❌

Reading view

There are new articles available, click to refresh the page.

A Data Breach At Shipping Giant Ceva Logistics Is Rippling Across Banks, Retailers, Steam Gamers, and Beyond

An anonymous reader quotes a report from TechCrunch: Ceva Logistics, one of the world's largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent, the company told TechCrunch. Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses. Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world. [...] The hack at Ceva also resulted in a data breach, affecting a large amount of personal information belonging to retail customers that Ceva relies on for delivering goods to people's home addresses. Several companies reported that hackers took their customers' names, home addresses, phone numbers, and email addresses used to place their orders from Ceva's systems. Dutch online retail giant Bol said on its website that hackers gained access to systems of its warehousing partner, Ceva, and warned that their customers' data may have been taken. Bol also said that it expects delays and some customer orders to be canceled as a result of the incident. De Bijenkorf, another Dutch luxury retailer, similarly confirmed order delays following the theft of its customers' data, per local media. Football club Ajax, banking giant ING, and eyeglass maker Ace & Tate also reported that customers' shipping information was affected. Video game giant Valve told customers that it learned on August 7 that data was taken from Ceva's systems, and alerted customers who recently bought its Steam hardware that they had personal information taken in the incident. Valve said in its note to customers, posted to Reddit, that Ceva stores their shipping and delivery information for 90 days following their order. So far, Ceva says the agency has received data breach reports from 10 organizations in relation to the incident.

Read more of this story at Slashdot.

How Accurate Are Flock's AI-Powered License-Reading Cameras?

Futurism reports: 404 Media revealed that a July 10 audit by the Los Angeles Police Department Office of the Inspector General caught the department's ALPR cameras generating 161 false stolen-vehicle alerts in just two months β€” each one ending with officers pulling over an innocent driver. Factoring in 337 alerts which "resulted in the recovery of stolen vehicles," the LAPD's cameras carry an error rate of 32.3 percent, effectively giving officers a one-in-three chance at pulling an innocent person over. "The biggest issue remains this national database at the FBI called NCIC," Flock's CEO Garrett Langley recently told The Drive, complaining about "how archaic its structure is." Flock CEO: There's no feedback loop mechanisms; it's really just a static comma-separated file. We've tried to build around it. We have this concept called "suppression." A local agency β€” let's take Atlanta, where I live β€” might see that there's a stolen plate out of California, but it's already been resolved because it's a rental car or a dealer car. They can, in Flock, suppress that: "Never alert us on that for the next year." That's to get around the fact that they can't force another agency to remove it from NCIC. Ideally, the way it would work is if enough agencies β€” let's call it one, two, or three β€” flag a tag as no longer valid or a bad entry, it should just get removed. Or at least it should get pushed more aggressively by the FBI... I'm hopeful that they'll see there's an opportunity to make something like NCIC, which is an important tool not just for companies like Flock, but for police departments to work together, start to make some enhancements to modernize what's a central part of our policing system. Later in the interview he says "It's less than one in a million alerts that an officer says, 'I'm not sure if that's right.' Less than one in a million." A recent report from Business Insider shares a worst-case scenario. In the summer of 2024 a Sacramento police officer said Flock's cameras had sent six false alerts for the same vehicle, wrongly saying it had been stolen or used in a felony crime in the nearby suburb of Roseville: Roseville police could see that Flock's software kept confusing the "9" on the man's license plate for an "8." The car owner said he would take off his license plate cover. Soon after, it happened again. It's "easier at this point we have it memorized," a dispatch supervisor in Roseville wrote in an email to a colleague. Flock says that in optimal conditions, its cameras accurately read more than 96% of license plate characters. Hundreds of pages of records from the Roseville Police Department show a different picture. In 2023 and 2024, Flock sent 1,427 alerts to Roseville police, flagging vehicles as stolen or used in a felony after they passed one of the city's Flock cameras. An analysis by the police department found that in 71% of those alerts, Flock's machine-learning software incorrectly read the license plates... The cameras regularly missed vehicles, captured blurry images, misread license plate characters and states, and sent delayed alerts to police about vehicles possibly connected to crimes, the records show... A factor that contributed to the misread problems in Roseville was the "particularly unique deployment" that the city requested, a Flock spokeswoman said. Roseville said it has its cameras configured so that they capture only the backs of vehicles, a setup intended to avoid capturing personally identifiable information like faces. Roseville's setup included older hardware and placement of cameras higher and further from vehicles than the company typically recommends, Flock added... In Toledo, Ohio, driver Brandon Upchurch was mauled by a police dog after a Flock camera misread the "7" on his license plate as a "2." As a result of his injuries, he said, he lost his job and was evicted from his home. He settled a lawsuit against the city and police officer for $35,000. None of the incorrect Flock alerts in Roseville resulted in a traffic stop or arrest, a department spokesman said. Roseville requires police officers to verify that a license plate is stolen or have independent reasonable suspicion of a crime before making a traffic stop... Flock said Roseville's camera performance has significantly improved, which the police department disputed... Flock's cameras also missed vehicles altogether... At one point, Flock's product director for machine learning suggested that officers ask drivers to remove license plate frames that made it "very difficult for the machine vision to tell it is actually a 'E' and not an 'F.'" Roseville told Flock at the time that it wouldn't do so, according to the department spokesman. Flock in 2024 shared an analysis with Roseville's police department, outlining reasons for the misreads. Vehicles far from a camera were sometimes blurry. Plates were cut off by trees or license plate frames. And Flock's software confused similar characters, mistaking an "N" for a "V", or a "1" for a "4...." Roseville isn't the first organization to flag inaccuracies in Flock's technology. In 2021, the research firm IPVM independently tested Flock's license plate readers, concluding that Flock misidentified the state in about one of 10 reads, and that the system regularly misclassified vehicles' type and make. IPVM said that Flock subsequently blocked it from purchasing its cameras for testing. Thanks to long-time Slashdot reader Cognitive Dissident for sharing the article.

