Why Are People Mad at Mullvad?
Our top stories this week:
- Mullvad Donation Controversy
- An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion
- The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
- OpenAI Models Escaped Containment and Hacked Hugging Face
- Apple Fixes Hide My Email Vulnerability After 404 Media Coverage
TWIP Live 🔴
Updates from the Team
Site Updates
We've finally published a bunch of overdue site updates, such as removing Cromite and Proxitok, updating our recommendations for the Brave browser on mobile, adding updated information about things like MV2 and quad9, and more. Check it out!
News Briefs
A lot of important stuff happened this week, like a macOS vulnerability that allows attackers to replace any app with malicious code, Gemini allowing attackers to bypass the Android lock screen, malware stored in SVG images, and more. It was a busy week, so definitely make sure you didn't miss anything!

Sources
Mullvad Donation Controversy
Several weeks ago, it came to light that Daniel Berntsson - one of the co-owners of Mullvad VPN - donated a significant amount of money to the Swedish "Örebro Party" or "ÖP." According to Wikipedia, the ÖP holds views that have been accused of being both left- and right-wing, but typically do align with populism, nationalism, and conservativism. This donation has sparked a debate in the privacy community about whether such donations by people in these positions count as being personal, private affairs or if customers have an expectation of how project personnel spend the money they make off the project in their personal lives.

An Explosion of Surveillance Towers is Coming to U.S. Borders, Costing Over $1 Billion
A new report from the Government Account Office shows that the Department of Homeland Security plans to nearly triple the number of surveillance towers along the US-Mexico border from 830 to 2,300 by 2034. These towers are AI-powered and use radar, thermal infrared, and optical systems to track vehicle and foot traffic. This raises questions about the balance between protecting borders and protecting privacy, as many cities are directly on the border and these cameras would almost certainly capture ordinary citizens going about their business in their own country without crossing the border.

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
In the recent U.S. v. Belmonte Cardozo case, the Fourth Circuit court has ruled that border agents are allowed to search your phone by hand - meaning no forensic tools, no copying of the data, etc - for any reason. While this search is definitely less invasive and worriesome than use of forensic tools, there's still a lot of data that can be uncovered through such a simple search, and it's disappointing that police don't even need a basic legal justification such as "reasonable suspicion."

OpenAI Models Escaped Containment and Hacked Hugging Face
In a high-profile story that's been making the rounds, OpenAI's latest two AI models were able to escape containment during testing to try to steal the answers to a test they were being graded on from Hugging Face - the open AI model database. The models were able to chain vulnerabilities across both OpenAI and Hugging Face to escape to the wider internet. We covered the breach more in this week's Data Breach Roundup.

Apple Fixes Hide My Email Vulnerability After 404 Media Coverage
A few weeks ago, we shared how a vulnerability had been discovered that exposed your main email address when using Apple's "Hide My Email" feature. Apple was being slow and unresponsive to fix the bug. Thanks to public pressure, it has finally been fixed and details have been released about how it worked. Simply put, it required the attacker to send an email that got rejected as spam, which the victim might never have even seen. This would often result in the primary email address being exposed in the log report.

Forum Updates






