601
192

Source: https://xcancel.com/vxunderground/status/2032600868005310638#m

Yeah, so basically the current prevailing schizo internet theory is that AI nerds have destroyed the >internet and created infinite spam.

The advertisement goons are now incapable of determining who is a bot and who is an actual human. The advertisement goons no longer want to pay as much to social media networks.

Social media networks, in full blown panic of losing potential revenue, decided to lobby governments saying "we gotta protect the kids! ID everyone to protect the kids from pedophiles!".

The social media networks know this doesn't really protect kids. But, it does two things (and a third accidentally).

  1. They now can identify who is human and who is AI slop machine, or enough to appease the advertisement goons

  2. Advertising to children is a general no-no from politicians, or something, so with ID verification they can say with confidence they're not advertising to children because it's been ID verification. Basically, they can weed out the children and focus on advertising to adults

  3. The feds can now tell who is human and who is AI slop. This inadvertently helps them with tracking people and serving fresh daily dumps of propaganda, or whatever they want to do.

It's a win-win-win for advertisers, social media networks, the government, and any business which does data collections.

It fucks over everyone else.

Chat, I'm not going to lie to you. This is an extremely good conspiracy schizo theory and I unironically believe it.

602
19

The teacher opens an app on their phone, holds it up, and takes several photos of the room. Within seconds, the images travel to a cloud server, where a facial-recognition algorithm detects each student’s face, extracts it, and compares it against a database of biometric profiles. The app LRCO Paraná returns a list of names. Students identified in the photos are marked present; those the system does not find are marked absent.

For some students, a false absence is a bureaucratic irritation. For others, it could threaten their family’s access to welfare. In Brazil, eligibility for the Bolsa Família program depends in part on school attendance, and in Paraná such records are now largely generated by an algorithm.

603
65
604
112
605
16
submitted 5 months ago by Blaze@piefed.zip to c/privacy@programming.dev
606
17
submitted 5 months ago by Blaze@piefed.zip to c/privacy@programming.dev
607
19

This vote fails to reject the whole regulation but approves text amendments and now the whole process goes back to the LIBE Committee (Committee on Civil Liberties, Justice and Home Affairs)

Amendment 5, tabled by Pirate Party MEP Markéta Gregorová (Greens/EFA group) and adopted by a narrow margin, demands that any scanning of private communications must be strictly limited to individual users or groups of users suspected by a competent judicial authority of being linked to child sexual abuse. This aligns with the European Parliament’s 2023 mandate on the permanent Chat Control regulation (CSAR).

Other sources:

608
53
submitted 5 months ago* (last edited 5 months ago) by XLE@piefed.social to c/privacy@programming.dev

I was reading a review of Firefox's experimental Smart Window feature, and this stood out as a potential huge issue:

Smart Window uses ‘memories’, things Mozilla says “…it learns from your activity” to inform its responses.

You can delete memories individually, and you can set any given chat session to not use/store them.

Fine so far.

The problem? My memory list isn’t populated with things Smart Window learned since I enabled it. Oh no.

It has activity going back months. We’re talking searches and website interactions from long before I enabled this. features.

Firefox just handed that history to the AI models to plough from, without telling me upfront.

I found this the creepiest aspect of Smart Window.

Mozilla says this was a flub; it will refine the onboarding around Smart Window to limit memory formation to post-opt-in activity only. That’s obviously the right fix.

Because sharing a user’s prior browsing history with third-party AI models, silently, on feature activation, without any headset? Yeah, a bit icky – but that’s the price of testing features that are finished, I guess.

This news leaves me with more questions than answers:

  • Was this summarized on enabling this window, or earlier?
  • Did it use an existing model, or re-use one that someone may have already downloaded for a different feature?
  • Is this activity going anywhere else, like Mozilla's recent "privacy-preserving" advertising?
  • When this releases, what will the default be?
609
72
610
13

Originally Umbrachat was a web app named Peersuite ( that I also developed) that was distributed as a docker image, web site, or electron app. Umbrachat has chat with channels, file sharing, threaded replies, and image preview in chat. Also, audio/video conferencing and screenshare.

