Vue lecture

FBI Probes Service Selling 153M+ Drivers Licenses

A dark-web identity theft service called Nexus claims to be selling scans of more than 153 million U.S. and Canadian driver's licenses, along with millions of other identity documents. "Based on interviews with individuals whose licenses are available for purchase through the service, it appears to be siphoning images collected by a widely used Louisiana-based identity verification company," reports KrebsOnSecurity. The outlet also reports that the FBI's New Orleans field office has launched an official inquiry into the source of the images. From the report: On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit, offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit. The service, dubbed Nexus, claims to have more than 153 million drivers licenses for people in the United States and Canada, as well as more than 10 million identification cards; more than three million travel documents and/or international IDs; and at least 579,000 medical cards. [...] The people behind Nexus claim the license images are coming from an active breach at "a major identity verification company" whose customers include multiple Fortune 500 companies. "We have been continuously exfiltrating new data for over a year into our private database," the service enthused in its introductory post on Exploit. "Records are available to preview before purchase with pertinent information redacted. Customer photos are displayed if available." Indeed, over the past 24 hours, the number of drivers license records listed as available in Nexus has increased by nearly 400,000, suggesting that freshly stolen license data is being harvested and uploaded to this service on a semi-regular basis. KrebsOnSecurity traced the apparent source by comparing timestamps on stolen license images with when their owners had their IDs scanned, including at Hertz rental counters and a Planet13 dispensary. Both companies use identity-verification services from Louisiana-based idscan.net, whose technology also scans IDs using infrared and ultraviolet light. Since the story was published, Krebs reports that the Nexus identity theft service website "vanished from the darkweb, replacing its login page with a plain text message that reads, 'This service is no longer available.'"

Read more of this story at Slashdot.

  •  

AliExpress Leverages User Audio Systems For Fingerprinting

A developer says AliExpress is using the browser's WebAudio API to help fingerprint users by playing inaudible audio and measuring tiny differences in how their devices process it. CyberNews reports: The developer, "laserphile," wrote on their blog that they recently ran into some weird issues with their Bluetooth headphones. They couldn't play music via their phone when, at the same time, the AliExpress website was open on their PC. The headphones, laserphile explained, support multipoint Bluetooth audio so they can be connected to the PC and phone at the same time, for instance, playing music on the phone and announcing notifications through the PC. "Shortly after loading the AliExpress homepage, audio from my phone would stop playing. Closing the AliExpress tab fixes it immediately," the developer said in the blog post. "Muting the tab/Firefox/Windows does not help, and there is no visible video, music, or other media playing on the page. This seemed suspicious enough to investigate." It turns out that Alibaba has been secretly leveraging AliExpress users' audio systems to track them and build detailed fingerprints of them. [...] The AliExpress site was using the browser's WebAudio API to run invisible sound waves at zero volume. By measuring tiny hardware differences in how each PC processed those signals, the site created a unique digital fingerprint to track devices -- without user knowledge or consent. The secret audio path froze the developer's Bluetooth connection while covertly scraping hardware memory, screen dimensions, and network data in the background. The data collection extends beyond audio. Further inspection revealed that the same scripts also measure canvas, WebGL, hardware specs, WebRTC, mouse/touch events, and automation indicators. All of these form a broad device fingerprint that is sent back to Alibaba's telemetry servers. The simplest fix is to use a privacy-focused browser such as Firefox or Brave, which can limit or block this kind of fingerprinting. Brave goes further by randomizing fingerprint data and blocking the AliExpress tracking scripts involved.

Read more of this story at Slashdot.

