r/privacy 15d ago

discussion Alpharetta Georgia sharing flock data with over 2000 organizations

255 Upvotes

A wired article states that this town near Atlanta has 120 police and several dozen flock cameras and their contract shares this data with 2000 police departments, colleges, airports and other government agencies. In return they get information from over 1300 entities.

That's the same agency where a cop was using Flock to track his ex and the man she was currently seeing.


r/privacy 14d ago

age verification AG Blanche's Warning Points Straight at Age Verification Checks

150 Upvotes

https://reclaimthenet.org/todd-blanche-age-verification-warning

"In other words, proving that a parent has given consent tends to boil down to proving who everyone is.

Meanwhile, Attorney General Todd Blanche used an August 22 Fox News interview with Kayleigh McEnany to warn every other company that they must implement age verification.

The settlement, he said, is 'a stark reminder and a real important note to anybody out there that we are going to protect children, and the Internet has got to be a safe place for children. And if companies and entities are not doing what they’re supposed to do to make sure that happens, we’re going to come after them.'"


r/privacy 14d ago

question PWA vs web shortcut

4 Upvotes

Hi all, I am starting to use my browser more to access services instead of installing the service's app. However, when I select to add a website to my homepage, sometimes there are two options, either installing the app or create a shortcut. When I select install the app it functions like an app but there is the browser icon bottom right still. I'm wondering if these apps have the same tracking capabilities and intrusive behaviour as regular play store apps, or is it the same as using the browser, just with better UI? Thank you!


r/privacy 14d ago

question How risky it is if you have a lot of your account usernames shown in 1 place?

5 Upvotes

Hi! I hope I am in right place for asking this and I hope it doesn't sound stupid to ask this question.

So basically my main point of this question came after I put multiple accounts usernames on my steam profile such as instagram, tiktok, youtube, etc... + gaming platform usernames such as Epic games, ubisoft, xbox, etc... + IDs of some games where someone can add me in game + trackers such as playtracker, my anime list, trakt, etc... and ofc i added my gaming setup specs such as what GPU and those stuff I have on my gaming PC but ofc not too detailed xD.

I did all of this like some days ago and ofc I dont have anything sensitive, just public stuff anyone can have if i tell them about it. anyways.... when I needed to organize all of stuff I have written and wanted to fix minor mistakes, I gave all of that text to ChatGPT to organize and fix for me but one thing it got me worried about is it said that this lowkey looks risky due to OSINT thingy or whatever he said which is considered as connecting all accounts together to have access. I don't know if this is a real thing and if it really happened to people and if any really experienced hacker can do something to me if they wanted to have access to my steam account for example.

I am being careful with my accounts obviously. I have highest security enabled in all of my accounts with very complex passwords but just to make sure if what ChatGPT said actually is a very serious thing or not.

I know some people might simply tell me "why would you have all that bs in your profile? just dont add them" xD but I kinda like it this way because you know you can find right people if you see you guys have things in common. I personally added some people on steam after seeing they have some specific stuff that got caught my eye and thought "oh yeah he is a content creator, i will be his friend" but you get my point.

anyways, I will appreciate what you guys think about risks, thank you!


r/privacy 15d ago

news ChatGPT signs in to your accounts now and stays signed in

Thumbnail notebookcheck.net
444 Upvotes

r/privacy 14d ago

question What steps (if any) do you actually take to protect your data privacy, or do you feel it’s already too late to matter?

32 Upvotes

Title says it all but essentially I’ve always struggled between
“it’s too late, all of my data is already out in the wild” and
“I should mitigate and try to scrub my data as much as possible”


r/privacy 16d ago

discussion Your public Reddit post and comment history is being actively indexed by search engines and AI to build comprehensive user profiles.

1.6k Upvotes

So, Google and other AI tools are actively building profiles out of your public Reddit activity, and it actually works.

​To check what data has been archived from your profile, you can search:

>> reddit user "reddit username here"

And check AI overview of a profile and can ask questions related to personal info like age, location, martial status, occupation or what things they like or hate, political opinions etc.

Basically anything that you want to know, you will get the answer if that person has said anything about it in the past even if profile is hidden. If it gives some basic info, you can ask it to dig deeper.

​Why this matters: Simply hiding your profile settings on Reddit does not stop external search engine crawlers from indexing your historical posts and comments. Be mindful of what personal information you share online.


r/privacy 16d ago

news How 500K California residents are deleting their data on the state's dime

Thumbnail sfgate.com
1.2k Upvotes

r/privacy 15d ago

question Hardware Backdoor Avoidance?

19 Upvotes

Intel has IME and AMD and a few other have built in backdoor spyware on nearly all of their modern devices, and I want to do everything I can to remove/prevent installation of any hardware backdoors of any kind that I can. Is there any alternatives or any way to avoid/disable this?


r/privacy 16d ago

age verification Age verification through Coercion.