Read more of this story at Slashdot.

Privacy Backlash Explodes Against Meta's Smart Glasses

With nearly 70% of the market, "Meta wants its smart glasses to be a big hit," writes the Los Angeles Times. But after some users found ways to disable the light that warns people they're being filmed, "the high-tech specs have also turned into a liability, as some are calling the gadget 'pervert glasses...'" Some people are using the glasses β€” which look like a pair of regular spectacles β€” to record people without their knowledge and publish the videos on social media. The users secretly videotape and share what happens when they try to pick up women. Now, a growing number of people are worried they could be covertly recorded at the gym or even during sex. The backlash has prompted Meta to update its glasses to address privacy concerns, and some places have banned them, adding to the angst surrounding technology that's rapidly evolving... Concern about the glasses has exploded as more videos of interactions with people who don't know they're being recorded go viral on social media. On Instagram, some videos depict people getting approached in malls and grocery stores and on college campuses and sidewalks. While the videos are portrayed as jokes, the people filmed don't appear to know they're being recorded and sometimes seem uncomfortable, telling the strangers to leave them alone or stop harassing them. The outcry has spread beyond social media, with comedian Jimmy Kimmel calling the Meta devices "pervert glasses" on national television and singer Lorde telling concertgoers that smart glasses are "not sexy..." Instagram, which is owned by Meta, has been disabling accounts and taking down some of these pickup or prank videos for violating the platform's rules against harassment and bullying... Businesses are making their own calls about smart glasses. The 5 Point Cafe in Seattle, which banned Google Glass in the past, has banned Meta glasses from its diner and dive bar. "Leave your Meta-SpyBan Display at home, they are officially Ray-Ban-ned from all of our restaurants. We serve privacy, not side-eye surveillance," a 2025 Instagram post from the business states. An Android app that warns people if they're being recorded has roughly 110,000 downloads in the last six months, according to the article. The app's creator says it's a "social problem" that "we don't value privacy, that we feel entitled to use others for our entertainment or our private gain, and technology amplifies that." The American Civil Liberties Union and more than 70 organizations even sent a letter urging Meta to promise they'd leave facial recognition features out of their smart glasses, according to the article. But a Meta spokesperson said "no final decision has been made."

