Researchers at Northeastern University, in collaboration with Consumer Reports, evaluated how much modern cars spy in their drivers:
The new Northeastern study shows, for the first time, data flowing among the vehicles, the vehicle apps you download when you buy your car, and third-party companies, documenting exactly what kind of data gets siphoned from our vehicles and which companies are receiving that information.
Basically, your car’s manufacturer has you under constant surveillance, and they use that data against you.
Smart TVs can feel like a dumb choice if you’re looking for privacy, reliability, and simplicity.
Today’s TVs and streaming sticks are usually loaded up with advertisements and user tracking, making offline TVs seem very attractive. But ever since smart TV operating systems began making money, “dumb” TVs have been hard to find.
In response, we created this non-smart TV guide that includes much more than dumb TVs.
A human deputy sitting beside the road in 1987 might never have noticed. He probably wouldn’t have cared unless there was some reason to stop the vehicle in the first place.
The computer doesn’t get bored.
It doesn’t look away.
It doesn’t forget.
And increasingly, that is the privacy question Americans need to be discussing.
This isn’t really about whether Dad should have gone to the Secretary of State and spent the money to register the replacement trailer correctly. He should have.
The interesting question is whether every minor violation that was once practically invisible should become permanently detectable simply because technology has made detection cheap.
There is a profound difference between a police officer seeing something suspicious and investigating it and building a technological environment in which everyone’s ordinary movements can be recorded, searched and reconstructed later.
For most of American history, privacy wasn’t created entirely by law.
Some of it came from friction.
Following someone required manpower. Checking plates required effort. Remembering where somebody’s pickup was Tuesday afternoon required an actual human being who saw it Tuesday afternoon.
Government theoretically possessed considerable investigative authority, but exercising that authority cost something.
Technology is removing that friction.
A camera doesn’t need overtime.
A database doesn’t need coffee.
An algorithm doesn’t say, “I’m not spending twenty minutes investigating whether Earl’s 1993 Harbor Freight trailer has the correct plate.”
It simply remembers.
And that creates a strange new world where activities that were always technically discoverable can potentially become automatically discoverable.
Those aren’t necessarily the same thing.
Claims follow scrutiny over monitors installing adware without user consent
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming increasingly common on American streets.
Bill Swearingen, founder of SIXCYBER, has spent the past year running an impressive 31 million tests developing what he calls noRecognition. noRecognition is a reinforcement learning model that generates patterns capable of defeating the algorithms built into surveillance cameras to detect objects.
The patterns do not prevent cameras from actually recording footage, so a human watching the video would still see a car. But what fails is the software use to identify objects, logs vehicle licence plates, and triggers alerts.
On Thursday, Flock announced plans to require all agencies with access to license plate reader data to use a safety tool that automatically detects abnormal activity and locks out cops who abuse their access to stalk people they know in their personal lives.
Flock’s audit assistance tool suspends access when user activity “meets defined criteria for abnormal behavior,” Flock said. The suspension can only be lifted by administrator review, with the goal being “to intervene before misuse becomes recurring or widespread.” //
However, experts caution that there is no data to show how well the tool works to detect nefarious logins or malicious activity. In a press release, the ACLU recommended that an independent evaluator should review Flock’s tech. Until then, the ACLU warned that there is “no evidence that the tool works consistently” to address what The Washington Post found was a growing pattern of stalker cops using Flock cameras to spy on their exes. As of now, the ACLU said, “We don’t know if the tool is a real security measure or just window dressing.”
Additionally concerning—although Langley predicted to The Verge that “you are going to see more officers fired and more officers arrested for abusing police power”—experts warn that the public will only know the tool is working if agencies are fully transparent about how much abuse is found. //
“It’s very difficult for anybody outside the department to know about it, and very easy for the department to sweep it under the rug,” Boudin said. “Even with the best intentions from Flock, it’s just not enough to ensure accountability. //
All4vols Ars Centurion
11y
325
Subscriptor
Having active general surveillance is bad. Targeting general surveillance is worse. Non-regulated, non-audited, non-accountable surveillance state is worse. I thought we, as Americans, were against this. If we HAVE to have a Flock equivalent (and we don't), it should only be accessible through a signed warrant, just like any other search. Only exceptions should be for Silver or Amber Alerts. And all activity should be audited regularly the results made public.
