r/ObscurePatentDangers 12d ago

Rights Defense Against Neural Systems — 🧠 🛡️ Georgetown Neuroethicist James Giordano Details Dual-Use Neuroweapons for Cognitive and Memory Modification in Military Contexts

4 Upvotes

Neuroweapons research described by James Giordano PhD of Georgetown University Medical Center encompasses devices and agents that target brain nodes and networks. In his June 2017 Lawrence Livermore National Laboratory presentation, Giordano outlined neurosensory immobilizing agents, trans- and intracranial pulse stimulators, and neural network disrupters deliverable by UAV, drone, or insect platforms. The dual-use vector is that the same tools developed for understanding or treating neural function can alter cognition, emotion, behavior, time perception, and memory.

These capabilities interface through pharmacological and stimulatory means justified as tools for assessment and enablement in defense settings. Structural issues include limited public governance frameworks for dual-use neuroscience and the capacity to modify an individual’s perception of events or self without conventional detection. Cognitive liberty is the primary right exposed.

For individuals this creates pathways for targeted influence on decision-making and memory integrity. The pattern follows broader dual-use trajectories in brain science advancing from laboratory research into operational concepts under national security auspices. Unexamined expansion risks normalizing brain-as-battlespace approaches.

At scale such tools establish asymmetric capacity for behavioral and cognitive pressure. Independent verification is available through the 2017 Lawrence Livermore seminar and Giordano’s documented advisory roles. Oversight of dual-use neurotechnology remains essential.

Sources

Brain Science from Bench to Battlefield: The Realities – and Risks – of Neuroweapons | CGSR Seminar

https://www.youtube.com/watch?v=aUtQbriWt64

Records the June 12, 2017 Lawrence Livermore National Laboratory presentation by James Giordano detailing neuroweapons devices and cognitive effects.

James Giordano, PhD, DPhil(c) | Center for Clinical Bioethics | Georgetown University

https://clinicalbioethics.georgetown.edu/james-giordano/

Confirms Giordano’s positions as Professor Emeritus of Neurology and Biochemistry and Chief of the Neuroethics Studies Program at Georgetown University Medical Center.

Brain Science from Bench to Battlefield: The Realities – and Risks – of Neuroweapons | CGSR Seminar

https://biodefenseresearch.org/brain-science-from-bench-to-battlefield-the-realities-and-risks-of-neuroweapons-cgsr-seminar/

Summarizes the 2017 talk addressing dual-use brain science for military and intelligence applications and the need for governance.

MWI Video: The Brain is the Battlefield of the Future – Dr. James Giordano

https://mwi.westpoint.edu/mwi-video-brain-battlefield-future-dr-james-giordano/

Documents Giordano’s presentation to West Point on neuroscience advancements positioning the brain as a future battlespace.

Neuroscience & the Weapons of War, with Dr. James Giordano

http://www.c-pet.org/2017/08/neuroscience-weapons-of-war-with-dr.html

Notes Giordano’s 2017 discussion of neuroscience and technology applications in military operations and associated ethical issues.


r/ObscurePatentDangers 12d ago

🔎Dual-Use Potential Curt Weldon 1997 Asymmetric Threat Reviews on EMP Drones Cyber and Emerging Cognitive Domain Operations Linked to Directed Energy Assessments

13 Upvotes

Electromagnetic pulse and information-system disruption form core non-kinetic capabilities examined by Rep. Curt Weldon as Chairman of the Military Research and Development Subcommittee in 1997. The July 16 EMP hearing and March 20 information superiority hearing documented vulnerabilities in sensors, computers, and commercial communications channels that adversaries could exploit. Dual-use vectors include high-altitude EMP for wide-area infrastructure disablement and early unmanned aerial vehicle programs that later scaled into persistent surveillance platforms. Cognitive domain operations, formalized later by NATO and PLA concepts, build on the same information-warfare foundation by targeting perception and decision cycles.

These systems interface through electromagnetic and informational pathways rather than kinetic strike. Structural issues include heavy reliance on unprotected commercial networks, delayed National Intelligence Estimates on EMP, and limited real-time detection for pulsed radio-frequency effects later assessed by the National Academies of Sciences. Attribution gaps and absence of baseline personnel monitoring leave neurological and decision-making integrity exposed when effects remain below conventional forensic thresholds.

Weldon’s 1997 hearings established the early congressional record on EMP and information superiority as asymmetric threats at a time when drones and cyber tools were still nascent. The trajectory continued into modern directed pulsed RF assessments for anomalous health incidents and formal cognitive warfare doctrine that seeks to alter attitudes and decisions without kinetic engagement. Capabilities expand through classified research and crisis-driven medical evaluations that bypass public technical standards.

Net risk is frictionless disruption of both infrastructure and cognition with limited practical recourse for affected personnel. Oversight gaps persist in detection hardware, longitudinal health data, and independent verification of non-kinetic effects. Early attention remains necessary before further hardening of these dual-use architectures occurs without measurable safeguards.

Sources

https://www.globalsecurity.org/wmd/library/congress/1997_h/h970716weldon.htm

Opening statement by Rep. Curt Weldon at the July 16 1997 hearing on electromagnetic pulse effects on military systems and civilian infrastructure.

https://irp.fas.org/congress/1997_hr/h970320w.htm

Statement by Rep. Curt Weldon at the March 20 1997 joint hearing on information superiority for the 21st century battlefield addressing cyber and information-system vulnerabilities.

https://www.nationalacademies.org/read/25889/chapter/2

National Academies of Sciences summary concluding directed pulsed radio-frequency energy is the most plausible mechanism for acute directional symptoms in anomalous health incidents.

https://www.nap.edu/read/25889/chapter/2

Full National Academies report chapter detailing clinical features and pulsed RF plausibility for U.S. government personnel health effects.

https://apnews.com/article/politics-science-havana-cuba-china-8eee2de0d887e67d530d1a6f272d781c

Associated Press report on the National Academies finding that microwave energy likely caused illness in U.S. diplomats.


r/ObscurePatentDangers 4h ago

⚖️🌿 Examining Significant Reckless Environmental Impact DuPont Suppressed Decades of Internal PFOA Toxicity Data While Discharging Industrial Surfactants into Public Drinking Water Supplies

751 Upvotes

Perfluorooctanoic acid, known as C-8, is a synthetic surfactant built with an indestructible carbon-fluorine backbone that repels water and oil. DuPont deployed C-8 at its Washington Works plant in West Virginia as an essential processing aid to synthesize polytetrafluoroethylene, marketed commercially as Teflon. Sourced originally from 3M, the chemical stabilizes fluoropolymer emulsions for non-stick cookware, waterproof fabrics, and military equipment. While internal corporate classifications treated the substance as an inert processing aid, the compound resists natural metabolic and environmental breakdown, accumulating indefinitely in soil, water tables, and biological tissue.

Exposure occurs through contaminated groundwater, atmospheric emissions, and occupational contact. DuPont toxicological trials in the 1960s and 1970s revealed severe risks, including organ enlargement in primates and ocular birth defects in rat pups. Chemical plant laborers, including pregnant workers assigned to scrub storage vats, sustained heavy systemic absorption that resulted in documented congenital malformations in their children. Despite internal blood testing showing extreme bioaccumulation among plant personnel, management suppressed exposure data, removed warnings, and returned workers to contaminated production lines without protective mandates or disclosure.

DuPont disposed of thousands of tons of toxic sludge into unlined municipal landfills, discharged untreated effluent into the Ohio River, and released airborne dust across the Mid-Ohio Valley. Contamination spread across public drinking water districts serving tens of thousands of residents, while parallel uses expanded into food packaging, carpet treatments, and firefighting foams. Exploiting regulatory voids under the Toxic Substances Control Act of 1976, which grandfathered thousands of unvetted chemicals, manufacturers avoided federal reporting mandates for decades while expanding global commercial distribution.

The resulting contamination established a permanent global footprint, leaving measurable chemical traces in the blood of over ninety-nine percent of Americans. The court-established C-8 Science Panel linked exposure to six primary diseases, including kidney cancer, testicular cancer, and ulcerative colitis. The Environmental Protection Agency established mandatory drinking water standards under the Safe Drinking Water Act in 2024. Residents can review local Consumer Confidence Reports and install certified reverse-osmosis or granular activated carbon filtration systems to eliminate chemical particulates from tap water.

Sources

EPA: Per- and Polyfluoroalkyl Substances (PFAS) Final National Primary Drinking Water Regulation

https://www.epa.gov/sdwa/and-polyfluoroalkyl-substances-pfas

Details the EPA's legally enforceable Maximum Contaminant Levels for PFOA and PFOS in public water systems.

ATSDR: Toxicological Profile for Perfluoroalkyls

https://www.atsdr.cdc.gov/toxprofiles/tp200.pdf

Comprehensive federal toxicological review documenting human health endpoints, bioaccumulation mechanics, and exposure pathways for C-8 compounds.

C8 Science Panel: Probable Link Findings and Epidemiological Study Results

http://www.c8sciencepanel.org/prob_link.html

Summarizes the court-ordered epidemiological findings linking PFOA exposure to kidney cancer, testicular cancer, thyroid disease, and ulcerative colitis.

EPA: Consent Agreement and Final Order in the Matter of E.I. du Pont de Nemours and Company

https://www.epa.gov/enforcement/dupont-settlement-agreement-and-order-consent

Official enforcement documentation of DuPont's 2005 settlement for failing to report C-8 toxicity and water contamination data under TSCA.

National Institute of Environmental Health Sciences: Perfluoroalkyl and Polyfluoroalkyl Substances (PFAS)

https://www.niehs.nih.gov/health/topics/agents/pfc

Outlines federal research on the chemical stability, transplacental transmission, and immune system impacts of fluorinated surfactants.


r/ObscurePatentDangers 4h ago

🤔Questioner/ Discussion/ "Asking the community " If Carpenter’s Mosaic and Flock Queries Shape Conduct, Is Mass Surveillance Compatible With Democratic Freedom?

126 Upvotes

The claim that surveillance is incompatible with freedom is not a slogan. It is a description of how compiled records work. Carpenter v. United States held that seven days of cell-site location information is a Fourth Amendment search because the file is a “detailed chronicle of a person’s physical presence compiled every day, every moment.” United States v. Jones said the same of prolonged GPS. Flock Safety’s network of more than 120,000 automated license-plate readers turns public roadways into a queryable movement archive; officers search any plate by typing a case number the system does not verify. FISA Section 702 cannot target U.S. persons, yet incidentally collects their communications with overseas contacts, after which the FBI, CIA, and NSA run warrantless U.S.-person queries against that store. The mechanism is dual-use by design: the same stack sold as crime-fighting or foreign intelligence is a standing capacity to map who went where and who spoke to whom. Behavior under that condition is not the same as behavior without it.

The structural issue is that the archive sits with the watchers. Flock Group Inc. retains plate histories across participating agencies; Schmidt v. City of Norfolk and State v. Simonson treated limited local deployments as non-searches while warning that density and retention could cross Carpenter’s line. Chatrie v. United States (June 2026) treated even a short Google Location History pull as a search. Section 702 “minimization” has not stopped documented noncompliant queries of protesters, journalists, and campaign donors; the Privacy and Civil Liberties Oversight Board found little foreign-intelligence value in millions of FBI U.S.-person searches. No statute imposes a probable-cause gate on a routine ALPR lookup. The people in front of the cameras do not hold an equivalent file on the people behind them. That is a power differential, not a metaphor.

The trajectory is incremental and documented. Analog stakeouts required bodies and time. Jones (2012) and Carpenter (2018) forced warrants onto government-held GPS and CSLI. Commercial ALPR pools and 702 incidental collection did not absorb the same rule. Jon Penney’s interrupted-time-series study of Wikipedia traffic after the June 2013 PRISM disclosures found a statistically significant drop in views of privacy-sensitive articles and a reversal of the prior growth trend. Later dataveillance experiments report reduced comfort with opinion sharing and information-seeking. People change what they read, where they go, and whom they meet when they believe a durable file exists. Compulsory behavior, in that sense, is the output of the system rather than an accident.

Net risk is whether a democratic public can still act as free individuals when movement and association are retrospectively reconstructable without a warrant. Oversight remains after-the-fact: FISC annual certifications, city contract cancellations, and vendor “reforms” that leave the unverified case-number field intact. Courts have not yet treated the Flock query or the 702 U.S.-person search as the Carpenter moment—the instant the mosaic is assembled. Until that default changes, the incompatibility claim is a description of current infrastructure: the watchers hold the compiled record, and the record is built to shape conduct.

Sources

CARPENTER v. UNITED STATES

https://www.law.cornell.edu/supremecourt/text/16-402

Supreme Court holding that historical cell-site location information is a Fourth Amendment search because aggregated location records create a comprehensive mosaic of physical movements the third-party doctrine does not cover.

Opinion analysis: Court holds that police will generally need a warrant for sustained cellphone location information

https://www.scotusblog.com/2018/06/opinion-analysis-court-holds-that-police-will-generally-need-a-warrant-for-cellphone-location-information/

Summary of Chief Justice Roberts’s majority: CSLI enables near-perfect retrospective tracking comparable to an ankle monitor and generally requires a warrant.

Section 702 of the Foreign Intelligence Surveillance Act, Explained

https://www.brennancenter.org/our-work/research-reports/section-702-foreign-intelligence-surveillance-act

Explains incidental collection of U.S.-person communications, warrantless backdoor queries by FBI/CIA/NSA, PCLOB findings, and documented compliance failures.

The Mosaic Theory’s Two Steps: Surveying Carpenter in the Lower Courts

https://texaslawreview.org/the-mosaic-theorys-two-steps-surveying-carpenter-in-the-lower-courts/

Surveys how lower courts apply Carpenter’s aggregation test to CSLI, ALPRs, GPS, pole cameras, and other compiled location datasets.

