soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
social@octade.net

Search results for tag #privacy

[?]The New Oil » 🤖 🌐
@thenewoil@mastodon.thenewoil.org

Cops Say Snitched on Teens for Allegedly Drinking and Shooting a Toy Gun

404media.co/waymo-called-polic

    [?]Grow Your Own Services 🌱 » 🌐
    @homegrown@social.growyourown.services

    CryptPad is a free open source collaborative online office suite with the emphasis on privacy and "zero knowledge" encryption. You can find out more at:

    🌱 cryptpad.org

    You can follow the project at:

    🌱 @CryptPad

    CryptPad can be self-hosted online, installation instructions are at:

    🌱 docs.cryptpad.org/en/admin_gui

    It can also be self-hosted locally, instructions for local hosting are at:

    🌱 docs.cryptpad.org/en/dev_guide

      [?]The New Oil » 🤖 🌐
      @thenewoil@mastodon.thenewoil.org

      [?]Autonomie und Solidarität » 🌐
      @autonomysolidarity@todon.eu

      Ministerrat trickst EU-Parlament zu umstrittenen Geräte-Scans aus

      Mit einem fragwürdigen Manöver wollen die EU-Staaten für die Neuauflage der »Chatkontrolle 1.0« sorgen. So bleibt auch die Version 2.0 auf der Agenda……

      nd-aktuell.de/artikel/1200941.

      [?]The New Oil » 🤖 🌐
      @thenewoil@mastodon.thenewoil.org

      [?]Indigo Privacy » 🌐
      @indigoprivacy@mastodon.social

      Brave is a free browser built on Chromium that blocks ads, trackers, and fingerprinting scripts by default - no extensions needed. It includes private windows routed through the Tor network on desktop, and its own independent search engine that doesn't track searches.

        [?]DigitalEscapeTools » 🌐
        @xabd@mastodon.social

        Ghost is a free, open-source publishing platform for blogs, newsletters, and membership sites.

        Self-host it, own your content, and enjoy built-in newsletters, memberships, SEO tools, and a fast headless CMS, making it a strong alternative to WordPress, Medium, and Substack.


        More details: digitalescapetools.com/tools/t

        Screenshot of the Ghost project page showing the Ghost logo, project links, release information, and badges highlighting over 100 million downloads, version 6.51.0, and contributor statistics.

        Alt...Screenshot of the Ghost project page showing the Ghost logo, project links, release information, and badges highlighting over 100 million downloads, version 6.51.0, and contributor statistics.

          [?]Catchlight » 🌐
          @catchlightapp@mastodon.social

          Most privacy apps still start by asking you to make an account. Which has always struck me as odd, the account is the thing that gets breached, leaked, or subpoenaed.

          Which is why Catchlight has none. No email, no sign-up, no password to reset.

          A 12-word phrase you generate on your phone is the only key, and it never leaves the device.

          Less to trust, because there's less to take.

            [?]Glyn Moody » 🌐
            @glynmoody@mastodon.social

            rules out a ban after a fierce backlash - thenextweb.com/news/new-zealan " Ministers deny the tools were ever in the frame for the under-16 social media ban, but the panic exposed how age-check laws keep drifting toward encryption "

              [?]Woodoo Prod » 🌐
              @WoodooProd@mastodon.cloud

              Windows est un logiciel de surveillance” : un identifiant caché piste 1,4 milliard de PC, même sous VPN, la preuve vient de tomber

              Un expert l'affirme, le FBI lui a donné raison

              lesnumeriques.com/informatique

              [?]ISOC LIVE » 🌐
              @isoclive@mastodon.nycmesh.net

              WEBCAST 9 JUL 16:00 UTC - Re-Drawing the Privacy Line: Chatrie's Legislative and Oversight Implications

              isoc.live/21532

              The Congressional Internet Caucus Academy hosts a Rayburn lunch panel breaking down the Chatrie v US decision on geofence warrants, location data & the Fourth Amendment, with Jennifer Huddleston (Cato), Jake Laperruque (@CenDemTech) & Paul Taske (NetChoice).

              Blue event title slide for the Congressional Internet Caucus Academy. The Congressional Internet Caucus Academy logo appears in the upper left, with the date "July 9, 2026" in the upper right. Centered in large white text is the session title, "Re-Drawing the Privacy Line: Chatrie's Legislative and Oversight Implications." In the lower left are the hashtag "#locationprivacy" and the handle "@NetCaucusAC." The background is a solid dark blue with no additional graphics.

              Alt...Blue event title slide for the Congressional Internet Caucus Academy. The Congressional Internet Caucus Academy logo appears in the upper left, with the date "July 9, 2026" in the upper right. Centered in large white text is the session title, "Re-Drawing the Privacy Line: Chatrie's Legislative and Oversight Implications." In the lower left are the hashtag "#locationprivacy" and the handle "@NetCaucusAC." The background is a solid dark blue with no additional graphics.

                [?]Indigo Privacy » 🌐
                @indigoprivacy@mastodon.social

                Privacy is a practice, not a product. Start here.

                  [?]The New Oil » 🤖 🌐
                  @thenewoil@mastodon.thenewoil.org

                  [?]Earl » 🌐
                  @Earl@mast.john1126.com

                  AI Spy

                  Trying to live outside, without buying or selling with money, is prohibited.

                  "Audio sensors" have been installed, with the help of Yandex, in one of Russia's protected areas. Eavesdropping with artificial intelligence will detect violations:

                  hunting
                  cutting down trees and bushes
                  lighting fires
                  organizing tourist camps

                  Not allowed!

                  mastodon.ml/@Murga/11685109469

                    [?]The New Oil » 🤖 🌐
                    @thenewoil@mastodon.thenewoil.org

                    [?]ADHDBard » 🌐
                    @rogerc2738@social.vivaldi.net

                    Oracle CEO Larry Ellison, owner of Tik Tok, Paramount Skydance, & others recently noted in an industry discussion on AI surveillance that "citizens will be on their best behavior because we’re constantly recording and reporting."

                    theguardian.com/commentisfree/.

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]The New Oil » 🤖 🌐
                      @thenewoil@mastodon.thenewoil.org

                      [?]Indigo Privacy » 🌐
                      @indigoprivacy@mastodon.social

                      Police have used genealogy DNA databases including GEDmatch to identify criminal suspects, implicating relatives who never consented to law enforcement use.

