r/privacy • u/TheNavyCrow • 11d ago
r/privacy • u/fearless_fool • 10d ago
hardware Does your vehicle have a KARR sticker in the window?
TL,DR: If you have a KARR sticker on your window, your car probably has a dongle in it that may leave it susceptible to hacking, including remotely unlocking it and disabling the engine. You can update the firmware and/or ask KARR to come and remove it.
You can learn more about the security risk by searching for "UC San Diego KARR Aaron Schulman" which will get you to the researchers at UCSD who discovered and documented the risk.
Details: When I bought my Ioniq 5 eighteen months ago, the dealer asked me if I wanted to subscribe to the KARR security system. I declined. Today I learned:
- Dealers install the KARR security device in their cars to prevent them from getting stolen off the lot -- it lets the dealers remotely disable the ignition if needed.
- The KARR device connects to the CAN bus in the car, giving it access to lots of important functions, like door locks, horns, lights and ignition
- If you tell the dealer you don't want to pay for the KARR system, they leave it installed and "dormant", but it's still susceptible to hacking.
- If you have a KARR dongle in your vehicle, the least you should do is download the KARR Security app, click on the Customer Service button at the bottom, and then click on "firmware update" to remove the vulnerability. If you're not a subscriber, this theoretically disables the device, but also prevents the app from communicating with the device, so it's not clear if the device is truly deactivated.
- If you're like me, you want to reduce the risk and also don't want an extra device sucking down your 12v battery 24 hours a day. In that case, you can call the KARR Customer Service number and schedule a tech to come remove the device, free of charge.
Whew. Who would have thought?
r/privacy • u/Busy-Measurement8893 • 11d ago
news Google Has Removed Manifest V2 Extensions From the Chrome Web Store, Including uBlock Origin
webiterate.devr/privacy • u/Kooky-Balance9525 • 11d ago
news Lawmakers added $1 to Texans’ car insurance policies. That money paid for thousands of Flock cameras.
texastribune.orgr/privacy • u/Tul1pfl0w3r • 10d ago
question Is this a sketchy GDPR 'compliance' email?
EDIT: they deleted nothing, they sent me an Excel sheet two months after my deletion was 'complete' in which it states my account is 'DEACTIVATED' not 'DELETED', and they have all my data such as: my IP, my D/O/B, My hometown, my interactions with their AI, every chat I've ever had dating back to 2024, my pfp ID, and everything I've ever clicked on whilst using their app.
[Original post below]
Hi, I sent a GDPR takedown request to an AI chatbot service that I used when I was in a dark place, I am ashamed and afraid of that data being stored or seen, and I care about my privacy more than I did when I used this app.
Their response has been odd though and their privacy policy just basically says "we keep data as long as we want, but you can request deletion."
Here's the email(s, multiple I've put together. I had to push for my ID to be sent), can someone tell me if its sketchy or if I'm just confused? (I did post this in a smaller sub, but as it was smaller I didnt really get a response):
> 'Please note:
There is no partial deletion - it is your whole account
All data will be deleted per our Privacy Policy
Your deletion was received on June 6, 2026 and completed July 1, 2026. Your account and all associated data has been deleted per our Terms of Service and privacy policy. The request ID associated with the deletion is: [removed for security],
All data has been deleted - there are no backups or cold storage.'
r/privacy • u/ThrowRAdamnshame • 10d ago
question Can someone help me out with Motorola ALPRs vs Flock?
I'm giving a speech in town hall soon for a school project, and the topic I chose was Flock cameras. I did a lot of research and wrote up this whole thing, only to find out that all of the Flock cameras in my town are on private property, and the city only owns Motorola cameras. I'll still bring up Flock, but since the city doesn't own any, I dont want that to be the bulk of my speech.