Read more of this story at Slashdot.

Flock Camera Vandalism Continues Around America, While 100 Communities Reject ALPRs

Dozens of Flock cameras have been vandalized around Dallas Texas in the last six months, reports a local news station. In Utah, ABC News reports, a county sheriff's office even said Wednesday a Flock camera was even vandalized within days of its being installed. And in the Minnesota city of Winona, "Every Flock license plate reader camera operated by the Winona Police Department has been sawed off and stolen in what investigators believe was a coordinated theft," according to local media: All eight cameras were taken August 1, according to the Winona Police Department. A patrol officer first noticed the cameras had not sent any alerts in 24 hours. When officers checked the locations, they found the cameras had been cut from their poles and taken. The poles were left behind. Two additional Flock cameras on the Mississippi River Bridge, owned by Buffalo County, were also stolen in the same manner... The thefts are part of a broader national trend. Flock cameras have been vandalized and cut down in communities across the country. When someone in Florida filmed a damaged Flock camera lying in the grass in Florida, their footage attracted 980,000 views on social media, according to a local news report, with the uploader saying "Most of the people that are commenting are against Flock cameras." But that report adds it's one of at least five cameras recently damaged just in Florida: - In another incident, investigators "found the black camera and its pole lying on the ground." - Two days later, sheriff's deputies found a camera destroyed "with pieces scattered on the ground. Deputies reported the damage appeared to have been caused by a blunt object." - On July 31, "Police said two camera poles had been intentionally cut in half, causing an estimated $10,000 in damage to the system." In West Virginia 20-year-old Wesley Jackson has been arrested for allegedly vandalizing Flock cameras, with another 20-year-old (a university student) now arrested for being his accomplice, according to a local news report. Ironically, Jackson's arrest was made possible partly by information from... automated license plate readers. But the Washington Post notes there's now a flood of Facebook commenters jokingly offering to provide a fake alibi: "Couldn't have been him β€” we were out counting blades of grass," said one of the 29,000 commenters on a post about the arrest from the local news station WDTV. Others attested that the man, Wesley Jackson, had been helping them "replace the roof on a homeless shelter," "playing halo 2," "changing the tires" on their car or giving their "doggie a treat" at the time the cameras were destroyed. Meanwhile, the anti-surveillance group DeFlock reports 100 communities have now rejected automated license plate readers. Wednesday an Arizona county sheriff explained to his local Board of Supervisors why he will not renew his office's contract with Flock when it expires next month. Local Arizona media reports: "We have a camera system that can do facial recognition technology and can start building a data set on what our citizens are doing on a day-to-day basis," Teeple told supervisors. "That, in my training and experience, is a huge Fourth Amendment violation." Recently an Arizona man even told his city council he'd be launching AI-powered satellites to monitor "where government officials go, where they stop, who they meet with, and when they return home," reports 404 Media: It would be no different than how the city monitors its citizens using Flock cameras, he said... He said he'd already started compiling profiles on their vehicles, spouses vehicles, children's vehicles, and planned to combine that data with Bluetooth signals, advertising IDs, and commercial data sources, "so our authorized users can replay the movements of every government official and their immediate family," he said. Local businesses would be invited to join the network, to "protect" officials while they shop, eat at restaurants, and move around the city. And CNET reports "a quiet battle is happening across the US" between "towns working to adopt Flock Safety systems and those trying to ban them entirely." From major cities like Los Angeles canceling its Flock contract to towns wrapping Flock AI cams in plastic bags because Flock won't take them down, it's a wild time for surveillance and questions about government accountability.