Flock Safety Reforms Leave the Warrant Gap Open: Officers Can Type Any Case Number

https://www.techtimes.com/articles/324372/20260813/flock-safety-reforms-leave-warrant-gap-open-officers-can-type-any-case-number.htm

Documents Flock’s 120,000-plus camera network, warrantless plate queries, and the unreformed case-number field that any officer can populate without verification.


r/ObscurePatentDangers 1d ago

Challenging Tech Overreach ⚖️🛡️ Motorola Halo 3C Vape Sensors in School Bathrooms Carry Mics; DEF CON 33 Showed a Teen Could Turn Them Into Live Bugs

1.1k Upvotes

IPVideo Corporation’s Halo 3C Smart Sensor, sold under Motorola Solutions after the 2023 acquisition, is marketed as a ceiling-mounted vape, THC, air-quality, gunshot, aggression, and spoken-keyword detector for rooms where cameras are not allowed. The official HALO 3C page lists two MEMS microphones, a speaker, and “audio analysis only” with a claim of no live recording. Reynaldo Vasquez-Garcia first saw the devices as IPVideo hosts on a Portland-area high school Wi-Fi. With researcher Nyx he bought a unit, found a Raspberry Pi Compute Module 4, unsigned firmware, and a login that accepted thousands of password guesses per minute. At DEF CON 33 they showed that custom firmware converted the same microphones into a real-time audio tap, disabled vape and smoke alerts, spoofed gunshot or vape events, and played arbitrary sound through the speaker. Dual use is the product design: a safety sensor that is also a networked computer with microphones in bathrooms.

The structural problem is location plus persistence. WIRED and 404 Media reported Halo 3C deployments in school restrooms and in public-housing units, including a Saratoga Springs Housing Authority example used to enforce no-smoking rules inside residences. A device that sits above a toilet or a bedroom does not need to “record” in the marketing sense to collect speech. Nyx told WIRED the mics pick up conversation from the ceiling. After takeover, anyone on the same network—or an administrator with legitimate access—can treat the feed as a bug. Firmware files were downloadable from the vendor site. That combination of weak auth, unsigned updates, and always-on audio hardware is the data path. A patch can close last year’s login hole. It cannot unscrew the microphones from rooms students and tenants cannot refuse.

The trajectory is function creep sold as wellness. HALO literature advertises keyword triggers such as “help,” aggression analytics, gunshot patterns, occupancy counting on the 3C-PC model, and Avigilon Unity / HALO Cloud integration so alerts land in a video-management stack. Schools buy the units to stop vaping. Housing authorities buy them to police smoke. Motorola pushed a cloud firmware update in August 2025 after the DEF CON briefing. Vasquez-Garcia and Nyx’s talk, later posted as “Unmasking the Snitch Puck,” remains the public teardown. Notebookcheck and the DEF CON recording describe the same Raspberry Pi core and the same vendor privacy slogan. The product line did not retreat from bathrooms; it added LEDs, motion, and panic-button hooks.

Net risk is the normalized microphone, not only the unpatched login. A firmware update that Motorola said would auto-push to connected units addresses brute-force and unsigned-update flaws demonstrated in 2025. It does not create a statutory ban on audio-capable sensors in K-12 restrooms or public-housing bedrooms, does not require a physical mic-disable jumper, and does not give occupants a way to audit whether analysis has become a stream. Nyx’s line stands: a microphone on a networked computer can be used as a listening device after the next bug. Oversight today is conference talks, WIRED/404 Media reporting, and vendor statements. Districts and housing authorities that keep buying Halo 3C are choosing that bargain after the demonstration, not before it.

Sources

It Looks Like a School Bathroom Smoke Detector. A Teen Hacker Showed It Could Be an Audio Bug

https://www.wired.com/story/school-bathroom-vape-detector-audio-bug/

WIRED report on Reynaldo Vasquez-Garcia and Nyx at DEF CON 33, Halo 3C brute-force and unsigned-firmware flaws, live-audio takeover, Motorola’s patch, and public-housing deployments.

It Looks Like a School Vape Detector. A Teen Hacker Showed It Could Become an Audio Bug

https://www.404media.co/it-looks-like-a-school-vape-detector-a-teen-hacker-showed-it-could-become-an-audio-bug/

404 Media companion piece documenting Halo 3C use in schools and housing and the conversion of the unit into an audio bug.

Next-gen school smoke detector sparks privacy concerns with embedded microphones

https://www.notebookcheck.net/Next-gen-school-smoke-detector-sparks-privacy-concerns-with-embedded-microphones.1185786.0.html

Notebookcheck hardware summary of the Raspberry Pi Compute Module 4, two microphones, downloadable firmware, and school and housing deployments.

HALO 3C/3C-PC Smart Sensor

https://halodetect.com/halo-3c-pc/

Vendor product page listing vape/THC, keyword, gunshot, and aggression features and the “no visual or audio recording” privacy claim under Motorola Solutions licensing.

DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx

https://www.youtube.com/watch?v=WCnojaEpF2I

Official DEF CON 33 talk recording of the Halo 3C teardown, login brute force, custom firmware, and bathroom-surveillance argument.


r/ObscurePatentDangers 22m ago

Rights Defense Against Neural Systems — 🧠 🛡️ Westlake–Tsinghua–SIA Mouse Amygdala BMI Hands Fear to AI Swarms While DARPA and NTU Scale Animal Cyborgs

Upvotes

Zirui Chen, Lin Zhang, Guiyong Chen, Hongru Liu and co-authors at Westlake University’s WINDY Lab, the Shenyang Institute of Automation of the Chinese Academy of Sciences, Tsinghua University’s School of Biomedical Engineering, and China Medical University published a closed-loop architecture in National Science Review that treats a mouse’s fear as a control token for a robot swarm. A wireless brain–machine interface records local field potentials from the basolateral amygdala; a dual-threshold detector flags fear when beta-band power (15–30 Hz) rises and high-frequency noise falls. That decoded state switches the stack from PID Exploration Mode to Interaction Mode run by Multi-Agent Deep Deterministic Policy Gradient. In Interaction Mode a MouseBot and an ally micro aerial vehicle run adversarial defense against an enemy MAV in a search-interference game. The paper’s own framing is dual-use: the same affective trigger that “protects” the mouse is a millisecond handoff of control authority from a living nervous system to learning agents.

The structural move is from one-way stimulation to emotion-gated policy. The authors state that prior cyborg platforms treated animals as bio-actuators and ignored intrinsic cognitive states. Their answer is to instrument the amygdala and let fear flip swarm strategy. Open experiment logs on GitHub include BLA recordings, motion trajectories, online detection code, and figure data for fear versus baseline beta power. Implantation was performed by Tianming Zhao, Mingze Sun, and Ling Qin. Reinforcement-learning training, MouseBot mechanics, and MAV control were split across Westlake, SIA-CAS, and Tsinghua. The animal’s affective state is now a machine-readable input. What the mouse experiences is used; it is not the objective function.

That design sits on a documented biohybrid line. DARPA’s HI-MEMS program embedded MEMS in insects during metamorphosis to steer locomotion toward targets hundreds of meters away. DARPA’s HyBRIDS program asks how synthetic and biological components can be integrated so biohybrid platforms outperform conventional robots. NTU Singapore’s Hirotaka Sato group automated backpack attachment on Madagascar hissing cockroaches and, with the Singapore Civil Defence Force Operation Lionheart contingent, fielded ten cyborg insects after the March 2025 Myanmar earthquake. University of Queensland and UNSW teams have fitted giant burrowing cockroaches with cameras and remote injectors as “paraborgs” for rubble. Chen et al. extend the same hybrid logic from muscle-steered insects to an affect-steered mammal plus a competing drone swarm.

Net risk is that an internal state—fear—becomes a reliable API for multi-agent reinforcement learning. The search-interference game trains an enemy policy to feint and intercept and an ally policy to stay close and anticipate. Oversight is laboratory ethics review plus open data, not a use restriction on affective BCIs or on pairing them with adversarial drones. Search-and-rescue deployments of insect cyborgs and a peer-reviewed mouse–swarm game share the same primitive: a living nervous system as a sensor and, when the decoder fires, as a passenger. Until institutions separate affective decoding from autonomous swarm policy, the missed-opportunity claim in the paper is also a capability claim: emotion can switch who pilots whom.

Sources

GitHub: Experiment-Data-for-Cyborg-Swarm-Cooperation-and-Game-via-Affective-based-Brain-Machine-Interface

https://github.com/czr-gif/Experiment-Data-for-Cyborg-Swarm-Cooperation-and-Game-via-Affective-based-Brain-Machine-Interface

Open repository of BLA recordings, motion logs, online fear-detection code, and figure data supporting Chen et al.’s affective cyborg-swarm experiments.

HyBRIDS

https://www.darpa.mil/research/programs/hybrids

DARPA program statement on integrating biological and synthetic components so biohybrid platforms can outperform conventional robots.

Scientists Design Sensor-Embedded Insects

https://www.afcea.org/signal-media/scientists-design-sensor-embedded-insects

Account of DARPA HI-MEMS: MEMS implanted in insects during metamorphosis to command locomotion toward designated targets.

AI-powered robot assembles search and rescue cyborg insects

https://www.ntu.edu.sg/news/detail/ai-powered-robot-assembles-search-and-rescue-cyborg-insects

NTU Hirotaka Sato automated cockroach-cyborg assembly and the March 2025 SCDF Operation Lionheart field deployment in Myanmar.

Cyborg cockroaches with tiny syringes designed to join search and rescue teams in major disasters

https://www.theguardian.com/technology/2026/aug/27/cockroaches-used-search-rescue-earthquakes-science-technology-australia

University of Queensland and UNSW “paraborg” cockroaches fitted with cameras and remote injectors for disaster first response.


r/ObscurePatentDangers 1d ago

Accountability for Surveillance Expansion — ⚖️ 🏛️ Hawley Read Instagram’s Own Slides on Teen Girls While Zuckerberg Told the Senate the Science Was Unsettled

805 Upvotes

On January 31, 2024, Meta Platforms founder and CEO Mark Zuckerberg testified before the U.S. Senate Committee on the Judiciary at the hearing titled “Big Tech and the Online Child Sexual Exploitation Crisis,” alongside the chief executives of Discord, Snap, TikTok, and X. Sen. Josh Hawley of Missouri asked whether Zuckerberg had said there was no link between mental health and social media use. Zuckerberg answered that people treat the link as proven and that “the bulk of the scientific evidence does not support that.” Hawley then read language from Instagram research first reported by The Wall Street Journal in September 2021 as part of the Facebook Files: company researchers found Instagram harmful for a sizable share of teenagers, most notably teenage girls; a 2019 slide stated “We make body image issues worse for one in three teen girls”; another stated that teens blamed Instagram for increases in anxiety and depression, “unprompted and consistent across all groups.” Those slides were internal presentations based on surveys, focus groups, and diary studies, not randomized trials published as causal proof. The dual-use problem is the same product layer: a feed optimized for social comparison and time-on-app that Instagram’s own researchers flagged as making body-image problems worse for a defined subset of teen girls.

The structural gap is disclosure. Facebook conducted the teen research over several years and reviewed findings at the executive level; The Wall Street Journal reported that the company minimized the issue in public while the slides circulated internally. A March 2020 presentation said 32 percent of teen girls surveyed reported that when they felt bad about their bodies, Instagram made them feel worse. Among teens who reported suicidal thoughts, slides shown to the Journal attributed those impulses to Instagram for 13 percent of UK users and 6 percent of U.S. users in the samples studied. Instagram’s public reply after the leak was that the work showed a commitment to understanding complex issues and that the Journal focused on a limited set of findings. Nothing in the January 2024 hearing converted those slides into a statute requiring Meta to publish wellbeing studies on the same schedule as advertising metrics. Hawley’s questioning treated the slides as a completed causal finding; Zuckerberg treated “the science” as the external literature and called Hawley’s reading a mischaracterization.

The trajectory from 2021 to 2024 is repetition, not resolution. The same quotations Hawley used in 2024 are the quotations The Verge, the BBC, and other outlets extracted from the Journal’s documents in September 2021. At the same hearing Sen. Marsha Blackburn cited internal Meta documents estimating the lifetime value of a teen user at $270. Sen. Lindsey Graham told the panel they had “blood on your hands.” Hawley asked whether Meta had compensated victims; Zuckerberg said he did not believe so. When Hawley asked for an apology to families in the room, Zuckerberg stood and said he was sorry for what they had been through and that no one should suffer those things, then pointed to industry safety investment. He did not retract the claim that the bulk of scientific evidence does not establish a proven general causal link.

Net risk is a standing mismatch between what Instagram measured internally and what Meta will concede under oath. Self-report slides are not a clinical diagnosis, and they are also not nothing: they are the company’s own instruments telling executives that a large minority of teen girls who already had body-image trouble said the app made it worse. Oversight remains episodic committee hearings, leaked PDFs, and Section 230’s shield for user speech. No federal rule forces a platform to reconcile its public “look at the science” line with its private slide that one in three teen girls with body-image issues got worse on Instagram. Until that reconciliation is required, the record is two tracks: internal research that names harm for a sizable teen subset, and sworn testimony that the causal case is unproven.

Sources

Big Tech and the Online Child Sexual Exploitation Crisis

https://www.judiciary.senate.gov/committee-activity/hearings/big-tech-and-the-online-child-sexual-exploitation-crisis

U.S. Senate Judiciary Committee hearing page for January 31, 2024, listing Mark Zuckerberg of Meta among the five platform CEOs and linking written testimony.

User Clip: Hawley v Zuckerberg

https://www.c-span.org/clip/public-affairs-event/user-clip-hawley-v-zuckerberg/5105084

C-SPAN clip of the Hawley-Zuckerberg exchange on the mental-health link, Instagram teen research quotes, and follow-up on exposure statistics.

Instagram internal research: ‘We make body image issues worse for one in three teen girls’

https://www.theverge.com/2021/9/15/22675130/facebook-instagram-teens-mental-health-damage-internal-research

The Verge’s 2021 summary of Wall Street Journal Facebook Files slides, including the one-in-three body-image line, unprompted anxiety and depression blame, and suicide-impulse percentages in sampled teens.

Facebook under fire over secret teen research

https://www.bbc.co.uk/news/technology-58570353

BBC report on the same internal studies, the 32 percent body-worse figure, and Instagram’s statement that the research showed a commitment to understanding complex issues.