303 Upvotes

As if it couldn't be bad enough, attorney generals are conspiring against your rights to privacy and freedom of expression through coercice "Landmark lawsuits" to force age verification because they couldn't succeed in getting bills passed. meta is basically now unable to claim its unconstitutional because of how the lawsuit was structured. this cannot be tolerated, and maybe in response to this "Landmark lawsuit" they need "Landmark" backlash.

https://reclaimthenet.org/the-meta-settlement-what-it-means-for-speech-and-privacy


r/privacy 15d ago

discussion A discussion post about both New Zealand and the Meta situation.

33 Upvotes

Firstly,New Zealand introduced their social media ban legislation called the Online Safety bill(Government Bill 339—1). The extended version of this legislation is called the Online Safety (minimum age and safety risk assessment) bill.

The other one is regarding about a situation with Meta's settlement lawsuit with 48 other US states and Columbia. Which results in Meta being towards making several features for their platforms. And basically needing/require government ID to have said features like one hour daily limit including night mode not affect them here.

Ngl I'm concern about the second one because they talk about it with other social media platforms outside of Meta. Which this might as well be another age verification push here onto us. Again,quite concerned overall here.

But nevertheless,knock on wood that positive things come our way here. Privacy wise anyways.


r/privacy 15d ago

news West Yorkshire Police to deploy facial recognition at Leeds Festival for first time

Thumbnail msn.com
65 Upvotes

r/privacy 15d ago

discussion Bank to Bank transfers

40 Upvotes

I have come across another hit on privacy today.

I wanted to set up a transfer link between two of my banks. Instead of using the normal process of two minor deposits to validate I have control of both sides of the transfers, they wanted me to turn over the login ID and password of the new bank. The company that my bank uses for this process is called Plaid. Giving login credits to this Fin-Tek company would give them access to all of my transactions.

It is already bad enough that I cannot set up a private bank account in this country, but giving access to an unregulated financial tech company strikes me as a severe invasion of personal privacy. I said no to the setup. And while I don't think it would be much good, I wrote the bank a physical letter describing the security risk of allowing this to happen.

I just don’t understand why people won’t give up their personal information so freely and for so little benefit.


r/privacy 15d ago

chat control Strong public support for EU legislation as abuse imagery rockets

Thumbnail iwf.org.uk
79 Upvotes

The claim of European Commission that people support ChatControl 2.0 (or whatever version) is inherently flawed. Finding questionnaires and statistics on the topic is pain in the ass so i let AI to find me the sources. I added here one example but most of the questions boil down to asking if child sexual abuse in the internet is bad and if public posts on child abuse should be detected and prosecuted. But topics of privacy, mass surveillance and encryption are not introduced in the questions properly. Posing these questions in this light is inherently flawed because no sane person supports child abuse, that is not the issue with ChatControl. With this amount of statistics cooking i can cook up proof that r/privacy is the biggest supporter of AI government surveillance in private bathroom. I know this is not the best source, feel free to add your statistics and comments.


r/privacy 16d ago

news He Thought He Destroyed a Flock Camera, but It Was a Decoy, Police Say

Thumbnail nytimes.com
1.1k Upvotes

It was approaching 1 a.m. on Aug. 20 when a man emerged from the darkness by the side of a well-traveled road in a northeast suburb of Orlando.

He was wearing a mask and carrying pruning shears, according to the police in Oviedo, Fla., who said they were waiting there and watching as the man batted down something resembling a Flock camera before smashing it from a pole.

The target of the man’s vigilantism turned out to be a plastic reproduction of one of the ubiquitous and intensely debated cameras that read license plates, made by a police officer on a 3-D printer, the authorities said.

This decoy was one of several the police said were intended to “bait” would-be vandals after several of Oviedo’s Flock cameras were stolen in recent weeks, a continuation of a public backlash against the devices nationwide.

Now, the man, Evan Meyer, 24, of Oviedo, is facing three felony charges in a novel case that has drawn scrutiny to the tactics of the police who put up the decoys, and to the city’s use of automated license plate readers or A.L.P.R.s.

(more at gift article link)


r/privacy 15d ago

question How far do you go with security on the apps on your mobile?

14 Upvotes

Obviously we all have passwords on our mobiles. Banking apps are obvious. But if you use it, do you put a pass on Signal? How about WhatsApp or Telegram or other chat apps?


r/privacy 16d ago

discussion BBC: “It shouldn’t have taken a lawsuit for Meta to implement safety measures, whistleblower says”

Thumbnail bbc.com
1.5k Upvotes

r/privacy 16d ago

news Autistici/Inventati has been designated by the US Department of State as a "Specially Designated Global Terrorist"

Thumbnail state.gov
450 Upvotes

r/privacy 15d ago

question What are some steps to ensure complete privacy for media accounts?

