A new Meta published Thursday says a system, like its AI glasses, would use facial recognition to identify people, current a series of video clips, then provide you with a highlight reel of your night.#Privacy #Meta #News


Meta Patents AI Glasses to Use Facial Recognition to Identify People, Make Highlight Reels of Your Dinner Party


Meta has filed a patent for its AI smartglasses that uses facial recognition to automatically detect who is in the frame, creates a video clip whenever one of those people does something — like picking an item up or walking around — and then generates a highlight reel of what just happened, according to a copy of the patent published Thursday. One example given is the system capturing highlights from a dinner party and then serving those up to the user.

The patent gives new, granular insight into what Meta may be planning around its highly controversial push into facial recognition in combination with its AI glasses, which have already been widely lauded as “pervert glasses.”

💡
Do you work at Meta and know anything else about these glasses? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


It's usually very difficult to investigate the advertising industry. A new tool called DecryptAds aims to make it much easier with a massive dataset anyone can query.#Privacy #ads #News


This Tool Unmasks the Shadowy World of Ads that Track Your Location


The advertising industry is simultaneously everywhere and incredibly difficult to investigate. Ads can power all sorts of surveillance, from the relatively mundane like inferring someone’s age or gender, right up to harvesting their precise location data and selling this to the government. But researching that omnipresent surveillance is, ironically, an uphill struggle because the relevant data is spread across the web, nestled in obscure files that most people never look at or even know to look for, and can’t be searched all at once.

A new research tool called DecryptAds hopes to change that by bringing together a massive corpus of data. It can show what advertising brokers are operating on a particular website, and, more importantly, many other places those same brokers are operating. The tool cuts down on work that would ordinarily take much longer, and creates entirely new ways to explore the world of advertising and surveillance.

💡
Do you work for a data broker or advertising company selling this sort of data? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

“For years I’ve personally worked on some of the biggest data privacy problems that have impacted the world, and I’m damn sick of people trying to guess how hundreds of data brokers are selling location data on people and a wide variety of other sensitive audience segments,” Zach Edwards, chief product and research at DecryptAds, told 404 Media. “We want to make it easy for anyone to look up a website or app and quickly understand the data sharing implications to risky ad tech companies and data brokers.”

In a process called real-time bidding (RTB), advertising companies outbid one another to have their clients’ ads placed in the web browsing session or app of a particular type of person. A side effect of that process is that companies can harvest all sorts of sensitive information about peoples’ devices, in some cases including their location. 404 Media has covered this type of surveillance extensively, from an Israeli spy firm monitoring billions to uncovering thousands of specific apps that siphon location data, with middlemen then selling it to the U.S. government.

When 404 Media and other outlets have investigated this industry, it has typically been through sources, leaks and hacks, or technical analysis of certain apps. DecryptAds takes a different approach. The site brings together ads.txt and app-ads.txt files — which list the advertising systems plugged into websites or apps — and sellers.json files which advertising exchanges use to list the companies they work with. Ordinarily these files cannot be easily compared to one another or searched in aggregate. DecryptAds makes that possible.
playlist.megaphone.fm?p=TBIEA2…
“It’s my hope that a new generation of researchers and activists starts to step up and demand more from publishers we frequent and support. We built DecryptAds to empower people with information which is currently spread out across complex datasets and tough to parse, but we believe with the right data and tools, we can help people understand the complex web of programmatic advertising and its relationship to the global data broker ecosystem, and start to make a dent in the changes with these systems that will improve privacy, security and advertising outcomes for everyone,” Edwards said.

At the time of writing, a counter at the bottom of the site said DecryptAds’ database includes 284,250,766 ads.txt files, 183,939,277 app-ads.txt files, and 201,389,256 sellers.json files.

It’s possible to search the DecryptAds data by a specific app, advertising company, a relevant domain, IP address, and more. The tool is also monitoring for changes on the sellers.json files, which Edwards says may help “to identify suspicious publishers or app makers who could be quietly banned from multiple exchanges without any public notice or fanfare.”

DecryptAds adds context to the collected data in various ways. One of those is by giving ad systems a “geo risk” score. This includes those who are linked to sanctioned countries (such as Russia, Belarus, and Iran); determined as U.S. adversaries under Executive Order 14117 (like China and Hong Kong); and “financial-secrecy havens” (including Cyprus and the British Virgin Islands).

Having one of these flags does not necessarily mean any single exchange is harvesting data for nefarious purposes, but it can be a strong lead for journalists or researchers to look into. “If the ad tech company has ties to Russia or China, expect shenanigans. If a company is based in Cypress or another jurisdiction for shell companies, expect them to be connected to numerous other suspicious companies, probably hide their beneficial owners, and potentially be the type of company who has poor KYC [know your customer] and partner standards and is more likely to be the source of a malvertising attack,” Edwards said.

Last month, advertising company Adform discovered hackers had targeted it. It found the hackers implanted code that would replace cryptocurrency wallet addresses displayed in a web browser. In other words, these hackers attempted to use the advertising ecosystem as a way into peoples’ active browsing sessions, and then potentially use that access to steal peoples’ funds.

Using data in DecryptAds, it is possible to see nearly 20,000 websites that declare Adform in their ads.txt or app-ads.txt. That includes 404 Media; we removed Adform from our ads.txt after finding this.