Read more of this story at Slashdot.

Woman Pulled From Car at Gunpoint By Police After Mistaken Flock Alert - Twice

The police surrounded her car Thursday, "drew their guns, and told her to come out with her hands up," reports a local news station. The police thought they were pulling over a murder suspect, but "It turns out it was a mistake by another department with the Flock license plate reader technology." The black woman says she'd wanted to call her mother, "but I'm like, if I make a sudden move, it's going to be over. It's going to end my life." And amazingly, the same thing happened Monday, according to the local news report. "Milwaukee police pulled her over with guns drawn. She says officers never explained why, towed her car, and let her go." She now describes herself as "traumatized," recalling her second detention by police on Thursday. "After they put us in cuffs, they walked us to the car. I'm not knowing what's going on. I'm scared. All you see is people in their cars recording." She now says she's scared to drive her car, and so is her daughter. "Because she doesn't know if the police are going to pull us over and do it again..." "I haven't been to sleep since this happened. Every time I close my eyes, all I can see is guns." She wants an apology, since the local police would only say it wasn't their fault, it was the fault of the Milwaukee police department that failed to remove the alert from Flock's system. "Milwaukee police emphasized this was not a Flock camera issue, it was a data entry mistake," according to the local news report. The woman's response? "Y'all failed. Y'all failed the system. Y'all failed me. Y'all failed everybody."

Read more of this story at Slashdot.

Framework Notifies 'All Customers' of a Data Breach Via Compromised Metabase BI Service

"Framework has been sending out email notifications to customers alerting of a limited data breach in which customer information was accessed through a Metabase BI service zero-day exploit," writes Slashdot reader DuoDreamer. Data includes customer names, email addresses, phone numbers, and physical addresses. "Framework is investigating whether or not this included Framework for Business customers as well." TechCrunch reports: Framework's spokesperson Eric Schumacher told TechCrunch that the breach affected "all customers," but declined to specify a specific number. Framework computers are relatively niche products, but some estimates say the company sold hundreds of thousands of devices. Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers' databases stored on Metabase's cloud servers. In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework's cloud instance. The computer maker said it investigated the incident and found that hackers had stolen its customers' personal data, but did not include their payment information.

Read more of this story at Slashdot.

'Tower Dump' Warrants Ruled Unconstitutional

alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations. A "tower dump" involves cellphone companies providing law enforcement with access to the time and location data of all mobile devices connected to specific cell towers during a designated time window. Law enforcement had sought approval for several of these search warrants as part of criminal investigations into gang-related activity in the Jackson, Miss., area last year, arguing the data could help identify all those potentially involved, particularly in incidents with unknown suspects. A magistrate judge denied the applications, holding that "tower dumps" are impermissible general warrants. The district judge agreed. The order repeatedly referenced the Supreme Court's recent decision in Chatrie v United States, in which the majority held that geofence warrants require constitutional privacy protections. "With this information, the Government asserts that it will be able to identify all potential suspects," Judge Carlton Reeves wrote in a 30-page order (PDF). "Even so, law enforcement would also have access to the cellular records of countless individuals, the vast majority of whom were merely passing by a location at the 'wrong' time." "That is an unreasonable search under the Fourth Amendment," the judge concluded.

Read more of this story at Slashdot.

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay. [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal. "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was Γ’dire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Read more of this story at Slashdot.

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals. A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector. [...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Read more of this story at Slashdot.

Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool

A woman found her police officer ex-boyfriend had used Flock's camera system 600 times to look up the location of her and her daughter, reports the Washington Post (Alternate URL here). (She found out through Have I Been Flocked, described as "a website that aggregates police search logs made available through public records.") But it turns out dozens more police officers have also misused Flock... Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found. In 26 of these cases, police investigators and prosecutors said the officers used the technology to spy on their wives, their girlfriends, their exes, their exes' new partners or women they wanted to meet. In other cases, police or prosecutors have not specified the alleged surveillance targets. Flock's system was used in 46 of the cases analyzed by The Post, while the other cases involved competing products... After The Post relayed its findings to Flock, the company said in a statement it "will soon be announcing better filters and tools to stop abuse before it happens...." In April, the company rolled out a new voluntary "audit assistance" feature, which agencies can choose to enable, that automatically scans officers' searches for suspicious activity, such as queries repeatedly targeting the same vehicle or run by officers off the clock. In an interview with The Post, Flock chief executive Garrett Langley said misuse of its systems is inevitable and that the company is focused on providing tools to catch perpetrators after the fact... "We're not going to change humans, and humans make bad decisions," Langley said. "What we can do is make sure that they know if you use this tool, you will be held accountable...." Through automated license-plate reader systems, or ALPRs, officers could trace the rhythms and travels of their subjects' daily lives, leading in some instances to violent confrontations, moments of psychological manipulation, and threats of coercion and control, the analysis found. - In Wisconsin, a police officer allegedly used Flock to check whether his ex-girlfriend had gone to an abortion clinic, according to a police affidavit for a case set for trial this month. - In Kansas, a police chief who tracked his ex through Flock sneaked up on her while she was intimate with another man, a state police certification body alleged, leading to his firing. - In Florida, a deputy speeding to stop a young actress he'd added to a watch list for a license-plate tool called Guardian nearly caused a head-on crash, according to a police report and video from his dashboard camera. The deputy was arrested in March, and his attorney declined to comment. - And in California, prosecutors said a former deputy, Alexander Vanny, used Flock as part of a months-long campaign of "stalking" and "humiliating" his former fiancΓ©e that also involved following her around town and installing a hidden camera in her roommate's bathroom, according to a sentencing brief... While some of the searches resulted in officers' firings, prosecutions and prison sentences, police departments in other cases allowed officers to continue using the systems even after receiving warnings that they were being misused... An array of privacy advocates has argued that Flock could deter bad actors by making simple changes to its product, such as requiring officers to label every search with a criminal case number. Some policing experts also warned that agencies' inconsistencies in developing and enforcing standard procedures for license-plate readers could lead to further misconduct. With no federal laws governing use and only a patchwork of state laws, many of the country's roughly 18,000 police agencies are left to decide their rules on their own... Langley, Flock's chief, has dismissed pushes by activists for the company to further limit how officers use its product. "No one elected me the police chief of America," he told Forbes last year, adding, "I don't think it's our job to police the police." The Post also got this quote from an officer was fired and sentenced to probation after pleading no contest to charges of computer-system misuse, stalking and battery. "Pretty much everybody uses that computer system" improperly in the department, he said, and "they don't audit it [nearly] as much as they should." Flock told The Post it now has over 120,000 cameras in more than 6,000 communities, recording 20 billion license plate scans every month.

Read more of this story at Slashdot.

