WEBVTT
Kind: captions
Language: en

00:00:02.280 --> 00:00:14.300
This week's Surveillance Report covers the pileup of identity verification breaches from the last couple weeks, including a couple new ones, the global age verification push forcing even more ID collection.

00:00:14.380 --> 00:00:16.780
I'm sure those two stories aren't related at all.

00:00:17.440 --> 00:00:25.620
OpenAI's rogue AI agents, and the more that we learn about that, the more interesting it gets, and lots of the usual data breaches, threats, and open source updates.

00:00:25.740 --> 00:00:39.400
Welcome, everybody, to the Techlore Surveillance Report, your essential weekly tech news, delivering deep analysis on the latest threats to your security, privacy, and digital freedom, and of course, empowering you to reclaim control and defend your rights along the way.

00:00:39.700 --> 00:00:43.360
Before we get into that highlight story, um, thank you everyone for the missed week.

00:00:43.440 --> 00:00:47.540
Uh, we just had a lot of stuff going on with Go Incognito, but it's pretty close to being ready to launch.

00:00:47.660 --> 00:00:50.840
We're just a few weeks away, which I'm really excited about, so keep an eye out for that.

00:00:51.160 --> 00:00:56.180
And also, I'll be at the next cloud conference if anyone else is going, and it happens to be in Berlin, so come say hi.

00:00:56.220 --> 00:01:00.640
I'll have these fun stickers here, uh, these like got privacy stickers.

00:01:00.720 --> 00:01:01.660
I think they look pretty cool.

00:01:01.860 --> 00:01:04.019
So if you see me, just, uh, ask for one and I'll give one to you.

00:01:04.060 --> 00:01:06.340
So we're gonna kick off this story to talk about Revolut.

00:01:06.460 --> 00:01:08.860
So for those who don't know, Revolut's a financial company.

00:01:09.060 --> 00:01:10.480
There's a couple interesting layers to this.

00:01:10.520 --> 00:01:22.400
There's the actual breach itself, which exposed data which include people's identity, their contact details, their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents, including passports and driver's licenses.

00:01:22.620 --> 00:01:34.400
The second thing here that I really wanted to outline is how this happened, because this wasn't just your typical data breach where they didn't patch some vulnerability or they were missing some kind of security protocol.

00:01:34.780 --> 00:01:49.140
No, this was something that they just actively handed over because this came from a fraudulent request, like an email request from a government that was illegitimate because they spoofed the agency's email domain.

00:01:49.360 --> 00:01:50.640
I think there's a lot of lessons here.

00:01:51.300 --> 00:02:00.340
It's tough because it's, it's really easy to take a valid domain as a, you know, something is safe, but there are ways to impersonate domains.

00:02:00.380 --> 00:02:08.940
So this is a situation where technology can always help if people are using DKIM across the board, which if you have your own email set up, um, you probably know what that is.

00:02:09.060 --> 00:02:09.820
Otherwise, look it up.

00:02:09.860 --> 00:02:11.060
It's called D-K-I-M.

00:02:11.120 --> 00:02:16.480
It's something I recommend everybody sets up, and they set up some protocols as well involving this because it keeps everybody safer.

00:02:16.660 --> 00:02:27.320
What we do actually internally is when we get an email and it doesn't pass DKIM or something gets flagged, even if it looks legit and it comes from the right domain, I actually flag with that team.

00:02:27.340 --> 00:02:32.360
And this has happened with some projects behind the scenes who reach out to us for, like, sponsorships or something like that.

00:02:32.680 --> 00:02:41.980
They don't actually have their DKIM set up properly, which, A, yes, is kind of funny if when you have a privacy and security company that doesn't do it properly, but everyone can make mistakes, especially when they're early on.

00:02:42.540 --> 00:02:49.200
Um, but also it typically leads to them fixing it, and either way, um, it at least makes them have to verify they say who they are.

00:02:49.440 --> 00:02:57.900
I think the more systemic kind of takeaway that especially I saw online a lot is why is it possible for a company to just say, "Okay, yeah," like, "We get all these government requests here.

00:02:57.960 --> 00:03:07.140
Just take this as well." So I think this is a good reminder of the kind of personal information that companies who are run by employees who are human, who make mistakes, have about you.

00:03:07.420 --> 00:03:12.540
There's this really big disconnect that people have across the board, not even with just identity verification.

00:03:12.600 --> 00:03:17.920
I think people think, "When I'm using Facebook, Facebook has my data." Yes, Facebook has your data.

00:03:17.960 --> 00:03:22.420
It's on Facebook servers, but it's also the thousands of employees that have access to your data.

00:03:22.840 --> 00:03:29.400
It's Mark Zuckerberg, like the creepiest person in the world, being able to log in and literally see what he wants about different people.

00:03:29.440 --> 00:03:32.380
Like, I think people also lose the human element to this.

00:03:32.440 --> 00:03:47.820
We saw kind of the most creepy version of this, which was kind of those stories that started to come out that Amazon, I think even Apple and some of these other big tech companies, were using third-party contractors to analyze your voice that you were using with voice assistance, and this wasn't really disclosed whatsoever.

00:03:48.020 --> 00:03:58.780
I know it's hard to avoid financial institutions, so this is a tough one to say, "Just avoid the service outright." No matter what, try to give up as little real information as you can when it comes to these situations, right?

00:03:58.820 --> 00:04:01.480
Like, use something like a passport instead of a driver's license.

00:04:01.540 --> 00:04:05.380
It typically has a little bit less sensitive information on there, like your home address.

00:04:05.640 --> 00:04:14.040
I would recommend everybody has a private mailbox, and ideally you have some way that you can sign up with things with alias emails, alias phone numbers, et cetera.

00:04:14.100 --> 00:04:15.260
So do your best with this.

00:04:15.480 --> 00:04:16.500
Freeze your credit.

00:04:16.560 --> 00:04:23.920
And if you have a higher threat model or a public presence, you should already have some kind of address situation so that your actual home address is kept safe.

00:04:24.080 --> 00:04:33.500
This is more of a confirmation of one that we already talked about in a recent Surveillance Report, which is that IDscan has confirmed the data breach the one that everyone knew already happened.

00:04:33.900 --> 00:04:38.200
Um, but they did confirm that they had more than 150 million driver's licenses stolen.

00:04:38.340 --> 00:04:40.680
That confirmation took a little longer than I would like.

00:04:40.920 --> 00:04:48.688
If you missed this one, there was pretty much a mysterious website that was publishing people's IDs, and they- Saw about 150 million of them on there.

00:04:48.708 --> 00:04:52.508
It's like a dark website where you just type in someone's name, and then their ID comes up.

00:04:52.708 --> 00:05:04.348
People were speculating it came from this company called IDScan, which is used when you rent, uh, vehicles at Hertz, and also when you go to a cannabis dispensary apparently is ano- another place where they're commonly used.