“Our goal is to continue working to layer context onto the programmatic advertising ecosystem so that people can understand the data sharing implications of consenting to ads on these sites, and so that security and ad tech companies can understand the complex publisher ecosystem and opportunities to reduce the risks from working with unscrupulous publishers and their partners,” Edwards added.


The media in this post is not displayed to visitors. To view it, please log in.

A Flock presentation shows the company planned to use around 350,000 Uber, Lyft, and delivery drivers to collect license plate data for its surveillance system.#Flock #Privacy #News


Flock Pitched a Plan To Turn Uber and Lyft Drivers Into Roaming Surveillance Vehicles


Flock planned to use dashcams installed in hundreds of thousands Uber, Lyft, and delivery drivers’ vehicles to scan license plates those drivers travelled passed, essentially turning Uber and Lyft drivers into roaming surveillance vehicles, according to a Flock presentation shared with 404 Media.

The document provides more details on Flock’s planned partnership with Nexar, a popular dashcam company. 404 Media first revealed the intended partnership last August when multiple sources provided information on the plan. The presentation shows Flock was actively pitching this partnership, and its use of Uber and Lyft drivers, to potential customers right around the time 404 Media reported on it.

💡
Do you work for Flock, Axon, or a similar company? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

Flock told 404 Media in an email it never executed the partnership with Nexar. But the presentation still shows Flock’s ambitious plan to conscript rideshare and delivery drivers to collect license plate data for its network. It is not clear whether Uber or Lyft, or drivers working for those apps, would have been aware of the data collection.

“Hundreds of Commercial Business and HOA [home owners associations] in GA [Georgia] are part of the network,” the presentation, written by Flock to present to the Georgia Office of the Attorney General last August, reads. “Plus Nexar partnership which includes 350k Uber/Lyft and other delivery service devices.”

Jason Hunyar, a Dunwoody, Georgia, resident who obtained the presentation through a public records request, shared the document with 404 Media.
Image: screenshot of the presentation.
Flock’s automatic license plate reader (ALPR) cameras are usually stationary cameras installed on tall poles that constantly scan the license plate, color, make, and brand of every vehicle that drives past. The Nexar partnership would have made those data collection efforts mobile. Axon, the law enforcement contracting giant that also sells ALPR cameras, sells some of its cameras to be installed in police officers’ roaming cars. Vigilant Solutions and the Digital Recognition Network (DRN), two ALPR companies now owned by Motorola, perform similar license plate data collection through cameras in vehicles belonging to repossession agencies.

Nexar sells various different models of dashcams providing front, cabin, and rear views, and already can provide “clear license plate capture with Full HD video,” according to its website. Nexar markets the cameras to rideshare drivers and also “commuters,” “long-distance drivers,” and “casual drivers.”
youtube.com/embed/BKYYpLC9u5I?…
In September, 404 Media reported that a hacker broke into Nexar and accessed a database of terabytes of video recordings taken by customers’ cameras. Those included footage of people driving around sensitive Department of Defense locations.

Flock has explored obtaining other unusual datasets too. Last May, 404 Media reported Flock was building a massive people lookup tool that would use hacked data to “jump from LPR to person,” according to leaked audio. Flock scrapped those plans after 404 Media’s coverage and internal pressure.

Neither Uber nor Lyft responded to a request for comment. Neither did Nexar.

In May, 404 Media reported a company called BusPatrol, that has cameras installed in tens of thousands of school buses, plans to turn those cameras into ALPRs and give access to that data to law enforcement.


Rather than get rid of ALPR cameras entirely, many cities and towns are switching to Axon, whose cameras can be mounted to an existing streetlamp, helping them blend into their surroundings.#Flock #axon #Privacy #News


Cities Are Ditching Flock, Immediately Replacing It With Axon License Plate Readers


A handful of cities across the U.S. have ditched Flock’s automatic license plate reader (ALPR) cameras and immediately replaced them with equivalent systems from law enforcement contracting giant Axon, according to local media reports and government documents from around the country. Axon, for example, advertises AI-powered cameras that attach to an existing streetlamp and are designed to completely blend in with their surroundings, and also collects license plate data with cameras installed inside police officers’ patrol vehicles.

💡
Do you work at Axon? Do you know anything else about its technology or expansion? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


Researchers found a group of issues that mean Private Relay isn't actually protecting users' real IP addresses. 404 Media verified the issues do expose IP addresses.#Apple #Privacy


Apple's ‘Private Relay’ Is Exposing Users’ Real IP Addresses


A series of issues in Apple’s web browser engine — the tech underlying all browsers on iOS — means that Apple’s iCloud Private Relay tool, which is supposed to hide a user’s IP address, in many cases doesn’t actually work. Instead, the issues mean a malicious attacker can set up a website to learn a Private Relay user’s real IP address, or that many websites have also already collected this information incidentally. The issues also impact OnionBrowser, an iOS app for browsing the web through the Tor anonymity network, the researchers who discovered the issues say.

The Private Relay leak is the second issue to recently impact Apple’s paid-for privacy products. Last month 404 Media reported a bug in Apple’s Hide My Email feature was actually revealing peoples’ real email addresses. Apple knew about that issue for more than a year before fixing it.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The SEC bought access to worldwide airline ticketing records. Airlines including Delta, United, and American sold the data.#Privacy #News


The SEC Bought Airline Data to Monitor Flights Worldwide


The Securities and Exchange Commission (SEC) bought access to what it described as more than a billion airline ticketing records, related to not just U.S. domestic flights or those landing in the country, but also flights between foreign countries, according to SEC documents obtained by 404 Media. A group of the world’s airlines, including Delta, United, and American, previously sold the data under the company name ARC; that is where the SEC bought the data from.

