually a lot of things that are of concern in the UK right now.

79
00:05:00,140 --> 00:05:04,600
And so this is something that is a small win in the right direction, but I'm still following

80
00:05:04,620 --> 00:05:05,760
a lot of other UK news.

81
00:05:05,980 --> 00:05:07,880
So I guess we'll see where the UK heads.

82
00:05:08,020 --> 00:05:11,460
Maybe this kind of leadership change may change things drastically for the other places.

83
00:05:11,920 --> 00:05:12,400
Time will tell.

84
00:05:12,660 --> 00:05:13,220
Stay subscribed.

85
00:05:13,480 --> 00:05:14,720
I will definitely let you all know.

86
00:05:15,540 --> 00:05:20,880
Now, another piece of good news here is that California Senate has dropped browser age ID

87
00:05:21,160 --> 00:05:23,420
mandates, but the operating system checks still remain.

88
00:05:23,660 --> 00:05:28,180
So I did coverage for this in a dedicated video not too long ago on the main Techlore channel.

89
00:05:28,780 --> 00:05:31,260
But California has been teasing age verification.

90
00:05:31,650 --> 00:05:34,740
But apparently this age verification is designed to be grouped into buckets.

91
00:05:35,340 --> 00:05:40,160
And it's attestation, I believe, which if I'm getting the terminology correct,

92
00:05:40,420 --> 00:05:42,340
means that there isn't verification beyond that.

93
00:05:42,460 --> 00:05:46,160
But this is actually what prompted the entire Linux world to freak out

94
00:05:46,170 --> 00:05:49,900
because it requires Linux users to have to then start signaling to developers.

95
00:05:49,950 --> 00:05:53,420
And this is built into the operating system what age each user is.

96
00:05:53,450 --> 00:05:56,640
And so you started saying to Linux community, go crazy about this.

97
00:05:56,860 --> 00:05:59,660
And you started seeing forks of projects saying we're not going to add this in.

98
00:05:59,860 --> 00:06:03,920
Some projects even said we're not going to deliver software anymore to California as a result.

99
00:06:04,180 --> 00:06:06,480
So there's a few things going on here that I want to be clear about.

100
00:06:06,540 --> 00:06:10,020
There was two different pathways that they were looking to explore this age bracketing scheme.

101
00:06:10,580 --> 00:06:12,080
The first was actually in browsers.

102
00:06:12,580 --> 00:06:14,760
So a browser gets your age scheme.

103
00:06:15,260 --> 00:06:20,220
Ideally, you just say what it is, but it's unclear quite what that would look like because it hasn't been done yet.

104
00:06:20,620 --> 00:06:23,180
And then each site could essentially request that from the browser.

105
00:06:23,580 --> 00:06:27,640
And then the second version of this was from the operating system to specific applications.

106
00:06:27,980 --> 00:06:30,200
Now, they have dropped the browser level one.

107
00:06:30,220 --> 00:06:32,060
So that is the big positive news here.

108
00:06:32,280 --> 00:06:37,340
And also for those who missed it, they actually did add an exemption for open source operating

109
00:06:37,500 --> 00:06:38,180
systems as well.

110
00:06:38,200 --> 00:06:42,100
So if you're using any kind of open source operating system, you don't have to worry about

111
00:06:42,320 --> 00:06:42,420
this.

112
00:06:42,640 --> 00:06:47,520
But if you're using Apple, Microsoft Windows, anything there, there is this age bracketing

113
00:06:47,800 --> 00:06:47,880
scheme.

114
00:06:48,200 --> 00:06:50,020
This still isn't signed into law.

115
00:06:50,220 --> 00:06:53,560
It still needs a governor's signature and there's still unfolding things about it.

116
00:06:53,560 --> 00:06:57,680
So it's not too late to still continue to contact your representatives, especially in California.

117
00:06:58,380 --> 00:07:05,140
But they also talk about a lot in this article about Texas and the different approaches they're taking and how Texas hasn't been backing off on theirs.

118
00:07:05,480 --> 00:07:07,680
So there's a lot of stuff going on all around the world right now.

119
00:07:07,750 --> 00:07:10,180
And so I really want us to zoom out.

120
00:07:10,490 --> 00:07:12,480
And, you know, you might be listening in from the Netherlands.

121
00:07:12,570 --> 00:07:13,920
You might be listening in from Canada.

122
00:07:13,970 --> 00:07:15,740
You might be listening in from Brazil.

123
00:07:16,160 --> 00:07:17,480
wherever you're listening in from,

124
00:07:18,120 --> 00:07:21,140
just remember that these things are spreading like wildfire.

125
00:07:21,280 --> 00:07:23,360
So right now I'm talking about these three regions.

126
00:07:23,560 --> 00:07:25,200
But last week it was a different set of regions,

127
00:07:25,340 --> 00:07:27,740
and I'm sure next week will be a different set of regions.

128
00:07:27,820 --> 00:07:29,920
And so that's why it's important to keep up with this news,

129
00:07:30,140 --> 00:07:33,040
whether it's on your own time or if it's the podcast or the newsletter.

130
00:07:33,520 --> 00:07:34,400
Keep up with this stuff.

131
00:07:34,660 --> 00:07:37,960
And also make sure that you're trying to find even a subtle way to get involved,

132
00:07:38,140 --> 00:07:41,320
whether it's contacting your reps, whether it's educating people around you,

133
00:07:41,380 --> 00:07:44,440
whether it's just making a single post on socials if you're on social media.

134
00:07:44,760 --> 00:07:46,640
And just communicate some concerns you have with it.

135
00:07:46,660 --> 00:07:48,660
It doesn't have to be a massive essay.

136
00:07:49,120 --> 00:07:51,440
I think just getting the word out, educating people,

137
00:07:51,820 --> 00:07:53,720
communicating with the politicians as best you can,

138
00:07:53,840 --> 00:07:55,340
it can actually make a pretty big difference

139
00:07:55,840 --> 00:07:57,220
when you have thousands, hundreds of thousands,

140
00:07:57,340 --> 00:07:58,900
even millions of people getting involved.

141
00:07:59,100 --> 00:08:00,680
So make sure to find a way to get involved

142
00:08:01,020 --> 00:08:03,540
that is most aligned with what you're good at

143
00:08:03,660 --> 00:08:04,640
and what you enjoy doing.

144
00:08:10,820 --> 00:08:14,720
All right, this next story is a very exciting one

145
00:08:14,740 --> 00:08:20,060
cover. Well, it's not exciting. It's actually not really good, but it's exciting from a technical

146
00:08:20,400 --> 00:08:24,980
perspective because there's a lot of lessons here and I just thought across the United States that

147
00:08:25,100 --> 00:08:30,600
leaves them completely vulnerable to hacking and paralysis. The overall concept here starts

148
00:08:31,100 --> 00:08:37,919
with something called a car alarm device, K-A-R-R. These are installed by typically car dealers,

149
00:08:38,280 --> 00:08:43,620
not manufacturers or owners, and used as a measure to prevent auto theft from the lots of these

150
00:08:43,640 --> 00:08:48,420
dealers. Yet when the cars are sold, the alarms typically aren't removed, even if the buyer

151
00:08:48,560 --> 00:08:52,840
declines to pay for it as an additional feature. This means that car owners across the U.S. have a

152
00:08:53,020 --> 00:08:56,840
hackable device under their hood whose code they'll need to update to protect their vehicle,

153
00:08:57,360 --> 00:09:02,560
but one that in many cases they never purchase and have no idea is there. So there is a very good

154
00:09:02,780 --> 00:09:06,940
chance that if you have a vehicle in the U.S., you could even have this thing in it and not know. So

155
00:09:07,120 --> 00:09:12,000
everybody, especially in the U.S., listening to this with a vehicle should probably follow up,

156
00:09:12,080 --> 00:09:14,560
and I'll have some more actionable steps as we go along.

157
00:09:14,940 --> 00:09:17,920
This discovery came from researchers at UC San Diego,

158
00:09:18,240 --> 00:09:19,960
and this happens all over Bluetooth.