  •  

Flock is Secretly Building a Powerful New Prompt-Based AI Tool for Police

Slashdot reader fjo3 shared this article from Wired: [Flock] has told the public for years that its technology "cannot recognize, identify, or track individuals." It has now built a system that does both, an artificial intelligence tool for police that can identify drivers and track vehicles by their patterns of movement alone, WIRED has learned... Because the system also reaches police case files, 911 dispatch logs, and commercial identity records, those plates can be turned into names, home addresses, and relatives. It can search for people in an area drawn on a map based on nothing more than a physical description... The code describes 45 tools at the AI's disposal, giving it access to plate scans and camera metadata, arrest records, case files, dispatch logs, ballistics results, and commercial databases that contain Social Security numbers, dates of birth, phone numbers, email addresses, relatives and associates. Flock says it is testing the product with a small group of law enforcement partners and describes it as still in development, with capabilities that may not reflect what it eventually sells. It arrives as the company faces bipartisan political pressure, a growing record of officers caught misusing its platform, and a wave of vandalism that has left cameras sawed off and lenses painted over in cities across the country... An officer no longer needs a plate, a name, or a crime to begin: They supply a place, a stretch of time, and a pattern of behavior, and the system is designed to hand back the people who fit... One prompt Flock preloaded into the system reads: "Find me witnesses based on vehicles most seen in [neighborhood] during [last 14 days] during [daily timeframe] *(will not include whitelisted vehicles)." An officer would fill in the blanks and submit it. The output is a list of plates, which other tools in the product then convert into names and home addresses. Another prompt instructs the system to list everyone arrested more than twice in two years for "any offense," exempting only narcotics arrests, and then says to map where those people live, retrieve the calls for service at their homes, and "do a workup on the top three individuals." The prompt begins with everyone in the area who has an arrest record and ends with dossiers on three of them, chosen by the software. A "workup," in Flock's terminology, is a one-command background check. It starts with a name and a date of birth and returns what the department's records and commercial data hold: vehicles, prior listings as a suspect, and, on a second screen, relatives, phone numbers, and online accounts. Wired shares this reaction from a law professor at George Washington University. "It is clear Flock has aspirations far beyond ALPRs to become a digital platform for policing,"

Read more of this story at Slashdot.

  •  

American Who Wiped His Phone With 'Duress' Password During Border Search Gets Felony Charges

Federal prosecutors have charged activist Samuel Tunick with obstruction after he gave Customs and Border Protection officers a duress passcode that wiped his GrapheneOS-powered Pixel during a border search. "His prosecution is one of the earliest known instances of the federal authorities charging a person with destroying evidence using a program designed to wipe a device clean after a specific code is entered," reports The New York Times. From the report: "Obstructing federal law enforcement is a serious matter that has serious repercussions," Theodore Hertzberg, the U.S. attorney for the Northern District of Georgia, said in a statement. "Individuals who destroy or attempt to destroy property, including data, to prevent lawful search and seizure should expect to face prosecution and punishment for their actions." A spokeswoman for U.S. Customs and Border Protection said in a statement that the agency had the authority to search the electronic devices of anyone entering or leaving the United States, regardless of citizenship, to enforce laws addressing terrorism, child exploitation, drug- and human-smuggling, visa fraud and national security threats. "The border search will only include an examination of information that is present on the device at the time it is presented for inspection," the spokeswoman said, adding that it searched the electronic devices of fewer than 0.01 percent of all arriving international travelers in the last fiscal year. "Just the knowledge that the government is peering into your private life in this way, trying to dig up dirt on you, even though it's unsuccessful, is creepy," Tunick said, in response to a question about how the charges have affected him. His message: "The government doesn't own our communications, our relationships, as hard as they might try to. We have to defend our fundamental right to privacy; otherwise we can't say that we really live in a democracy."

Read more of this story at Slashdot.

  •  

Man Dressed As Darth Vader Defends Flock Cameras to San Diego City Council

A man dressed as Darth Vader used a Public Safety and Livable Neighborhoods Committee meeting in San Diego to mock the city's use of Flock surveillance cameras, sarcastically arguing that the technology would help the "emperor" track "rebel scum" and find Luke Skywalker. "This is what the emperor needs. This technology will help us find the rebel scum and the hidden base on Hoth," he said. The Hill reports: He urged that the cameras be used to surveil any "rebel scum as they move from playground to playground, from playground to pool, from pool to gymnasium, because we all know that the Flock cameras are not only following the license plate readers, they are following children." The plea for the cameras shifted to raising taxes to clear out storm drains and to the clearing of homeless encampments in the city. The man said the council members can use "doublespeak" to say the police department is humanitarian. "And how will the people trust this City Council when this City Council continues to vote for surveillance technology that imprisons them? Ms. Campbell, you must work on your Jedi mind tricks," he said, addressing City Council member Jennifer Campbell, before waving his hand to the audience. "Do it like this." His last plea was for the Flock cameras to be used to "help us find Luke Skywalker as he traverses the universe in his X-wing." "This technology is a necessary, necessary force," he concluded. According to DeFlock, San Diego has more than 550 Flock cameras across the city.

Read more of this story at Slashdot.

  •  

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket, despite advertising its reverse-image search as "private and secure." A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired reports: Overall, according to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. All of the images were stored in an unsecured Amazon S3 bucket, with files in folders named "faces" and "profiles," which could be accessed by anyone online through a URL included in the company's publicly available website code. ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck's website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds." While ClarityCheck secured the giant image database after WIRED contacted the company in July, Fowler warns that it was seemingly exposed for months, and his initial efforts to flag the problem to the company were unsuccessful. Accidental data exposures create risk for any personal information, but particularly for sensitive and unchangeable biometric data like face images. [...] In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were "sourced from publicly available information and licensed third-party data providers." A spokesperson for ClarityCheck said in a statement: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it. "We do not accept that data in the temporary storage location was 'publicly exposed,' which implies large-scale public access," the spokesperson says. "Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search."