ARC, or the Airlines Reporting Corporation, stopped selling airline ticketing records after repeated coverage from 404 Media and pressure from lawmakers last year. But the newly obtained records provide additional insight into the breadth of data that airlines were selling without their customers' knowledge, and that law enforcement agencies were tapping into, likely without a warrant.

“ARC's ticketing data includes not only US domestic flights and international flights to/from the US, but also flights entirely between or within foreign countries,” one of the documents obtained by 404 Media reads. 404 Media obtained them through a Freedom of Information Act (FOIA) request with the SEC.

The data includes each passengers’ name, their credit card number used to buy the ticket, the departure and arrival cities of their travel, the date of their flight, the flight number, and the “selling agency,” likely referring to the travel agency the person used, according to the documents. ARC obtained its data by acting as the conduit between airlines and travel agencies. Whenever someone booked a flight with a travel agency like Expedia or Kayak, ARC received information about that booking and then resold it as part of its data broker business.

💡
Do you know about any other companies selling data to the government? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

ARC’s Travel Intelligence Program (TIP), as the data product was called, was also capable of sending daily search results related to a specific list of names, the document says. “ARC sends daily reports regarding any air ticketing purchased by individuals over the prior 24 hours),” it adds. The document says SEC required access to 1-25 daily searches through this alert service.

The SEC did not respond to a request for comment.

ARC previously told 404 Media that TIP “was established by ARC after the September 11, 2001, terrorist attacks and has since been used by the U.S. intelligence and law enforcement community to support national security and prevent criminal activity with bipartisan support. Over the years, TIP has likely contributed to the prevention and apprehension of criminals involved in human trafficking, drug trafficking, money laundering, sex trafficking, national security threats, terrorism and other imminent threats of harm to the United States.”


The U.S. government has charged Samuel Tunick with allegedly typing in a passcode to wipe his phone before officers could search it. “I hope people understand that the charges against me are meant to intimidate people,” he said.#Privacy #News


‘The Government Hopes To Set a Precedent’: An Interview With the Man Charged for Allegedly Wiping His GrapheneOS Phone


In charging a man for allegedly typing in a duress password which wiped his privacy-focused GrapheneOS phone, the U.S. government is trying to intimidate other activists from protecting their data and participating in social movements, Samuel Tunick, the man charged, told 404 Media in an interview on Tuesday.

The case of Tunick, who participated in the Stop Cop City movement in Atlanta, has resonated across privacy and civil liberties circles. 404 Media first broke news of the case in December. Last week, The Guardian reported additional details including from a court hearing in the case. The maximum sentence for the alleged crime is five years in federal prison.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


”Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” the person who reported the issue said.#Privacy #News


Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses


A vulnerability in Apple’s “Hide My Email” tool lets almost anyone discover a person’s real email address that is supposed to be hidden by the feature, and Apple has failed to fix it for more than a year, according to a security researcher and 404 Media’s own tests.

404 Media is not revealing the exact details of the vulnerability because it can still be exploited as of Monday, when 404 Media verified the issue with one of our own hidden email addresses.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The new policy, which forbids "noise infusion" as a technique for anonymizing data, will "handcuff" the Census Bureau and limit what information becomes public, data experts say.#Privacy #data #census #policy #Trumpadministration #Trump #redistricting


The Trump Administration’s New Census Data Rules Are a Policy Disaster


Behind closed doors and without expert input, the Trump administration issued a major policy change to how census data is released. Data experts are concerned the result will be less reliable public data related to redistricting, natural disasters, the workforce, housing, and more.

On June 4, the Trump administration released an order, Disclosure Avoidance for Statistical Products, that forbids “any use of noise infusion” for statistical products. “Coarsening shall be the preferred category of Disclosure Avoidance methods for all statistical products,” the order states. “Suppression shall be permitted as a last resort, only to be used when coarsening is prohibited by law or would substantially defeat the accuracy or usability of a statistical product.”

In statistical terms, noise infusion is a common and accepted technique for privacy protection when working with data: it creates “fuzz” or random values within a dataset, making the published statistics slightly different from the actual, sensitive data. Coarsening is the process of grouping and rounding data, or reporting it in ranges instead of potentially identifiable specifics. Suppression is what it sounds like: redacting information, replacing it with asterisks, or not releasing the data entirely.

NPR’s Hansi Lo Wang first reported on the policy change and its implications. People who work with census data and statistical analysis are worried that limiting the ways the Census Bureau and the Bureau of Economic Analysis (BEA) can release data will severely limit what information ends up available to the public.

Data coming out of small communities and industries, especially, could be heavily affected by the change. “Because ‘coarsening’ (grouping, rounding, reporting in ranges) and suppression are the only not-prohibited tools named in the order, it means that to keep information safe, the Census Bureau and BEA need to group small things (like small communities or small business types) into larger ones, or they need suppress the data completely,” Beth Jarosz, a senior fellow at Georgetown University's Massive Data Institute and vice president of the Association of Public Data Users, told me in an email. “Small industries may get rolled into bigger industry categories. Small counties may get rolled into county groups or not reported at all.”

