F-Droid 2.0 Is a Game Changer
Our top stories this week:
- F-Droid 2.0: A New Chapter for Android Freedom
- Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day
- An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
- DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising
- Researchers found a way to eavesdrop on headphones from 30 meters away, and encryption can't stop it
TWIP Live 🔴
Updates from the Team
The iPhone the FBI Couldn’t Hack
In 2016, a locked iPhone 5C sparked a massive showdown between Apple and the FBI. When the US government demanded Apple push a modified compromised update to bypass iOS Security, it created a national debate; where does individual privacy end and public safety begin?

Upcoming Site Changes
This week we pushed some small changes that will appear on the next site release. We fixed typos and improved wordings and warned that Molly is no longer updating every two weeks as promised.
News Briefs
Our news briefs remain a fantastic source of keeping up-to-date with breaking stories. In addition to the weekly Data Breach Roundup, this week featured stories about Discord's new age verification rollout, the FBI's headline-making data breach impacting virtually all agents and applicants, and a major vulnerability in Meta's new AI agent app. Be sure to sign up or subscribe via RSS.

Sources
F-Droid 2.0: A New Chapter for Android Freedom
This week, F-Droid released a major update to their app store. The majority of changes focus on modernizing the UI and adding additional categories to make it more user friendly, but also include improving the search function, adding more filtering options, and improving the installation process. For privacy and security improvements, the app no longer ships with the F-Droid Privileged Extension, integrates Tor functionality better, and better clarifies what the panic button is capable of.

Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day
Meta's new AI assistant has been making headlines and topping the download charts in app stores. However, as usual, it seems the security has been heavily exaggerated. Researchers have discovered that Muse can be easily Man-in-the-Middled with an attack as simple as ClickFix, and once compromised can function as backdoor access to the user's machine. Meta has rolled out a fix, but this just illustrates the privacy and security concerns that come with such powerful tools.

An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
Yet another scandal making headline news, it seems that OpenAI's agents hacked Australia's healthcare records nearly 3 months ago, but only recently disclosed it this month. The company had been conducting "internet based research into health statistics in a development project." When the agent could not access certain information, it found workarounds and gained unauthorized access. OpenAI later quietly disclosed the breach to the government via a public email channel. The good news is that the government believes only non-sensitive data and statitics such as spending were accessed, but they're still investigating to determine the appropriate response.

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising
In a textbook example of why privacy matters, EFF alleges that online sports company DraftKings is using AI to target customers who are most likely to place losing bets and respond to promotions. This demonstrates how our data can be weaponized against us in unethical ways - not to just reach the people most likely to become customers but those specifically most likely to enrich the company even at the expense of the customer in dire ways.

Researchers found a way to eavesdrop on headphones from 30 meters away, and encryption can't stop it
Researchers in Hong Kong have developed a technique they call InjectEave, which targets even analog components that can leak signals that are normally too weak to be captured by typical electromagnetic eavesdropping. Using this technique, researchers were able to capture understandable headphone audio from up to 30 meters away and even through walls. The attack even worked on wired headphones. Researchers showed it is possible in the real world, but would require advanced knowledge. Shielding, flitering, and twisted-pair wiring can make the attack harder but it's not a guaranteed fix.

Forum Updates