                        [?]ChiefGyk3D » 🌐
                        @chiefgyk3d@social.chiefgyk3d.com

                        The FCC wants to change how we get cell service. 😬 Sounds good on paper (stopping robocalls!), but what about privacy & safety? This could seriously impact domestic violence survivors. New video explores the concerns. Check it out!

                        youtube.com/watch?v=di4UBWPvL-M

                        🔴 LIVE

                        Alt...🔴 LIVE

                          [?]The New Oil » 🤖 🌐
                          @thenewoil@mastodon.thenewoil.org

                          [?]The New Oil » 🤖 🌐
                          @thenewoil@mastodon.thenewoil.org

                          US Engineer Charged With Sawing Down Cameras Receives Thousands of Dollars from Supporters Across the Country

                          futurism.com/future-society/ai

                            [?]The New Oil » 🤖 🌐
                            @thenewoil@mastodon.thenewoil.org

                            [?]The New Oil » 🤖 🌐
                            @thenewoil@mastodon.thenewoil.org

                            [?]Indigo Privacy » 🌐
                            @indigoprivacy@mastodon.social

                            Not all smart glasses have cameras, but no camera doesn't mean no recording. Camera-free pairs like the new Solos AirGo A6 still have mics that capture what you say. Get familiar with both: a lens and light mean video, but audio recordings count too.

                              [?]The New Oil » 🤖 🌐
                              @thenewoil@mastodon.thenewoil.org

                              [?]zerionchat » 🌐
                              @zerionchat@mastodon.social

                              Japan’s KDDI just disclosed a breach affecting up to 14.2 million email accounts across six providers. The detail that stands out: some passwords were stored in plain text, not even hashed.

                              This keeps happening because centralized services hold enormous pools of credentials, and one flaw in one vendor exposes all of them at once.

                              Zerion has no accounts, no passwords on any server, nothing pooled to steal. There’s simply no database to breach.

                              zerion.chat

                                [?]CosicBe » 🌐
                                @CosicBe@mastodon.social

                                EU Chat control is back on the table. Bart Preneel warns in De Morgen: scanning private messages at scale risks treating all citizens as suspects, without solid scientific basis for AI detection.
                                matters. Proportionality matters.
                                demorgen.be/tech-ai/chat-contr (paywall)

                                  muddle 🥣 boosted

                                  [?]Xavier Ashe :donor: » 🌐
                                  @Xavier@infosec.exchange

                                  The arrest of a teenage hacker has revealed that can track a Windows PC and its online activity through a “Global Device ID" that seems to have no easy opt-out, sparking fears about potential .
                                  pcmag.com/news/a-hackers-arres

                                    [?]Indigo Privacy » 🌐
                                    @indigoprivacy@mastodon.social

                                    Privacy News That Actually Matters. Every Monday, one story from the data privacy world. Recent, relevant, and actually readable.

                                      [?]Aaron Longchamps » 🌐
                                      @heatsink@infosec.exchange

                                      Another instance of why real-time plate tracking is really bad. I wish we had privacy legislation in the US. Flock and other companies like them shouldn't even be legal.

                                      404media.co/footage-shows-cop-

                                        [?]Marcus "MajorLinux" Summers » 🌐
                                        @majorlinux@toot.majorshouse.com

                                        This game could be used as a huge explainer into how surveillance capitalism works and how people are exploited on both sides of the screen.

                                        MajorOffline: Hae Stack – MajorLinux

                                        buff.ly/ANONU8v

                                          [?]Indigo Privacy » 🌐
                                          @indigoprivacy@mastodon.social

                                          Ransomware is now the most common cause of retailer data breaches: 32% of claims and 61% of the losses, per Verizon's 2026 study. Every store you shop at holds your payment and personal data, and that data is the target.

                                            [?]PrivacyDigest » 🌐
                                            @PrivacyDigest@mas.to

                                            Musk’s X poses “serious risk to Americans’ privacy,” advocates warn

                                            Ahead of a July 2 deadline to submit public comments, advocates are warning the Federal Trade Commission that it must keep close watch over Elon Musk’s X and firmly reject a recent bid to end the agency’s ongoing audits of the platform’s data handling.

                                            Last month, the FTC posted a notice explaining that X had argued that an FTC order was no longer necessary due to changes had made to the platform.

                                            arstechnica.com/tech-policy/20

                                              [?]PrivacyDigest » 🌐
                                              @PrivacyDigest@mas.to

                                              Defense "No Expectation of In Public" Is Wrong (Public Report)

                                              Online, Flock draws far more critics than defenders. But among those who do, the most common argument is a familiar one: there is no expectation of privacy in public, and license plates are visible to anyone on the road, so what's the problem? It is a reasonable instinct. It is also an oversimplification, and not what courts are being asked to decide.

                                              ipvm.com/reports/flock-no-priv

                                                [?]OpenMedia » 🌐
                                                @OpenMediaOrg@mastodon.social

                                                If you are out at the Stampede in and you see us, come to say hi and sign the petition to bring political parties under law in person!

                                                We will be talking with attendees about the privacy loophole and how to prevent the breach from happening again!

                                                Learn more at voterprivacy.ca/

                                                  [?]Indigo Privacy » 🌐
                                                  @indigoprivacy@mastodon.social

                                                  Hospital emergency departments collect patient location data through mobile check-in apps and share it with marketing vendors through third-party analytics tools.

                                                    [?]Kevin Dominik Korte » 🌐
                                                    @kdkorte@fosstodon.org

                                                    While the Trump administration is strong-arming developing countries into giving up their citizens' privacy, other countries can afford to be more conscious about keeping their data safe.

                                                    connexionfrance.com/practical/

                                                      [?]thecybersecguru » 🌐
                                                      @thecybersecguru@infosec.exchange

                                                      🚨 WHOIS privacy is under pressure.

                                                      GoDaddy is challenging an Indian court ruling that could fundamentally change how domain privacy works by requiring:

                                                      🔹 Mandatory e-KYC for domain registrations
                                                      🔹 WHOIS privacy no longer enabled by default
                                                      🔹 Registrars to disclose registrant details within 72 hours to parties claiming a "legitimate interest"

                                                      This isn't just about India.