On June 17, five groups — the Population Association of America, Council of Professional Associations on Federal Statistics, Association of Public Data Users, Inter-university Consortium for Political and Social Research, and Association of Population Centers — released a joint statement condemning the order. “This order subverts processes developed over decades to foster transparency and public trust and creates a scenario in which there will either be less privacy for our personal information, or less usable data, or both,” the statement says.

The Director of Science Policy for the American Statistics Association Steve Pierson wrote that the order “handcuffs the Census Bureau and the Bureau of Economic Analysis in terms of the techniques they can use for protecting the privacy of respondents.”

John Abowd, the former Associate Director for Research and Methodology and Chief Scientist at the Census Bureau, posted a list of data products on Linkedin that this order would affect. These include the OnTheMap for Emergency Management system, a public data tool that provides real-time U.S. population and workforce statistics for areas being affected by natural disasters; Quarterly Workforce Indicators which include data about employment, job creation and destruction, wages, hires, and more; business formation and dynamics statistics; veteran employment statistics; data related to post-secondary educational outcomes, and many more. Many of these use noise infusion, which Trump’s order just banned.

There’s also confusion about how this order will even be enacted in practice. “Regarding the datasets that used noise infusion, it is unclear how this policy will impact public access,” Lynda Kellam, who leads the Research Data and Digital Scholarship team at the University of Pennsylvania Libraries and is a founding organizer of the Data Rescue Project, wrote following the order. “The policy is intended to be retroactive, raising concerns that data might be removed, but how that will play out is uncertain.”

In the immediate fallout, at least, we’re already losing some public information. As Wang from NPR pointed out on Bluesky last week, multiple webpages related to noise infusion and differential privacy on the Census Bureau's website were removed following the order. Most of those pages have since been restored. At the Data Rescue Project, a team led by Lena Bohman has been proactively collecting and archiving Census Bureau working papers and making them available to the public.

Jaroz said that along with the risk of unreliable or missing data, the abandonment of long-agreed-upon privacy protection methods can damage public trust in Census data. “When the Census Bureau and Bureau of Economic Analysis gather data, they promise respondents that they will keep responses confidential. When a person responded to the American Community Survey or a business owner provided information about their employees or sales, they expected that the Census Bureau and BEA would protect that information. By taking away tools that those agencies use to protect privacy and confidentiality, people may question whether or not Census and BEA can live up to that promise,” she said. “Similarly, the Census Bureau and BEA are producing information for public benefit. People respond, for example, to the American Community Survey (at least in part) because it will benefit their community. If the new rule results in cutting back how the data can be published and used, it also weakens trust and it is worth responding.”

As Wang noted, America First Legal, a law group co-founded by Trump's deputy chief of staff for policy Stephen Miller, attempted to force the release of new 2020 Census data in a lawsuit last year, by challenging the Census Bureau's differential privacy system. Judges ruled it was too late to sue, but they refiled the case in February.

As NPR also reported last year, Trump and Republicans in Congress have been pushing to exclude people living in the U.S. without legal status in the 2030 Census. “People who are in our Country illegally WILL NOT BE COUNTED IN THE CENSUS,” Trump wrote on Truth Social in August 2025. This would be a radical change in how the Census has been conducted for more than 200 years. Redistricting and gerrymandering have been a massive fight for the Trump administration for years, and has ramped up ahead of the 2026 midterms, as the Supreme Court recently weakened the Voting Rights Act and allowed for more redistricting that would favor Republican control of the House.

The data policy change is also happening in light of the Trump administration’s gutting of Census practice test locations in the South. In February, the Associated Press reported that the administration is eliminating four out of the six locations that were slated to test new methods for the 2030 census. “The Census Bureau would be essentially flying blind into communities that need testing most — tribal lands, rural areas with limited connectivity and places with historically low response rates,” Mark Mather, an associate vice president at the Population Reference Bureau, told the AP. “You can’t fix what you don’t test.”


The document, titled “Facial Recognition Activists.docx,” includes specific activists’ comments about MSG's facial recognition program and tweets criticizing it.#Privacy #News


Madison Square Garden Made Dossier on Activists Who Opposed Facial Recognition


Madison Square Garden compiled a list of activists who have publicly criticized the venue’s use of facial recognition technology, putting their tweets and comments into a document that was then accessible to other people inside the company, 404 Media has found.

The news shows that MSG, operated by Jim Dolan who has garnered a reputation for being pernicious against his perceived enemies, is not only deploying controversial facial recognition technology but keeping track of specific people who take issue with it. The document was included in a 45GB cache of data hackers stole from MSG and posted online this month, which 404 Media then downloaded and reviewed.

“The wake of a data breach would be a good time for Madison Square Garden to stop subjecting its patrons to biometric surveillance,” Adam Schwartz, privacy litigation director at the Electronic Frontier Foundation (EFF), and one of the people included in the document, told 404 Media.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The FCC wants to legally force telecoms to collect new and renewing customers' government issued identity number and physical address, impacting everyone from the privacy-conscious to domestic abuse survivors. “We never thought that would happen here.”#Privacy #News


FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers’ IDs


The Federal Communications Commission (FCC) wants to make it effectively impossible for people to buy what many call burner phones—a phone not explicitly linked to your identity at the point of purchase—which would impact privacy-conscious people, to domestic abuse survivors, to journalists, and many more. The FCC plans to do this by legally forcing the country’s telecoms to store a wealth of personal information about essentially all phone customers, including a government issued identification number and their physical address, alarming privacy advocates and civil rights activists who compare the measures to those from authoritarian countries where it can be difficult to buy a mobile phone plan without giving up your identity.

