WEBVTT
Kind: captions
Language: en

00:00:02.220 --> 00:00:10.680
This week's surveillance report covers three cracks in Apple's armor that users should definitely act on, and I want to make sure you guys know how to proceed forward.

00:00:11.300 --> 00:00:22.480
Browsers are quietly getting a little bit less private, a court forcing Google to open the Play Store and that they're not happy with their recent flow, and the usual data breaches, threats, and open source updates.

00:00:22.980 --> 00:00:28.040
Welcome, everybody, to the Techlore Surveillance Report, your essential weekly tech news delivering

00:00:28.160 --> 00:00:33.220
deep analysis on the latest threats to security, privacy, and digital freedom, and of course,

00:00:33.500 --> 00:00:37.820
empowering you to reclaim control and defend your rights.

00:00:38.020 --> 00:00:42.440
So the highlight story I'm breaking up into kind of three unique stories, starting with

00:00:42.440 --> 00:00:46.440
the first one being this tech radar piece, which I think is quite interesting.

00:00:46.460 --> 00:00:48.120
They bring up lots of good points.

00:00:48.400 --> 00:00:50.640
Apple has a couple privacy-focused features.

00:00:50.880 --> 00:00:57.060
The first one is Apple's iCloud Private Relay. This is essentially their VPN-style feature that

00:00:57.200 --> 00:01:01.580
lives inside of Safari. The actual white paper and the methodology behind the feature is very

00:01:01.880 --> 00:01:06.620
impressive, but here's the thing. There is a browser called Silo from the security research

00:01:06.920 --> 00:01:11.100
team MISC, and they discovered some issues with Private Relay, the first of which was a vulnerability

00:01:11.250 --> 00:01:16.360
which involved DNS prefetching, which is a feature designed to speed up browsing, but Safari was

00:01:16.380 --> 00:01:22.960
incorrectly resolving domain queries outside that secure proxy tunnel, leaking users' real DNS server.

00:01:23.180 --> 00:01:27.040
The second leak is through something called Web Transport, which is a protocol designed to enable

00:01:27.280 --> 00:01:32.400
faster communication between the browser and the website. And they found that that exact protocol is

00:01:32.540 --> 00:01:38.280
exposing the real user's IP address, even if they had private relay enabled. They also discovered that

00:01:38.280 --> 00:01:43.460
the passkey system specifically, which allows passwordless logins, also bypasses the proxy and

00:01:43.480 --> 00:01:48.460
reveals users' IP addresses. The second privacy-exclusive feature that was impacted was

00:01:48.620 --> 00:01:53.500
Hide My Email, which again is used to hide your email address from different websites. And what's

00:01:53.800 --> 00:01:57.520
crazy about this is this was discovered from the founders of Easy Opt Outs. They've been a

00:01:57.700 --> 00:02:01.900
recurring sponsor of this podcast, so it's kind of fun to see them discover this issue organically

00:02:01.930 --> 00:02:05.800
in the wild. They said that while they were investigating bounce issues to try to figure

00:02:05.940 --> 00:02:09.440
out why emails weren't being delivered, they noticed that they were seeing the customer's

00:02:09.460 --> 00:02:13.960
real email addresses in addition to their hide my email addresses in the bounce logs.

00:02:14.350 --> 00:02:17.820
They reported it to Apple and after a few months of no resolution, they just went to

00:02:17.820 --> 00:02:20.180
the media because that was the best way to get things done.

00:02:20.310 --> 00:02:24.220
A week after the news came out, they finally got it patched on July 7th.

00:02:24.480 --> 00:02:25.280
So those are the two issues.

00:02:25.450 --> 00:02:29.980
I thought it was kind of fun that these two people who have privacy based projects actually

00:02:30.140 --> 00:02:31.480
were the people who discovered these issues.

00:02:31.660 --> 00:02:34.000
So props to the privacy world for figuring these out.

00:02:34.480 --> 00:02:39.160
But also the tech radar piece has some really interesting commentary of like, hey,

00:02:39.660 --> 00:02:44.840
You know, there are these holes that are starting to open up in Apple's privacy in their ecosystem.

00:02:45.260 --> 00:02:50.940
And also the people that discovered these issues, both Murphy from Easy Optouts and also the MISC team,

00:02:51.160 --> 00:02:53.880
said that like these issues should have never happened in the first place.

00:02:54.160 --> 00:02:54.980
These are pretty embarrassing.

00:02:55.150 --> 00:02:57.700
And also Apple's just not taking this seriously.

00:02:57.730 --> 00:03:00.760
They seem to wait too long to take actually deal with these issues.

00:03:01.420 --> 00:03:03.480
And then it's kind of just leaving their users in the dark.

00:03:03.670 --> 00:03:08.760
So when I see security researchers and people who discover these issues all say the same thing,

00:03:08.920 --> 00:03:13.440
which is they are unhappy with how Apple deals with these issues, how they respond to them,

00:03:14.000 --> 00:03:18.480
and that they don't get them fixed typically in the way that they should until they finally make

00:03:18.480 --> 00:03:23.720
a big scene about it and then Apple decides to quietly fix it. That's a real problem. And so I

00:03:23.860 --> 00:03:28.060
think that's my biggest concern. And it's something that Apple really needs to figure out if they want

00:03:28.140 --> 00:03:34.340
to retain that kind of, I don't know, reputation that they've built up. I mean, Murphy from Easy

00:03:34.540 --> 00:03:38.880
Optouts even said, I'm personally a little surprised the hive my email issue ever even

00:03:38.900 --> 00:03:43.180
into production. I also think that the private relay issue is something that has been this

00:03:43.400 --> 00:03:48.180
recurring issue with Apple that I'm quite annoyed about too, is Apple just clearly does not kind of

00:03:48.380 --> 00:03:55.740
care whatsoever about users' IP-based protection. Even if private relay properly tunneled all of

00:03:55.740 --> 00:04:00.020
your Safari traffic, why is it only in Safari? Like, why can't they enable it system-wide?

00:04:00.340 --> 00:04:04.900
And then even if you get a system-wide VPN, let's say you go with Mullvad or you go with Obscura,

00:04:05.040 --> 00:04:11.500
you go with iVPN, Windscribe, Proton, whichever VPN you pick, none of them right now in 2026 can

00:04:11.760 --> 00:04:16.680
actually guarantee that 100% of your web traffic on an iPhone actually goes through the VPN tunnel

00:04:17.019 --> 00:04:21.340
because Apple still does these random ass exclusions for your web traffic. So this is

00:04:21.459 --> 00:04:25.160
something that people don't really know about or think about. And it's something that I think Apple

00:04:25.340 --> 00:04:30.320
really needs to take seriously. Apple is trying to sell this idea that we deliver this much privacy

00:04:30.340 --> 00:04:36.020
and security to you. And actually, I would say that a lot of it's true. But those little

00:04:36.360 --> 00:04:41.300
differences where they actually aren't meeting kind of the marketing that they imply are major

00:04:41.560 --> 00:04:45.620
issues, especially for people with higher threat models. Where I push back on TechRadar's coverage

00:04:45.840 --> 00:04:49.640
is they say that this is the issue when you just choose one provider to keep you safe.

