Reading up on privacy
100 deep · digging since dec 08, 25
- Celebrities Are Raving About Full-Body Scans. Doctors Urge Caution
Full-body scans marketed for health monitoring are discouraged by doctors, who warn they offer little benefit to healthy individuals and may cause harm.
- Self-hosting mail without opening a single port - dilluti0n.com
The author shows how to run a home mail server with no open ports by routing mail via Cloudflare, a Rust http2lmtp proxy, Dovecot, OpenSMTPD, and smtp2go.
- Exa is now powering search in Firefox
Exa now powers AI‑driven Smart Window in Firefox desktop and Quick Answers on iOS, providing live‑web sourced answers with citations while retaining no Firefox query data.
- weather.baby – Harrison Was Here
Harrison created weather.baby, a minimalist ad‑free weather site using Go and Pirate Weather data to provide fast, private forecasts for users.
- Bradley Cadenhead: The Boy Who Became 764
The article details how bullied Texas teen Bradley Cadenhead created the extremist Discord network 764, coercing minors into self‑harm and CSAM, leading to an 80‑year sentence.
- Browser Fingerprinting & Bot Detection Test
The article introduces an online scanner that measures browser fingerprinting, WebRTC leaks, bot risk scores, and related device attributes to help users assess tracking exposure.
- OpenAI Introduces ‘ChatGPT for Teens’ as Safety Concerns Grow
OpenAI has launched a teen‑focused ChatGPT mode that automatically restricts certain conversations to enhance safety for younger users and address parental concerns.
- Kithly: Family-Safe Social Media — No Ads, No Tracking
Kithly launches a family‑focused social network that eliminates ads, tracking, and addictive feeds while giving parents full control and offering free membership.
- ChatGPT can now remember what you did on your Mac — without screenshots - The New Stack
OpenAI’s new opt-in Computer History feature for ChatGPT Work on macOS tracks app and website interactions locally—without screenshots—to help the AI recall user context and automate tasks.
- A researcher bought noreply.net. Companies started sending him secrets. - Ars Technica
A researcher purchased the noreply.net domain and received over 400,000 automated messages in 18 months, revealing widespread corporate misconfiguration where companies inadvertently send sensitive data to invalid email addresses.
- Bloomberg - Are you a robot?
Bloomberg detected unusual network activity and is prompting users to verify they are not robots via a CAPTCHA.
- ShieldFont
ShieldFont is a web font that swaps key words in HTML so humans see original text while AI scrapers receive altered, meaning‑distorted content to deter unauthorized training.
- Kill the Cookie Banner!
The EU Commission proposed a browser-level privacy signal to replace deceptive cookie banners, but the tracking industry, led by Google, is lobbying to block it.
- This page does not exist - Committees - UK Parliament
The UK Parliament’s Communications and Digital Committee seeks evidence on whether the Online Safety Act has improved online safety, examining Ofcom’s implementation and potential legislative reforms.
- Aw, It’s Baby’s First A.I. Surveillance System
Nanit and similar start‑ups aim to monitor infants with AI during sleep and eventually expand that surveillance to longer periods beyond nighttime.
- How China Keeps Tabs on Foreigners
A leaked Chinese police dashboard reveals authorities systematically gather and combine extensive personal data to monitor foreigners across multiple provinces.
- Launching Health in ChatGPT
OpenAI announced a U.S.-only feature letting ChatGPT users connect Apple Health and medical records for personalized health insights while promising privacy safeguards.
- URL Source: https://www.reddit.com/r/micro_saas/s/Ji8Fx27j2d
The user attempted to access a Reddit post in the r/micro_saas subreddit via the given URL but encountered a network security block preventing content retrieval, leaving no article text for analysis.
- URL Source: https://www.reddit.com/r/SaaS/s/JxkhWzSZmp
The user encountered a network security block that prevented access to the specified Reddit SaaS post, displaying a message indicating the blockage.
- Ente – Opening Our Books
Ente publishes its full financial statements, revealing revenue, expenses, and user growth to demonstrate transparency and build trust with its privacy‑focused community.
- Apple in talks with startup that shrinks AI models to run on an iPhone
PrismML compressed Alibaba's Qwen model from 54 GB to under 4 GB to run on an iPhone, and Apple is in early talks to evaluate the technology.
