F-Droid 2.0 Is a Game Changer

Our top stories this week:

  • F-Droid 2.0: A New Chapter for Android Freedom
  • Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day
  • An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
  • DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising
  • Researchers found a way to eavesdrop on headphones from 30 meters away, and encryption can't stop it

TWIP Live 🔴


Updates from the Team

The iPhone the FBI Couldn’t Hack

In 2016, a locked iPhone 5C sparked a massive showdown between Apple and the FBI. When the US government demanded Apple push a modified compromised update to bypass iOS Security, it created a national debate; where does individual privacy end and public safety begin?

The iPhone the FBI Couldn’t Hack
In 2016, a locked iPhone 5C sparked a massive showdown between Apple and the FBI. When the US government demanded Apple push a modified compromised update to bypass iOS Security, it created a natio…

Upcoming Site Changes

This week we pushed some small changes that will appear on the next site release. We fixed typos and improved wordings and warned that Molly is no longer updating every two weeks as promised.

Commits · privacyguides/privacyguides.org
Protect your data against global mass surveillance programs. - Commits · privacyguides/privacyguides.org

News Briefs

Our news briefs remain a fantastic source of keeping up-to-date with breaking stories. In addition to the weekly Data Breach Roundup, this week featured stories about Discord's new age verification rollout, the FBI's headline-making data breach impacting virtually all agents and applicants, and a major vulnerability in Meta's new AI agent app. Be sure to sign up or subscribe via RSS.

Privacy & Security News
The latest news in data privacy, cybersecurity, and consumer rights brought to you by Privacy Guides.

Sources

F-Droid 2.0: A New Chapter for Android Freedom

This week, F-Droid released a major update to their app store. The majority of changes focus on modernizing the UI and adding additional categories to make it more user friendly, but also include improving the search function, adding more filtering options, and improving the installation process. For privacy and security improvements, the app no longer ships with the F-Droid Privileged Extension, integrates Tor functionality better, and better clarifies what the panic button is capable of.

F-Droid 2.0: A New Chapter for Android Freedom | F-Droid - Free and Open Source Android App Repository
After more than a year of hard work, we are thrilled to announce the launch of F-Droid 2.0, a complete redesign of the official F-Droid app and the largest a…

Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day

Meta's new AI assistant has been making headlines and topping the download charts in app stores. However, as usual, it seems the security has been heavily exaggerated. Researchers have discovered that Muse can be easily Man-in-the-Middled with an attack as simple as ClickFix, and once compromised can function as backdoor access to the user's machine. Meta has rolled out a fix, but this just illustrates the privacy and security concerns that come with such powerful tools.

Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day
A simple ClickFix attack is only one way to completely hijack the new agent.

An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later

Yet another scandal making headline news, it seems that OpenAI's agents hacked Australia's healthcare records nearly 3 months ago, but only recently disclosed it this month. The company had been conducting "internet based research into health statistics in a development project." When the agent could not access certain information, it found workarounds and gained unauthorized access. OpenAI later quietly disclosed the breach to the government via a public email channel. The good news is that the government believes only non-sensitive data and statitics such as spending were accessed, but they're still investigating to determine the appropriate response.

An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
The country’s prime minister expressed disappointment at being informed of the hack only via email. Now Australia is investigating whether OpenAI broke the law.

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising

In a textbook example of why privacy matters, EFF alleges that online sports company DraftKings is using AI to target customers who are most likely to place losing bets and respond to promotions. This demonstrates how our data can be weaponized against us in unethical ways - not to just reach the people most likely to become customers but those specifically most likely to enrich the company even at the expense of the customer in dire ways.

DraftKings Is Using AI to Supercharge the Harms of Online Behavioral Advertising
Online sports betting company DraftKings is using AI to target customers who are most likely to place losing bets and respond to gambling promotions. This kind of targeting is a form of online behavioral advertising, which is when companies personalize the ads they show you based on the data they’…

Researchers found a way to eavesdrop on headphones from 30 meters away, and encryption can't stop it

Researchers in Hong Kong have developed a technique they call InjectEave, which targets even analog components that can leak signals that are normally too weak to be captured by typical electromagnetic eavesdropping. Using this technique, researchers were able to capture understandable headphone audio from up to 30 meters away and even through walls. The attack even worked on wired headphones. Researchers showed it is possible in the real world, but would require advanced knowledge. Shielding, flitering, and twisted-pair wiring can make the attack harder but it's not a guaranteed fix.

Researchers found a way to eavesdrop on headphones from 30 meters away, and encryption can’t stop it
The research comes from the Hong Kong University of Science and Technology in Guangzhou and the Hong Kong Polytechnic University. The team presented its paper, “Injected and…

Forum Updates

Should Privacy Guides still have translations?
Inspired by Request for adding the Arabic translation into the website - #2 by ph00lt0 should Privacy Guides even have translations in this decade? Now for SEO one could say local languages are probably helping us to be discovered, on the other hand (at least for the Dutch version) the translations are both incomplete and not really the best either. To me the reader experience in incomplete translations is rather bad. Junping from one English sentence into a Dutch one is not really a good way t…
Proton partners with Apertus, Switzerland’s sovereign AI model | Proton