00:04:49.980 --> 00:04:53.800
I don't fully agree with that. I think there are some situations where I'd say there actually is

00:04:53.900 --> 00:04:58.620
one provider that can do a few things very well. I think Proton's a good example of this. Tud is a

00:04:58.620 --> 00:05:03.420
good example of this. We have some VPN companies that also expand beyond just offering a VPN

00:05:03.900 --> 00:05:08.980
provider. I would be making this more of an exclusive Apple issue. I think it almost discounts

00:05:09.190 --> 00:05:13.780
the responsibility Apple should be taking if they just say, oh, this is what happens when one company

00:05:13.980 --> 00:05:17.560
does, you know, all these privacy things. And it's like, I actually think theoretically,

00:05:18.230 --> 00:05:22.480
they can do it right. And it doesn't have to be a compromise. So I actually would like to see a

00:05:22.510 --> 00:05:27.100
little bit more blame on Apple here. And what Apple's doing internally, how they're not taking

00:05:27.120 --> 00:05:32.200
security researchers seriously. Clearly, their response times are whack. And there's not enough

00:05:32.380 --> 00:05:35.740
transparency and disclosure on how they handle this. Now, before moving on to the next story,

00:05:35.920 --> 00:05:43.120
just to make it very crystal clear, Apple has not fixed that private relay issue. So if Safari and

00:05:43.300 --> 00:05:48.300
your IP address being safe in Safari is something that is a must for you, definitely stop using

00:05:48.540 --> 00:05:52.980
private relay. And this is unfortunate because it's a tool that I actually have some appreciation

00:05:52.980 --> 00:05:57.520
for and I've used it in the past. But I think in light of this, we should definitely hold off until

00:05:57.640 --> 00:06:01.780
there's more information and Apple decides to treat this a little bit more seriously. The hide my email

00:06:02.060 --> 00:06:07.280
issue is fixed, though, again, I think it doesn't really fully dismiss maybe the longer term concerns

00:06:07.320 --> 00:06:12.120
of how Apple is dealing with these issues. Now, the second story is regarding a vulnerability on

00:06:12.280 --> 00:06:17.020
macOS. I'd say this is more of a typical vulnerability that we'll find in different

00:06:17.220 --> 00:06:21.460
operating systems and software. But it's a screen sharing bug that let remote hackers log in without

00:06:21.480 --> 00:06:25.860
a password. And I think the few takeaways I have to share with you on this one is one,

00:06:26.190 --> 00:06:30.260
get yourself updated because Apple already patched it in Tahoe, Sequoia, and Sonoma.

00:06:30.740 --> 00:06:35.960
Any computer out there, check your screen sharing setting right now to see if that's enabled. And if

00:06:36.060 --> 00:06:40.720
it's not used for anything, turn it off. That's a very easy thing to reduce your attack surface on.

00:06:41.180 --> 00:06:45.420
But the macOS firewall opens the port when you enable screen sharing. Routers and dedicated

00:06:45.640 --> 00:06:49.320
firewalls generally block the port unless configured to override that setting. So just

00:06:49.520 --> 00:06:54.360
check your firewall. The macOS firewall for a lot of people isn't enabled by default. And so this is

00:06:54.580 --> 00:06:59.580
another reminder to check your firewall settings in macOS. If you're curious, go into your system

00:06:59.880 --> 00:07:05.440
preferences, go to network and then go to firewall and turn that on. And if you have a little bit more

00:07:05.640 --> 00:07:10.700
know-how, go ahead and customize it so you can strengthen things a little bit better. And now the

00:07:10.960 --> 00:07:15.520
third Apple story I think is actually where Apple shines a little bit better, especially from the

00:07:15.540 --> 00:07:21.660
security side of things, which is that Apple has alerted tons of people out there that they are

00:07:21.730 --> 00:07:27.620
being targeted by spyware. Some context, if you're new, there are pretty much these, a lot of times

00:07:27.740 --> 00:07:32.900
governments, it seems like, but they are using these spyware attacks where they purchase unknown

00:07:33.180 --> 00:07:39.120
vulnerabilities for, you know, things like iOS, Android, etc. And they individually target people.

00:07:39.530 --> 00:07:44.060
Now, these are typically state-sponsored, and they are typically a lot of money, and it's not

00:07:44.000 --> 00:07:49.360
something that is typically, I'm saying typically a lot here, because this isn't the kind of thing I

00:07:49.480 --> 00:07:56.060
want just, you know, regular person, a teacher, you know, someone who goes to their small business

00:07:56.190 --> 00:08:00.980
in the morning, who is serving, you know, coffee, their cafe, etc. Like, that's not the person who

00:08:01.060 --> 00:08:05.700
needs to be worried about this. But what is concerning is that this specific batch of

00:08:06.100 --> 00:08:12.180
notifications sent out to people who were targeted, which Apple does do, was higher in number than

00:08:12.200 --> 00:08:17.080
normal. So we saw people like iVerify, the cybersecurity firm, and we also saw another

00:08:17.210 --> 00:08:23.720
firm called Access Now, who reported that they saw a good significant bump in what they normally get

00:08:23.750 --> 00:08:29.160
when people start receiving these notifications. So remember, guys, Hide My Email issue was fixed,

00:08:29.210 --> 00:08:33.039
though you can still move to a dedicated aliasing service, which I recommend because that gives you

00:08:33.039 --> 00:08:38.159
more ownership regardless. And there's nothing that Hide My Email is doing that's any more privacy

00:08:38.300 --> 00:08:42.159
respecting those services. In fact, those services are open source and they have some other benefits

00:08:42.180 --> 00:08:44.500
I would say outperform hide my email.

00:08:45.060 --> 00:08:46.600
Private Relay is really hard to replicate.

00:08:46.900 --> 00:08:48.260
It's actually a really interesting service.

00:08:48.390 --> 00:08:50.180
And again, on paper, it's very cool.

00:08:50.700 --> 00:08:53.440
But in light of this issue, you should really proceed carefully.

00:08:53.570 --> 00:08:57.920
Make sure to update macOS for that vulnerability on macOS and also check your firewall settings.

00:08:58.320 --> 00:09:00.740
Enable lockdown mode if you are concerned about those notifications.

00:09:01.130 --> 00:09:04.380
And especially if you got one of those, contact some digital rights organizations.

00:09:10.720 --> 00:09:14.720
All right, coming soon, we have a judge giving Google one week to fix their anti-competitive

00:09:14.900 --> 00:09:19.100
Play Store, and we have France. I actually had some really good news, but before we get there,

00:09:19.480 --> 00:09:23.340
we have a quick story on a couple things regarding your browsers that I wanted to flag,

00:09:23.560 --> 00:09:27.080
which I think are quite important regarding the privacy of all of your web browsing.

00:09:27.660 --> 00:09:32.160
So the first one is that there were hundreds of fake Chrome VPN extensions that route traffic

00:09:32.400 --> 00:09:38.100
through a proxy. The specific number was 737 browser extensions that were published on the

00:09:38.080 --> 00:09:42.980
official Chrome web store that impersonated well-known VPN and proxy services. These

00:09:43.220 --> 00:09:48.940
impersonations impacted things like ProtonVPN, NordVPN, Surfshark ExpressVPN, and even Cloudflare's

00:09:49.080 --> 00:09:54.740
1.1.1.1 DNS resolver. What's fascinating is that Google removed more than 200 of the extensions

00:09:55.060 --> 00:09:59.020
related to the identified campaign. Over 500 of them, though, at the time of them writing this,

00:09:59.360 --> 00:10:04.960
were still available in the Chrome web store. Guys, I continue to say this, and I don't know

00:10:04.900 --> 00:10:11.440
how else I can say this to get people just more aware of these issues. Extensions are like crazy

00:10:11.660 --> 00:10:15.940
right now. I mean, the Chrome Web Store, all these big tech companies try to come forward and say,

00:10:16.280 --> 00:10:20.420
you know, the only safe way to get software is through our app stores because we vet things so

00:10:20.600 --> 00:10:25.480
carefully. And then meanwhile, we see stuff like this, or even after they find the issue,

00:10:25.560 --> 00:10:30.459
they still haven't actually removed 500 different things that are straight up impersonating

00:10:30.480 --> 00:10:35.800
legitimate projects. So it is really bad. I would always, especially the Chrome Web Store,

00:10:36.310 --> 00:10:40.440
second guess everything I'm installing. Personally, for me, I almost never install extensions. You

00:10:40.520 --> 00:10:44.620
should try to avoid them at all costs just for privacy and security reasons. But if you do need

00:10:44.630 --> 00:10:48.180
an extension in your browser, which definitely happens, I'm not saying people should just never

00:10:48.420 --> 00:10:53.300
install an extension. But when it happens, go to the official developer's website. So if I'm getting

00:10:53.350 --> 00:10:59.220
the ProtonVPN extension, I'm going to ProtonVPN's website and looking for their download extension

00:10:59.240 --> 00:11:04.240
button and having it redirect me to the Chrome web store. I'm not going to my search engine where

00:11:04.340 --> 00:11:08.940
there could be some search advertisements that takes me to the wrong page. I'm not going to the

00:11:09.020 --> 00:11:14.480
Chrome web store and relying on their search, which may or may not actually give me the right thing.

