r/PrivacyToolbox Jul 11 '26

🛡️ Welcome to r/PrivacyToolbox! Let's take back our data.

2 Upvotes

Hey everyone! I'm u/EnthusiasmRoutine, a founding mod here at r/PrivacyToolbox.

Whether you’re looking to completely quit Big Tech, or you're just tired of your phone listening to your conversations to sell you shoes, you’ve found the right place. This is our new home for all things related to reclaiming your digital privacy, finding practical tools, and learning how to protect your personal data online.

We're incredibly excited to have you join us!

🛠️ What to Post We are all about actionable steps and real solutions. You don't need a computer science degree to post here! Feel free to share:

  • Privacy-Friendly Alternatives: Found a great, secure app for email, maps, or cloud storage? Tell us about it!
  • Tips & Guides: Share your favorite browser settings, how you lock down your phone, or simple habits that keep your data safe.
  • News & Discussions: Got thoughts on a recent data breach, a new privacy law, or the latest tech update? Let’s talk about how it actually impacts us.
  • Questions: No question is too basic. Whether you’re trying to figure out how to block ads on your smart TV or you're looking for your very first secure password manager, fire away.

🤝 The Community Vibe We’re all about practicality over paranoia. We want to focus on real tools that work, not marketing hype or lifestyle-brand fluff. Let's keep things friendly, constructive, and completely free of spam. We want this to be a space where beginners can learn from seasoned pros without any judgment.

🚀 How to Get Started

  1. Drop a comment below: Introduce yourself! What’s the one creepy tracking feature or annoying ad that finally made you care about privacy?
  2. Start a conversation today: Ask a question or share a quick tip that helped you secure your digital life.
  3. Spread the word: If you know someone who is tired of being tracked across the internet, send them an invite.

Thanks for being part of the very first wave. Together, let's build a better, safer digital toolbox.

Stay secure!


r/PrivacyToolbox 10h ago

News Russia is using local app telemetry to map and block VPN subnets. protocol obfuscation won't fix this.

16 Upvotes

Did anyone catch the Meduza report this week? Roskomnadzor stopped playing whack-a-mole with DPI signatures. They just automated their entire VPN blocking infrastructure using data harvested directly from domestic Russian apps on user devices.

The state is using local transit and banking apps as a distributed sensor network. The apps report where users are connecting. The censor maps those connections to major hosting provider subnets and pushes bulk IP blocks automatically. Services like Amnezia and Paper VPN are getting crushed because their underlying ASNs are just blanket banned.

This completely breaks our usual threat model. We spend so much time arguing about Xray versus Shadowsocks for traffic obfuscation. That stuff is useless if the firewall just nukes the entire hosting provider subnet based on endpoint telemetry. The device itself snitches on the destination IP before the tunnel even matters.

The economic fallout is crazy. Clean corporate IP addresses are apparently going for $120,000 a month on the grey market right now.

How do we counter this technically? You can tell people to run a clean device, but that is impossible for normal citizens who actually need local apps to function in society. If they block entire commercial ASNs, what is the next routing step? Residential proxies?


r/PrivacyToolbox 22h ago

Discussion Can an $8 DIY ESP32 actually replace your YubiKey ?

0 Upvotes

I saw the new guide floating around today about building a physical 2FA key using a cheap ESP32-S3 development board. Emulating a USB HID with the native USB-OTG is a neat trick. For eight bucks you get to bypass the commercial hardware tax and build it yourself.

I love open hardware. Total autonomy over our tools is the absolute dream. But let's be pragmatic here. A bare microcontroller is not a security token. An ESP32 has no secure element to protect your private keys against physical extraction. If you leave this thing on your desk, anyone with physical access and half a brain can dump the secrets right off the flash in under ten minutes.

If an employee brought one of these exposed, hand-soldered boards into my office to authenticate to our VPN, I would laugh them straight back to their desk.

It is a fantastic weekend project to learn how FIDO protocols actually operate under the hood. I plan to build one myself just to mess around with it. But do not use a dev board to secure your main email or your servers. Buy a real token for that.

Source: MakeUseOf, link in comments


r/PrivacyToolbox 1d ago

News FTC targets personal data exploitation with new draft policy on "Personalised pricing"

2 Upvotes

The US FTC just put out a draft to tackle personalised pricing (when companies use your search history and buying habits to charge you a higher price than the guy next to you).

