Privacy

Flock is Secretly Building a Powerful New Prompt-Based AI Tool for Police (wired.com) 57

Slashdot reader fjo3 shared this article from Wired: [Flock] has told the public for years that its technology "cannot recognize, identify, or track individuals." It has now built a system that does both, an artificial intelligence tool for police that can identify drivers and track vehicles by their patterns of movement alone, WIRED has learned... Because the system also reaches police case files, 911 dispatch logs, and commercial identity records, those plates can be turned into names, home addresses, and relatives. It can search for people in an area drawn on a map based on nothing more than a physical description...

The code describes 45 tools at the AI's disposal, giving it access to plate scans and camera metadata, arrest records, case files, dispatch logs, ballistics results, and commercial databases that contain Social Security numbers, dates of birth, phone numbers, email addresses, relatives and associates. Flock says it is testing the product with a small group of law enforcement partners and describes it as still in development, with capabilities that may not reflect what it eventually sells. It arrives as the company faces bipartisan political pressure, a growing record of officers caught misusing its platform, and a wave of vandalism that has left cameras sawed off and lenses painted over in cities across the country...

An officer no longer needs a plate, a name, or a crime to begin: They supply a place, a stretch of time, and a pattern of behavior, and the system is designed to hand back the people who fit... One prompt Flock preloaded into the system reads: "Find me witnesses based on vehicles most seen in [neighborhood] during [last 14 days] during [daily timeframe] *(will not include whitelisted vehicles)." An officer would fill in the blanks and submit it. The output is a list of plates, which other tools in the product then convert into names and home addresses. Another prompt instructs the system to list everyone arrested more than twice in two years for "any offense," exempting only narcotics arrests, and then says to map where those people live, retrieve the calls for service at their homes, and "do a workup on the top three individuals." The prompt begins with everyone in the area who has an arrest record and ends with dossiers on three of them, chosen by the software. A "workup," in Flock's terminology, is a one-command background check. It starts with a name and a date of birth and returns what the department's records and commercial data hold: vehicles, prior listings as a suspect, and, on a second screen, relatives, phone numbers, and online accounts.

Wired shares this reaction from a law professor at George Washington University.

"It is clear Flock has aspirations far beyond ALPRs to become a digital platform for policing,"
Social Networks

Watching TikTok Videos and Instagram Reels Deactivates the Brain's Cognitive Control Network (rathbiotaclan.com) 41

An anonymous reader quotes a report from RathBiotaClan: Millions of people finish short video after short video every day; a new brain-scan study shows that the very act of finishing a clip they like temporarily quiets the brain regions that normally help them stay focused and weigh longer-term goals. When people watch a short video they enjoy enough to finish, two brain regions involved in cognitive control show significant deactivation. That is the central finding of a new study from Zhejiang University, published in NeuroImagein January 2026.

Using functional MRI alongside proton magnetic resonance spectroscopy (H-MRS), the research team examined 56 young adults while they freely watched short video clips inside an MRI scanner. Both the dorsal anterior cingulate cortex (dACC) and the dorsolateral prefrontal cortex (dlPFC) showed reduced activity specifically when participants watched clips they liked enough to view to completion. Cognitive control helps people balance immediate pleasures against longer-term goals, and impairments in this system are linked to conditions such as depression, anxiety, ADHD, and addiction. Short-video platforms present rapid, algorithmically curated streams that are built for continuous, low-effort consumption.

Prior behavioral research has tied both internet addiction and smartphone addiction to weaker self-control, and separate neuroimaging work has documented disruptions to reward and cognitive-control circuits in people with behavioral addictions. Despite this, few studies had directly tested whether the act of watching entertaining short videos itself suppresses the brain's cognitive control regions. The Zhejiang University team set out to answer that question, along with a second one: what neurochemical factors might explain why this suppression varies from person to person?

Security

CISA: Medusa Ransomware Hit Over 500 Critical Infrastructure Orgs (bleepingcomputer.com) 6

CISA says the Medusa ransomware operation has breached more than 500 U.S. critical infrastructure organizations since 2021, up from more than 300 reported last year. The group has targeted healthcare, government, defense, manufacturing, IT and financial organizations, evolving into a ransomware-as-a-service operation that recruits initial-access brokers and uses stolen data to pressure victims into paying. BleepingComputer reports: The three federal agencies recommended that network defenders secure their networks against the ransomware group's attacks by mitigating security vulnerabilities to protect operating systems, software, and firmware from exploitation attempts. Security teams are also advised to segment networks to block lateral movement after compromise and to block access from untrusted origins to remote services on internal systems.