                                                      The outcome could influence domain privacy, ICANN policy, RDAP adoption, cybersecurity investigations, trademark enforcement, and the future of online anonymity worldwide.

                                                      I break down:
                                                      ✅ What the court actually ordered
                                                      ✅ Why GoDaddy is appealing
                                                      ✅ How WHOIS and RDAP really work
                                                      ✅ The privacy vs law enforcement debate
                                                      ✅ What it means for domain owners, security researchers, and businesses

                                                      Read the full analysis 👇
                                                      thecybersecguru.com/news/godad

                                                      [?]The CyberSec Guru » 🌐
                                                      @guru@thecybersecguru.com

                                                      GoDaddy Is Quietly Fighting for WHOIS Privacy, and Almost No One’s Paying Attention

                                                      Delhi High Court ordered registrars to end default WHOIS privacy. GoDaddy's 5,000-page appeal explains why, and how it collides with RDAP's 2025 rollout [SENSITIVE CONTENT]

                                                      The order that has GoDaddy filing a 5,121-page appeal did not appear out of nowhere. It is the endpoint of a batch of Delhi High Court proceedings running since 2019, and the technical mechanism it targets, WHOIS privacy protection, happens to be a protocol that global internet governance had already spent the better part of a decade trying to fix through consensus rather than court order. Understanding why GoDaddy is worried requires understanding both threads: what an Indian judge actually ordered, and what WHOIS was already in the middle of becoming before she ordered it.

                                                      GoDaddy

                                                      The case and the numbers behind it

                                                      The order in question is Dabur India Limited v. Ashok Kumar & Ors. (CS(COMM) 135/2022, citation 2025:DHC:11862), delivered on December 24, 2025 by Justice Prathiba M. Singh. It was the lead matter in a consolidated batch stretching back to 2019, folding in suits from Colgate-Palmolive, Godrej Properties, The Himalaya Drug Company, and others, all chasing the same problem: domain names that mimicked their trademarks, sold fake franchises, or ran phishing operations, with the actual registrant hidden behind privacy protection features. The judgment blocked more than 1,100 such domains impersonating brands including Tata Sky, Amul, Bajaj Finance, Meesho, Croma, ITC, and Mont Blanc. Delhi Police’s Intelligence Fusion and Strategic Operations unit had traced crores of rupees extracted from victims through these sites, and the court noted that out of those 1,132 infringing registrations, barring one or two, not a single bona fide registrant ever came forward to claim a legitimate interest in the domain. Nobody showed up to defend their WHOIS-shielded identity, which the judge treated as fairly damning on its own.

                                                      The scale problem behind the ruling is real. India’s internet penetration went from 15 percent of the population in 2015 to roughly 70 percent by 2025, a jump that outpaced the average user’s ability to spot a spoofed domain. Home Minister Amit Shah cited a cybercrime victim roughly every 37 seconds nationally, and the National Technical Research Organisation logged over 1,100 phishing domains in Q1 2025 alone. Reuters reported 2.4 million cyber fraud complaints last year totaling $2.4 billion in losses. Justice Singh explicitly rejected the idea that case-by-case takedowns could keep up, describing the pattern as a whack-a-mole problem structurally incapable of being solved by injunctions against individually named domains.

                                                      The three directives GoDaddy is fighting

                                                      The judgment issued 14 directions to domain name registrars. Three are the ones under appeal:

                                                      Mandatory e-KYC with periodic re-verification for every domain registration, run by the registrar, functionally identical to what NIXI already does for .in domains.

                                                      Termination of privacy-by-default. Registrars can still offer WHOIS masking, but only as a paid opt-in, not a baseline feature bundled into every registration.

                                                      72-hour disclosure of registrant name, address, phone number, and email to any party asserting “legitimate interest,” a term the court borrows straight from GDPR without defining who qualifies or who adjudicates the claim.

                                                      GoDaddy’s appeal argues, correctly as a matter of engineering, that it has no scalable way to arbitrate “legitimate interest” claims within a 72-hour SLA across millions of domains. It also argues the order is jurisdictionally impossible to contain: DNS resolution doesn’t respect borders, so a registrar can’t run one WHOIS policy for Indian registrants and a separate one for everyone else without rebuilding its entire registration data pipeline around a single country’s court order. Farzaneh Badii, an internet governance researcher based in New York, made the point that WHOIS redaction was adopted globally in the first place because publicly listed contact data had been repeatedly exploited for stalking and harassment campaigns, meaning the rollback risks reintroducing the exact harm category the order claims to be solving, just aimed at a different population (private registrants and small businesses instead of the fraud operators who mostly used fabricated details anyway).

                                                      That last point matters technically. The Dabur judgment itself notes that WHOIS records tied to the fraudulent domains frequently contained fake names, dead phone numbers, and throwaway emails. Removing privacy-by-default doesn’t touch registrants who never entered real data in the first place. It mainly exposes people who did.

                                                      How Whois Privacy Services Work

                                                      Why this collides with a protocol transition that was already underway

                                                      Here’s the part that gets lost in the legal coverage: WHOIS, as a protocol, was already being retired independent of anything happening in Delhi. WHOIS dates to RFC 812 in 1982, a plaintext, unauthenticated, TCP port 43 query-response format with no standardized output. Every registry answered in its own dialect of free text, there was no encryption, and there was no way to distinguish a security researcher’s query from a spammer scraping contact data at scale. ICANN approved the RDAP Global Amendments in April 2023, setting a sunset date of January 28, 2025, after which gTLD registries and registrars were no longer contractually obligated to run WHOIS on port 43. Registration Data Access Protocol, standardized by the IETF (RFC 7480, 7481, and 9083, since updated by 9082/9083), replaced it with a RESTful HTTPS service returning structured JSON, discoverable through IANA’s bootstrap registry rather than a flat list of per-registry servers to memorize.

                                                      The adoption numbers moved fast once the deadline hit. ICANN logged around 122 billion WHOIS queries per month in January 2025 against 7 billion RDAP queries. By June 2025, RDAP query volume overtook WHOIS. By August, WHOIS had dropped to roughly 49 billion monthly queries against RDAP’s 65 billion, and 374 of about 1,000 gTLDs had shut off WHOIS entirely. In January 2026 ICANN revoked registrar Brennercom’s accreditation specifically for failing to implement RDAP, establishing that compliance is not optional going forward. For anyone doing domain recon as part of a pentest engagement or OSINT workup, this is the practical takeaway that matters more than the Indian litigation: if your tooling still shells out to a whois binary or opens a raw socket on port 43 for gTLD lookups, you’re querying a service nobody is obligated to keep answering. Grep your scripts for it. ccTLD coverage is patchier (roughly 60 percent RDAP adoption, with .de, .cn, and .jp still WHOIS-only in many configurations), so a mixed lookup strategy is still required if your target surface spans country-code domains.