159
00:09:20,400 --> 00:09:22,320
And again, I do want to cite here in the article,

160
00:09:22,390 --> 00:09:24,260
they say at least half of car owners

161
00:09:24,350 --> 00:09:25,740
who have this car device installed

162
00:09:26,040 --> 00:09:27,460
didn't ask for it to be in their vehicles.

163
00:09:27,860 --> 00:09:29,760
So you should check for a car sticker

164
00:09:29,810 --> 00:09:31,080
in your car's driver's side window,

165
00:09:31,480 --> 00:09:33,780
or in some cases, a sticker reading SWDS

166
00:09:34,300 --> 00:09:35,580
for Southwest Dealer Services.

167
00:09:35,840 --> 00:09:37,080
You can also look for a small button

168
00:09:37,170 --> 00:09:38,380
with a blinking light attached

169
00:09:38,480 --> 00:09:40,060
to the underside of your car's dashboard.

170
00:09:40,520 --> 00:09:44,600
Apparently, car owners in Southern California are the most likely to have this device installed

171
00:09:44,650 --> 00:09:47,560
due to popularity among car dealers in that specific region.

172
00:09:48,060 --> 00:09:52,180
So these exploits that they found in this device can, with the tap of a button,

173
00:09:52,740 --> 00:09:54,920
unlock a car at a start to prevent it from starting,

174
00:09:55,260 --> 00:09:59,300
or it even has a mayhem button that they built into the app to hack a group of cars

175
00:09:59,740 --> 00:10:02,700
to simultaneously and repeatedly trigger their horned lights.

176
00:10:03,320 --> 00:10:08,080
Now, there is a video of this happening, which I recommend you all see in the show notes

177
00:10:08,390 --> 00:10:09,920
if you are watching the video version.

178
00:10:10,940 --> 00:10:14,780
you're going to see them tap the mayhem button here and you're going to see all the cars behind

179
00:10:14,930 --> 00:10:19,460
them light up, which is pretty wild. Again, it's all over Bluetooth. The only thing that they can't

180
00:10:19,580 --> 00:10:23,580
do, which is somewhat good news, is that they can't actually start the car's ignition. So there is a

181
00:10:23,760 --> 00:10:28,300
silver lining here. But they did show how a locksmith tool, commonly available for resale, can, once a

182
00:10:28,300 --> 00:10:31,760
car thief is inside the vehicle, be plugged into the car's dash to create a working key within a few

183
00:10:31,920 --> 00:10:35,899
minutes and drive it away anyway. The security flaw here is that they used a single authentication

184
00:10:35,900 --> 00:10:40,980
key shared across all car devices. So the UCSD researchers spotted that key in the code of the

185
00:10:41,180 --> 00:10:45,640
smartphone app, which customers who pay for the alarm can use to control it. And with that key

186
00:10:45,760 --> 00:10:50,000
and the homemade app they created by reverse engineering the car's app code, they found they

187
00:10:50,000 --> 00:10:53,620
could just spoof radio commands that would be accepted by any nearby Bluetooth-enabled car

188
00:10:53,880 --> 00:10:59,420
device. Very poor implementation of something that should be considered basic security. And the fact

189
00:10:59,500 --> 00:11:03,779
that dealers weren't removing these from your car and it could just be on a car that you own is

190
00:11:04,100 --> 00:11:11,740
wild. So takeaways here. Cars in general are kind of a nightmare still in 2026. So I like to really

191
00:11:11,880 --> 00:11:16,760
proceed with caution here and advice because there isn't a huge amount you can do. You know, a lot of

192
00:11:16,880 --> 00:11:23,180
people online are going to tell you, oh, that's why I drive around my 1964 vehicle and it avoids

193
00:11:23,320 --> 00:11:27,620
all these problems. And it's like, okay, that's great. But also a lot of people have newer vehicles

194
00:11:27,960 --> 00:11:31,980
and you can't get around some of these problems. So I always like to look at opt-outs when possible.

195
00:11:32,440 --> 00:11:35,900
You have tools like privacy for cars that do exist on their sites.

196
00:11:36,080 --> 00:11:40,180
There is a bit of a paid funnel there, but you can do a free scan to see what kind of

197
00:11:40,340 --> 00:11:42,600
data is collected by your car's manufacturer by default.

198
00:11:43,140 --> 00:11:46,760
It's good to check in with your dealer when you're purchasing your vehicle to ask, hey,

199
00:11:47,160 --> 00:11:51,240
are there any add-ons or devices that are in this vehicle that I should know about?

200
00:11:51,580 --> 00:11:55,720
And now we know the name KARR is a good name to throw around if you're getting a new vehicle

201
00:11:55,830 --> 00:11:56,180
as well.

202
00:11:56,480 --> 00:11:58,740
Again, utilize opt-outs when possible.

203
00:11:59,140 --> 00:12:04,060
And if you really want to go on the more extreme side of things, on most cars, you can typically

204
00:12:04,290 --> 00:12:09,800
find a way to disable the cell modem or remove the SIM card or have some way to take the

205
00:12:10,040 --> 00:12:10,660
vehicle offline.

206
00:12:10,890 --> 00:12:14,340
But that typically will come with some kind of usability limitation.

207
00:12:14,820 --> 00:12:16,720
This is a very difficult place for me to give advice.

208
00:12:16,830 --> 00:12:20,300
But all I can say is to at least be educated and alert about these things.

209
00:12:20,590 --> 00:12:24,840
And you can typically at least know what the risks are with your specific vehicle, which

210
00:12:24,840 --> 00:12:27,860
is better than not knowing the risks and just kind of yoloing it.

211
00:12:28,020 --> 00:12:33,260
And I think the best thing about knowing the risks, even if you can't solve all of them, is that you can keep it on the back of your mind.

212
00:12:33,340 --> 00:12:42,580
And as things develop, as we get more tools accessible to us, some of those might have some better overlap and be able to at least partly remedy some of those other concerns.

213
00:12:48,540 --> 00:12:52,060
Coming soon, we have Apple and Google being forced to open up.

214
00:12:52,480 --> 00:12:56,940
But before we get there, I just had a quick thread from Patrick Breyer from Europe about

215
00:12:57,500 --> 00:13:01,040
chat control and these new stats that came out speaking to how effective it is.

216
00:13:01,050 --> 00:13:05,720
Now, last week, I talked about chat control and how the EU, unfortunately, has decided

217
00:13:05,880 --> 00:13:09,960
to bring back chat control 1.0, which allows voluntary scanning of your data.

218
00:13:10,220 --> 00:13:14,320
Chat control 2.0 is the more concerning one because it attacks encrypted data, which is

219
00:13:14,400 --> 00:13:16,740
end-to-end encrypted and isn't supposed to be read.

220
00:13:16,750 --> 00:13:22,440
And it's in some ways just requiring backdoors into sensitive conversations, which is far

221
00:13:22,940 --> 00:13:27,820
but both of these are concerning. Now, we do have a guide coming out probably in the next 24 hours to

222
00:13:27,940 --> 00:13:32,380
48 hours on what you can do about chat control and what it looks like to keep your data safe from

223
00:13:32,380 --> 00:13:37,400
these kind of scanning tools. But I wanted to share a quick stat from Patrick Brayer that he posted on

224
00:13:37,500 --> 00:13:42,820
Mastodon because he says that tech reports have never been so unreliable. This came from the NCMEC

225
00:13:43,350 --> 00:13:49,240
slash US, and they found that in 2025, 52% of flags were legally irrelevant, which means of those

226
00:13:49,260 --> 00:13:56,160
scans that were done, those 113,000 private photos were wrongfully exposed. They also found that 40%

227
00:13:56,160 --> 00:14:01,760
of investigations targeted children aged 10 to 14 themselves, not actually people who are adults

228
00:14:01,940 --> 00:14:05,920
exploiting those children necessarily. They take those photos themselves or share them without

229
00:14:06,200 --> 00:14:11,860
thinking. Last year alone, these U.S. reports hit over 8,000 children in Germany, is what Patrick

230
00:14:12,220 --> 00:14:16,980
reported. They also found that 53% of investigations targeted minors themselves, which criminalized

231
00:14:17,020 --> 00:14:22,180
12,000 teenagers rather than going after the real people causing issues. And then Patrick has a good

232
00:14:22,180 --> 00:14:27,140
way of closing these stats out, which is the police crime clearance rate for the online distribution

233
00:14:27,460 --> 00:14:33,440
of illegal content online is already extremely high, reaching 87.1% in 2025. Now, again, this is

234
00:14:33,440 --> 00:14:37,340
a very sensitive topic, but it's important to discuss and it's important to have open conversations

235
00:14:37,640 --> 00:14:42,360
about it because it is a real issue online. So I don't want to dismiss this very real issue here,

236
00:14:42,460 --> 00:14:46,960
but I am in the camp of finding a real solution to it. And I don't think just that mass scanning

237
00:14:46,980 --> 00:14:51,100
out there is going to necessarily solve this problem. And that's what the stats are pointing

238
00:14:51,300 --> 00:14:55,300
at, too. There weren't any other EU chat control updates this week, but I at least wanted to put

239
00:14:55,420 --> 00:15:00,100
this on everybody's radar so you all can keep up with some stats given what happened last week.