The proposed change would drastically shake up how people obtain phone plans in the U.S., and have all sorts of privacy and cybersecurity knock-on effects. The FCC is proposing the data collection partly as a way to combat scammers, with telecoms being required to collect other information on business and foreign customers like the intended use case of their bulk phone plan purchase and their IP address. But the changes would mean telecoms collect data on all new and renewing customers, and the FCC provides a long list of other things that the collected data could help authorities with.

💡
Do you know anything else about this proposed change? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

“For decades, civil libertarians have looked overseas at authoritarian countries where the government requires people to register to get a mobile phone to ensure they can be tracked. We never thought that would happen here,” Jay Stanley, senior policy analyst at the American Civil Liberties Union’s (ACLU) Speech, Privacy, and Technology Project told 404 Media in an email. “But make no mistake: with this rulemaking, the government is contemplating taking away people’s ability to get a burner phone, which will hurt low-income people, domestic violence victims, and anyone else who cares about their privacy.”

In a synopsis of the proposed changes, the FCC writes, “Specifically, we seek comment on requiring originating providers to, at a minimum, obtain and retain the name, physical address, government issued identification number, and an alternate telephone number of any new and renewing customer before granting access to its services.” The goal of collecting this data, the FCC writes, is to deter some scammers from getting onto a telecom network in the first place, and so “enforcers will be better able to identify the scammers when they do.” The FCC compares the changes to the sort of data collected by banks to prevent money laundering.

One section stresses that the newly collected data would help “law enforcement to more easily identify callers that use the network to perpetuate crimes by ensuring that voice providers have accurate and complete customer information.” It goes on to ask if the data would help identify people buying and selling illicit goods; the investigation of “fraud, espionage, or influence operations that undermine national security”, and “address abuse in text messaging networks.”
playlist.megaphone.fm?p=TBIEA2…
“Criminals continue to leverage the anonymity provided by phone calls and texts to defraud Americans and exploit communications networks to further other crimes,” one section reads.

At the moment, the FCC is seeking comments about its proposed changes, with interested or concerned parties—think telecom companies, law enforcement, or privacy advocates—able to weigh in. But the intention of the FCC is clear: the agency wants telecoms to be legally obligated to collect much more personally identifying information on new and returning customers, linking them directly to their phone number and phone usage data. The FCC also asks whether the amount of data collected should change depending on whether a customer is seeking a prepaid or a postpaid service plan.

Multiple privacy and technology experts strongly pushed back against the proposed changes. “This proposal by the FCC will do little to combat scams and robocalls, since most people doing that will have no trouble creating fake documentation or identities,” Cooper Quintin, security researcher and senior public interest technologist with the Electronic Frontier Foundation (EFF), told 404 Media. “Given this administration’s crackdown on free expression, protest, immigrants, and women’s health we have trouble seeing this as a bold attack on freedom of communication. They want to take away our ability to make an anonymous phone call.”

Eric Null, the director of the Privacy & Data Project at the Center for Democracy & Technology, told 404 Media in an emailed statement “To address the scourge of illegal robocalls, the FCC has unfortunately proposed to force every wireless subscriber in the nation to sacrifice their privacy and give up significant personal details before receiving or renewing a wireless line. While some carriers already collect such details, there are specific circumstances where a person may need privacy and anonymity when seeking a cell phone, including if that person is a victim of domestic violence, or is a journalist or whistleblower. This proposal represents a loss of privacy across the board, and from an agency whose remit includes protecting privacy. The FCC might let a few bad apples spoil the whole bunch.”

Cape is a privacy-focused telecom company that limits the amount of data it collects on its customers. John Doyle, the company’s CEO, told 404 Media in an emailed statement “We hate robocalls and support eliminating them, but entrusting telecom carriers to effectively create a nationwide ID registry for every American with a phone is not the solution. Mobile carriers have been breached time and again because the incentives to secure trillions of dollars of legacy architecture aren’t there. Further enriching compromised telecom datasets with government ID, physical addresses, and alternate phone numbers harms our security rather than improving it.”

Given this proposal is in the comments stage, the FCC has many questions it is hoping to receive information on, such as whether “renewing” customers should be only those new to the provider, or those switching plans with their current telecom; or whether they should not allow the use of P.O. boxes or shared office locations as the required “physical address.”

The FCC did not respond to 404 Media’s request for comment. The proposal is open to comments until June 25.


SignalTrace “links devices that regularly travel together, correlating them to license plate.” It is a surveillance product that will sweep up and add all sorts of Bluetooth and other data to license plate readers, linking specific devices—and people—to cars.#Privacy #News


This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers


A surveillance company plans to add sensors to automatic license plate readers (ALPRs) that would mean the devices, as well as capture the license plate of passing vehicles, would also sweep up unique identifiers of mobile phones, wearables, and other Bluetooth-enabled devices in those cars, potentially letting law enforcement identify specific drivers or passengers.

The technology, called SignalTrace, would turn ALPR cameras from devices focused on tracking cars to ones that can more readily track the location of particular people. ALPR cameras have become a commonly deployed technology all across the U.S.; SignalTrace would make some of those cameras capable of collecting much more data.