One of my latest projects is the Baochip-1x, a mostly-open, full-custom silicon chip fabricated in TSMC 22nm, targeted at high assurance applications. It’s a security chip, but far more open than any other security chip; it’s also a general purpose microcontroller that fills a gap in between the Raspberry Pi RP2350 (found on the Pi Pico2) and the NXP iMXRT1062 (found on the Teensy 4.1).
It’s the latest step in the Betrusted initiative, spurred by work I did with Ed Snowden 8 years ago trying to answer the question of “can we trust hardware to not betray us?” in the context of mass surveillance by state-level adversaries.
The Financial Times has a good article on how AI is changing the capabilities of video surveillance, with information from both Israel/Iran and Russia.
I wrote about this sort of thing a few years ago, how AI enables mass spying in the way that computers and networks enabled mass surveillance. The interesting development in the article is that AI allows people to ask natural language questions about video footage to AIs—and AIs can answer them. //
That lets intelligence officers hunt through massive streams of videos using simple search terms, such as two men handing a bag to each other; a person who has changed their appearance, or has changed clothes multiple times in a day; or a vehicle that has recently been painted over, or has driven past the same spot several times in a short period.
TL;DR: The 2021 Infrastructure Investment and Jobs Act requires all new cars sold after September 2027 to include technology that monitors whether you're impaired or distracted—and can prevent you from driving. Infrared cameras will track your eyes, breath sensors will measure alcohol, and your car can refuse to start or limit its speed. Privacy advocates warn this biometric data could be shared with insurance companies, law enforcement, or sold to data brokers.
What's coming to your car
Tucked into the 2,702-page Infrastructure Investment and Jobs Act that President Biden signed in November 2021 was a provision that few Americans noticed. Section 24220 requires NHTSA to issue safety standards mandating "advanced drunk and impaired driving prevention technology" in all new passenger vehicles.
The law gave NHTSA until November 15, 2024 to finalize rules. Enforcement begins no later than September 2027. That deadline is now 18 months away.
There was a time in America when you could punch your Army captain, skip town, grow a beard, head west, and become “Samuel Whitaker, cattleman and church deacon.”
Today? You can’t change your Instagram handle without a two-factor authentication code, three archived screenshots, and your ex forwarding it to your employer.
We romanticize the 1800s as rough, lawless, and dangerous. And they were. But they were also gloriously anonymous. Identity wasn’t a federal project. It was a handshake and a story. If you said your name was John Carter and no one in Kansas knew you from Ohio, congratulations — you were John Carter.
Try that today and watch your credit report laugh at you. //
Now let’s be clear: this isn’t a defense of criminals dodging consequences. Murderers should not get a prairie do-over. But the cultural cost of total traceability is rarely discussed.
We used to believe in redemption arcs. The disgraced soldier who became a rancher. The bankrupt merchant who moved west and rebuilt. The man who made a mess in one town and quietly matured in another.
Today we say we believe in second chances — but we engineered a system that never forgets the first mistake.
The modern world is one giant memory palace. A Tower of Babel made of servers and compliance officers. Every institution, public and private, hoards information not because it makes us better — but because bureaucracies exist first to preserve themselves. Information is leverage. Leverage is control. Control is stability.
Or at least the illusion of it.
We’ve scaled record-keeping beyond what human forgiveness can handle.
The irony? In the 1800s, it was easier to vanish — but harder to fake competence. If you showed up calling yourself a blacksmith and couldn’t shoe a horse, you were exposed by noon. Reputation rebuilt itself through actual skill and conduct.
Today you can curate a flawless LinkedIn persona while your past mistakes sit quietly indexed beneath it. We don’t test character locally anymore; we audit it digitally.
We show that from a handful of comments, LLMs can infer where you live, what you do, and your interests—then search for you on the web. In our new research, we show that this is not only possible but increasingly practical.
A federal judge in Virginia ruled Tuesday that the City of Norfolk’s use of nearly 200 automated license plate readers (ALPRs) from Flock is constitutional and can continue, dismissing the entire case just days before a bench trial was set to begin.
The case, Schmidt v. City of Norfolk, was originally filed in October 2024 by two Virginians who claimed that their rights were violated when the Flock network of cameras captured their cars hundreds of times, calling the entire setup a “dragnet surveillance program.”