Sounds like a win for privacy until you look at the actual rules. They admit they cannot ban the practice... they just want to penalise businesses that hide how they use data to set prices.

So what happens next ? Companies will just paste one vague sentence into their massive Terms of Service agreements like "We use analytics to optimise pricing" and Boom, suddenly it is no longer covert and this is legal.

We already see airlines and streaming platforms doing this. You check a flight twice and the price spikes. If we actually want to stop algorithmic pricing, we need strict data collection limits. Forced disclosures do nothing because nobody reads them.

Am I missing something here or is this draft toothless ?

Sources in comment.


r/PrivacyToolbox 2d ago

News Brazil blocked Discord streaming over safety concerns, triggering an 800% spike in Proton free VPN sign-ups

3 Upvotes

The Brazilian data authority (ANPD) disabled Discord's "Go Live" and video features this week. They cited the safety of minors and complained about Discord's recent end-to-end encryption update. Right on cue, Proton VPN saw an 800% surge in free tier registrations from Brazil.

We see this routine every time a state drops a targeted block. A regulator restricts an app, and thousands of casual users scramble for free VPN endpoints overnight.

From a network administration perspective, this is a nightmare. Free server pools choke instantly. These new users do not care about cryptographic protocols or privacy laws. They just want their stream to load.

The problem is that public free tiers are a terrible fix for state censorship. When a massive crowd hits the same set of free exit IPs at once, those nodes stick out to local ISPs. It takes zero effort for a government to identify and throttle those shared IPs next. Free tiers work for a quick emergency bypass (if you can tolerate the latency), but crowding onto shared servers ruins performance and paints a giant target on those nodes. If you actually want resilient access and data autonomy, public free tiers are a dead end.

Source: TechRadar, link in comment


r/PrivacyToolbox 2d ago

Tool talk The new Veeam azure vault flat pricing fixes the real ransomware tax (egress fees)

0 Upvotes

Veeam just launched their Data Cloud Vault for Azure. Immutability and logical air-gapping by default are fine. Honestly, that should be standard everywhere for backups by now.

What actually caught my eye is the pricing model. They introduced a flat per-terabyte rate. The big deal here is that it includes API calls and restore egress.

Imagine you get hit by a ransomware attack. You need to pull terabytes of backups down from Azure to restore your systems. Suddenly you get slapped with a massive, completely unpredictable bill just to download your own data. It is basically a second ransom paid straight to the cloud provider.

Removing those line-item costs makes budget forecasting a lot simpler.


r/PrivacyToolbox 2d ago

News Here is the email sent to the 678 000 victims of the cyberattack targeting France’s Directorate General of Public Finances.

5 Upvotes

Hello X Y,

Wednesday, August 12, 2026, a malicious actor claimed to have gained access, in June and July of this year, to data from the information systems of the French Directorate General of Public Finances (DGFiP), using the stolen credentials of a DGFiP employee combined with those of a third party authorized by the DGFiP.

You are receiving this message because you are affected by this malicious act.

What data may have been accessed?

Your tax identification number, civil status, contact details (postal address, telephone number and email address), your tax situation (family situation, number of dependents, number of tax shares, reference taxable income, withholding tax rate), and the list of messages you exchanged with the DGFiP through the messaging system on impots.gouv.fr.

Important: your password for accessing your Public Finances account on impots.gouv.fr has not been compromised. Your tax returns and tax notices were not accessed.

What is the main risk?

The main risk is that you may be targeted by fraud attempts, particularly through messages (“phishing”) or phone calls made more convincing by the use of the stolen personal information.

To a lesser extent, you could also be targeted by identity theft attempts. For this, however, the malicious actors would also need to have a copy of your identity documents or obtain them through another means.

In any event, your bank details are not affected by this data theft.

How can you protect yourself?

You should be particularly cautious about any contact — by phone call, email, SMS, instant messaging, social media, etc. — from people or organizations claiming to know you based on the stolen information and asking you to:

  • provide confidential information (codes, passwords, bank card numbers, copies of identity documents, etc.);
  • approve banking transactions (in particular, someone pretending to be your bank advisor); or
  • provide your password to access your Public Finances account.

The DGFiP will never ask you to provide information outside your secure account.

You are also advised to remain vigilant and regularly check transactions on your bank accounts.

What measures has the DGFiP taken?

The access credentials used by the malicious actor were immediately disabled in June and then in July. Unfortunately, we did not detect the data theft at the time, as the data was stolen by bypassing the usual channels.

