Spyke
privacy·PrivacybyXLE

Mozilla's new Exa partnership: the privacy implications

Mozilla recently announced a partnership with the AI company Exa. They say:

Firefox is investing in partnerships with companies like Exa.ai to bring deep expertise in specific areas while sharing our commitment to user choice, privacy, and transparency.

They continue:

We’re picking partners for the same reason each time: people who think AI in a browser should work for you, not the other way around.

This is a little ironic when Exa's CEO describes it differently:

We’re organizing the world’s knowledge, but this time for AI

...But I digress. Mozilla promises three things above.

  1. User choice
  2. Privacy
  3. Transparency

I'll be looking into privacy exclusively (and leave the fact Exa is an undisclosed member of the Andreesen Horowitz portfolio for another day).

A Privacy Audit

Exa's privacy policy is short and troubling. It starts with an entitled attitude towards private data that might be available online:

Although publicly available data is not considered "personal information" under certain data privacy laws, we have nevertheless described how we collect, use and disclose such information...

This is an appeal to technical legality: common sense would dictate that a publicly leaked database of social security numbers would be personal information, but apparently the possibility that it's not explicitly enumerated under some (unnamed) privacy laws irks the AI company.

Not a great start, but maybe things get better...

When you use or access the Services, we collect certain categories of information about you from different sources. In addition to the specific uses discussed below, we may use this information to provide and improve the Services and to maintain our business relationship... and protecting our rights and the rights of our employees, users or other individuals.

What other individuals need this company'a protection? How will information be used to "improve" their product? These questions are unanswered. But we do get told a bit more about sources:

We and third parties also automatically collect certain information about your interactions with the Services, including through cookies, pixels or other tracking technologies. This information is collected and used to better understand user interactions with the Services, run analytics, monitor and improve performance, measure engagement and to tailor and enhance user experience. Such information includes:

  • Device information, such as device type, operating system, unique device identifier, and internet protocol (IP) address.

  • Location information, such as approximate location based on IP address.

  • Other information regarding your interaction with the Services, such as browser type, log data, date and time stamps, clickstream data (e.g., page requests, page views, how much time is spent on a page, content viewed or interacted with, text entered, etc.), interactions with marketing emails

That's a ton of data!

Exa describes how they refuse to honor requests not to track you.

Your browser settings may allow you to transmit a "Do Not Track" signal when you visit various websites. Like many websites, our website is not designed to respond to "Do Not Track" signals received from browsers.

Exa admits they knowingly collect personal data by default, and it's unclear how or if Firefox Smart Window uses can steer clear of the privacy problems.

On default plans, we use anonymized data...

[You can] opt out of Exa's collection of brokered personal information, opt out of its database, or out of its certain sale of data customers...

Opt out of certain, but not all, sales.

Exa has a second privacy page that describes its compliance with requests to delete private data or opt out of selling it. It received 50 total requests to delete or opt out of selling private data, and "complied", which can include incomplete compliance for some reason, with only 5 of them. That's a 10% compliance rate.

[new] Exa monetized "finding" individual people

I just found out about another skeleton in Exa's closet: the stalkerish People Search that scraped and started publicizing work information. From a LinkedIn post:

I can pull entire staff lists for companies. I can [get] an individual’s work history. I can pull lists of people with a particular job title in a geographical area. I can also combine all this with richer company information and web search data...

Exa are very brave as I can’t imagine LinkedIn likes it very much.

Does this fit Mozilla?

On privacy alone: no.

Mozilla promises a commitment to user privacy, and promises to only work with companies that share that commitment. Exa demonstrates hostility towards user privacy.

Maybe the New, AI-First Mozilla has abandoned this charter, but their website still says:

Individuals’ security and privacy on the internet are fundamental and must not be treated as optional.

View original on piefed.social
25

With Nitter getting a cease and desist today, I'm glad I moved family photos off big platforms last winter

Saw the top post today about Nitter getting a cease and desist. Not surprised, but it hit a nerve.

Last winter I finally moved my family off Google Photos. Not for ideology, just tired of paying for One that gets more expensive every year.

Old Dell Optiplex 7040 in the closet, Immich for photos, Nextcloud for docs, Matrix for family chat. It was messy. I forgot to set up proper backups and almost lost a month of kid photos in January. My wife still brings it up.

Before that I thought privacy was about picking a better provider. Nitter was part of that logic too - use a private frontend for a bad platform. But frontends die. Nitter, Invidious, all of them. One letter and it's gone.