00:05:04.508 --> 00:05:16.248
Now, this investigation is still ongoing, but this is like the absolute peak example of why this random verification with random third parties with random security practices is a bad idea.

00:05:16.788 --> 00:05:17.448
I just...

00:05:17.708 --> 00:05:19.188
This makes my blood boil, guys.

00:05:19.248 --> 00:05:26.928
It's like you are handling people's most sensitive information, and to just violate people's trust like that, I think, just speaks volumes.

00:05:26.968 --> 00:05:38.128
Like, if identification companies who are handling the most sensitive data about you aren't taking security and privacy seriously, what does that tell you about people who are handling things that aren't as sensitive?

00:05:38.168 --> 00:05:42.868
Like, this is kind of the state of the internet summed up for me and why it's so frustrating for me.

00:05:42.908 --> 00:05:53.728
And then the last story here when it comes to, like, the hidden cost of handing over your ID, which is how I'm framing this overall head- highlight story, uh, is that there was also a Florida motor vehicle database that was leaked.

00:05:53.988 --> 00:06:03.348
This came from the ShinyHunters hacking group, and it's nice because I guess two of these shortened the data breaches section this week, 'cause normally that's where the- they're in, actually.

00:06:03.748 --> 00:06:09.668
Um, but this is from the Florida Motor Vehicle Agency, FLHSMV, uh, which is a crazy acronym.

00:06:09.708 --> 00:06:15.968
But they have confirmed a data breach in a statement last week after the hackers obtained a police officer's credentials that were stored on a personal device.

00:06:16.128 --> 00:06:20.448
That's another important lesson for both enterprise listeners and also just regular people.

00:06:20.488 --> 00:06:22.448
Don't mix work and personal when you can.

00:06:22.488 --> 00:06:24.508
This stuff can really be exploited.

00:06:24.688 --> 00:06:32.608
Now, these hackers stole hundreds of thousands of certificates of vehicle ownership records, which contained vehicle owners' names and addresses of buyers and sellers.

00:06:32.948 --> 00:06:44.328
The records also contained vehicle identification numbers, and there were a smaller number of files which did include government-issued documents, Social Security numbers, and immigration papers, but no driver's licenses.

00:06:44.388 --> 00:06:46.608
But this is still a pretty sensitive breach.

00:06:46.688 --> 00:06:52.468
I think it's really sad because it puts a lot more on you all as individuals to have to take initiative on this.

00:06:52.628 --> 00:07:01.368
So, I mean, it really does in many ways expose the limitations of a lot of privacy advice that even I'm gonna give you guys because at the end of the day, most of you probably need to have bank accounts.

00:07:01.388 --> 00:07:12.408
And if your bank account was Revolut and you were targeted in this, unless you really, like, went through the preventative steps, which I do recommend you do, for the record, you still could have had a lot of sensitive information exposed about you.

00:07:12.528 --> 00:07:19.888
So for me, this is kind of a humbling story of, like, no matter how well we do, there are some things that are probably going to be unavoidable in our lives.

00:07:20.248 --> 00:07:30.508
And so for me, it's a reminder of, like, yes, let's do everything we can ourselves, but we also need to be putting, you know, at least more energy into demanding better from politicians, from companies, et cetera.

00:07:30.568 --> 00:07:33.288
So that's my weird takeaway from this.

00:07:33.828 --> 00:07:35.408
Uh, but I'd love to hear what you guys think.

00:07:35.468 --> 00:07:37.208
These stories are never fun to cover.

00:07:43.048 --> 00:07:53.068
While we see these data breaches of identity verification systems, we also see governments demanding more verification through all these proposals that they're putting out.

00:07:53.108 --> 00:07:58.028
So the EU is set to propose a ban on social media and AI cha- chats for under 15s.

00:07:58.108 --> 00:08:12.628
Children from 15 onwards can set up their own accounts under the proposal, while children 13 to 14 can ask parents to open introductory accounts for social media, and for accounts for children between 3 and 12 will be fully controlled by parents and will only be for child-friendly services with strict safety standards.

00:08:12.788 --> 00:08:23.588
And also, the thing that is a little bit more concerning to me, and this is from the EDRI, who's a very trustworthy, um, EU organization, they actually put forward why the EU age verification tool does not solve privacy concerns.

00:08:23.808 --> 00:08:32.207
EDRI criticizes the eID Wallet, which is proposed as being very privacy respecting, but they cover all the technical limitations with it.

00:08:32.408 --> 00:08:37.248
They also say that they suggest using zero knowledge proofs, but they don't make it mandatory.

00:08:37.648 --> 00:08:45.788
So my understanding is that there is kind of the centralized open source app, um, that can be used, but every country can choose to use it or make their own.

00:08:45.828 --> 00:08:52.748
They can base it off their code, and there's few mandatory things to actually guarantee the kind of safety in every single identity verification system.

00:08:52.948 --> 00:08:58.128
And even in those scenarios with zero knowledge proofs, the EDRI still says it's not good enough.

00:08:58.188 --> 00:09:00.208
Unlinkability can hardly be guaranteed.

00:09:00.448 --> 00:09:03.528
They talk about the shortcomings because these are not perfect technologies.

00:09:03.788 --> 00:09:07.427
We've had security and privacy scientists and researchers that have publicly commented about this.

00:09:07.788 --> 00:09:09.928
I'm not gonna get into it because it's just not the main story here.

00:09:10.128 --> 00:09:22.388
But I think if you're in the EU especially, it's important for you to read this article so that you can start developing some of your language and understanding around the tools that are being proposed to verify people, and they did a wonderful, wonderful job making this a very short...

00:09:22.448 --> 00:09:28.628
I mean, if you're watching the video, this is overall a very short article, but it's extremely dense and contains all the information you need.

00:09:28.668 --> 00:09:30.528
It's just what you need and nothing more.

00:09:30.748 --> 00:09:41.648
Now, here in California, where I'm based out of, we are no more innocent than these other places because California governor has signed law protecting kids from risks of social media and AI chatbots.

00:09:41.908 --> 00:09:45.868
Now, this has some good and some bad, and I think the EFF does a really good job summarizing this.

00:09:46.428 --> 00:09:50.388
But there's three unique bills here that they really harp on.

00:09:50.468 --> 00:09:54.088
One of them is AB 1709, which is the bad one that we don't like.

00:09:54.188 --> 00:09:58.008
It's a functional ban on young people under 16 using social media in California.

00:09:58.388 --> 00:10:07.608
Now, two of them the EFF did support, which is AB 2071 and AB 2298, which require that children learn critical digital literacy and cybersecurity topics.

00:10:07.948 --> 00:10:15.488
They are an affirmative and constitutional way for the state to address valid concerns about young people's internet use without violating the First Amendment rights.