💡
Do you know anything else about SignalTrace? Do you work for Leonardo? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


BusPatrol plans to scan the license plates of all vehicles the buses drive past, and then let law enforcement search that data. The plan would essentially turn school buses into roaming surveillance vehicles.#News #Privacy #ALPR


‘BusPatrol’ Put AI Cameras in Tens of Thousands of School Buses. Now They Want to Give Cops Access


BusPatrol, a company that has installed AI-powered cameras in tens of thousands of school buses around the U.S., now plans to turn those cameras into automatic license plate readers (ALPRs), capturing the location of every vehicle the buses drive past, and give that data to law enforcement, 404 Media has learned. The plan will essentially transform school buses into roaming surveillance vehicles, taking a technology that was originally designed to issue tickets to people illegally passing stopped buses and using it for much wider and general law enforcement, likely without a warrant.

BusPatrol has already taken steps to share the collected data with law enforcement contracting giant Axon, according to leaked BusPatrol documents and a source with knowledge of the plans. Internally, BusPatrol has acknowledged how controversial its plan to collect and share this data is, pointing specifically to concerns about ICE using license plate data, but emphasizes the likely success of selling the angle of protecting children.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


Only a couple vendors could likely fulfill what the FBI is after, namely Flock and Motorola.#Privacy #News


The FBI Wants to Buy Nationwide Access to License Plate Readers


The FBI wants to buy access to automated license plate readers (ALPRs) nationwide, which would likely allow the agency to track the movements of vehicles—and by extension people—across the country without a warrant, according to FBI procurement records reviewed by 404 Media.

The documents show that ALPRs continue to be a sought-after tool for law enforcement, not just for local police and individual communities, but federal agencies too. The news also comes as protests and pushback against ALPRs have spread around the country.

💡
Do you work at Flock or Motorola? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


“With your permission, your child’s lead teacher may wear a small teacher-worn camera that captures the teacher's approximate first-person perspective, and/or we may place a fixed video camera in the classroom,” a document given to parents and later shared with 404 Media reads.#Privacy #News


Researchers Wanted Preschool Teachers to Wear Cameras to Train AI


University of Washington researchers planned to have preschool teachers wear cameras that would record everything they saw from a first-person perspective, including the children they were teaching, then use that footage to develop AI models. One parent who spoke to 404 Media understood the program as opt-out, rather than opt-in. The university said classroom participation was contingent upon receiving parental permission for all of the children.

“With your permission, your child’s lead teacher may wear a small teacher-worn camera that captures the teacher's approximate first-person perspective, and/or we may place a fixed video camera in the classroom,” a document given to parents and later shared with 404 Media reads. “These videos simply capture the normal interactions between teachers and children during regular classroom activities. Recordings occur during morning program hours up to 150 minutes, up to 4 visits in one month. Your child will not be asked to do anything new or different. Their daily routine will stay exactly the same.”

💡
Do you know anything else about how researchers are using AI? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


Mayo Clinic's "Ambient Listening" has been around for a couple of years, but clearly not all patients know their interactions with nurses are being passively recorded and processed by AI.#Privacy #News


Mayo Clinic is Using AI to Listen to Emergency Room Visits


Mayo Clinic, the massive U.S. hospital network, is using what it describes as “Ambient Listening” to record patient interactions with nurses, including in emergency rooms, then using AI to process that collected data. The recording is opt-out, rather than opt-in, and at least some patients are likely not aware the recording is happening.

The recording brings up questions of informed consent and whether the generated notes may be accurate enough. A study last month found that AI-powered scribe tools sometimes produce much less accurate notes than humans depending on the situation.

💡
Do you know anything else about AI use in healthcare? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


At a New York party, attendees spent Trans Day of Visibility dancing, DJing, and learning how to become less visible online.#Privacy #Security #opsec #persec


A 'Self-Doxing' Rave Helps Trans People Stay Safe Online


It’s Trans Day of Visibility, and I’m at an event space in the heart of New York City’s Commie Corridor to learn how to become less visible online.

The crowd gathered at the aptly-named Trans Pecos in Ridgewood, Queens is here for “404: Deadname Not Found,” a digital self-defense workshop which promises to teach trans people how to find and remove their sensitive personal information from the internet (and which also has no relation to this website). The vibe is giving OpSec rave happy hour—attendees sip colorful drinks, groove to DJ sets, and huddle around laptops using online tools to track down their own digital footprints.

The goal of the exercise is to find holes in your digital defenses, a practice cybersecurity folks call “red-teaming.” A slide deck guides participants through this “self-doxing” ritual, instructing them to use websites like IntelBase, PimEyes, and haveibeenpwned to find addresses, selfies, passwords, old names and aliases, and other personal info that might have been left sitting around on the open internet.

It makes for great cocktail party banter. One participant raises their arms in triumph upon receiving a clean bill of health while checking if their information was leaked in a data breach. Others swivel laptop screens and compare notes on the various places their digital detritus had cropped up. In my case, I was lucky: I mostly found data brokers with incorrect information, a long-forgotten MySpace page, and a woman whose spam calls I’ve been receiving for the past 10 years. Finally, participants are directed to various pages where they can request data to be removed, or sign up for discounted services like Kanary and DeleteMe that do the removals on your behalf.