- What xAI Grok Build CLI actually sends to xAI - a wire-level analysis (grok 0.2.93)
xAI Grok Build CLI sends file contents—including .env secrets—to xAI via model turns and uploads entire repositories as git bundles to GCS bucket grok-session-traces, regardless of what the agent reads.
- Apple's New Speech API vs Whisper: The First Real Benchmark
Apple's new SpeechAnalyzer achieves 2.12% WER on clean LibriSpeech, beating Whisper Small and legacy SFSpeechRecognizer while running about three times faster.
- URL Source: https://www.reddit.com/r/founder/s/lIJCOgIueI
The user attempted to view a Reddit founder community post but received a network security block message indicating access was denied due to protective filtering.
- URL Source: https://www.reddit.com/r/founder/s/xrgdNOGY84
Attempting to view the Reddit founder community link resulted in a network security block, displaying a message that access was denied.
- A new way to reflect on how you use Claude \ Anthropic
Anthropic launches a beta reflection dashboard that lets Claude users track, visualize, and assess their AI usage patterns against personal goals.
- Introducing the <usermedia> HTML element | Blog
Chrome 151 introduces the <usermedia> HTML element to handle camera and microphone access declaratively, replacing script-triggered prompts and improving permission recovery rates.
- Hotswap - Drop-in open coding models hosted for you
Arcjet provides runtime security for AI applications, including prompt injection detection, data loss prevention, and agent tool controls.
- The Cypherpunk Library
The Cypherpunk Library offers a curated collection of public-domain readings on cryptography and privacy, free and available for browsing.
- taken. — Since You Arrived Vol. IV
The page reveals the browser data websites silently collect—IP, timezone, GPU, fonts, battery level—without permission, highlighting fingerprinting prevalence.
- I Stored a Website in a Favicon
The author encoded a 208-byte HTML page into a 9x9 pixel favicon by storing RGB values and decoded it with JavaScript, demonstrating data storage in unintended places.
- Cloudflare teams up with Chrome, Firefox, and Edge on a privacy-first anti-bot protocol
Cloudflare, Mozilla, Google, and Microsoft are developing PACT, a privacy-first protocol to verify web traffic legitimacy without tracking users.
- Anthropic says Claude may want to see your ID
Anthropic may require some Claude users to upload government ID to appeal flagged accounts, citing fraud prevention amid tensions with the Trump administration.
- Show HN: Are You in the Weights?
A tool queries multiple LLMs to see if they recognize a name, but users report that even confident responses are often hallucinated or inaccurate.
- Ask HN: Has anyone replaced Claude/GPT with a local model for daily coding?
Users replacing Claude/GPT with local Qwen 3.6 models report a 5x speedup (vs 15x for cloud models) but require precise prompts and experience more loops and tool-call errors.
- Local Qwen isn't a worse Opus, it's a different tool
Local Qwen models are a different tool from frontier LLMs, offering privacy and fixed costs but suffering from looping and hallucination issues.
- Apple is about to make Hide My Email useless
Apple's decision to move Hide My Email and Sign in with Apple aliases to @private.icloud.com makes it trivial for services to block them, gutting the feature's privacy benefits.
- Google Chrome update will fully close the door on ad blockers
Google Chrome is fully removing Manifest V2 support in upcoming releases, finally ending the last loophole that allowed ad blockers like uBlock Origin to work.
- Google Chrome is killing all uBlock Origin bypasses, Microsoft Edge, Opera to follow - Neowin
Google Chrome removed the final feature flags that allowed uBlock Origin and other Manifest V2 extensions to function, with Edge and Opera expected to follow.
- The 4 iPhone Security Settings You Should Turn On Right Now
Enabling four specific iPhone privacy and security settings—Stolen Device Protection, iMessage Contact Key Verification, iCloud Advanced Data Protection, and Lockdown Mode—immediately reduces risk from device theft and targeted attacks.
- Google offers opt-out of “AI” search results for websites, promises it won’t affect regular search rankings – OSnews
Google adds a Search Console toggle allowing websites to opt out of AI Overviews and other generative AI search features, promising no impact on regular rankings.
- DuckDuckGo search saw 28% more visits after Google said people love AI mode
DuckDuckGo saw a 28% increase in visits after Google promoted its AI mode, sparking polarized reactions on Hacker News.