00:10:15.548 --> 00:10:16.348
I think this is great.

00:10:16.548 --> 00:10:18.108
Like, education's a great approach.

00:10:18.388 --> 00:10:21.868
Microsoft has formally rolled out a new age awareness API.

00:10:21.988 --> 00:10:24.188
I don't know if it's tied be...

00:10:24.228 --> 00:10:32.608
And I, I can't, I can't directly link it to that desktop operating system age verification that is being proposed and passed already in California.

00:10:32.948 --> 00:10:37.328
Um, or it could just be something they're doing broadly because they see the pattern happening all around the world.

00:10:37.688 --> 00:10:52.468
But they have this new age range thing which, again, aligns very much with that, uh, proposal, but this is called GetUserAgeRangeAsync to retrieve age groups, while GetAgeVerificationStatusAsync can tell an app whether a user's age has already been ver- verified.

00:10:53.108 --> 00:10:56.828
So yeah, pretty much you're getting age verification on Microsoft Windows.

00:10:57.068 --> 00:11:01.508
This is no different from what Apple's required to do on macOS and iOS now due to these laws.

00:11:01.568 --> 00:11:03.108
So this is what happens.

00:11:03.148 --> 00:11:04.028
You know, people...

00:11:04.548 --> 00:11:17.292
This is- Kind of a s- a side rant, but I, I get so many comments, uh, from, from people who say, like, "Oh, my gosh, why do you talk so much about, like, you know, reaching out to politicians and, like, standing up for things on the legal side of things?

00:11:17.772 --> 00:11:20.972
It doesn't matter anyway." Like, there's so much doomerism, but this is why.

00:11:21.032 --> 00:11:27.032
You flip it on its head, and you actually see what states can mandate, what countries can mandate, what regions can mandate.

00:11:27.452 --> 00:11:28.252
This is what we get.

00:11:28.312 --> 00:11:30.032
We get a controlled internet.

00:11:30.092 --> 00:11:39.332
So just like laws can be used to make all of our technology even more privacy-invasive, we can have laws go the other direction, too, where they can actually help protect your privacy.

00:11:39.612 --> 00:11:45.072
I don't think anybody thinks that laws, regulation, et cetera, can actually fix problems by themselves.

00:11:45.132 --> 00:11:48.832
I don't think that's at all what the claim is, but it is a very important part of the fight.

00:11:49.172 --> 00:11:52.492
And I think the more that we appreciate that, the better off we're gonna be in the long run.

00:11:52.692 --> 00:11:59.192
So the Calyx Institute, the digital rights organization, has a little triangle which I really like, and the triangle has three things for digital rights.

00:11:59.472 --> 00:12:01.372
It's tools, so the actual tools we use.

00:12:01.412 --> 00:12:02.592
It's using ProtonMail.

00:12:02.652 --> 00:12:03.892
It's using a nice browser.

00:12:03.912 --> 00:12:05.132
It's using a nice search engine.

00:12:05.392 --> 00:12:10.992
We have education, which hopefully is why you're here, to learn and understand what's going on and stay on top of it.

00:12:11.332 --> 00:12:13.232
And then the third thing they talk about is legal.

00:12:13.372 --> 00:12:24.852
Those three things are all very important, and there's a really tight relationship between them, so don't forget that, uh, when you're keeping up with the news because there's normally some kind of angle across all three in every single story I cover.

00:12:25.092 --> 00:12:29.352
Speaking of tools, I wanted to mention the sponsor of this podcast, Easy Optouts.

00:12:29.412 --> 00:12:35.072
Now, this isn't just your regular sponsor who just pays good money and ends up, um, on a podcast.

00:12:35.132 --> 00:12:37.652
Like, we have had Easy Optouts on here for many years.

00:12:37.712 --> 00:12:39.172
They're just run by a couple guys.

00:12:39.392 --> 00:12:43.272
They've been shown by Consumer Reports to be one of the most effective, tied with Optery.

00:12:43.552 --> 00:12:46.992
But unlike Optery, their plans are $20 a year.

00:12:47.052 --> 00:12:49.512
There's no, like, tiered subscription model.

00:12:49.812 --> 00:12:53.512
It's meant to be extremely accessible to people, which is how I think it should be.

00:12:53.552 --> 00:12:59.952
It's already asking a lot for someone to have to pay to be removed from these sites that they never opted into using in the first place.

00:13:00.012 --> 00:13:04.852
But Easy Optouts will opt you out of all of these random people-searching websites on your behalf.

00:13:05.112 --> 00:13:11.772
You can upload as much or as little information as you want to make it easier for them to find your information, and they work all around the US.

00:13:12.032 --> 00:13:15.032
They have business plans, so you can also get some discounts at scale.

00:13:15.312 --> 00:13:19.212
Go visit Easy Optouts and get started for $20 a year down in the description.

00:13:19.312 --> 00:13:21.652
Again, I don't think they can make this a better value.

00:13:21.852 --> 00:13:23.992
They are one of the most effective services out there.

00:13:24.112 --> 00:13:29.772
Thank you, Easy Optouts, as always, for sponsoring us, and now back to OpenAI's rogue agents.

00:13:35.752 --> 00:13:38.312
This last week, I, I don't know what happened.

00:13:38.472 --> 00:13:47.612
I don't know if it's because I skipped a week at Surveillance Report, but I have found some kind of, like, newfound rage at these AI companies, 'cause I really think this is getting to a peak.

00:13:47.672 --> 00:13:54.392
So I, I think it makes sense why I'm starting to feel this rage, but I- I'm gonna hold it back until after I do coverage for the stories.

00:13:54.792 --> 00:14:18.852
So this came out a, a f- a couple weeks ago now, but "OpenAI agents hijacked a German website in a previously undisclosed AI breakout this spring", and "OpenAI agents repurposed the site into a message board, sharing tactics to cheat on some tasks, bypassing OpenAI's restrictions and masking their behavior." There's another Reuters article here that the rogue agents have been used at least 10 more times for unauthorized communications.

00:14:18.992 --> 00:14:25.572
And this all, of course, came from that original Hugging Face breach, which if you remember my take, is still pretty relevant today.

00:14:25.652 --> 00:14:31.792
So, you know, they hacked Hugging Face, and the way that it was presented then was that these models just broke out.

00:14:31.852 --> 00:14:33.532
They started acting autonomously.

00:14:33.572 --> 00:14:35.972
They destroyed, you know, u- Hugging Face.

00:14:36.672 --> 00:14:36.812
It...

00:14:36.852 --> 00:14:39.352
When we learn more about the breach, it wasn't like that at all.

00:14:39.452 --> 00:14:46.292
It really did follow an overall path that a human would have followed too, just far more, you know, quick, autonomously, yes.

