1101
12
submitted 10 months ago by cm0002@infosec.pub to c/privacy@programming.dev
1102
17
submitted 10 months ago by Blaze@piefed.zip to c/privacy@programming.dev
1103
60
submitted 10 months ago by Blaze@piefed.zip to c/privacy@programming.dev
1104
9
submitted 10 months ago by Blaze@piefed.zip to c/privacy@programming.dev

Privacy-focused browser receives major updates while ending support for legacy platforms.

1105
24
submitted 10 months ago by Sunshine@lemmy.ca to c/privacy@programming.dev
1106
202
1107
144

Someone recently managed to get on a Microsoft Teams call with representatives from phone hacking company Cellebrite, and then leaked a screenshot of the company’s capabilities against many Google Pixel phones, according to a forum post about the leak and 404 Media’s review of the material.

The leak follows others obtained and verified by 404 Media over the last 18 months. Those leaks impacted both Cellebrite and its competitor Grayshift, now owned by Magnet Forensics. Both companies constantly hunt for techniques to unlock phones law enforcement have physical access to.

“You can Teams meeting with them. They tell everything. Still cannot extract esim on Pixel. Ask anything,” a user called rogueFed wrote on the GrapheneOS forum on Wednesday, speaking about what they learned about Cellebrite capabilities. GrapheneOS is a security- and privacy-focused Android-based operating system.

rogueFed then posted two screenshots of the Microsoft Teams call. The first was a Cellebrite Support Matrix, which lays out whether the company’s tech can, or can’t, unlock certain phones and under what conditions. The second screenshot was of a Cellebrite employee. 💡 Do you know anything else about phone unlocking technology? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

According to another of rogueFed’s posts, the meeting took place in October. The meeting appears to have been a sales call. The employee is a “pre sales expert,” according to a profile available online.

The Support Matrix is focused on modern Google Pixel devices, including the Pixel 9 series. The screenshot does not include details on the Pixel 10, which is Google’s latest device. It discusses Cellebrite’s capabilities regarding ‘before first unlock’, or BFU, when a piece of phone unlocking tech tries to open a device before someone has typed in the phone’s passcode for the first time since being turned on. It also shows Cellebrite’s capabilities against after first unlock, or AFU, devices.
Screenshot via GrapheneOS forum.

The Support Matrix also shows Cellebrite’s capabilities against Pixel devices running GrapheneOS, with some differences between phones running that operating system and stock Android. Cellebrite does support, for example, Pixel 9 devices BFU. Meanwhile the screenshot indicates Cellebrite cannot unlock Pixel 9 devices running GrapheneOS BFU.

In a statement, Victor Cooper, senior director of corporate communications and content strategy at Cellebrite, told 404 Media “We do not disclose or publicize the specific capabilities of our technology. This practice is central to our security strategy, as revealing such details could provide potential criminals or malicious actors with an unintended advantage.” Google did not immediately respond to a request for comment.

GrapheneOS is a long running project which makes sizable security changes to an Android device. “GrapheneOS is focused on substance rather than branding and marketing. It doesn't take the typical approach of piling on a bunch of insecure features depending on the adversaries not knowing about them and regressing actual privacy/security. It's a very technical project building privacy and security into the OS rather than including assorted unhelpful frills or bundling subjective third party apps choices,” the project’s website reads.

As well as being used by the privacy and security conscious, criminals also turn to GrapheneOS. After the FBI secretly ran its own backdoored encrypted phone company for criminals, some drug traffickers and the people who sell technology to the underworld shifted to using GrapheneOS devices with Signal installed, according to interviews with phone sellers.

In their forum post, rogueFed wrote that the “meeting focused specific on GrapheneOS bypass capability.”

They added “very fresh info more coming.”

1108
50

Differential privacy keeps that data private. It’s a mathematical framework whereby a statistical output can’t be used to determine any individual’s data in a dataset, and the bureau’s algorithm for differential privacy is called TopDown. It injects “noise” into the data starting at the highest level (national), moving progressively downward. There are certain constraints placed around the kind of noise that can be introduced—for instance, the total number of people in a state or census block has to remain the same. But other demographic characteristics, like race or gender, are randomly reassigned to individual records within a set tranche of data. This way, the overall number of people with a certain characteristic remains constant, while the characteristics associated with any one record don’t describe an individual person. In other words, you’ll know how many women or Hispanic people are in a census block, just not exactly where.

