Whitney Merrill

@wbm312.bsky.social

I nudge people to care about privacy and security. CPO/DPO. Privacy/infosec lawyer. Hacker. Fighting for privacy, digital civil liberties & the users. Ex @EA @FTC |my views are my own. I used to post on Twitter at @wbm312.

most tech outlets spent the week burying the lede that this was a completely avoidable error (or intentional marketing decision) by a human being, and not a malevolent self aware cyber consciousness that slipped its leash

OpenAI’s Hacking Debacle Comes Down to Human Error

If the generative AI giant had followed well-known security best practices, it’s likely that its AI agent would never have escaped to the open internet and hacked multiple companies.

wired.com

“The vast majority of the talent and agents at our events felt that these were a violation of their privacy and were damaging and spoiling the interactions at the tables. Several expressed concerns that they might not continue to attend in-person events if they were being recorded in secret.”

Meta glasses banned by Comic-Con promoter after 'secret filming'

A number of guests said they would be reluctant to appear at conventions again after cases of recordings taking place without their knowledge.

bbc.com

Flock's CEO keeps saying people don't understand their tech. Just told local news their cameras take a "static picture." But the company has spent the last year announcing it was bringing real-time video to existing ALPRs and public records show this was turned live: www.404media.co/flocks-ceo-s...

Flock's CEO Says its ALPRs Don't Do Video After Repeatedly Announcing They Can

Flock's CEO Garrett Langley says people don't understand the capabilities of its ALPR system, but they do.

404media.co

Meanwhile, I'll remind folks that everyone cheering on New Mexico's big lawsuit win against Meta... that one of the remedies NM's AG is seeking is stopping Meta from offering encrypted messaging. Indeed, some of the "evidence" against Meta was literally "they offer encryption."

Riana@riana.bsky.social · 3w ago

Disincentivizing widely-used online services from offering strong encryption. During a war with Iran. A country that's been conducting cyber operations against U.S. targets for years. That's what both parties think belongs in the NATIONAL DEFENSE BILL.

Disincentivizing widely-used online services from offering strong encryption. During a war with Iran. A country that's been conducting cyber operations against U.S. targets for years. That's what both parties think belongs in the NATIONAL DEFENSE BILL.

John Perrino@johnperrino.com · 3w ago

There's another effort to break encryption in the US Senate! The STOP CSAM Act was added to the current version of the annual defense spending bill, known as the NDAA. If passed, it could require Internet infrastructure services and online platforms to break encryption to scan all data.

Flock Safety cameras are tracking and sharing our data without a warrant, but local communities across the U.S. are fighting and winning against this gross privacy violation. Get involved in the nationwide movement to say Get the Flock Out at aclu.org/gtfo_

Gray graphic reading "Flock is tracking our movements and putting this information in a nationwide database that can be accessed by police officers and ICE agents." There are collaged images of police officers, ICE agents, and surveillance cameras at the bottom of the graphic.

New: there is a major vulnerability with Apple’s Hide My Email feature that lets attackers discover peoples’ real emails. Verified it works on my own email. We’re not disclosing how it works because Apple has not fixed it. But Apple has known for more than a year www.404media.co/apple-hide-m...

Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses

”Hide My Email users deserve to know that it may be possible for attackers to discover their hidden email addresses,” the person who reported the issue said.

404media.co

"Sadly, data breaches are an all-too-common feature of modern life, which is one more reason that corporations like Madison Square Garden should not harvest and hoard personal information about their customers," EFF’s @adamdschwartz.bsky.social told @cnet.com.

Madison Square Garden Targeted Privacy Activists and Surveillance Critics

A leaked dossier exposes the private data of prominent digital rights activists who publicly criticized the company's facial recognition technology.

cnet.com

NEW: Insane screwup inside Meta. The company exposed worker keystroke data that was being used to train AI — making it potentially accessible to anyone at the company. The data included personnel and performance info, private convos, full transcriptions…imagine your coworkers seeing all of that.

Meta Exposed Data Internally From Its Controversial Employee-Tracking Program

Employees had previously raised concerns about the initiative, which involves collecting workers’ keystroke data to train AI models.

wired.com

This expiration happened because surveillance maximalists in Congress refuse to make key reforms to 702, specifically a warrant requirement that would prevent the FBI from dipping into a massive communications database to spy on Americans without probable cause. We say: warrant requirement or bust.

The 702 Ultimatum: Warrant Requirement or Bust

For months now, Congress has been kicking the ball down the road—temporarily postponing the expiration of the mass surveillance authority Section 702 of FISA in hopes that some consensus could be reac...

eff.org