                                                      The irony for the Delhi court’s order is that RDAP already ships with the exact capability the judges are trying to bolt onto WHOIS by judicial fiat. RDAP’s spec explicitly supports differentiated, role-based access: a registry can serve full contact data to an authenticated law enforcement query and a redacted response to an anonymous one, all through the same endpoint, governed by policy rather than a court re-litigating the question domain by domain. ICANN’s Registration Data Request Service (RDRS) exists precisely to handle law-enforcement and rights-holder requests for non-public registration data through participating registrars. GDPR is actually why any of this privacy tooling exists at all: the 2018 Tucows/EPAG dispute in Germany forced ICANN to adopt a Temporary Specification for WHOIS data handling almost overnight, and that temporary fix eventually hardened into the RDAP privacy model in use today. The Delhi court is essentially trying to solve, through a commercial trademark suit, a problem that the multilateral RDAP framework was purpose-built to solve through protocol design and contractual policy. Whether a system built for global consistency can survive a national court insisting on a different, manually-adjudicated disclosure standard is the actual question the larger bench has to answer on July 16.

                                                      The legal scaffolding under the order

                                                      The judgment leans on Section 7(e) of India’s Digital Personal Data Protection Act, which allows a data fiduciary to process personal data without consent when complying with a court order, and applies the Puttaswamy proportionality test to conclude that privacy protections cannot be used to shield ongoing illegality. GoDaddy’s appeal points out an inconvenient wrinkle: weeks before this ruling, the same Delhi High Court read the DPDP Act the opposite way in a right-to-be-forgotten matter, ordering Google and Indian Kanoon to de-index the names of acquitted persons. The larger bench has effectively been asked to decide which interpretation of the statute is going to govern going forward, since right now the same court has issued contradictory readings of the same law within the same season.

                                                      There’s also an enforcement lever most coverage skips. ICANN’s Registrar Accreditation Agreement, Section 5.5.2.1.4, allows ICANN to terminate a registrar’s accreditation if a court of competent jurisdiction finds the registrar failed to comply with an order relating to domains it sponsors. MeitY has already engaged ICANN’s Contractual Compliance Mechanism over non-compliant registrars in this same batch of litigation, and earlier orders in the case directed the Ministry to act under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 against registrars who hadn’t appointed grievance officers. Registrars operating in India also risk losing Section 79 IT Act safe harbor as intermediaries if courts decide they aren’t doing enough to prevent trademark infringement on their platforms. That’s the actual leverage India holds over a company like GoDaddy: not just a disclosure order, but the threat of losing both its ICANN accreditation and its intermediary liability shield in one of its largest markets.

                                                      The court didn’t stop at registrars, either. It ordered the RBI to build bank-side fraud tooling, and the Beneficiary Bank Account Name Lookup facility for RTGS and NEFT transfers went live on December 30, 2024, with mandatory bank-wide implementation by April 1, 2025, letting anyone verify the actual name on a receiving account before sending money. That single fix closes a gap that had nothing to do with domains: fraudsters were collecting payments into accounts that didn’t match the billing name a victim thought they were paying.

                                                      The trademark-scope argument

                                                      Separate from privacy, GoDaddy is also contesting the order’s bar on registering alphanumeric variations of a protected trademark. Its argument here is more linguistic than technical, but it’s a good illustration of how brand protection collides with the domain namespace. GoDaddy points out that “McDonald” is a Scottish surname predating the fast food chain by centuries, and that treating any string variation as off-limits risks handing a monopoly over common words and names to whichever company trademarked them first. Its filing cites Merriam-Webster research showing 118 English words contain the string “HUL,” Unilever’s Indian trademark, including “hulk” and “moghul,” and argues it’s close to impossible to register any domain in English that doesn’t overlap somewhere with a registered mark. Reuters found mcdonalds-india-franchise.com still purchasable on GoDaddy India for about $10 as of the reporting, which either undercuts the enforcement claims or just shows how far a 1,100-domain blocklist is from actually closing the gap, depending on how charitable you’re feeling.

                                                      Namecheap and Hosting Concepts (Openprovider’s parent) have filed separate challenges to the same order, though the specifics of their appeals haven’t surfaced publicly. The larger bench hears all three on July 16. If it narrows the December directives, that reaffirms that ICANN’s negotiated global frameworks still take precedence over a single national court’s order. If it upholds them, any court with jurisdiction over a major registrar has effectively been shown a template for rewriting WHOIS policy unilaterally, and the assumption that domain privacy works the same way everywhere stops being something you can rely on.

                                                      GoDaddy Is Quietly Fighting for WHOIS Privacy

                                                      Alt...GoDaddy Is Quietly Fighting for WHOIS Privacy

                                                      GoDaddy

                                                      Alt...GoDaddy

                                                      How Whois Privacy Services Work

                                                      Alt...How Whois Privacy Services Work

                                                        [?]🐈‍⬛David Sommerseth » 🌐
                                                        @dazo@infosec.exchange

                                                        fact check!

                                                        @EUCommission

                                                        Chat Control is NOT about protecting children at its core. On the very surface, yes. But the proposed approach is so far reaching that it will enable surveillance of the whole population at the next political intersection.

                                                        We all really want to fight child abuse. CSAM is an incredibly cruel crime against defendless individuals. Yes, we want those criminals to be sentenced harshly and hard in courts.

                                                        But Chat Control is not the right solution. Do you really want to call out several hundred millions of European citizens as potential perpetrators just to catch the abusers?

                                                        What happened to the presumption of innocence? Which is the foundation in the law system across all of Europe. What kind of regime are we preparing for in Europe if we don't enforce and protect the presumption of innocence?

                                                        Europe has had a strong stance of opposing supressing regimes. Regimes which builds their power through controlling the population. Control which comes through surveillance of the population.

                                                        When did Europeans vote for a regime change in Europe? We threw fascists out of the political influence over 80 years ago. We do not want to do the same again.