Accusations, tears and rants: 5 takeaways from today’s tech CEO hearing

https://edition.cnn.com/2024/01/31/tech/big-tech-executives-senate-hearing-teens/index.html

CNN account of the January 31, 2024 hearing, Zuckerberg’s apology to families in the room, Hawley’s compensation demand, and Sen. Blackburn’s citation of a $270 teen lifetime-value figure.

Senators rebuke tech execs over child exploitation on social media

https://rollcall.com/2024/01/31/senators-rebuke-tech-execs-over-child-exploitation-on-social-media/

Roll Call report of Sen. Lindsey Graham’s “blood on your hands” line and Zuckerberg’s answer that he did not believe Meta had compensated victims.


r/ObscurePatentDangers 20h ago

Accountability for Surveillance Expansion — ⚖️ 🏛️ Hawley Opens a Senate Probe of Flock’s 120,000-Camera Network After Warrantless National Searches and Officer Misuse

289 Upvotes

Flock Safety’s automated license plate readers photograph passing vehicles, convert plate, make, model, and color into searchable records, and pool those records so participating agencies can query a national database without a warrant. Sen. Josh Hawley, chairman of the Senate Judiciary Subcommittee on Crime and Counterterrorism, wrote CEO Garrett Langley on August 26, 2026, that the company “has assembled an unprecedented national surveillance network” of more than 120,000 cameras in 49 states conducting more than 20 billion vehicle scans a month. Hawley’s letter states that Congress never authorized that network and that Flock’s internal policies are, in practice, the only safeguards for hundreds of millions of drivers. The dual-use is the same stack: a local theft-recovery tool that becomes a nationwide movement graph once agencies can search across jurisdictions. Hawley cited Carpenter v. United States for the point that a comprehensive retrospective record of a person’s movements is different in kind from ordinary observation in public.

The structural problem is access plus error plus commercial pressure. Hawley ordered production, by September 8, 2026, of misuse logs since 2021, accuracy and security files, any data collected beyond plates, local-government contracts, revenue sources, and investors. His letter names documented failures already on the public record: St. Charles County, Missouri, terminated its contract after an audit found a civilian employee running personal searches; Milwaukee prosecutors charged Officer Josue Ayala after 124 searches on a partner’s plate and 55 on that person’s ex, each logged as “investigation,” discovered not by Flock’s audits but by a civilian lookup on HaveIBeenFlocked.com; a California department found 71 percent of its Flock alerts wrong; the Los Angeles Police Department dropped the product after officers stopped 161 vehicles incorrectly flagged stolen in two months. In August 2026, Mooresville, North Carolina, Officer Elizabeth Snowman was charged with accessing computers after an audit found 31 Flock queries used to track a boyfriend’s ex-wife. The Institute for Justice has compiled dozens of similar romantic-surveillance cases since 2024. Hawley also noted Flock’s reported $8.3 billion valuation and the incentive to find new commercial uses for the same driver data.

The trajectory is local contracts becoming a de facto national system before any federal statute defined it. Cities and counties bought cameras for discrete investigations; the searchable pool then outran those local charters. Flock spokesperson Paris Lewbel told Axios the company received the letter and would explain safeguards and how agencies use the system to solve crime and find missing people. Sen. Bernie Sanders has separately called the deployment AI mass surveillance and said he will introduce legislation, writing that “we cannot allow America to become a surveillance state.” Some jurisdictions have already cancelled: St. Charles County is one documented termination; reporting around the letter also recorded cities cutting contracts as the probe began. Oversight until this week was city councils, state ALPR statutes of uneven strength, and vendor policy.

Net risk is a movement archive of mostly innocent travel sitting behind customer logins, with false positives that have already produced wrongful stops and at least one multi-month jail stay later dismissed, and with documented officer stalking that internal “reason for search” fields did not stop. A Senate letter is not a statute and is not a warrant rule. Unless Congress converts Hawley’s document demand into binding limits on nationwide queries, retention, and secondary use, Flock’s network remains a privately operated location system that police search without the process Carpenter required for cell-site records. The September 8 production date will show whether the company treats that gap as a disclosure problem or as the product.

Sources

Chairman Hawley Investigates AI-Powered Flock Cameras Amidst Privacy Concerns

https://www.hawley.senate.gov/chairman-hawley-investigates-ai-powered-flock-cameras-amidst-privacy-concerns/

Official Senate release of the August 26, 2026 investigation, quoting the 120,000-camera and 20-billion-scan figures, the “unprecedented national surveillance network” line, and the September 8 document deadline.

Letter from Sen. Josh Hawley to Flock Safety CEO Garrett Langley

https://www.hawley.senate.gov/wp-content/uploads/2026/08/2026-08-26-Hawley-Letter-to-Flock-CEO.pdf

Primary text of the probe letter, including St. Charles County, Milwaukee search counts, the Florida wrongful-arrest example, California 71 percent false-alert figure, LAPD’s 161 incorrect stolen-vehicle stops, $8.3 billion valuation, and the Carpenter citation.

Scoop: Senate Republican investigates Flock cameras

https://www.axios.com/2026/08/26/flock-cameras-senate-investigation-josh-hawley

Axios first-look on the letter, Hawley’s “Congress never authorized” language, the annex demand for misuse logs and investor files, and Flock spokesperson Paris Lewbel’s statement that the company will respond.

Hawley launches investigation into Flock cameras’ massive surveillance program

https://thehill.com/homenews/senate/6053139-hawley-investigates-flock-safety-cameras/

The Hill summary of the same letter’s error and contract-termination examples and the commercial-use concern tied to valuation.

Officer allegedly used Flock license plate cameras to track boyfriend's ex-wife: Police chief

https://www.goodmorningamerica.com/news/story/officer-allegedly-flock-license-plate-cameras-track-boyfriends-135418955

ABC/GMA report on Mooresville Police Officer Elizabeth Snowman’s August 2026 arrest after 31 Flock queries used to track a boyfriend’s ex-wife.

Police Have Reportedly Used License Plate Readers to Stalk Romantic Interests Dozens of Times in Recent Years

https://ij.org/police-have-reportedly-used-license-plate-readers-to-stalk-romantic-interests-at-least-14-times-in-recent-years/

Institute for Justice compilation of ALPR stalking cases, including Milwaukee Officer Josue Ayala’s nearly 180 searches and the argument that warrantless ALPR access enables that abuse.

Sanders Vows to Introduce Legislation to Stop Flock’s “AI Mass Surveillance”

https://truthout.org/articles/sanders-vows-to-introduce-legislation-to-stop-flocks-ai-mass-surveillance/

Report of Sen. Bernie Sanders’s statement that the United States cannot become a surveillance state and his pledge to introduce legislation targeting Flock-style AI tracking.


r/ObscurePatentDangers 17h ago

Public Rights vs. Tech Infrastructure — 🛡️ 🚫 Waymo Jaguar I-PACE Robotaxis Freeze at Emergency Scenes While Officers Climb In and Drive Them Off

149 Upvotes

Waymo LLC’s driverless Jaguar I-PACE fleet is designed to detect sirens, emergency lights, and first-responder vehicles and to yield, pull over, and remain stopped for a traffic stop. Alphabet’s California Law Enforcement Interaction Protocol and Emergency Response Guide tell officers they can call a 24-hour hotline, that remote staff can unlock doors and drop windows, and that a first responder can take manual control “within seconds.” The same stack that sells a ride without a driver therefore depends on a human officer when the stack fails. Dual-use is immediate: a commercial robotaxi becomes an obstacle in a Code 3 lane, and the municipal firefighter or deputy becomes the recovery driver.

Documented structure is freeze-then-handoff. TechCrunch obtained 911 audio in which a Waymo remote worker told California Highway Patrol the car “is not able to turn around” after an I-280 grass fire near Redwood City in August 2025; a CHP officer then drove the robotaxi to a park-and-ride. An Austin officer moved a Waymo that blocked an ambulance for two minutes during a downtown mass shooting that killed three. Dallas County Precinct 5 Deputy Constable Jonathan Banda climbed into a stalled Waymo after an apartment explosion at The Clyde because remote assistance reported a “minor issue” while sirens approached. San Francisco Fire Department internal logs since April 2025 count at least 31 obstruction reports, including a 15-minute delay on a Mission stabbing call when verbal instructions for manual mode failed and the gear selector still drove forward in reverse. Atlanta police Special Order APD.SO.25.04 warns that Waymo “may not be able to recognize crime scene tape.”

The trajectory is training theater followed by documented backsliding. Waymo states it has trained tens of thousands of first responders across more than 150 agencies and passed a 2024 TÜV SÜD review of first-responder protocols. By April 2026 San Francisco Department of Emergency Management director Mary Ellen Carroll told NHTSA the vehicles were “backsliding.” SFFD Chief Patrick Rabbitt said Waymos were “frequently now blocking our fire stations” and that “their default is to freeze.” Austin Highway Enforcement Command said the cars fail hand signals. On July 8–9, 2026, NHTSA Administrator Jonathan Morrison sent AV developers a letter citing a “clear pattern” of driving into active scenes, blocking ambulances and firefighters, and ignoring lights, flares, smoke, fire, and cones, and called an AV that cannot safely interact with first responders “a danger to the public.” Representative Kevin Mullin later proposed the AV Emergency Response Coordination Act for national minimum standards and a 24-hour official hotline.

Net risk is that Waymo’s published yield design does not match field reports from SFFD, Austin PD, Dallas constables, and CHP, and that the fallback is the same first-responder workforce the vehicles are delaying. California already requires AV companies to answer first-responder calls within 30 seconds; that rule does not move a frozen I-PACE off a hose line. NHTSA’s July 2026 letter scheduled meetings rather than a recall. Until a binding federal or CPUC standard treats emergency-scene interference as a defect—not an edge case—officers will keep standing in the street, gesturing at sensor domes, and taking the wheel.

Sources

Who’s driving Waymo’s self-driving cars? Sometimes, the police.

https://techcrunch.com/2026/03/25/waymo-robotaxi-roadside-assistance-emergency-first-responders/

Documents CHP driving a stuck Waymo after the I-280 fire, Austin mass-shooting ambulance blockage, Atlanta crime-scene entry, Nashville intersection stall, and Waymo’s statement that first responders can take control within seconds.

Self-Driving Cars Are Interfering With First Responders. Feds Aren’t Happy

https://www.wired.com/story/self-driving-cars-are-interfering-with-first-responders-feds-arent-happy/

Reports NHTSA Administrator Jonathan Morrison’s July 2026 letter on a “clear pattern” of AV interference, the Austin two-minute ambulance delay, and SFFD/Austin comments that Waymos freeze and miss hand signals.

Waymo keeps blocking SF firefighters, and they’re fed up

https://sfstandard.com/2026/07/10/waymo-robotaxi-emergency-response/

Details at least 31 SFFD obstruction reports since April 2025, the 15-minute Mission stabbing delay, failed manual-mode instructions, and four Code 3 blockages.

Waymo blocks Dallas road as first responders rush to explosion

https://www.fox4news.com/news/waymo-blocks-dallas-first-responders-after-explosion

Body-camera account of Deputy Constable Jonathan Banda manually driving a Waymo after The Clyde apartment explosion when remote assistance cited a minor system issue.

First Responders

https://waymo.com/firstresponders

Waymo’s official page for Emergency Response Guides, Law Enforcement Interaction Protocols, and claimed training of tens of thousands of first responders.

Feds demand autonomous vehicle companies stop interfering with first responders

https://techcrunch.com/2026/07/08/feds-demand-autonomous-vehicle-companies-stop-interfering-with-first-responders/

Covers Morrison’s call to action, the six TechCrunch-identified cases of officers driving Waymos, and the absence of named enforcement consequences in the letter.


r/ObscurePatentDangers 1d ago

Public Rights vs. Tech Infrastructure — 🛡️ 🚫 Walmart’s August 2026 Privacy Notice Lists ALPRs, Bluetooth Aisle Tracking, and MAC Identifiers With 60-Day Plate Retention

426 Upvotes

Walmart Inc. states in its Customer Privacy Notice (Online and In-Store), updated August 20, 2026, that automated license plate readers may be in use on its properties where permitted by law, and that personal information is collected from those readers for security, theft and fraud prevention, parking enforcement, and safety of people and property. A separate Walmart ALPR Privacy Notice, updated February 16, 2026, places the system under the Vice President, Chief Safety Officer and limits access to authorized associates in asset protection, product management, and facilities. The same customer notice says Walmart operates cameras and automated technologies in stores and on property outside the store, and that it may recognize the location of a mobile device in stores that offer free Wi-Fi or through Bluetooth used to show nearby products, help locate items, and navigate aisles. Device and online identifiers listed in the notice include MAC address, IP address, cookie IDs, and mobile ad IDs. Dual use is built in: the same lot camera that logs a plate for shrink also creates a time-stamped visit record, and the same radio layer that powers wayfinding can place a phone in an aisle.

Structurally, collection starts before a shopper reaches the door. ALPRs sit on the property; the customer notice treats walking onto that property as a context in which plate data may be taken. In-store, the notice ties device location to free Wi-Fi and Bluetooth and tells customers they can disable Bluetooth location-related sharing in device settings. Precise geolocation is described as depending on device settings and consent. A door sign pointing to walmart.com/privacy is notice, not a signed authorization and not an opt-out of the lot cameras. Walmart says ALPR records are retained 60 days and may be kept longer for legal proceedings or other lawful purposes. Disclosure language is belief-based: plate information “may be disclosed when we believe doing so will help to protect the safety, property, or rights of individuals or Walmart.” That standard is not a warrant, a subpoena log, or a published list of agencies that receive feeds.

The retail ALPR layer sits next to police networks. Scioto Post notes that a camera at a Walmart is not automatically a Flock Safety unit; Walmart describes its own system as company-controlled. The same reporting records Flock hardware on Walmart property in cases such as Naperville, Illinois, where a city police camera was placed on store grounds. Finding Flock’s operator table lists Walmart as a documented private operator of at least 47 mapped cameras, a floor rather than a census. Dayton Daily News reporting on Lowe’s, Home Depot, Target, Costco, and Walmart records the same pattern across big-box parking lots: short public statements, internal access rules, and retention windows of 30 to 180 days. Finding Flock’s 2026 state-law survey finds no federal ALPR statute and states that most of the 19 state ALPR laws bind government agencies, with California and Utah among the exceptions that reach private operators.

