soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
«#Proton CEO warns global #ageVerification push will mean "the death of anonymity online"
Protecting children #online is crucial, but forcing every user to hand over their ID is a privacy #nightmare waiting to happen, according to the head of the #Swiss #privacy firm»
It's never about #childProtection that's just an argument to convince people to voluntarily hand over their #personalData. In today's #Internet, people are the product and the #web is their #market.
«Librecast - Decentralisation and Privacy with Multicast»
Do any of you know this and use it? What is this good for and is it almost like the Gemini protocol?
🌐 https://librecast.net
@librecast
#librecast #gemini #internet #web #internet #privacy #muticast #askfedi #decentralization #geminiprotocol #privacy #security
Proton CEO warns global age verification push will mean "the death of anonymity online"
Protecting children online is crucial, but forcing every user to hand over their ID is a privacy nightmare waiting to happen, according to the head of the Swiss privacy firm
#Proton #privacy #AgeVerification #IDVerification #surveillance #technology
Federal Surveillance Tech Becomes Mandatory in New Cars by 2027
Your next car purchase comes with an unwelcome passenger: a federal mandate requiring surveillance technology that monitors your every blink, glance, and head nod.
https://www.gadgetreview.com/federal-surveillance-tech-becomes-mandatory-in-new-cars-by-2027
#cars #privacy #surveillance #enshittification #dystopia #technology
Free software offers trust and privacy; #Ring offers mass surveillance: https://u.fsf.org/4aw #Flock #privacy #surveillance
🔐 #Privacy news & updates from @privacyguides:
“A bill for the people? We nearly forgot the government could do that 👀 The US government regularly gets around the 4th Amendment by buying data from “third-party” data brokers, to invade your privacy with no oversight...”
https://mastodon.neat.computer/@privacyguides/116460818656550124
🤖 via RSS feed. May not reflect our views.
Right of Access as Reconnaissance, who needs a hack when you can request. In 2019, security researcher James Pavur submitted 150 forged subject access requests at Black Hat USA — using only a target's name and a look-alike email. 24% of responding companies returned sensitive personal data (passwords, home addresses, payment card digits, travel history). 3% deleted the account with no verification at all.
Six years later, I wanted to see whether anything had meaningfully changed.
#privacy #cybersecurity #GDPR #ethics
First part: https://privacyinsightsolutions.com/blog/right-of-access-reconnaissance-gdpr-art-15-gap?utm_medium=info
X launched XChat messaging app on iPhone Friday, marketing end-to-end encryption and "no tracking." Security researchers quickly flagged Apple's privacy label showing collection of contact info, identifiers, and usage data. The app stores private keys on X's servers behind 4-digit PINs, departing from Signal's device-only approach. 481-member group chat limit planned to expand to 1,000.
📰 Apple Rushes Fix for iOS Flaw That Let FBI Recover Deleted Signal Messages
🚨 Apple issues emergency patch for iOS flaw (CVE-2026-28950) that let the FBI recover deleted Signal message notifications. The bug improperly stored notification data, undermining user privacy. Update your iPhone & iPad now! 📱🔒 #iOS #Privacy #In...
#Surveillance vendors caught abusing access to telcos to track people’s phone locations, researchers say
A bill for the people? We nearly forgot the government could do that 👀
The US government regularly gets around the 4th Amendment by buying data from “third-party” data brokers, to invade your privacy with no oversight.
Why this is legal? We have no idea, but Rep. Thomas Massie (KY) just introduced the Surveillance Accountability Act (with help drafting from Naomi Brockwell!) which closes this loophole.
The bill would mandate warrants for all surveillance, including a ban on invasive AI and facial recognition mass surveillance in public spaces 💪
Check it out here and let us know what you think: https://surveillanceaccountability.com
#SurveillanceAccountabilityAct #Privacy #USpol #Surveillance #USgov #USA
"A new Republican privacy bill could be ‘worse than no standard at all’"
"But while it would introduce new protections in some states, it would weaken privacy rights in others - and it's missing several elements that privacy advocates deem necessary. Congress is once again attempting to pass a national data privacy law."
https://www.theverge.com/policy/917828/data-privacy-bill-secure-act-house-state-laws
We must keep #AgeVerification from killing #anonymity online
https://proton.me/blog/keep-age-verification-from-killing-anonymity-online
In my work as a privacy advocate, I regularly encounter two types of discourse:
1: The abdication mindset: The idea that privacy is dead, implying it's not worth putting any effort to protect personal data anymore. Like a self-fulfilling prophecy, privacy is dead if you let it die.
2: The absolutist mindset: The idea that for anything to have value in data privacy it needs to be 100% perfectly private and secure. But the reality is much more nuanced than this.
Even if they sound like diametric opposites, both those ideas can be very damaging to privacy.
Privacy isn't just about the tools we use. Privacy is a culture we need to build, together.
https://www.privacyguides.org/articles/2025/02/17/privacy-is-not-dead/
How and Why Russian Apps Search for #VPN on Users' Phones
#iOS 26.4.2 Patches Flaw That Let #FBI Extract Deleted #Signal Messages
https://www.macrumors.com/2026/04/22/ios-26-4-2-notification-database-security-fix/
OmniTools is a self-hosted web app that bundles dozens of everyday tools into one place.
Edit images, work with PDFs, format text, handle JSON/CSV . All directly in your browser.
Everything runs client-side, so your files never leave your device. No uploads, no tracking.
👉 https://github.com/iib0011/omni-tools
👉 More privacy-friendly tools: https://digitalescapetools.com/
#OpenSource #SelfHosting #Privacy #DevTools #Productivity #DigitalMinimalism
The Supreme Court will decide when the police can use your phone to track you
modern technology enables the government to invade everyone’s privacy in ways that would have been unimaginable when the Constitution was framed. The Supreme Court has spent the past several decades trying to make sure that its interpretation of the Fourth Amendment keeps up with technological progress.