However, in a 51-page ruling, US District Court Judge Mark S. Davis disagreed, finding that the “…plaintiffs are unable to demonstrate that Defendants’ ALPR system is capable of tracking the whole of a person’s movements.” //
I intended to NOT drop what I was doing and just let the video play in the background. But after 1 minute, I dropped what I was doing to give the video my full attention. https://www.youtube.com/watch?v=vU1-uiUlHTo
See also "We’re All So F’d | NVIDIA x Palantir, Global Surveillance, 'Pre-Crime' Arrests, & AI." https://www.youtube.com/watch?v=5lYsO4k7OIY
It may well be that IP addresses are simply the wrong starting place to fulfil these desires relating to compliance, security, customisation and performance: "You cannot get to where you want to go to from where you appear to be!"
EFF is against age gating and age verification mandates, and we hope we’ll win in getting existing ones overturned and new ones prevented. But mandates are already in effect, and every day many people are asked to verify their age across the web, despite prominent cases of sensitive data getting leaked in the process.
At some point, you may have been faced with the decision yourself: should I continue to use this service if I have to verify my age? And if so, how can I do that with the least risk to my personal information? This is our guide to navigating those decisions, with information on what questions to ask about the age verification options you’re presented with, and answers to those questions for some of the top most popular social media sites. Even though there’s no way to implement mandated age gates in a way that fully protects speech and privacy rights, our goal here is to help you minimize the infringement of your rights as you manage this awful situation.
Introducing Confer, an end-to-end AI assistant that just works.
Moxie Marlinspike—the pseudonym of an engineer who set a new standard for private messaging with the creation of the Signal Messenger—is now aiming to revolutionize AI chatbots in a similar way.
His latest brainchild is Confer, an open source AI assistant that provides strong assurances that user data is unreadable to the platform operator, hackers, law enforcement, or any other party other than account holders. The service—including its large language models and back-end components—runs entirely on open source software that users can cryptographically verify is in place.
Data and conversations originating from users and the resulting responses from the LLMs are encrypted in a trusted execution environment (TEE) that prevents even server administrators from peeking at or tampering with them. Conversations are stored by Confer in the same encrypted form, which uses a key that remains securely on users’ devices. //
All major platforms are required to turn over user data to law enforcement or private parties in a lawsuit when either provides a valid subpoena. Even when users opt out of having their data stored long term, parties to a lawsuit can compel the platform to store it, as the world learned last May when a court ordered OpenAI to preserve all ChatGPT users’ logs—including deleted chats and sensitive chats logged through its API business offering. Sam Altman, CEO of OpenAI, has said such rulings mean even psychotherapy sessions on the platform may not stay private. Another carve out to opting out: AI platforms like Google Gemini may have humans read chats.
The result would be a "checkpoint society" where identity checks become an unavoidable part of daily life, Big Brother Watch says.
The group says such a system would fundamentally alter the relationship between citizen and state, creating a surveillance infrastructure vulnerable to abuse, discrimination, and hacking. A Big Brother Watch poll, carried out by YouGov, shows that 63 percent of Brits don't trust the government to protect their data – hardly surprising given Whitehall's track record of bungled IT projects, data leaks, and multi-billion-pound write-offs.
The group has also sounded the alarm over the UK's existing digital identification system, One Login, which underpins the credential issuing process in the so-called "BritCard" proposal, which it says is known to suffer from substantial cybersecurity and data protection weaknesses.
Big Brother Watch also warns of mission creep, arguing that once a system is live, "voluntary" quickly becomes mandatory. Those who fail or refuse to enrol risk being locked out of jobs, housing, or healthcare, while errors could leave people wrongly excluded from essential services.
"The notion that digital ID will provide a magic-bullet solution for unauthorised immigration is ludicrous," said Rebecca Vincent, interim director of Big Brother Watch. "It will not stop small boat crossings, and it will not deter those intent on using non-legal means of entering the country from doing so. But digital ID will create a huge burden for the largely law-abiding 60 million people who already live here and insert the state into many aspects of our everyday lives."