On August 28, Republican Representative August Pfluger introduced the COUNT Act. If passed, it would add a citizenship question to the census and force the Census Bureau to “cease utilization of the differential privacy process.” Pfluger’s office did not immediately respond to a request for comment.

1109
69
submitted 10 months ago by throws_lemy to c/privacy@programming.dev
  • Google has reportedly started rolling out its new age verification requirements for the Play Store.
  • Failure to prove you are 18 or older could lead to disruptions in app downloads.
  • Adult users find these new systems very intrusive also report being wrongly flagged as minors and forced to verify using sensitive personal information, including selfies, credit cards, or government IDs.
1110
113
submitted 10 months ago by Blaze@piefed.zip to c/privacy@programming.dev
1111
34
SimpleX goes NFT / Shitcoin (mementomori.social)

It's really sad to see SimpleX goes the shitcoin route to try and fund their project, Ethereum is not ethical as I briefly explained in this post

Now is a perfect opportunity to fork the project with I2P and add Monero as the payment option both for people to transact and fund the developers and I2P operators

1112
24
submitted 10 months ago by Blaze@piefed.zip to c/privacy@programming.dev

From confidential contracts, communications, and employee records, unencrypted emails put your business at risk. Here’s why companies must ensure emails are end-to-end encrypted by default.

1113
9
submitted 10 months ago by Sunshine@lemmy.ca to c/privacy@programming.dev
1114
11
submitted 10 months ago by Sunshine@lemmy.ca to c/privacy@programming.dev
1115
37

A very, very helpful article to help get people we fight with to understand why this is important for anyone and everyone. Send this to friends and family.

1116
18
submitted 10 months ago by Blaze@piefed.zip to c/privacy@programming.dev

Meta AI is here to stay, but you can control what it learns about you. Find out why and how to turn off AI on Facebook, Instagram, WhatsApp.

1117
14

Good if you need to use Chrome stuff

1118
35

In this post, I hope to clarify and expand on some of the points and rebut some of the counter-messaging that we have witnessed.

1119
22
Know Your Enemy pt. 2: META (blog.rebeltechalliance.org)

Deep dive on why Meta need to be totally boycotted.

People here will know all this, but please share with your less knowledgable friends and family so they can realise the truth: Meta products need to be dumped!

1120
44
1121
19
submitted 10 months ago* (last edited 10 months ago) by cm0002@lemmings.world to c/privacy@programming.dev

A software architect discovered his iLife A11 smart vacuum was secretly transmitting data to overseas servers in 2025. When he blocked the data collection, the vacuum was remotely disabled through hidden software that allowed manufacturer access[^1].

The vacuum contained sophisticated hardware including an AllWinner A33 processor running Linux and Google Cartographer mapping software. Through reverse engineering, the author found rtty remote access software that let manufacturers secretly control devices[^1].

The incident sparked discussions about IoT device privacy and control. Multiple vacuum brands including Xiaomi, Wyze, and Viomi use the same hardware platform (3irobotix CRL-200S), suggesting widespread vulnerability[^1].

The story gained attention in October 2025, with tech commentators highlighting it as a cautionary tale about smart home devices[^2]. Forum discussions revealed similar experiences with other robot vacuums losing connectivity or requiring resets after firmware updates[^7][^9].

[^1]: The Day My Smart Vacuum Turned Against Me
[^2]: Suggested Read: The Day My Smart Vacuum Turned Against Me - Troy Patterson
[^7]: Wyze Forums - Robot vacuum does not connect to wifi
[^9]: Wyze Forums - Wyze Vacuum Save Created Maps in App

1122
79
submitted 10 months ago by Blaze@piefed.zip to c/privacy@programming.dev
1123
8
1124
11
Your data, their rules (blog.42futures.com)
1125
71
submitted 10 months ago by throws_lemy to c/privacy@programming.dev

If you thought living in Europe, Canada, or Hong Kong meant you were protected from having LinkedIn scrape your posts to train its AI, think again. You have a week to opt out before the Microsoft subsidiary assumes you're fine with it.

view more: ‹ prev next ›

Privacy

5091 readers
97 users here now

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

founded 3 years ago
MODERATORS