#legal #SCOTUS #constitution #fourthamendment #surveillance #privacy #technology #tech
https://www.vox.com/politics/485973/supreme-court-chatrie-cell-phone-geofence-warrant
New Yorkers, it's not too late to demand your representatives drop state-mandated censorship and surveillance from the proposed budget. https://eff.org/3DPrintNY #3dprinting #opensource #privacy #NewYork
#German Cabinet Approves #IPAddress Storage Law to Combat Online Crime
https://www.newsworm.de/news/german-cabinet-approves-ip-address-storage-law-to-combat-online-crime
At #BlackHatAsia 2026, Seppe Wyns, Sayon Duttagupta & Nikola Antonijević presented #WhisperPair, exposing flaws in #Google Fast Pair. Mis-implementations enable device hijacking & tracking via Find Hub, showing how small add‑ons create big #privacy risks.
#Bluetooth
https://blackhat.com/asia-26/briefings/schedule/
Stava esaminando le configurazioni di Brave sul suo MacBook quando Alexander Hanff, esperto di privacy e collaboratore occasionale di The Register, ha trovato un file che non aveva mai messo lì. Proveniva da Anthropic.
Il file si chiama com.anthropic.claude_browser_extension.json ed è un manifest Native Messaging, il documento che un browser basato su Chromium consulta quando un’estensione vuole richiamare un eseguibile sul sistema locale. Secondo Hanff, Claude Desktop lo aveva scritto nella directory di Brave senza alcuna comunicazione, senza richiesta di consenso e senza che lui avesse mai installato alcuna estensione Claude.
// affiliato ▸ Tuta · Email criptata, un mese extra gratuito · Provalo gratis →
Secondo la sua analisi, il manifest pre-autorizza tre identificatori di estensioni Claude a richiamare un eseguibile incluso in Claude Desktop, chrome-native-host, che gira al di fuori del sandbox del browser con i privilegi dell’utente. Hanff ha poi verificato lo stesso comportamento su un secondo dispositivo e ha trovato il manifest scritto nelle directory di sette browser Chromium-based, tra cui Chrome, Brave, Edge, Vivaldi, Arc e Opera, inclusi quattro che su quella macchina non erano nemmeno installati. Le directory corrispondenti sono state create da Claude Desktop al primo avvio.
I log interni dell’applicazione, come riporta Hanff, registrano esplicitamente l’operazione sotto il nome di sistema Chrome Extension MCP e mostrano oltre trenta eventi di installazione nei file di log correnti e archiviati. I timestamp di modifica indicano che il file viene riscritto a ogni avvio dell’app: cancellarlo manualmente non basta, ricompare al lancio successivo.
Secondo Hanff, le capacità documentate da Anthropic per l’integrazione con Chrome includono l’accesso alle sessioni autenticate dell’utente, la lettura del contenuto delle pagine, la compilazione di moduli e la registrazione delle interazioni. Con il bridge già installato, un attacco di prompt injection riuscito contro l’estensione Claude avrebbe, sempre secondo Hanff, un percorso diretto verso l’eseguibile esterno al sandbox. Anthropic stessa, nella documentazione di lancio di Claude for Chrome, indica un tasso di successo degli attacchi di prompt injection dell’11,2% anche con le mitigazioni attive.
Hanff ritiene che il comportamento costituisca una violazione dell’articolo 5(3) della Direttiva ePrivacy europea, che richiede consenso esplicito per la scrittura di dati sui dispositivi degli utenti, salvo casi di stretta necessità tecnica.
Noah Kenney, consulente di Digital 520, interpellato da The Register, ha confermato che le affermazioni tecniche sono verificabili e riproducibili da revisori indipendenti. Sul piano normativo, secondo Kenney, la scrittura del manifest rientra nell’ambito di applicazione dell’articolo 5(3) e l’argomento della “stretta necessità” regge poco in Europa, dove i regolatori tendono a interpretare il termine in modo restrittivo. Kenney ha tuttavia preso le distanze dall’etichetta “spyware” usata da Hanff, precisando che si tratta di un livello di integrazione pre-posizionato e dormiente, non di una esfiltrazione attiva di dati, anche se il rischio per la superficie di attacco è comunque reale.
Anthropic non ha risposto né alla richiesta di commento di The Register né al post di Hanff. Quest’ultimo ha dichiarato di non aver ancora presentato un esposto formale, ma di avere intenzione di farlo qualora l’azienda non intervenga sul meccanismo di installazione.
ConsiglioVPN illimitata, privacy senza confini da 2€ al mesePassa sopra / Tocca
🚨 Bitwarden CLI got compromised.
A malicious npm package targeted developers, stealing tokens, SSH keys, and cloud creds through a supply chain attack.
If you installed it, your secrets could be exposed.
Remove it. Rotate everything. Check your CI now.
👉️ https://digitalescapetools.com/2026/04/bitwarden-cli-attack.html
Daily Digest | 24 April 2026
Your daily dose of Privacy, Data Protection, AI & Cybersecurity news.
5 stories you should not miss.
Read more: https://www.nicfab.eu/daily-digest/
Age verification is expanding from laws into platforms and operating systems, linking access to identity checks across services and devices 🌐
Implementations often require IDs or biometrics, creating centralized data targets and reducing anonymity despite privacy claims 🔐
🔗 https://proton.me/blog/age-verification-explained
#TechNews #AgeVerification #Privacy #DigitalID #Cybersecurity #OpenSource #FOSS #DataProtection #Security #Encryption #Surveillance #Regulation #Infosec #Tech #Identity