[...] "Medusa developers typically recruit initial access brokers (IABs) in cybercriminal forums and marketplaces to obtain initial access to potential victims," the advisory says. "Potential payments between $100 USD and $1 million USD are offered to these affiliates with the opportunity to work exclusively for Medusa."

Music

Top Album Releases Linked To Rise In Fatal Crashes (theguardian.com) 86

An anonymous reader quotes a report from The Guardian: The release of a new album by Taylor Swift might be a cause for celebration among her fans, but such events have also been linked to a more sombre phenomenon: an increase in fatal car crashes. The team behind a new study say it sheds light on the impact of distracted driving. Writing in the journal Jama Network Open, [Vishal Patel, first author of the study based at Harvard Medical School] and colleagues report how they focused on the release of 10 major albums, launched between 2017 and 2022, selected for having the highest number of Spotify streams over a single day. [...] The team found streaming volume for the top 200 songs in the US was 43% higher on the date of major album releases compared with the days surrounding the releases -- although such data does not reveal whether the music was being streamed in a car.

[...] The researchers used data from a population-based registry of fatal US motor vehicle crashes to look at the number of traffic fatalities on the dates these albums were released, as well as for the 10 days either side. After taking into account the day of the week upon which the album was released, as well as federal holidays, and time of year, the researchers found the number of US traffic fatalities showed a relative increase of 15.1% on the date of major album releases, compared with similar days either side. "This is equivalent to approximately 182 fatalities in the US attributable to the release days of the 10 included albums," the team writes.

Patel said the release of a new album could distract drivers because accessing music is a search task, not a single button press. "You unlock the phone, open the app, find the release, read down a tracklist, tap the right song. That's several seconds of looking at a screen," he said, adding unfamiliar music also demands more attention, while research has suggested listening to new, high-energy music measurably degrades driving performance. The researchers add the rise in traffic fatalities was greater among certain groups -- such as younger drivers, male drivers, people who were driving alone, and people driving cars with a built-in infotainment platform. The authors say the results suggest that "online music streaming through smartphones may significantly contribute to distracted driving and traffic fatalities."

The Courts

Disney, ABC Sue FCC Over Threats to Broadcast Licenses (reuters.com) 137

Disney and ABC are suing the FCC to block an early review of eight station licenses, arguing the Trump administration is using the agency's regulatory power to punish the network over programming and editorial decisions it dislikes. Reuters reports: In a lawsuit (PDF) filed in U.S. District Court in Washington, Disney said the FCC was seeking to coerce and retaliate against "a network that refuses to bow to the administration's demands," calling the agency's actions an "extraordinary assault on free speech."

Trump has waged an aggressive series of attacks on the news media and the latest move follows a two-year-long battle between Trump and Disney. Last month, Trump again called for ABC stations to lose their licenses because the network refused to air a prime-time speech on elections. The court case will pose a key test of the free speech rights of media outlets. Disney and ABC asked the court (PDF) to quickly issue a temporary restraining order halting the license renewal proceedings and preventing the FCC from scheduling a hearing. The company said the public comment period ended earlier this month and the FCC could act at any time.

The lawsuit alleges that the administration is violating the company's First Amendment free speech rights, saying that the FCC "is using its regulatory power to retaliate against (Disney and ABC) for programming and editorial decisions the administration dislikes." The FCC said the move stemmed from a year-long investigation into whether Disney's diversity policies amounted to unlawful discrimination, an allegation the company denies. U.S. District Judge Loren AliKhan issued an order on Tuesday directing the company and the FCC to propose a schedule for considering the request for a temporary restraining order and told the agency to notify her if it moves to start the process of revoking the ABC licenses.

The Almighty Buck

India Paves the Way For Charging Merchants a Fee On UPI Transactions (bbc.com) 21

An anonymous reader quotes a report from the BBC: For most Indians, paying by Unified Payments Interface (UPI) has become almost absurdly routine. Scan a QR code, tap a few buttons and the money moves instantly. There is no card machine, no cash, and -- most importantly -- for the user, no visible fee. That may be about to change. India has paved the way for banks and payment companies to charge merchants a fee on UPI transactions, potentially ending a decade-long experiment in free digital payments.

The government has yet to decide the rate or exactly where it will apply, but proposals under discussion include a merchant discount rate (MDR) of 0.3-0.5% -- a small fee paid by a business to the banks and payment companies that process its UPI payments -- on larger transactions at big businesses. The government says consumers and person-to-person UPI payments will remain free. If merchant fees are introduced, they will apply only to some transactions above a set threshold, at a nominal rate, meaning most UPI payments will remain free. The question is whether putting a price on UPI could weaken the network that made it such a success.