Catastrophic MoD Data Breach Caused By Lack of Training On Excel

A UK parliamentary inquiry found that a catastrophic Ministry of Defense breach exposing 18,700 Afghans could have been prevented with basic Excel training, after an employee unknowingly shared a hidden worksheet containing their details. The Independent reports: The leak, in February 2022, exposed the details of 18,700 Afghans who said they were in danger from the Taliban because of their links to UK forces and now wanted to escape to Britain. The blunder triggered an unprecedented superinjunction used against the national media, including The Independent, and prompted a secret evacuation program -- the cost of which is still unclear but which likely ran into the billions of pounds. Following the revelation by this outlet and others in July last year of the hidden operation, MPs set up an inquiry to scrutinize what had happened. In their report, the defense selection committee concluded that: - The data breach could have been prevented if Ministry of Defense (MoD) personnel had received basic Excel training - By August 2023, when the department discovered the leak, thousands of people already knew that a significant data incident had taken place - The government did not strike "the right balance between operational secrecy and democratic accountability" -- and the superinjunction was in place for too long - Secrecy denied affected Afghans the chance to take steps to protect themselves and their families and caused delays to evacuation program - Thousands of Afghans eligible to come to Britain are still trapped in Afghanistan with the government failing to explain how they will help get families to safety. MPs have called on the government to publish periodic reassessments of the risks facing Afghan applicants to UK resettlement schemes, with officials to report findings annually. They also want ministers to publish a clear policy explaining how they will help Afghans who are eligible to come to Britain but who have not yet been evacuated. The defense committee have also called on the MoD to explain who was responsible for data protection risk before the Afghan breach, criticizing the lack of accountability within the civil service.

Read more of this story at Slashdot.

DEF CON Bans Meta-Style 'Pervert Glasses'

DEF CON has banned "Meta-style glasses with recording capabilities," with no exceptions being made even for those with prescription versions. "Be sure to pack non-violating eyewear if you need them," DEF CON said. The Register reports: [The conference's official photo policy] has not been updated since 2023, predating the recent growth of camera-equipped eyewear developed by Meta with EssilorLuxottica under its Ray-Ban and Oakley brands. It states that public photography is permitted but with several caveats that essentially prohibit capturing the image of anyone, except on-stage speakers, unless the photographer obtains consent from the subject(s). "Love to see a 'no pervert glasses' policy at DEF CON," said EFF director of cybersecurity Eva Galperin.

Read more of this story at Slashdot.

GrapheneOS Defends Data-Wiping Function That Blocked US Border Search

GrapheneOS is defending its duress-password feature after an environmental activist used it to wipe his Pixel phone during a U.S. Customs search and was later indicted for allegedly destroying property under government control. The nonprofit says the operating system is "completely legal," cannot recover the erased data, and should not be weakened with encryption backdoors. Meanwhile, the activist faces up to five years in prison if found guilty. PCMag reports: In a post on Saturday, the Canadian nonprofit behind the operating system, the GrapheneOS Foundation, explained that the software offers a range of features to prevent data extraction. For example, one safeguard is the "auto-reboot timer" that'll reboot a locked device after a set period of time to put the data at rest, leaving all files inside encrypted. The group's post subtly suggests that GrapheneOS phones can withstand law enforcement searches without requiring users to resort to a duress password. "People should carefully consider how to use it in an actual duress situation where there can be physical or legal consequences for wiping the device," the nonprofit wrote. "GrapheneOS doesn't require it to protect data from being extracted from the device, but it takes recovering it completely off the table even with the PIN/password for each profile on the device." On X, the nonprofit has also said it can do nothing to help US law enforcement recover data from Tunick's phone. "Data cannot be recovered after the key derivation material is reliably wiped. It's not possible and there's nothing we can do to assist with it," the group wrote. "Similarly, it's not possible to assist with bypassing encryption because the hardware and software has been designed to prevent it."

Read more of this story at Slashdot.

Tons of Peoples' Claude Chats and Creations Are Exposed On Google

An anonymous reader quotes a report from 404 Media: Claude is exposing a wealth of users' chats and creations in Google search results, meaning anyone can dig through conversations or other material that people used Claude to make but may not have realized were publicly available for strangers to see. The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data. Exposed chats reportedly include private cryptocurrency wallet keys and personal information like peoples' addresses Like other chatbots, Claude lets people share their conversations with others by creating a publicly accessible link of the chat. People may do this to send the full text of a conversation to their friends or coworkers in a group chat, for example. But they may not realize Google is also surfacing these links in search results, making them available to essentially anyone. [...] Claude users can change their privacy and sharing settings to make their chats no longer publicly accessible.

Read more of this story at Slashdot.