Self-hosting didn't solve everything, but at least my photos don't depend on someone else's frontend staying alive. The problem now is family. My server is in my closet, but my sister is still on Messenger, my mom on iCloud. My setup doesn't protect them.

Curious how you handle this part. When the frontend you rely on disappears, do you try to move family to Signal/Matrix or just accept you can only protect your own node?

View original on lemmy.world
30
privacy·Privacybybeep

Nitter(X/Twitter frontend) project received cease and desist

cross-posted from: https://piefed.world/c/tech/p/1358432/nitter-project-received-cease-and-desist

Cease and desist

On 24 August 2026 cease and desist letters have been sent by X Corp. demanding a permanent takedown of Nitter instances and the project's repository.

nitter.net is offline and development has stopped for the time being. I'm seeking legal advice and won't be commenting further on the specifics for now.

Thank you to everyone who used, hosted, packaged, donated and contributed to Nitter over the past seven years.


— zedeus, 25 August 2026

Photo source: Official website/instanceArchive.

More info: GitHub issue 1442.

View original on piefed.world
146
privacy·PrivacybyXLE

Apple Won't Change Hide My Email Domain After Backlash

Apple today said it is reversing its decision and will not change the email domain used for the iCloud+ Hide My Email feature. Emails sent using Hide My Email will continue to use the same icloud.com domain that Apple uses for standard iCloud emails. In June, Apple said it would unify the email domains used by Sign in with Apple and Hide My Email under a single private.icloud.com domain.

This is good news, should they not try the same trick at a later date.

Apple Won't Change Hide My Email Domain After Backlashhttps://www.macrumors.com/2026/08/24/apple-hide-my-email-domain/Open linkView original on piefed.social
25

AliExpress tracks users via inaudible audio fingerprinting

cross-posted from: https://scribe.disroot.org/post/10925160

Archived version

If you shop on AliExpress and your Bluetooth headphones stop switching between devices, this is caused by hidden tracking scripts on the site, not broken hardware. Install uBlock Origin and add filter rules to block collina.js and fireyejs.js on aliexpress.com, then close all open AliExpress tabs and reload the site for the fix to take effect.

...

AliExpress users report a privacy-invasive tracking mechanism on the company's homepage that interferes with Bluetooth hardware. The site runs hidden audio processes that prevent multipoint headphones from switching between devices. This behavior occurs even when the tab is idle and no media is visible to the user. The issue is caused by Alibaba's security scripts designed for device identification and anti-fraud detection.

...

AliExpress tracks users via inaudible audio fingerprintinghttps://beyondmachines.net/event_details/aliexpress-silent-webaudio-fingerprinting-uses-bluetooth-hardware-9-o-c-m-i/gD2P6Ple2LOpen linkView original on scribe.disroot.org
46

How terrifying is government mass surveillance?

This is different from tech corpo mass surveillance since the government has the authority to imprison, silence or kill dissidents (while Palantir doesn't have that power since they're a company, not the federal government). Put it this way, Palantir can only spy on people harvesting their data but cannot arrest them since they are not cops nor the FBI, meanwhile the government (via FBI, NSA or CIA) has the leverage to detain people.

Instead of Palantir harvesting people's data, it's the FBI or NSA themselves doing that building a profile based on the people they're "keeping tabs" on, what would it be like if mass surveillance is endorsed by the government rather than tech companies in a dystopia? That data gets shared with state authorities (police or sheriff) in which they one day visit your home just because of the content you posted online.

View original on feddit.online
41

noRecognition: defeating a live Flock detector with a small printed pattern

Pretty awesome. He holds up the paper and the cam instantly fails to detect any human in the frame.

This is how we take it back. Force them to keep adapting. Fashion is the new monkeywrench.

Testing an adversarial pattern against a live Flock Safety person detector (YOLOv5-320). No pattern, the camera locks on at 0.81 confidence and reports a person. Hold up the printed sheet and detection drops to nothing.

This run was about size. I wanted to see how small a printed pattern could get and still cause the detection to fail. The sheet here is a hand-held print at close range, not a finished garment, and this is a live detector, not a composite.