                                                        We threw out communists from European influence 40 years ago. Communists who was behind Stasi in the DDR - Do we need to repeat what the state controlled surveillance did to the population there?

                                                        You may rightfully claim that Chat Control is not meant to be that extreme. No, it isn't right now. But it has the power of ending there. Once the tools to surveil the population has arrived, it is hard to withdraw them. And the idea behind Chat Control is in practice surveillance of what Europeans do on their electronic devices. Regardless if they are a suspect or innocent.

                                                        Chat Control MUST be stopped, once and for all. And the work to protect children must be more clever, more targeted at clearly defined suspects. Not to surveil the whole European population.

                                                        And this message has not even dug into the rabbit hole of how flawed the chat control approach is on a technical level. Where the real offenders and abusers will find technologic ways to avoid chat control and this surveillance. Leaving the rest of the innocent population, the majority of the population under surveillance by default.

                                                        fightchatcontrol.eu/

                                                          [?]jcrabapple » 🌐
                                                          @jcrabapple@dmv.community

                                                          🔒 A 19-year-old cybercriminal was caught despite using a VPN across multiple countries - because Windows has a tracking number built into every install that a VPN can't hide.

                                                          Peter Stokes, arrested in Finland in April and extradited to the US last week, is tied to Scattered Spider, the hacking group behind the 2023 MGM and Caesars casino breaches. The group is linked to 100+ intrusions and over $100 million in extortion.

                                                          The FBI didn't crack his VPN. Microsoft handed over his Global Device ID (GDID), a unique identifier baked into every Windows installation at setup. It doesn't change when you update, switch networks, or use a VPN. The only way to reset it is a full OS reinstall.

                                                          Investigators matched Stokes's GDID across IP addresses in Estonia, New York, and Thailand, correlating with login times on his Snapchat, Apple, and Facebook accounts. The same device that breached a luxury jewelry retailer and demanded $8 million in ransom also logged into Snapchat and a video game from his real network.

                                                          So while VPNs mask your IP address, they were never designed to hide device-level identifiers embedded in your operating system. The tracking can live one layer deeper than the one most people defend.

                                                          Read more:
                                                          itnews.com.au/news/microsoft-d
                                                          databreachtoday.com/scattered-

                                                            [?]The CyberSec Guru » 🌐
                                                            @guru@thecybersecguru.com

                                                            GoDaddy Is Quietly Fighting for WHOIS Privacy, and Almost No One’s Paying Attention

                                                            Delhi High Court ordered registrars to end default WHOIS privacy. GoDaddy's 5,000-page appeal explains why, and how it collides with RDAP's 2025 rollout [SENSITIVE CONTENT]

                                                            The order that has GoDaddy filing a 5,121-page appeal did not appear out of nowhere. It is the endpoint of a batch of Delhi High Court proceedings running since 2019, and the technical mechanism it targets, WHOIS privacy protection, happens to be a protocol that global internet governance had already spent the better part of a decade trying to fix through consensus rather than court order. Understanding why GoDaddy is worried requires understanding both threads: what an Indian judge actually ordered, and what WHOIS was already in the middle of becoming before she ordered it.

                                                            GoDaddy

                                                            The case and the numbers behind it

                                                            The order in question is Dabur India Limited v. Ashok Kumar & Ors. (CS(COMM) 135/2022, citation 2025:DHC:11862), delivered on December 24, 2025 by Justice Prathiba M. Singh. It was the lead matter in a consolidated batch stretching back to 2019, folding in suits from Colgate-Palmolive, Godrej Properties, The Himalaya Drug Company, and others, all chasing the same problem: domain names that mimicked their trademarks, sold fake franchises, or ran phishing operations, with the actual registrant hidden behind privacy protection features. The judgment blocked more than 1,100 such domains impersonating brands including Tata Sky, Amul, Bajaj Finance, Meesho, Croma, ITC, and Mont Blanc. Delhi Police’s Intelligence Fusion and Strategic Operations unit had traced crores of rupees extracted from victims through these sites, and the court noted that out of those 1,132 infringing registrations, barring one or two, not a single bona fide registrant ever came forward to claim a legitimate interest in the domain. Nobody showed up to defend their WHOIS-shielded identity, which the judge treated as fairly damning on its own.

                                                            The scale problem behind the ruling is real. India’s internet penetration went from 15 percent of the population in 2015 to roughly 70 percent by 2025, a jump that outpaced the average user’s ability to spot a spoofed domain. Home Minister Amit Shah cited a cybercrime victim roughly every 37 seconds nationally, and the National Technical Research Organisation logged over 1,100 phishing domains in Q1 2025 alone. Reuters reported 2.4 million cyber fraud complaints last year totaling $2.4 billion in losses. Justice Singh explicitly rejected the idea that case-by-case takedowns could keep up, describing the pattern as a whack-a-mole problem structurally incapable of being solved by injunctions against individually named domains.

                                                            The three directives GoDaddy is fighting

                                                            The judgment issued 14 directions to domain name registrars. Three are the ones under appeal:

                                                            Mandatory e-KYC with periodic re-verification for every domain registration, run by the registrar, functionally identical to what NIXI already does for .in domains.

                                                            Termination of privacy-by-default. Registrars can still offer WHOIS masking, but only as a paid opt-in, not a baseline feature bundled into every registration.

                                                            72-hour disclosure of registrant name, address, phone number, and email to any party asserting “legitimate interest,” a term the court borrows straight from GDPR without defining who qualifies or who adjudicates the claim.

                                                            GoDaddy’s appeal argues, correctly as a matter of engineering, that it has no scalable way to arbitrate “legitimate interest” claims within a 72-hour SLA across millions of domains. It also argues the order is jurisdictionally impossible to contain: DNS resolution doesn’t respect borders, so a registrar can’t run one WHOIS policy for Indian registrants and a separate one for everyone else without rebuilding its entire registration data pipeline around a single country’s court order. Farzaneh Badii, an internet governance researcher based in New York, made the point that WHOIS redaction was adopted globally in the first place because publicly listed contact data had been repeatedly exploited for stalking and harassment campaigns, meaning the rollback risks reintroducing the exact harm category the order claims to be solving, just aimed at a different population (private registrants and small businesses instead of the fraud operators who mostly used fabricated details anyway).