00:14:46.332 --> 00:14:54.552
But people really kind of overlooked the responsibility that OpenAI had in that breach, and that really is what is just pissing me off so much.

00:14:54.592 --> 00:15:07.072
Like, the more I'm seeing these stories, the more I'm seeing people just treat the LLMs as if they are their own thing and not a tool that is managed by a company who has protocols in place to be able to control this.

00:15:07.352 --> 00:15:22.812
And when you look at these kind of responses, "OpenAI," I'm reading this from the article, "did not directly address questions about how many different sites its agents used to communicate or say why it kept the activity under wraps for months." Again, months with an M, not, not a, a Y, not yonths, months.

00:15:23.271 --> 00:15:37.392
"In a statement, it said it was undertaking a broader review of agent activity and had so far not identified other activity matching the severity or scale of Hugging Face." I, I think what's really been making me so mad the last week is these a- AI companies have proposed this vision, right?

00:15:37.432 --> 00:15:42.812
Like, we look at Elon Musk, Sam Altman, and Dario, these three big key AI players.

00:15:43.252 --> 00:15:50.392
They are spouting every flipping day, and there was also that viral tweet recently, that, you know, "Yeah, AI's just gonna kill humanity.

00:15:50.632 --> 00:15:53.252
You know, like, we, we think it's gonna do that," blah, blah, blah.

00:15:53.612 --> 00:16:08.192
"Meanwhile, we're building those tools that we think are gonna kill humanity," which doesn't make any sense, "and by the way, we're just totally chill with them doing this, and we're not gonna actually apply proper protocols." The amount of incentives that these people have to push this narrative is too high for me.

00:16:08.532 --> 00:16:11.752
When they push this narrative, it puts everybody in a fear-based state.

00:16:12.012 --> 00:16:21.512
It also, funny enough, puts them in control of, "Well, we have the technology, and so we need to decide what to do with it," which is what we're seeing now.

00:16:21.532 --> 00:16:28.092
We're starting to see talks about halting AI development and all these different things right now, and who's leading all those discussions?

00:16:28.472 --> 00:16:31.092
The AI companies who caused all the problems to get here.

00:16:31.572 --> 00:16:33.572
Why does that make any sense to anybody?

00:16:33.732 --> 00:16:35.732
They have done the same thing for years.

00:16:35.832 --> 00:16:41.412
Many of these people literally are, like, narcissistic assholes that just have very low bars for ethics.

00:16:41.732 --> 00:16:43.812
They run these companies that are move fast and break things.

00:16:44.032 --> 00:16:45.612
They're fine to exploit you for years.

00:16:45.652 --> 00:16:47.432
They're fine to leave your passwords in plain text.

00:16:47.472 --> 00:16:53.892
They're fine to leave all their customers/you, at users, exposed, and they don't care about your safety.

00:16:53.932 --> 00:16:55.032
They don't care about your privacy.

00:16:55.072 --> 00:16:57.172
They don't care about your rights online.

00:16:57.352 --> 00:17:00.752
Facebook was literally a core part of a genocide in Myanmar.

00:17:00.812 --> 00:17:02.032
That is something that happened.

00:17:02.092 --> 00:17:08.955
We also see how they're fine exploiting children even though they know- Full well that what they're doing harms teens' mental health.

00:17:09.016 --> 00:17:12.376
Like, these are well-established things that these companies are fine doing.

00:17:12.756 --> 00:17:27.896
So when we actually come together as a society, when politicians say, "Hey, let's ask the AI companies run by these people," who I think are kind of crazy, "Let's ask them what they think we need to do to rein in this technology," that is the wrong discussion to be having.

00:17:28.076 --> 00:17:32.236
And then you might ask, "Okay, so who should be running that?" And that is the problem.

00:17:32.296 --> 00:17:35.356
We don't have anyone right now to hold these people accountable.

00:17:35.456 --> 00:17:40.476
It's very scary because a lot of times these companies are writing the laws that your politicians are signing.

00:17:40.616 --> 00:17:41.876
So I don't know where my rant's going.

00:17:41.976 --> 00:17:43.416
I feel like I got really rambly there.

00:17:43.576 --> 00:17:45.716
But I, I, I've just been really frustrated by this.

00:17:45.816 --> 00:17:47.736
I would love to hear your guys' thoughts in the comments.

00:17:53.716 --> 00:17:53.856
All right.

00:17:53.916 --> 00:17:55.156
Now we have the Defense Bulletin.

00:17:55.216 --> 00:17:56.136
Again, three sections.

00:17:56.156 --> 00:18:01.056
We have the data breaches, we have the threats, so you know what to watch out for, and we also have the open source updates.

00:18:01.536 --> 00:18:08.116
Um, and I'm gonna be a bit quicker this week because I'm looking here and it- there's probably at least, like, 30 to 50 stories across these three sections.

00:18:08.396 --> 00:18:12.516
So Adapt Health confirmed a 4.1 million data breach in a July cyber attack.

00:18:12.676 --> 00:18:15.756
This is your reminder that breaches happen typically retroactively.

00:18:15.776 --> 00:18:19.856
It's quite rare for a breach to happen, and then you just find out about it right when it happens.

00:18:20.196 --> 00:18:23.496
So if you have any kind of relationship with this company, check out the show notes.

00:18:23.956 --> 00:18:30.676
Um, this one was a Berlin data leak that ended up on the dark web, and it really calls into question Germany's IT infrastructure.

00:18:30.716 --> 00:18:34.816
And this is from TUTA, and they talk about what happened and kind of their take about it.

00:18:34.876 --> 00:18:38.776
So especially if you live in Berlin and you wanna learn more about this, I would check this out.

00:18:38.816 --> 00:18:46.976
Trezor, the cryptocurrency hardware wallet, had a data breach that impacted about 81,000 customers, which is, I guess, currently what the tally is.

00:18:47.016 --> 00:18:50.116
It includes full names, shipping addresses, email addresses, and phone numbers.

00:18:50.396 --> 00:18:58.676
I'm really not a fan of these data breaches because it exposes potential customers who are holding potentially a lot of money, and it puts a huge target on their back.

00:18:58.716 --> 00:19:02.356
And so if you purchased a Trezor, you should look to see if you are impacted by this.

00:19:02.696 --> 00:19:05.716
And if you were, I would just take appropriate precautions from there.

00:19:05.876 --> 00:19:14.655
On this note, just a heads-up, Trezor has warned people of phishing attacks probably as a result of that breach now that they have people's emails, so just be extra cautious of those kind of emails.

00:19:14.976 --> 00:19:19.576
Surfshark VPN has said that hackers breached their internal testing proxy servers.

00:19:19.656 --> 00:19:27.156
Um, they did say it didn't affect customers and it didn't extend to other parts of the infrastructure, but it exposed service con- uh, configurations and build-related credentials.