Read more of this story at Slashdot.

  •  

Sainsbury's Store Pauses Facial Recognition After False Shoplifting Claim

Bruce66423 shares a report from The Guardian: Sainsbury's has paused the use of AI face scanning in one of its stores after a customer was wrongly identified as a shoplifter and ejected from the shop. "I was embarrassed, mortified even, and felt quite humiliated and powerless," Matt Arnold, 46, said of his ordeal. The comedy promoter was buying supplies in the store in East Dulwich, in south-east London, for a standup event at Dulwich Hamlet football club when, after scanning his items and a Nectar card, he was approached by two managers who told him he could not be served owing to an earlier incident. He was then asked to leave and they tried to escort him from the store. As he left, he saw an overhead CCTV monitor alert with a red circle surrounding his face. He asked the shop staff to keep his shopping in the trolley so his friend could come and pick up the supplies for the comedy night happening soon next door. "I think they were quite confused by this, understandably, but agreed and my colleague Dave went in to pay for and pick up the shop about five minutes later. There was no pause for thought from the staff, no suggestion that they understood this is not how a shoplifter would behave. Just blindly following the machine's orders." Sainsbury's head office apologised to Arnold the next day and has paused use of its AI-assisted Facewatch technology in the store while an investigation takes place. Arnold says the facial recognition tech should be paused in all stores. "Anyone could be falsely accused and at some point that will be someone vulnerable, someone with mental health issues like anxiety. It's inevitable," said Arnold. "Also, I would worry about the confidence-destroying effect of it happening to a younger person or someone less willing or able to stand up for themselves as I have done." A Sainsbury's spokesperson said: "We have contacted Mr Arnold to apologise for his experience at our Dulwich superstore. The incident was caused by human error, not the facial recognition technology. Customers can be reassured that the Facewatch system has a 99.98% accuracy rate, and every match is reviewed by a trained manager." A Facewatch spokesperson said their technology was not at fault in this case. "A correct alert was sent to the retailer, but was subsequently subject to human error in the way it was handled in store," they said.

Read more of this story at Slashdot.

  •  

OpenAI Ditches Recall-Style Screenshot Surveillance For Friendly Keylogging

An anonymous reader quotes a report from The Register: If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you. It's called Computer History, an opt-in way to record your computer interactions across apps and websites as memories organized on a timeline. Why would you want to do so? Maybe you found Chronicle, the predecessor of Computer History which compiled similar histories using screenshots, a bit too intrusive but don't mind Computer History's approach -- recording input events and storing them unencrypted locally for 48 hours (or more), with a brief visit to OpenAI's servers. Maybe you're not bothered by the warning OpenAI includes in its documentation: "Computer History files can contain sensitive information. They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them." Perhaps, having given OpenAI's Codex and GPT Work the run of your computer, you're already sold on the suggestion that storing your computer activity in memory files and arranging those interactions in a timeline will improve ChatGPT responses, surface opportunities for automation, and make it easier to resume prior work. Computer History is, to put it bluntly, a keylogging and event capture system. "Computer History creates an interaction-event stream from allowed apps and websites," OpenAI's documentation explains. "Events can include clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system. Computer History periodically turns these events into text summaries and local memory files." OpenAI says the feature doesn't capture screen images, microphone input, or system audio. It also doesn't record private-mode browsing. "Turn it off during communications with other people unless you have their prior express consent," the company advises, perhaps in acknowledgement of legal risk. "Consider pausing it or excluding apps that contain sensitive health, financial, or personal information." ChatGPT and Codex delete locally stored Computer History interaction events after 48 hours, but data sent to OpenAI to generate memories may be retained locally longer and reused in future chats.

Read more of this story at Slashdot.

  •  

Bipartisan 'Uprising' Against Flock Cameras: a Larger Fight Against Big Tech and Surveillance?