- A.I. Is Making Scams Hard to Spot. Here’s How to Protect Yourself.
AI-generated deepfakes and voice clones make scams harder to detect, requiring new verification habits like safe words and direct callback.
- China Is Testing Its State Surveillance Model Abroad
China is testing its state surveillance model abroad in a remote Pacific village, sparking backlash from locals.
- What Apple and Google are doing to your push notifications
Apple and Google have transformed push notifications from a simple delivery pipe into an on-device AI-edited channel that summarises, reorders and deprioritises content, mirroring the intermediation that email underwent a decade earlier.
- Their Phones Were Stolen in London. Then the Threats Started.
London phone theft victims face escalating threats after their devices are stolen, as criminals exploit personal data for extortion.
- Local AI needs to be the norm
Commenters argue local AI is already viable for many tasks and will become the norm, driven by open-weights models and privacy concerns, not just cloud convenience.
- Apparently Google hates us now
HN commenters argue that Google's services have degraded due to enshittification, driving users to alternatives like Kagi, Yandex, and DuckDuckGo.
- Goodbye Visa and Mastercard: 130M Europeans switching to sovereign payment
European consumers are shifting to the sovereign payment system Wero, which redirects payments through banks, reducing reliance on Visa and Mastercard, but commenters debate the risks of central bank control.
- The Quiet Renovation at Bitwarden - ByteHaven - Where I ramble about bytes
Bitwarden is quietly enshittifying under new private-equity CEO Michael Sullivan, removing "Always free" and core values like inclusion and transparency.
- Apple Silicon costs more than OpenRouter
Running local LLMs on Apple Silicon is not cheaper than using cloud APIs like OpenRouter when factoring hardware, electricity, and speed costs.
- OpenAI launches ChatGPT for personal finance, will let you connect bank accounts
OpenAI launches personal finance tools for ChatGPT Pro users, letting them connect bank accounts via Plaid for spending analysis and planning.
- Why ‘Smart’ Products Have Started to Look Like the Dumb Choice
A growing consumer backlash against Wi-Fi-connected, app-based 'smart' products in the name of simplicity is driving preference for non-connected 'dumb' alternatives.
- Tenderly Tracking My Husband
Using location tracking to follow a spouse's movements creates a paradoxical sense of closeness and anxiety about their safety.
- Green Card Holders Targeted for Deportation by New ‘Removal Apparatus’
The Department of Homeland Security created a new unit to review and potentially deport thousands of green card holders by scrutinizing past immigration records more aggressively.
- Bambu Lab is abusing the open source social contract - Jeff Geerling
Bambu Lab threatened a developer with legal action over an AGPL-licensed OrcaSlicer fork, escalating its crackdown on local-only printer control.
- DeepSeek V4 – almost on the frontier
DeepSeek V4 Pro offers coding quality near frontier models like Opus 4.7 at a fraction of the cost, though some users note slower thinking and data privacy concerns.
- EU calls VPNs “a loophole that needs closing” in age verification push
EU research arm warns VPNs are a loophole enabling minors to bypass age-verification laws, with some policymakers calling for age checks on VPN access.
- Google’s Prompt API
Google's Prompt API ships as a Chrome-only web standard requiring users to accept Google's use policy and download Gemini Nano without permission, drawing opposition from Mozilla and WebKit.
- SoundOff: Low-cost Passive Ultrasound Tags for Non-invasive and Non-Intrusive Smart Home Sensing — Yibo Fu
SoundOff uses passive, battery-free 3D-printed metal tags that emit unique ultrasound chirps when moved, enabling private, zero-infrastructure smart home sensing.
- The duality of language models in the browser - daverupert.com
The author expresses cautious optimism about small language models in browsers, highlighting privacy and low cost while noting concerns about calcification and standardization.
- How ChatGPT serves ads
OpenAI serves ads in ChatGPT by injecting single_advertiser_ad_unit objects into the SSE response, with four Fernet-encrypted tokens and contextual targeting.
- How ChatGPT serves ads. Here's the full attribution loop.
OpenAI's ChatGPT ad platform injects structured ad units into conversation streams and uses Fernet-encrypted tokens with a browser SDK to track conversions.