00:19:27.416 --> 00:19:32.096
So it seems to be a pretty small-scale breach, but if you wanna learn more about what happened there, again, there's always the show notes.

00:19:32.296 --> 00:19:40.036
By the way, on the show notes, uh, like, about every week I get a person saying, "You know, you don't put the links in the show notes." Uh, the way it works, there's one link in the description.

00:19:40.076 --> 00:19:41.256
It's, it's linked.

00:19:41.296 --> 00:19:51.356
It says, you know, "Click here for show notes." You click that link, and guys, remember, Surveillance Support is a newsletter and a video and an audio podcast, so it's kind of hard to do everything for everybody perfectly.

00:19:51.416 --> 00:19:59.256
But if you click that link, the very top of the link, it says, "Click here for all sources." Then you just click that, and it'll take you to a dropdown that has all the sources there.

00:19:59.376 --> 00:20:10.156
The reason it's set up this way is because that page that you click on is also sent to people as a free newsletter each week, and so that's why the sources are on the bottom of that page, so I don't just spam people with sources at the very top.

00:20:10.196 --> 00:20:17.916
And that's also a way for me to say that you can subscribe to our newsletter and you get, like, a five-min-minute written version of this podcast if you prefer that kind of thing.

00:20:18.176 --> 00:20:24.196
Now, a French hospital was fined €500,000 after a breach exposed data of over 700,000 people.

00:20:24.256 --> 00:20:27.916
So this is probably for a breach that I covered someday in the past, I'm assuming.

00:20:28.336 --> 00:20:31.296
Um, but this was just more of a, like, consequence to that breach.

00:20:31.636 --> 00:20:35.736
Now, there's something called Mathspace which disclosed a data breach affecting over a million people.

00:20:35.796 --> 00:20:40.116
This is an online math learning platform, so if you use this, please, again, check out the show notes.

00:20:40.436 --> 00:20:45.736
We also have Veradigm, I think that's how you say that, that warns of patient data breach after a ransomware gang claims attack.

00:20:45.776 --> 00:20:50.416
This is a health tech company, and it's a third-party vendor that exposed all that information.

00:20:50.556 --> 00:20:52.096
All right, now we're gonna get into the threats.

00:20:52.136 --> 00:20:56.176
The first one is that Google says some Pixel phone owners were hacked in zero-day attacks.

00:20:56.376 --> 00:21:00.916
This is from a bug in the Pixel phone's modem, which lets the device connect to the internet.

00:21:00.956 --> 00:21:06.716
So exploiting the bug could allow an attacker to gain access beyond a sandboxed wall of the modem and into the broader s- phone data.

00:21:06.896 --> 00:21:13.996
The concerning thing is I still haven't seen any kind of information about this, like how many people it impacted, who was behind it.

00:21:14.316 --> 00:21:20.296
As Zach Whitaker says here in this article, this is typically used by spyware makers, and so that's also where my mind would've gone.

00:21:20.316 --> 00:21:23.355
But again, there's no proof of that yet, and there's no proof of the scale.

00:21:23.516 --> 00:21:26.876
Now, it has been patched, so this is no longer something to be concerned about.

00:21:26.915 --> 00:21:31.696
But I would have loved to get more information, and I hope that Google at some point does come forward with that info.

00:21:31.736 --> 00:21:33.996
This was a really big week in terms of Chrome vulnerabilities.

00:21:34.036 --> 00:21:36.576
They had 230 vulnerabilities on Tuesday.

00:21:36.776 --> 00:21:38.136
So you should always be updating your browsers.

00:21:38.176 --> 00:21:44.496
They're one of your most sensitive pieces of software, so make sure if this is your reminder, update your browser right now if you haven't already.

00:21:44.896 --> 00:21:49.876
Kind of on this note, Chrome is now shipping updates every two weeks as AI changes the security landscape.

00:21:49.896 --> 00:21:52.096
That's how TechCrunch, uh, kind of frames it.

00:21:52.156 --> 00:21:58.796
Uh, Mozilla, Microsoft, and Brave have also said that they're, uh, adopting a faster two-week, uh, schedule following Chrome's lead as well.

00:21:58.856 --> 00:22:08.336
So this is about to be, uh, pretty much a universal browser thing at this point, except for Safari, who has their own little update, uh, system that doesn't align with anybody else's way.

00:22:08.416 --> 00:22:08.636
Uh, Mr.

00:22:08.916 --> 00:22:10.696
Nightmare Eclipse is still here, man.

00:22:10.816 --> 00:22:12.636
I- every time I cover a story, I'm like, "You know what?

00:22:12.816 --> 00:22:16.316
I'm seeing less of these Nightmare Eclipse stories." But he comes back.

00:22:16.756 --> 00:22:23.536
So Nightmare Eclipse is a disgruntled security researcher, um, who has released a CrowdStrike Falcon zero-day exploit named FalconFlank.

00:22:23.576 --> 00:22:35.616
And he also released privilege escalation zero-days for Kaspersky antivirus, for Endpoint and Gen Digital Avast antivirus, as well as a denial of service zero-day for Nvidia that will crash the system, and so they're, they're on a roll, man.

00:22:35.656 --> 00:22:40.576
I don't know how they're finding all these different zero-days, but Nightmare Eclipse is, is really...

00:22:41.116 --> 00:22:42.236
Yeah, they're, they're doing it to them.

00:22:42.556 --> 00:22:47.496
One of those, if you wanna learn more specifically, is called ShieldCrash, which impacts Microsoft Defender.

00:22:47.676 --> 00:22:49.636
So again, they're still going after Microsoft.

00:22:50.216 --> 00:22:50.336
I...

00:22:51.416 --> 00:22:54.056
Man, I'd, I'd love to, like, see an interview with this person somehow.

00:22:54.116 --> 00:22:57.176
I'd love to hear, like, how they're doing it, and also just...

00:22:57.596 --> 00:22:58.876
Yeah, I just wanna learn more, man.

00:22:58.916 --> 00:23:06.036
This one is something that I've been having to say a lot in content, which is that we just can't trust mobile VPNs as much, unfortunately.

00:23:06.076 --> 00:23:11.796
And iOS and Apple have actually taken a lot of flak for this the last several weeks, but Mullvad just came forward with this.

00:23:12.316 --> 00:23:14.896
Another way to leak traffic on Android has been discovered.

00:23:15.646 --> 00:23:19.286
And this is even if you use that setting, which is block connections without VPN.

00:23:19.446 --> 00:23:25.886
So the leak involves telling Android to create a keep-alive UDP connection that is, uh, offloaded to the hardware Wi-Fi or cellular chip.

00:23:26.046 --> 00:23:32.286
A malicious app can misuse that to send UDP packets on port 4500 to any server on the internet.