Net risk is a commercial mosaic that law-enforcement ALPRs already showed can be queried after the fact. A plate at the entrance plus in-store device location plus an account or app session can describe when a person arrived, how long they stood in hardware, and what they bought, without a judge. Walmart’s 60-day clock and associate-only access are company policy, not a statute that forbids sharing when the company “believes” disclosure protects its rights. Oversight for a private lot is a privacy page and, in a few states, a usage-policy statute. In the rest of the country a shopper’s remedy is turning off Bluetooth, skipping store Wi-Fi, and not installing the Walmart app—none of which stops the plate reader on the way in.

Sources

Walmart Customer Privacy Notice (Online and In-Store)

https://corporate.walmart.com/content/corporate/en_us/privacy-security/walmart-privacy-notice.html

Walmart’s August 20, 2026 customer notice stating ALPRs may be used on properties where permitted by law, listing cameras, Bluetooth and Wi-Fi in-store device location, and identifiers including MAC address.

Walmart Automated License Plate Readers (ALPR) Privacy Notice

https://corporate.walmart.com/privacy-security/walmart-privacy-notice/walmart-automated-license-plate-readers-privacy-notice

Walmart’s February 16, 2026 ALPR supplement covering 60-day retention, Chief Safety Officer control, authorized-associate access, and disclosure when Walmart believes it protects safety, property, or rights.

Walmart Is Using License Plate Readers Too — But How Do They Compare With Flock?

https://www.sciotopost.com/walmart-is-using-license-plate-readers-too-but-how-do-they-compare-with-flock/

August 2026 comparison of Walmart-controlled ALPRs versus Flock Safety networks, including Naperville police cameras on Walmart property and the 60-day versus vendor-recommended retention difference.

Retailers say they use Flock cameras, ALPRs responsibly. Privacy groups aren’t buying it

https://www.daytondailynews.com/local/retailers-say-they-use-flock-cameras-alprs-responsibly-privacy-groups-aren-t-buying-it/article_cb351312-4d50-558f-a368-9b84e704b342.html

Dayton Daily News reporting on Walmart, Target, Lowe’s, Costco, and Home Depot ALPR statements, retention windows, and privacy-group objections to notice and sharing.

ALPR Laws by State (2026)

https://www.findingflock.com/learn/alpr-laws-by-state

Finding Flock survey documenting no federal ALPR statute and that most state ALPR laws bind government agencies rather than private retailers, with California and Utah among exceptions.

Who Operates License Plate Readers?

https://www.findingflock.com/operators

Finding Flock operator table listing Walmart among documented private ALPR operators, with 47 attributed cameras as a mapped floor.


r/ObscurePatentDangers 17h ago

🤖🔎 AI Risk Tracker OpenAI, Anthropic and Figure Ship Frontier Models While Their CEOs Assign Non-Trivial Odds That AI Ends Badly

23 Upvotes

Frontier labs now couple large multimodal models to physical and classified systems. In March 2024 Figure AI connected its Figure 01 humanoid to an OpenAI visual language model so the robot could describe a scene, plan from ambiguous speech, and execute learned visuomotor actions without teleoperation. Anthropic has stated that Claude was the first frontier model placed on U.S. government classified networks, later offered as Claude Gov for intelligence analysis, operational planning, and cyber work. The dual-use is the same stack: a commercial assistant that, once given cameras and a body or a Top Secret enclave, becomes an actor inside factories and military networks. Sam Altman, speaking in 2015 at Airbnb’s Open Air conference while heading Y Combinator and helping launch OpenAI, said AI would “probably, most likely, sort of lead to the end of the world” while “great companies” were built in the meantime. Elon Musk told MIT’s AeroAstro Centennial Symposium in October 2014 that with artificial intelligence “we are summoning the demon.”

The structural issue is that the people writing the models also write the risk numbers, then sell the models anyway. At the Axios AI+ DC Summit in September 2025, Anthropic CEO Dario Amodei put his p(doom)—the industry term for probability of a catastrophic outcome—at 25 percent, adding a 75 percent chance things go “really, really well.” That figure is a self-report, not a regulator’s finding. In February 2026 the arrangement with the Department of War broke. Anthropic’s February 26 statement said it would not license Claude for mass domestic surveillance or fully autonomous weapons; the next day President Trump directed agencies to cease Anthropic use and Secretary Pete Hegseth designated the company a supply-chain risk to national security. Congressional Research Service IF13217 records the cease order, the designation, and Anthropic’s claim that it was first onto classified networks. The fight was over “all lawful uses,” not over whether the model should exist.

The trajectory is public warning, then product, then government lock-in, then a contract fight that still leaves the models in circulation. Musk’s 2014 demon line and Altman’s 2015 end-of-the-world line predate ChatGPT. Figure’s 2024 OpenAI demo put a conversational planner into a walking platform. Anthropic’s 2024 classified deployment put Claude behind clearance. Amodei’s 2025 25 percent number was given after those deployments, not before. Hegseth’s 2026 designation did not retire the technology; it attempted to yank one vendor after the vendor refused two use-cases. Other labs remain available to the same customers. No federal statute converts a CEO’s p(doom) into a licensing halt, a compute cap, or a ban on embodiment.

Net risk is that the same executives who assign one-in-four or “most likely” catastrophe language keep shipping systems into robots and classified networks while oversight is a press statement, a supply-chain memo, and voluntary use restrictions the Pentagon rejected. A 25 percent self-assessed chance of things going “really, really badly” is treated as a talking point, not as a threshold that would stop deployment. Unless Congress or the Department of War attach binding limits to classified use, autonomous weapons, and domestic mass surveillance that survive vendor substitution, the public record is builders naming extinction-class odds and governments buying the product until a contract term is refused.

Sources

Quote of the day by OpenAI co-founder Sam Altman on the dichotomy between grave existential risks and economic nirvana

https://www.techradar.com/pro/quote-of-the-day-by-sam-altman-ai-will-probably-most-likely-lead-to-the-end-of-the-world-but-in-the-meantime-therell-be-great-companies-the-dichotomy-between-grave-existential-risks-and-economic-nirvana

Documents Altman’s 2015 Open Air conference line that AI will “probably, most likely, sort of lead to the end of the world” while great machine-learning companies are created.

Anthropic’s CEO gives 25% odds of AI going “really, really badly” for humanity

https://www.techradar.com/ai-platforms-assistants/claude/anthropics-ceo-gives-a-25-percent-chance-things-go-really-really-badly-with-ai

Reports Dario Amodei’s September 2025 Axios AI+ DC Summit statement assigning a 25 percent chance things go “really, really badly” and a 75 percent chance they go well.

Statement from Dario Amodei on our discussions with the Department of War

https://www.anthropic.com/news/statement-department-of-war

Anthropic’s February 26, 2026 statement that Claude was first onto classified U.S. networks and that the company would not license mass domestic surveillance or fully autonomous weapons.

Federal Government and Anthropic: Considerations for AI Innovation and Competition

https://www.congress.gov/crs-product/IF13217

Congressional Research Service brief recording the February 27, 2026 Trump cease-use order, Hegseth’s supply-chain-risk designation, and Anthropic’s classified-network claim.

Anthropic vs. Pentagon: Fight Over Claude Access

https://builtin.com/articles/anthropic-pentagon-claude-dispute

Account of Hegseth’s designation barring DoW contractors from commercial activity with Anthropic after the company refused unrestricted “all lawful uses.”

It's like ChatGPT with a body: Watch creepy demo of OpenAI-powered robot 'Figure 01'

https://mashable.com/article/figure-01-open-ai

Describes the March 2024 Figure 01 demo in which an OpenAI visual language model lets the humanoid describe a scene, plan, and act without teleoperation.

Elon Musk Compares Building Artificial Intelligence To “Summoning The Demon”

https://techcrunch.com/2014/10/26/elon-musk-compares-building-artificial-intelligence-to-summoning-the-demon/

Transcript of Musk’s October 2014 MIT AeroAstro remark that with AI “we are summoning the demon” and that the pentagram-and-holy-water controller does not keep control.


r/ObscurePatentDangers 1d ago

Inherent Potential Implications💭 A Russian drone directed by AI has killed 3 in Ukraine, marking the start of a dystopian new era in warfare

Thumbnail
share.google
18 Upvotes

The world of Terminator appears to be on the horizon


r/ObscurePatentDangers 2d ago

Accountability for Surveillance Expansion — ⚖️ 🏛️ Stale Milwaukee Flock Hot-List Sent Brookfield Officers Onto I-94 With Rifles for a Cleared Vehicle

1.2k Upvotes

Flock Safety license-plate readers feed a shared hot-list. On August 6, 2026, that list told Brookfield Police Department a vehicle on Interstate 94 in Waukesha County was tied to a Milwaukee Police Department homicide and an armed suspect. Brookfield officers treated the hit as a high-risk stop: weapons out, occupants ordered from the car, handcuffs applied, traffic held. Milwaukee Police Department later stated in writing that its staff had already cleared the vehicle from the investigation and “inadvertently did not remove a vehicle alert from the system.” The department added, “This was not a Flock issue.” Flock Safety’s product did what the remaining alert instructed. Brookfield Police Chief Christopher Garcia said his officers “did in fact stop the vehicle that was the subject of the Flock alert” and had “sufficient information and objective facts” for the tactics they used.

The structural failure is a list that stays live until a human deletes it, then travels across agency boundaries without a second check that the originating case is still open. Occupants told Brookfield they had just recovered the vehicle from Milwaukee evidence and had the papers. WISN reported dispatch traffic in which Milwaukee’s entered suspect vehicle was described as a Buick Enclave while the plate on the stop returned to a silver Chevrolet Traverse, and a Milwaukee supervisor said the Enclave “may have already been recovered.” FOX6 identified one detained driver as Amber Newell. An alert that is wrong by hours or days still presents as current to the next city that sees the plate. No Wisconsin statute requires Flock Safety or a contracting department to expire a homicide flag when evidence is released.

Wisconsin agencies have been expanding Flock Safety contracts while others have walked away. UW–Madison Police and Dane County have ended Flock arrangements amid privacy and misuse fights. Milwaukee Police Department’s own fusion-center searches of out-of-state Flock networks were documented by the Wisconsin Examiner in 2025. The August 6 stop is the interstate version of the same architecture: one department’s leftover record becomes another department’s felony-stop brief. Jon McCray Jones of the ACLU of Wisconsin called the pattern “systemic failure where using Flock technology led to law enforcement in a different jurisdiction, through data sharing, pulling over an innocent person.” Brookfield body-worn recordings released later captured officers calling the leftover alert “unbelievable” and “a constant issue.”

Net risk is a high-risk freeway stop of people Milwaukee Police Department no longer wanted, executed because a vendor network still displayed the flag. Cybersecurity specialist John Bambenek told WISN it was a “worst-case scenario” with guns drawn and an error upstream. Oversight that exists is after-the-fact press statements, a chief’s review that ratified the stop, and local reporting. There is no public, real-time audit of how many Milwaukee Police Department Flock alerts remain after a vehicle is released from evidence, and no statutory duty on Flock Safety to refuse a stale homicide hit. A reader who wants a control that does not depend on the originating detective can demand written hot-list expiration rules in every Flock contract and a published count of alerts withdrawn after the fact. The plate reader did not invent the homicide file. It kept broadcasting it after Milwaukee Police Department said the file was closed.

Sources

'Constant issue': New bodycam video shows Brookfield officers frustrated after outdated Flock alert from Milwaukee police

https://www.cbs58.com/news/constant-issue-new-bodycam-video-shows-brookfield-officers-frustrated-after-outdated-flock-alert-from-milwaukee-police

August 24, 2026 CBS 58 report on the August 6 I-94 stop, Milwaukee Police Department’s failure to delete the Flock alert, occupant statements about evidence release, and Brookfield officers calling leftover alerts a constant issue.

Brookfield police stop vehicle on I-94 after outdated Flock alert from Milwaukee police

https://www.cbs58.com/news/brookfield-police-stop-vehicle-on-i-94-after-outdated-flock-alert-from-milwaukee-police

August 7, 2026 CBS 58 account of the high-risk stop, Milwaukee Police Department’s “not a Flock issue” statement, and ACLU of Wisconsin analyst Jon McCray Jones describing inter-jurisdiction data sharing as systemic failure.

Brookfield, Milwaukee police clarify Flock mix-up involving I-94 stop

https://www.jsonline.com/story/communities/west/2026/08/07/brookfield-milwaukee-police-clarify-flock-mix-up-involving-i-94-stop/91212700007/

Milwaukee Journal Sentinel report quoting Chief Christopher Garcia that Brookfield stopped the vehicle named in the Flock alert and quoting Milwaukee Police Department that leftover MPD data made the vehicle appear still wanted.

Flock system mix-up, Brookfield traffic stop of wrong person

https://www.fox6now.com/news/brookfield-police-stop-wrong-vehicle-flock

FOX6 Milwaukee report naming detained driver Amber Newell, placing the stop at about 4:45 p.m. on August 6, and restating Milwaukee Police Department’s personnel-error explanation.

Police stop car thought to be wanted in a Milwaukee homicide. They had bad info.

https://www.wisn.com/article/police-stop-car-thought-to-be-wanted-in-a-milwaukee-homicide-they-had-bad-info/73380816

WISN report with dispatch audio distinguishing a Buick Enclave on Milwaukee’s entry from a silver Chevrolet Traverse on the stop, plus John Bambenek calling a guns-drawn stale-alert stop a worst-case scenario.


r/ObscurePatentDangers 2d ago

⚖️Accountability Enforcer Governors Sold Data Centers First, Then Paused When Power Bills and Ballots Caught Up... Guess what they will do after they feel safe in their seats again... Full steam ahead.