The stakes are enormous. Launched in 2016, UPI has grown into one of the world's biggest real-time payment networks. According to official data, in July alone, there were 23.6 billion UPI transactions worth 29.87 trillion rupees ($313.5 billion). Fintech apps such as PhonePe and Google Pay account for most UPI payments. In the financial year just ended, the figure was about 241.6 billion transactions -- almost 12,000 times the volume in UPI's first full year. More than 550 million people now use it, and the system is now available in some form for payments in 11 countries outside India.
India's UPI became ubiquitous partly because it made digital payments almost frictionless for merchants, including small vendors who can accept payments with little more than a QR code. New research suggests that merchant acceptance was "not just a result of UPI growth, but one of its key drivers."

As RBI governor Sanjay Malhotra put it, "Someone will have to pay the cost." The challenge will be making UPI sustainable without weakening the merchant network that helped it take off.
Privacy

Bipartisan 'Uprising' Against Flock Cameras: a Larger Fight Against Big Tech and Surveillance? (salon.com) 36

Politico notes that over 20 local jurisdictions in America "either stopped using Flock cameras or began the process of doing so in July, according to a tracker maintained by DeFlock, an activist group that has been mapping the company. It's the highest amount in a single month since they began tracking in 2021." Some local officials said the public safety promises weren't worth the cost. The cameras "didn't help us with anything. From a utility aspect, they were just kind of not useful," said Eric Couture, a Democratic first selectman in Killingworth, Connecticut, another city that recently canceled its contract with Flock. "I'd say it was a net negative."
And their article adds that it's a bipartisan pushback that "runs parallel to sprawling fights over the future of technology in American life, including the rise of increasingly advanced artificial intelligence tools and the construction of massive data centers needed to power them."

Salon even argues Flock's cameras "have become a symbol of growing anger over the efforts by technology oligarchs to impose their dystopian fantasies on the country, replacing liberal democracy with a surveillance state... People are sick of tech billionaires trying to control our lives"" By targeting Flock cameras, activists are building momentum for a larger rebellion against the tech industry — and against political leaders who are complicit in their assault on our freedoms. Flock Safety embodies the dishonesty that has been the prevailing theme of tech corporate communications and marketing for at least the past decade. While the cameras are sold to the public as a banal traffic safety measure, they have prompted an outpouring of stories about how they're being used to violate civil liberties and undermine democracy...

According to an exhaustive 10-month analysis by Electronic Foundation Frontier, a nonprofit dedicated to defending civil liberties in our digital age, local police were using the cameras to track protesters, such as those at No Kings rallies, who were then put in a national database to be used across all jurisdictions. Despite claims that the cameras only record license plates, the technology-focused outlet 404 Media found that the database is also being used to collect information on individual people whom cops can then search for using descriptions of clothing, race, gender and body type.

The Flock uprising, though, is the stirrings of public understanding that none of this inevitable — and we have the right to fight back... Along with protests against data centers, it's a sign that the public is desperate for a way to fight back against not just AI, but also the anti-democratic forces fueling this latest tech wave.

Salon's writer also adds that "what stands out about the burgeoning public rebellion against Flock security cameras is just how fun it all is," citing "a national cat-and-mouse game between vandals and cops that is being merrily followed on social media, mostly by people rooting for the vandals." City council meetings in which citizens swarm to protest paying for the cameras are the new must-see TV. In Huntington, West Virginia, a small city in the heart of Appalachia, one man became an internet folk hero when he stood up at a city council meeting and said, "I'm not gonna waste your time; I'm kinda hungry. But one last thing: Every single Flock camera has about 2-3 pounds of copper and about 1-2 grams of gold. Do with that information what you will." He then walked off in triumph.
United States

Flock's 'Creepy Cameras' Remain Major Threat to Privacy Despite Small Recent Changes, Warns ACLU (aclu.org) 35

While Flock announced changes for its AI-powered traffic cameras, "Several of the proposed changes Flock is touting are merely retreads of previous ," complains the American Civil Liberties Union. "Flock's latest announcement still appears more focused on addressing a perceived PR problem than the significant harms its products create... [T]his is hardly the step forward Flock wants us to think it is "

The ACLU continues to urge that default retention periods be shortened to 48 hours — not one week. And they warn Flock allows longer retention to any police department that asks for it, or when police officers activate "Evidence Mode" (the scope of which is not yet clear): Even if "Evidence Mode's" data retention hold only applies to hits returned on a given search, it would still retain significant amounts of location data on persons and vehicles who law enforcement do not suspect have engaged in any wrongdoing...