00:11:14.900 --> 00:11:20.500
I'm going to the actual website that belongs to the verified developer. And that is a general

00:11:20.820 --> 00:11:25.319
thing you should always strive for when you're downloading software. The next story is from

00:11:25.340 --> 00:11:29.620
AdGuard, and it's pretty much just a quick announcement that Microsoft Edge is finally

00:11:29.920 --> 00:11:35.100
preparing to say goodbye to Manifest V2. So a bit of context here, there is an underlying extension

00:11:35.340 --> 00:11:40.740
technology that enables extensions to do things in your browser. Manifest V2 is what we've been

00:11:40.830 --> 00:11:44.880
using for a very long time, and it's what's enabled ad blockers and all these wonderful

00:11:45.060 --> 00:11:51.080
things that we know and have grown to love. But Manifest V3 is the new version, and while there

00:11:51.060 --> 00:11:56.080
are some interesting things that it does. It does a lot to limit things like ad blockers, and it

00:11:56.180 --> 00:12:00.700
makes it a little bit more challenging for ad blocker developers to be able to do the same job

00:12:00.810 --> 00:12:05.540
they did in v2. They say that there still are some restrictions despite their head start with v3,

00:12:05.760 --> 00:12:09.220
which is rule counts are limited. Certain filtering techniques cannot be reproduced exactly,

00:12:09.290 --> 00:12:13.800
and most filter updates must still be delivered with the extension itself. Maintaining functionality

00:12:14.060 --> 00:12:18.300
close to our MV2 version therefore takes more work, while some improvements may take longer to

00:12:18.320 --> 00:12:22.680
reach users. So this is just a heads up. I mean, it's already happened in Google Chrome. Google

00:12:22.720 --> 00:12:27.980
Chrome already has, for the most part, largely ruled out MV2. And it's why we see things like

00:12:28.500 --> 00:12:34.060
uBlock Origin Lite instead now, which is the MV3 version of uBlock Origin. And this is just to say

00:12:34.160 --> 00:12:40.320
that Edge is now following in their footsteps. And so if you want a browser that doesn't do this

00:12:40.320 --> 00:12:46.319
and still supports MV2, Firefox has committed to support MV2 kind of indefinitely. I wouldn't

00:12:46.340 --> 00:12:50.700
expect these browsers to do it forever, but they still do it. The Brave browser still allows it.

00:12:50.900 --> 00:12:56.100
In fact, in the Brave browser settings, if you type manifest, and I'm showing this on screen,

00:12:56.190 --> 00:13:00.720
you're going to see a whole section in the Brave browser settings called manifest v2 extensions.

00:13:01.320 --> 00:13:07.220
And they literally let you actively enable AdGuard or uBlockOrigin, NoScript or uMatrix in the Brave

00:13:07.360 --> 00:13:12.779
browser as the MV2 variants. They actively still support that in the Brave browser. I believe

00:13:12.800 --> 00:13:17.080
Vivaldi does as well. And pretty much any other Firefox fork should as well. Pretty much if you're

00:13:17.240 --> 00:13:21.800
using a browser that's not from a big tech company, you're still fine. And if you're using a browser

00:13:21.900 --> 00:13:27.420
from a big tech company, you're kind of not fine. Coincidence? I think not. All right, guys, we have

00:13:27.560 --> 00:13:31.560
a judge giving Google one week to fix their anti-competitive Play Store. And we have France,

00:13:31.700 --> 00:13:34.900
which had some really good news. But we have a quick message from our sponsor.

00:13:36.760 --> 00:13:42.760
Quick one, go into your email inbox right now and type in unsubscribe. However, many hundreds or

00:13:42.780 --> 00:13:48.420
of results you just got, that's how many companies have your real email address. So the moment any of

00:13:48.420 --> 00:13:53.280
them gets breached or quietly sells you out, it's your real inbox eating the spam, the trackers,

00:13:53.520 --> 00:14:00.000
and the hackers forever. Addy.io is designed to fix this entire problem. The whole idea is you

00:14:00.220 --> 00:14:05.600
stop giving out your real email address and instead hand every single site its own alias that just

00:14:05.860 --> 00:14:11.120
forwards to the inbox you already have. Think like Apple hide my email, except it's open source and

00:14:11.140 --> 00:14:15.480
you can bring it to any email inbox. And my favorite part is that once you get all your

00:14:15.700 --> 00:14:19.760
accounts using an email alias, you can always swap the email provider behind the scenes,

00:14:19.950 --> 00:14:25.080
like moving from Gmail to a private email provider without needing to update every single account's

00:14:25.450 --> 00:14:29.520
email. And it's possible because you're really just putting Addy in front of your email. It's

00:14:29.600 --> 00:14:33.740
like your email bodyguard. This also offers a lot of protection. If a site starts to spam you,

00:14:34.060 --> 00:14:38.100
or you show up in a data breach, or you realize they sold your data because that one specific

00:14:38.100 --> 00:14:42.300
alias suddenly started getting junk, you just deactivate the alias. It's fully open source,

00:14:42.540 --> 00:14:45.980
so you're not trusting a black box. And you can even self host the entire thing if you're that

00:14:46.040 --> 00:14:50.140
kind of person, which I know many of you are. It's on F Droid, there are browser extensions and

00:14:50.240 --> 00:14:53.960
mobile apps so you can spin up a fresh alias right as you're signing up for something. And if you

00:14:54.040 --> 00:14:57.700
want to go all in, you can even use it with your own custom alias. It's free to start and they have

00:14:57.700 --> 00:15:02.320
a crazy generous free plan to get started. Visit Addiio or just check them out down in the description.

00:15:02.540 --> 00:15:04.980
And thank you guys for sponsoring us. Now back to the video.

00:15:05.000 --> 00:15:16.020
go. The fun thing about Addy.io sponsoring this is it's actually a really good solution to that

00:15:16.220 --> 00:15:21.380
first vulnerability we talked about with Apple, the Hide My vulnerability. So Addy.io is a really

00:15:21.550 --> 00:15:27.020
perfect swap in if you use the Hide My ecosystem. Now, the next story here is that a judge has given

00:15:27.170 --> 00:15:32.680
Google one week to fix their anti-competitive app store download in Google Play. This has to do with

00:15:32.700 --> 00:15:39.320
a story we just recently covered, which is that Google and Epic have this ongoing thing happening,

00:15:39.520 --> 00:15:44.600
and Google finally has decided, hey, we're going to allow third-party app stores inside of the

00:15:44.640 --> 00:15:49.200
Google Play Store. Now, what's quite fascinating is we have a few things happening at the same time.