240
00:15:00,320 --> 00:15:04,760
And because chat control 2.0 is still around the corner and we need to already be getting ahead of

241
00:15:04,900 --> 00:15:10,620
that. And you can go to fight chat control to get involved. It has never been easier with a site

242
00:15:10,720 --> 00:15:15,120
like fight chat control dot EU. It really makes a difference. They've already failed 2.0 before.

243
00:15:15,300 --> 00:15:19,900
we can do it again. We just got to keep fighting. All right. And we're about to get into the courts

244
00:15:20,100 --> 00:15:25,000
forcing Apple and Google to open up. But before then, I wanted to share a bit about our sponsor

245
00:15:25,050 --> 00:15:30,560
of this episode, Easy Opt Outs. They are who I personally use to remove my data from people

246
00:15:30,800 --> 00:15:34,980
searching where you live, your family members, and they just do this all behind the scenes without

247
00:15:35,240 --> 00:15:39,640
any direct relationship with you. And they take that profile and they give it to people searching

248
00:15:39,820 --> 00:15:44,500
websites who then profit off of your data without your knowledge. Now, there are many removal tools

249
00:15:44,520 --> 00:15:48,460
out there. But the reason why I like Easy Opt-Outs is it's not run by the data brokers themselves.

250
00:15:48,780 --> 00:15:53,120
It's just run by a couple guys who knew they could do it for a bit cheaper. It's also one of the two

251
00:15:53,280 --> 00:15:58,340
top performers in Consumer Reports' research from 2024, where they actually analyzed how effective

252
00:15:58,520 --> 00:16:02,520
these tools are. They were tied with Optory, but the difference with Easy Opt-Outs is it is a

253
00:16:02,800 --> 00:16:07,620
fraction of the price from Optory. Additionally, they only give your information to sites that

254
00:16:07,940 --> 00:16:12,439
actually already have it. They don't just mass send all your information to every person and call it

255
00:16:12,400 --> 00:16:16,360
a day. They actively look and you get a report quarterly with what that looks like. If you're

256
00:16:16,420 --> 00:16:20,020
going fully automated, this is the best recommendation I have to share with people, especially in the

257
00:16:20,140 --> 00:16:25,140
United States. And even if you go manual, I do recommend combining manual with an automated path

258
00:16:25,140 --> 00:16:30,080
to make your life a bit easier. It is $20 a year, so it's extremely accessible compared to the other

259
00:16:30,260 --> 00:16:34,400
providers. Check them out down in the description. Again, it's who I use personally. It's who I

260
00:16:34,600 --> 00:16:38,460
recommend to my friends and family. So it's genuinely what I do recommend if you are looking

261
00:16:38,550 --> 00:16:40,460
for a tool like this. Check them out down below.

262
00:16:46,560 --> 00:16:51,280
the europe is really cracking down on a concept called interoperability this is not strictly a

263
00:16:51,440 --> 00:16:55,960
privacy thing and i think it's really important for us to get away from this being just a privacy

264
00:16:56,100 --> 00:16:59,740
thing because i don't think interoperability actually has very much to do with privacy i think

265
00:16:59,740 --> 00:17:04,120
it has more to do with the broader concept of digital rights now i've had people from the free

266
00:17:04,339 --> 00:17:08,900
software foundation of europe on tech lore talks our sister podcast and they explain this 10 times

267
00:17:08,920 --> 00:17:12,500
better than I ever can. And they're literally the people who are fighting this war that I'm about to

268
00:17:12,640 --> 00:17:16,819
talk about. And they're in the front lines. The concept of interoperability to them based on,

269
00:17:17,040 --> 00:17:22,000
you know, I'm trying my best to relay their messaging is it's allowing small players to

270
00:17:22,500 --> 00:17:27,199
take part in this ecosystem that these big companies have developed. As you grow in size,

271
00:17:27,310 --> 00:17:31,680
if you're WhatsApp, if you're Apple, you actually have a lot less incentive to make your platform

272
00:17:31,940 --> 00:17:36,760
work with everybody else. Whereas people who are smaller don't have that same incentive. They need

273
00:17:36,780 --> 00:17:41,200
to work with what's out there. So WhatsApp isn't incentivized to make their platform work with

274
00:17:41,320 --> 00:17:44,920
anybody else, but everybody else is pretty incentivized to work with WhatsApp users.

275
00:17:45,160 --> 00:17:48,840
And the reason for that is Meta doesn't want you to use any other clients. They want you to be on

276
00:17:48,840 --> 00:17:53,140
a Meta platform, but everybody else, if you're building a messenger and you're small and you want

277
00:17:53,240 --> 00:17:58,020
to make a name for yourself, the fact that you don't work with WhatsApp means you can't tap into

278
00:17:58,120 --> 00:18:03,880
the multi-billion user platform that WhatsApp has. And so these interoperability requirements are

279
00:18:03,900 --> 00:18:06,460
assigned to the largest players, not the smallest ones.

280
00:18:06,580 --> 00:18:08,200
So if you're small, you don't have to interoperate.

281
00:18:08,240 --> 00:18:10,740
But if you're large, you have to open up your platform.

282
00:18:11,160 --> 00:18:12,600
Now, Apple fought against this, saying,

283
00:18:12,780 --> 00:18:15,880
no, developers shouldn't be allowed to publish apps in other places.

284
00:18:16,240 --> 00:18:18,580
No, we don't need to open up to third-party browsers.

285
00:18:19,040 --> 00:18:20,920
No, we don't need to open up to web apps.

286
00:18:21,100 --> 00:18:23,720
No, we don't need to open up to other messengers.

287
00:18:24,140 --> 00:18:26,420
What this is really targeting is the concept of an ecosystem.

288
00:18:26,540 --> 00:18:29,360
When people talk about how hard it is to leave Apple's ecosystem,

289
00:18:29,540 --> 00:18:31,920
it's because of these design decisions that they've made

290
00:18:31,940 --> 00:18:36,580
to purposely make it difficult for people to use third-party services and tools within their

291
00:18:36,760 --> 00:18:40,720
platform. And that's what interoperability is trying to target. And so Apple did fight it.

292
00:18:40,900 --> 00:18:45,660
They are continuing to fight it. The court said no. And so this is just a quick update from the

293
00:18:45,780 --> 00:18:49,500
EFF. They also covered this story. I don't think there's anything too new from the last time I

294
00:18:49,660 --> 00:18:53,500
talked about it on the podcast, but I did want to just remind people it's going on. And the EFF

295
00:18:53,720 --> 00:18:58,240
story was a perfect way to do that. So if you want to learn more about this, the EFF covers it quite

296
00:18:58,260 --> 00:19:02,900
well in the show notes. Separately, we also have third-party app stores that are coming to Google

297
00:19:03,120 --> 00:19:08,500
Play next week as Epic settlement is withdrawn. There is a whole story leading up to this between

298
00:19:08,860 --> 00:19:13,560
Google and Epic Games. I am not going to get into those details right now because that can take the

299
00:19:13,660 --> 00:19:19,020
next 15 minutes, and I think it's not too relevant to the practical stuff for the story. But Google

300
00:19:19,050 --> 00:19:23,080
has confirmed that it will begin distributing rival app stores next in the stage for competing

301
00:19:23,300 --> 00:19:28,000
platforms to take a bite out of Google Android's revenue stream. And this was published on July 15th,

302
00:19:28,080 --> 00:19:30,900
which means by the time you're listening to this, this could already be live.