                                                            That last point matters technically. The Dabur judgment itself notes that WHOIS records tied to the fraudulent domains frequently contained fake names, dead phone numbers, and throwaway emails. Removing privacy-by-default doesn’t touch registrants who never entered real data in the first place. It mainly exposes people who did.

                                                            How Whois Privacy Services Work

                                                            Why this collides with a protocol transition that was already underway

                                                            Here’s the part that gets lost in the legal coverage: WHOIS, as a protocol, was already being retired independent of anything happening in Delhi. WHOIS dates to RFC 812 in 1982, a plaintext, unauthenticated, TCP port 43 query-response format with no standardized output. Every registry answered in its own dialect of free text, there was no encryption, and there was no way to distinguish a security researcher’s query from a spammer scraping contact data at scale. ICANN approved the RDAP Global Amendments in April 2023, setting a sunset date of January 28, 2025, after which gTLD registries and registrars were no longer contractually obligated to run WHOIS on port 43. Registration Data Access Protocol, standardized by the IETF (RFC 7480, 7481, and 9083, since updated by 9082/9083), replaced it with a RESTful HTTPS service returning structured JSON, discoverable through IANA’s bootstrap registry rather than a flat list of per-registry servers to memorize.

                                                            The adoption numbers moved fast once the deadline hit. ICANN logged around 122 billion WHOIS queries per month in January 2025 against 7 billion RDAP queries. By June 2025, RDAP query volume overtook WHOIS. By August, WHOIS had dropped to roughly 49 billion monthly queries against RDAP’s 65 billion, and 374 of about 1,000 gTLDs had shut off WHOIS entirely. In January 2026 ICANN revoked registrar Brennercom’s accreditation specifically for failing to implement RDAP, establishing that compliance is not optional going forward. For anyone doing domain recon as part of a pentest engagement or OSINT workup, this is the practical takeaway that matters more than the Indian litigation: if your tooling still shells out to a whois binary or opens a raw socket on port 43 for gTLD lookups, you’re querying a service nobody is obligated to keep answering. Grep your scripts for it. ccTLD coverage is patchier (roughly 60 percent RDAP adoption, with .de, .cn, and .jp still WHOIS-only in many configurations), so a mixed lookup strategy is still required if your target surface spans country-code domains.

                                                            The irony for the Delhi court’s order is that RDAP already ships with the exact capability the judges are trying to bolt onto WHOIS by judicial fiat. RDAP’s spec explicitly supports differentiated, role-based access: a registry can serve full contact data to an authenticated law enforcement query and a redacted response to an anonymous one, all through the same endpoint, governed by policy rather than a court re-litigating the question domain by domain. ICANN’s Registration Data Request Service (RDRS) exists precisely to handle law-enforcement and rights-holder requests for non-public registration data through participating registrars. GDPR is actually why any of this privacy tooling exists at all: the 2018 Tucows/EPAG dispute in Germany forced ICANN to adopt a Temporary Specification for WHOIS data handling almost overnight, and that temporary fix eventually hardened into the RDAP privacy model in use today. The Delhi court is essentially trying to solve, through a commercial trademark suit, a problem that the multilateral RDAP framework was purpose-built to solve through protocol design and contractual policy. Whether a system built for global consistency can survive a national court insisting on a different, manually-adjudicated disclosure standard is the actual question the larger bench has to answer on July 16.

                                                            The legal scaffolding under the order

                                                            The judgment leans on Section 7(e) of India’s Digital Personal Data Protection Act, which allows a data fiduciary to process personal data without consent when complying with a court order, and applies the Puttaswamy proportionality test to conclude that privacy protections cannot be used to shield ongoing illegality. GoDaddy’s appeal points out an inconvenient wrinkle: weeks before this ruling, the same Delhi High Court read the DPDP Act the opposite way in a right-to-be-forgotten matter, ordering Google and Indian Kanoon to de-index the names of acquitted persons. The larger bench has effectively been asked to decide which interpretation of the statute is going to govern going forward, since right now the same court has issued contradictory readings of the same law within the same season.

                                                            There’s also an enforcement lever most coverage skips. ICANN’s Registrar Accreditation Agreement, Section 5.5.2.1.4, allows ICANN to terminate a registrar’s accreditation if a court of competent jurisdiction finds the registrar failed to comply with an order relating to domains it sponsors. MeitY has already engaged ICANN’s Contractual Compliance Mechanism over non-compliant registrars in this same batch of litigation, and earlier orders in the case directed the Ministry to act under the IT (Intermediary Guidelines and Digital Media Ethics Code) Rules, 2021 against registrars who hadn’t appointed grievance officers. Registrars operating in India also risk losing Section 79 IT Act safe harbor as intermediaries if courts decide they aren’t doing enough to prevent trademark infringement on their platforms. That’s the actual leverage India holds over a company like GoDaddy: not just a disclosure order, but the threat of losing both its ICANN accreditation and its intermediary liability shield in one of its largest markets.

                                                            The court didn’t stop at registrars, either. It ordered the RBI to build bank-side fraud tooling, and the Beneficiary Bank Account Name Lookup facility for RTGS and NEFT transfers went live on December 30, 2024, with mandatory bank-wide implementation by April 1, 2025, letting anyone verify the actual name on a receiving account before sending money. That single fix closes a gap that had nothing to do with domains: fraudsters were collecting payments into accounts that didn’t match the billing name a victim thought they were paying.

                                                            The trademark-scope argument

                                                            Separate from privacy, GoDaddy is also contesting the order’s bar on registering alphanumeric variations of a protected trademark. Its argument here is more linguistic than technical, but it’s a good illustration of how brand protection collides with the domain namespace. GoDaddy points out that “McDonald” is a Scottish surname predating the fast food chain by centuries, and that treating any string variation as off-limits risks handing a monopoly over common words and names to whichever company trademarked them first. Its filing cites Merriam-Webster research showing 118 English words contain the string “HUL,” Unilever’s Indian trademark, including “hulk” and “moghul,” and argues it’s close to impossible to register any domain in English that doesn’t overlap somewhere with a registered mark. Reuters found mcdonalds-india-franchise.com still purchasable on GoDaddy India for about $10 as of the reporting, which either undercuts the enforcement claims or just shows how far a 1,100-domain blocklist is from actually closing the gap, depending on how charitable you’re feeling.