Flock claims that its changes will provide "more local control," meaning local police can decide what types of offenses other Flock customers can search their data for... This is not new. Flock has attempted this before, and the security measure failed because users were easily able to circumvent the system's requirement that police input the purpose of their search. For example, on June 12, 2025 Flock started claiming its new "Proactive Search Term Tool" would block any "impermissible" searches, such as abortion-related searches in states like Illinois that prohibit sharing reproductive healthcare data. But police officers quickly realized they could just input "investigation" or even "hehehe" as a search reason and it would be approved. Flock later switched from an open text box to a drop-down menu of reasons, but that just offered police a list of acceptable purposes they could choose from, whether it was accurate or not. Until Flock demonstrates they can develop a reliable, workable system to prevent improper searches, this promise of local control provides nothing more than a false sense of security...

While providing "Audit Assistance" to all departments makes sense, there is no evidence that the tool works consistently to address what the Washington Post observed is a growing pattern of police officers turning Flock into a personal stalking tool. While dozens of officers have recently been arrested, fired, or otherwise disciplined for misusing Flock for personal reasons, Flock claims these arrests are proof its auditing tool works. However, unless we know the number of officers misusing the system, we cannot conclude if Flock and its auditing tools are catching 95 percent of violators or 5 percent. Flock needs to have its auditing tool analyzed by an independent evaluator to determine its actual effectiveness. Until then, we don't know if the tool is a real security measure or just window dressing.

Perhaps the oddest part of Flock's announcement is its claims that "now every search will require" police to input a case code... While claiming that a "search without a reason is a search that shouldn't happen in the first place," Flock's announcement fails to note how easily users have circumvented "search reason" security measures in the past... This leaves the public wondering how making an ineffective voluntary security measure mandatory will improve its functionality.

Flock's "nearly $1 billion in venture capitalist funding has locked it into an operational model that seeks to trade our privacy for massive profits," concludes the ACLU's statement, as they promise to continue "The ACLU is fighting alongside communities to cancel local ALPR contracts and push lawmakers to protect our rights from this surveillance nightmare..."
Twitter

X Open Sources Its Ranking and Filtering Algorithms (techcrunch.com) 57

An anonymous reader shared this report from TechCrunch: X is significantly expanding its open source codebase, which includes the app's "For You" algorithm and its core ranking engine, and adding a feature that will let users see if their account or posts have been impacted by any of its ranking systems, the social network said on Thursday. The company is making the source code for the "For You" timeline, the default feed you see when you open the app, available on GitHub under the Apache v2 license. It's also expanding its previous efforts to open source parts of its codebase to add more detail, including the model configuration, filter, and core ranking system details. That means it includes the parameters used to weight different signals — key to understanding which posts are actually displayed. This also makes the codebase roughly 10 to 15 times larger than it was before.

"You'll get the core ranking code that pulls posts and ranks them for any given user and assembles the feed," X's VP of Product Keith Coleman told TechCrunch in an interview ahead of the announcement. "You can see the systems that filter out potentially problematic, rule-violating content...And some of those systems, like the ranker and the score, you can even run yourself outside the company."

"This is the kind of thing that I think people will be fairly shocked that we are releasing," he added.

In addition to the repository, X is providing tools that will let users see for themselves if and how X's ranking systems have impacted their account or posts. A new transparency tool is rolling out to an "Under the Hood" page in the app's settings, which will let users who have posted 10 or more times over the past month download their aggregate stats as a JSON file. The file will show if any labels have been applied to their account or posts over the past calendar month.

X's VP of Product told TechCrunch that X engineers will consider pull requests. "That would be amazing to have people submitting code that improves the algorithm...I mean, how cool would it be for the X algorithm to be not just visible to the public, but also, like, by the public?"
Privacy

Flock Announces Changes Amid Backlash Over Its License Plate Reader Network 33

Flock Safety is tightening controls on its nationwide license plate reader network after mounting backlash over privacy and documented police misuse. By January 1, law enforcement customers will be required to use automated auditing, tie searches to specific case numbers, and accept a shorter seven-day default retention period. Critics, including the ACLU, argue the changes still leave too much surveillance power in police hands. The Associated Press reports: In an interview, Flock CEO Garrett Langley said many of the product changes will make what were once optional guardrails mandatory for its users to implement by Jan. 1. Among them: All law enforcement customers will have to implement an audit tool that's intended to flag abnormal search behavior. When the system detects abnormal behavior, the user would be locked out pending an internal review, the company said in a description of the changes provided ahead of Thursday's announcement.