303
00:19:31,100 --> 00:19:32,100
Now I'm going to level with you all.

304
00:19:32,400 --> 00:19:35,680
I think what I'm a bit confused about here with this story is that

305
00:19:36,080 --> 00:19:39,040
it kind of goes against some of the things that Google is doing

306
00:19:39,120 --> 00:19:41,060
to try to prevent things like sideloading,

307
00:19:41,320 --> 00:19:44,440
aka installing apps from other third-party app stores on your phone.

308
00:19:44,860 --> 00:19:47,640
We've seen Google that's put out this advanced flow that they call

309
00:19:47,800 --> 00:19:52,460
where you got to tap your tummy five times while you make circles around your head

310
00:19:52,820 --> 00:19:54,800
and you got to kick your legs left and right.

311
00:19:55,240 --> 00:19:56,580
And you do all these crazy things.

312
00:19:56,780 --> 00:20:00,180
then Google says, okay, sure, yeah, you can finally start installing apps on your own phone.

313
00:20:00,540 --> 00:20:04,180
I'm exaggerating, but really what it is, is there's like a 24-hour waiting period. You have

314
00:20:04,180 --> 00:20:07,620
to reboot your device. You have to go into the developer settings, enable developer settings.

315
00:20:07,980 --> 00:20:11,780
You got to do these crazy things to pretty much just start downloading apps from another app

316
00:20:11,900 --> 00:20:17,300
source. So I don't really know how this decision from them goes with that decision. Are these

317
00:20:17,620 --> 00:20:22,740
combined? Does it mean you can install a third-party app store from the Play Store? And then if you

318
00:20:22,790 --> 00:20:26,220
try to actually install another app from that app store, you're going to have to go through this

319
00:20:26,240 --> 00:20:29,420
advanced flow. So I'll do my best to do coverage for it as it comes out.

320
00:20:35,480 --> 00:20:39,980
All right, everybody. And now we're going to get into the defense bulletin. This is the quicker

321
00:20:40,440 --> 00:20:44,680
kind of segment of the podcast if you're new. And there's three subsections. There's the data

322
00:20:44,840 --> 00:20:49,340
breaches, which is data breaches. There's the threats, which are things to keep you up to date

323
00:20:49,390 --> 00:20:53,360
with the latest things happening so you can stay safe. And then there's just the open source news.

324
00:20:53,460 --> 00:20:57,780
So if you're following kind of the better, more positive tools, we can end the podcast in that way.

325
00:20:58,130 --> 00:21:00,900
And I can share with you all the new stuff happening in that side of things.

326
00:21:01,080 --> 00:21:07,800
Now, the first data breach is from the AI music generator, Suno, which affected 55 million users per Have I Been Pwned.

327
00:21:08,060 --> 00:21:11,840
If you're not already using Have I Been Pwned, I highly recommend setting it up already.

328
00:21:12,190 --> 00:21:16,540
Or if your password manager integrates with it, however you're using this, it's good to stay up to date.

329
00:21:16,730 --> 00:21:18,780
But they did get a copy of the breach data set.

330
00:21:18,920 --> 00:21:25,400
And it includes names, physical addresses, and email addresses, phone numbers, purchases, and partial payment card numbers taken from the Stripe account.

331
00:21:25,880 --> 00:21:27,040
Pretty brutal data breach.

332
00:21:27,400 --> 00:21:32,080
So if you are in any way affected by this or you use this service, investigate in the show notes.

333
00:21:32,660 --> 00:21:36,360
Now, South Korea has also disclosed a data breach impacting diplomats worldwide.

334
00:21:36,880 --> 00:21:38,740
So if you want to learn more about this, check it out.

335
00:21:38,770 --> 00:21:42,760
It impacted 6,000 individuals, 350 of them being current government attaches.

336
00:21:43,320 --> 00:21:44,740
I haven't heard that word before.

337
00:21:45,160 --> 00:21:47,580
A-T-T-A-C-H-E with an accent S.

338
00:21:47,940 --> 00:21:48,280
Attaches.

339
00:21:48,760 --> 00:21:52,000
That sounds very nice, but check that out if you want to learn more in the show notes.

340
00:21:52,320 --> 00:21:53,800
Now, this story is a little crazy.

341
00:21:54,080 --> 00:21:59,580
Apparently, a hacker deleted Romania's entire land registry database after a failed extortion

342
00:21:59,860 --> 00:22:02,440
attempt, paralyzing the entire real estate market.

343
00:22:02,740 --> 00:22:05,880
I didn't make it the main story because there was other more important stories to share

344
00:22:06,000 --> 00:22:09,700
with you all, but this is one of those just really entertaining stories that you need

345
00:22:09,700 --> 00:22:10,540
to just trust me.

346
00:22:10,920 --> 00:22:14,360
You should read it in the show notes because it is kind of crazy.

347
00:22:14,540 --> 00:22:15,320
It's got everything.

348
00:22:15,620 --> 00:22:16,800
It's got high stakes.

349
00:22:17,080 --> 00:22:19,780
It's got obvious things they could have done to prevent this issue.

350
00:22:20,180 --> 00:22:21,040
It's got lessons.

351
00:22:21,410 --> 00:22:23,600
And the hacker is even named and he has a history.

352
00:22:23,770 --> 00:22:25,040
So again, it's a great story.

353
00:22:25,130 --> 00:22:26,360
I do recommend reading it.

354
00:22:26,520 --> 00:22:29,200
And I hope that you all read that into that one.

355
00:22:29,420 --> 00:22:31,480
All right, next data breach is from Ernst & Young,

356
00:22:31,730 --> 00:22:35,620
who has disclosed a data breach after a support system hack.

357
00:22:35,820 --> 00:22:38,500
This is an auditing and professional services provider.

358
00:22:38,590 --> 00:22:43,420
They offer auditing, tax, consulting, and transaction advisory services to major organizations.

359
00:22:43,700 --> 00:22:44,980
So I think it's more B2B.

360
00:22:45,600 --> 00:22:48,660
So if you don't personally use these, that's probably why.

361
00:22:48,790 --> 00:22:51,800
If you have any relationship with this company, I would suggest reading more.

362
00:22:52,260 --> 00:22:53,160
Now, this next one.

363
00:22:53,260 --> 00:22:56,120
And oh, man, these are more embarrassing things I'm going to pronounce incorrectly.

364
00:22:56,620 --> 00:22:58,480
Stay lauder, lauder.

365
00:22:58,780 --> 00:23:01,020
Don't worry, though, guys, I'm going to do something a bit different today.

366
00:23:01,270 --> 00:23:04,380
I am going to get someone else to do the pronunciation from me.

367
00:23:04,820 --> 00:23:07,080
From the YouTube channel Face Palette Makeup.

368
00:23:11,320 --> 00:23:11,680
Estilada.

369
00:23:12,200 --> 00:23:12,560
Estilada.

370
00:23:13,000 --> 00:23:13,420
There we go.

371
00:23:13,940 --> 00:23:19,240
Alotta has disclosed a data breach via Oracle e-business flaw. They are notifying employees

372
00:23:19,520 --> 00:23:24,520
of this after hackers exploited the flaw. So this is more human resources, employees of the company.

373
00:23:24,880 --> 00:23:28,120
So if you are an employee of this company, check it out because it impacts a lot of sensitive

374
00:23:28,320 --> 00:23:32,900
things like full names, addresses, email addresses, socials, passport numbers, literally your whole

375
00:23:33,040 --> 00:23:37,460
life. So it's a pretty serious one if you are impacted. Please look into it. Now, if you enjoy

376
00:23:37,800 --> 00:23:42,399
eating chickens, Chick-fil-A disclosed a data breach after credential stuffing attacks. So this

377
00:23:42,400 --> 00:23:46,340
is an undisclosed number of customers at this point in time. It seems like very limited information.