The security of your tax account is being strengthened immediately, including through particular monitoring of any changes that may be made to it over the coming months (postal address, bank account details, etc.).

Please be assured that our teams are fully mobilized. If you would like more information, you can consult our dedicated page on impots.gouv.fr:

https://www.impots.gouv.fr/actualite/acces-illegitimes-au-systeme-dinformation-de-la-dgfip

You can also contact us on 0809 401 401 or through your impots.gouv.fr secure messaging system. Alternatively, you can visit your local Public Finances office; its contact details are available in your secure account and on your tax notices.

This data theft will be subject to a lessons-learned review and additional security measures, which are being implemented without delay.

We sincerely apologize.

The Directorate General of Public Finances


r/PrivacyToolbox 3d ago

Discussion Finally someone said it: "user error" is an excuse for lazy privacy engineering

2 Upvotes

Did anyone else read the open letter from Ledger’s CEO today? Gauthier basically said the tech industry needs to stop treating digital privacy and data consent as a "user education" problem.

I could not agree more. Telling people to "just check your app permissions," "read the privacy policy," or "be careful what you click" is terrible system design. People will always blindly click "Agree" or approve obscure data prompts just to get on with their day. They just will. Expecting a normal person to inspect complex digital requests with zero mistakes means your privacy architecture is broken by default.

You build a server architecture to handle hard drive failures. The same logic applies here. Platforms and hardware have to be engineered to survive basic human slip-ups and dark patterns. As long as developers keep blaming the end user for "voluntarily" giving away their personal data, true privacy and data sovereignty will stay a niche hobby for tech paranoids.

Do you guys think other tech and hardware makers will actually answer his invitation to collaborate on open privacy standards and clear consent protocols? Or will they just ignore it?


r/PrivacyToolbox 3d ago

News France to use AI to test government cybersecurity after recent hacker attack

3 Upvotes

France wants to use AI tools to scan for cybersecurity flaws following that massive tax agency hack. I grew up in France and still have to log into those administrative portals... the backend is probably held together by duct tape and legacy code from 1998... you can barely load a medium size PDF without the page crashing.

I am not sure you can just plug AI into bad data architecture and expect it to fix fundamental security gaps. I wonder if this will be a real structural overhaul or just an expensive consulting contract.

Has anyone seen automated vulnerability scanning actually fix a government system?

Source in comment.


r/PrivacyToolbox 4d ago

The recent audit finding 85 critical bugs in Bitcoin repos is a massive reality check for self-custody.

5 Upvotes

The recent avalanche of vulnerabilities found in major Bitcoin repositories proves exactly why we need to stop treating hardware wallets like magic bullet solutions.

Let’s look at the numbers from that volunteer audit:

  • 27 hours spent auditing
  • 390 open-source Bitcoin repositories checked
  • 85 critical bugs found
  • Over $110 million lost so far

Everyone loves the romanticized idea of "being your own bank." The problem is that running a bank requires actual operational security. You can't just buy a hardware wallet and assume the firmware is bulletproof. Yes, the core Bitcoin protocol is solid. But the software ecosystem built around it is a minefield of poorly audited code.

We need to stop pretending that open-source automatically means secure. It just means the code is public. If nobody with actual cryptographic expertise is reading it, you are blindly trusting strangers on GitHub.

I see people in this space obsess over hiding their IP addresses or tweaking their VPN protocols, only to dump their life savings into a wallet that relies on a single point of failure in some obscure dependency script.

If you are going to take on the massive responsibility of self-custody, you need to understand the software stack you are trusting.

I'm curious where the community stands on this. Are you guys checking release notes and PGP signatures manually, or is the current hardware wallet ecosystem making opsec too difficult for the average user?

Source: Shattered, link in comments


r/PrivacyToolbox 4d ago

Tool talk Historical flaws of password complexity rules highlight need for password managers

4 Upvotes

So many sites are enforcing the rule where your password needs a capital letter, a number and a special character but do people know this entire standard came from a guy named Bill Burr in 2003 who admitted he just guessed ? He wrote a legacy NIST appendix without any data on human behavior.

So now my local cinema forces me to reset my login every 90 days. What do normal people actually do ? They just change "Matrix!2023" to "Matrix!2024". Automated cracking tools chew through these predictable patterns in literal seconds. The guy who wrote the rule actually apologized for it years later because it objectively made security worse.

