r/privacy 14h ago

news Florida bans Flock and other license plate readers from state highways as backlash grows

Thumbnail nbcnews.com
1.4k Upvotes

r/privacy 14h ago

news Meta Settlement Ignites Global "Child Safety" Digital ID Push

Thumbnail reclaimthenet.org
279 Upvotes

r/privacy 17h ago

news Google Has Removed Manifest V2 Extensions From the Chrome Web Store, Including uBlock Origin

Thumbnail webiterate.dev
248 Upvotes

r/privacy 5h ago

discussion Xfinity recently implemented a “WiFi motion” software update August 18th and they claim it isn’t a security feature and it’s “opt-in”

Thumbnail xfinity.com
114 Upvotes

As many data breaches we’ve seen in recent years, I have no idea how we can circumvent this. Has anyone responded to this craziness. I only have Verizon & Comcast in my city.


r/privacy 3h ago

news A N.J. school district found a new way to enforce the cell phone ban — and parents are fighting it

Thumbnail nj.com
74 Upvotes

A New Jersey school district is using an app that geofences students' personal phones to shut down most capabilities during school hours. Parents are pushing back over privacy concerns, particularly around location tracking. The superintendent says it's optional, but critics argue families weren't consulted before implementation.


r/privacy 10h ago

discussion Friend's phone was stolen and they made her unlock it. How to recover from this (security-wise)?

59 Upvotes

Hearing this story was very unsettling.

I have been working on the assumption that if my phone was stolen, it is just a brick, since it's encrypted and locked with biometrics and a strong password.

A friend was robbed at gunpoint (while out for a run!), and they made her unlock the phone, so they could turn off the data connection and have access.

If her password manager was unlocked - or autofill was turned on - they could then go to her bank, access her accounts, and the 2FA would be right in their hands already.

If my phone was stolen, my first move would be to have T-Mobile cancel my number to protect my 2FA. Then I would want to change my important passwords. But how do you regain access to your accounts so you can change passwords, etc. if you don't have your phone number for 2FA?

Lessons I learned from hearing her story:

  1. Never leave your password manager unlocked. I use 1Password, and it is always locked when the phone is locked. I can unlock it with my fingerprint or password. I do have somethings in auto-fill in Chrome, but nothing critically important.

  2. Consider moving away from 2FA to something else. I use Ente as my authenticator for about 100 sites, but many, including my bank, use my phone number for 2FA. Should I be moving everything away from my phone number as 2FA? Should I move to a YubiKey or similar? And I usually leave my Ente unlocked on my phone - need to change that.

  3. Don't allow text messages (2FA codes) to appear on the lock screen.

  4. Anything else to consider here?


r/privacy 9h ago

question Can someone help me out with Motorola ALPRs vs Flock?

13 Upvotes

I'm giving a speech in town hall soon for a school project, and the topic I chose was Flock cameras. I did a lot of research and wrote up this whole thing, only to find out that all of the Flock cameras in my town are on private property, and the city only owns Motorola cameras. I'll still bring up Flock, but since the city doesn't own any, I dont want that to be the bulk of my speech.

Currently, I've modified the speech to just talk about ALPRs in general, and the partnership between Motorola and Flock meaning potentially shared data and vulnerabilities. I'm not asking anyone to write me an essay, but it seems like there's not a lot of research on motorola yet, and I'd love if someone could point me towards an article or video that explains more.


r/privacy 2h ago

hardware Does your vehicle have a KARR sticker in the window?

12 Upvotes

TL,DR: If you have a KARR sticker on your window, your car probably has a dongle in it that may leave it susceptible to hacking, including remotely unlocking it and disabling the engine. You can update the firmware and/or ask KARR to come and remove it.

You can learn more about the security risk by searching for "UC San Diego KARR Aaron Schulman" which will get you to the researchers at UCSD who discovered and documented the risk.

Details: When I bought my Ioniq 5 eighteen months ago, the dealer asked me if I wanted to subscribe to the KARR security system. I declined. Today I learned:

  • Dealers install the KARR security device in their cars to prevent them from getting stolen off the lot -- it lets the dealers remotely disable the ignition if needed.
  • The KARR device connects to the CAN bus in the car, giving it access to lots of important functions, like door locks, horns, lights and ignition
  • If you tell the dealer you don't want to pay for the KARR system, they leave it installed and "dormant", but it's still susceptible to hacking.
  • If you have a KARR dongle in your vehicle, the least you should do is download the KARR Security app, click on the Customer Service button at the bottom, and then click on "firmware update" to remove the vulnerability. If you're not a subscriber, this theoretically disables the device, but also prevents the app from communicating with the device, so it's not clear if the device is truly deactivated.
  • If you're like me, you want to reduce the risk and also don't want an extra device sucking down your 12v battery 24 hours a day. In that case, you can call the KARR Customer Service number and schedule a tech to come remove the device, free of charge.

Whew. Who would have thought?


r/privacy 19h ago

discussion What should an audit log show to the person whose data was accessed?

5 Upvotes

Organizations often keep internal access logs for security teams while the person described by the data sees only a generic privacy notice. A user-facing record could show when access occurred, which organization or system accessed it, the category of data, the stated purpose, whether it was exported or shared, and the retention or appeal path. Full detail can create new privacy and security risks by exposing employee identities, investigation methods, or other people's records. Where should that boundary sit? Would delayed disclosure, role-level identities, tamper-evident event IDs, and exceptions that require later review provide meaningful transparency without turning the audit log into another sensitive dataset?


r/privacy 14h ago

question Any good standalone, E2EE contacts apps for iOS? Trying to keep some contacts isolated

5 Upvotes

As most of you probably know, even if you turn on Advanced Data Protection on iOS, Apple doesn't E2E encrypt contacts due to legacy CardDAV support. Obviously, this isn't just an Apple issue (Android and standard Google sync have the exact same problem), but iOS is just the ecosystem I'm using right now.

Between cloud exposure and third-party apps always begging for full address book access, I'm trying to clean things up. The goal is to delete people I rarely talk to from my native iOS Contacts app and move them to a separate, encrypted, sandboxed app.

I already use Proton, but Proton Contacts is baked directly into the Proton Mail app. There's no standalone contacts app, so it ends up mixing my actual phone contacts with every random email address I've ever replied to. It gets messy fast.

Right now, my only real workaround is saving them as Identities / Secure Notes in Bitwarden or in an encrypted notes app, but I'd prefer an actual dedicated contacts manager if one exists.

Does anyone know of a solid, privacy-focused standalone contacts app on iOS that keeps its own encrypted database rather than just syncing everything back into the native Apple Contacts pool? What is everyone else doing to handle this?