378
00:23:46,450 --> 00:23:50,740
And so I hope they follow up and disclose a bit more about this data breach. So stay subscribed

379
00:23:50,940 --> 00:23:55,540
and maybe we'll get more information about that one. Now, Coca-Cola has suspended production at

380
00:23:55,540 --> 00:24:00,780
its Fairlife Dairy after a ransomware attack. I did not know that Fairlife was owned by Coca-Cola.

381
00:24:00,850 --> 00:24:04,980
So that was news to me. I don't drink Fairlife. So for me, this was another like, oh my God,

382
00:24:05,300 --> 00:24:09,320
Coke owns that moment. But they said in the disclosure with the US Securities and Exchange

383
00:24:09,340 --> 00:24:12,880
commissioned that its Fairlife Dairy Company was hit by that ransomware and that its production

384
00:24:13,060 --> 00:24:17,840
systems were even affected. Specifically in the US, I might add, apparently Canada's kept separate

385
00:24:18,080 --> 00:24:22,020
and they went unaffected. All right, I think this is like the 30th week in a row. I'm exaggerating,

386
00:24:22,160 --> 00:24:26,240
but I actually think that it's been many months in a row where every single week we have at least

387
00:24:26,480 --> 00:24:32,060
one WordPress exploit. And so this week's was called WP2 Shell. And this flaw was exploited

388
00:24:32,100 --> 00:24:36,779
to install web shells. If you're a WordPress administrator and you have any kind of extensions

389
00:24:36,780 --> 00:24:39,320
or anything that has to do with it,

390
00:24:39,600 --> 00:24:40,720
please check out the show notes.

391
00:24:41,540 --> 00:24:42,540
This is happening every week

392
00:24:42,540 --> 00:24:43,700
and you need to stay on top of this stuff

393
00:24:43,730 --> 00:24:45,700
to keep you and also your users safe.

394
00:24:45,900 --> 00:24:48,280
And this is just kind of a recap article from TechCrunch.

395
00:24:48,380 --> 00:24:49,420
It's called Hackers Are Exploiting

396
00:24:49,640 --> 00:24:50,700
Recently Patched WordPress Bugs,

397
00:24:50,820 --> 00:24:51,980
Putting Millions of Websites at Risk.

398
00:24:52,080 --> 00:24:54,640
It's kind of just a summary of this entire incident.

399
00:24:55,120 --> 00:24:57,900
Not that specific exploit, but just, like I said,

400
00:24:58,100 --> 00:25:00,140
the many months of this kind of thing happening.

401
00:25:00,420 --> 00:25:02,340
So if you want to learn more, check that out.

402
00:25:02,660 --> 00:25:05,020
Now, the next one is an Adobe Chrome extension flaw

403
00:25:05,040 --> 00:25:07,700
that lets sites access private WhatsApp chats.

404
00:25:08,160 --> 00:25:10,820
So this is from the Adobe Acrobat extension for Chrome,

405
00:25:11,080 --> 00:25:13,520
and it could have been used to access conversations

406
00:25:13,760 --> 00:25:15,940
and data rendered in the WhatsApp web client

407
00:25:16,420 --> 00:25:17,640
without any form of authentication.

408
00:25:18,360 --> 00:25:20,380
This did require you to access a webpage

409
00:25:20,660 --> 00:25:21,900
under the threat actor's control,

410
00:25:22,100 --> 00:25:23,780
but the fact that this was possible in the first place

411
00:25:23,780 --> 00:25:25,800
is crazy and should remind you to be careful

412
00:25:26,000 --> 00:25:27,620
about the extensions that you have in your browser.

413
00:25:28,020 --> 00:25:29,860
And if you have to use extensions you're not a fan of,

414
00:25:30,160 --> 00:25:32,060
try to separate them from other sensitive things.

415
00:25:32,100 --> 00:25:34,240
I think this is a great area for work profiles

416
00:25:34,680 --> 00:25:35,940
or just separate browsers altogether

417
00:25:36,380 --> 00:25:38,540
so that you can separate extensions from your web traffic.

418
00:25:38,940 --> 00:25:40,120
Now, this was patched,

419
00:25:40,120 --> 00:25:42,320
so make sure you're also keeping all this stuff up to date

420
00:25:42,580 --> 00:25:43,900
and it should no longer be a concern.

421
00:25:44,010 --> 00:25:46,140
But again, that principle I just shared with you

422
00:25:46,360 --> 00:25:48,220
should be carried over into the future as well.

423
00:25:48,520 --> 00:25:50,340
Now, there was a 7-zip exploit

424
00:25:50,410 --> 00:25:53,120
and this was patched with version 26.02

425
00:25:53,420 --> 00:25:55,580
and it was a remote code execution vulnerability

426
00:25:56,100 --> 00:25:58,260
that could allow attackers to execute malicious code

427
00:25:58,340 --> 00:26:01,400
by convincing users to open specially crafted compressed files.

428
00:26:01,660 --> 00:26:04,140
So get yourself up to date if you haven't already.

429
00:26:04,200 --> 00:26:08,580
And if you want to read more about that exploit, it's actually a pretty interesting one if you want to get more technical.

430
00:26:09,000 --> 00:26:09,700
It's all in the show notes.

431
00:26:10,130 --> 00:26:12,900
Now, Zoom has warned of a critical account takeover vulnerability.

432
00:26:13,560 --> 00:26:19,020
This was discovered internally, and it was tracked, and it received a severity score of 9.8 out of 10.

433
00:26:19,360 --> 00:26:24,680
This was specifically in their Windows client, and it's important to remind you that they have patched it, so get yourself up to date.

434
00:26:24,900 --> 00:26:27,920
And sadly, they haven't actually disclosed too much of how it works.

435
00:26:28,120 --> 00:26:33,280
So there might be more information that comes out, but that's all I have right now.

436
00:26:33,380 --> 00:26:42,140
I covered a hide my email vulnerability a few weeks ago on this podcast that Apple's hide my email feature was exposing customers real email addresses.

437
00:26:42,340 --> 00:26:46,120
Now, I want to be clear, there's two specific issues that were happening with hide my email.

438
00:26:46,540 --> 00:26:50,820
There's the vulnerability, which actually exposes the real email address to the iCloud account.

439
00:26:51,360 --> 00:26:52,640
That is a real security issue.

440
00:26:52,920 --> 00:26:53,920
And that was patched.

441
00:26:54,140 --> 00:27:01,920
Apple was looking to move away from that system and create a new subdomain for those hide my emails, which instantly tells people that you are using an alias email.

442
00:27:02,380 --> 00:27:07,720
And if you use alias emails like I do, like SimpleLogin or Addy.io, you know that they can sometimes be blocked on websites.

443
00:27:08,180 --> 00:27:09,380
That is still an ongoing thing.

444
00:27:09,490 --> 00:27:10,540
This has nothing to do with that.

445
00:27:10,840 --> 00:27:14,440
This was just that first issue, which is now resolved, which is at least something good.

446
00:27:14,720 --> 00:27:16,060
This is something else from 404.

447
00:27:16,180 --> 00:27:21,780
I'm not going to get too far into it, but they did find some links in that when you apply for a new credit card and you open one,

448
00:27:22,420 --> 00:27:28,140
ICE now knows where you live because of all the data sharing happening between private and public companies and all this crazy stuff.

449
00:27:28,600 --> 00:27:33,260
I know ICE is a very politically charged thing, and it has been a politically charged thing,

450
00:27:33,540 --> 00:27:34,360
especially this year.

451
00:27:34,900 --> 00:27:39,020
But for me, the concern, especially with all of this stuff, is just the lack of consent

452
00:27:39,070 --> 00:27:40,620
in what is going on with your data.

453
00:27:40,900 --> 00:27:45,200
If I'm applying for a credit card, I think what is reasonable to expect is my credit file

454
00:27:45,290 --> 00:27:49,280
is touched and the company that I'm applying to gets my information.

455
00:27:49,760 --> 00:27:53,820
So when you start realizing that, oh, they're also sharing data with these five middlemen

456
00:27:54,080 --> 00:27:57,400
companies and they're all sending data to all these other data brokers and the government,

457
00:27:57,840 --> 00:28:01,080
That is my problem, and I think everybody should be pretty pissed about that.