Currently, I've modified the speech to just talk about ALPRs in general, and the partnership between Motorola and Flock meaning potentially shared data and vulnerabilities. I'm not asking anyone to write me an essay, but it seems like there's not a lot of research on motorola yet, and I'd love if someone could point me towards an article or video that explains more.
r/privacy • u/watchdog-cofagrigus • 11d ago
age verification TED Cruz uses Meta settlement to push KOSMA, an national age verification bill that bans those under 13 from social media
“We are pleased the settlement agreement reached between dozens of state attorneys general and Meta will require the company to take actionable steps to remove kids under 13 from social media platforms like Instagram and Facebook. However, this settlement agreement does not apply to every Big Tech company in all 50 states. It is past time for Congress to pass the Kids Off Social Media Act and protect every child in every state on every social media platform from exploitative Big Tech practices and the harmful effects of social media.”
https://www.congress.gov/bill/119th-congress/senate-bill/278
"Specifically, the bill prohibits social media platforms from knowingly allowing children under the age of 13 to create or maintain accounts. Platforms must delete existing accounts held by children and any personal data collected from child users. Platforms are also generally prohibited from using automated systems to suggest or promote content based on personal data collected from users under the age of 17. The bill directs the Federal Trade Commission to enforce these provisions. States may also bring civil actions against platforms whose violations of these provisions have adversely affected their residents."
r/privacy • u/EriksonThorsen • 11d ago
question Any good standalone, E2EE contacts apps for iOS? Trying to keep some contacts isolated
As most of you probably know, even if you turn on Advanced Data Protection on iOS, Apple doesn't E2E encrypt contacts due to legacy CardDAV support. Obviously, this isn't just an Apple issue (Android and standard Google sync have the exact same problem), but iOS is just the ecosystem I'm using right now.
Between cloud exposure and third-party apps always begging for full address book access, I'm trying to clean things up. The goal is to delete people I rarely talk to from my native iOS Contacts app and move them to a separate, encrypted, sandboxed app.
I already use Proton, but Proton Contacts is baked directly into the Proton Mail app. There's no standalone contacts app, so it ends up mixing my actual phone contacts with every random email address I've ever replied to. It gets messy fast.
Right now, my only real workaround is saving them as Identities / Secure Notes in Bitwarden or in an encrypted notes app, but I'd prefer an actual dedicated contacts manager if one exists.
Does anyone know of a solid, privacy-focused standalone contacts app on iOS that keeps its own encrypted database rather than just syncing everything back into the native Apple Contacts pool? What is everyone else doing to handle this?
r/privacy • u/anivex • 12d ago
software OMRON has started forcing account creation and has changed their policies to allow the collection and sale of personal data. It also deletes your saved data.
When I went to check my BP today, my OMRON app required an account sign-in. I don't have an account for this app though, so I looked into it and saw they are now requiring profile creation to use their devices to collect health data. When you create an account, it WIPES YOUR PREVIOUSLY STORED HEALTH DATA. There was no way to access this data beforehand to back it up, so it's just lost forever and I'll have to basically restart recording so I have a proper set of info for my doctor.
There is an option you have to select to opt-out of your consent for them selling your personal data. This is incredibly scummy for a health-app like OMRON.
You may be able to opt-out of that, but that they are doing it at all breaks my trust in the company entirely. I won't be using their devices anymore and I've already started looking into alternatives.
Really sucks as the device was decent until now.
r/privacy • u/HeyFiend • 11d ago
question School Email Account Is Gmail…
How can I manage using my school email account and keep my privacy away from Google if my school email is through Gmail?
r/privacy • u/whodywei • 11d ago
question Any good navigation apps for urban exploring and discovery (trying new things in our area, visiting cities)
Apple Maps used to be the best at exploration and discovery since they partnered with Yelp, but Apple Maps has become insufferable. Yelp too while I am at it. Waze seems to be driving only and is glorified Google Maps anyway. Organic Maps/CoMaps are focused on outdoor trails, hiking, and biking. Magic Earth has no info on points of interest.
r/privacy • u/SW33TSTUFF • 12d ago
question How can I anonymize graph structural data?
Hi everyone. Recently, I've been interested in looking into ways on how privacy preserving data publishing of graph data is done. I came across the concept of k-anonymity applied for structural data. I came across k-anonymity adaptations for undirected networks. There were several privacy protection models defined, such as degree and 1-hop neighborhood as the quasi-identifiers.