- Meta to start capturing employee mouse movements, keystrokes for AI training
Meta is installing software to capture employee mouse movements, keystrokes, and screen content for training AI agents to perform work tasks autonomously.
- LittleSnitch for Linux
Objective Development releases Little Snitch for Linux as a free, closed-source network monitor using eBPF, with limitations in reliability compared to its macOS counterpart.
- Personal Encyclopedias
A project uses AI to automatically generate a personal encyclopedia from photos, location data, and digital exports, preserving family history with structured cross-referencing.
- ICE Agents at Some Airports Begin Checking IDs in Security Lines - The New York Times
ICE agents have begun checking IDs in TSA security lines at some airports, raising traveler concerns, with unclear effects on wait times.
- GitHub - matthartman/ghost-pepper: Hold-to-talk speech-to-text for macOS. 100% local, powered by WhisperKit and local LLM cleanup. Hold Control to record, release to transcribe and paste.
Ghost Pepper is a free, open-source macOS app that provides 100% local, hold-to-talk speech-to-text and meeting transcription using on-device AI models.
- OpenAI rolls out ChatGPT Library to store your personal files
OpenAI rolls out a ChatGPT Library feature that automatically saves uploaded files to cloud storage for later reference in conversations.
- A.I. Bots Can Act as Personal Digital Assistants, but There Are Serious Risks - The New York Times
AI bots that can edit files and book trips pose serious risks of data breaches, unwanted actions, and loss of user control.
- Reddit User Uncovers Who Is Behind Meta's $2B Lobbying for Age Verification Tech
A Reddit researcher uncovered that Meta funneled $2 billion through nonprofits to lobby for age verification laws that would force Apple and Google to build OS-level age verification while exempting Meta's own platforms.
- Ageless Linux – Software for humans of indeterminate age
Ageless Linux is a Debian-based OS that deliberately flouts California's AB 1043 age verification law, framing its noncompliance as a civil liberties stand.
- Sitegeist - Your AI Companion for the Web
Sitegeist is a browser-based AI assistant that lets users automate web tasks, extract data, and build reusable skills while keeping data local and offering flexible AI model choices.
- The 49MB web page
News websites like the NYT have grown bloated with ads and tracking, reaching 49MB, driving users to block JavaScript or seek alternatives.
- Cloudflare crawl endpoint
Cloudflare launches a managed crawl endpoint that respects robots.txt, aiming to provide a well-behaved alternative to aggressive AI scrapers.
- Innocent woman jailed after being misidentified using AI facial recognition
An innocent woman was jailed for months after AI facial recognition wrongly identified her as a bank fraud suspect, despite clear evidence she was far away.
- A.I. Chatbots Want Your Health Records. Tread Carefully. - The New York Times
Microsoft upgrades its AI assistant to track health records, following Amazon and OpenAI, warning users of both benefits and risks.
- Microsoft’s New AI Health Tool Can Read Your Medical Records and Give Advice - WSJ
Microsoft launches Copilot Health, an AI-powered concierge doctor within its Copilot app that provides personalized advice based on user medical records and biometric data.
- Yaak – The API client you'll actually enjoy
Yaak is an offline-first, local-only API client supporting HTTP, GraphQL, gRPC, WebSocket, and SSE, developed by the original creator of Insomnia as a simpler, privacy-focused alternative to Postman and Insomnia.
- X’s Chatbot Started Undressing Women. Was This What A.I. Wanted All Along? - The New York Times
Grok Imagine's nudify scandal shows that AI's image-manipulation capabilities enable non-consensual sexualization, fulfilling a troubling desire to control photos of women.
- Online age-verification tools for child safety are surveilling adults
Age-verification tools required by child-safety laws effectively surveil and de-anonymize all adult internet users, not just protect minors.
- A.I. Complicates Old Internet Privacy Risks - The New York Times
AI chatbots revive old internet privacy risks by collecting user conversations, potentially exposing sensitive data without users' full awareness.
- Our agreement with the Department of War
OpenAI announces a contract with the Pentagon for classified AI deployments, emphasizing cloud-only deployment, retained safety guardrails, and explicit prohibitions against domestic surveillance and autonomous weapons.