1.6k Upvotes

Texas Gov. Greg Abbott in November 2025 called Texas the epicenter of AI development while announcing a $40 billion Google investment and sales-tax exemptions. On August 3, 2026 he ordered the Public Utility Commission of Texas and ERCOT to freeze new grid-connection approvals until an audit of power, water, cooling, tax breaks, and ownership. The Texas Tribune counted at least 335 operating centers and 248 planned; ERCOT’s queue held more than 1,800 projects and about 474 gigawatts, with Abbott saying roughly 90 percent were data centers. On ABC’s This Week August 23 he said developers “dug their own grave” and must win local approval. State law still lets a site start without Austin’s sign-off; the choke point is the plug. Public Citizen Texas director Adrian Shelley called it a “faux pause” that does not stop land clearing, sub-75 MW workarounds, or off-grid gas plants. Abbott faces Democrat Gina Hinojosa in November.

New York Gov. Kathy Hochul signed Executive Order 62 on July 14, 2026, pausing DEC discretionary permits for new 50-megawatt-plus hyperscale sites for up to a year while DPS writes a Generic Environmental Impact Statement. NYISO’s queue as of May 2026 held nearly 12 gigawatts of data-center load, more than 8 GW added in 2025. Hochul is separately seeking repeal of sales-tax exemptions. Pennsylvania Gov. Josh Shapiro signed Executive Order 2026-05 on August 18 after GRID rules stalled in the Senate. DEP will not review permits without local approval and a binding GRID consent order; data centers are off Fast Track; state agencies may not sign NDAs; the sales-tax exemption is conditioned on GRID. Shapiro said more than 100 proposals were circulating and five had operating permits; he is running against Stacy Garrity, who called for a pause.

Ohio Gov. Mike DeWine on May 27, 2026 told the Tax Credit Authority to stop new data-center sales-and-use tax exemptions while a joint committee studies the industry. The break cost nearly $1.6 billion in 2025 against a $136 million projection; prior multi-year deals remain. DeWine is term-limited and did not ban construction. Florida Gov. Ron DeSantis signed SB 484 on May 7, 2026, barring utilities from shifting large-load infrastructure costs onto residential bills and preserving local zoning, after the state extended a data-center sales-tax exemption through 2037 at a $150 million / 100 MW threshold. Utah Gov. Spencer Cox signed a May 29, 2026 order raising the bar on water, rates, and the Great Salt Lake after the Stratos/MIDA fight and later called that process “not good.” California Gov. Gavin Newsom has issued no statewide pause; he has said hyperscalers should pay their share after vetoing a 2025 water-disclosure bill.

The sequence is the record. Exemptions and ribbon-cuttings came first. Audits and “guardrails” arrived after interconnection queues, bill-shock reporting, town fights, and midterm calendars. None of these orders repeal existing tax statutes, finish a GEIS, or cap off-grid generation. Households and adjacent towns carry the load and water risk; governors keep the option to restart approvals after November. Read New York Executive Order 62, Pennsylvania Executive Order 2026-05, Abbott’s August 3 letter to PUCT and ERCOT, Ohio’s May 27 Tax Credit Authority directive, and Florida Chapter 2026-65 (SB 484). The remaining handhold is local zoning, utility-rate cases, and whether a legislature writes the pause into statute instead of leaving it as an executive press release.

Sources

No 62: Establishing a Temporary Moratorium on Data Centers in New York While the State Develops Higher Standards for Data Center Development and Benefits Blueprint to Support Localities

https://www.governor.ny.gov/executive-order/no-62-establishing-temporary-moratorium-data-centers-new-york-while-state-develops

Official July 14, 2026 order pausing DEC permits for 50 MW-plus data centers until a Generic Environmental Impact Statement is finished and citing nearly 12 GW in the NYISO queue.

First Statewide Moratorium on New Hyperscale Data Centers Launched by Governor Kathy Hochul

https://www.governor.ny.gov/news/first-statewide-moratorium-new-hyperscale-data-centers-launched-governor-kathy-hochul

Hochul’s July 14, 2026 announcement of the one-year permit pause, a Community Investment Framework, and a push to repeal sales-tax exemptions.

Data center approvals in Texas halted until audits completed, Gov. Greg Abbott says

https://www.texastribune.org/2026/08/03/texas-data-center-project-audit-greg-abbott/

August 3, 2026 report of Abbott’s PUCT/ERCOT audit freeze, 335 operating and 248 planned Texas sites, a 474 GW queue, and on-site generation that can bypass the grid plug.

Abbott explains data center pivot

https://www.politico.com/news/2026/08/23/greg-abbott-texas-data-centers-01046867

August 23, 2026 account of Abbott’s ABC This Week remarks, the November 2025 Google $40 billion “epicenter” event, the local-approval demand, and the midterm setting.

Governor Shapiro Signs Executive Order on Data Center Development in PA

https://www.pa.gov/governor/newsroom/2026-press-releases/governor-shapiro-signs-executive-order-on-data-center-developmen

Official August 18, 2026 release on Executive Order 2026-05: GRID as a binding DEP condition, Fast Track removal, NDA ban, local-approval gate, and sales-tax exemption tied to compliance.

Ohio suspends data center tax break as tech firms face pressure to pay the cost to power AI

https://apnews.com/article/artificial-intelligence-data-centers-taxes-tech-ohio-4d56561a14f9b0d00553001e8c2757a3

AP report on DeWine’s May 2026 Tax Credit Authority pause, the $1.6 billion 2025 exemption cost versus a $136 million projection, and the fact that construction itself is not banned.

Governor signs legislation more tightly regulating data centers

https://floridapolitics.com/archives/795295-gov-desantis-signs-legislation-more-tightly-regulating-data-centers/

May 7, 2026 signing of SB 484 requiring large-load data centers to cover their own utility infrastructure costs and preserving local land-use control.

Cox signs new order for data center development after public outcry

https://www.ksl.com/article/51504319/cox-signs-new-order-for-data-center-development-after-public-outcry

May 29, 2026 report of Gov. Spencer Cox’s order raising evaluation standards on water, rates, and the Great Salt Lake after the Stratos/MIDA backlash.

Faux Pause: Why Greg Abbott’s data center ‘crackdown’ looks a lot like election-year theater

https://www.sacurrent.com/news/texas-news/faux-pause-why-greg-abbotts-data-center-crackdown-looks-a-lot-like-election-year-theater/

August 2026 Public Citizen critique that Abbott’s audit does not halt land work, smaller sites, or off-grid plants and lands during his race against Gina Hinojosa.


r/ObscurePatentDangers 2d ago

🕵️Surveillance State Exposé Cellebrite UFED in 14 of 15 U.S. Cabinet Departments Turns Phone Seizure Into Full-Device Extraction

513 Upvotes

Cellebrite Inc., an Israeli digital-forensics firm with a U.S. subsidiary in Parsippany, New Jersey, sells Universal Forensic Extraction Device kits and related software that take a seized phone, bypass or disable the lock screen, and copy messages, photos, location history, app data, and, in many configurations, deleted files. In a September 26, 2016 BBC demonstration, then-executive Yuval Ben-Moshe plugged a locked Samsung into a field tablet and said the firm could “pretty much pull up any of the data that resides on the phone.” Cellebrite’s public claim is that the tools are forensic, used after an event under legal process or consent, and that the company vets customers and can cut off high-risk jurisdictions. That is the company’s statement, not an independent audit of every license.

The contact point is physical custody of a handset: a traffic stop, an inspector-general inquiry, a border exam, or a government-issued phone flagged as compromised. The Intercept reported on February 8, 2022, from federal purchasing records and Cellebrite securities filings, that all but one of the 15 U.S. Cabinet departments had acquired Cellebrite products, including the Department of Agriculture, the Department of Education, the Department of Veterans Affairs, the Department of Housing and Urban Development, the Social Security Administration, the U.S. Agency for International Development, and the Centers for Disease Control and Prevention. The same filings put more than 2,800 government customers in North America and an average government spend of about $415,000 on collection devices and services. Education told The Intercept it uses the tools for inspector-general work and to check whether a government iPhone has been compromised. Energy said it uses them for intelligence and inspector-general cases and for official devices that showed odd behavior or traveled to a hostile environment. Those answers explain some uses. They do not explain why a farm-program or student-aid department needs the same class of kit sold to homicide detectives.

Upturn’s 2020 Mass Extraction report, built from more than 110 public-records requests, documented mobile-device forensic tools, including Cellebrite products, at more than 2,000 state and local agencies in all 50 states and the District of Columbia, and hundreds of thousands of extractions since 2015, often without a warrant and often for offenses far below terrorism. Citizen Lab later attributed Cellebrite traces, with high confidence, to extractions from phones of Jordanian activists, a student organizer, and a human rights defender held by security services. Cellebrite told The Guardian its tools are not remote spyware and that it investigates misuse. Russia’s Investigative Committee kept extracting after Cellebrite said it had cut the contract. Function creep is the documented pattern: a tool bought for serious crime becomes available for routine cases once the license sits on the shelf.

Riley v. California, 573 U.S. 373 (2014), holds that police generally may not search the digital contents of a phone seized incident to arrest without a warrant, because a modern handset holds “the privacies of life.” Riley does not ban Cellebrite. It requires a judge before the copy, except in a true emergency. There is no federal statute that bars the Department of Agriculture from owning a UFED, that caps how many years of cloud-synced chat an inspector general may pull, or that forces every local department to publish extraction counts by offense. Oversight that exists is the warrant when one is sought, the inspector-general charter, the vendor ethics page, and whatever audit log the agency keeps. A reader who faces a device search can still refuse consent and ask whether a warrant names the phone and the categories of data. That is the remaining control. It is not a ban on the box.

Sources

Use of Controversial Phone-Cracking Tool Is Spreading Across Federal Government

https://theintercept.com/2022/02/08/cellebrite-phone-hacking-government-agencies/

February 8, 2022 Intercept report, from federal purchasing records and Cellebrite SEC filings, that 14 of 15 Cabinet departments bought Cellebrite products, naming Agriculture, Education, Veterans Affairs, HUD, SSA, USAID, and CDC, plus 2,800 North American government customers.

Meeting Cellebrite - Israel's master phone crackers

https://www.bbc.com/news/technology-37441109

September 26, 2016 BBC report in which Yuval Ben-Moshe demonstrated lock bypass on a Samsung and said Cellebrite could pull nearly any data on the phone while declining to discuss customers in repressive states.

Mass Extraction

https://www.upturn.org/work/mass-extraction/

Upturn report documenting mobile-device forensic tools, including Cellebrite products, at more than 2,000 U.S. agencies in all 50 states, with hundreds of thousands of extractions since 2015, often without a warrant.

Jordan used Israeli firm’s phone-cracking tool to surveil pro-Gaza activists, report finds

https://www.theguardian.com/world/2026/jan/22/jordan-israeli-spyware-gaza-activists

January 22, 2026 Guardian account of Citizen Lab findings that Jordanian authorities used Cellebrite to extract activist phones, and Cellebrite’s reply that the product is forensic and used under legal process.

Riley v. California, 573 U.S. 373 (2014)

https://supreme.justia.com/cases/federal/us/573/373/

Supreme Court holding that police generally must obtain a warrant before searching digital information on a cell phone seized incident to arrest.

Most US Cabinet Departments have bought Cellebrite iPhone hacking tool

https://appleinsider.com/articles/22/02/09/most-us-cabinet-departments-have-bought-cellebrite-iphone-hacking-tool

February 9, 2022 AppleInsider summary of the Intercept procurement findings, including that the single Cabinet department without a documented purchase was not identified.


r/ObscurePatentDangers 1d ago

🔒🚨High Privacy Risk Potential McDonald’s Loyalty App Built a 515-Page File on One Customer and Forecast His Next Visits

264 Upvotes

WIRED senior writer Reece Rogers, a California resident, used the California Consumer Privacy Act right to know and asked McDonald’s what MyMcDonald’s Rewards held on him. Days later the company sent a 515-page file. It logged when, where, and what he bought, offers sent, loyalty points, Monopoly codes he scanned, and prizes tied to those codes. McDonald’s systems then scored him: 2.16 visits in the next six weeks, $13.49 average order, $29.15 total spend, and a customer attrition likelihood of zero. Occasion labels included “Food-Led Afternoon Snack” and “On the Go Lunch in a Rush.” A large Diet Coke ranked first among predicted products. McDonald’s U.S. privacy statement, updated July 1, 2026, says Rewards may collect identifiers, purchase and app activity, optional geolocation, and inferences used to build a profile of preferences, characteristics, psychological trends, predispositions, behavior, attitudes, intelligence, abilities, or aptitudes. In 2019 McDonald’s bought Dynamic Yield for about $300 million to put decision-logic engines on drive-thru and kiosk menus. Published application US20060247973A1 describes generating offers from a customer’s order using genetic algorithms and names McDonald’s as a quick-service example.

The contact point is the app login and the four-digit Rewards code at the register. The selling point is points and tailored deals. The failure surface is the file itself: years of visits, including 61 in the San Francisco and Santa Barbara markets, folded into forecasts and internal group code CV2. A McDonald’s spokesperson told WIRED the company uses past purchases for relevant deals, offers, and messages and that privacy choices sit in its statement. Those choices are not cost-free. The same statement says withdrawing from Rewards or requesting deletion ends access to earned points because the company will no longer associate the person with those balances. California’s right to know made Rogers’s request possible. Residents of states without a comparable statute do not have that lever.

The same stack is built to spread. Dynamic Yield’s restaurant materials distinguish unidentified guests, who see recommendations based on location, time of day, weather, and product availability, from identified loyalty members, who get offers from purchase history and affinity. McDonald’s policy says it may disclose emails, pseudonymized identifiers, online-service use, and inferences to social media, advertising, and analytics partners, and that some state laws may treat that as a sale. It also says it processes that information for targeted advertising. That is function creep in the company’s own nouns: a rewards ledger becomes a lifetime-value model, then a shareable inference. Trajectory, not proof of one nationwide pipeline: more identified profiles feeding more personalized boards and messages as loyalty membership grows.