00:15:49.240 --> 00:15:53.720
We have Google coming forward and making this concept of air quotes, sideloading,

00:15:54.200 --> 00:15:58.640
a bit harder to do. You have to go through this advanced flow, you have to activate developer

00:15:58.640 --> 00:16:03.860
settings, and then you have to reboot your phone, you have to wait 24 hours, and you have to confirm

00:16:04.080 --> 00:16:09.100
that you actually are doing this at your own will. And while they're doing that, they're now making it,

00:16:09.660 --> 00:16:15.880
I guess, in theory, possible to get third-party app stores from the Play Store. But that comes

00:16:15.960 --> 00:16:21.000
with a lot of kind of caveats. You have to pay to get in there, they have to still let you in there,

00:16:21.380 --> 00:16:26.960
and it's kind of Google, in some ways, in my view, still taking a lot more control. Because you have

00:16:26.900 --> 00:16:31.480
to go through some confusing menus, the lawyer showed the court that even searching for App Store

00:16:31.680 --> 00:16:36.340
and Aptoid, which is the first App Store on there, didn't show the intended results like any other

00:16:36.600 --> 00:16:40.740
search. Instead, the Play Store shows an are you looking for banner that links to the third-party

00:16:40.960 --> 00:16:45.800
App Store page. They say another problem is the process of actually installing the store. When you

00:16:45.920 --> 00:16:50.780
finally get to the page with Aptoid and eventually other stores, there is actually no install button

00:16:51.080 --> 00:16:56.860
as you'd get with a normal app or game from the normal store. A view button opens another dialogue

00:16:56.880 --> 00:17:01.200
to actually install. They said this additional step was unnecessary and seemed geared towards

00:17:01.420 --> 00:17:05.780
discouraging users from downloading alternative stores. He said the button must change to install

00:17:06.150 --> 00:17:10.220
instead of view. So that's just one more thing that Google was doing to make it harder. Google's

00:17:10.319 --> 00:17:14.439
legal team agreed to make the changes and they gave the company one week noting they should contact

00:17:14.680 --> 00:17:19.600
them if there's any problem with that timeline. So it should be a little bit easier. Now, again,

00:17:19.750 --> 00:17:24.500
I think that this is maybe winning. Was it winning the battle but losing the war? Is that I think

00:17:24.500 --> 00:17:29.840
that's the right order of things, but they're still ultimately making it harder to actually

00:17:30.060 --> 00:17:33.700
get these app stores away from the Google Play Store, which has its own problems.

00:17:33.920 --> 00:17:35.520
Like, I think, yes, it's good.

00:17:35.760 --> 00:17:39.000
You know, we have things going through the Google Play Store, but Google's really still

00:17:39.600 --> 00:17:43.520
ultimately kind of winning if they're still requiring people to go through the Google

00:17:43.700 --> 00:17:43.940
Play Store.

00:17:44.080 --> 00:17:47.400
What happens to users who use custom ROMs who don't want to use the Google Play Store?

00:17:47.760 --> 00:17:48.640
How do they get software?

00:17:49.020 --> 00:17:51.920
Oh, Google's making that harder and more obnoxious for third-party developers.

00:17:52.040 --> 00:17:53.560
So that's still a net loss, right?

00:17:54.060 --> 00:17:57.620
So I'm still very kind of mixed on this whole story.

00:17:57.810 --> 00:18:03.140
What needs to also be targeted is Google's clamping down of things outside of the Play Store

00:18:03.540 --> 00:18:08.680
as they're opening up the Play Store and requiring these third-party app stores to pay them money.

00:18:08.940 --> 00:18:12.420
While, again, this is a small win, I'm kind of looking at this overall theme

00:18:12.450 --> 00:18:16.180
and trying to figure out how does this impact the broader Android ecosystem,

00:18:16.500 --> 00:18:21.420
and is this really fixing those other concerns that I'm kind of watching for?

00:18:21.800 --> 00:18:25.540
So keep an eye out on this, and I'll be updating the podcast as more information comes to light.

00:18:31.560 --> 00:18:35.660
The next story is genuinely super good news, at least for now.

00:18:36.280 --> 00:18:40.140
France's top court has blocked social media ban for under 15.

00:18:40.480 --> 00:18:43.800
So these social media bans have been popping up all over the world.

00:18:43.820 --> 00:18:48.720
The entire concept is we're not going to actually hold big tech companies accountable.

00:18:49.160 --> 00:19:05.500
Instead, we're going to let them do what they've been doing for years, which is manipulating people, giving them infinity scroll feeds, letting them do scroll, letting them do whatever, giving dark patterns, not being transparent about data collection, doing everything possible to exploit humans and their basic autonomy, right?

00:19:05.720 --> 00:19:11.800
If you're under 15 or under 16 or whatever age we decide, we're just going to not let you on those platforms.

00:19:12.180 --> 00:19:14.800
And that is our solution, apparently, to this problem.

00:19:15.140 --> 00:19:20.840
This is a clear privacy issue because now you're requesting that people upload their ID to the very platforms that are a problem.

00:19:21.200 --> 00:19:24.600
The only way to verify who's a child and who's an adult is for everyone to upload their ID.

00:19:25.160 --> 00:19:28.800
We've seen data breaches as a result of these kind of ID uploads.

00:19:29.170 --> 00:19:36.920
And now it feels like, to me, the individual is being regulated instead of the big tech company who should be regulated in these situations.

00:19:37.120 --> 00:19:48.800
I've been very concerned about this because many countries like Australia, the UK, and even some places in Europe have either proposed, have already put into law, or are getting ready to put this into law.

00:19:49.120 --> 00:19:52.160
And France was one of the recent stories that we've been covering on this podcast.

00:19:52.620 --> 00:20:04.480
But thank goodness, France's top court blocked this bill, saying it infringed upon freedom of expression and delivered a setback for President Macron, who asked his government to rewrite the legislation.

00:20:04.780 --> 00:20:11.700
Macron, I know we have some French listeners, so I hope you appreciate my embarrassing way of pronouncing the French names.

00:20:11.970 --> 00:20:25.380
The council holds that the contested provisions on the one hand disproportionately infringe upon the freedom of expression and communication and on the other fail to provide the legal safeguards necessary to ensure the right to respect for private life.

00:20:25.680 --> 00:20:29.840
Now, this doesn't mean that this is completely gone and it's over in France.

00:20:29.980 --> 00:20:33.440
So I really don't want to celebrate this as an ultimate win.

00:20:33.460 --> 00:20:36.080
But this is a huge win in the right direction, guys.

00:20:36.460 --> 00:20:41.500
And I think it really sets good precedent for the rest of the EU because the EU has come

00:20:41.720 --> 00:20:42.880
forward as a unit.

00:20:43.160 --> 00:20:44.440
And this is a quote from the article.

00:20:44.680 --> 00:20:48.440
They have said that they are planning to seek stronger protections for children from harmful

00:20:48.660 --> 00:20:49.520
social media features.

00:20:50.000 --> 00:20:53.620
Do you know what would keep children safer from harmful social media features?

00:20:54.280 --> 00:20:57.480
Actually regulating those harmful social media features.

00:20:57.900 --> 00:20:59.800
And all these bans are just pseudo solutions.

00:21:00.180 --> 00:21:03.720
right? Like it doesn't change the platform. Children are either going to get around the

00:21:03.820 --> 00:21:07.980
bands or they're just going to have their parents let them access the service anyway. And now they're

00:21:07.980 --> 00:21:12.700
getting access to the same service as it's always been. Or let's say the child actually does avoid

00:21:12.700 --> 00:21:17.520
the platform until they're 16. So what? They turn 16 and now they're back on the same invasive,

00:21:17.820 --> 00:21:22.140
crappy platform. I really wish that these politicians would actually take the same energy,

00:21:22.390 --> 00:21:27.819
but apply it towards the companies and regulate the freaking companies who are actually actively

00:21:27.820 --> 00:21:32.040
doing all these things. That's actually why I'm a little bit optimistic about this recent stuff

00:21:32.060 --> 00:21:36.700
that's been happening in the US, which is directly targeting Facebook and these other big tech

00:21:37.000 --> 00:21:43.700
companies to say that they are actively making these platforms addictive to children. And they

00:21:43.700 --> 00:21:48.620
are targeting those addictive features and holding the companies accountable for the addictive

00:21:49.060 --> 00:21:53.780
features. I'll also use this as a shameless plug that you can join things like Mastodon. You can

00:21:53.980 --> 00:21:57.800
join things like better social media platforms. We're on these platforms. We have our own peer

00:21:57.820 --> 00:22:02.060
Tube server, these things don't use these kind of exploitive algorithms that are just designed to

00:22:02.100 --> 00:22:06.560
keep you on them all day. The whole purpose is to give you and deliver you a good experience,

00:22:06.920 --> 00:22:10.800
good service, and then you move on with your day. And that's what these platforms could do as well.