I pulled out the non-social business type features ( document editing, whiteboard, and kanban ) and simplified the CSS and the code. I got everything down to under 200k in size and packaged it as a browser extension, which IMO is a way simpler method to use it.

All datastreams ( chat, audio, video) are encrypted end to end. After the initial connection to the server you are connected directly to your friends in a mesh network with superpeer capability.

github: >https://github.com/openconstruct/umbrachat peersuite github: https://github.com/openconstruct/Peersuite

Firefox: https://addons.mozilla.org/en-US/firefox/addon/umbrachat/

Chrome: https://chromewebstore.google.com/detail/umbrachat/jdgneoijldkiffdnhkibcdnajchecaip?hl=en-US

By Developer @jerrimu@lemmy.world

611
104
612
17
613
38
submitted 5 months ago by Blaze@piefed.zip to c/privacy@programming.dev
614
88
submitted 5 months ago by who@feddit.org to c/privacy@programming.dev
615
23
616
8

Proton Mail provided Swiss authorities with payment data for defendtheatlantaforest@protonmail.com — the account linked to Stop Cop City protests in Atlanta. The FBI obtained this information through a Mutual Legal Assistance Treaty request on January 25, 2024, identifying the activist behind the anonymous account through their credit card identifier.

617
23

From the official Dutch Intelligence and Security Service


information.

“Despite their end-to-end encryption option, messaging apps such as Signal and WhatsApp should not be used as channels for classified, confidential or sensitive information,” states Director of the MIVD, vice-admiral Peter Reesink.

Individual accounts

An interesting aspect of this Russian campaign is that it does not exploit any technical vulnerabilities of the messaging services. The attackers instead make malicious use of legitimate security features of the apps. Director-General of the AIVD Simone Smit states, “It is not the case that Signal or WhatsApp as a whole have been compromised. Individual user accounts are being targeted.”

To increase resilience against this Russian campaign, MIVD and AIVD have published a Cyber Advisory explaining how to identify and respond to attacks. The advisory also give instructions for Signal users on how to identify potentially compromised contacts.

All Signal users can personally check whether there are any potentially compromised contacts in their group chats. If you see any people who appear twice in the list of members (under the same or a slightly different name), this may be evidence of either a compromised account or a new account created by a victim.If you suspect this to be the case, report this to the information security department of your organisation. Together you can try to verify (preferably using a channel other than Signal or WhatsApp, such as an email or a telephone call) whether it is correct that the account in question appears twice in the chat group contact list. Should this not be the case, ask the group administrator to remove both accounts from the group chat, after which the legitimate account holder can request to rejoin the group. Please remain vigilant for group members who are not recognised by the rest of the group. The actor may occasionally change the display name of a compromised account to remain unnoticed in chat groups, for example to names such as 'Deleted account'. If a member’s display name changes, the group will receive a notification. When the change is the legitimate transition to 'Deleted account', no notification is sent. Actor-controlled accounts can also gain entry to the group via an obtained Group Link, of which the group always receives a notification. In all such unauthorised scenarios, ask the group administrator to remove the offending accounts from the chat.If there is any indication that the group administrator themselves may have been compromised, it is advisable to exit the group and create a new one.

618
33

EU rules regarding anti-money laundering, counter-terrorist financing and sanctions law (AML/CFT) have increasingly shifted responsibilities to detect crime from public entities to companies . AML/CFT law requires “obliged entities”, like banks, to collect large amounts of financial and other personal data about their customers.

The way banks implement these rules in the EU has led to a systemic negative impact on human rights, often because of over-compliance, risk-aversion and weak accountability. This has been the case in the Netherlands where, among large number of human rights breaches by banks, Dutch ING Bank has even publicly apologised for discriminating against its customers based on profiling.