That led to a quick trip to an 'Urgent Care' - the frontline medical center for most Americans. At the check-in counter, the check-in nurse asked to see some ID, so I handed over my Australian driver's license. The nurse looked at the license and typed some of the info on it into a computer, then they looked up at me and asked: "Are you the same Mark Pesce who lived at...?" and then proceeded to recite an address that I resided at more than half a century ago.
Dumbstruck, I said, "Yes...? And how did you know that? I haven't lived there in nearly 50 years. I've never been in here before - I've barely ever been in this town before. Where did that come from?"
"Oh," they replied. "We share our patient data records with Massachusetts General Hospital. It's probably from them?"
I remembered having a bit of minor surgery as an 11 year old, conducted at that facility. 51 years ago. That's the only time I'd ever been a patient at Massachusetts General Hospital.
Somehow that had never been forgotten.
We seem perfectly willing to accept that everything we do today leaves a permanent record. It appears that long before Eric Schmidt declared, "Privacy is dead," any of our pretensions to privacy had already joined the Choir Invisible. //
I don’t much care how my records made it into 2025. I am interested in why nobody ever decided to delete them.
I realize we all want our medical records instantly available to inform treatment in moments of great need. But half a century of somewhat senseless recordkeeping strains credulity. Most likely my record remained in that database simply because it's never been cleaned out - an operation that would take time and budget that would never be approved because, why would you ever delete patient data?
This has the feel of a situation we had no idea we were making for ourselves - countless sensible decisions culminating in a ridiculous outcome. Go forward another fifty years, when it's quite likely I, too, will have joined the Choir Invisible. Will my patient record still be in that database? What purpose would that serve? If my records as a child are in there, half a century later, it's easy to imagine this database holds records of many other people who have passed on and therefore shouldn't be in there at all. Privacy lost to laziness. //
Alex 72
Reply Icon
Medical records should be kept but access should be controlled
I agree yes you want medical records kept, patient history is always useful and provided they are only shared with the patient or a doctor or other professional they have consented to be cared for by, and who is not engaged in malpractice, it's not harmful. The hard part is drawing the line on how much anonymised data can be used for research, ensuring that data remains anonymous and managing consent for sharing data when patients are treated elsewhere or researchers want to use data from multiple sources.
and if you keep them for someone's entire lifespan then you should provided they did not object in their lifetime and next of kin explicitly consent or at least don't object probably archive it for future research in the near/medium term and historical value in the long term. Again managing consent, allowing reasonable anonymised research in the public interest, preventing de-anonymisation and deciding the limits of how long parts of it stay private vs when genealogists and historians can have unrestricted access.. is the challenge.
To do any of this effective durable storage, access control, authentication and authorisation are just some of the challenges. I have seen data analytics firms who's job is just this struggle to get everything correct so a group of organisation just trying to provide healthcare, research, treatments, disease, prevention.... Having to do this as an add on with a limited budget I am honestly impressed its only now with ransomware we are starting to see issues and paper records were not being stolen and abused on a massive scale in the past...
I don't know the answer but I don't think its the delete key
Gene CashSilver badge
Why would you ever delete patient data?
Yes, seriously.
I can understand other records, but not medical ones.
I was able to get proper medical care, including surgery, for a broken coccyx after proving I had fallen off a hay bale in 1973 and seriously injured myself, and thus it was a chronic thing and not just the minor recent incident my doctor insisted it was. I would have otherwise not been considered eligible for the surgery.
And after you're dead, it's no longer a privacy issue and becomes historical records. It's no different than census records.
Should this data be held indefinitely? Yes.
This is the same sort of data that let me piece together that my great^9 grandfather was Edward Reavis, born 1680 in Paddington, England, and left to come to Virginia, after being held in Newgate prison for his religious beliefs. He moved to Henrico county, Virginia in 1721 and died in Northampton county, North Carolina in 1751. I've also found 454 other relatives down to me, through a ton of things including bible notes, estate papers, census records, marriage records, medical records, military records, family papers, private letters, obituaries, social security records, tombstones, and even old wedding invitations.
The Solid protocol, invented by Sir Tim Berners-Lee, represents a radical reimagining of how data operates online. Solid stands for “SOcial LInked Data.” At its core, it decouples data from applications by storing personal information in user-controlled “data wallets”: secure, personal data stores that users can host anywhere they choose. Applications can access specific data within these wallets, but users maintain ownership and control.