Flock, which says its customers own the data that the cameras record, is also shortening the standard data retention window from 30 days to seven. It said it will allow data to be preserved for longer when it is evidence tied to a case number. Law enforcement users will now also be required to enter a code from their records management system tying each search to a specific case before it is run, something Langley said civil liberties advocates have long been calling for. Overrides for emergencies would be automatically flagged for review, the company said.

Customers will also be allowed to decide which offense types -- such as homicide or arson -- outside agencies can search their data for, which would allow a customer to block outside searches related to immigration enforcement, the company said. Langley said that change will give individual cities and departments control to use the system in a manner "consistent with community values."
Critics say Flock's changes don't address the core problem: police can still decide for themselves when and whom to search without judicial oversight. The ACLU called the shorter data-retention period "a step in the right direction," but dismissed the other safeguards as "retreads" of inadequate protections, while Institute for Justice attorney Robert Frommer called the reforms "window dressing" from a company in "panic mode."

He argued that searches should instead be approved "by judges with real warrants."
Data Storage

PBS Station Fears Losing 50TB of Data After Being Ghosted By Cloud Provider (arstechnica.com) 101

An anonymous reader quotes a report from Ars Technica: After its cloud storage provider went defunct, a PBS affiliate decided to sue a data center provider to regain access to 50TB of TV shows, videos, and other data dating back 70 years. As reported this week by Current, a trade newspaper covering public broadcasting, St. Louis affiliate Nine PBS filed a lawsuit against Iron Mountain Data Centers on July 28, seeking access to the data. In the litigation filed in Denver District Court, Nine PBS says that its cloud storage provider, Open Source Storage (OSS), used one of Iron Mountain's Denver data centers to store the channel's data. However, OSS is being unresponsive, and Nine PBS says Iron Mountain has refused to release its data.

The data in question includes the station's coverage of the COVID-19 pandemic, East St. Louis' history, The Great Flood of 1993, and over 11,000 files, The Denver Post reported in July. The lawsuit claims that "most" of the data is "unique and irreplaceable," according to the Post. Last month, a judge blocked Iron Mountain from deleting or modifying the data.

In a hearing on Wednesday, a judge ruled that Iron Mountain must hand over any physical devices holding the data, Current reported today. The judge also said that Nine PBS must find a third party, such as a former OSS worker, who can help retrieve the data within 30 days and without sharing or corrupting data belonging to other OSS clients. Nine PBS is already communicating with a former OSS employee "who is willing to help," the report said. If complications arise, such as from the data being encrypted, another hearing will be scheduled. Nine PBS and Iron Mountain must provide updates by September 14.
Iron Mountain's spokesperson said the company only provides physical infrastructure, such as the building, network connectivity, power, and environmental controls. "Our customers rent space for their servers and other hardware. These are the client's assets. We don't have access to the data on the hardware/servers because they belong to our customers," the company said.

If it granted "unauthorized access to third-party hardware without a court order," Iron Mountain said the company would violate basic data privacy protocols, breach its contract with OSS, and "potentially [expose] confidential data belonging to other clients of OSS."
Wireless Networking

DEF CON Crowd Suspected In Fake-Hotspot Attack On Delta Flight (arstechnica.com) 36

An anonymous reader quotes a report from Ars Technica: On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS.

According to the "ACARS Drama" account, a message was sent by pilots from the plane stated: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A description of the incident posted to Reddit further stated that these passengers created a fake hotspot ("Delta WiFi Fast"), with a phishing landing page "designed to harvest passengers' personal credentials."

This technique, sometimes known as an "evil twin" attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data.
"One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," said a Delta spokesperson. Delta further noted that the flight's safety was "never in question and no aircraft operating systems were affected," and that no emergency was declared.

Ars notes that the "actual onboard Wi-Fi was disabled for 30 minutes."
Google

The Pixel Tag Is Google's Answer To the AirTag (theverge.com) 61

Google has unveiled the $29 Pixel Tag, its long-awaited AirTag rival that combines UWB with Bluetooth 6.0 Channel Sounding for two forms of precision tracking. It launches November 11. The Verge reports: The Pixel Tag is a slim oblong device available in one grayish color -- Fog -- that weighs about 12g, or 0.4oz. Like the AirTag, it has no built-in hooks or clips for attaching to objects you want to track. There's a single button that will trigger a sound on your phone, for the rare occasion when you've got the Tag but have lost your main device. It also has an IP67 rating, so it should be safe from dust and rain. As for the battery, the Pixel Tag takes CR2032 coin batteries, and says one battery should last for over a year.