619
7
submitted 5 months ago by Sunshine@piefed.ca to c/privacy@programming.dev
620
37

For decades, satellites, drones, and human spotters have all been part of war’s surveillance and reconnaissance tool kit. In an age of cheap, insecure, Internet-connected consumer devices, however, militaries have gained another powerful set of eyes on the ground: every hackable security camera installed outside a home or on a city street, pointed at potential bombing targets.

621
54
submitted 5 months ago by Blaze@piefed.zip to c/privacy@programming.dev

It was reported in Brazil last week that the Federal Police was able to access previously displayed WhatsApp "view once" messages during an "extraction carried out by specific software that jointly displays the messages and files sent, reversing, in practice, the single view of the message" .

Here follows the original report, in Portuguese, and a quick translation to English.
Emphases and text within square brackets on the translation are my own.

Original Report

Mensagens trocadas entre Vorcaro e Moraes foram extraídas e periciadas pela PF, diz jornal

Reportagem publicada pelo blog da jornalista Malu Gaspar, do jornal "O Globo", trouxe prints de mensagens atribuídas ao banqueiro Daniel Vorcaro enviadas ao ministro Alexandre de Moraes horas antes de Vorcaro ser preso pela primeira vez.

O jornal o Globo publicou, na noite desta sexta-feira (6), uma reportagem informando que os dados das mensagens trocadas no dia 17 de novembro entre Daniel Vorcaro e o ministro Alexandre de Moraes, do Supremo Tribunal Federal (STF), foram retirados do celular do dono do Master por meio de análise técnica da Polícia Federal (PF), e que essa análise permite visualizar, ao mesmo tempo, a tela de whatsapp com as mensagens e as imagens de visualização única nela contida.

O jornal informa também que, diferentemente do material enviado à CPMI do INSS, o conteúdo a que o Globo teve acesso não é fruto de comparação entre os horários dos textos que constam em blocos de nota de Vorcaro e as mensagens enviadas por ele, embora coincidam, e sim resultado da extração realizada por um software específico que exibe conjuntamente as mensagens e os arquivos enviados, revertendo, na prática, a visualização única da mensagem.

English Translation

Messages exchanged between Vorcaro and Moraes were extracted and examined by the Federal Police, says newspaper

A report published by journalist Malu Gaspar's blog, from the newspaper "O Globo", brought prints of messages attributed to banker Daniel Vorcaro sent to minister Alexandre de Moraes hours before Vorcaro was arrested for the first time.

The newspaper "O Globo" published, on the night of this Friday (6), a report informing that the data of the messages exchanged on November 17th between Daniel Vorcaro and Minister Alexandre de Moraes, of the Federal Supreme Court (STF), were removed from the [banker's] cell phone through technical analysis by the Federal Police (PF), and that this analysis allows viewing, at the same time, the WhatsApp screen with the messages and the single-view images contained therein.

The newspaper also informs that, unlike the material sent to [a National Congress investigation], the content that "O Globo" had access to is not the result of a comparison between the times of the texts contained in Vorcaro's notebooks and the messages sent by him, although they coincide, but rather the result of extraction carried out by specific software that jointly displays the messages and files sent, reversing, in practice, the single view of the message .

622
32
submitted 5 months ago* (last edited 5 months ago) by A_norny_mousse@piefed.zip to c/privacy@programming.dev

Disclaimer: This is not technically a privacy matter for the reader, but I believe it is adjacent and important enough for this community.

Around January 11, 2026, archive.today (aka archive.is, archive.md, etc) started using its users as proxies to conduct a distributed denial of service (DDOS) attack against Gyrovague, my personal blog. All users encountering archive.today's CAPTCHA page currently load and execute the following Javascript: setInterval(function() { fetch("https://gyrovague.com/?s" + Math.random().toString(36).substring(2, 3 + Math.random() * 8), { referrerPolicy: "no-referrer",…

Far too many netizens still try to ignore this or even come up with reasons why gyrovague is the bad guy here.