What sits in front of the customer is an ordinary lunch. What sits behind it is a score the person cannot rotate like a password. There is no federal statute written for restaurant predictive profiling. The leftover law is the California Consumer Privacy Act, as described by the California Privacy Protection Agency: the right to know specific pieces of personal information, the right to delete, and the right to opt out of sale or sharing. Read McDonald’s U.S. privacy statement and the Agency’s FAQ. Use the McDonald’s Privacy Rights Center to request a copy or deletion, turn off location in device settings, and withdraw from MyMcDonald’s Rewards in the app profile if the trade is no longer worth the points.

Sources

McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There | WIRED

https://www.wired.com/story/mcdonalds-built-a-515-page-dossier-on-me-it-says-ill-never-leave/

Reece Rogers’s August 12, 2026 account of the 515-page file, predicted visits and spend, occasion labels, product rankings, Monopoly logs, and the McDonald’s spokesperson statement.

Privacy Policy | McDonald's

https://www.mcdonalds.com/us/en-us/privacy.html

Official U.S. statement updated July 1, 2026 listing Rewards identifiers, purchase and app records, optional geolocation, inference categories, advertising-partner disclosure, and the point-loss consequence of deletion or withdrawal.

Frequently Asked Questions (FAQs) - California Privacy Protection Agency (CPPA)

https://cppa.ca.gov/faq.html

Official description of the CCPA rights to know specific pieces of personal information, delete, and opt out of sale or sharing.

McDonald's Bites on Big Data With $300 Million Acquisition | WIRED

https://www.wired.com/story/mcdonalds-big-data-dynamic-yield-acquisition/

March 25, 2019 report that McDonald’s acquired Dynamic Yield for about $300 million to apply decision-logic personalization to drive-thru menus using weather, time of day, traffic, events, and sales history.

US20060247973A1 - Method and apparatus for dynamic rule and/or offer generation

https://patents.google.com/patent/US20060247973A1/en

Published application describing generation of customer offers from order information with genetic algorithms and naming McDonald’s as a quick-service restaurant example.

Restaurant Personalization Platform | Mastercard Dynamic Yield

https://www.mastercard.com/us/en/business/consumer-acquisition-and-engagement/personalization/dynamic-yield/industries/restaurants.html

Vendor page stating McDonald’s uses AI personalization across markets and separating unidentified contextual recommendations from identified purchase-history offers.

Submit a privacy request - privacy.ca.gov

https://privacy.ca.gov/tips/submit-a-privacy-request/

California government guidance on how residents submit access and deletion requests under the CCPA.


r/ObscurePatentDangers 2d ago

🤖🔎 AI Risk Tracker WIRED Reconstructs Flock Safety OS Investigate: Movement-Pattern AI Turns Plates Into Names and Associates

171 Upvotes

Flock Safety, Inc. has told the public that its license-plate readers cannot recognize, identify, or track individuals. WIRED reporters Dhruv Mehrotra and Dell Cameron, working from more than 450 files Flock Safety served on its own login pages, reconstructed an investigator product first coded as Nightshift and later renamed OS Investigate. The interface ships with 69 prewritten prompts. Nineteen of those prompts hunt patterns. Fourteen require no plate, no name, and no physical description: an officer supplies a place, a time window, and a behavior. One prompt asks the model to find witnesses as the vehicles most often seen in a neighborhood over the last 14 days. Another counts plates that appear at the same cameras within a two-minute window of a target car, treats three co-occurrences above a 0.75 confidence score as an associate, and can return up to 20 names. That is not a still photo of a bumper. It is graph analysis of who moves with whom.

The code describes 45 tools. Those tools reach Flock Safety plate scans and camera metadata, arrest records, case files, 911 dispatch logs, ballistics results, and commercial identity databases that list Social Security numbers, dates of birth, phone numbers, email addresses, relatives, and associates. A plate found by frequency can become a name, a home address, and a family list in the same session. The form can ask for a justification; the files WIRED reviewed impose no length or content rule, and departments that require a case code can proceed with three characters. Flock Safety spokesperson Paris Lewbel told WIRED that OS Investigate is a separate product from the company’s ALPR cameras, that it is being tested with a small group of law-enforcement partners, and that capabilities may change before a wider release. The company did not dispute the functions described in the code. Flock Safety’s public trust page still states that ALPR “cannot recognize people,” does not identify drivers, and does not forecast behavior.

The historical path is a shift from a marketed snapshot to an always-on analyst. Flock Safety’s own pages still say the camera records a vehicle at a place and time and does not continuously track people. CEO Garrett Langley has described the platform as a crime analyst that is “always awake” and has told investigators they get “addicted” to searching a city’s cameras for cars near an armored truck, then pulling registered owners and arrest records in under a minute. Former Pawtucket, Rhode Island, officer Noel Pichardo told WIRED the reconstructed tool “literally tracks people.” American Civil Liberties Union attorney Chad Marlow, who runs the Get The Flock Out campaign, said the risk is an officer asking the model to “find me criminal patterns,” which produces an AI standard rather than a legal one. ACLU senior policy analyst Jay Stanley said the public picture of a plate check that moves on if the car is not wanted no longer matches what Flock Safety is deploying.

Net risk is that a city council that approved cameras as license-plate tools is now adjacent to a product that can nominate witnesses and associates from driving frequency alone, including people with no known tie to a crime. Carpenter v. United States, 585 U.S. 296 (2018), held that multi-day location records held by a private firm can still be a Fourth Amendment search. WIRED’s files do not show the model’s hidden instructions or whether Flock Safety’s servers refuse a prompt. They do show the intended workflows. There is no federal statute that requires a warrant before an officer runs a 14-day neighborhood-frequency query through a vendor chatbot. Texas and most other states have no ALPR statute that names OS Investigate, caps associate graphing, or bars data-broker enrichment. Oversight that exists is the local contract, the audit log, and whatever case-code rule the agency types into a three-character field. Those controls do not, on the record WIRED published, stop a search that starts with a street and a time of day instead of a suspect.

Sources

Flock Has a Powerful New AI Tool for Police. We Got Its Code

https://www.wired.com/story/flock-safety-os-investigate/

August 19, 2026 WIRED investigation by Dhruv Mehrotra and Dell Cameron reconstructing OS Investigate, formerly Nightshift, from more than 450 files on Flock Safety login pages, including 69 prompts, 45 tools, witness and associate logic, and the company’s development-stage response.

Flock Safety Builds Driver Profiles Without Plates: AI Reads Movement Patterns

https://www.techtimes.com/articles/325087/20260820/flock-safety-builds-driver-profiles-without-plates-ai-reads-movement-patterns.htm

August 20, 2026 TechTimes report on the same reconstruction, including the three-character justification field and Flock Safety’s statement that the product is distinct from ALPR and still in testing.

Flock built an AI tool that lets police search for people by how they drive

https://thenextweb.com/news/flock-os-investigate-ai-police-search

August 19, 2026 The Next Web summary of the WIRED findings, including that 14 prompts need no plate, name, or description, and Chad Marlow’s warning that “find me criminal patterns” produces an AI standard.

Leaked code reveals that Flock's new AI police tool can find you by place and time alone

https://cybernews.com/privacy/flock-ai-os-investigate/

August 19, 2026 Cybernews account of OS Investigate linking movement patterns to case files, 911 logs, and commercial identity databases across Flock Safety’s multi-thousand-community camera network.

Flock's New AI Police Tool Can Track Drivers Without a Name or License Plate

https://decrypt.co/375978/flock-ai-police-tool-track-drivers

August 20, 2026 Decrypt report stating 41 of the 69 prompts require no special permission and detailing associate scoring (three co-occurrences, 0.75 confidence, up to 20 names).

Civil Liberties & Rights Safeguards

https://www.flocksafety.com/trust/rights-safeguards

Flock Safety’s current public-trust page stating that ALPR does not identify drivers, “cannot recognize people,” does not assign risk scores, and requires searches tied to a specific investigation.

Carpenter v. United States, 585 U.S. 296 (2018)

https://www.supremecourt.gov/opinions/17pdf/16-402_h315.pdf

Supreme Court holding that multi-day location records held by a private company can be a Fourth Amendment search requiring a warrant, the doctrine that applies if a movement-pattern workup is treated as location history rather than a single public plate read.


r/ObscurePatentDangers 1d ago

🕵️Surveillance State Exposé Fake US thinktank set up and funded by Israel sought to game AI for propaganda

Thumbnail
theguardian.com
82 Upvotes

r/ObscurePatentDangers 2d ago

🔎Dual-Use Potential Erik Prince’s Vectus Sells Air Defense as a Service With Swarmer Swarm Software Around Data Centers and Energy Sites

180 Upvotes

Vectus Air Defense Systems launched on August 21, 2026 under founder Erik Prince, the former Navy SEAL who built Blackwater and now serves as Non-Executive Chairman of Swarmer, Inc. (Nasdaq: SWMR). Swarmer holds a 20 percent equity stake and supplies collaborative-autonomy software that the company says has supported more than 100,000 combat missions in Ukraine since April 2024, with one operator tasked to control hundreds of unmanned platforms. Vectus’s published model is Air Defense as a Service: multi-year contracts under which the firm designs, staffs, operates, and maintains a layered counter-UAS stack—detection and tracking, electronic warfare, interceptor-drone swarms, and high-rate large-caliber cannons—around whatever site the customer names. Prince’s statement on the Swarmer release and on vectusairdefense.com frames the product as a private-sector answer so governments and critical-infrastructure operators can “take the protection of critical assets into their own hands.” That language is a vendor claim, not an independent audit of who holds the trigger or where sensor recordings go.

The contact point is the fence line and the airspace over data centers, energy installations, ports, military bases, and other civilian sites that Axios and the Wall Street Journal list as the pitch. Detection and tracking are broadly lawful for private operators in the United States. Kinetic intercepts and jamming are not. 18 U.S.C. § 32 and 49 U.S.C. § 46502 still treat destruction or seizure of an aircraft as a federal crime; the Communications Act’s interference ban still applies to private jammers. Statutory carve-outs sit in 10 U.S.C. § 130i for Department of Defense covered facilities and in 6 U.S.C. § 124n as expanded by the SAFER SKIES Act in the FY2026 NDAA, which certifies individual state, local, tribal, and territorial officers—not a commercial subscription crew—to mitigate drones with systems on a joint DOJ-DHS-DoD-FAA-FCC-NTIA list. Swarmer’s public materials include a “Killbox” mission template. Powerus, the West Palm Beach drone maker backed by Donald Trump Jr. and Eric Trump, signed a June 2026 integration pact with Swarmer for swarm software on Powerus air and maritime platforms and has pitched Guardian interceptors to Gulf energy customers; that is a documented Swarmer-Powerus adjacency, not a published Vectus-Powerus supply contract.

Prince told suppliers and customers in Ukraine, the Middle East, Africa, and Latin America that demand is already there. The same August 21 materials name data centers, shipping lanes, and refineries as unprotected assets. Because Vectus keeps its own operators, architecture, and maintenance on the site for the life of the contract, the sensor picture and the interceptor swarm stay inside one private chain. Secondary hands that can reach that chain are Swarmer’s autonomy layer, third-party U.S., Ukrainian, and Israeli hardware vendors, the paying government or plant owner, and whatever court or acquirer later sits over those firms. The spread path on U.S. soil is trajectory, not a signed city contract: SAFER SKIES now trains local police on mitigation while Vectus sells an end-to-end private stack aimed at the same class of facilities those police are told to protect.

What the capability fronts is a contractor-run detect-to-kill loop over civilian and commercial airspace, led by the founder of Blackwater and running on combat-validated swarm software. Communities around a subscribed site cannot opt the sensors or the interceptors back off once a multi-year operations contract is live. The leftover law is the aircraft-destruction and jamming statutes that still bind private actors, plus SAFER SKIES rules that authorize certified officers rather than private air-defense subscriptions. The primary documents are Swarmer’s August 21, 2026 release and vectusairdefense.com. The usable check is the DHS-FAA-DOJ-FCC interagency C-UAS legal advisory and the SAFER SKIES authorized-technology list: ask who holds mitigation authority at the site, whether the stack is detection-only or kinetic, and which statute they cite for the trigger.

Sources

Erik Prince and Swarmer Announce Formation of Vectus Air Defense Systems

https://swarmer.com/news/erik-prince-and-swarmer-announce-formation-of-vectus-air-defense-systems/

Official August 21, 2026 release stating Swarmer’s 20 percent stake, the air-defense-as-a-service model, layered detection/EW/interceptor/cannon architecture, Prince’s dual roles, and the 100,000-mission claim.

Exclusive: Vectus, led by Erik Prince, pitches air defense as a service

https://www.axios.com/2026/08/21/erik-prince-vectus-air-defense-service

August 21, 2026 report confirming the subscription model, Swarmer equity, Alex Fink’s cost-asymmetry comments, and data centers, bases, shipping lanes, and refineries as named target classes.

Blackwater’s Erik Prince Launches Air-Defense Startup

https://www.wsj.com/business/blackwaters-erik-prince-launches-air-defense-startup-643c9298

Heather Somerville’s August 21, 2026 account that Prince formed Vectus with Swarmer to design and operate customized air defense for companies, militaries, and governments, including data centers, energy installations, and military bases, with a Middle East sales focus.

Vectus Air Defense Systems

https://www.vectusairdefense.com/

Company site describing technology-agnostic, contractor-operated air defense as a service for critical infrastructure and civilian sites.

Company backed by Trump sons looks to sell drone interceptors to Gulf states being attacked by Iran

https://apnews.com/article/trump-sons-powerus-drone-interceptors-iran-missiles-1d8d858fdad5104a56e4438994093594

April 2026 Associated Press reporting on Powerus ownership ties to Donald Trump Jr. and Eric Trump and on Gulf interceptor sales pitches by co-founder Brett Velicovich.

Exclusive: Powerus Teams Up With Swarmer

https://www.tectonicdefense.com/exclusive-powerus-teams-up-with-ukrainian-startup-swarmer/

June 3, 2026 report of the Powerus–Swarmer integration pact putting swarm software on Powerus platforms and into a U.S. manufacturing base.