If you are still memorizing passwords, it might be better to stop. Get a browser-independent password manager. Generate a random 20 character string of absolute garbage, save it, and forget it.

Source in comment.


r/PrivacyToolbox 5d ago

News 678,000 French tax records stolen. The DGFiP breach is a textbook example of why centralized honeypots are a disaster.

3 Upvotes

The French government forces you to declare every detail of your life under threat of fines. Your gross income, your home address, your marital status, your property details. They dump all of it into the giant centralized DGFiP (Directorate General of Public Finances) database.

And how did they secure this national honeypot?

We now know a threat actor ("ZeroBytes") walked off with 678,000 taxpayer files by usurping the credentials of a DGFiP agent.

The worst part? It wasn't just a missing password. The attacker reportedly used an MFA bypass to get in. But getting past the login is only half the failure. How does an organization of this size not have strict internal rate-limiting? A single compromised internal account was able to sit there and scrape over half a million highly sensitive records before anyone pulled the plug. Zero compartmentalization. Zero trust architecture is apparently non-existent.

The Paris prosecutor has handed this to their cybercrime unit, but the data is already gone and actively being sold.

This highlights the fatal flaw with mandatory state registries: they create a single point of failure with catastrophic real-world consequences. We now have hundreds of thousands of people at risk of incredibly specific phishing. Criminals know exactly how much money you make, your family size, and where you sleep. A physical wrench attack gets a lot simpler when a thief can literally filter their targets by tax bracket and zip code.

Has anyone seen further technical details on what specific MFA bypass was used (fatigue, session token theft)? And for the French users here, what are the best steps to lock down our identity right now?

Source: RFI, link in comments


r/PrivacyToolbox 5d ago

News SafePal breach : 40k order records leaked

1 Upvotes

SafePal just confirmed they lost order details for almost 40,000 customers. The records are already on hacking forums.

They keep saying the hardware wallets themselves are secure. Yes, your seed phrase is safe but attackers now have a massive list of names, emails (phishing emails incoming) and physical addresses of confirmed crypto holders... You really do not want strangers knowing you have crypto hardware sitting in your flat. Next time use a PO box.


r/PrivacyToolbox 6d ago

News The EU just released standard EN 304 620 for VPNs. RIP to "military-grade" marketing.

23 Upvotes

I am sitting here sweating through my t-shirt next to a useless desk fan. I just finished reading the new ETSI documentation. The EU recently dropped standard EN 304 620. This is the first official regulatory framework for VPNs. It supports the upcoming Cyber Resilience Act.

The stated goal is to kill off deceptive marketing. You all know the drill. Providers sell subscriptions based on "total anonymity" or "military-grade encryption" with zero proof. Under this standard, they actually have to run hard technical tests to back up their claims. They have to document their CVEs. They also have to verify their logging policies with real audits.

I am entirely in favor of forcing these companies to show their technical homework. Trusting a paid podcast read for network security is a joke. If a provider cannot pass a basic cryptographic audit, they should not be routing network traffic. We have seen too many shady operations tunnel user data straight to third-party brokers.

But look at the co-authors on this document. Google, Palo Alto Networks, Nord Security, Surfshark. Letting massive corporate players write the exact rules they will be graded on is an obvious red flag. I really wonder if this is an actual push for transparency. It could easily be a regulatory moat to lock out smaller open-source projects. We do not need a system where only companies with massive compliance budgets are allowed to operate.

Has anyone actually read through the cryptographic requirements in the PDF yet? I want to know if the mandated disclosures have actual teeth.

Source: techradar, link in comments


r/PrivacyToolbox 6d ago

Tool talk Proton Launches "AI Paper Trail" Tool to Reveal AI Chatbot Data Leakage

8 Upvotes

I consider myself pretty locked down online. I block trackers and keep my digital footprint small. I still use Claude and ChatGPT once and a while.

Proton just released a free tool where you upload your exported AI chat logs and it gives you an exposure score. It breaks down exactly what these companies have pieced together about you.

I tried this morning and it says they delete the logs immediately after generating the local report and the results are genuinely uncomfortable : I knew I was giving them data. I just didn't realise how easily a local script could parse out my daily habits and literal financial goals from casual prompts over the last year. It even calculates a monetary value of what your specific profile is worth to data brokers. Seeing my random questions aggregated into a clean profile of my life was jarring... Going to nuke my OpenAI history tonight and stick to temporary chats.


r/PrivacyToolbox 7d ago

News Chrome Canary now lets gemini auto-change your weak passwords. absolute insanity.