00:22:10.980 --> 00:22:15.380
So good job, France. And I hope other countries follow in their footsteps because this was a rare

00:22:15.520 --> 00:22:19.360
France win. I feel like every time I've covered France on this podcast the last couple years,

00:22:19.760 --> 00:22:24.860
almost always it's not for the best reasons for personal privacy, personal security.

00:22:25.300 --> 00:22:27.520
But this is one of the good wins. So good job, France.

00:22:33.520 --> 00:22:37.680
all right and now we're going to get into the defense bulletin this is split into three sections

00:22:38.010 --> 00:22:42.320
the first is the data breaches of the week then we're going to go into the threats of the week

00:22:42.390 --> 00:22:46.800
which is things i want to flag to make sure that you're aware of to stay safe and the third thing

00:22:46.960 --> 00:22:51.140
is the open source news to end on a positive note so the first data breach comes from health tech

00:22:51.270 --> 00:22:55.919
firm which is called care cloud this is a data breach that impacted 3.7 million patients they

00:22:55.940 --> 00:23:01.820
disclosed this back in March. And apparently, we are finding out about it now. The blast radius in

00:23:01.860 --> 00:23:05.880
terms of what was exposed is pretty large. And so if you have any relationship with ClearCloud,

00:23:06.020 --> 00:23:10.100
you should really check out the show notes down in the description. The next data breach is a

00:23:10.300 --> 00:23:14.680
supply chain attack and terabytes worth of credentials, many belonging to the world's

00:23:14.840 --> 00:23:19.780
biggest and most sensitive organizations was exposed in a supply chain attack on Lite LLM,

00:23:19.780 --> 00:23:24.400
which is an open source tool that streamlines AI driven software development. Earlier in the

00:23:24.320 --> 00:23:28.900
episode, I said, I always go to the official website. I download the extension. Imagine if

00:23:28.900 --> 00:23:33.160
you do that, but it's still compromised. That is how these supply chain attacks work. And that's

00:23:33.160 --> 00:23:36.740
what makes them so scary. So if you want to learn more about the story and supply chain attacks in

00:23:37.000 --> 00:23:40.840
general and all the people impacted by it, check out the show notes. Again, I keep the data breaches

00:23:41.060 --> 00:23:45.600
pretty brief so you guys can investigate the data breaches that impacts you specifically. Otherwise,

00:23:45.740 --> 00:23:50.700
this would be a two-hour podcast if I dove into each data breach individually. The next one is

00:23:50.720 --> 00:23:55.780
that a hacker claims that 3.6 million Azure accounts records were stolen from major companies.

00:23:56.080 --> 00:24:00.440
This apparently started July 31st, and multiple posts from someone using the alias The Hat Man

00:24:00.920 --> 00:24:06.020
advertised data dumps from major orgs, including McDonald's, Gap, Vodafone, Tata Consulting Services,

00:24:06.480 --> 00:24:12.080
HCL Technologies, Intercontinental Hotels, and Kindrel. So if you want to learn more about that,

00:24:12.340 --> 00:24:16.320
check it out in the show notes. RingCentral is a cloud-based collaboration and communication

00:24:16.340 --> 00:24:21.200
platform used by over 600,000 businesses. And they also had a data breach, which impacted the

00:24:21.440 --> 00:24:26.320
personal information from 1.6 million accounts. And so if you or someone you know has any relationship

00:24:26.500 --> 00:24:32.400
with RingCentral, check that one out in the show notes. We also have Sakura, which is a Japanese

00:24:32.600 --> 00:24:36.720
cloud and data center service provider, which disclosed that hackers access its sales management

00:24:36.960 --> 00:24:41.600
system where customer contract and membership information is stored. And so if you have ever

00:24:41.620 --> 00:24:45.820
had this internet provider or still do, this is another data breach to look into.

00:24:46.200 --> 00:24:49.480
This one pisses me off because this is one of those services that a lot of people are

00:24:49.680 --> 00:24:52.420
probably in, but they never actually created the damn account.

00:24:52.600 --> 00:24:54.280
And this is the whole data broker industry.

00:24:54.580 --> 00:24:55.500
It's just so frustrating.

00:24:55.780 --> 00:24:57.700
But there's a reverse lookup service.

00:24:58.300 --> 00:25:03.200
This is a people searching tool called Clarity Check, which just scrapes data about people

00:25:03.400 --> 00:25:06.180
that they never consented to directly, at least knowingly.

00:25:06.600 --> 00:25:09.740
And they exposed millions of photos of people's faces

00:25:10.380 --> 00:25:11.860
because they have all this data

00:25:11.880 --> 00:25:13.320
and they weren't properly securing it.

00:25:13.320 --> 00:25:14.820
And it's not just their faces.

00:25:14.920 --> 00:25:18.520
It also exposed people's email addresses and phone numbers.

00:25:19.040 --> 00:25:21.400
These data brokers are just like a bane

00:25:21.500 --> 00:25:22.460
of everybody's existence.

00:25:22.740 --> 00:25:24.860
They're just, they're mosquitoes, man.

00:25:25.000 --> 00:25:26.500
They literally, you don't see them.

00:25:26.820 --> 00:25:27.360
They're there.

00:25:27.400 --> 00:25:29.040
They take something precious from you

00:25:29.140 --> 00:25:32.360
and they just like feed off of you and nobody likes them.

00:25:32.600 --> 00:25:34.600
Mosquitoes are still useful, you know,

00:25:34.720 --> 00:25:39.500
the circle of life and the environment. And there's actually important reasons for mosquitoes

00:25:39.540 --> 00:25:45.180
to exist because other animals feed on them. These things are just straight up parasites that have no

00:25:45.220 --> 00:25:50.360
other benefit to the world. I hate data brokers. And this is another reason why data brokers suck.

00:25:50.640 --> 00:25:56.260
Next story comes from France. Their French tax authority data breach affected 678,000 individuals.

00:25:56.620 --> 00:26:02.940
And so if you are French, I would very much look into this story. The cryptocurrency hardware wallet

00:26:03.100 --> 00:26:10.200
SafePal is warning of a data breach impacting 39,798 customers, specifically that number,

00:26:10.880 --> 00:26:15.420
which was stolen for sale. Now, this didn't impact wallet seed phrases, private keys,

00:26:15.740 --> 00:26:21.040
passwords, bank account information, payment card numbers, etc. But it impacted email addresses,

00:26:21.520 --> 00:26:25.900
names, shipping addresses, phone numbers, and purchase information. My concern with these is

00:26:26.000 --> 00:26:31.660
that a lot of people who might have wealth are storing wealth on these devices. And so when you

00:26:31.620 --> 00:26:36.720
leak the personal information of those individuals, it puts them at much greater risk of further

00:26:36.980 --> 00:26:42.300
targeting and phishing attacks. So if you ever purchased anything from SafePal, well, first,

00:26:42.520 --> 00:26:47.080
welcome to the club because Ledger and I believe Treasure is the next one. Yes, that is the next

00:26:47.220 --> 00:26:51.820
story. They disclosed a data breach affecting nearly 14,000 customers. After ShipMonk, its

00:26:52.040 --> 00:27:01.580
shipping and logistics provider was hacked. Very similar kind of scope of what was attacked. So

00:27:01.600 --> 00:27:05.860
That means using alias emails, like something like Addy.io or Simple Login.