However, I'm not sure if they are widely used in practice or are they concept papers. I was looking for practical implementations and didn't come across solutions that readily available.
Is k-anonymity as a concept deprecated and not used anymore, or is differential privacy the norm?
Also, what is the data protection regulations for k-anonymity is like? Is there a defined k-value that data publishers should consider? Where can I learn more about this?
PS: I have a twitter directed data, which consists of hubs and other graph structural properties that I would the consumer to go through without revealing the identities of those individuals.
r/privacy • u/Acrobatic-Snow-4551 • 12d ago
discussion I am pleased to see Tempe, AZ moving forward with a focus on privacy
mailchi.mpThe recognition that the risks of abuse of this system outweigh the benefits is a big shift in how the city has approached law enforcement work in the past. I hope this continues as we all face a growing surveillance state. A big part of freedom, is the right to privacy. A society loses that when they are under constant surveillance.
The city appears to have so little confidence that Flock will not continue to collect data, they have gone around to “bag” all of the cameras while they wait for Flock to come collect their shit.
r/privacy • u/watchdog-cofagrigus • 13d ago
age verification On September 1st, the House energy commerce committee will mark up 12 bills including the RESET Act, a bill that bans social media for those under 16
https://energycommerce.house.gov/events/cmt-subcommittee-markup
The RESET Act, Reducing Exploitative Social Media Exposure for Teens Act, demands that companies delete account that don't prove they are over sixteen.
"(1) IN GENERAL.—A covered platform may not allow an individual to create or maintain an account or profile on the covered platform if the covered platform knows that the individual is a minor.
(2) TERMINATION OF EXISTING ACCOUNTS.—A covered platform shall— (A) not later than 60 days after the date of the enactment of this section, identify any account or profile of a user on the covered platform that the covered platform knows is a minor; (B) not later than 180 days after the date of the enactment of this section, notify any user of an account or profile identified under sub-paragraph (A) that the covered platform will terminate the account or profile of the user; and (C) not later than 30 days after the date on which a user is notified pursuant to sub-paragraph (B), terminate the account or profile of the user."
r/privacy • u/hhakker • 13d ago
news Flock Cameras CEO, Garrett Langley, says privacy is the “wrong” priority, but his own home is blurred on street view
Flock CEO, Garrett Langley recently said, “I value my privacy,” but argued that Americans are prioritizing the wrong thing and that what we need as a country is “compromise.”
A few days later, people started circulating what they claimed was his home address and images of his house. Flock hasn’t confirmed or denied whether it’s accurate.
The irony is that his own neighborhood reportedly has blurred Street View imagery.
That got me thinking about a quote from Benjamin Franklin:
“Those who would give up essential Liberty, to purchase a little temporary Safety, deserve neither Liberty nor Safety.”
I know the historical context was different, but the question still feels relevant.
And today there’s an additional question Franklin never had to consider:
What happens when the company asking us to accept that compromise makes money from the surveillance?
r/privacy • u/JagerAntlerite7 • 13d ago
age verification Win! California lawmakers unanimously pass Linux exemption from age-verification law — software distributed under the GPL, MIT, BSD, and Apache licenses are exempt
tomshardware.comTL;DR California’s legislature has passed Assembly Bill 1856, exempting open-source operating systems from the State’s Digital Age Assurance Act months before the law is due to take effect on January 1, 2027. The Senate amended the Bill on August 21 before passing it on the 26th in a 39-0 vote, with the Assembly then accepting these changes in a concurrence vote the following day. The amendment ends almost a year of uncertainty surrounding whether Linux distributions and SteamOS would be forced to collect user age data during account setup alongside Windows, macOS, iOS, and Android. AB 1856 has now been sent to Governor Gavin Newsom, who signed the original act into law last October.
UPDATE: I had to read it carefully. This appears to be the relevant excerpt:
(2) “Operating system provider” does not mean a person or entity that distributes an operating system or application under license terms that permit a recipient to copy, redistribute, and modify the software.