458
00:28:01,320 --> 00:28:05,600
There's a reason why warrants exist, and things just aren't publicly available to anyone all the time.

459
00:28:05,760 --> 00:28:10,160
There are probably safeguards that we want to have if we want to have a proper society.

460
00:28:10,480 --> 00:28:14,740
This one also pisses me off, so I guess this is like the heated moment of the podcast,

461
00:28:14,950 --> 00:28:20,360
because a period tracker app called Stardust was sharing users' health data with an analytics firm.

462
00:28:20,560 --> 00:28:21,780
The company had a quote,

463
00:28:21,900 --> 00:28:23,620
Your data is private, period.

464
00:28:24,160 --> 00:28:26,260
Says period tracker Stardust on its website.

465
00:28:26,700 --> 00:28:27,660
Period is part of the quote.

466
00:28:27,800 --> 00:28:28,680
Like they said, period.

467
00:28:29,300 --> 00:28:35,240
And Mozilla Foundation found that they were actually sharing user-sensitive health information

468
00:28:35,580 --> 00:28:38,400
with a third-party analytics company, Rudderstack.

469
00:28:38,800 --> 00:28:42,220
This included their birth dates, their birth control types, their reproductive goals,

470
00:28:42,440 --> 00:28:44,520
and specific symptoms that the user was experiencing.

471
00:28:44,640 --> 00:28:49,040
And it tied that record to a unique identifier in place of the person's name.

472
00:28:49,540 --> 00:28:55,140
And even the FTC, which is not really like crazy privacy first on a lot of things,

473
00:28:55,560 --> 00:28:59,740
Even they said it does not make the data anonymous or prevent it from being linked back to a person.

474
00:28:59,970 --> 00:29:03,200
The Mozilla Foundation Security Researcher who found this, whose name is Wadinski,

475
00:29:03,450 --> 00:29:09,020
even said that Stardust was the only app out of the six tested that shared the user's sensitive health data with another company.

476
00:29:09,180 --> 00:29:10,840
This kind of stuff really pisses me off.

477
00:29:11,080 --> 00:29:13,360
And again, back to that video that I made not that long ago,

478
00:29:13,430 --> 00:29:16,580
I made a video that talked about this service that was on Shark Tank,

479
00:29:16,920 --> 00:29:22,960
where you send a photo of your children to their platform and they build, I think, a book out of it,

480
00:29:23,100 --> 00:29:24,660
or they build something out of it.

481
00:29:24,720 --> 00:29:30,160
the point is they used very interesting terms and it's important that we get our terminology right

482
00:29:30,320 --> 00:29:34,440
because so many services nowadays say they're encrypted your data is always private with us

483
00:29:34,740 --> 00:29:39,460
encryption and transit encryption at rest they use all these terms which pretty much implies like

484
00:29:39,480 --> 00:29:43,820
your data is yours man like nothing to worry about but the terminology is really important

485
00:29:43,860 --> 00:29:48,360
to nail down i want to remind everybody encryption and transit i'm showing you here on the screen if

486
00:29:48,360 --> 00:29:53,220
you're watching the video podcast it's the padlock the security padlock for your website it means

487
00:29:53,240 --> 00:29:58,680
they're using basic TLS. Every website has HET vector data between you and the website. So in the

488
00:29:58,800 --> 00:30:03,700
case of Stardust, if I'm accessing Stardust and their website and their app, it just means that

489
00:30:03,800 --> 00:30:07,720
all the data I upload to them can only go between me and them. That's a great step in the right

490
00:30:07,940 --> 00:30:11,260
direction, but they can still access that data and they can do anything they want beyond that.

491
00:30:11,700 --> 00:30:15,580
Now, encryption at rest means that when they collect my data and they're storing it on their

492
00:30:15,780 --> 00:30:20,120
servers, they're implementing encryption on their servers. So a hacker who gets in is going to have

493
00:30:20,120 --> 00:30:24,640
a more difficult time accessing my data. The problem, though, is that encryption key is still

494
00:30:24,900 --> 00:30:29,500
held by Stardust. It's not like Stardust can't read the data themselves. That's not the same as

495
00:30:29,660 --> 00:30:34,520
something that we would call probably zero-knowledge encryption, where a service actually allows you

496
00:30:34,520 --> 00:30:38,380
to control your own encryption key, and while they still hold your data on their servers,

497
00:30:38,680 --> 00:30:43,360
it's encrypted in a way where not even the service themselves can access the data. These things might

498
00:30:43,640 --> 00:30:49,479
sound like technical nitpicks or whatever, but these are huge implications. It's the reason why

499
00:30:49,500 --> 00:30:54,100
Stardust can even access your data and can freely share it with third parties however they choose

500
00:30:54,240 --> 00:30:58,740
to. It's the reason why a Stardust employee might be able to access your data, whereas with a zero

501
00:30:58,900 --> 00:31:03,060
knowledge provider, they're incapable of doing those things because they don't have the data in

502
00:31:03,060 --> 00:31:07,160
the first place. It's important to get the terminology right. Be very skeptical when

503
00:31:07,480 --> 00:31:12,320
companies say your data is yours, your data is private, without actually verifying their technical

504
00:31:12,500 --> 00:31:17,739
implementation of trying to guarantee that. If they don't let you control your own data, there are very

505
00:31:17,760 --> 00:31:22,960
few safeguards and it's mostly a trust system that the company won't do anything nefarious with it.

506
00:31:23,380 --> 00:31:28,220
Rant over, this stuff really pisses me off. And now we're going to move on with a quick victory

507
00:31:28,430 --> 00:31:33,840
from the EFF who has said that Flock, the surveillance network all around the country

508
00:31:34,120 --> 00:31:38,160
right now that's getting a lot of headlines. And I actually interviewed someone on a sister podcast

509
00:31:38,340 --> 00:31:43,660
Techlore Talks from DFlock, which is the organization fighting Flock and all the advocacy that they're

510
00:31:43,800 --> 00:31:47,720
doing. It's not live yet, but stay subscribed on that sister podcast or the YouTube channel

511
00:31:47,740 --> 00:31:52,020
gatch that, but they have ended their rollout of the distress detection of human voices.

512
00:31:52,540 --> 00:31:57,080
This was meant to try to analyze human distress, but they actually found that there was tons

513
00:31:57,170 --> 00:31:57,840
of false positives.

514
00:31:57,970 --> 00:31:58,920
It didn't work very well.

515
00:31:59,060 --> 00:32:01,240
There's privacy implications for recording all this stuff.

516
00:32:01,290 --> 00:32:03,320
And so it's good that they paused that.

517
00:32:03,320 --> 00:32:07,260
And I know people who are anti-flock, which is definitely me back here too, are going to

518
00:32:07,260 --> 00:32:08,300
be proud about that one.

519
00:32:08,430 --> 00:32:09,120
All right.

520
00:32:09,280 --> 00:32:12,340
And now we are down to just the open source section.

521
00:32:12,600 --> 00:32:16,480
Now Signal, the open source end-to-end encrypted messenger has had polls and groups for a long

522
00:32:16,500 --> 00:32:20,980
time now, allowing you to just ask whatever you want. We use them quite a bit in our Signal group.

523
00:32:21,120 --> 00:32:24,620
If you want to join our Signal group, you can become a Techlorian in the description. But now

524
00:32:24,800 --> 00:32:28,620
they have extended that functionality to direct messages. And so if you're messaging a partner or

525
00:32:28,720 --> 00:32:32,880
a friend, you can still send the poll to them, which is kind of a fun thing. I think there's less

526
00:32:32,960 --> 00:32:38,500
use cases for that, but I still think it's pretty cool. Tor Browser has released version 15.0.19.

527
00:32:38,860 --> 00:32:46,460
This includes some security updates, and there's a few other little things in their changelogs. So

528
00:32:46,480 --> 00:32:51,400
launched 5.8, which extends pass keys from secure authentication to verifiable authorization.