Apple's Smart Glasses Delayed, As Engineers Consider Privacy Concerns

Digital Trends reports: Apple could unveil its first smart glasses at WWDC in June 2027, followed by a consumer release toward the end of the year, according to Bloomberg... Part of the delay reportedly stems from Apple's engineering and marketing teams spending more time refining the product and deciding how to address the privacy concerns... Apple has reportedly considered glasses without cameras, as well as a version where the cameras can analyse the surroundings but cannot record photos or video. Such an approach could still support object recognition, navigation, Siri, calls, and music playback. The company is also expected to favor on-device processing, avoid facial recognition, keep recordings away from AI training, and use a more visible light around the camera.

Read more of this story at Slashdot.

US Accuses American of Allegedly Wiping His Phone Using a 'Duress' Password During Border Search

An anonymous reader quotes a report from TechCrunch: The U.S. Justice Department is prosecuting an American for allegedly providing U.S. border authorities with a passcode that wiped the contents of his phone, according to an indictment and media reports. This is thought to be the first known case in the United States where federal prosecutors have charged someone for the alleged destruction of data using a so-called "duress" password built into a phone's software. According to The Guardian, which covered the story earlier this week following the court's first hearing on Monday, Atlanta resident Samuel Tunick is fighting the charges. Tunick's attorneys said that it was unlawful for U.S. Customs and Border Protection to seize his phone as he arrived back in the U.S. last year, and that any evidence -- including the alleged wiping of his phone -- should be thrown out. The case centers on a feature included in GrapheneOS, a custom Android operating system that runs in place of the software on most modern Google Pixel devices. Tunick's attorneys confirmed GrapheneOS was running on his phone. The software feature allows the device owner to set a passcode that deliberately wipes the contents of that device if entered instead of the user's unlock passcode. Tunick's case also raises ongoing questions about what constitutional rights can be invoked at the border, which the U.S. government has long asserted is not U.S. soil until a person is authorized to enter. Bill Budington, a senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, a digital security expert who works to protect at-risk people as the founder of security consultancy firm Granitt, told TechCrunch that they had not seen similar cases involving the use of duress passwords. "I have not seen this before, though I've discussed the potential scenario with activists and journalists over the years," said Sandvik. "I think this case serves as a reminder that authorities may argue you knowingly destroyed data, so it's better to not have that data on you when you cross certain borders." "With a little planning ahead of time, you can always download the data you need once you get to where you're going," said Sandvik.

Read more of this story at Slashdot.

Google Adds Selfie Video As a Log-In Option

An anonymous reader quotes a report from Engadget: You'll now be able to use selfie videos to log into your Google account. It has long been possible to log into Google using your face, via your phone's face unlock or if your passkey login uses biometrics for verification. This is yet another option to get into your account using your face to authenticate your identity, which could be especially useful if you don't have access to the phone or computer you typically use or if you got locked out of your account and none of the other log-in options are working. [...] Google will ask you to turn your head in certain ways during the verification and every time you use the option to log in. The company says it's to fend off impersonation attempts, such as deepfake videos, and prove you're currently in front of the camera. It will, of course, have to save your selfie video and use it for comparison for future logins.The company says it will encrypt your video and only use to help you sign in, but if you ever change your mind, you can delete it from your Google account. It's worth noting the option is currently unavailable for Workspace accounts, child accounts and those enrolled in Google's Advanced Protection Program. You can set it up and give it a try at g.co/signin-selfie.

Read more of this story at Slashdot.

1Password Lets Claude Use Credentials Without Exposing Passwords

BrianFagioli writes: 1Password has launched a Claude integration that allows the AI agent to sign in to websites using credentials stored in a 1Password vault. The password manager says Claude never sees the password or one-time code. Instead, users approve each request, and 1Password injects the credentials directly into the target website while locking down access to the rest of the vault. The design appears safer than simply handing passwords to an AI model, but it does not remove every risk. Once Claude is authenticated, it may still be able to view private data, change settings, place orders, or perform other actions available inside the account. Users may want to limit the feature to low-risk tasks until browser-based agents become more predictable.