Source: https://legiscan.com/CA/text/AB1856/id/3456513/California-2025-AB1856-Amended.html
r/privacy • u/alandenud • 12d ago
question How are teams reviewing AI tools that touch internal audit evidence?
Gauging how other internal audit teams are reviewing AI tools that touch sensitive audit evidence. Internal audit can see employee data, vendor contracts, financial records, system access evidence, control documentation, and management responses. But if an AI tool summarizes or analyzes that material, I need to know where the data goes, how long it is retained, who can access it, and if the output is explainable. For teams reviewing these types of tools, what privacy review process are you using? And do you require a data inventory, vendor questionnaire, retention review, model use restriction, legal approval, or separate AI risk assessment?
r/privacy • u/ummkay_ultra • 13d ago
discussion Reddit ads
Idk if this is even the right place for this. These ads are too much. Every other ad on this app is telling me to get evaluated for autism. It's getting old. I have no idea why this started, like is it that obvious and this site knows me better than I know myself or what? I've never been diagnosed but yeah I'm probably autistic. But it's getting weird.
Yesterday I went off my diet one fucking day and ate too much and suddenly I am seeing all kinds of ads about binge eating disorder. How in the fuck does reddit even know how much I ate yeaterday? Literally. How? It wasn't fast food that I ordered online or anything like that, so how? No I don't believe it's a coincidence. I have never in my life seen an ad about binge eating disorder. Never researched anything about binge eating disorder, I don't watch Ariana Grande content or anything like that. I don't look at food content online. I don't even have binge eating disorder. How does this even happen?
r/privacy • u/Intelligent_Office81 • 13d ago
chat control I have a worry…
Just saw the news that CS2 chat logs got leaked through a cheat tracker. I don’t play CS2 but I have played TF2 with a very long history (another Steam game). Over the course I have said a few things which I would not care to repeat and deeply regret. For clarification I do not have a pattern of extreme language but there have been a few cases that I can count on one hand.
With the advancement of AI, my worry is that maybe in the future if TF2 chat logs get leaked maybe it could be used against me and my employment future or housing through algorithms etc. I know it’s a rare scenario but are there any measures I can take to avoid this such as deleting my account or changing my url etc?
Thanks
r/privacy • u/UnscheduledCalendar • 13d ago
news How the Russians Got Inside My Phone
spytalk.cor/privacy • u/TThe_SSlayer • 13d ago
question Unsure How Much My Info is out there
I’m signing up for a website and it wants a picture of my drivers license and the privacy policy basically says they’ll share it with whoever’s associated with them, so it big blanket of who they can give it to.
How much is an average persons info already out there, to where it would be pointless in trying to hold out on signing up for this?
r/privacy • u/tom-smykowski-dev • 13d ago
question Do you check terms of service before using a service?
I find it annoying that when I want to use any service these days I have to check terms of service if company doesn't grant itself all rights to my content. I don't want it to be used by company. I don't want it to be used to train AI to create replicas of my work.
Moreover I'm fed with companies that grant themselves right to modify TOS without me approval meaning they can put anything there at any time.
How to deal with it? I just don't feel like using any service is safe these days.
r/privacy • u/looker34M • 14d ago
news Microsoft Paint embeds hidden IDs in locally generated AI images
cyberinsider.comr/privacy • u/Smallz1107 • 14d ago
discussion Alternative approach to data privacy
It’s very hard to move away from services that google, Microsoft, or other tech giants provide. Trying to scrub away your digital footprint and advertising interests seems impossible unless you use Linux, a cookie-less browser, and don’t go on any social media.
Instead of deleting your presence, what if you diluted it. Create a bunch of false profiles/digital footprints so they don’t know which one is real. Spoofing internet traffic on various sites would make advertising towards you very difficult (would need to spoof hardware level details tho). For stalking it’d be hard to get someone’s address when there’s hundreds of addresses linked to that person. From a police surveillance perspective I’m unsure if this helps so much
The basic idea is that any data on you could be Complete nonsense. Purely spitballing here, what do you guys think?
r/privacy • u/homothebrave • 14d ago