Politico notes that over 20 local jurisdictions in America "either stopped using Flock cameras or began the process of doing so in July, according to a tracker maintained by DeFlock, an activist group that has been mapping the company. It's the highest amount in a single month since they began tracking in 2021." Some local officials said the public safety promises weren't worth the cost. The cameras "didn't help us with anything. From a utility aspect, they were just kind of not useful," said Eric Couture, a Democratic first selectman in Killingworth, Connecticut, another city that recently canceled its contract with Flock. "I'd say it was a net negative." And their article adds that it's a bipartisan pushback that "runs parallel to sprawling fights over the future of technology in American life, including the rise of increasingly advanced artificial intelligence tools and the construction of massive data centers needed to power them." Salon even argues Flock's cameras "have become a symbol of growing anger over the efforts by technology oligarchs to impose their dystopian fantasies on the country, replacing liberal democracy with a surveillance state... People are sick of tech billionaires trying to control our lives"" By targeting Flock cameras, activists are building momentum for a larger rebellion against the tech industry — and against political leaders who are complicit in their assault on our freedoms. Flock Safety embodies the dishonesty that has been the prevailing theme of tech corporate communications and marketing for at least the past decade. While the cameras are sold to the public as a banal traffic safety measure, they have prompted an outpouring of stories about how they're being used to violate civil liberties and undermine democracy... According to an exhaustive 10-month analysis by Electronic Foundation Frontier, a nonprofit dedicated to defending civil liberties in our digital age, local police were using the cameras to track protesters, such as those at No Kings rallies, who were then put in a national database to be used across all jurisdictions. Despite claims that the cameras only record license plates, the technology-focused outlet 404 Media found that the database is also being used to collect information on individual people whom cops can then search for using descriptions of clothing, race, gender and body type. The Flock uprising, though, is the stirrings of public understanding that none of this inevitable — and we have the right to fight back... Along with protests against data centers, it's a sign that the public is desperate for a way to fight back against not just AI, but also the anti-democratic forces fueling this latest tech wave. Salon's writer also adds that "what stands out about the burgeoning public rebellion against Flock security cameras is just how fun it all is," citing "a national cat-and-mouse game between vandals and cops that is being merrily followed on social media, mostly by people rooting for the vandals." City council meetings in which citizens swarm to protest paying for the cameras are the new must-see TV. In Huntington, West Virginia, a small city in the heart of Appalachia, one man became an internet folk hero when he stood up at a city council meeting and said, "I'm not gonna waste your time; I'm kinda hungry. But one last thing: Every single Flock camera has about 2-3 pounds of copper and about 1-2 grams of gold. Do with that information what you will." He then walked off in triumph.

Read more of this story at Slashdot.

  •  

Flock Announces Changes Amid Backlash Over Its License Plate Reader Network

Flock Safety is tightening controls on its nationwide license plate reader network after mounting backlash over privacy and documented police misuse. By January 1, law enforcement customers will be required to use automated auditing, tie searches to specific case numbers, and accept a shorter seven-day default retention period. Critics, including the ACLU, argue the changes still leave too much surveillance power in police hands. The Associated Press reports: In an interview, Flock CEO Garrett Langley said many of the product changes will make what were once optional guardrails mandatory for its users to implement by Jan. 1. Among them: All law enforcement customers will have to implement an audit tool that's intended to flag abnormal search behavior. When the system detects abnormal behavior, the user would be locked out pending an internal review, the company said in a description of the changes provided ahead of Thursday's announcement. Flock, which says its customers own the data that the cameras record, is also shortening the standard data retention window from 30 days to seven. It said it will allow data to be preserved for longer when it is evidence tied to a case number. Law enforcement users will now also be required to enter a code from their records management system tying each search to a specific case before it is run, something Langley said civil liberties advocates have long been calling for. Overrides for emergencies would be automatically flagged for review, the company said. Customers will also be allowed to decide which offense types -- such as homicide or arson -- outside agencies can search their data for, which would allow a customer to block outside searches related to immigration enforcement, the company said. Langley said that change will give individual cities and departments control to use the system in a manner "consistent with community values." Critics say Flock's changes don't address the core problem: police can still decide for themselves when and whom to search without judicial oversight. The ACLU called the shorter data-retention period "a step in the right direction," but dismissed the other safeguards as "retreads" of inadequate protections, while Institute for Justice attorney Robert Frommer called the reforms "window dressing" from a company in "panic mode." He argued that searches should instead be approved "by judges with real warrants."

Read more of this story at Slashdot.