529
00:32:52,080 --> 00:32:56,660
I'm going to be pretty real with you guys. This is very technical stuff that are very standards

530
00:32:56,800 --> 00:33:03,040
based that I haven't dug very deep into. So like this supports the CTAP 2.3 standard and preview

531
00:33:03,200 --> 00:33:06,580
support for the emerging web auth and signing extension, providing developers with modern

532
00:33:06,780 --> 00:33:11,820
standards to implement secure flood enterprise at a station. And we also have 16 unique relying

533
00:33:12,060 --> 00:33:16,160
party IDs. These are things I'm not as focused on. These are things that seem more IT focused.

534
00:33:16,460 --> 00:33:19,060
I still wanted to put it on your radar so you all can dig into this.

535
00:33:19,500 --> 00:33:23,580
Now, I did a whole video on a YouTube channel demoing this one, but Firefox has now made

536
00:33:23,700 --> 00:33:26,440
their containers native in Firefox 153.

537
00:33:26,820 --> 00:33:30,920
Previously, you had to install the extension in your Firefox browser to get multi-account

538
00:33:31,140 --> 00:33:34,300
containers, but they are now just bringing that directly into Firefox.

539
00:33:34,800 --> 00:33:38,740
It is technically a preview, but this is super cool, and I think it's going to make containers

540
00:33:39,300 --> 00:33:41,440
even more easily accessible than they are already.

541
00:33:41,540 --> 00:33:42,780
So I'm super excited about that.

542
00:33:42,820 --> 00:33:46,040
And again, I covered this more in a dedicated video on the YouTube channel.

543
00:33:46,400 --> 00:33:49,780
And how it compares to Brave, who also just released containers, actually.

544
00:33:49,920 --> 00:33:54,660
And so it's pretty cool to have both browsers now support both profiles and containers.

545
00:33:54,900 --> 00:33:58,780
So you don't have to really choose any one of those browsers for either one of those features.

546
00:33:59,000 --> 00:34:03,440
There's also an update for Firefox for Android, where you can now group related tabs together.

547
00:34:04,160 --> 00:34:07,020
And they go through how this works and how you can sort them.

548
00:34:07,060 --> 00:34:09,560
And it's on the blog in the show notes if you want to learn more.

549
00:34:10,180 --> 00:34:15,679
Vivaldi, the browser, hit version 8.1, which launches more customization features and more options for Android users.

550
00:34:15,919 --> 00:34:18,540
So if you are a Vivaldi user, go check that one out.

551
00:34:19,159 --> 00:34:23,100
WhatsApp has also developed first-party encrypted cloud backups for Android and iOS.

552
00:34:23,379 --> 00:34:24,580
This is really big news.

553
00:34:24,929 --> 00:34:26,800
The reason why I like this a lot is that previously,

554
00:34:26,889 --> 00:34:29,760
if you wanted to do an encrypted backup of your WhatsApp data,

555
00:34:29,790 --> 00:34:31,240
you actually had to opt into it.

556
00:34:31,379 --> 00:34:33,520
And very few people actually knew this was the case.

557
00:34:33,899 --> 00:34:37,899
A lot of people didn't know that if you did a cloud backup of your WhatsApp messenger,

558
00:34:38,110 --> 00:34:41,280
it was actually going unencrypted to somewhere else where your messages could be scanned,

559
00:34:41,440 --> 00:34:44,300
which kind of negates the reason to use an end-to-end encrypted messenger.

560
00:34:44,600 --> 00:34:52,100
This implementation is stored on WhatsApp servers, and it will have end-to-end encryption enabled by default, which I think is a big step in the right direction.

561
00:34:52,500 --> 00:34:56,200
It's two gigabytes of free cloud storage with paid plans available for those needing more space.

562
00:34:56,639 --> 00:35:00,740
It seems like lately WhatsApp has been copying Signal with a lot of things, like they're copying usernames.

563
00:35:01,040 --> 00:35:05,860
This is exactly kind of the system that Signal has set up as well for their native backups feature as well.

564
00:35:05,960 --> 00:35:09,920
This doesn't solve WhatsApp's issues with metadata and the fact it's owned by Meta.

565
00:35:10,000 --> 00:35:13,820
There's lots of other concerns with WhatsApp, but this is a step in the right direction,

566
00:35:14,000 --> 00:35:14,480
I think, for them.

567
00:35:14,700 --> 00:35:16,840
This is an update to a smaller project.

568
00:35:17,200 --> 00:35:18,020
It's called Briar.

569
00:35:18,240 --> 00:35:23,840
It's an open source, end-to-end encrypted messenger that is like balls to the wall on

570
00:35:23,840 --> 00:35:25,100
the anonymity side of things.

571
00:35:25,280 --> 00:35:26,180
It's Tor routed.

572
00:35:26,180 --> 00:35:28,940
You can even use it without an internet connection over Blitz mode.

573
00:35:29,460 --> 00:35:34,600
The app will still receive essential security updates and bug fixes, but no kind of feature

574
00:35:34,760 --> 00:35:35,680
plans at the moment.

575
00:35:36,060 --> 00:35:48,980
I don't think this is necessarily a permanent decision, but it's safe to assume now for the foreseeable future that Breyer is in this maintenance mode that they're calling, which I think is a good way to put it. And I'm glad they came forward to clear it up so we don't have to wonder anymore.

576
00:35:49,260 --> 00:36:19,040
All right, this next one. You know, I really didn't want to cover this topic because it's not fun to cover. These aren't the reasons why I do this podcast. I don't like talking about random annoying controversies because I think everybody deserves the right to have digital rights. And so these stories are annoying for me. And actually, I wasn't going to do any coverage for this Mullvad story. But Mullvad themselves put a blog article about it on their own freaking website. And now I kind of can't because they have now taken this controversy and attached it to themselves on their own website.

577
00:36:19,100 --> 00:36:24,400
site, so I got to talk about it. Now, Mullvad has a co-founder whose name is Daniel, and they don't

578
00:36:24,500 --> 00:36:29,480
say who Daniel is in the very first beginning of the article, which is fantastic. So that's a good

579
00:36:29,660 --> 00:36:35,320
start. I have to pull up his article, and it's Daniel Bernstein, who is a libertarian anarchist,

580
00:36:35,470 --> 00:36:41,160
as he calls himself. And he made a pretty large donation to a political organization in Sweden.

581
00:36:41,480 --> 00:36:45,420
That donation, a lot of people were not happy about. And especially if you're a Mullvad subscriber,

582
00:36:46,000 --> 00:36:53,820
A lot of Mullvad users feel a bit betrayed because they don't align with the political beliefs of Daniel necessarily.

583
00:36:54,270 --> 00:36:55,700
And it was a pretty massive donation.

584
00:36:55,770 --> 00:36:57,480
I believe it was about like half a million dollars.

585
00:36:58,010 --> 00:37:01,480
And it was, I think, the largest or one of the largest donations made to that party.

586
00:37:01,650 --> 00:37:05,740
In terms of my role here for this podcast, my job is to educate you all.

587
00:37:05,770 --> 00:37:08,520
And you guys should be able to make a decision on what is best for you.

588
00:37:08,590 --> 00:37:10,520
And so I'm alerting you of this issue.

589
00:37:10,760 --> 00:37:12,600
It's in the show notes if you want to learn more about it.

590
00:37:12,900 --> 00:37:14,320
They even linked to Daniel's blog.

591
00:37:14,600 --> 00:37:15,920
And that's where I think it's a bit annoying.

592
00:37:16,100 --> 00:37:17,060
It's like, hey, this is what's really

593
00:37:17,640 --> 00:37:18,560
taking a lot of people off.

594
00:37:18,680 --> 00:37:19,340
They don't like this.

595
00:37:19,680 --> 00:37:20,600
By the way, here's his blog.

596
00:37:20,660 --> 00:37:21,520
You can read it for yourself.

597
00:37:21,840 --> 00:37:23,400
And by the way, now it's on our website.

598
00:37:23,820 --> 00:37:24,900
And we are, as a company,

599
00:37:25,320 --> 00:37:26,460
adding commentary to this,

600
00:37:26,640 --> 00:37:27,660
which now involves them.

601
00:37:27,920 --> 00:37:29,260
And this doesn't have anything to do

602
00:37:29,340 --> 00:37:30,460
with Mulvaz's privacy and security.