- Visitors - Privacy-friendly Google Analytics alternative
Visitors is a privacy-focused Google Analytics alternative offering GDPR compliance, realtime analytics, and revenue tracking through integrations.
- Tell HN: YC companies scrape GitHub activity, send spam emails to users
YC companies such as Run Anywhere scrape GitHub commit metadata to send unsolicited marketing emails to developers, violating GDPR and GitHub's terms of service.
- Americans are destroying Flock surveillance cameras
Across the US, people are vandalizing Flock license plate cameras in protest of the company's data sharing with ICE and immigration authorities.
Takes
WIRED magazine just gave a 10/10 rating to a piece of hardware for the first time in a decade. It is a robot vacuum. Meet Matic. You do not use an app to control it. You literally treat it like a pet. You can point at a coffee spill and say "Hey Matic, clean this." You can even tell it to "follow me" and it walks behind you. It spent 9 years in development to solve the biggest smart home problem: privacy. It has 5 cameras, but it processes everything locally on an Nvidia chip. Your data is deleted in real-time. Hardware is finally getting fun again.
@shiri_shh
We've gotten a lot of great questions on privacy implications of Computer History. Here's a few things we've done to build a super powerful feature while keeping things private. First off, you can review all of your Computer History in the timeline view:
@AriX
Another cloud provider down. ❌ Tailscale ✅ Headscale Now my company and products run on my self-hosted, private VPN.
@SimonHoiberg
Vibecoded a silly little tool that transfers files from your computer to your phone air-gapped using your camera at ~50 Kbps. Nice to have when you're offline or on a plane, or need to send something super duper securely.
@deedydas
🤯 Wow I can't believe I'm open sourcing the email platform we built internally. Self-hosted, runs on your own AWS SES. You pay @awscloud $0.10 per 1,000 emails instead of a SaaS markup, and your email data never leaves your infra. MIT licensed. Here's what it does 🧵
@vijaytupakula
Knockoff is now live! Filter out the knockoff crap brands on Amazon. Sorry to brands like WNPETHOME, EHEYCIGA, YXYL, LU&MN, JOYIN, TOMY, GODONLIF, YOOJEE, LINGTENG, LANEIGE, VISCOO, BIODANCE, COOFANDY, BALENNZ, TOSY and LUENX. https://knockoff.shopping
@Shpigford
I'm bullish on open source AI. Was paying $15/month for a popular AI voice to text tool. But switched to an open source one where you download the model to your computer, and everything is done locally. It's better, faster, more private, and it's free! I wonder what other subscriptions I can get rid of?
@thepatwalls
🎉 Mole for Mac 1.7 is live. Apple Silicon fan control, camera/mic privacy alerts, stay awake for AI coding, lock input to wipe your screen, VoiceOver, built-in app updates, Blue Marble earth, fast treemap. Ready for macOS 27. Early bird $9 till Jun 15. http://mole.fit
@HiTw93
My new macOS app just launched 🎉🥳 Here’s your new favorite macOS app: http://Supaste.com Clipboard history + manager app 👇 For sure: local, private, offline, no subscription.
@soltwagner
User Journeys is finally here, which was our most requested major feature ever! Now, you'll be able to see exactly how visitors use your site. How they navigate from page-to-page, reach goals, where they drop off, and conversion rates for each path. It works backwards too. So you can pick any endpoint and trace back the paths that led to it. ✅ Simple to use (as always) ✅ Privacy-friendly (no compromise) ✅ Zero setup required, available on your dashboard now ✅ Works on all your historical data
@PlausibleHQ
never share / record your email / ssn / address again shades is a chrome extension that masks sensitive input (in a fun way)
@mattyp
Brave just added a feature people have wanted for YEARS. Containers. And most users don’t realize how powerful this is. Here’s why it changes how you browse 👇
@Techjunkie_Aman
When Brave users told us they'd pay for a minimalist version of our browser, we listened. Brave Origin, now in Nightly, is a paid version of our browser for users who don't need all of Brave’s features but still want its leading privacy and ad blocker: https://account.brave.com/?intent=checkout&product=origin
@BraveNightly
So @brave just launched Brave Origin, a bare-bones, privacy-first browser without any ads, AI, or web3. It's $60. Unless you're on Linux, in which case it's free. Pic related (arch btw)
@o7laurence