00:27:06.170 --> 00:27:10.460
You can also use privacy.com to purchase them, or you could purchase them with cryptocurrency

00:27:10.650 --> 00:27:14.480
if they support it and try to get them shipped to a private mailbox or somewhere safer.

00:27:14.800 --> 00:27:17.160
And the last data breach of the week before we get into the threats,

00:27:17.560 --> 00:27:21.920
Pokemon Center is notifying customers in the UK and Germany that it suffered a third-party data

00:27:22.040 --> 00:27:24.340
breach after a hacker stole customer personal information.

00:27:24.490 --> 00:27:26.880
So if you want to learn more about that, check it out in the show notes,

00:27:27.040 --> 00:27:30.040
or you probably were already notified if it impacted you directly.

00:27:30.420 --> 00:27:31.860
All right, now we're into threats.

00:27:31.970 --> 00:27:37.340
And this first one is a Linux botnet, which turns routers into traffic relay nodes.

00:27:37.520 --> 00:27:40.720
And fantastic imagery here by Bleeping Computer if they made that.

00:27:41.380 --> 00:27:47.780
But it's a Mirai-based modular Linux botnet malware called EV0001Bot,

00:27:47.810 --> 00:27:52.440
which has been targeting internet-facing gateway devices, turning them into SOX5 traffic relay nodes.

00:27:52.760 --> 00:27:58.200
They've been targeting devices from Alcatel, Netgear, Tenda, Mitsubishi Electric, Telesquare, and D-Link

00:27:58.140 --> 00:28:00.940
across various regions by exploiting known vulnerabilities.

00:28:01.450 --> 00:28:04.200
I would very much look into the story if you want to learn more.

00:28:04.480 --> 00:28:07.920
The main defense that they cite here against botnet malware in general

00:28:08.120 --> 00:28:10.900
is to keep your Internet of Things devices firmware updated,

00:28:11.300 --> 00:28:14.960
replace default admin credentials, turn off remote access panels,

00:28:15.460 --> 00:28:18.520
and replace devices when the vendor no longer provides support for them.

00:28:18.860 --> 00:28:21.160
I think one of the most dangerous things I see over the years

00:28:21.340 --> 00:28:25.000
is people who have devices who haven't been updated in five, six, seven years.

00:28:25.440 --> 00:28:30.040
You can maybe push an old device, I think, for a month, two months, three months.

00:28:30.330 --> 00:28:36.960
But you guys have to remember each month, each year that passes where a device is the end of life.

00:28:37.640 --> 00:28:42.200
It's just slowly building up more and more things that can be exploited.

00:28:42.410 --> 00:28:48.500
I like to think of this as like, you know, if you're running, you have flat ground and the flat ground is good, right?

00:28:48.580 --> 00:28:49.980
We like to run on flat surfaces.

00:28:50.420 --> 00:28:51.460
Hills are tougher, right?

00:28:51.900 --> 00:28:56.720
And so if you keep your devices and they're out of date, you know, you slowly start going.

00:28:56.900 --> 00:28:58.360
The mountain starts to creep up.

00:28:58.580 --> 00:29:01.380
What originally is just a little hump comes Mount Everest.

00:29:01.870 --> 00:29:07.080
And then at that point, you can't really do much in terms of protecting yourself as well, right?

00:29:07.280 --> 00:29:08.280
We can always lock things down.

00:29:08.290 --> 00:29:09.840
You can make them completely offline.

00:29:10.110 --> 00:29:12.020
You can add further multi-factor authentication.

00:29:12.250 --> 00:29:15.900
You can do a lot of things to still make it harder to exploit those vulnerabilities.

00:29:16.250 --> 00:29:18.680
But ultimately, you got to climb Mount Everest, man.

00:29:18.880 --> 00:29:20.700
So keep your devices up to date.

00:29:20.860 --> 00:29:22.020
And this is your reminder to do that.

00:29:22.560 --> 00:29:24.280
Now, this next story is from Comcast,

00:29:24.320 --> 00:29:27.180
who is adding motion sensing to millions of its newer routers.

00:29:27.460 --> 00:29:30.080
It's supposed to notify you when there's movement inside your house.

00:29:30.220 --> 00:29:31.920
And all it does is notify you of the movement.

00:29:32.060 --> 00:29:33.900
So it doesn't really do anything beyond that.

00:29:34.260 --> 00:29:36.680
But there are serious privacy implications for this technology.

00:29:36.720 --> 00:29:38.720
In fact, there was research published about a week ago

00:29:38.920 --> 00:29:43.460
that actually showed that you can identify people 99.5% of the time.

00:29:43.600 --> 00:29:46.040
Fortunately, this is opt-in on Comcast's routers.

00:29:46.060 --> 00:29:47.740
It doesn't just enable itself by default,

00:29:47.920 --> 00:29:50.580
but it should seriously get you wondering about this technology.

00:29:51.020 --> 00:29:54.640
how creepy it is and the fact that Comcast literally says they can disclose information

00:29:54.960 --> 00:29:58.820
to third parties, which means that they can access your information, including internal

00:29:59.120 --> 00:30:03.740
employees. I made a whole dedicated video on this feature where I dive a lot deeper into how it

00:30:03.900 --> 00:30:09.040
works, the research behind it, what you can do and what third party routers look like and why I

00:30:09.180 --> 00:30:13.040
would consider using those in this kind of situation. So check out that video. I put some

00:30:13.080 --> 00:30:17.520
good time into it and I hope you guys enjoy it. This one was another healthy reminder that I think

00:30:17.540 --> 00:30:22.420
people forget about, right? When you have a relationship with a company, in this case,

00:30:22.640 --> 00:30:26.920
Spirit Airlines, you think that your data is only being shared with Spirit Airlines and you only

00:30:26.920 --> 00:30:32.200
have to trust Spirit Airlines. But what happens when Spirit Airlines goes under? Well, what happens

00:30:32.280 --> 00:30:38.380
is Google buys all that data to feed its AI models. Yes, that is the story here. They halted all their

00:30:38.520 --> 00:30:43.880
operations in May, Spirit Airlines went under, and now Google says we want all that data. So they buy

00:30:43.900 --> 00:30:49.100
it. This is not the first time we saw it. I think another egregious example we saw was with 23andMe.

00:30:49.560 --> 00:30:55.920
23andMe is the DNA company, and they kind of went under because I think the original founder lady

00:30:56.560 --> 00:31:02.500
lost control or it went bankrupt. And then there was multiple people who wanted to buy it,

00:31:02.500 --> 00:31:07.680
and then people wanted to just buy the data, but then she bought it back. It's very confusing what

00:31:07.920 --> 00:31:11.960
happened there. But either way, there was a long stretch of time here where we were doing coverage

00:31:11.980 --> 00:31:18.360
on this where it was like, oh my God, is this DNA data that people gave to 23andMe, which I would

00:31:18.410 --> 00:31:22.780
still say wasn't a good idea, but is that now going to be sold to just random tech companies

00:31:22.890 --> 00:31:28.000
who just want to buy it? That seems kind of wrong. But guys, there's no legal framework for that.

00:31:28.120 --> 00:31:31.340
There's nothing stopping these companies from doing that. In fact, if you read the terms and

00:31:31.600 --> 00:31:36.180
conditions and privacy policies of lots of big tech companies, they specifically say that your

00:31:36.320 --> 00:31:41.940
data might be transferred to another party in the event of bankruptcy or the business going under

00:31:41.960 --> 00:31:46.720
Or an acquisition is another common example where a company gets acquired by another company,

00:31:47.070 --> 00:31:48.400
and now it's that company's data.