Read more of this story at Slashdot.

How Flock Cameras Wrongly Tracked a Journalist for Days, Then Sent Police to Arrest Him

"Are you armed?!" the police officer screamed. "Get out of the car!" A writer for the car-news site The Drive describes how "a technological chain linking surveillance cameras, AI, and law enforcement... led to me and my wife being surrounded by police, hands on their guns, in a Kohl's parking lot in suburban Minnesota." After dropping off our Amazon returns, we'd just gotten back in the Range Rover and reversed maybe two feet out of the spot when four cop cars came flying out of nowhere and boxed us in... The Plymouth Police Department had been tracking me for days using Flock license plate cameras, waiting for the right moment to strike, because they thought I'd stolen the Range Rover. And the reason I was ID'd as a dangerous car thief was a simple data error made 2,000 miles away in California, creating an edge case within an edge case that Flock's AI camera network was unable to handle... "The plates on this car are stolen," Officer Ganshyn said... This made absolutely no sense. Car companies keep meticulous track of the fleets they loan out to the media. The vehicles all have special manufacturer or dealer plates that are logged every time one enters or exits... The New Jersey plates that were allegedly stolen from the LA dealer were 34 03 DTM, not 34 10 DTM. But when the police report was created and the plate was entered into Flock's system, it was just recorded as 34 DTM. Just the five large characters, no little number in the middle... Flock's AI tech wasn't registering that non-standard little number when it began picking up the Range Rover around town... I connected the final dot. A lot of vehicles in [Range Rover manufacturer] JLR's media fleet have a New Jersey manufacturer plate with the same alphanumeric structure β€” 34 ## DTM β€” and Officer Ganshyn observed that meant it was now a nationwide issue. Anywhere a police department has a partnership with Flock, any other JLR-owned car with the same plate structure is going to get flagged as stolen. In fact, four other 34 ## DTM cars were being tracked around Minnesota that week, according to Officer Ganshyn. I was just the first one to get nabbed. The only way to stop it would be for the LAPD to correct their initial report and update Flock's system, which Jaguar Land Rover was now racing to make happen following the phone call. Still, he warned me to drive straight home, park the Range Rover, and leave it there. If I were to cross into the neighboring town, I'd probably get flagged again and go through this entire ordeal again with a different set of officers. His parting words were ominous: "You're lucky we're in Plymouth. If you were in Minneapolis, they definitely would've come at you with guns drawn." Ironically, even the original license plate wasn't stolen either, the article points out. It was reported misplaced during a Los Angeles photo shoot, and "The corporation had to report the plate as lost to law enforcement," according to the police report β€” and even then, the plate "was reported as NJ 34DTM instead of NJ 3403DTM." The author's conclusion? "Once these systems have you in their crosshairs, there's pretty much only one way it can go... A simple data-entry error, magnified and broadcast nationwide by a growing surveillance network operated through an opaque partnership between a private company and public agencies, led police to identify me as a car thief and set up a sting to take me down. I mean, they even had a drone flying overhead during the 'bust'... "Thank God our kids weren't with us." Thanks to long-time Slashdot reader sinij for sharing the article.

Read more of this story at Slashdot.

Meta's Glasses Will Turn Off the Camera If You Tamper With the Privacy Light

Meta is rolling out an update that will disable the camera on its smart glasses if the device detects that someone has tampered with or destroyed the privacy LED. "The update is meant to address modders who have taken actions such as physically drilling into the LED light," reports The Verge. "Meta has previously tried to discourage tampering with the LED light. For example, starting with its second generation glasses, blocking the light with tape or other objects will trigger a prompt asking users to uncover the recording light. However, many modders have found various workarounds for that particular measure."

Read more of this story at Slashdot.

❌