  •  

A Data Breach At Shipping Giant Ceva Logistics Is Rippling Across Banks, Retailers, Steam Gamers, and Beyond

An anonymous reader quotes a report from TechCrunch: Ceva Logistics, one of the world's largest shipping and logistics giants, has been hacked. Several companies that rely on Ceva for shipping their products to their customers say that their personal information was also stolen in the breach. The cyberattack on Ceva is affecting at least eight warehouses across Europe used for shipping goods across the continent, the company told TechCrunch. Industry news site FreightWaves reports that the hack began on July 29 and is causing shipping delays for many of the goods in affected warehouses. Ceva is a France-headquartered shipping and logistics giant that companies around the world rely on to deliver their goods from their assembly lines to customer homes. The company, which brought in $18.3 billion in revenue in 2025, has over a thousand warehouses across the world. [...] The hack at Ceva also resulted in a data breach, affecting a large amount of personal information belonging to retail customers that Ceva relies on for delivering goods to people's home addresses. Several companies reported that hackers took their customers' names, home addresses, phone numbers, and email addresses used to place their orders from Ceva's systems. Dutch online retail giant Bol said on its website that hackers gained access to systems of its warehousing partner, Ceva, and warned that their customers' data may have been taken. Bol also said that it expects delays and some customer orders to be canceled as a result of the incident. De Bijenkorf, another Dutch luxury retailer, similarly confirmed order delays following the theft of its customers' data, per local media. Football club Ajax, banking giant ING, and eyeglass maker Ace & Tate also reported that customers' shipping information was affected. Video game giant Valve told customers that it learned on August 7 that data was taken from Ceva's systems, and alerted customers who recently bought its Steam hardware that they had personal information taken in the incident. Valve said in its note to customers, posted to Reddit, that Ceva stores their shipping and delivery information for 90 days following their order. So far, Ceva says the agency has received data breach reports from 10 organizations in relation to the incident.

Read more of this story at Slashdot.

  •  

How Accurate Are Flock's AI-Powered License-Reading Cameras?

Futurism reports: 404 Media revealed that a July 10 audit by the Los Angeles Police Department Office of the Inspector General caught the department's ALPR cameras generating 161 false stolen-vehicle alerts in just two months — each one ending with officers pulling over an innocent driver. Factoring in 337 alerts which "resulted in the recovery of stolen vehicles," the LAPD's cameras carry an error rate of 32.3 percent, effectively giving officers a one-in-three chance at pulling an innocent person over. "The biggest issue remains this national database at the FBI called NCIC," Flock's CEO Garrett Langley recently told The Drive, complaining about "how archaic its structure is." Flock CEO: There's no feedback loop mechanisms; it's really just a static comma-separated file. We've tried to build around it. We have this concept called "suppression." A local agency — let's take Atlanta, where I live — might see that there's a stolen plate out of California, but it's already been resolved because it's a rental car or a dealer car. They can, in Flock, suppress that: "Never alert us on that for the next year." That's to get around the fact that they can't force another agency to remove it from NCIC. Ideally, the way it would work is if enough agencies — let's call it one, two, or three — flag a tag as no longer valid or a bad entry, it should just get removed. Or at least it should get pushed more aggressively by the FBI... I'm hopeful that they'll see there's an opportunity to make something like NCIC, which is an important tool not just for companies like Flock, but for police departments to work together, start to make some enhancements to modernize what's a central part of our policing system. Later in the interview he says "It's less than one in a million alerts that an officer says, 'I'm not sure if that's right.' Less than one in a million." A recent report from Business Insider shares a worst-case scenario. In the summer of 2024 a Sacramento police officer said Flock's cameras had sent six false alerts for the same vehicle, wrongly saying it had been stolen or used in a felony crime in the nearby suburb of Roseville: Roseville police could see that Flock's software kept confusing the "9" on the man's license plate for an "8." The car owner said he would take off his license plate cover. Soon after, it happened again. It's "easier at this point we have it memorized," a dispatch supervisor in Roseville wrote in an email to a colleague. Flock says that in optimal conditions, its cameras accurately read more than 96% of license plate characters. Hundreds of pages of records from the Roseville Police Department show a different picture. In 2023 and 2024, Flock sent 1,427 alerts to Roseville police, flagging vehicles as stolen or used in a felony after they passed one of the city's Flock cameras. An analysis by the police department found that in 71% of those alerts, Flock's machine-learning software incorrectly read the license plates... The cameras regularly missed vehicles, captured blurry images, misread license plate characters and states, and sent delayed alerts to police about vehicles possibly connected to crimes, the records show... A factor that contributed to the misread problems in Roseville was the "particularly unique deployment" that the city requested, a Flock spokeswoman said. Roseville said it has its cameras configured so that they capture only the backs of vehicles, a setup intended to avoid capturing personally identifiable information like faces. Roseville's setup included older hardware and placement of cameras higher and further from vehicles than the company typically recommends, Flock added... In Toledo, Ohio, driver Brandon Upchurch was mauled by a police dog after a Flock camera misread the "7" on his license plate as a "2." As a result of his injuries, he said, he lost his job and was evicted from his home. He settled a lawsuit against the city and police officer for $35,000. None of the incorrect Flock alerts in Roseville resulted in a traffic stop or arrest, a department spokesman said. Roseville requires police officers to verify that a license plate is stolen or have independent reasonable suspicion of a crime before making a traffic stop... Flock said Roseville's camera performance has significantly improved, which the police department disputed... Flock's cameras also missed vehicles altogether... At one point, Flock's product director for machine learning suggested that officers ask drivers to remove license plate frames that made it "very difficult for the machine vision to tell it is actually a 'E' and not an 'F.'" Roseville told Flock at the time that it wouldn't do so, according to the department spokesman. Flock in 2024 shared an analysis with Roseville's police department, outlining reasons for the misreads. Vehicles far from a camera were sometimes blurry. Plates were cut off by trees or license plate frames. And Flock's software confused similar characters, mistaking an "N" for a "V", or a "1" for a "4...." Roseville isn't the first organization to flag inaccuracies in Flock's technology. In 2021, the research firm IPVM independently tested Flock's license plate readers, concluding that Flock misidentified the state in about one of 10 reads, and that the system regularly misclassified vehicles' type and make. IPVM said that Flock subsequently blocked it from purchasing its cameras for testing. Thanks to long-time Slashdot reader Cognitive Dissident for sharing the article.