Naturally, it'll be compatible with Google's Find Hub network, which leverages the Bluetooth capabilities of Android devices worldwide to help locate lost objects. [...] Once you're close enough to the Pixel Tag, UWB lets the Find Hub app display the distance and direction to the tracker, so long as you're using a phone with a UWB chip. Channel Sounding is a newer development that can display the exact distance, but not direction, and it will work with any phone or tablet that includes Bluetooth 6.0. The Moto Tag 2 is the only other tracker to currently support it.

Crime

German Advocacy Group Lodges Criminal Complaint Over Meta AI Glasses (reuters.com) 42

A German digital-rights group has filed a criminal complaint against Meta, Ray-Ban parent EssilorLuxottica, and several retailers over Meta's AI smart glasses, arguing the devices can enable covert recording in violation of German privacy law. Prosecutors have begun a preliminary review, while Germany's network regulator says smart glasses are legal "as long as the recording function is clearly visible." Reuters reports: "There's no place to escape from smart glasses. You have to expect at any moment to be filmed and then exposed on the internet," said HateAid managing director Josephine Ballon. The organization reported the management of Meta, units of spectacles maker EssilorLuxottica including Ray-Ban, as well as retailers Fielmann, Apollo-Optik, Mister Spex and MediaMarkt to the Frankfurt-based digital crime prosecution unit ZIT. HateAid said its complaint was based on a federal digital data protection law that prohibits the sale of communication devices designed to film people without them noticing.

ZIT confirmed it received a complaint from HateAid invoking that law, saying it would routinely investigate on a preliminary basis whether there are grounds for a deeper probe. MediaMarktSaturn Retail Group said it was taking the complaint very seriously, adding that its suppliers had contractual obligations for all goods to be compliant with the law. Mister Spex said it had not been officially notified of a complaint and that it was taking protection of privacy very seriously.

The Internet

Freenet Creator Ian Clarke Shares Progress on Its New Decentralized Network 66

Ian Clarke (aka ancient Slashdot reader Sanity), designer of the peer-to-peer communication platform Freenet, is back with an update on the project's progress following the launch of its P2P network in March. He writes: Earlier this year, Slashdot covered the launch of the completely redesigned Freenet. I recently gave a talk about what we've been building since then. Unlike traditional web applications, apps on Freenet have no central server or database; instead application state is distributed across the network. These now include decentralized group chat, publishing, search, and fully decentralized Git hosting. The talk also gets into some of Freenet's internals, including how we use machine learning for network routing.
Government

California City Declares State of Emergency After Cyberattack (nbcbayarea.com) 22

NBC Bay Area brings news from the small idyllic California town of Suisun City (population: 29,518). The city council "declared a state of emergency Saturday after a cyberattack that shut down computer systems including 911 public safety operations." "Malicious software infected and compromised" the East Bay community's information technology systems beginning about 5:45 a.m. Friday, the city said on social media. "The cybersecurity incident hit critical public safety operations, including 911 routing, police and fire dispatch, records and city services," the city said.

"There is no imminent threat to the public," the city said. "All public safety services remain active." The city shut down its computer network "to contain the threat and preserve evidence for a federal investigation," it said... Suisun City dispatchers were taking calls for service through the Solano County dispatch center. Suisun City police officers and firefighters continued responding to calls for service, the city said, but online city services and internal operations were unavailable.

On Facebook the city said it was "working alongside federal, state and regional agencies, including the FBI, Department of Homeland Security and California Office of Emergency Services to maintain emergency services, investigate the incident and restore systems."

But Bay Area PBS station KQED notes "They're only the latest local government in the region to be hit by a cyberattack." Earlier this year, Foster City and Pittsburg experienced other cyberattacks that impacted services in their own jurisdictions. Foster City declared a state of emergency after a March ransomware incident that shut down many services for more than a week. Pittsburg lost almost $1 million to a February phishing attack, though over half of it was recovered.
AI

OpenAI Announces It's Enhancing Security Controls, Pausing Some Work for New AI Model Astra (theguardian.com) 20

OpenAI announced Friday it's pausing work on its Astra AI model because of security concerns. The Guardian reports: The company had evaluated the agent, Astra, and found "significant advancements in agentic coding and cybersecurity", which had moved to a "critical" threshold... OpenAI stated that the model was not involved in an incident in which one of its AI agents went rogue during a test, accessed the open web and hacked a startup, Hugging Face... The reports have increased concerns about advancements in AI models and humans' ability to control them.