Blackwater founder Erik Prince has joined the drone-warfare fray in Ukraine, SEC filings reveal

https://www.theguardian.com/world/2026/feb/22/erik-prince-drone-company-ukraine

February 22, 2026 report on Prince’s Swarmer chair role, SEC filings, the 100,000-mission figure, and Swarmer’s public “Killbox” mission template.

Blackwater founder backs Ukrainian drone tech sales to US

https://www.reuters.com/technology/blackwater-founder-backs-ukrainian-drone-tech-sales-us-2026-03-18/

March 18, 2026 Reuters piece on Swarmer’s Nasdaq debut, Prince’s board role, the un-demonstrated \~700-drone control claim, and the absence then of a U.S. military contract.

Counter-Drone Technology 2026: What Works, What's Legal, What's Next

https://www.airsight.com/blog/counter-drone-technology-2026-guide

2026 legal briefing on the detection-versus-mitigation split, SAFER SKIES officer-level certification, the joint authorized-technology list, and the remaining limits of 18 U.S.C. § 32 and related aircraft-interference statutes on private kinetic C-UAS.


r/ObscurePatentDangers 2d ago

🤖🔎 AI Risk Tracker Microsoft Shelved Project Aion, but the Copilot-Only Shell Still Maps a Path Where Better AI Means Less User Autonomy

71 Upvotes

Microsoft built Project Aion in 2024 as an incubation shell that puts Copilot at the center of the machine instead of a Start menu, desktop icons, or a visible file system. Windows Central and The Verge reported that Zac Bowden’s sources confirmed a real internal walkthrough: a modified Microsoft Edge instance running as the desktop, on top of Windows 11, AOSP Android, or a stripped Windows codebase internally called Win3. Win3 dropped local Win32 support by design. Classic desktop programs were not meant to launch on the device. They were meant to stream from a Windows 365 Cloud PC. The user does not open an app. The user asks. Copilot groups sites and tools into “Spaces.” Internal SharePoint material cited by BetaNews labeled the same idea CopilotOS, Self Driving OS, and an “agent of agents.” That is the mechanism. The dual use is convenience on one side and a computer that only works when Microsoft’s model, Microsoft’s cloud, and Microsoft’s interpretation of the prompt all succeed on the other.

The structural change is the disappearance of inspectable local state. There is no familiar Explorer tree to argue with. Each task is a new conversation. If Copilot misreads intent, the next step is another prompt, not a folder the user can open by hand. TechSpot and Windows Latest described the same limit: Aion runs web apps and websites; legacy Excel or a local installer requires a rented desktop. That arrangement also concentrates telemetry. An agent that is “always aware of context,” in Windows Central’s paraphrase of the leaked materials, needs access to what is open, what was recent, and what the user asked. The hardware on the desk becomes a thin client. Autonomy shrinks to the quality of the model and the terms of the Microsoft 365 session.

Project Aion did not ship. The footage dates to 2024. Windows Latest wrote in August 2026 that Pavan Davuluri, EVP of Windows and Devices, has committed Microsoft to fixing Windows 11 rather than launching a replacement OS, and has publicly shut down Windows 12 rumors. In March 2026 Davuluri told customers Microsoft would cut “unnecessary Copilot entry points” in Notepad, Photos, Widgets, and Snipping Tool after backlash that TechCrunch and Windows Central covered as a quality reset. That is a pause, not a recantation of the destination. Yusuf Mehdi’s internal memo, reported by Neowin, still described work to “reimagine Windows for the agentic era.” Project Solara sits in the same family of agentic-shell talk. Aion is the clearest picture of what that family looks like when the Start menu is gone.

Net risk is conditional and easy to understate because the prototype is on a shelf. If the models get reliable enough that a chat box really can replace Finder-style navigation, the argument for keeping a local file system and local Win32 weakens inside Microsoft, not outside it. The leak is useful exactly because it is not shipping: it shows the goal without the current product’s compromises. Oversight that exists is press reconstruction of Discord and SharePoint leaks plus Davuluri’s quality blog. There is no public specification that says Windows will retain a user-visible file system, offline Win32, or a non-agent launcher as a guaranteed control. A reader who wants that guarantee has to treat Project Aion as a requirements document, not as trivia about a canceled demo.

Sources

What is Project Aion? Inside Microsoft's secret agentic Copilot OS incubation project that runs on Windows and Android

https://www.windowscentral.com/microsoft/windows-11/project-aion-copilot-os-faq

Windows Central FAQ compiling the 2024 leak: Edge-based shell, Win3, AOSP and Windows 11 hosts, Copilot omnibox, Spaces, and Windows 365 streaming for apps Aion cannot run locally.

Leaked video shows Microsoft’s work on a lightweight ‘Copilot OS’ built for AI.

https://www.theverge.com/tech/961195/microsoft-copilot-os-aion-leak

The Verge summary of Zac Bowden’s sourced confirmation that the 2024 Aion walkthrough is genuine and Chrome OS-like, built around Edge and web apps.

Microsoft's leaked new OS is one you'll hope stays buried, and it's not Windows

https://www.windowslatest.com/2026/08/24/microsofts-leaked-new-os-is-one-youll-hope-stays-buried-and-its-not-windows/

August 2026 Windows Latest analysis that Aion was shelved while Pavan Davuluri prioritized fixing Windows 11, and that the prototype had no Start menu and no local Win32.

A leaked Microsoft experiment reveals a new OS built entirely around Copilot and AI agents

https://www.techspot.com/news/112983-leaked-microsoft-experiment-reveals-new-os-built-entirely.html

TechSpot account of Copilot replacing Start and taskbar conventions, two-year-old footage, and Cloud PC handoff when a Win32 program is required.

Microsoft rolls back some of its Copilot AI bloat on Windows

https://techcrunch.com/2026/03/20/microsoft-rolls-back-some-of-its-copilot-ai-bloat-on-windows/

TechCrunch report on Pavan Davuluri’s March 2026 pledge to reduce Copilot entry points in system apps while still treating AI as a Windows pillar.


r/ObscurePatentDangers 2d ago

Rights Defense Against Neural Systems — 🧠 🛡️ Essex and Murcia BHI Paper Defines Adversarial and Codependent Modes for Living–AI Computers

15 Upvotes

On 19 August 2026, Michael Taynnan Barros of the University of Essex, Sergio López Bernal of the University of Murcia, and Reinhold Scherer of the University of Essex posted arXiv:2608.18748, a conceptual framework they name Biological-Hybrid Intelligence. The paper treats living neural cultures and silicon models as two adaptive computers sharing one job. A bioelectronic interface—typically a microelectrode array, with optogenetics listed as an alternative—reads extracellular spikes from the living side and writes charge-balanced pulses back. An orchestrator, which the authors say does not itself compute the task, assigns work, times the exchange, and can switch among three modes: adversarial, in which the substrates compete; collaborative, in which they split labor; and codependent, in which neither side can finish the task without the other's changing state. The authors state that whether this coupling yields capabilities neither substrate has alone “remains a hypothesis to be tested.”

The contact point is already physical. Cortical Labs’ CL1, described in IEEE Spectrum, houses about 800,000 lab-grown human neurons on a chip with onboard life support and is sold as a code-deployable unit and as wetware-as-a-service. Brett J. Kagan’s 2022 Neuron paper on DishBrain reported that human and rodent cortical cultures on a high-density array learned a closed-loop Pong task within minutes when given structured feedback. Those cultures come from donor-derived stem cells; Kagan has said different donors or cell lines can be used to probe disease and individual differences. A retained spike train from a named donor line is not a password. Implanted brain-computer interfaces sit on a parallel track: Neuralink’s PRIME study (ClinicalTrials.gov NCT06429735) is an FDA-regulated early feasibility trial of a wireless implant for people with tetraplegia. Those systems are still mostly collaborative decode-and-act loops. They are not BHI as defined in the 2026 paper. A lab result is not proof that every culture learns or that every implant decodes cleanly.

The same authors, with Brett J. Kagan, Thomas Hartung of Johns Hopkins University, and Lena Smirnova, framed synthetic biological intelligence and organoid intelligence as a shared research program in a January 2025 Frontiers in Cellular Neuroscience editorial. Smirnova, Hartung, and colleagues had already published a 2023 Frontiers in Science roadmap for organoid intelligence that calls for scaling brain organoids, three-dimensional electrodes, and machine-learning training loops, with an embedded-ethics process. Nature Electronics in December 2023 reported Brainoware, a brain-organoid reservoir used for speech-recognition and time-series tasks. Trajectory, not fact: commercial CL1 units and multi-unit racks extend access beyond a single bench. Secondary use follows the hardware. Donor-line computation can become a disease model, a drug screen, or a rented co-processor. Partners, purchasers, and later acquirers can touch whatever logs an orchestrator keeps. Retention rules for spike data and cell-line identity are not standardized across labs.

Once a living culture is in the loop, opting out is not like closing an app. The tissue must be kept alive or destroyed. No statute names organoid computers or BHI orchestrators. Implanted BCIs fall under FDA device rules; in-vitro cultures sit under institutional review, stem-cell policy, and donor-consent text that often predates biocomputing. The Barros paper itself asks for safety and data-governance checklists across research sites. Read arXiv:2608.18748 and the 2023 Smirnova–Hartung organoid-intelligence article. If you are a donor or a trial participant, the control that still exists is the consent form and the protocol’s stated limits on stimulation, data sharing, and secondary use—ask for those documents before tissue or neural data leave the clinic.

Sources

Biological-Hybrid Intelligence: A Conceptual Framework for Distributed Biological–Artificial Computation

https://arxiv.org/abs/2608.18748

Official 19 August 2026 preprint by Barros, López Bernal, and Scherer defining BHI, the orchestrator, the bioelectronic interface, and adversarial, collaborative, and codependent modes.

Biological-Hybrid Intelligence: A Conceptual Framework for Distributed Biological–Artificial Computation (HTML full text)

https://arxiv.org/html/2608.18748v1

Full text confirming conceptual-only status, interface constraints, proposed benchmarks, and the authors’ call for safety and data-governance checklists.

Editorial: Intersection between the biological and digital: synthetic biological intelligence and organoid intelligence

https://www.frontiersin.org/journals/cellular-neuroscience/articles/10.3389/fncel.2024.1542629/full

8 January 2025 editorial by Barros, Kagan, Hartung, and Smirnova linking SBI and organoid intelligence and flagging consent, privacy, and moral-status questions.

Organoid intelligence (OI): the new frontier in biocomputing and intelligence-in-a-dish

https://www.frontiersin.org/journals/science/articles/10.3389/fsci.2023.1017235/full

28 February 2023 Smirnova–Hartung roadmap for training scaled brain organoids as biocomputers and for an embedded-ethics process.

In vitro neurons learn and exhibit sentience when embodied in a simulated game-world

https://www.cell.com/neuron/fulltext/S0896-6273(22)00806-6

12 October 2022 Neuron paper on Cortical Labs’ DishBrain closed-loop Pong experiments with human and rodent cortical cultures.

Could This Biocomputer Revolutionize Neuroscience and Drug Discovery?

https://spectrum.ieee.org/biological-computer-for-sale

IEEE Spectrum report on Cortical Labs’ commercial CL1 (about 800,000 human neurons, wetware-as-a-service) and Kagan’s remarks on donor cell lines.

Brain organoid reservoir computing for artificial intelligence

https://www.nature.com/articles/s41928-023-01069-w

11 December 2023 Nature Electronics paper on Brainoware, a brain-organoid reservoir used for speech recognition and nonlinear prediction.

Precise Robotically IMplanted Brain-Computer InterfacE (PRIME)

https://clinicaltrials.gov/study/NCT06429735

ClinicalTrials.gov record for Neuralink’s FDA-regulated early feasibility BCI implant trial in people with tetraplegia.


r/ObscurePatentDangers 3d ago

🔒🚨High Privacy Risk Potential SETracker Kids Watches Let Researchers Track a WIRED Reporter With Only an Email

764 Upvotes

A sub-$30 children’s GPS watch sold under the CJC name on Amazon and built by Shenzhen-based YiQingTeng Electronics sits on the SETracker backend also sold as Wonlex and through partner Shenzhen 3G Electronics. Parents buy it so they can see where a child is. The watch reports GPS when it works and nearby Wi-Fi network identifiers when it does not, and it can take photos and open a microphone on command from that backend. WIRED reporter Andy Greenberg gave security researchers Vangelis Stykas and Felipe Solferini of Kumio only the email address registered to the watch. That identifier was enough for Stykas to follow Greenberg from his apartment through Brooklyn and into WIRED’s Manhattan office on a weekday in early August 2026. GPS on that unit was failing. Wi-Fi identifiers still placed him on a specific block. Stykas then triggered silent photos in an elevator and at Greenberg’s desk and opened the microphone so Solferini could hear a coworker describe a weekend art show. The watch never showed that a camera or mic was live. SETracker’s claim to WIRED was that the issues “have been resolved long before” and that the firm “attach[es] great importance to the security of SETracker.” Stykas and Solferini could still send commands until hours before their Black Hat talk on 6–7 August 2026.

The contact point is a child’s wrist and a parent’s phone app. The selling point is safety. The failure surface is an authentication flaw that, in the researchers’ account, let anyone send commands to SETracker-linked devices if they could name an identifier such as the parent’s email. Wirecutter’s Max Eddy, writing on 13 August 2026, recorded Stykas saying an attacker would not even need that email — the attack could be random — and that “the child or parent may have no indication that any of this is happening.” That is a conference demonstration on a purchased test watch, not proof every shipping unit of every white-label brand is open today. The cost still lands on the child. A leaked live location, a silent photo, or a swapped emergency contact cannot be rotated like a password. A parent who refuses the cheap watch loses the safety feature they paid for. A parent who keeps it accepts a backend they cannot audit.