Read more of this story at Slashdot.

  •  

Privacy Backlash Explodes Against Meta's Smart Glasses

With nearly 70% of the market, "Meta wants its smart glasses to be a big hit," writes the Los Angeles Times. But after some users found ways to disable the light that warns people they're being filmed, "the high-tech specs have also turned into a liability, as some are calling the gadget 'pervert glasses...'" Some people are using the glasses — which look like a pair of regular spectacles — to record people without their knowledge and publish the videos on social media. The users secretly videotape and share what happens when they try to pick up women. Now, a growing number of people are worried they could be covertly recorded at the gym or even during sex. The backlash has prompted Meta to update its glasses to address privacy concerns, and some places have banned them, adding to the angst surrounding technology that's rapidly evolving... Concern about the glasses has exploded as more videos of interactions with people who don't know they're being recorded go viral on social media. On Instagram, some videos depict people getting approached in malls and grocery stores and on college campuses and sidewalks. While the videos are portrayed as jokes, the people filmed don't appear to know they're being recorded and sometimes seem uncomfortable, telling the strangers to leave them alone or stop harassing them. The outcry has spread beyond social media, with comedian Jimmy Kimmel calling the Meta devices "pervert glasses" on national television and singer Lorde telling concertgoers that smart glasses are "not sexy..." Instagram, which is owned by Meta, has been disabling accounts and taking down some of these pickup or prank videos for violating the platform's rules against harassment and bullying... Businesses are making their own calls about smart glasses. The 5 Point Cafe in Seattle, which banned Google Glass in the past, has banned Meta glasses from its diner and dive bar. "Leave your Meta-SpyBan Display at home, they are officially Ray-Ban-ned from all of our restaurants. We serve privacy, not side-eye surveillance," a 2025 Instagram post from the business states. An Android app that warns people if they're being recorded has roughly 110,000 downloads in the last six months, according to the article. The app's creator says it's a "social problem" that "we don't value privacy, that we feel entitled to use others for our entertainment or our private gain, and technology amplifies that." The American Civil Liberties Union and more than 70 organizations even sent a letter urging Meta to promise they'd leave facial recognition features out of their smart glasses, according to the article. But a Meta spokesperson said "no final decision has been made."

Read more of this story at Slashdot.

  •  

Flock Camera Vandalism Continues Around America, While 100 Communities Reject ALPRs

