Dean Pierce

@deanpierce.net

Security Research in Portland, Oregon #HackThePlanet 🧑‍💻🌎🌍🌏

Tons of peoples' Claude chats are exposed on Google. Cryptocurrency keys, API keys, login credentials, legal discussions, more. This happened with ChatGPT last year. And Claude too. There's clearly an ongoing issue with search engines indexing peoples' AI chats www.404media.co/tons-of-peop...

Tons of Peoples’ Claude Chats and Creations are Exposed on Google

Claude users are creating public share links, but probably don't realize that means their chats are now ending up in Google searches where anyone can dig through them.

404media.co

Can online voting stay anonymous, AI remain open and mesh messaging survive government pressure? This week: Freedom Tool, Google’s face-video recovery, open-weight AI, rollup security councils, Bitchat in India and more. Read Web3Privacy Now: news.web3privacy.info/2026-31/

Bild

San Francisco police accidentally livestreamed their drones’ video and data on the open web. The hours of footage—including several apparent arrests—should never have been made public, but now offer a glimpse of modern aerial urban surveillance. www.wired.com/story/sfpd-d... w/ @dmehro.bsky.social

A Leak of San Francisco Police Drone Footage Exposes the New Reality of Urban Surveillance

The SFPD’s exposure of hours of videos from drone platform Skydio reveals how broadly it’s watching the city from above—and how the results can spill online.

wired.com

www.bleepingcomputer.com/news/securit... "don't use scary china apps, because their government can access your data and that's a privacy risk" friendly reminder from US cops that you're better off under the palantir/google panopticon; make sure the creeps reading your DMs are all-american 🇺🇸

FBI warns against using Chinese mobile apps due to privacy risks

The U.S. Federal Bureau of Investigation (FBI) warned Americans against using foreign-developed mobile applications, particularly those created by Chinese developers.

bleepingcomputer.com

Apple and Google are gradually expanding their use of hardware-based attestation. They're convincing a growing number of services to adopt it. Google's Play Integrity API and Apple's App Attest API are very similar. Apple brought it to the web via Privacy Pass, which Google intends on doing too.

Keyed nonces are not just a way to add stronger in-protocol support for privacy solutions. They are also a potential first foray into a new state scaling strategy for Ethereum: create new types of storage that are more… https://firefly.social/post/ff-556bd7e35ea64383af98efa6e6c975c2?s=bsky

Continue reading on Firefly.Social

Keyed nonces are not just a way to add stronger in-protocol support for privacy solutions. They are also a potential first foray into a new state scaling strategy for Ethereum: create new types of storage that are more optimized for handling categories of use cases that we care about, with restrictions on their use that make them usable at extreme scale while preserving the protocol's decentralization. Let's zoom in on this case (in-protocol nullifiers). Let's say we get to 2000 TPS of privacy-preserving transactions onchain, for eight years. Then we get 2^11 tx/sec * 2^25 sec/year * 2^3 years = 2^39 [ie. 500 billion] nullifiers stored onchain (the challenge with nullifiers is that they are fundamentally not possible to prune). It's actually far easier to keep Ethereum decentralized if we have 500 billion nullifiers onchain in a dedicated nullifier store, than if we just let them grow in the current state. The reason is that the more restrictive structure of nullifiers (only used to check validity, and we can require the nullifier ID to be explicitly specified in the tx) enables more decentralized ways of handling them. This includes: * Sharding: each node (incl builders) can hold a small percentage of nullifiers, and make sure to have a connection to an honest peer in each other shard * Bloom filters: see this somewhat wacky idea here for reducing the VOPS requirement for nullifiers to ~8 bits per nullifier: https://docs.fileverse.io/d/020001fc0012#k=UT7Btd6tyqHgOj47t-TX06F8D6OpcpM_2PKdf7s4tGE Both techniques are not possible to use for dynamically accessible state. And so builders would have to download the full 16 TB to become viable (not just optimal, viable!), and privacy protocol users would not be able to use FOCIL without providing a Merkle branch proving that their nullifier is unspent, and there would be very few nodes capable of providing such a branch... Zooming back out, the moral of the story is that fully dynamic state is much harder to handle at extreme scale (tens to hundreds of TB) than state that is more controlled and restricted in how it can be used. And so if we can move the majority of usage into these more specialized forms of state (which we can make much cheaper in terms of gas), then we can keep Ethereum decentralized, and highly scalable, and keep the fully dynamic state available for applications (eg. defi) that really need its full functionality.

firefly.social

Residents of an Atlanta suburb learned that Flock had been accessing cameras in the town—including in a children's gymnastics room—to demonstrate the company’s surveillance technology to police departments around the country. The city renewed the contract anyway. www.404media.co/city-learns-...

Teen suicide rates are down 11% since I helped create the national teen suicide hotline. Republicans are actively trying to defund it so they can pay for Trump's war in the Middle East. They don't care if kids die as a result as long as they get their oil.

PBS News@pbsnews.org · 3mo ago

Nearly 4,400 fewer U.S. teens and young adults died by suicide than projected in the first two-and-a-half years of the 988 mental health crisis hotline, a sign the program is working even as it faces long-term funding challenges. https://to.pbs.org/4cFt4ao