Utah Targets VPNs for Age Verification
Governor Spencer Cox has signed a law stating that websites are accountable for determining if a user is physically located in Utah, even from behind a VPN.
Fria is a privacy advocate and synthwave enthusiast who has been volunteering with Privacy Guides since 2023. They are an unapologetic tech optimist, and believes with the right technology we can solve any problem.
Governor Spencer Cox has signed a law stating that websites are accountable for determining if a user is physically located in Utah, even from behind a VPN.
Canvas, software used by thousands of schools in the U.S., has been hacked and the private data of staff and students stolen.
Two new Linux local privilege escalation vulnerabilities were discovered in the same vulnerability class as Copy Fail, affecting most Linux distributions.
Google announced that “you can now choose to share your approximate location with websites, instead of sharing precise location” on Chrome for Android.
Proton Mail now offers post-quantum encryption to protect against future threats from quantum computers.
9to5mac spotted in the release notes of iOS 26.5 RC confirmation that the long-awaited RCS end-to-end encryption feature will ship with iOS 26.5.
Fedora 44 has released, and with it comes a new offering: sealed bootable container images, which “include all the components needed to create a fully verified boot chain.”
OpenAI has introduced new security protections for ChatGPT accounts called Advanced Account Security, to protect users against account takeover.
A new exploit called copy.fail has emerged that can root just about any Linux distribution shipped since 2017 using just an unprivileged user account.
Firefox has bundled adblock-rust, Brave’s memory-safe content blocker, into Firefox in version 149, although disabled by default.
The fingerprinting company fingerprint.com discovered a vulnerability affecting “all Firefox-based browsers” that would allow a “stable process-lifetime identifier” during a browsing session, including after pressing the “New Identity“ button in Tor browser.
Apple has released iOS 26.4.2, which fixes the notification bug that allowed the FBI to extract Signal messages from a defendant’s iPhone.
According to WIRED, Madison Square Garden’s incredibly invasive facial recognition system has been used to ban critics of the stadium and even track a trans woman around who did nothing wrong.
Reuters reports that the Indian government has decided it won’t go through with a proposal to require operating systems to preinstall the biometric ID app Aadhaar.
A security researcher on Hacker News claims that sensitive documents like tax forms shared between Fiverr users in private messages ended up publicly indexed by search engines like Google.
Mastodon announced they were awarded a €614k service agreement by the Sovereign Tech Fund to fund the development of new features and improvements, including end-to-end encrypted private messages.
Google announced on their security blog that Device Bound Session Credentials (DBSC), a protection against session theft, are shipping for Windows users on Chrome 146.
The Coalition of Alberta Public Libraries issued a letter raising privacy concerns over Bill 28, or the Municipal Affairs and Housing Statues Amendment Act, in Alberta, which requires age restrictions on library materials.
The FTC has determined that OkCupid and their owner Match Group don’t have to pay a fine after settling a case in which they shared 3 million user photos and location information to a facial recognition firm.
macOS 26.4 is now out, and with it comes a new feature in the Terminal app to help prevent malicious commands pasted into the terminal from running.
Angela Lipps, an innocent, 50-year-old grandma who was arrested after wrongfully being identified by facial recognition software, has finally been released.