00:23:32.346 --> 00:23:40.326
So this does require you to have a malicious app to misuse this, but the fact that that, you know, capability exists is obviously something to close up.

00:23:40.486 --> 00:23:46.046
So the real conclusion, and Mullvad says this, use trusted apps on your device, and hopefully we'll see patches coming soon.

00:23:46.146 --> 00:23:49.306
Graphene has said they are working on a fix, but it doesn't look like it's live yet.

00:23:49.386 --> 00:23:51.486
So right now, just install trusted apps.

00:23:51.686 --> 00:23:56.086
This one, if you are on YouTube, have-- You've probably seen this more than enough times.

00:23:56.226 --> 00:24:01.546
The coverage for this has been crazy, and I, I missed the wrong week 'cause this would've been a good highlight story for me.

00:24:01.846 --> 00:24:06.166
But LG TV was shown scanning your LAN for third-party phones and other devices.

00:24:06.306 --> 00:24:11.886
And this really came from GamersNexus on YouTube, who worked with Level 1 Techs, which is a tech-focused YouTube channel.

00:24:12.326 --> 00:24:16.206
And they analyzed, uh, LG TV's tracking capabilities.

00:24:16.266 --> 00:24:22.426
They shared packet captures that pointed to the TVs, um, and it pretty much, like, literally tries to find everything.

00:24:22.486 --> 00:24:27.626
The concept and the concern here is it collects this data even if the TV is offline.

00:24:27.666 --> 00:24:45.386
So if you have an LG TV, it's just constantly, constantly, constantly collecting all of this data, and the big fear is that it either connects to some kind of, uh, public Wi-Fi network, or if you ever connect it online someday, it actually will upload all that data retroactively because it's not actually that hard to store that data for a long term.

00:24:45.566 --> 00:24:53.126
I actually think one of the most timeless videos I made was my video on, like, why I hate smart TVs, and so I'll leave that linked as well if you wanna see that.

00:24:53.546 --> 00:24:59.886
Um, but it, it just, it covers all of these concerns I have with smart TVs from, like, five years ago probably.

00:25:00.086 --> 00:25:05.506
And it's crazy to see, like, real information now really expose how, uh, kind of exploitive this can be.

00:25:05.986 --> 00:25:07.686
Now, LG does downplay this.

00:25:07.746 --> 00:25:09.746
They say, "Oh, all smart TVs have this.

00:25:09.786 --> 00:25:16.986
This is native functionality." My whole counterpoint to all of this is why not make it easy for people to say, "No, I don't want this.

00:25:17.146 --> 00:25:18.406
Just don't collect that data"?

00:25:18.806 --> 00:25:22.206
If you're not doing that, I'm not gonna trust really much of what you have to say.

00:25:22.306 --> 00:25:32.146
It's not that hard to say, "Hey, yeah, we're gonna collect all this invasive crap about you, but we're gonna tell you, A, and B, uh, here's how you opt out." Not a hard thing to request.

00:25:32.206 --> 00:25:40.066
That should be a bare minimum standard, and in fact, I would say there should probably be some kind of laws or legal requirements for companies to have to do that.

00:25:40.386 --> 00:25:41.806
That is not a thing in the US.

00:25:42.006 --> 00:25:48.586
Moving on, we have 36,000 exposed Plex servers vulnerable to recent flaws, so if you have a Plex server, make sure to check out that story.

00:25:48.906 --> 00:25:58.426
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking, so if you happen to have one of these or you're just curious to learn about this, 'cause this is an interesting one, I would check out the show notes.

00:25:58.746 --> 00:26:06.626
There was a cPanel backup plugin called Acronis, Acronis, which, uh, yeah, it, it has an exploitable flaw.

00:26:06.706 --> 00:26:09.226
So make sure to check that out if you use that plugin.

00:26:09.506 --> 00:26:13.206
And on that topic of plugins, we have WordPress plugin issues.

00:26:13.286 --> 00:26:15.006
One of them is the WooCommerce plugin.

00:26:15.066 --> 00:26:17.746
The other one is Admin Menu Editor Pro.

00:26:18.246 --> 00:26:19.586
That, that is the name of the plugin.

00:26:19.646 --> 00:26:23.466
So if you're a WordPress admin, make sure to look into those stories and get your stuff patched.

00:26:23.746 --> 00:26:25.446
All right, and now the open source section.

00:26:25.486 --> 00:26:27.726
Tor Browser hit version 15.0.22.

00:26:28.126 --> 00:26:29.206
Your reminder to be updated.

00:26:29.266 --> 00:26:31.386
It seems like it mostly includes security updates.

00:26:31.746 --> 00:26:38.586
Tails, the anonymous operating system, hit version 7.13, which updates brows- uh, the Tor Browser to, um, the newest version.

00:26:38.646 --> 00:26:39.726
It updates the Tor client.

00:26:39.766 --> 00:26:41.366
It simplifies the shutdown procedure.

00:26:41.846 --> 00:26:44.166
Um, and there was also a few other changes there.

00:26:44.466 --> 00:26:52.326
Now, there was a security update from CalyxOS, 7.2.5.20, uh, which includes some new stuff, uh, but it seems like it's mostly security there.

00:26:52.626 --> 00:27:00.106
Uh, Graphene OS is pretty exciting, has planned to overhaul the bundled, uh, Android open source apps, including messaging with RCS support.

00:27:00.146 --> 00:27:06.086
The reason why this is big is that we finally have seen end-to-end encryption rolled out in the RCS protocol.

00:27:06.146 --> 00:27:12.846
So this is meant to be a better version of SMS, which means anybody with any cell phone can communicate with each other over their cell company.

00:27:13.226 --> 00:27:20.146
But up until now, RCS, uh, especially with end-to-end encryption, was only found in Google Messages, uh, for the most part.

00:27:20.166 --> 00:27:30.986
And so what I'm really excited to see is some kind of RCS first party with end-to-end encryption, and if Graphene can pull it off, that would be awesome, and hopefully they keep it open source so other people can also copy that too.

00:27:31.506 --> 00:27:40.786
Uh, Addy.io, which is a really nice email aliasing service, they're fully open source, and they let you keep your email safe from countless websites, now blocks email tracking pixels by default.

00:27:40.906 --> 00:27:43.746
So if you use Addy.io, that's a nice little change there.

00:27:44.006 --> 00:27:50.766
They've also partnered with something called Leave Me Alone, uh, which is a privacy-first tool to unsubscribe from newsletters and manage your inbox.

00:27:50.866 --> 00:27:54.486
I have never heard of this service, uh, so I'm not, like, formally condoning it.

00:27:54.586 --> 00:27:59.926
But if you are an Addy.io, uh, customer, you get some kind of discounts here, uh, with Leave Me Alone as well.

00:28:00.466 --> 00:28:02.466
Now, image hit version 3.2.