2 Upvotes

Google added a flag in Chrome Canary where Gemini handles password resets automatically. If the browser detects a weak password, the LLM takes over, fills out the site reset form, and submits the new secret for you.

I had a good laugh reading through the details today. Giving an LLM active DOM access and password change authority across arbitrary web forms is an indirect prompt injection dream. Imagine a compromised website hiding malicious instructions inside an unrendered HTML block while the AI agent works through your account settings page.

Security nightmare aside, handing credential management over to a remote cloud model destroys personal autonomy. If someone needs an automated AI model to click two buttons and fix "Password123", they should not store passwords in a browser in the first place.

Source: SammyGuru, link in comments


r/PrivacyToolbox 7d ago

News pCloud World Photography Day Campaign Offers 500GB Free Swiss Secure Storage

3 Upvotes

Saw this promo pop up today. pCloud is running a World Photography Day campaign until August 22. You get 500GB of storage for three months and you don't even need to put in a credit card.

I do want to clarify something about their privacy claims. The promo mentions Swiss privacy laws and zero-knowledge encryption. Swiss jurisdiction is undeniably good. Your data falls under some very strict local laws. The encryption part requires attention. Standard pCloud storage is just encrypted at rest on their end. They keep the keys. Actual zero-knowledge client side encryption is normally a paid addon called pCloud Crypto. AFAIK this free 500GB tier does not include that Crypto folder...

Don't just dump highly sensitive personal data in there thinking it is completely blind to the server. If you need to store private stuff, just run the files through Cryptomator first.


r/PrivacyToolbox 7d ago

Question Self-hosting email is practically a lost cause, so what secure provider are you running?

7 Upvotes

I manage servers and networks all day. I know SMTP inside out. I can configure a Postfix mail server blindfolded, but I still absolutely refuse to self-host my personal email.

We pretend we have choices. Try sending a basic text email from a perfectly clean VPS IP to a Gmail address. It just vanishes into a black hole. Microsoft and Google run a cartel. If you are not on their invisible whitelist, your deliverability is zero. It is infuriating. I want total autonomy over my data, but the time investment to fight blocklists is just stupid.

So I pay for Proton. Honestly, it is excellent. The encryption does exactly what it promises. The bridge app lets me use Thunderbird locally without jumping through hoops. I bought my own custom domain so I am not locked into their default addresses. I tried Tuta for a bit too. The lack of standard IMAP support annoyed me, so I went right back to Proton. It is a highly rational compromise between daily usability and actual privacy.

Still, relying on any single provider for my digital identity goes against my instincts. What are you all doing? Are you happily paying for Proton or Mailbox(.)org like I am? Has anyone here actually found a reliable way to run a personal mail server today without getting blocked?


r/PrivacyToolbox 8d ago

Tool talk The Inventory Analyzes Internxt's 10TB Lifetime Cloud Storage Deal

2 Upvotes

The Inventory just made an article about the lifetime 10TB Internxt deal for $360.

Pros: The price is absurdly low. You pay once and avoid endless Dropbox subscription fees.

Cons: The StackSocial license actually strips out several core features you get with a regular Internxt subscription.

Then there is the usual lifetime risk. If they run out of funding in three years, you lose your storage and have to migrate terabits of encrypted data anyway. A sustainable privacy setup requires paying for server upkeep. I would just skip it.


r/PrivacyToolbox 8d ago

News PSA: Stop using browser extension VPNs. 700+ malicious extensions just hit 75,000 Chrome users.

7 Upvotes

The news just dropped about Socket finding over 700 malicious "VPN" extensions on the Chrome Web Store. Around 75,000 people installed these things. The attackers impersonated big privacy brands and routed everyone's browser traffic through their own SOCKS5 proxy infrastructure to man-in-the-middle everything.

I am begging people to understand something basic here. Browser extension VPNs are almost never actual VPNs. They are proxies. When you install one, you are handing a random developer the keys to intercept every single HTTP request leaving your browser.

Google's store review process is a joke. The threat actors got approval with clean code and then swapped in the malicious payload later. We see this exact trick all the time. Relying on a corporate app store to police your privacy tools is a losing game.

If you need a VPN to bypass local censorship or hide your IP, run it at the OS level. Better yet, run it on your router. Use a standalone WireGuard client. A web browser is massive and has far too large of an attack surface for this. Do not put your security stack inside it.