Dozens of Flock cameras have been vandalized around Dallas Texas in the last six months, reports a local news station. In Utah, ABC News reports, a county sheriff's office even said Wednesday a Flock camera was even vandalized within days of its being installed. And in the Minnesota city of Winona, "Every Flock license plate reader camera operated by the Winona Police Department has been sawed off and stolen in what investigators believe was a coordinated theft," according to local media: All eight cameras were taken August 1, according to the Winona Police Department. A patrol officer first noticed the cameras had not sent any alerts in 24 hours. When officers checked the locations, they found the cameras had been cut from their poles and taken. The poles were left behind. Two additional Flock cameras on the Mississippi River Bridge, owned by Buffalo County, were also stolen in the same manner... The thefts are part of a broader national trend. Flock cameras have been vandalized and cut down in communities across the country. When someone in Florida filmed a damaged Flock camera lying in the grass in Florida, their footage attracted 980,000 views on social media, according to a local news report, with the uploader saying "Most of the people that are commenting are against Flock cameras." But that report adds it's one of at least five cameras recently damaged just in Florida: - In another incident, investigators "found the black camera and its pole lying on the ground." - Two days later, sheriff's deputies found a camera destroyed "with pieces scattered on the ground. Deputies reported the damage appeared to have been caused by a blunt object." - On July 31, "Police said two camera poles had been intentionally cut in half, causing an estimated $10,000 in damage to the system." In West Virginia 20-year-old Wesley Jackson has been arrested for allegedly vandalizing Flock cameras, with another 20-year-old (a university student) now arrested for being his accomplice, according to a local news report. Ironically, Jackson's arrest was made possible partly by information from... automated license plate readers. But the Washington Post notes there's now a flood of Facebook commenters jokingly offering to provide a fake alibi: "Couldn't have been him — we were out counting blades of grass," said one of the 29,000 commenters on a post about the arrest from the local news station WDTV. Others attested that the man, Wesley Jackson, had been helping them "replace the roof on a homeless shelter," "playing halo 2," "changing the tires" on their car or giving their "doggie a treat" at the time the cameras were destroyed. Meanwhile, the anti-surveillance group DeFlock reports 100 communities have now rejected automated license plate readers. Wednesday an Arizona county sheriff explained to his local Board of Supervisors why he will not renew his office's contract with Flock when it expires next month. Local Arizona media reports: "We have a camera system that can do facial recognition technology and can start building a data set on what our citizens are doing on a day-to-day basis," Teeple told supervisors. "That, in my training and experience, is a huge Fourth Amendment violation." Recently an Arizona man even told his city council he'd be launching AI-powered satellites to monitor "where government officials go, where they stop, who they meet with, and when they return home," reports 404 Media: It would be no different than how the city monitors its citizens using Flock cameras, he said... He said he'd already started compiling profiles on their vehicles, spouses vehicles, children's vehicles, and planned to combine that data with Bluetooth signals, advertising IDs, and commercial data sources, "so our authorized users can replay the movements of every government official and their immediate family," he said. Local businesses would be invited to join the network, to "protect" officials while they shop, eat at restaurants, and move around the city. And CNET reports "a quiet battle is happening across the US" between "towns working to adopt Flock Safety systems and those trying to ban them entirely." From major cities like Los Angeles canceling its Flock contract to towns wrapping Flock AI cams in plastic bags because Flock won't take them down, it's a wild time for surveillance and questions about government accountability.

Read more of this story at Slashdot.

  •  

Woman Pulled From Car at Gunpoint By Police After Mistaken Flock Alert - Twice

The police surrounded her car Thursday, "drew their guns, and told her to come out with her hands up," reports a local news station. The police thought they were pulling over a murder suspect, but "It turns out it was a mistake by another department with the Flock license plate reader technology." The black woman says she'd wanted to call her mother, "but I'm like, if I make a sudden move, it's going to be over. It's going to end my life." And amazingly, the same thing happened Monday, according to the local news report. "Milwaukee police pulled her over with guns drawn. She says officers never explained why, towed her car, and let her go." She now describes herself as "traumatized," recalling her second detention by police on Thursday. "After they put us in cuffs, they walked us to the car. I'm not knowing what's going on. I'm scared. All you see is people in their cars recording." She now says she's scared to drive her car, and so is her daughter. "Because she doesn't know if the police are going to pull us over and do it again..." "I haven't been to sleep since this happened. Every time I close my eyes, all I can see is guns." She wants an apology, since the local police would only say it wasn't their fault, it was the fault of the Milwaukee police department that failed to remove the alert from Flock's system. "Milwaukee police emphasized this was not a Flock camera issue, it was a data entry mistake," according to the local news report. The woman's response? "Y'all failed. Y'all failed the system. Y'all failed me. Y'all failed everybody."

Read more of this story at Slashdot.

  •  

Framework Notifies 'All Customers' of a Data Breach Via Compromised Metabase BI Service

"Framework has been sending out email notifications to customers alerting of a limited data breach in which customer information was accessed through a Metabase BI service zero-day exploit," writes Slashdot reader DuoDreamer. Data includes customer names, email addresses, phone numbers, and physical addresses. "Framework is investigating whether or not this included Framework for Business customers as well." TechCrunch reports: Framework's spokesperson Eric Schumacher told TechCrunch that the breach affected "all customers," but declined to specify a specific number. Framework computers are relatively niche products, but some estimates say the company sold hundreds of thousands of devices. Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers' databases stored on Metabase's cloud servers. In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework's cloud instance. The computer maker said it investigated the incident and found that hackers had stolen its customers' personal data, but did not include their payment information.