Part of the noRecognition project

View original on piefed.social
26

what am i doing wrong? i feel like i have no privacy or connivence.

cross-posted from: https://sh.itjust.works/post/65506805

(this is my first post im new) ive noticed something no one seems to have a problem with. do you have this problem to? am i just doing something wrong?

i use a privacy friendly browser plus a privacy friendly os and use fingerprint spoofer/blocker. i watch videos on invidious. i noticed that the "popular" tab shows videos related to videos i watched before. even if i clear my cookies, or change my idenity in (offiscial) tor browser i still get recommended related videos meaning no matter what i do google knows what i watch. whats worse, if i go on invidious on a totally different device with a normal broswer normal os, i get the same videos. meaning websites know what videos i watch across multiple sessions but also multiple devices. im sick of this. it feels like i've tried everything, sacrificed so much connivence but no results.

(this isn't a question spefecifically about youtube google or invindious just how to get webisites to stop knowing everything i do across multiple identities and every device i use)

Things I tried

*Proton vpn+librewolf(max security according to settings)+nosircpt+Ublock(with the filters it comes with)+ officisal recommended invidious instances+Quad9 via settings

*Tails+Tor browser(max security settings apprentaly)+default bridge+no javascirpt+fingerprint spoofing estendsion+bluetooth disabled by tails+all the previous mentioned (exculding vpn i heard its risky)+invidious again (Tails doesn't work well for me the police are not after me and it takes so long to start and presisent stoarage is annoying)

*Qubes+Whonix vm+Tor browser(max again)+no javascript (I love and hate qubes from my first impression it meets my security needs and you can run any os in a vm on it but i wish it just worked. theres a steep learning curve and my hardware isn't the best for it)

No results on any of these just slower internet and some websites are broken. Its just like using a normal browser that tracks you but slow as a privacy one. im getting tired of this. i use all this super deep level paranoid overkill stufff and nothing happens. like im burning my house to get rid of a spider but the spider is still there

possible causes -google wireless access point (does qubes/whonix/tor NOT protect against this at all??) (also my family HATES any changes or mild inconveniences) -i logged in to google without a vpn ONCE does this automatically doom you forever even if you change os and browser and device? -hardware is framework laptop

for clairtiy I am not -a criminal -a journalist -a gooner -willing to go off grid in the woods I am -creeped out -tired -about to give up My privacy goals -be able to actually cut ties with my shadow profile and have websites not know everything ive done in my life -control what data brokers and compaines knsw -not have any website at all know every device i use -be able to use any network safely

I feel like giving up on privacy because nothing seems to work. the only results I get is slower more broken internet

View original on sh.itjust.works
10
privacy·PrivacybyNightOps

Is "banning" social media outright stupid?

Both the UK & AU have passed legislation in which they aim to "ban" social media for kids -16 (or that's the excuse they're using) when its the catalyst for mass surveillance (unfortunately, even if you tell them the truth: it's either people including your own family consider you paranoid or a conspiracy theorist). To avoid that, one must gather sufficient evidence debunking or dispelling the lies being shoved into the masses via media.

The common defense for this is "think of the children" from either lazy parents or Christian conservatives as that's the easiest lie ever told besides social media or internet usage (you heard that from games, movies or music restrictions in the past). IMO, "banning" SM outright or trying to reinforce AV towards everyone creates more hassle for both sides (users and companies) as SM companies can face large fines for non-compliance.

If you look at the larger picture: it treads on one's liberties such as freedom of speech & expression as what appears to be "no SM for -16" soon morphs into a 1984-esque dystopia where people will be detained for speaking their mind or the truth. This is what digital privacy advocates fear, basically saying that internet anonymity will cease or be deemed illegal if people lack critical thinking or can't see through the fog.

Even though the laws have passed in both countries: it does nothing as people (kids and adults) can still access SM. They know VPN's exist, banning or trying to lock that under AV will make them look stupid. SM is toxic due to the slop and demographic, but IMO should remain up to the individuals or families rather than the government (all MSM side with the state using "no SM for -16" omitting mass surveillance in the headlines).

View original on nord.pub
32

Aaron Rodgers Reportedly Funded NJ Police Surveillance Cameras

Aaron Rodgers, then quarterback for the New York Jets, reportedly lived in Cedar Grove, New Jersey when the alleged 2024 donation was made. Drivers passing through Cedar Grove, New Jersey on a routine errand in 2024 may not have noticed the cameras. According to an investigation by FOIAball, every time a car passed certain intersections, a camera was logging its plate, location, and time of arrival into a searchable police database. The person allegedly funding that network was, at roughly the same moment, publicly complaining about surveillance drones over his own property.

Aaron Rodgers Reportedly Funded NJ Police Surveillance Camerashttps://www.gadgetreview.com/aaron-rodgers-reportedly-funded-nj-police-surveillance-camerasOpen linkView original on lemmy.world
60
privacy | Spyke