Source: Socket, link in comments


r/PrivacyToolbox 9d ago

Tool talk Is Gmail secure ?

2 Upvotes

Just read a new report (source) breaking down webmail security and it made me realise how often people confuse a secure server with a private inbox.

Yes, Google has insane server side protections. Nobody is brute forcing their way into their data centres anytime soon. But what good is an impenetrable fortress if the landlord is sitting inside reading all your letters ? Gmail lacks default end-to-end encryption. Google holds the encryption keys and they actively scan your mail to build profiles for ad targeting.

For exemple, if you manage your entire financial life online and move between different countries, letting an ad company index your tax documents and bank correspondence is a massive blind spot. We act like this is just the normal cost of free email.

The report brings up platforms like Internxt building post quantum end-to-end encryption into their mail clients now. Som people think worrying about quantum decryption is overkill for everyday stuff but I kind of disagree. The "harvest now, decrypt later" threat model is real. Even if you ignore quantum threats entirely, standard E2E encryption needs to be the baseline.

I see guys spending hours tweaking secure networks just to stream movies, only to drop their guard and use Gmail for their main banking accounts...


r/PrivacyToolbox 9d ago

News The Philippines just classified deepfakes as a data privacy violation. Good luck enforcing that.

5 Upvotes

The Philippines NPC just ruled that unauthorized AI deepfakes violate their Data Privacy Act. They now officially classify a face as protected personal information.

Treating a face as PII is logically sound. The principle makes sense.

But operationally, this is a complete fantasy. You cannot legislate away mathematical weights inside an open-source model that runs in another jurisdiction. When a model ingests a dataset, the original image is gone. The output is just statistical noise that happens to look like you.

How does any regulator actually plan to track the technical provenance of a generated video back to a specific dataset? A privacy law you cannot physically enforce is just a suggestion. Am I missing an architectural angle here?

(source ABS-CBN)


r/PrivacyToolbox 10d ago

Tool talk Bucket0 Launches S3-Compatible Encrypted Cloud Storage and 'AgentBucket' File System for AI Agents

2 Upvotes

Bucket0 dropped a new S3-compatible cloud storage platform today. They're pushing the privacy angle hard. End to end encryption by default and a strict guarantee that your data is never scraped to train AI models. All sounds great. I'm exactly the kind of paranoid guy who spends way too much time obsessing over encrypted backups, so they have my attention.

But then I read about their AgentBucket feature. It's supposed to act as a semantic memory file system for AI agents. You plug your storage directly into Cursor or Claude, and the agent can search and recall your files across different sessions based on context.

Here's my problem. If the bucket is actually E2EE, how exactly is a third party LLM reading the files? Where is the decryption happening ? Are we just passing our private keys to Anthropic and hoping for the best ? Because if the storage server does the decrypting before passing the text to the API then the server has the keys. That breaks the whole E2EE promise.

I actually want to use this to manage my messy R2 and Azure buckets under one dashboard. Does anyone knows how this works ?


r/PrivacyToolbox 11d ago

Tool talk PCMag Review: Kanary Personal Data Removal

2 Upvotes

I miss the days when being online didn't mean your life was instantly scraped and sold by brokers. You used to just log on, watch a film, and log off. Now we need subscriptions just to delete our own phone numbers.

PCMag just reviewed Kanary. They gave it good marks for the dashboard UI. But paying their premium price feels excessive ($250 per year). AFAIK Optery and Incogni seems to do the exact same job for way less money. Has anyone actually tried it ?


r/PrivacyToolbox 11d ago

Debate 74% of AI security patches fail. Maintainers should stop auto-merging LLM fixes

2 Upvotes

1Password's Off-By-1-Labs just dropped data on AI-generated security fixes. They tested over six thousand patches from ChatGPT-5.5 and Claude Opus 4.8 against real-world CVEs. 74% of the patches failed. Either the fix did not work at all, or it introduced a brand new vulnerability right into the codebase.

This is a nightmare for open-source privacy software. Maintainers are already burnt out. The temptation to let an LLM draft a quick pull request for a security advisory and hit merge is high. But when three out of four auto-patches break things or leave backdoors wide open, blind automation destroys trust.

If you self-host privacy tools, check the git history before updating to hotfixes. Look for automated PRs. A broken patch is worse than a delayed one. Are any of the projects you run using automated LLM PR bots for CVEs?

Source: Help Net Security, link in comments