Solid is more than distributed data storage. This architecture inverts the current data ownership model. Instead of companies owning user data, users maintain a single source of truth for their personal information. It integrates and extends all those established identity standards and technologies mentioned earlier, and forms a comprehensive stack that places personal identity at the architectural center.
This identity-first paradigm means that every digital interaction begins with the authenticated individual who maintains control over their data. Applications become interchangeable views into user-owned data, rather than data silos themselves. This enables unprecedented interoperability, as services can securely access precisely the information they need while respecting user-defined boundaries.
Solid ensures that user intentions are transparently expressed and reliably enforced across the entire ecosystem. Instead of each application implementing its own custom authorization logic and access controls, Solid establishes a standardized declarative approach where permissions are explicitly defined through control lists or policies attached to resources. Users can specify who has access to what data with granular precision, using simple statements like “Alice can read this document” or “Bob can write to this folder.” These permission rules remain consistent, regardless of which application is accessing the data, eliminating the fragmentation and unpredictability of traditional authorization systems. //
Peter Galbavy • July 24, 2025 9:30 AM
Maybe I have failed to have boned up on Solid, but the charming naivete that people will maintain their own personal data stores in an honest and trustworthy way is only slightly less laughable than how it’s done right now. Or maybe not.
Again, perhaps, because I have not spent any time looking at the actual protocol details I am confused where the veracity comes from? Or am I suddenly able to call myself an Admiral with a law degree and a healthy trust fund as a credit line?
Financial criminality would be democratised overnight, if nothing else.
atanas entchev • July 24, 2025 11:01 AM
The Solid protocol is charmingly naive. It assumes — like the early internet — good-will participation from everyone. We know that this is not how the real world functions.
What is to stop bad actors from building and presenting a fake profile / history / whatever?
Peter A. • July 24, 2025 11:11 AM
There’s also another problem: partial identities, pseudonymous/fake identities, companies that collect too much data, etc. Having a data store that has it all is a bit risky, as you can accidentally share too much, especially the people that are a little less competent with all that computer stuff.
Shashank Yadav • July 24, 2025 8:57 AM
People like to own things which accord them status or meaningful utility – which is where all expectations of users considering data ownership falter.
Moreover, for enterprise users this may work, the vast majority of individual users cannot be expected to maintain such personal data pods. Hypothetically, let us say you make a law requiring this way of data management, there will immediately be third-parties who people would prefer to handle this for them. Kind of like the notion of consent managers in India’s data protection laws, because competent and continuous technical administration cannot be expected from ordinary users.
Encrypted chat apps like Signal and WhatsApp are one of the best ways to keep your digital conversations as private as possible. But if you’re not careful with how those conversations are backed up, you can accidentally undermine your privacy.
When a conversation is properly encrypted end-to-end, it means that the contents of those messages are only viewable by the sender and the recipient. The organization that runs the messaging platform—such as Meta or Signal—does not have access to the contents of the messages. But it does have access to some metadata, like the who, where, and when of a message. Companies have different retention policies around whether they hold onto that information after the message is sent.
What happens after the messages are sent and received is entirely up to the sender and receiver. If you’re having a conversation with someone, you may choose to screenshot that conversation and save that screenshot to your computer’s desktop or phone’s camera roll. You might choose to back up your chat history, either to your personal computer or maybe even to cloud storage (services like Google Drive or iCloud, or to servers run by the application developer).
Those backups do not necessarily have the same type of encryption protections as the chats themselves, and may make those conversations—which were sent with strong, privacy-protecting end-to-end encryption—available to read by whoever runs the cloud storage platform you’re backing up to, which also means they could hand them at the request of law enforcement.
“…as a condition of participating in the modern economy, Americans are forced to disclose details of their private lives to a financial industry that has been too eager to pass this information along to federal law enforcement.”
A report from the House Judiciary Committee and Government Weaponization Subcommittee exposed the FBI for abusing the Bank Secrecy Act (BSA) to spy on Americans’ bank accounts without a warrant.
“Documents show that federal law enforcement increasingly works hand-in-glove with financial institutions, obtaining virtually unchecked access to private financial data and testing out new methods and new technology to continue the financial surveillance of American citizens,” according to the report.