Read more of this story at Slashdot.

  •  

'Tower Dump' Warrants Ruled Unconstitutional

alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations. A "tower dump" involves cellphone companies providing law enforcement with access to the time and location data of all mobile devices connected to specific cell towers during a designated time window. Law enforcement had sought approval for several of these search warrants as part of criminal investigations into gang-related activity in the Jackson, Miss., area last year, arguing the data could help identify all those potentially involved, particularly in incidents with unknown suspects. A magistrate judge denied the applications, holding that "tower dumps" are impermissible general warrants. The district judge agreed. The order repeatedly referenced the Supreme Court's recent decision in Chatrie v United States, in which the majority held that geofence warrants require constitutional privacy protections. "With this information, the Government asserts that it will be able to identify all potential suspects," Judge Carlton Reeves wrote in a 30-page order (PDF). "Even so, law enforcement would also have access to the cellular records of countless individuals, the vast majority of whom were merely passing by a location at the 'wrong' time." "That is an unreasonable search under the Fourth Amendment," the judge concluded.

Read more of this story at Slashdot.

  •  

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay. [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal. "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Read more of this story at Slashdot.

  •  

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals. A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector. [...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Read more of this story at Slashdot.

  •  

Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool

A woman found her police officer ex-boyfriend had used Flock's camera system 600 times to look up the location of her and her daughter, reports the Washington Post (Alternate URL here). (She found out through Have I Been Flocked, described as "a website that aggregates police search logs made available through public records.") But it turns out dozens more police officers have also misused Flock... Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found. In 26 of these cases, police investigators and prosecutors said the officers used the technology to spy on their wives, their girlfriends, their exes, their exes' new partners or women they wanted to meet. In other cases, police or prosecutors have not specified the alleged surveillance targets. Flock's system was used in 46 of the cases analyzed by The Post, while the other cases involved competing products... After The Post relayed its findings to Flock, the company said in a statement it "will soon be announcing better filters and tools to stop abuse before it happens...." In April, the company rolled out a new voluntary "audit assistance" feature, which agencies can choose to enable, that automatically scans officers' searches for suspicious activity, such as queries repeatedly targeting the same vehicle or run by officers off the clock. In an interview with The Post, Flock chief executive Garrett Langley said misuse of its systems is inevitable and that the company is focused on providing tools to catch perpetrators after the fact... "We're not going to change humans, and humans make bad decisions," Langley said. "What we can do is make sure that they know if you use this tool, you will be held accountable...." Through automated license-plate reader systems, or ALPRs, officers could trace the rhythms and travels of their subjects' daily lives, leading in some instances to violent confrontations, moments of psychological manipulation, and threats of coercion and control, the analysis found. - In Wisconsin, a police officer allegedly used Flock to check whether his ex-girlfriend had gone to an abortion clinic, according to a police affidavit for a case set for trial this month. - In Kansas, a police chief who tracked his ex through Flock sneaked up on her while she was intimate with another man, a state police certification body alleged, leading to his firing. - In Florida, a deputy speeding to stop a young actress he'd added to a watch list for a license-plate tool called Guardian nearly caused a head-on crash, according to a police report and video from his dashboard camera. The deputy was arrested in March, and his attorney declined to comment. - And in California, prosecutors said a former deputy, Alexander Vanny, used Flock as part of a months-long campaign of "stalking" and "humiliating" his former fiancée that also involved following her around town and installing a hidden camera in her roommate's bathroom, according to a sentencing brief... While some of the searches resulted in officers' firings, prosecutions and prison sentences, police departments in other cases allowed officers to continue using the systems even after receiving warnings that they were being misused... An array of privacy advocates has argued that Flock could deter bad actors by making simple changes to its product, such as requiring officers to label every search with a criminal case number. Some policing experts also warned that agencies' inconsistencies in developing and enforcing standard procedures for license-plate readers could lead to further misconduct. With no federal laws governing use and only a patchwork of state laws, many of the country's roughly 18,000 police agencies are left to decide their rules on their own... Langley, Flock's chief, has dismissed pushes by activists for the company to further limit how officers use its product. "No one elected me the police chief of America," he told Forbes last year, adding, "I don't think it's our job to police the police." The Post also got this quote from an officer was fired and sentenced to probation after pleading no contest to charges of computer-system misuse, stalking and battery. "Pretty much everybody uses that computer system" improperly in the department, he said, and "they don't audit it [nearly] as much as they should." Flock told The Post it now has over 120,000 cameras in more than 6,000 communities, recording 20 billion license plate scans every month.

Read more of this story at Slashdot.

  •  
❌