Still, critics of the AI industry have warned that such disclosures from OpenAI and its competitors Anthropic and Meta could be designed to generate hype about the technology's power and thus spur additional interest from investors.

To prevent potential rogue behavior from AI agents, OpenAI is "implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access", the company's blogpost stated. It will also install "enhanced model weight protections and encryption, additional monitoring and detection capabilities". The company will pause internal activities involving Astra that do not meet these new requirements.

"We believe it's important to be transparent with the public and the safety and security communities about this potential shift in capabilities..." OpenAI wrote in a blog post titled "Responding to the next frontier of critical cyber capabilities." Under our Preparedness Framework, a model reaches the Critical cybersecurity threshold if it can identify and develop functional zero-day exploits of all severity levels in many hardened real-world critical systems without human intervention, or can devise and execute end-to-end novel strategies for cyberattacks against hardened targets given only a high level desired goal. While we continue to benchmark and assess this model, our preliminary evaluations indicate strong enough performance that we cannot rule out Critical capability level at this time... Accordingly, we have scaled up robustness testing of our safeguards and security controls so that they are appropriate for a deployment of these capabilities...

- We are implementing stricter security controls for higher-capability models and associated activities, including isolated testing environments, restricted network and tool access, enhanced model weight protections and encryption, additional monitoring and detection capabilities, and sandboxed execution.

- We are pausing internal activities involving Astra that do not yet meet these strengthened security control requirements.

- We have implemented universal monitoring for risky actions and misalignment across all agentic applications of Astra, including training and evaluation. Monitors evaluate the model's Chain of Thought and trigger a security response to review and interrupt high risk activity.

- We will work with relevant government agencies and select AI safety organizations to test the capabilities for this model...

We believe advanced cyber-capable models should help defenders identify and address vulnerabilities before attackers do. We're committed to working alongside governments, safety institutes, and civil society to ensure that the frontier capabilities of models like Astra, and those that follow, are deployed responsibly and broadly for the benefit of all humanity.

Privacy

Flock Camera Vandalism Continues Around America, While 100 Communities Reject ALPRs (clickorlando.com) 132

Dozens of Flock cameras have been vandalized around Dallas Texas in the last six months, reports a local news station. In Utah, ABC News reports, a county sheriff's office even said Wednesday a Flock camera was even vandalized within days of its being installed. And in the Minnesota city of Winona, "Every Flock license plate reader camera operated by the Winona Police Department has been sawed off and stolen in what investigators believe was a coordinated theft," according to local media: All eight cameras were taken August 1, according to the Winona Police Department. A patrol officer first noticed the cameras had not sent any alerts in 24 hours. When officers checked the locations, they found the cameras had been cut from their poles and taken. The poles were left behind. Two additional Flock cameras on the Mississippi River Bridge, owned by Buffalo County, were also stolen in the same manner...

The thefts are part of a broader national trend. Flock cameras have been vandalized and cut down in communities across the country.

When someone in Florida filmed a damaged Flock camera lying in the grass in Florida, their footage attracted 980,000 views on social media, according to a local news report, with the uploader saying "Most of the people that are commenting are against Flock cameras." But that report adds it's one of at least five cameras recently damaged just in Florida:

- In another incident, investigators "found the black camera and its pole lying on the ground."

- Two days later, sheriff's deputies found a camera destroyed "with pieces scattered on the ground. Deputies reported the damage appeared to have been caused by a blunt object."

- On July 31, "Police said two camera poles had been intentionally cut in half, causing an estimated $10,000 in damage to the system."

In West Virginia 20-year-old Wesley Jackson has been arrested for allegedly vandalizing Flock cameras, with another 20-year-old (a university student) now arrested for being his accomplice, according to a local news report. Ironically, Jackson's arrest was made possible partly by information from... automated license plate readers.