00:31:48.490 --> 00:31:49.580
We saw this with Fitbit.

00:31:49.900 --> 00:31:50.260
Same thing.

00:31:50.460 --> 00:31:54.480
Google bought Fitbit and now took Fitbit's data from all the previous customers.

00:31:55.100 --> 00:31:59.560
So again, always keep that in mind, and it's something to flag before you register for any

00:31:59.810 --> 00:31:59.920
service.

00:32:00.360 --> 00:32:03.400
There was a DDoS attack against Threema, the end-to-end encrypted messenger.

00:32:03.490 --> 00:32:05.880
So this is just kind of flagging that.

00:32:05.990 --> 00:32:10.000
If you are a Threema user, that's probably why that was happening if you had any kind

00:32:10.030 --> 00:32:10.520
of downtime.

00:32:11.320 --> 00:32:14.480
Microsoft Copilot revealed secret input that allowed it to be hacked.

00:32:14.540 --> 00:32:17.560
And so if you want to read about this Copilot attack, check it out.

00:32:17.580 --> 00:32:19.980
We're running low on time, so I'm not going to dive too much into that.

00:32:20.100 --> 00:32:22.780
It's just another example of Copilot being a little bit reckless.

00:32:23.040 --> 00:32:28.220
So I would suggest all of you either use Copilot extremely carefully and limit where it's used,

00:32:28.560 --> 00:32:29.660
or just don't use it at all.

00:32:29.840 --> 00:32:30.520
All right, everybody.

00:32:30.680 --> 00:32:36.700
And now we are in the final little bit of the podcast here, which is the open source news.

00:32:36.980 --> 00:32:40.840
So we have Tor Browser, which is the anonymity privacy-focused browser,

00:32:40.900 --> 00:32:43.680
and they released version 15.0.20.

00:32:43.860 --> 00:32:45.440
There's a full changelog if you want to see it.

00:32:45.440 --> 00:32:47.700
It seems like mostly security updates and minor fixes.

00:32:48.300 --> 00:32:49.800
Waterfox is a Firefox fork.

00:32:50.260 --> 00:32:53.100
They hit version 6.7, which they're calling Supernova.

00:32:53.520 --> 00:32:57.380
It moved to ESR 153 and now features native tree tabs,

00:32:57.820 --> 00:33:00.180
the Nova style, which is, I believe, the redesign,

00:33:00.700 --> 00:33:01.920
and 12 color palettes.

00:33:02.000 --> 00:33:04.280
It also boasts a rebuilt ad blocker panel,

00:33:04.580 --> 00:33:06.600
legacy extension support, a new setup flow,

00:33:06.820 --> 00:33:09.560
and update controls that finally deliver on their promises.

00:33:09.900 --> 00:33:10.840
And it looks very pretty.

00:33:10.940 --> 00:33:12.080
The Radblocker looks really nice.

00:33:12.120 --> 00:33:13.620
I got to say, I'm looking at the screenshot here.

00:33:13.620 --> 00:33:17.820
I haven't personally tested it, but it looks very brave inspired in terms of like what it

00:33:18.080 --> 00:33:19.620
visually tells you about each site.

00:33:19.880 --> 00:33:20.980
So super cool stuff.

00:33:21.440 --> 00:33:26.300
Speaking of Firefox and ad blockers, Firefox for iOS now has an experimental native ad

00:33:26.480 --> 00:33:26.780
blocker.

00:33:27.200 --> 00:33:30.980
It's off by default and you can try it out if you use Firefox for mobile.

00:33:31.200 --> 00:33:35.460
And it uses a filter list based on easy list to block a variety of ads.

00:33:35.700 --> 00:33:37.820
Also, speaking of Firefox, they have added Startpage.

00:33:37.960 --> 00:33:43.080
And so Start Page is now another option you can select easily within Firefox.

00:33:43.640 --> 00:33:48.100
Brave version 1.93 has been updated with GPU fingerprinting protections.

00:33:48.440 --> 00:33:53.420
So if you want the latest and greatest on fingerprint protection, Brave now has some extra stuff there.

00:33:54.180 --> 00:33:57.920
This one I actually saw organically before I saw the story, which is quite rare.

00:33:58.600 --> 00:34:02.460
But ProtonMail now has categories inside of the mail experience.

00:34:02.880 --> 00:34:05.460
Personally, for me, it is not my thing.

00:34:06.020 --> 00:34:10.860
I tried using even these categories in Apple Mail back when it came out.

00:34:11.149 --> 00:34:11.919
I can't stand it.

00:34:11.950 --> 00:34:15.960
I'm an inbox zero kind of person, and so I don't want things split into folders.

00:34:16.220 --> 00:34:19.340
And now it feels like I have to check four or five different folders.

00:34:19.659 --> 00:34:20.639
That's the way I see it.

00:34:21.040 --> 00:34:25.120
But if you are not like me, I know this is something a lot of people love.

00:34:25.120 --> 00:34:26.560
I know this is what Gmail does now.

00:34:26.659 --> 00:34:27.700
It's what Apple does now.

00:34:27.750 --> 00:34:31.659
And I think from that perspective, this is crazy important because now you have those

00:34:31.679 --> 00:34:36.600
categories and they default to primary social promotions, newsletters, transactions, and updates.

00:34:36.659 --> 00:34:41.260
And for the record, this is on by default, but it prompts you and I just turned it off right when I

00:34:41.379 --> 00:34:47.040
saw it. This is not my kind of feature, but I am so happy this exists because I know for a lot of

00:34:47.080 --> 00:34:51.879
you out there, you want this feature. Let me know what you think and let me know how you handle your

00:34:52.000 --> 00:34:56.340
email inbox because I'm quite curious. The next article is also from Proton and I just wanted to

00:34:56.520 --> 00:35:00.619
showcase this new feature. And the reason I found out about this was from our signal group. So if

00:35:00.640 --> 00:35:05.080
you're not already supporting us and making this podcast even better as time goes on and making it

00:35:05.340 --> 00:35:08.960
sustainable, check out how to support the podcast down in the description. We have a fun little

00:35:09.280 --> 00:35:13.380
community. And you guys kind of started playing around with that. And then I saw you talk about it.

00:35:13.500 --> 00:35:18.660
But it's called AI Paper Trail. And it's a new, I think it's new feature that Proton released.

00:35:18.720 --> 00:35:25.160
The way it works is you go to your OpenAI or your Clot account, and you pretty much export your data

00:35:25.180 --> 00:35:30.560
from the account and you upload it to Lumo AI. And what it does is it just tells you what does

00:35:30.580 --> 00:35:36.360
your AI know about you. And a lot of people in our signal group were like, holy crap, it like knows

00:35:36.420 --> 00:35:41.220
so much about me. And it's not until it really lists it out in this creepy manner that you really

00:35:41.420 --> 00:35:45.980
understand how it works. Now, of course, Lumo does this in a privacy respecting way. It's from

00:35:46.380 --> 00:35:51.600
Proton. And of course, it's meant to be a tool to kind of like showcase how things aren't as private

00:35:51.620 --> 00:35:52.160
as they can be.

00:35:52.190 --> 00:35:53.760
So maybe you should consider using Lumo.

00:35:53.830 --> 00:35:55.740
So it is partially a marketing tool, of course.

00:35:56.160 --> 00:35:57.520
But I still think it's a useful tool

00:35:57.530 --> 00:35:58.760
to maybe share with friends or family.

00:35:58.980 --> 00:36:01.200
And either way, I plan to run it after I record

00:36:01.290 --> 00:36:02.360
because it looks pretty fascinating.

00:36:02.600 --> 00:36:04.000
Next story comes from Entei,

00:36:04.110 --> 00:36:05.060
who has put out a blog

00:36:05.240 --> 00:36:07.380
talking about their first steps to post-quantum.