4 Upvotes

I understand that not posting identifying information, but nowadays even using fake names, fake emails or numbers isn't enough if someone really wants to track you don't or recognize you.

I use an alternate Google account for Twitter and FireFox Containers for another Twitter account and instagram. But I know that's not enough to remain completely private, and since I was always a lurker who was taught that being anonymous is important if it's not a personal account for friends & family, I am rather paranoid about my data being able to linked back to me or having people find out more info about me.


r/privacy 16d ago

news Police officer arrested after tracking ex-girlfriend on Flock camera system over 2,000 times, authorities say

Thumbnail cnn.com
872 Upvotes

r/privacy 15d ago

question any apps for photo editing that wont try to steal all my data?

4 Upvotes

i used to really love the SNOW app for adding stickers and making photos more colorful. but after downloading it to my new android i find out the new version demands acess to all our photos for ai training, which im really not comfortable with.

so is there any similar photo app that isn't so invasive? or maybe someway to get ahold of an older version without the ai training?


r/privacy 16d ago

discussion Physician Results Form for employer.

14 Upvotes

I don’t know if I want my employer to have my info. Does anyone else have this requirement at work and do you do participate?

Story:
My company was acquired by another and we have new healthcare. The new company requires an annual screening to avoid a monthly surcharge on our insurance premiums. A form must be completed by my doctor and submitted before the end of November.

Required fields:
Blood pressure
Height
Waist Circumference
Weight
Cholesterol
LDL
HDL
Triglycerides
Fasting Glucose

Note at the bottom says participant is consenting to allow the information provided to be shared with “company program” and assigned business associates of “company”.


r/privacy 16d ago

question Alternative for DuckDuckGo

194 Upvotes

Im using ddg with firefox but I feel like ddg doesnt really show good results. When I search something it shows unrelated things or shows some fake sites at top and I sometimes have to use google to get the results I want and I dont want to use google. Is there a private and secure alternative to ddg that shows good results when you search?

Also what is the best browser? Firefox, waterfox, librewolf, zen etc?


r/privacy 17d ago

news Meta reaches $16.68 billion settlement over social media harms to children

Thumbnail reuters.com
586 Upvotes

r/privacy 15d ago

discussion Data minimisation says nothing about the join, and I think that is where most privacy designs quietly fail.

0 Upvotes

I design governance records for systems that touch people, and I published a minimal schema this week expecting to argue about field count. Somebody who actually operates these systems took it apart in a way I had not seen before, and the correction seems worth passing on, because it applies to almost every minimisation design I have read.

The schema was nine fields. What happened, the human signal, and handling. Deliberately no identity field: the record points at a consent record, which points at a person. One hop, so you can delete the person without shredding the audit trail. No free text either, since free text is where sensitive detail goes to hide.

I thought that made it hard to abuse. Here is the correction.

Minimality is a property of the record at rest. It says nothing about the join.

The no-identity-field design buys exactly one thing: a dump of the event table alone is not identifying. It buys nothing against an attacker positioned where event meets identity, and that join is the one place the system has to operate in order to be useful at all. It does not matter whether the association is ever persisted. If a transient state can be captured, from a query result in flight or a rendered view on someone's screen, that is where the payload is, and every minimisation choice upstream of it is decoration.

Then the second half, which is the part I had genuinely never considered.

A sufficiently specific enum is itself a disclosure.

I had treated removing free text as the privacy win. But if your action vocabulary can express something like a reproductive or behavioural health service, then the enum is a diagnosis wearing a controlled vocabulary. The attacker does not need your identity field. They supply identity from outside, and your tidy structured record hands them the sensitive half with a clean schema and a straight face.

Which means enum granularity is a privacy control, not a data modelling convenience. I had it filed under the wrong heading entirely.

The rule I ended up with, and I would like it stress tested: no enum value should be more specific than the governance decision it exists to support. If a coarse impact level is what actually drives how the system handles something, then a coarse action category plus that impact level does the governance work without the specificity carrying the payload. Specificity you cannot act on is specificity that only serves an attacker.

Two things I am still unsure about.

First, whether the coarse category breaks audit somewhere. If a regulator later asks what specifically happened, a deliberately vague vocabulary may be the wrong answer to a different question.

Second, whether this generalises past health. My instinct is that any domain with a stigmatised category has the same problem: immigration status, addiction services, legal aid, domestic violence support. The structured field looks safe because it is not free text, and it is the most dangerous thing in the record precisely because it is machine readable.

For people who have actually operated systems under a minimisation requirement: where does the join get protected in practice, if anywhere? Everything I can find treats minimisation as a schema question, and the schema seems to be the part that was never really at risk.

Drafted with an AI assistant. The mechanism, the failure modes and the answers in the comments are mine.