00:28:02.606 --> 00:28:08.690
This is an open source photo, um- Tool, service, uh, from Fudo that is typically self-hosted.

00:28:09.110 --> 00:28:13.870
Um, it debuts a new search API, cluster groups, workflows expansion, and much more.

00:28:13.950 --> 00:28:18.050
So if you use Image, uh, check out the f- the show notes for the full changelog.

00:28:18.270 --> 00:28:23.370
This one really flew under my radar, but Control D is, uh, there's actually a couple things here.

00:28:23.430 --> 00:28:24.510
So the first one's just the story.

00:28:24.570 --> 00:28:26.530
Control D is now available through Tailscale.

00:28:26.870 --> 00:28:30.970
Control D is a DNS service from the team from Win- Windscribe, actually.

00:28:31.130 --> 00:28:33.810
It's pretty much NextDNS if you guys have used them.

00:28:33.850 --> 00:28:35.930
It's a way to control your whole DNS.

00:28:35.990 --> 00:28:37.590
You choose what filters you wanna use.

00:28:37.630 --> 00:28:40.070
And now they're supported in Tailscale, which is a VPN.

00:28:40.130 --> 00:28:42.890
Not like a traditional privacy VPN necessarily.

00:28:43.370 --> 00:28:46.130
Um, Tailscale lets you connect to, like, remote devices.

00:28:46.170 --> 00:28:50.010
So, like, I have my NAS behind me, and the way I connect to my NAS remotely is through Tailscale.

00:28:50.410 --> 00:29:01.670
Now, Tailscale has done a partnership with Mullvad, so as part of that same VPN connection, you get routed through a Mullvad exit server, so you get Mullvad's protections, and you can connect to your NAS, which is why I use Tailscale.

00:29:01.910 --> 00:29:10.470
But now you can also use Control D as the DNS provider by just pasting your ID from Control D directly in there, and then you'll start using, uh, Control D automatically.

00:29:10.510 --> 00:29:11.150
It's pretty cool.

00:29:11.190 --> 00:29:17.650
You could have always probably set Control D manually, uh, in this, but this is just a nice partnership that makes it a little bit simpler.

00:29:17.730 --> 00:29:26.630
Now, the second thing I wanted to mention here, this isn't new whatsoever, but it's new to my brain, uh, because Mullvad actually shut down their encrypted DNS resolver service.

00:29:26.690 --> 00:29:34.050
Well, they haven't shut it down yet, but they're going to, and this is, comes with out-of-the-box filtering that's maintained for you, and it's something I've been using for a long time.

00:29:34.190 --> 00:29:36.710
And I just wanted to flag because I covered this news last week.

00:29:36.750 --> 00:29:40.550
It was really sad, and a lot of you expressed, um, that you are also sad about this.

00:29:40.910 --> 00:29:46.370
Um, Control D actually has the same exact thing, and this is the perfect swap-in, and it's what I started using.

00:29:46.470 --> 00:29:50.470
So you can see here if you're watching the video, they have a malware protection.

00:29:50.510 --> 00:29:51.870
That's just malware filtering.

00:29:51.910 --> 00:29:53.510
They have ads and tracking filtering.

00:29:53.550 --> 00:29:54.510
They have social filtering.

00:29:54.550 --> 00:29:56.510
They have family-friendly filtering, and they have advanced.

00:29:56.850 --> 00:29:58.070
This is completely free.

00:29:58.110 --> 00:30:03.950
You just click Select, and it tells you, um, if you wanna use DoQ, if you wanna use HTTPS 3.

00:30:04.370 --> 00:30:06.310
Like, you can use whatever you want for free.

00:30:06.330 --> 00:30:08.230
You don't even need an account to use those.

00:30:08.430 --> 00:30:16.630
You don't get the customization, um, but I think this is the best kind of swap-in, uh, for Mullvad's DNS service that was recently announced to be shut down soon.

00:30:16.950 --> 00:30:20.510
So just a heads-up, uh, because I thought this really solves at least my concern.

00:30:20.550 --> 00:30:30.950
This is a quick PSA that Switzerland's federal government is testing open source alternatives to Microsoft on 3,000 computers, so I hope that's successful for them, and it's exciting to see countries really test that kind of stuff out.

00:30:31.430 --> 00:30:37.850
Android is rolling out passkey transfers between password managers, which is native to, uh, the operating system, which is pretty exciting.

00:30:38.270 --> 00:30:45.250
We also have Homebrew 7.0, which is a package manager for macOS, which arrives with faster installs, hardened security, and a native macOS app.

00:30:45.310 --> 00:30:49.930
The native app looks really clean just based on the screenshot, and it's nice to see security get better.

00:30:50.170 --> 00:30:53.030
Ente Photos is open source end-to-end encrypted photos.

00:30:53.090 --> 00:30:57.370
It is typically hosted, but they also have a one-command self-hosting option as well.

00:30:57.430 --> 00:31:01.810
But their machine learning is now faster, so if you use that, that is good.

00:31:02.110 --> 00:31:03.050
Uh, pretty cool.

00:31:03.390 --> 00:31:09.050
They also have introduced library sharing, so you can share a whole library with a partner, which is pretty awesome.

00:31:09.070 --> 00:31:18.130
And now they also have a service that I covered, uh, I think a couple months ago now called Locker, which is a separate app, uh, from Ente as well, which can now scan paper documents.

00:31:18.170 --> 00:31:20.790
So you can keep documents in there, uh, based on a scan.

00:31:20.850 --> 00:31:29.770
Waterfox, the open source Firefox fork, hit version 6.7.2, which is more improvements to their recent big update, including improvements to tree tabs and the vertical sidebars.

00:31:29.830 --> 00:31:34.210
So I'd say this is just overall polishing up their recent pretty huge update for them.

00:31:34.290 --> 00:31:35.350
I'm excited for Waterfox.

00:31:35.390 --> 00:31:36.450
They've had some really good stuff.

00:31:36.510 --> 00:31:42.770
And also they released an Android version, 1.2.7, which has tab groups, homepage improvements, and privacy controls as well.

00:31:42.930 --> 00:31:48.210
Now, open source X front ends Nitter and XCancel resume their services after seeking legal advice.

00:31:48.270 --> 00:31:57.670
So X, formerly known as Twitter, uh, sent a cease and desist to these open source front ends, uh, to allow you to access fricking posts without needing an account.

00:31:57.750 --> 00:32:00.090
It's like, oh my gosh, I'm a social media company.

00:32:00.130 --> 00:32:11.590
I'm gonna make it harder for people to access content by account gatekeeping, account keeping literally as much as I can, and then we're gonna get open source front ends that will make that information publicly accessible anyway.

00:32:11.870 --> 00:32:13.430
Oh, now I'm gonna send them a cease and desist.