00:36:07.520 --> 00:36:09.200
They are end-to-end encrypted photo storage.

00:36:09.370 --> 00:36:11.040
And so they're trying to get ahead of that.

00:36:11.120 --> 00:36:12.360
And again, I think post-quantum

00:36:12.420 --> 00:36:14.880
is something that is nice to have right now in 2026,

00:36:15.200 --> 00:36:17.340
but I'm not looking at this as a must.

00:36:17.520 --> 00:36:18.440
So it's always cool.

00:36:18.600 --> 00:36:20.320
And it kind of shows the bleeding edge nature

00:36:20.980 --> 00:36:22.640
of a lot of the privacy and security organizations

00:36:23.040 --> 00:36:24.980
when they're looking at things like post-quantum already.

00:36:25.240 --> 00:36:27.020
Linux kernel 7.2 was just released

00:36:27.260 --> 00:36:28.600
with a lot of new features.

00:36:29.040 --> 00:36:30.760
So if you are a Linux user, check it out

00:36:30.860 --> 00:36:32.300
if you want to learn more about the kernel update.

00:36:32.780 --> 00:36:34.880
This one I am very excited for,

00:36:35.020 --> 00:36:38.400
but Fairphone has released the Gen 6 Plus,

00:36:39.380 --> 00:36:41.040
which is now available in the US.

00:36:41.560 --> 00:36:43.400
I am very excited about this, guys,

00:36:43.560 --> 00:36:45.260
because I have been wanting the Fairphone

00:36:45.260 --> 00:36:48.400
to be easy to access in the US for a long time now.

00:36:48.900 --> 00:36:50.540
So it's not an entirely new phone,

00:36:50.640 --> 00:36:53.320
but it is an upgraded version of the regular Fairphone 6.

00:36:53.360 --> 00:36:55.460
I was chatting to one of my friends recently about this,

00:36:55.520 --> 00:36:56.780
a European friend of mine,

00:36:57.200 --> 00:36:58.000
and they were like, oh my God,

00:36:58.080 --> 00:37:00.140
it seems like they really tried to make it like an iPhone.

00:37:00.900 --> 00:37:02.300
And it's like, yeah, but that's the thing.

00:37:02.300 --> 00:37:06.160
I think the US is so iPhone heavy that Fairphones,

00:37:06.440 --> 00:37:08.040
again, I'm just guessing here.

00:37:08.200 --> 00:37:09.720
I'm guessing that Fairphone was like,

00:37:09.820 --> 00:37:12.740
hey, so why don't we make a more iPhone-esque version

00:37:12.880 --> 00:37:15.340
of the Fairphone for US users?

00:37:15.900 --> 00:37:18.720
And I think that might be what they're going for.

00:37:18.800 --> 00:37:23.780
And so why I'm excited about this and why I'm sharing it is typically these Fair phones are supported by custom ROMs.

00:37:24.060 --> 00:37:27.520
And so we'll see what the support looks like as we learn more about it.

00:37:27.600 --> 00:37:33.660
But I'm excited to have a repairable device in the U.S. that I don't have to go through tons of hoops to get through.

00:37:33.940 --> 00:37:36.660
SimpleX, the messenger, they've previously sponsored this podcast.

00:37:37.700 --> 00:37:40.040
They are doing an equity crowdfunding launch.

00:37:40.360 --> 00:37:44.120
So you can invest in this on WeFunder and they are looking to raise money.

00:37:45.200 --> 00:37:46.780
I don't think I've ever seen this before.

00:37:46.980 --> 00:37:48.220
This is a first on the podcast.

00:37:48.340 --> 00:37:50.080
There aren't many firsts on this podcast.

00:37:50.410 --> 00:37:55.940
After years of doing this, episode 271, I can't tell you many situations where I'm like,

00:37:56.090 --> 00:37:58.140
okay, yeah, this is a first.

00:37:58.920 --> 00:38:07.740
But I have not seen a crowdfunding investment opportunity yet for a privacy-based tool that

00:38:07.860 --> 00:38:10.920
is commonly recommended throughout privacy circles.

00:38:11.520 --> 00:38:14.060
So if you're interested in this kind of thing, check it out.

00:38:14.680 --> 00:38:21.420
I am going to stay clear of any kind of like financial advice or anything like that,

00:38:21.860 --> 00:38:23.240
just because I feel like it muddies the waters.

00:38:23.520 --> 00:38:29.640
And the last story of the week, sadly, isn't the most positive, but Pine64, which is, you

00:38:29.640 --> 00:38:32.400
know, they make a lot of Linux hardware, specifically their phones.

00:38:32.800 --> 00:38:36.260
The Pine phones are quite popular, but they also make the Pine tab, the Pine Watch.

00:38:36.380 --> 00:38:40.580
They said that they have no plans to continue producing more Linux devices in the near future.

00:38:41.040 --> 00:38:46.780
Even more concerning, the company says the situation may not be reconsidered until after the middle of 2027.

00:38:47.240 --> 00:38:52.680
They're saying this is because of the DRAM and the eMMC shortage, aka the memory slash RAM shortage.

00:38:53.220 --> 00:38:57.060
And there isn't any more plans to continue producing more Linux devices in the near future.

00:38:57.200 --> 00:39:05.020
This is really sad because this is one of the few organizations that's really, I think, pushing the limits of what you can do in terms of mobile devices and Linux right now.

00:39:05.480 --> 00:39:13.960
And even though I don't think they're quite ready for mainstream use yet, this has been, I think, kind of setting the standard for what developers can do.

00:39:14.500 --> 00:39:18.320
And it's just creating and trying to create the ecosystem around Linux for mobile.

00:39:18.330 --> 00:39:19.700
I really hope that we figure this out.

00:39:19.730 --> 00:39:22.940
I hope that they continue when they get things going.

00:39:23.280 --> 00:39:26.160
So very sad news, but I'm still going to try to be optimistic.

00:39:26.290 --> 00:39:29.400
And if you can do something to help support them, please look into them.

00:39:29.400 --> 00:39:30.300
They do a lot of good work.

00:39:30.740 --> 00:39:33.420
And that everybody is going to conclude the surveillance report.

00:39:33.500 --> 00:39:37.220
If this analysis helped you reclaim control, become a Techlorian down in the description.

00:39:37.660 --> 00:39:39.340
It's a huge help for us back here.

00:39:39.340 --> 00:39:40.320
We could really use it.

00:39:40.660 --> 00:39:42.500
We're still trying to develop kind of our perks.

00:39:42.540 --> 00:39:47.480
And so if you have things that you wish that we did that could make it more enticing, please let me know.

00:39:48.060 --> 00:39:49.840
Right now you get access to our signal group.

00:39:49.920 --> 00:39:51.600
You get shown in the outro of our videos.

00:39:52.440 --> 00:39:54.560
And also you get access to my private RSS feed.

00:39:54.600 --> 00:40:00.740
So if you don't want to wait every single week to get access to the news, I personally curate the news throughout the week.

00:40:00.740 --> 00:40:02.620
And I flag things pretty much on a daily basis.

00:40:03.060 --> 00:40:08.260
So you could just follow that RSS feed instead of having to follow hundreds of sources like I have to do.

00:40:08.440 --> 00:40:14.580
If you don't want to support us, you can also leave a rating on Apple Podcasts or Spotify or leave a like on YouTube.

00:40:14.720 --> 00:40:18.540
You can also share a specific story or just share the episode with any friends or family.

00:40:18.920 --> 00:40:22.740
And of course, don't forget that there's a written version of this if you just want the newsletter variant.

00:40:22.900 --> 00:40:25.480
And you can access that on our website on techlore.tech.

00:40:26.040 --> 00:40:28.980
Thank you all for watching, and I'll see you next week for the next Surveillance Report.