                                                            Namecheap and Hosting Concepts (Openprovider’s parent) have filed separate challenges to the same order, though the specifics of their appeals haven’t surfaced publicly. The larger bench hears all three on July 16. If it narrows the December directives, that reaffirms that ICANN’s negotiated global frameworks still take precedence over a single national court’s order. If it upholds them, any court with jurisdiction over a major registrar has effectively been shown a template for rewriting WHOIS policy unilaterally, and the assumption that domain privacy works the same way everywhere stops being something you can rely on.

                                                            GoDaddy Is Quietly Fighting for WHOIS Privacy

                                                            Alt...GoDaddy Is Quietly Fighting for WHOIS Privacy

                                                            GoDaddy

                                                            Alt...GoDaddy

                                                            How Whois Privacy Services Work

                                                            Alt...How Whois Privacy Services Work

                                                            [?]Regendans [they/them/he/him] » 🌐
                                                            @regendans@todon.eu

                                                            Opinion
                                                            "AI surveillance is being supercharged – and it will chill social progress
                                                            Bruce Schneier and Jon Penney

                                                            These systems will soon be able to track our public and private lives. But we can make the policy choices to reject it"

                                                            theguardian.com/commentisfree/

                                                            (the images cover about half of the article)

                                                            In the near future, AI-powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong – shoplift, litter, jaywalk, you name it – the system will notice, retain it, tie it to your official government record, communicate that fact to you, and provide real-time alerts to any relevant authorities … and maybe also to the general public.

Think of these systems as automated speed cameras, but on steroids. Only they’ll enforce not just speed limits, but any other rule you can imagine. And you won’t receive a ticket weeks later by mail; you’ll be informed about and fined for your violation immediately.

These systems will combine powerful AI, public and private surveillance via real-time facial recognition technology and digital tracking, mass databases and highly personalized enforcement. If deployed at scale, they will have profound chilling effects not just on personal freedoms, but democracy and social progress itself.

China has been developing its surveillance infrastructure for years. The country has over 600 million surveillance cameras, increasingly powered by AI and facial recognition to enforce legal and social rules. Take the case of Lao

                                                            Alt...In the near future, AI-powered surveillance systems will be able to track everything we do in public, and much of what we do in private. And if we do something wrong – shoplift, litter, jaywalk, you name it – the system will notice, retain it, tie it to your official government record, communicate that fact to you, and provide real-time alerts to any relevant authorities … and maybe also to the general public. Think of these systems as automated speed cameras, but on steroids. Only they’ll enforce not just speed limits, but any other rule you can imagine. And you won’t receive a ticket weeks later by mail; you’ll be informed about and fined for your violation immediately. These systems will combine powerful AI, public and private surveillance via real-time facial recognition technology and digital tracking, mass databases and highly personalized enforcement. If deployed at scale, they will have profound chilling effects not just on personal freedoms, but democracy and social progress itself. China has been developing its surveillance infrastructure for years. The country has over 600 million surveillance cameras, increasingly powered by AI and facial recognition to enforce legal and social rules. Take the case of Lao

                                                            Duan, a Chinese citizen blacklisted by the system after he lost his job and was unable to repay a series of loans. When he visited Beijing, the city’s AI surveillance system identified him by his face at a major intersection and displayed his face, name, and citizen ID number on a large electronic billboard nearby with a message that he was an untrustworthy person. Similar systems are now being deployed across China and integrated with its infamous online monitoring, censorship, and social credit systems.

AI surveillance is now being experimented with in North America, South America, Europe, Asia and Africa. According to a new report, the US Department of Homeland Security is rapidly increasing its use of AI-based surveillance, including facial recognition and the monitoring of social media accounts, to keep tabs on immigrants, dissidents, journalists, legal observers and protesters. While the systems are ostensibly used to maintain security and public safety, the real aim is often social control. Larry Ellison, CEO of Oracle – a powerful tech giant that works closely with the Trump administration – has said: “Citizens will be on their best behavior because we’re constantly recording and reporting.” The chilling effects are the point.

                                                            Alt...Duan, a Chinese citizen blacklisted by the system after he lost his job and was unable to repay a series of loans. When he visited Beijing, the city’s AI surveillance system identified him by his face at a major intersection and displayed his face, name, and citizen ID number on a large electronic billboard nearby with a message that he was an untrustworthy person. Similar systems are now being deployed across China and integrated with its infamous online monitoring, censorship, and social credit systems. AI surveillance is now being experimented with in North America, South America, Europe, Asia and Africa. According to a new report, the US Department of Homeland Security is rapidly increasing its use of AI-based surveillance, including facial recognition and the monitoring of social media accounts, to keep tabs on immigrants, dissidents, journalists, legal observers and protesters. While the systems are ostensibly used to maintain security and public safety, the real aim is often social control. Larry Ellison, CEO of Oracle – a powerful tech giant that works closely with the Trump administration – has said: “Citizens will be on their best behavior because we’re constantly recording and reporting.” The chilling effects are the point.

                                                            AI surveillance raises a range of public policy challenges: technical biases, unauditable systems, and inflexible automated law and social rule enforcement that can promote discrimination and undermine transparency, accountability and the rule of law. But we believe the most urgent and long-term impact will be its broader chilling effects.

In a new book, Chilling Effects: Repression, Conformity, and Power in the Digital Age, Jon Penney explains how surveillance, technology and power can be weaponized to influence behavior at scale. Surveillance, personalization, uncertainty and authority are all key mechanisms to increase the scale and impact of chilling effects. They cause people to self-censor their words and actions, to become more conformist and compliant and thus easier to manage and control. And the effects are additive: the more mechanisms employed, and the more powerful the form, the greater the chill.

                                                            Alt...AI surveillance raises a range of public policy challenges: technical biases, unauditable systems, and inflexible automated law and social rule enforcement that can promote discrimination and undermine transparency, accountability and the rule of law. But we believe the most urgent and long-term impact will be its broader chilling effects. In a new book, Chilling Effects: Repression, Conformity, and Power in the Digital Age, Jon Penney explains how surveillance, technology and power can be weaponized to influence behavior at scale. Surveillance, personalization, uncertainty and authority are all key mechanisms to increase the scale and impact of chilling effects. They cause people to self-censor their words and actions, to become more conformist and compliant and thus easier to manage and control. And the effects are additive: the more mechanisms employed, and the more powerful the form, the greater the chill.