Behind the fun and light atmosphere, everyone here knows the unspoken reality that drives tonight’s activities: an unrelenting wave of discriminatory bills and executive orders that are rapidly demolishing trans rights across the US. “Trans Visibility” is a nice idea, but it turns out it really sucks to be visible in a fascist surveillance state where the highest levels of government are obsessively trying to destroy your ability to live.

“In this world of hyper-surveillance, I want to make sure all my stuff is safe and that no one is trying to harvest my data for anything,” Anna, a workshop participant, told 404 Media. Anna asked to use a pseudonym to protect her identity, which is not surprising given that the goal of the workshop is to make it harder to be doxed. “Especially now that there’s lots of incentives for the federal government to get into that business, I just wanna make sure all of that is under wraps.”

Like the event’s name suggests, many attendees are looking for traces of their “deadnames,” which is how some trans folks refer to the names they were given pre-transition. Trans people face a disproportionatelyhigh risk of being doxed online, and deadnames and other sensitive info are frequently dug up on right-wing hate forums like KiwiFarms and social media sites like Elon Musk’s X, where harassment campaigns and hate speech are allowed and even encouraged.

“We have to protect ourselves,” said Ryan, who also used a pseudonym. “It’s great to know how to find stuff like this, because you never know what’s still out there.”

Imani Thompson, a digital security trainer who organized the event as part of her series Cache Me Outside, says she started hosting the free workshops at queer bars in Brooklyn a year ago, after noticing trans and intersex friends who were noticeably shaken by the opening salvos of the second Trump administration.

“I hadn't seen cybersecurity events that looked like they would attract or resonate with the crowds I felt needed this information the most,” she told 404 Media. “I wanted to make this fun and un-intimidating and doing digital security training at the bar is kind of silly and fun and gives us a built-in VPN and protection from sensitive convos being recorded.”
playlist.megaphone.fm?p=TBIEA2…
There are specific reasons many trans people are anxious about their personal data and online presence these days. For one, trans identities often don’t fit neatly into government boxes, and the name and gender they are assigned at birth may or may not match their government-issued IDs. Recently, a new law in Kansas resulted in hundreds of trans people being told that theirdrivers licenses and IDs had been invalidated overnight, forcing them to obtain new documents that revert to the sex marker assigned at birth. JournalistMarissa Kabas later reported that the 300 trans IDs in question had been flagged and not immediately invalidated, but the goal of the law and its ensuing chaos was clear: requiring trans people to have IDs that don’t match their appearance or lived reality, forcing them to out themselves and introducing friction and discrimination into their everyday lives.

The same Kansas law also implemented the first state-level “bathroom bounty,” making it a crime for trans people to use appropriate bathrooms and changing rooms and promising rewards to random passersby who feel “aggrieved” by someone they think might be trans. Lawmakers in Idaho have passed an even harsher bill, which would charge repeat trans bathroom-users with a felony and up to 5 years of jail time. These bills threaten not only trans people, but anyone whose appearance might fall outside of someone’s normative expectations of “male” and “female.” And they are especially dangerous at a time when facial recognition can near-instantly identify someone with a quick search.

Thompson also worries about the information that queer folks can reveal while asking for help online. Trans people experienceunemployment,housing insecurity, andviolence at exponentially higher rates than cis people, and it’s not uncommon to see Gofundme pages and Venmo accounts flooding social media feeds. These posts will sometimes include personal details like a person’s name, face, transition status, location, immigration status, and even how much they have in their bank account—great for getting donations, but not so great for the doxable breadcrumbs they leave behind.

You Can’t Post Your Way Out of Fascism
Authoritarians and tech CEOs now share the same goal: to keep us locked in an eternal doomscroll instead of organizing against them, Janus Rose writes.
404 MediaJanus Rose


“I think the risk is tenfold for the dolls and Black trans siblings because of disproportionate scrutiny in light of these bathroom bills and also how we do mutual aid,” said Thompson. “Whenever I see a mutual aid request being reposted or processed it makes me nervous, because we're basically doxing our most vulnerable friends.” To reduce risk, she recommends people take down mutual aid posts as soon as needs are met and set their Venmo activity to private. “I feel like the intention in listing off how all these systems of oppression impact our friends are meant to create a sense of urgency and care, but then months later it's still floating around and is a goldmine for someone who wants to claim they were made to feel unsafe in a bathroom so they can claim $3k or further an agenda.”

The privacy attitudes on display at the event contrast with the dominant media narratives about trans communities a decade ago. Fresh off the Supreme Court victory in Obergefell vs. Hodges that legalized same-sex marriage, many at that time were convinced that trans visibility would pave the way to equality, as glossy magazine covers featuring stars like Laverne Cox declared a “Trans Tipping Point.” But while conditions for some trans people marginally improved, we all know what happened next: a wave of reactionary anti-trans state laws, culminating in the re-election of Donald Trump and a series of executive orders aimed at destroying trans peoples’ access to healthcare, sports, bathrooms—essentially the ability to live a normal life.

At the same time, protection can’t be a retreat back into the closet. “It’s still important for trans voices to be heard in online spaces,” said Anna. “It’s not like I wanna go into the shadows or anything. I just don’t want people to know my personal data, my personal records, any of that.”

“Being Black, I also understand the distinction between visibility and hypervisibility and the precarity and lack of agency that hypervisibility creates,” said Thompson. “It's tricky to find language around digital security that doesn't imply queerness is something to hide or a shameful thing, because of course it's not. I think having agency and purpose in how we can show up online and interact with tech as well as literacy around how technology and surveillance operates makes us better equipped.”