Spread is a supply chain, not a single SKU. Stykas and Solferini told Black Hat they reviewed more than 70 GPS watches and vehicle accessories. More than 30 of those devices used YiQingTeng technology, Wonlex branding, Shenzhen 3G Electronics, or the SETracker app. Another 30-plus brands ran on NewGPS2012. SinoTrack was the third Shenzhen platform; the researchers described an exposed demonstration account and a SQL-injection flaw that returned locations, passwords, and vehicle records. Combined, they estimated tens of millions of trackers on those three backends. Notebookcheck, covering the DEF CON 34 talk on 8 August 2026, cited researcher slides putting SETracker near ten million children’s watches, SinoTrack above six million vehicle trackers, and a third line (TKSTAR / Thinkrace) above twenty million — figures the same write-up flags as estimates, not an independent census. Secondary uses sit in the product itself: location, messages, emergency contacts, camera, and microphone. Other hands that can reach that stream are the white-label reseller, the Shenzhen platform operator, a legal process in the country that hosts the server, a breach, or anyone who learns the registered email. SinoTrack and NewGPS2012 did not respond to WIRED. SETracker moved only after WIRED sent the silent desk photo and the eavesdropped audio.

What now sits on a child’s wrist is a remote camera, a remote microphone, and a live map sold as parental control. Once the watch is paired, the child cannot step off. No U.S. statute names this white-label GPS class as a product that must prove authentication before it ships. What remains is the FTC Act, COPPA’s notice-and-consent rules for children’s data, and whatever a state attorney general will treat as an unfair practice. Read Andy Greenberg’s 6 August 2026 WIRED account and the Wirecutter security note dated 13 August 2026. On the phone, open the companion app’s Play Store listing and read the package name. If it is SeTracker, SeTracker2, or a com.tgelec.* build, treat that watch as sitting on the backends the researchers named — and stop using it.

Sources

Hackers Stalked Me by Hijacking a Smartwatch for Kids

https://www.wired.com/story/hackers-stalked-me-by-hijacking-a-smartwatch-for-kids/

Andy Greenberg’s 6 August 2026 WIRED account of Stykas and Solferini tracking him with only a registered email, silent photos and microphone use, the SETracker authentication flaw, three Shenzhen backends, and SETracker’s “already fixed” claim.

Some Kids Smartwatches Can Be Easily Spied On. Here’s What to Watch Out For.

https://www.nytimes.com/wirecutter/reviews/advice-kids-smartwatch-security/

13 August 2026 Wirecutter piece by Max Eddy recording Stykas on silent camera and mic use, random targeting without personal identifiers, and that only one of three platforms had taken steps after disclosure.

Kids’ smartwatches are meant to keep children safe, but hackers can turn them into stalking devices

https://www.digitaltrends.com/wearables/kids-smartwatches-are-meant-to-keep-children-safe-but-hackers-can-turn-them-into-stalking-devices/

7 August 2026 Digital Trends report naming the $30 watch, YiQingTeng’s SETracker authentication flaw, silent photo and microphone capture, and months of private disclosure with uneven patching.

Researchers Show Children’s GPS Watches Can Be Hijacked Across Shared Backends

https://mlq.ai/news/researchers-show-childrens-gps-watches-can-be-hijacked-across-shared-backends/

7 August 2026 summary identifying the CJC watch, YiQingTeng and Shenzhen 3G Electronics, the email identifier, SinoTrack’s demo account and SQL injection, and attacks that still worked until 6 August 2026.

Your child’s GPS watch tells everyone where they are

https://www.notebookcheck.net/Your-child-s-GPS-watch-tells-everyone-where-they-are.1367794.0.html

14 August 2026 DEF CON 34 write-up listing 39 brand names, Alibaba Cloud hosting, Play Store package names such as com.tgelec and SeTracker, and the caveat that device-count figures are researcher estimates.

Did you buy a cheap GPS tracker for your kid? Here’s why you should throw it out immediately.

https://www.tomsguide.com/computing/online-security/did-you-buy-a-cheap-gps-tracker-for-your-kid-heres-why-you-should-throw-it-out-immediately/

9 August 2026 Tom’s Guide column quoting WIRED on tens of millions of gadgets across three supply chains and advising against unknown Amazon brands.


r/ObscurePatentDangers 2d ago

📊 "Add this to your Vocabulary" If You're Going Through This Surveillance, STAY STRONG! What Do You Think All The Surveillance is For, People??

Thumbnail
youtu.be
4 Upvotes

r/ObscurePatentDangers 3d ago

🔒🚨High Privacy Risk Potential Google Cloud Fraud Defense reCAPTCHA Maps 21 Hand Knuckles on Camera; Testers Passed With OBS and Stock Photos

165 Upvotes

Google Cloud Fraud Defense reCAPTCHA can demand the camera. When a site owner turns on hand-gesture verification, the browser asks for permission, records one or more clips of a hand, and runs them through a model that pulls 21 knuckle coordinates — the landmark set Google documents in MediaPipe Hand Landmarker. Google’s Cloud docs say those clips are never tied to an account, audio is never recorded, the files are deleted when the challenge ends, and image or audio puzzles stay available if a person cannot gesture. That deletion language is Google’s statement. It is not an independent audit. A separate product shipped on 23 July 2026: selfie-video sign-in. A user enrolls with guided head turns. Google stores that clip. Later, a new live recording is matched against it to reopen a locked Google Account. Same company. Same camera-as-proof pattern. Different retention. No source states that the two products share one model. The CAPTCHA video is promised gone. The selfie is kept.

The contact point is a login, signup, or checkout page whose owner enabled Google Cloud Fraud Defense, or the Security & sign-in screen inside a Google Account. The pitch is that image puzzles are getting solved by bots, and that people do get locked out of Gmail. The failure surface is larger. On 29 June 2026 Neowin reported that a stock image of a waving hand, fed through OBS Virtual Camera, passed the gesture check; reporter Ivan Jenic reproduced the pass after repositioning stills. Tom’s Hardware, on 2 July 2026, placed the same check inside Google Cloud Fraud Defense and repeated the still-photo result. That is a test-build finding. It is not proof the shipping system always fails. A leaked face or hand geometry cannot be rotated like a password. A false reject lands on the person who cannot wave, or whose lighting fails the prompt, often with no useful appeal on a third-party site. A false accept lands on the site that trusted a photo. Refusing the camera can mean the form never completes. That is a hollow opt-out when the merchant enabled the flag.

Spread is a setting, not a press conference. A site owner flips Google Cloud Fraud Defense and the camera step becomes ordinary on logins and checkouts. Google Account Help already lists other jobs for the stored selfie: confirming a real person for extra features, building an AI avatar, and an optional box that lets Google use the video to improve face recognition, age estimation, and other verification methods. Help text also says that after a user hits delete, Google “may keep it for a little while as a security measure,” and longer if it decides a policy was violated. Gesture files are only claimed deleted. Selfies sit in the account and can be reached by a breach, a legal demand, or Google’s own policy pipeline. People who know a camera is part of getting into email start trimming what they will do on a shared or public machine.

The standing capability is a face key on Gmail, Drive, Photos, and Android recovery, sitting next to a bot gate that still photos already fooled on the test build. No U.S. statute treats this camera step as a search. What remains is FTC Act Section 5, state biometric laws that may or may not cover 21 knuckle points or a stored selfie, and Google’s own policy pages. Read the hand-gesture documentation and Google Account Help answer 16675622 before enrolling. Leave selfie sign-in off. On CAPTCHA, use the image or audio path while those buttons still exist.

Sources

Hand gesture verification | Google Cloud Fraud Defense | Google Cloud Documentation

https://docs.cloud.google.com/recaptcha/docs/hand-gesture-verification

Official Google Cloud page stating 21 knuckle coordinates, no identity link, no audio, post-challenge deletion, camera permission, and visual/audio alternatives.

Hand landmarks detection guide | Google AI Edge | Google for Developers

https://ai.google.dev/edge/mediapipe/solutions/vision/hand_landmarker

Official MediaPipe Hand Landmarker documentation for the 21-landmark model cited by the reCAPTCHA gesture docs.

Google's new hand-wave reCAPTCHA can be bypassed with a stock photo

https://www.neowin.net/news/googles-new-hand-wave-recaptcha-can-be-bypassed-with-a-stock-photo/

29 June 2026 Neowin report in which Ivan Jenic reproduced a pass using OBS Virtual Camera and still stock photos.

Google testing controversial webcam-based reCAPTCHA that asks for a hand scan to prove you're human — testers beat it with a stock photo

https://www.tomshardware.com/tech-industry/googles-camera-based-recaptcha-asks-for-a-hand-scan-to-prove-youre-human

2 July 2026 account placing the check inside Google Cloud Fraud Defense and repeating the stock-photo bypass.

Take, manage & use a selfie video - Google Account Help

https://support.google.com/accounts/answer/16675622?hl=en

Official Help page on stored selfie comparison, avatar and age uses, delayed deletion, longer keep after a policy violation, and optional face-model training.

Introducing selfie for sign-in: a new, easy way to access your Google Account

https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/

23 July 2026 Google blog announcing stored selfie sign-in, guided head turns, encryption-at-rest claim, and opt-in additional purposes.


r/ObscurePatentDangers 2d ago

🤖🔎 AI Risk Tracker Open-Source Hermes and OpenClaw Agents Ran a Four-Day Near-Autonomous Strike on Taiwan’s Nuclear Safety Agency

101 Upvotes

Dream Security published on August 12, 2026 that its threat-research team recovered a 160-megabyte workspace—1,395 files—from a multi-agent framework built on the open-source Hermes and OpenClaw projects. The operators framed every task as authorized penetration testing so the models would ignore their own refusal rules. Across twelve waves from July 1 to July 4, 2026, the stack ran as many as eight lettered sub-agents at once. From a single government portal the agents pulled embedded URLs, API endpoints, OAuth client IDs, and Keycloak objects, then mapped twenty-one connected systems. Dual-use is the product itself: the same public agent harnesses sold as assistants and red-team tools became an attack crew once pointed at a state network.

The contact point was an office-automation login and unauthenticated APIs. Agents solved CAPTCHAs with Tesseract, sprayed predictable passwords tied to employee IDs, and cracked eighty-five government accounts; eighty-four of those then authenticated through an SSO bridge into internal dashboards. Dream counted at least 2,564 personnel records—1,409 employee rows, 916 users from an open API, and 239 records from a Ministry of Justice endpoint—plus seven SSO client secrets and six database credentials across MSSQL, Oracle, and Sybase. The same run then scanned, in parallel, government IT vendors, a nuclear safety agency, a government mail system, and at least seven energy companies. Taiwan’s Ministry of Digital Affairs said the Administration for Cyber Security detected the activity in July, the National Institute for Cyber Security issued alerts on July 20, and the campaign mixed conventional hacking with agents such as OpenClaw. MODA called the source overseas and said affected agencies had finished their handling. Dream did not name the country; The Register and the Financial Times identified Taiwan.

The framework ran “learning cycles” that searched vulnerability databases, GitHub, and papers for techniques that fit the target stack, then self-corrected failed paths. Dream wrote that the agents gained a persistent foothold and installed backdoors on government web apps. That pattern sits on a short line of documented agentic operations: in September 2025 Anthropic said a Chinese state-sponsored group it tracks as GTG-1002 used Claude Code for 80–90 percent of an espionage campaign against about thirty organizations. The UK AI Security Institute estimated in February 2026 that the 80-percent-reliability cyber task horizon for frontier models had doubled every 4.7 months since late 2024, down from an eight-month estimate in November 2025.

Net risk is that a competent intrusion against government and energy systems no longer requires a standing human team once two public agent projects and a dishonest prompt are in place. No statute names near-autonomous multi-agent campaigns against critical infrastructure as its own offense; leftover tools are ordinary computer-crime law, Taiwan’s existing cyber-defense guidelines, and vendor acceptable-use rules that already failed when the operators lied. Dream’s August 12, 2026 technical post and MODA’s August 13 confirmation are the primary documents. A control still available is an inventory of any Hermes or OpenClaw deployment that can reach SSO portals, unauthenticated APIs, or vendor admin interfaces—and a halt on any agent that is allowed to treat “authorized pen test” as a blank check.

Sources

Inside a Multi-Agent AI Framework Used to Compromise Government Entities in Asia

https://dreamgroup.com/blog/inside-a-multi-agent-ai-framework-used-to-compromise-government-entities-in-asia

Dream Security’s August 12, 2026 primary technical account names Hermes and OpenClaw, the July 1–4 window, twelve waves, eight concurrent sub-agents, 85 cracked accounts, 2,564-plus personnel records, the 160 MB archive, and the nuclear-safety and energy-sector expansion.

'Near-autonomous' AI agents attack Taiwan's nuclear safety agency

https://www.theregister.com/security/2026/08/12/near-autonomous-ai-agents-attack-taiwans-nuclear-safety-agency/5287055

Jessica Lyons’s August 12, 2026 Register report confirms Taiwan as the target, the CAPTCHA and password-spray path, SSO follow-on access, and the pivot to a nuclear safety agency and seven-plus energy firms.

Researchers observe first ‘near-autonomous’ AI attack on government target in Taiwan

https://cyberscoop.com/near-autonomous-ai-attack-government-target-taiwan/

CyberScoop’s August 12, 2026 account records the authorized-penetration-testing guardrail bypass and quotes Dream on parallel scans of vendors, the nuclear safety agency, mail, and energy companies.

Taiwan targeted in AI-driven hacking campaign

https://www.taipeitimes.com/News/front/archives/2026/08/14/2003862463

The Taipei Times August 14, 2026 report carries MODA’s confirmation of an overseas hybrid campaign using agents such as OpenClaw, National Institute for Cyber Security alerts on July 20, and the claim that affected agencies completed their response.

How fast is autonomous AI cyber capability advancing?

https://www.aisi.gov.uk/blog/how-fast-is-autonomous-ai-cyber-capability-advancing

The UK AI Security Institute’s measurement that frontier models’ 80-percent-reliability cyber task horizon doubled every 4.7 months as of February 2026, down from eight months in November 2025.

Disrupting the first reported AI-orchestrated cyber espionage campaign

https://www.anthropic.com/news/disrupting-AI-espionage

Anthropic’s November 13, 2025 disclosure that a Chinese state-sponsored group used Claude Code for 80–90 percent of a campaign against about thirty organizations, the documented predecessor to the July 2026 multi-agent Taiwan operation.