                                                            Computerization has long allowed data collectors to track our locations, collect lists of whom we communicate with, and monitor our spending habits – unless we use cash. What’s new is an unprecedented fusion of each of these mechanisms, persistent and unrelenting. AI brings an analytical ability to spy on the contents of our communications, and to answer sophisticated questions about our whereabouts and activities: actions that previously required human analysts are now automated. The result will be a kind of supercharged societal level of chilling effects where fear, self-censorship and groupthink reign, and dissent, creativity and innovation become increasingly rare.

In this atmosphere of fear and conformity, risky ideas, social activism and self-reinvention – especially by disfavored groups and targeted populations – are also chilled. This will have long-term effects on social progress.

                                                            Alt...Computerization has long allowed data collectors to track our locations, collect lists of whom we communicate with, and monitor our spending habits – unless we use cash. What’s new is an unprecedented fusion of each of these mechanisms, persistent and unrelenting. AI brings an analytical ability to spy on the contents of our communications, and to answer sophisticated questions about our whereabouts and activities: actions that previously required human analysts are now automated. The result will be a kind of supercharged societal level of chilling effects where fear, self-censorship and groupthink reign, and dissent, creativity and innovation become increasingly rare. In this atmosphere of fear and conformity, risky ideas, social activism and self-reinvention – especially by disfavored groups and targeted populations – are also chilled. This will have long-term effects on social progress.

                                                              [?]Indigo Privacy » 🌐
                                                              @indigoprivacy@mastodon.social

                                                              AI glasses with built-in cameras are making people uneasy about being recorded in public without consent. Critics say they blur everyday life into surveillance, and the pushback is real: workplace bans, public callouts, and apps that scan for hidden cameras.

                                                                [?]Regendans [they/them/he/him] » 🌐
                                                                @regendans@todon.eu

                                                                "Bits of Freedom: AIVD en MIVD lijken eigen AI te trainen met data van burgers

                                                                Inlichtingendiensten AIVD en MIVD lijken hun eigen AI te trainen met data van burgers, zo stelt burgerrechtenbeweging Bits of Freedom (BoF). De organisatie reageerde op een rapport van de Commissie Toezicht op de Inlichtingen- en Veiligheidsdiensten (CTIVD) over het onrechtmatig verwerken van persoonsgegevens in bulkdata door de inlichtingendiensten en dat die persoonlijke privacy beter moeten beschermen.

                                                                Bij de uitvoering van hun taken maken de AIVD en MIVD gebruik van zogenaamde bulkdatasets. Het gaat om omvangrijke verzamelingen persoonsgegevens met soms miljoenen regels gegevens. Daarbij kan het gaan om namen en telefoonnummers maar ook om locatiegegevens, socialmediagegevens of inhoudelijke communicatiegegevens. De gebruikte datasets zijn afkomstig van overheidsinstanties. Het kan echter ook gaan om commercieel verkrijgbare datasets, of gestolen datasets die door criminelen worden aangeboden."
                                                                .,,.,.,.,.

                                                                security.nl/posting/943398/Bit

                                                                  [?]xoron :verified: » 🌐
                                                                  @xoron@infosec.exchange

                                                                  ArcaneChat boosted

                                                                  [?]ArcaneChat » 🌐
                                                                  @arcanechat@fosstodon.org

                                                                  not a supporter of ArcaneChat yet??? you can not only watch but also be part of the change! ✨

                                                                  no amount is too small!

                                                                  💜 join our contributors 👉 arcanechat.me/#contribute

                                                                    [?]Christoph Schmees » 🌐
                                                                    @PC_Fluesterer@social.tchncs.de

                                                                    @ketan
                                                                    Hi Ketan, many thanks for your report on Googles greed for energy. Great findings and great writing. ketanjoshi.co/2026/07/01/googl

                                                                    But one thing bothers me: You have an e-mail account at GOOGLE? Is this a cognitive dissonance? For the sake of my privacy I for one NEVER communicate w/ gmail or the other big-tech US providers. Reasons here (in german): pc-fluesterer.info/wordpress/v
                                                                    And except for mastodon you are on a lot of commercial antisocial platforms. Is it for the "reach"? Then pc-fluesterer.info/wordpress/2

                                                                      [?]PrivacyDigest » 🌐
                                                                      @PrivacyDigest@mas.to

                                                                      @eff and Allies: X’s Petition to Waive Violation Order Should be Rejected

                                                                      X Corp. should not be able to escape privacy compliance because it changed its name.

                                                                      eff.org/deeplinks/2026/06/eff-

                                                                        [?]PrivacyDigest » 🌐
                                                                        @PrivacyDigest@mas.to

                                                                        Credibility Lost as it Repeatedly Lies to City Councils, Departments, and Public Across the Country

                                                                        The documents how an automatic license plate reader company has lied about its operations, signaling a need for reputable governments to avoid working with Safety.

                                                                        aclu.org/news/privacy-technolo

                                                                          [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                                                          @nemo@mas.to

                                                                          Cape was founded by privacy-first innovators with deep expertise in security, telecom, and technology—built on the belief you can stay connected without compromising your privacy. As noted in The News, “a company is finally trying to seriously address privacy issues with aging telecommunications networks.” Learn more: cape.co/about 🔒📡🛡️

                                                                            [?]DigitalEscapeTools » 🌐
                                                                            @xabd@mastodon.social

                                                                            LibreTranslate is a free, open-source machine translation server that you can use online or self-host for complete control over your data.

                                                                            It supports multiple languages, offers a simple API, works without relying on Google Translate, and is a great privacy-friendly choice for websites, apps, and personal use.

                                                                            More details: digitalescapetools.com/tools/t

                                                                            Screenshot of the LibreTranslate project page showing it as a free, open-source, self-hosted machine translation API. It highlights support for Python 3.8–3.13, passing build and test badges, a Humane Tech badge, and a preview of the web translation interface translating English text into Spanish.

                                                                            Alt...Screenshot of the LibreTranslate project page showing it as a free, open-source, self-hosted machine translation API. It highlights support for Python 3.8–3.13, passing build and test badges, a Humane Tech badge, and a preview of the web translation interface translating English text into Spanish.

                                                                              Back to top - More...