603
00:37:30,840 --> 00:37:32,020
It's more about an ethical choice

604
00:37:32,140 --> 00:37:32,940
that you all need to make.

605
00:37:33,140 --> 00:37:34,660
Regardless of how you feel about him,

606
00:37:35,239 --> 00:37:37,260
sometimes private individuals of these companies

607
00:37:37,620 --> 00:37:39,140
donate to things that we don't agree with.

608
00:37:39,360 --> 00:37:41,220
And it's very hard to draw a line in the sand on this

609
00:37:41,240 --> 00:37:42,640
and be consistent about it.

610
00:37:42,920 --> 00:37:49,740
Now, I think the one thing that is universal, and yes, it is, I guess, something that I can promote of my own as a result of this crazy fiasco,

611
00:37:50,140 --> 00:37:52,940
is that there are kind of a lot of alternatives to Mullvad.

612
00:37:53,010 --> 00:37:59,440
And so if you do feel strongly about this and you don't like the way they handled this, our VPN tool is literally perfect for you.

613
00:37:59,680 --> 00:38:02,180
VPN.Techlore.tech, this is literally just data.

614
00:38:02,250 --> 00:38:03,760
It has tons of filters on it.

615
00:38:04,030 --> 00:38:05,300
You can sort by no logs.

616
00:38:05,660 --> 00:38:07,000
You can sort by disk lists.

617
00:38:07,050 --> 00:38:08,800
You can sort by anonymous registration.

618
00:38:09,130 --> 00:38:10,580
And you can be like, I want Monero.

619
00:38:11,140 --> 00:38:12,360
And then you'll see the three providers.

620
00:38:12,640 --> 00:38:17,440
are Mullvad, Windscribe, and AirVPN, and you can just compare them. And there was a funny

621
00:38:17,620 --> 00:38:22,260
Mastodon person who asked, is there a filter for avoided political controversies? Sadly,

622
00:38:22,360 --> 00:38:25,940
there isn't. It would be quite hard to, again, draw a line in the sand on that.

623
00:38:26,340 --> 00:38:30,240
But the tools are out there for you all to make your own choices about how you feel about this,

624
00:38:30,280 --> 00:38:34,760
and I hope that is the best that I can kind of communicate to you all. The only thing I would

625
00:38:35,000 --> 00:38:39,480
flag is that if you do personally not like Mullvad, and Mullvad's like off your list now,

626
00:38:39,940 --> 00:38:42,200
Obscura VPN still routes through Mullvad.

627
00:38:42,380 --> 00:38:46,160
And so I'm guessing some of the money you pay to Obscura would end up in Mullvad.

628
00:38:47,040 --> 00:38:52,060
And or Mozilla VPN as well is also a Mullvad partner.

629
00:38:52,580 --> 00:38:53,900
So just things to flag.

630
00:38:54,100 --> 00:38:57,640
Also, Tailscale uses Mullvad, but that's a little bit more clearly disclosed that it's Mullvad.

631
00:38:58,080 --> 00:39:00,980
Either way, I want you all to make your own decisions about this.

632
00:39:01,020 --> 00:39:03,580
It's really hard to communicate nuance and complexity on the internet.

633
00:39:04,080 --> 00:39:06,060
But I really do feel like you all appreciate that.

634
00:39:06,080 --> 00:39:09,239
And it's why you come to this podcast and why you listen to these longer news

635
00:39:09,540 --> 00:39:14,180
coverages that I make. So I'm hoping that it's what you all want. And again, the point is to

636
00:39:14,340 --> 00:39:17,500
empower you all to make your own decisions, which is really everything I'm about. Again, check it out

637
00:39:17,500 --> 00:39:21,100
in the show notes if you want to learn more. And speaking of the VPN finder, actually the last

638
00:39:21,400 --> 00:39:27,920
story of the week is my own. I published the July version of our tools with some big updates. Again,

639
00:39:27,970 --> 00:39:32,080
there are three tools. There is our quiz, which I think everybody should take. It's going to tell

640
00:39:32,110 --> 00:39:36,459
you what your threat model is based on an archetype. And you just answer some basic questions about

641
00:39:36,480 --> 00:39:40,200
yourself. It's kept only inside of your browser. You get to keep a private link when you're done,

642
00:39:40,210 --> 00:39:45,600
and it's going to score you out of 100 on how well you're doing and match it to your archetype.

643
00:39:45,800 --> 00:39:49,740
It's meant to be a practical tool to make you see what's going on and make things actionable

644
00:39:50,100 --> 00:39:55,800
and expose any gaps in your privacy and security. We also have our tools themselves, which is kind

645
00:39:55,800 --> 00:40:00,260
of like the starter pack kind of thing where I share what I think are really good services across

646
00:40:00,540 --> 00:40:04,439
different archetypes. So it covers different threat models on the tools page, but it covers everything

647
00:40:04,460 --> 00:40:09,000
from browsers and search engines, etc. And then I also have the VPN finder as well. And the main

648
00:40:09,220 --> 00:40:14,420
updates from this month is that I added a lot more accessibility features, which don't impact maybe

649
00:40:14,720 --> 00:40:19,220
most of you. But for any of you out there who are using screen readers or keyboard shortcuts,

650
00:40:19,500 --> 00:40:24,580
I also moved the wiki, which was a new tool back to just the Techlore.tech website, it was just a

651
00:40:24,660 --> 00:40:29,040
little bit harder to maintain. And I actually felt like it was smarter to put it as just its own tag.

652
00:40:29,160 --> 00:40:32,859
So if you want to keep up with the guides that I'm making, all those guides are now on just our

653
00:40:32,880 --> 00:40:37,140
main website, Techlore.tech. I think it's actually a bit more useful than asking people to go through

654
00:40:37,500 --> 00:40:41,800
an entire wiki to find what they're looking for. They're meant to be very friendly for people in

655
00:40:41,800 --> 00:40:45,720
your life as well who aren't tech savvy and don't know about this. I think the whole scoring thing

656
00:40:45,720 --> 00:40:50,440
for the quiz is extremely effective at getting people to see if they're private or not. And most

657
00:40:50,580 --> 00:40:55,280
people probably would be surprised by their score. All right, everybody. And that is going to conclude

658
00:40:55,560 --> 00:41:00,480
this week's surveillance report. If this analysis helped you reclaim control, make sure you subscribe

659
00:41:00,480 --> 00:41:01,860
to the newsletter in the description.

660
00:41:02,020 --> 00:41:02,800
It's completely free

661
00:41:02,920 --> 00:41:04,700
and it's just a written five minute version

662
00:41:04,940 --> 00:41:05,620
of this podcast.

663
00:41:06,160 --> 00:41:07,020
And while you're doing that,

664
00:41:07,040 --> 00:41:09,580
you can also become a Techlorian in the same place.

665
00:41:09,780 --> 00:41:11,480
You'll gain access to our private signal group.

666
00:41:11,780 --> 00:41:12,820
You're also gonna get other perks

667
00:41:12,920 --> 00:41:14,320
while keeping the podcast growing

668
00:41:14,580 --> 00:41:16,240
so that we can keep publishing this for free

669
00:41:16,540 --> 00:41:17,240
every single week.

670
00:41:17,540 --> 00:41:18,740
And I really enjoy doing it

671
00:41:18,740 --> 00:41:20,820
and I wanna keep doing it and I love it.

672
00:41:21,040 --> 00:41:22,980
So I hope that you all can also support back

673
00:41:23,140 --> 00:41:23,760
if you're able to.

674
00:41:24,120 --> 00:41:25,460
If you're not, you can still leave a rating,

675
00:41:25,800 --> 00:41:27,240
share this episode to spread digital freedom

676
00:41:27,260 --> 00:41:28,080
to people around you.

677
00:41:28,100 --> 00:41:29,440
That also is equally helpful.

678
00:41:29,740 --> 00:41:30,940
And I just want to thank you all for being here,

679
00:41:31,120 --> 00:41:32,680
taking control of your privacy and security

680
00:41:32,860 --> 00:41:34,100
a little bit more every single week.

681
00:41:34,120 --> 00:41:37,020
And I'll see you in the next episode of Surveillance Report.