But the Washington Post notes there's now a flood of Facebook commenters jokingly offering to provide a fake alibi: "Couldn't have been him — we were out counting blades of grass," said one of the 29,000 commenters on a post about the arrest from the local news station WDTV. Others attested that the man, Wesley Jackson, had been helping them "replace the roof on a homeless shelter," "playing halo 2," "changing the tires" on their car or giving their "doggie a treat" at the time the cameras were destroyed.
Meanwhile, the anti-surveillance group DeFlock reports 100 communities have now rejected automated license plate readers. Wednesday an Arizona county sheriff explained to his local Board of Supervisors why he will not renew his office's contract with Flock when it expires next month. Local Arizona media reports: "We have a camera system that can do facial recognition technology and can start building a data set on what our citizens are doing on a day-to-day basis," Teeple told supervisors. "That, in my training and experience, is a huge Fourth Amendment violation."
Recently an Arizona man even told his city council he'd be launching AI-powered satellites to monitor "where government officials go, where they stop, who they meet with, and when they return home," reports 404 Media: It would be no different than how the city monitors its citizens using Flock cameras, he said... He said he'd already started compiling profiles on their vehicles, spouses vehicles, children's vehicles, and planned to combine that data with Bluetooth signals, advertising IDs, and commercial data sources, "so our authorized users can replay the movements of every government official and their immediate family," he said. Local businesses would be invited to join the network, to "protect" officials while they shop, eat at restaurants, and move around the city.
And CNET reports "a quiet battle is happening across the US" between "towns working to adopt Flock Safety systems and those trying to ban them entirely." From major cities like Los Angeles canceling its Flock contract to towns wrapping Flock AI cams in plastic bags because Flock won't take them down, it's a wild time for surveillance and questions about government accountability.
Privacy

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses 46

Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay.

[...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal.

"Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.
Privacy

Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool (yahoo.com) 100

A woman found her police officer ex-boyfriend had used Flock's camera system 600 times to look up the location of her and her daughter, reports the Washington Post (Alternate URL here). (She found out through Have I Been Flocked, described as "a website that aggregates police search logs made available through public records.")

But it turns out dozens more police officers have also misused Flock... Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found. In 26 of these cases, police investigators and prosecutors said the officers used the technology to spy on their wives, their girlfriends, their exes, their exes' new partners or women they wanted to meet. In other cases, police or prosecutors have not specified the alleged surveillance targets. Flock's system was used in 46 of the cases analyzed by The Post, while the other cases involved competing products...

After The Post relayed its findings to Flock, the company said in a statement it "will soon be announcing better filters and tools to stop abuse before it happens...." In April, the company rolled out a new voluntary "audit assistance" feature, which agencies can choose to enable, that automatically scans officers' searches for suspicious activity, such as queries repeatedly targeting the same vehicle or run by officers off the clock. In an interview with The Post, Flock chief executive Garrett Langley said misuse of its systems is inevitable and that the company is focused on providing tools to catch perpetrators after the fact... "We're not going to change humans, and humans make bad decisions," Langley said. "What we can do is make sure that they know if you use this tool, you will be held accountable...."

Through automated license-plate reader systems, or ALPRs, officers could trace the rhythms and travels of their subjects' daily lives, leading in some instances to violent confrontations, moments of psychological manipulation, and threats of coercion and control, the analysis found.

- In Wisconsin, a police officer allegedly used Flock to check whether his ex-girlfriend had gone to an abortion clinic, according to a police affidavit for a case set for trial this month.

- In Kansas, a police chief who tracked his ex through Flock sneaked up on her while she was intimate with another man, a state police certification body alleged, leading to his firing.

- In Florida, a deputy speeding to stop a young actress he'd added to a watch list for a license-plate tool called Guardian nearly caused a head-on crash, according to a police report and video from his dashboard camera. The deputy was arrested in March, and his attorney declined to comment.

- And in California, prosecutors said a former deputy, Alexander Vanny, used Flock as part of a months-long campaign of "stalking" and "humiliating" his former fiancée that also involved following her around town and installing a hidden camera in her roommate's bathroom, according to a sentencing brief...

While some of the searches resulted in officers' firings, prosecutions and prison sentences, police departments in other cases allowed officers to continue using the systems even after receiving warnings that they were being misused... An array of privacy advocates has argued that Flock could deter bad actors by making simple changes to its product, such as requiring officers to label every search with a criminal case number. Some policing experts also warned that agencies' inconsistencies in developing and enforcing standard procedures for license-plate readers could lead to further misconduct. With no federal laws governing use and only a patchwork of state laws, many of the country's roughly 18,000 police agencies are left to decide their rules on their own...

Langley, Flock's chief, has dismissed pushes by activists for the company to further limit how officers use its product. "No one elected me the police chief of America," he told Forbes last year, adding, "I don't think it's our job to police the police."

The Post also got this quote from an officer was fired and sentenced to probation after pleading no contest to charges of computer-system misuse, stalking and battery. "Pretty much everybody uses that computer system" improperly in the department, he said, and "they don't audit it [nearly] as much as they should."

Flock told The Post it now has over 120,000 cameras in more than 6,000 communities, recording 20 billion license plate scans every month.

Slashdot Top Deals