Janus Rose is New York City-based journalist, educator and artist whose work explores the impacts of A.I. and technology on activists and marginalized communities. Previously a senior editor at VICE, she has been published in digital and print outlets including e-Flux Journal, DAZED Magazine, The New Yorker, and Al Jazeera.


TeleGuard is an app downloaded more a million times that markets itself as a secure way to chat. The app uploads users’ private keys to the company’s server, and makes decryption of messages trivial.#Privacy #News


A Secure Chat App’s Encryption Is So Bad It Is ‘Meaningless’


TeleGuard, an app that markets itself as a secure, end-to-end encrypted messaging platform which has been downloaded more than a million times, implements its encryption so poorly that an attacker can trivially access a user’s private key and decrypt their messages, multiple security researchers told 404 Media. TeleGuard also uploads users’ private keys to a company server, meaning TeleGuard itself could decrypt its users’ messages, and the key can also at least partially be derived from simply intercepting a user’s traffic, the researchers found.

The news highlights something of the wild west of encrypted messaging apps, where not all are created equal.

💡
Do you know anything else about this app or other security issues? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

“No storage of data. Highly encrypted. Swiss made,” the website for TeleGuard reads. The site also says, “The chats as well as voice and video calls are end-to-end encrypted.”

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The move isn't surprising, but shows what data is available to authorities when paying Apple customers use the Hide My Email feature.#Privacy #Apple #News


Apple Gives FBI a User’s Real Name Hidden Behind ’Hide My Email’ Feature


This article was produced in collaboration with Court Watch, an independent outlet that unearths overlooked court records. Subscribe to them here.

Apple provided the FBI with the real iCloud email address hidden behind Apple’s ‘Hide My Email’ feature, which lets paying iCloud+ users generate anonymous email addresses, according to a recently filed court record.

The move isn’t surprising but still provides uncommon insight into what data is available to authorities regarding the Apple feature. The data was turned over during an investigation into a man who allegedly sent a threatening email to ​​Alexis Wilkins, the girlfriend of FBI director Kash Patel.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


A court record reviewed by 404 Media shows privacy-focused email provider Proton Mail handed over payment data related to a Stop Cop City email account to the Swiss government, which handed it to the FBI.#News #Privacy


Proton Mail Helped FBI Unmask Anonymous ‘Stop Cop City’ Protester


Privacy-focused email provider Proton Mail provided Swiss authorities with payment data that the FBI then used to determine who was allegedly behind an anonymous account affiliated with the Stop Cop City movement in Atlanta, according to a court record reviewed by 404 Media.

The records provide insight into the sort of data that Proton Mail, which prides itself both on its end-to-end encryption and that it is only governed by Swiss privacy law, can and does provide to third parties. In this case, the Proton Mail account was affiliated with the Defend the Atlanta Forest (DTAF) group and Stop Cop City movement in Atlanta, which authorities were investigating for their connection to arson, vandalism and doxing. Broadly, members were protesting the building of a large police training center next to the Intrenchment Creek Park in Atlanta, and actions also included camping in the forest and lawsuits. Charges against more than 60 people have since been dropped.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


The site, camgirlfinder, is explicitly built as a tool to let people find a model's presence on other streaming platforms. The creator says “If that is a problem for you then the sad reality is this job is not for you.”

The site, camgirlfinder, is explicitly built as a tool to let people find a modelx27;s presence on other streaming platforms. The creator says “If that is a problem for you then the sad reality is this job is not for you.”#Privacy #News

Lockdown Mode is a sometimes overlooked feature of Apple devices that broadly make them harder to hack. A court record indicates the feature might be effective at stopping third parties unlocking someone's device. At least for now.

Lockdown Mode is a sometimes overlooked feature of Apple devices that broadly make them harder to hack. A court record indicates the feature might be effective at stopping third parties unlocking someonex27;s device. At least for now.#Privacy #News

Videos on social media show officers from ICE and CBP using facial recognition technology on people in the field. One expert described the practice as “pure dystopian creep.”#ICE #CBP #News #Privacy


ICE and CBP Agents Are Scanning Peoples’ Faces on the Street To Verify Citizenship


“You don’t got no ID?” a Border Patrol agent in a baseball cap, sunglasses, and neck gaiter asks a kid on a bike. The officer and three others had just stopped the two young men on their bikes during the day in what a video documenting the incident says is Chicago. One of the boys is filming the encounter on his phone. He says in the video he was born here, meaning he would be an American citizen.

When the boy says he doesn’t have ID on him, the Border Patrol officer has an alternative. He calls over to one of the other officers, “can you do facial?” The second officer then approaches the boy, gets him to turn around to face the sun, and points his own phone camera directly at him, hovering it over the boy’s face for a couple seconds. The officer then looks at his phone’s screen and asks for the boy to verify his name. The video stops.

💡
Do you have any more videos of ICE or CBP using facial recognition? Do you work at those agencies or know more about Mobile Fortify? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

This post is for subscribers only


Become a member to get access to all content
Subscribe now


A contractor for the Air Force and other government agencies wanted to get a good deal on some Graykeys from us (we're journalists FYI).

A contractor for the Air Force and other government agencies wanted to get a good deal on some Graykeys from us (wex27;re journalists FYI).#News #Privacy