00:32:13.590 --> 00:32:15.310
Yes, I'm the good guy in this equation.

00:32:15.350 --> 00:32:18.210
They haven't really commented on much, but feel free to keep using them.

00:32:18.250 --> 00:32:25.430
This came from Brave, but Brave did say that their desktop outperforms other browsers in both speed and performance, and they put all the numbers together.

00:32:25.790 --> 00:32:36.030
They found they use on average 44% less CPU, 10% less energy, 28% less memory, pages load 20% faster, and also faster transfers for inbound and outbound data.

00:32:36.070 --> 00:32:37.350
They go through the benchmark.

00:32:37.610 --> 00:32:40.190
They went through how they do this and resource usage.

00:32:40.530 --> 00:32:50.250
So i-i-it's pretty compelling stuff, and I think it really speaks to really the footprint of tracking online 'cause that's really the main thing that Brave is probably shutting off here.

00:32:50.270 --> 00:32:51.310
They're shutting off ads.

00:32:51.350 --> 00:32:52.510
They're shutting off trackers.

00:32:52.950 --> 00:32:57.770
So yeah, pretty cool stuff and one more reason to use any kind of browser that's gonna help you there.

00:32:58.010 --> 00:32:58.870
I love stuff like this.

00:32:58.970 --> 00:32:59.750
I love benchmarks.

00:32:59.830 --> 00:33:02.370
I love data, so it's pretty cool to see it actually measured.

00:33:02.590 --> 00:33:07.310
This is a heads-up that Surfshark has announced their acquisition of data removal service Optury.

00:33:07.570 --> 00:33:09.890
So Surfshark is actually owned by NordVPN.

00:33:09.930 --> 00:33:13.070
A lot of people don't know this, but NordVPN acquired Surfshark.

00:33:13.330 --> 00:33:21.410
Surfshark has this service called Incogni, which is a data removal service, and now Surfshark has acquired Optury, which is a data removal service.

00:33:21.810 --> 00:33:24.230
So, you know, a lot of messiness there.

00:33:24.610 --> 00:33:28.450
I see this as kind of the same consolidation we've seen in the VPN industry.

00:33:28.510 --> 00:33:34.350
If you've kind of missed this, most VPNs you see out there are owned by just a few of the same companies.

00:33:34.810 --> 00:33:39.050
Y- we're starting to see more of that consolidation now, it seems like, in the data removal space.

00:33:39.410 --> 00:33:40.650
So yeah.

00:33:41.110 --> 00:33:50.130
Shameless plug, I mean, I don't have to promote our sponsor outside of the sponsor segment, but seriously, easy opt-outs, uh, independent, just a couple guys, like very humble dudes.

00:33:50.250 --> 00:33:54.930
It's $20 a year, um, and I, I don't see them doing anything like this anytime soon.

00:33:55.090 --> 00:33:59.910
Debian hit version 13.7, which updates Trixie with security and bug fixes.

00:33:59.950 --> 00:34:02.270
And if you wanna see the full changelog, check out the show notes.

00:34:02.630 --> 00:34:09.230
Plasma 6.8 KDE, um, Beta has added CUP backups and expands Union theming, so that's just a heads-up there.

00:34:09.350 --> 00:34:10.929
CUP is a backup scheduler module.

00:34:11.409 --> 00:34:13.150
Um, so yeah, uh, it should be exciting.

00:34:13.530 --> 00:34:21.449
Uh, and also we have Linux Mint who's unveiled a new e-book reader, a calendar app, and a revamped document library, so some updates there for any of you who use Linux Mint.

00:34:21.870 --> 00:34:26.210
And Asahi Linux has added expert mode support for N3 Macs.

00:34:26.530 --> 00:34:35.110
This release includes webcams, microphones, Wi-Fi, Bluetooth, USB 3 at up to 10 gigabits per second, and hardware-accelerated video decoding with AV1 support.

00:34:35.710 --> 00:34:36.989
I love Asahi Linux.

00:34:37.030 --> 00:34:38.210
It is such a cool project.

00:34:38.290 --> 00:34:41.810
It allows you to install Linux on any kind of Apple Silicon devices.

00:34:41.850 --> 00:34:47.770
At least, I think it sounds like M1 through M3, um, are supported And it just keeps getting better guys.

00:34:47.810 --> 00:34:50.929
Like I was testing it out on my last MacBook Pro and I really liked it.

00:34:51.010 --> 00:34:54.850
I actually think that the MacBook Pro is like the best Linux machine out there.

00:34:54.889 --> 00:34:57.210
Maybe even the MacBook Air or the Pro, like either one.

00:34:57.670 --> 00:35:02.170
Uh, it's really nice hardware when you combine it with something like Asahi Linux, it was just so much fun to run.

00:35:02.529 --> 00:35:05.430
And it made me realize how behind Linux is in the ARM world.

00:35:05.670 --> 00:35:09.950
So, uh, kind of, uh, pros and cons, but overall I'm just hyped to see this.

00:35:10.270 --> 00:35:11.050
All right, everybody.

00:35:11.090 --> 00:35:15.130
That was a bit of a longer week, but I wanna thank you for getting through the two weeks of news.

00:35:15.250 --> 00:35:20.330
If this analysis helped you out, seriously, like the way it's possible is through so much of your guys' community support.

00:35:20.390 --> 00:35:24.370
So I have a private Signal group that I've set up just for all of you who wanna join.

00:35:24.610 --> 00:35:25.690
You can become a Techlorian.

00:35:25.770 --> 00:35:26.950
It's $5 a month.

00:35:27.250 --> 00:35:29.790
You join that Signal group, you get access to other people there.

00:35:30.050 --> 00:35:34.270
You also get access to my private RSS feed so you can keep up with these news as they go live.

00:35:34.550 --> 00:35:36.270
And also you get to support this content.

00:35:36.310 --> 00:35:38.450
And there's higher tiers as well for Techlorians.

00:35:38.490 --> 00:35:44.130
Like I have a monthly meeting one where you get to chat with me, and it really helps us out, and it's even cheaper if you go annual too.

00:35:44.290 --> 00:35:54.090
If you can't or don't want to support via the paid avenues, um, you can always support for free by just giving this a like on YouTube, sharing it around with people you know, and leaving a rating.

00:35:54.170 --> 00:35:59.790
I do see your ratings, and they also really help, um, on both Apple, Spotify, really any podcasting platform.

00:35:59.850 --> 00:36:02.650
So if you're able to leave a rating, please, please, please do.

00:36:03.070 --> 00:36:03.890
Thank you all for listening.

00:36:04.010 --> 00:36:08.370
I'll see you in the next episode of Surveillance Report, and potentially in Berlin if any of you are gonna be there.

00:36:08.710 --> 00:36:10.430
And I'll see you next week.