Alternative archive pages:

archive.org
ghostarchive.org
archivebox.io (self-hosted)

But how else to bypass a paywall?

I've read relevant articles and clicked old links - they all seem to be history. The only ones that still work just look for the article in various archives - the subject of this post always amongst them. The same applies to this article, but there's still some good tips.

Here is the original article from 2023: https://gyrovague.com/2023/08/05/archive-today-on-the-trail-of-the-mysterious-guerrilla-archivist-of-the-internet/ and what Patakallio has to say about it today:

The post mentions three names/aliases linked to the site, but all of them had been dug up by previous sleuths and the blog post also concludes that they are all most likely aliases, so as far as “doxxing” goes, this wasn’t terribly effective.

Here is a relevant ArsTechnica article: https://arstechnica.com/tech-policy/2026/02/wikipedia-bans-archive-today-after-site-executed-ddos-and-altered-web-captures/

Wikipedia editors discovered that the archive site altered snapshots of webpages to insert the name of the blogger who was targeted by the DDoS.

archive.today (.ph, .is, .md, .fo, .li, .vn) also loads a pixel and javascript from mail.ru. The script mentions lamoda.ru, kommersant.ru, dzen.ru, ad.mail.ru, vk.com, vkontakte.ru, ok.ru, odnoklasseniki.ru. I haven't researched this further, but I think one can assume that your IP address will be spread across all relevant Russian websites. 10 years ago I would have said "so what? The Russians have social media too" but today you can safely assume that all this data is available to the government itself and is actively contributing to the hybrid war.

All in all, archive.today has always been in the "too good to be true" category. Call me suspicious.

And once again because it's important:

The Wikipedia guidance points out that the Internet Archive and its website, Archive.org, are “uninvolved with and entirely separate from archive.today.”

623
8
624
92

go to the site, use the tool. where ever you are. Keep voicing your stance on this issue.

This isn't about protecting kids nor will it protect kids from anything. Kids will just go to darker corners of the internet where nothing is moderated

forcing everyone to dox themselves won't make anything safer. All that data in hackable databases would be ripe for the picking by any hacker or groups of hackers to sell to databrokers, who then sell it to scammers

Parental controls are very easy to set up in the modern day every commonly used OS has them built in. If you're a parent, it's YOUR responsibility to make sure your kids don't see things they're not supposed to see...don't let the government control that shit

There's also https://www.defendvpns.com/ to go to as well, sign both petitions.

the EFF has some petitions too https://www.eff.org/

I've already signed them I've already emailed all my people. Now you need to do that. For anyone who still has twitter, tweet to them with these hashtags

#crushthescreenact #crushthekosabill >#stopIDagechecksUSA >#saynotoappstoreaccountabilty >#dontrepealsection230 #SayNotoKOSMA >#NoToKIDSAct

625
49
submitted 5 months ago by Blaze@piefed.zip to c/privacy@programming.dev

Nobody wants to use AI to bug our phones, or to build a sprawling nerve system to track our vitals, because our phones are already bugged. Everything we do on them is recorded a dozen times over, by our wireless carriers, by the websites we visit and the apps we use, by the vendors and ad networks those companies are sending their data to, and in the marketplaces that sell that data. We built the eyes of the Greco decades ago.

But that data has remained relatively secure—or maybe more precisely, its potential energy has remained relatively buried—largely because it’s tedious to work with. It’s messy; it’s scattered across different sources and in different formats; combining it together is a pain, and most of us are simply not interesting enough to investigate. Data analysts who work at shadowy government agencies have lives too, and they do not want to write 595-line SQL queries either.

But AI doesn’t mind. And that’s the boring danger of what happens next: Not of AI becoming a superintelligent Sherlock Holmes finding impossible patterns in its enormous mind palace, but of it being a million monkeys at a million typewriters, doing the grunt work no person wanted to do. Because when prying questions are a prompt away—rather than 24 hours of work away—who wouldn’t get tempted to pry?

view more: ‹ prev next ›

Privacy

5085 readers
235 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS