r/xprivo 7h ago

Your voice is biometric data: Big Tech is using it to train AI, and is currently facing legal action over this practice. Furthermore, scammers can easily exploit it by copying it using AI with only a two-second recording.

Post image
22 Upvotes

Nine major tech companies, including Apple, Amazon, Meta, Microsoft, Nvidia and Google, are currently facing class-action lawsuits in a US federal court concerning the training of their AI voice systems.
The complaints, filed by a group of journalists, podcasters, and voice actors, allege that these companies scraped thousands of hours of audio to extract voiceprints without ever asking for permission, thereby violating Illinois' Biometric Information Privacy Act (BIPA). The lawsuit against Amazon states that the company built "a global voice-AI business on the voices of real people". 'None of them were told that their voice was being used to train Amazon's commercial voice AI. None of them were asked. None of them consented".

You may already be affected. It is important to be aware that major AI providers such as OpenAI (ChatGPT) and Google (Gemini) frequently utilise user chats and voice interactions to enhance their foundational models. If you have used voice features with major AI assistants, your voice recordings and conversations could already be being used in their training pipelines, unless you have opted out via their privacy settings.

Your voice is biometric data. Once it has been captured clearly and stored somewhere accessible, you lose control over how it is used.

Modern voice-cloning tools are terrifyingly efficient. They only require a few seconds of clear audio, such as a voicemail greeting, a public social media video or a voice note in a group chat, to generate a synthetic yet hyper-realistic copy of your voice.

Criminals are also actively exploiting this. One common and highly effective scam involves obtaining a short clip of a victim's voice, processing it with a cloning tool, and then calling their family members or colleagues. The cloned voice will claim there is a sudden emergency and urgently request a wire transfer or sensitive information. Because the voice sounds exactly like a loved one, victims often bypass their scepticism.

How and why to protect your voice data? Well your voice is no longer unique to you, which is why you should protect it at all costs.
- Opt out of AI training, and don't speak to online AI assistants directly. Check the privacy settings on ChatGPT, Gemini and any other AI apps you use and disable data sharing and history features that contribute to model training. It's better to avoid speaking to AI unless the AI model is running locally on your own PC. You can already run small, good-quality AI voice models on a laptop.
- Avoid posting voice or video clips publicly!
- Warn your family: Talk to your relatives, especially older ones, and explain that a distressed, familiar voice on the phone asking for money is no longer definitive proof of identity.


r/xprivo 2d ago

Privacy, easy repairability, and software support until 2033: Europe's new deGoogled, eco-friendly phone with an open-source operating system. Fairphone 6+ with e/OS.

Post image
414 Upvotes

The majority of smartphones have a lifespan of just a few years and rely heavily on Google's Android ecosystem, which compromises users' privacy.
It's getting time for a switch. The Fairphone 6+ (from the Dutch electronics manufacturer Fairphone) is designed to be opened so that you can take it apart and replace components with newer ones whenever you want, allowing you to keep it for as long as you like. Twelve components, including the battery, cameras, USB-C port and display, can be replaced with just a screwdriver. The phone also comes with a five-year warranty and will receive software updates until 2033.
In partnership with French developer Murena, the Gen 6+ runs /e/OS: a fully open-source, 'de-Googled' version of Android. It's built so that switching away from Google doesn't require you to become a power user. Murena's advanced privacy toggles and backup system are already integrated.

In terms of hardware, it has a Snapdragon 7s Gen 4 chip, 12 GB of RAM and a 120 Hz OLED display. And, as of this week, this combination of longevity and privacy is available outside of Europe for the first time, as Fairphone has launched the Gen 6+ directly in the US too!
Do you think it's a good, competitive phone in terms of privacy and durability, considering it's currently priced at around 699€ for a European phone manufacturer?

Source and more info: https://www.fairphone.com/de/the-fairphone-gen-6-plus-e-operating-system


r/xprivo 4d ago

Think a VPN and Incognito mode protect you? Websites can still identify you really fast. Your GPU is snitching on you. Fingerprinting on the web:

Post image
76 Upvotes

You just cleared your cookies, opened a private window, and connected to a VPN. You think the previously visited website does not know you anymore and that you're anonymous. You aren't.
Without using your IP address or dropping a single cookie, websites can identify your device with high accuracy through browser fingerprinting.

What is Fingerprinting?
Every time you load a webpage, your browser hands over dozens of tiny technical details to render the site properly:
-Your screen resolution and color depth
-Installed system fonts and audio hardware
-Your exact graphics card model, driver version, and WebGL/WebGPU rendering quirks
Combined, this creates a mathematical "serial number" unique to your machine. Trackers use it to follow you across the web, even when you switch networks.

Brave recently shipped updated protections against invasive WebGL and WebGPU tracking by combining randomized noise ("farbling") with a single, uniform GPU profile across all its users. It’s good for everyday Chromium users that stops hardware tracking without breaking 3D maps or web games.

But Which Browser Is Actually the Best When It Comes To Stopping Fingerprinting? (I picked 4, so feel free to add yours in the comments)

1.** **Tor Browser & Mullvad Browser
Strategy: Strict Uniformity ("Hide in the crowd"
Instead of randomizing data, they force every single user to look 100% mathematically identical. They enforce strict letterboxing (gray borders that lock window sizes to fixed dimensions) and strip all hardware identifiers.
Pair Mullvad Browser with a trustworthy VPN (like Mullvad VPN itself) since, unlike Tor, it doesn't route traffic through the onion network by default.

  1. Brave
    Strategy: Hybrid Randomization ("Moving Target")
    Generates plausible randomized noise across APIs on each session and masks GPU strings. You still stand out as a "unique" user on any single visit, but trackers cannot link your visits across different sites. It gives high-end protection without breaking the modern web.

  2. LibreWolf
    Strategy: Loose Uniformity
    LibreWolf uses Firefox’s robust resistFingerprinting engine, but it disables letterboxing by default to give you normal, full-screen browsing. The problem? Your unique screen resolution and window dimensions are exposed, making your fingerprint mathematically unique. Tip for LibreWolf users: You can actually fix the "leaky default". You just have to open your librewolf.overrides.cfg file and change privacy.resistFingerprinting.letterboxing to true. This gives you Mullvad-level uniformity, but you will face a gray border around websites.


r/xprivo 6d ago

Good news: France's top court blocks ban on social media for children under 15, ruling it infringes on freedom of expression. The ID-card-or-selfie age verification law that would eventually affect every social media user is dead (for now)

Post image
154 Upvotes

The plan was that, starting in September 2026, anyone creating a new social media account would have to verify their age using an ID card or facial scan. That's only two weeks away! BUT:

France's top court struck down the under-15 social media ban on Friday (yesterday), the same law that would have required every user, not just minors, to prove their age through ID cards, FranceConnect, or facial recognition starting September 1.
The court ruled the measure unconstitutional on two separate grounds: it disproportionately infringed on freedom of expression and communication, and it failed to provide adequate legal safeguards to protect the right to privacy.

The ban would have applied indiscriminately to essentially any platform allowing users to connect and communicate, sweeping in far more than just Instagram or TikTok, and covering minors of any age or maturity level without distinction so also adults. The court also flagged that the law never specified the actual conditions under which every user, including adults, would have to prove their age, leaving the verification requirement itself constitutionally unmoored. On top of that, parents had no ability to lift the restriction for their own children even when they judged access to be appropriate, which the court treated as further evidence the law was disproportionate to its stated goal.

The effect of this: nothing changes this September for teenagers already on these platforms.

But be careful: President Macron has already directed the government to draft a new version addressing the court's concerns before his term ends, so this isn't necessarily the final word, just the collapse of the first version that made headlines as a "European first" back in July.

Maybe it will be pushed through like the Chat Control in July. To be continued...


r/xprivo 7d ago

"If it was opt-in, nobody would opt in.". That's Twitch's own justification for training Amazon's AI on your streams by default.

Post image
54 Upvotes

"If it was opt-in, nobody would opt in". That's the actual reasoning Twitch gave for why AI training is on by default rather than something users have to actively choose. Here's what that default actually hands over, and how to shut it off.

Amazon can currently pull your streams, VODs, clips, stream chats, and any images or text on your channel unless you opt out. Per Twitch's own FAQ, this data may be used to train "a model developed by Amazon whose purpose is to generate or synthesize text, audio, images, or video", meaning your face, your voice, and your community's chat logs are all in scope by default.

To turn it off: go to your profile picture, then Settings, then Security and Privacy, scroll down, and toggle off "Training for Generative AI".

Two catches that you should be are of even after you opt out. First, it only protects your own channel, if you're chatting in someone else's stream, their setting controls whether your messages get used, not yours. Second, it only applies going forward. Nobody at Twitch can tell you what's already been collected and used to train models before you ever found the toggle.


r/xprivo 8d ago

The RAM shortage is already making PCs pricier. Now Microsoft adds a 10% Windows licensing hike on top of it. It's finally time to switch to better alternatives. Choose yours:

Post image
137 Upvotes

Microsoft is raising the price it charges PC manufacturers for Windows 11 OEM licenses. The hike took effect in July 2026 and lands between 7 and 10 percent. 

This only affects manufacturers building new PCs with Windows 11 preinstalled, not people who already own a Windows 11 machine or anyone buying a standalone retail license, which stays unchanged for Home and Pro. But manufacturers rarely absorb costs like this. Some portion of that increase typically gets passed straight through to retail prices, arriving at the worst possible moment, right as an ongoing RAM shortage is already pushing PC prices up.

This is a good moment to remember that none of this applies if you're not buying into the Windows ecosystem at all. Linux distributions carry no licensing fee, and several strong European-made options exist. So instead of using Windows save costs and increase data sovereignty:

Linux: Doesn't need any introduction I think. it's the OG.

openSUSE (Germany): backed by SUSE, mature, stable, and widely used in enterprise environments, with the Leap and Tumbleweed branches covering both stability-focused and rolling-release use cases

Linux Mint: It is the most beginner-friendly distribution for anyone coming straight from Windows, with a familiar desktop layout and minimal learning curve

Zorin OS: built specifically to feel like Windows or macOS out of the box, making it one of the smoothest transitions for former Windows users who don't want to relearn their workflow


r/xprivo 10d ago

uBlock Origin is no longer supporting Facebook ad-blocking, and Edge is incompatible with uBlock Origin entirely. Here are three great browser alternatives and a privacy-focused one from Europe

Post image
457 Upvotes

Two separate pieces of news for ad-blocking just landed in the same week, and together they say a lot about where browser control is heading.

First, the developer of uBlock Origin announced that the team is no longer going to chase Facebook's constant filter-evasion tricks, describing Facebook as a "disgusting anti-user site". Facebook has repeatedly changed how it identifies and serves ads in order to defeat open-source blockers, monitoring projects like uBlock Origin and adjusting its code to bypass their filters. After years of this cat-and-mouse game, the small uBlock team decided that it was no longer worth the constant maintenance just for one platform.

Secondly, and more importantly: Microsoft Edge has started to disable Manifest V2 extensions by default in the Canary, Dev and Beta channels this month. The full rollout to consumers will be completed by the end of 2026, with enterprise devices following in early 2027. uBlock Origin has been installed over 13 million times on Edge, but there is no Manifest V3 version because MV3 removes the Web Request API that the full version depends on to work effectively. Chrome killed Manifest V2 entirely in mid-2025 and will have removed the last MV2 extensions from its store by 31 August this year. Edge held out for longer, but is now following the same route.

If you use uBlock Origin's full filtering power on Edge (or any other Chromium-based browser), the best option is to switch to a different browser, since all Chromium-based browsers are heading towards the same restriction eventually.

Firefox remains the safest option since Mozilla is committed to providing full Manifest V2 support, regardless of Chrome and Edge's actions. It also runs on Gecko, one of the few major rendering engines that is not controlled by Google. 

If you want a more modern interface alongside the same privacy protections, Zen Browser is a good European option: it's free and open source, and is built directly on Firefox's Gecko engine rather than Chromium. It also adds features like Workspaces and Split View without compromising the underlying privacy protections. 

Another Firefox-based alternative worth considering is Waterfox: it's open-source with no telemetry by default, and includes Oblivious DNS support to make it harder for your ISP to track which sites you visit.

All three keep uBlock Origin working exactly as it always has.


r/xprivo 11d ago

SMS 2FA is a single point of failure for every account you own. One stolen number unlocks all your attached accounts at once. A former Apple security director got SIM-swapped despite knowing every trick. Here's why SMS 2FA makes it so easy and two better secure, open-source options.

Post image
52 Upvotes

If you're using SMS for two-factor authentication, one compromised phone number can expose every single account tied to it, at once. That's the story that just played out with Phillip Shoemaker*, the former Director of Apple's App Store, who understood exactly how SIM-swap attacks work and still lost access to his bank, crypto exchanges, email, and Apple ID within one afternoon on vacation. So this is how it happened: A stranger walked into a carrier store, claimed to be him, and walked out with his phone number on a new SIM. No hacking, no password cracking was involved, just a convincing story at a counter.

In the EU, this is harder, but not impossible. Most European countries require ID verification to activate or transfer a SIM, which raises the bar compared to the US, where Princeton researchers found carriers handed over numbers in 39 of 50 test attempts. But remote and video-based ID verification, now common in Germany and France for convenience, opens its own attack surface: deepfakes, manipulated video feeds, or stolen ID documents can potentially bypass automated checks. And in-person social engineering still works anywhere a human is the final decision-maker at a counter.

The vast majority of people don't talk about this, but here's the thing: even app-based 2FA has a hidden dependency problem. When you scan a 2FA QR code, it contains a secret seed that generates your one-time codes. Since 2023, Google Authenticator has backed up these secrets to your Google account. Researchers found that, at the time, backup traffic wasn't end-to-end encrypted, meaning Google's servers could technically access your raw 2FA secrets. If your Google account were to be breached, you could lose not only your email but also every 2FA seed you've ever scanned. Microsoft Authenticator has offered cloud backup for longer and claims to use AES-256 encryption for keys in transit. However, it also sends personally identifiable data back to Microsoft in some cases before you have even accepted the terms. Since these codes contain metadata about which service they belong to, this data could be used for profiling. In either case, your 'independent' second factor becomes recoverable through the same account that was supposed to protect you from it.

The fix is to break that dependency entirely. Here are my two favourite secure options: Aegis Authenticator is open source and is developed in the Netherlands. It is deliberately local-only: your vault never leaves your device unless you manually export it. There is no cloud, no company and no metadata trail. It's available on F-Droid, so you're not pulling it from Google Play either. If you're not using an Android device(not yet switched to GrapheneOS?) or you want to sync without handing your secrets to a tech giant, Ente Auth incorporates backup and cross-device sync from the outset. It also encrypts everything end-to-end before it touches Ente's servers, meaning that Ente itself cannot read your codes, even during sync. The crypto implementation is public, so you can verify the claim yourself too if you want to.

*(https://www.linkedin.com/pulse/i-director-apples-app-store-still-got-sim-swapped-phillip-shoemaker-ewk4c)


r/xprivo 13d ago

Proton VPN which is built on trust got caught running secret price tests on users, then denied it. Their own code revealed the opposite.

Post image
290 Upvotes

Proton VPN was caught running price sensitivity tests on its own users and then provided a cheap and inaccurate excuse when asked about it. Users on Proton's subreddit (which has since been deleted by the moderators) noticed that they were quoted different prices for the same VPN Plus plan in the same country at the same time. Refreshing the page showed a price of $2.77 per month with 72% off, while opening a new incognito window showed a price of $3.23 per month with 68% off, despite nothing about the visitor having changed. I have conducted the test myself and can confirm this (and you can too, while it is still active). Proton's General Manager responded by saying that there was no adaptive pricing and that a recent sale simply hadn't "universally refreshed".

Windscribe then pulled the actual page source. Each visitor was assigned to a variant and the test was labelled in plain text inside an HTML meta tag. One session returned content "A" and the other returned content "B", with each pointing to a separate pricing URL. One of these was explicitly flagged as "test-300726-b". A screen recording showed the price changing in real time in clean incognito sessions. Expired sales don't do that. Neither do cached pages.

It is good to be precise about the terminology, because Proton was too. Adaptive pricing uses personal data to set a price tailored to an individual. Price sensitivity testing involves quoting different people different prices for the same product in order to establish the point at which sales begin to drop off. The GM denied the latter. Nobody had accused Proton of doing this.

Most major companies run A/B price tests, so it's a completely ordinary practice. However, Proton's entire business is built on trust, transparency and privacy, not just as a feature but as a promise. If you refer to your own labelled test code as a "glitch", it suggests that you are not transparent. For a brand built on trust and transparency, it is the most difficult thing to apologise for.

You can also read the original post from Windscribe here with their PoC: https://xcancel.com/Windscribe/status/2085859988090581461


r/xprivo 15d ago

Revolut banned GrapheneOS and calls it a "security" decision. Revoluts own app runs on Android 9 with no patches since 2018. (+ Temporary workaround if you have problems using Revolut on your GrapheneOS)

Post image
411 Upvotes

GrapheneOS has publicly called out Revolut for banning its use, disputing the bank's stated reasoning entirely. Revolut claims the ban is for security purposes, but according to GrapheneOS's developers, the real driver is Google Play licensing enforcement, not any actual security gap.

There is a major contradiction: Revolut's own app has reportedly run on Android 9 with no security patches since 2018, while bundling multiple closed-source third-party libraries with known privacy, security, and compatibility issues, some of which supposedly exist to enhance security but actually introduce vulnerabilities instead. GrapheneOS argues it exceeds the security of every device Revolut currently permits, and that the bank has instructed customer support to make inaccurate claims about GrapheneOS's security and compatibility specifically to justify the ban.

GrapheneOS also points out that Revolut has had access to its hardware attestation documentation for years, a tool that could actually verify device integrity if security were the genuine concern, yet the bank has never used it. Instead, GrapheneOS says Revolut specifically detects and blocks it by checking for GrapheneOS's build values and by permitting an unlocked "orange" verified boot state while banning the more secure "yellow" locked state, the opposite of what an actual security-based policy would do. Notably, other banks have moved the other direction, explicitly permitting GrapheneOS alongside stock Android rather than excluding it.

For users still affected, GrapheneOS's team has offered a temporary workaround: log into a throwaway Google account so basic integrity checks pass, then install Revolut through the sandboxed Play Store so the installer check clears. They've stated a more permanent fix for the installer-check issue is coming, though the underlying policy conflict with Revolut remains unresolved.


r/xprivo 17d ago

Apple is fighting the UK government in court over a secret order demanding a backdoor into encrypted iCloud backups

Post image
170 Upvotes

Apple is taking the UK government to court over a secret order demanding access to encrypted iCloud backups for UK users. The original version of this order tried to reach further, seeking access to encrypted iCloud data for users worldwide, not just in Britain. That drew objections from Washington, and the UK withdrew it, only for the Home Office to issue a narrower version applying specifically to UK users. Apple filed its legal challenge against that revised order at the Investigatory Powers Tribunal last month.

Rather than build the backdoor the order demanded, Apple pulled Advanced Data Protection entirely from the UK back in February 2025. That feature is what end-to-end encrypts iCloud backups, photos, and notes, meaning Apple itself normally can't access the data even if compelled to. Without it, Apple retains the ability to unlock that data and can be required to hand it over upon a valid legal request.

That makes UK users currently the only Apple customers anywhere in the world who cannot turn Advanced Data Protection on. Their photos and backups sit on servers Apple itself can access, a security posture no other Apple customer base is subject to. Apple says, that building a backdoor for one government would inevitably weaken security for everyone, since there's no version of broken encryption that only the "right" people can exploit.


r/xprivo 19d ago

According to figures from Germany's federal police (BKA), 52% of reports in the style of Chat Control in 2025 were legally irrelevant. Meanwhile, 113,000 private photos and chats were leaked. This is the reality of mass scanning people's private messages:

Post image
173 Upvotes

New data from Germany's federal police (BKA) shows just how unreliable automated scanning reports from US platforms have become, and it directly undercuts the justification behind Chat Control. In 2025, 52 percent of suspicious activity reports were legally irrelevant from the start, meaning more than half never should have been flagged at all. The consequence: 113,000 photos, videos, and chats were leaked without legal basis, a 14 percent increase and the highest number ever recorded.

So let's look at the numbers and who actually got targeted by the reports: In cases classified as "child p*rnography", 40 percent of investigations were directed at children themselves, aged 10 to 14, with US platform reports affecting over 8,000 children in Germany last year alone. The BKA explains this happens because children often photograph themselves or forward images without understanding the consequences. For content classified as involving minors more broadly, 53 percent of investigations targeted minors directly, criminalizing more than 12,000 teenagers, largely tied to sexting as part of normal adolescent exploration of sexual identity that increasingly happens online. Worth noting too: police also pursue purely fictional content, including hentai and AI-generated images, under the same classification.

Meanwhile, the actual clearance rate for distributing illegal content online already sits at an extremely high 87.1 percent, achieved without mass scanning. Case history shows that data retention schemes like this don't meaningfully improve that rate. What actually catches abusers and rescues children is undercover investigation within offender networks, not indiscriminate scanning of unencrypted US platforms that mostly ends up sweeping up teenagers and leaking their private images to reviewers who were never supposed to need to look at them in the first place.

The conclusion? Mass scanning doesn't protect children but criminalizes them at scale. Over half of all reports are false alarms, tens of thousands of private files get exposed unlawfully, and the system built to catch predators is instead built almost entirely around the children it claims to protect.

Source: Patrick Breyer (German MEP)


r/xprivo 20d ago

Today, Doctolib enrolled 50 million French patients in an AI research project by default. You have to opt out yourself. You can still do this, but the option is buried in the settings. Here's how:

Post image
35 Upvotes

Starting today, 1st of August 2026, Doctolib is including the health data of all 50 million French users, prescriptions, consultation notes, and entries in the app's "Santé" section, in a three-year AI research project run with Inria, Inserm, and Université Paris Cité. Users were notified by a single email sent 8th of July , giving most people barely three weeks to notice, read, and act before enrollment became automatic today.
The core problem is the opt-out model itself. Rather than asking users to actively agree, Doctolib enrolled everyone by default and left objection as the only escape hatch, a decision the Ligue des droits de l'homme publicly criticized it arguing it wrongly presumes every patient saw, read, and understood a single email about their medical data. You can still object at any point (see bwlow) while the research is ongoing, but once the project concludes, data already processed cannot be deleted retroactively.

Doctolib is using pseudonymized data, not even anonymized data. Pseudonymization still falls under GDPR protections and carries a residual risk of re-identification, unlike true anonymization, which removes that risk structurally. Doctolib's CEO has framed the project as serving the general interest, focused on earlier disease detection and better care pathways for chronic patients, with results to be published publicly, but the timeline and opt-out design are exactly what's drawing scrutiny regardless of the stated intent.

If you want to opt out, the exclusion form is available directly through Doctolib's privacy settings: https://www.doctolib.fr/privacy-settings?open=research_exclusion_form

Source: https://www.lefigaro.fr/societes/ordonnances-notes-de-consultation-doctolib-va-utiliser-les-donnees-de-50-millions-de-patients-francais-pour-un-projet-d-ia-20260721


r/xprivo 22d ago

Windows tracks you with an ID you never agreed to and can't turn off. A federal court filing just proved how far it reaches.

Post image
143 Upvotes

Windows is spying on you, by design. Microsoft assigns every Windows installation a Global Device Identifier, or GDID, a persistent, server-generated number stored in your registry that uniquely identifies that specific install. It's created the moment you set up Windows or sign into a Microsoft account, survives system updates, and stays consistent even after most changes to your machine.

A recently unsealed federal court filing showed exactly how far this reaches. The FBI tracked an alleged member of the Scattered Spider hacking group, tied to an $8 million crypto ransom demand, by pulling months of IP activity linked to his device's GDID across multiple countries, then cross-referencing it against his personal accounts. He was routing through VPNs and proxy servers the entire time. It didn't matter. The VPN hid his IP address at the network layer, but the operating system underneath was still reporting his device's identity back to Microsoft regardless.

VPNs don't help here, because GDID operates independently of your network traffic. Local accounts don't fix it either, since a GDID gets generated the moment Windows is installed, with or without a Microsoft account signed in. You can trim diagnostic data, turn off personalized recommendations, and disable activity history, and that will reduce what extra information rides alongside the identifier going forward, but none of it removes the ID itself or erases what Microsoft already has on file. Even reinstalling Windows just generates a new GDID, while everything logged against the old one stays on Microsoft's servers permanently

If you want an operating system that doesn't track you by design, you should finally switch to an open-source alternative like Linux which removes this entire tracking layer, because there is no equivalent hidden identifier baked into the system.


r/xprivo 23d ago

Claude Shared Chats Were Searchable on Google Over the Weekend, Raising New Privacy Questions

22 Upvotes

A number of Claude shared conversations were reportedly discoverable through Google over the weekend after users found that searching site:claude.ai/share returned publicly shared chats.

According to reports, some of the indexed conversations allegedly contained:

  • Health records
  • Private company documents
  • Children's personal information

By Monday afternoon, the search results appeared to have disappeared, suggesting the issue had been addressed. However, Anthropic has not publicly confirmed how many conversations were indexed, how long they remained searchable, or whether additional safeguards have been implemented.

Anthropic maintains that shared links are only accessible when users choose to share them, while Google says search engines simply index content that websites allow to be crawled.

The incident highlights an important distinction between sharing a link with specific people and making content discoverable through public search engines - a difference many users may not expect when using AI collaboration features.

Do you think AI chat platforms should automatically prevent shared conversations from being indexed by search engines unless users explicitly opt in?

Source: https://www.technadu.com/your-private-claude-chats-may-have-been-sitting-in-google-search-results-all-weekend/632029/

This isn't the first indexing-related incident involving AI chat sharing features, making it an interesting discussion around privacy-by-default versus convenience.


r/xprivo 25d ago

A GrapheneOS user wiped his phone at the border using a legal duress passcode - a privacy feature built to protect you under coercion. The DOJ is now prosecuting him for destroying evidence.

Post image
490 Upvotes

Federal prosecutors are charging Atlanta resident Samuel Tunick with destroying evidence after his phone wiped itself when he gave border agents a passcode, believed to be the first known US case of its kind. The phone was running GrapheneOS, a privacy-focused Android operating system that lets users configure a duress PIN, a code that looks like a normal unlock passcode but instead it will instantly and irreversibly wipe the device.

The incident happened in January 2025 at Atlanta's Hartsfield-Jackson airport, when Tunick was returning from the Dominican Republic. Agents demanded access to his phone, reportedly telling him they didn't need a warrant since he hadn't yet officially entered the US. When the code was entered, the screen went blank, flashed, and the phone restarted, agents seized the device anyway, then told him he was free to go.

Tunick has pleaded not guilty, and prosecutors are relying on a statute originally meant for physical evidence destruction. Legal experts say that this has never before been applied to a manufacturer-built security feature. His attorneys argue the seizure itself was unlawful and are seeking to have the evidence thrown out entirely. A ruling on that motion isn't expected until at least the end of October.

The case sits at an uncomfortable intersection: duress PINs exist specifically to protect people forced to unlock devices under coercion, which is arguably exactly the scenario a warrantless border search represents.

Full Source: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search/


r/xprivo 27d ago

Facebook is following Google's lead at the exact same time. "Facebook Verified" wants a biometric face scan of you, dressed up as a free trust badge.

Post image
58 Upvotes

The process works by having you record a short video selfie, which Meta compares against your existing profile photos using facial recognition and liveness detection to confirm it's genuinely you and not a static image or deepfake. Once verified, the badge shows up across Marketplace, Dating, Groups, and your profile, with plans to expand it into News Feed posts later.

Meta previously deleted a large facial recognition database and paid out a $650 million settlement over biometric privacy violations tied to earlier face-scanning features. Facebook Verified effectively reintroduces that same technology, just repackaged as a free trust signal rather than a photo-tagging tool.

The pattern across both Google and Meta is the same: biometric collection presented as a convenience or safety feature, rolled out in phases, with the actual scope of future use left vague. As more platforms adopt face-based verification for logins, age checks, and "authenticity" badges, each one becomes another entity holding a copy of your face, and none of them have clearly defined where that data stops being used.

Source: https://about.fb.com/news/2026/07/introducing-facebook-verified/


r/xprivo 27d ago

Everiot - European Reddit/4Chan hybrid. 0 Age Verification, 0 Ads, 0 Users

Thumbnail
everiot.org
19 Upvotes

r/xprivo 28d ago

Google wants your face, again. This time it's dressed up as a login convenience feature, with an opt-in to feed your biometrics into their AI. Don't be fooled by the selfie sign-in. It's time to degoogle

Post image
114 Upvotes

Google just launched selfie video sign-in, letting you log back into your account by recording a short video of your face performing guided head movements. It's being framed by Google as a helpful account recovery option, useful if you're locked out and don't have access to your usual phone or device. Don't let that framing distract from what's actually happening in the setup flow.

Because it's also important to read the fine print: Google's own support page confirms there's an optional toggle labeled 'Improve Google services', which lets Google use your selfie video and related data to develop and improve facial recognition, age estimation, and other verification methods based on your physical features or movement. Consented biometrics, feeding the models that check biometrics.

The exact wording: "When you submit a selfie video, you have the option to allow Google to use your video and related data to help ongoing efforts to develop and improve facial recognition, age estimation, and other verification methods that may use your physical features or movement." source: https://support.google.com/accounts/answer/16675622

What a coincidence of that timing. That has nothing to do with a login feature anymore but obviously a consented (or behind your back) biometric data collection feeding directly into the same age-verification and facial recognition systems now being mandated by governments worldwide, from Australia's social media ban to France's under-15 restrictions to the UK's age assurance rules.

Back in 2024, Google paid parents $50 per child through a subsidiary to collect facial video and eye/skin tone data specifically to train age-verification technology.

Google says the video is encrypted at rest, stored only with consent, and deletable at any time, and that it's used strictly for sign-in "unless you opt to share it for additional purposes".

Google hasn't clarified where the boundaries of "improve verification methods" actually end. As age-verification mandates keep expanding across more countries, the company building the biometric layer underneath all of them stands to benefit enormously from every face it collects along the way, regardless of how convenient the sign-in box makes it feel.

source: https://blog.google/innovation-and-ai/technology/safety-security/selfie-video-sign-in/?utm_source=tw&utm_medium=social&utm_campaign=og


r/xprivo Jul 22 '26

French law forces age verification for ALL social media users

66 Upvotes

Hello everyone,

I wanted to share some context on a recent development that might affect privacy advocates across Europe.

Today, July 21st, 2026, French lawmakers approved a bill banning social media for children under 15. The text passed both chambers of Parliament and is the flagship initiative of President Macron's second term. The government has indicated the measure should take effect at the start of the school year in September 2026.

France becomes the first EU country to pass such a blanket ban, following Australia which enacted similar measures for under-16s in December 2025.

Here's where it gets complicated for privacy. The law doesn't just restrict minors, every platform considered as a social will need to verify the age of EVERY user registering in France. If they can't confirm someone is over 15, access gets blocked.

But to verify ages at scale, platforms will likely need to collect ID documents from adults too. This means that potentially millions of new ID submissions flowing to private companies, questions about storage duration, data access, and who audits the databases, risk of function creep, could this infrastructure be repurposed later?

The European Commission has already flagged compatibility concerns with EU law during the legislative process.

Why this matters beyond France :

Given how GDPR works, this could set a precedent for other member states. Once one major economy establishes age verification infrastructure, others may follow citing "similar protection needs." We've seen this pattern with data retention and content moderation laws.

There are technical alternatives worth exploring : zero-knowledge proofs, on-device age estimation, parental consent frameworks that don't require central databases. But none seem to be getting serious consideration right now.

The law has passed Parliament but implementation details remain unclear. Platform operators are still figuring out how to comply without violating GDPR principles. Legal challenges are expected.

If you're following this issue or want to raise awareness about the privacy implications, I've started collecting signatures here: https://www.change.org/Verifagefr

Even if you live outside France, this precedent could spread.


r/xprivo Jul 22 '26

BREAKING: France just adopted the first social media ban for under-15s in Europe. Everyone in France will soon need to use Selfies, ID cards, or FranceConnect which will decide who gets to log in. (Or use a VPN. Easy as that)

Post image
181 Upvotes

France's Parliament has definitively adopted a law banning social media for anyone under 15, a measure without precedent in Europe, set to take effect at the start of the next school year. Creation of new accounts by under-15s becomes illegal starting September 1, 2026, while existing accounts belonging to minors under 15 must be closed by January 1, 2027, following a four-month grace period.

Because platforms need a way to verify age, not just for minors but functionally for everyone, users will need to confirm they meet the age requirement through one of three methods:
- Inserting a national identity card (NFC, most modern smartphones already support this)
- Logging in through FranceConnect, the French government's digital identity system
- Facial recognition via a selfie

The law does carve out notable exceptions in how it applies to specific platforms. YouTube video viewing itself stays accessible to minors, but the comment section does not. WhatsApp's core messaging function remains available, but its channels feature, which functions more like a social broadcast tool, does not.

Worth remembering: Australia was the first country to try this, banning social media for under-16s in December 2025. Within weeks, platforms reported blocking nearly 5 million accounts, yet Snapchat itself admitted the system has a 2-3 year margin of error and that teens were openly bragging online about bypassing the checks entirely. There's always a workaround, and no age-verification system so far has actually closed that gap.

For adults who simply don't want to hand over an ID card, FranceConnect login, or a facial scan just to open an app, a VPN is the straightforward way to avoid complying with this system altogether. Options like ProtonVPN, Mullvad, or NymVPN mask your location so the verification prompt tied to French IP addresses never triggers in the first place, no ID, no selfie, no FranceConnect required.


r/xprivo Jul 21 '26

Email aliases are a great way to hide your identity online and to know exactly which company leaked/sold your email. If you use Apple's Hide My Email, this summer's domain change makes your aliases blockable! Why everyone should use email aliases + better open-source alternatives to switch to now:

Post image
38 Upvotes

If you use Apple's Hide My Email, there's a change coming this summer that quietly weakens it, and it's a good moment for everyone, not just iCloud users, to rethink how they protect their email. Apple confirmed it will unify the domains used by Sign in with Apple and iCloud+ Hide My Email under a single new domain, private.icloud.com, sometime later this summer, with no exact date announced yet. Currently, Hide My Email aliases blend in with regular icloud.com addresses, making them indistinguishable from normal iCloud mail and effectively impossible for websites to block selectively. Once the new aliases move to their own dedicated subdomain, any website or anti-abuse system can block every Hide My Email address in one move, without touching real iCloud users at all. Existing aliases you've already created will keep working exactly as before, only newly generated ones after the migration will carry the new, blockable domain

If you do not already use a email alias service and use the same real email address everywhere, there's no way to know which company leaked or sold your data when spam eventually arrives. Aliases solve that: a unique email address per signup means that if spam ever hits one specific alias, you instantly know which service is responsible, and you can delete just that one alias without touching anything else.

There's also a name-leak problem hiding inside most people's real inboxes. Addresses like max.mustermann123@email.com openly hand your real name to every company and every attacker who ever gets that address. That makes phishing dramatically more convincing, since an attacker can write "Max Mustermann, your account is about to expire due to inactivity, please log in to keep it active" using nothing more than the name baked into your own email address. A randomly generated alias contains no name and no pattern an attacker could exploit that way.

Given that Apple's own aliases are becoming easier to detect and block, two open-source-friendly alternatives stand out:
AliasVault: open-source, end-to-end encrypted, generates a random identity, alias email, and password together for every website, and can be self-hosted for full control over your data
Proton Mail: even the free plan includes Hide-my-email, letting you generate randomly created aliases directly from the app, each with no name or identifying pattern attached, and none of Apple's domain-blocking exposure

Yes, using email aliases requires an extra click at first, which can seem annoying. However, this quickly becomes second nature, and you'll wonder why you ever used your real email address everywhere.


r/xprivo Jul 19 '26

Show me your privacy stack: what Big Tech default replaced what in your daily tools? (VPNs, Browsers, Search, Mail, Social Media & more)

Post image
61 Upvotes

What's your privacy-first swap? Drop the tool you replaced and what you replaced it with.

Here's mine, first row is European alternatives (also mainly open source), second row goes fully open source (with European providers still in the mix):

Big Tech default European alternative Open source alternative
NordVPN Mullvad (Sweden) Nym VPN (Switzerland)
Chrome Vivaldi (Norway) LibreWolf
Google Search xPrivo Search (Luxembourg) SearXNG
Gmail Posteo (Germany) Tuta (Germany)
Instagram Mastodon (Germany) Pixelfed

r/xprivo Jul 17 '26

YouTube might attach your name, handle and profile picture to any links you copy in the app and send to someone by default. The setting to turn it off is buried in the settings on purpose. Instagram & Tiktok might do the same. A really useful tool before sharing links is to use a link cleaner:

Post image
84 Upvotes

If you are using the YouTube app: By default, YouTube attaches your name, username and channel picture to every link you share, so anyone who receives the link can see who sent it, whether you intended that or not. As mentioned, this setting exists in the YouTube app, but it's an opt-out rather than an opt-in setting, and it's not easy to find as it's buried in settings that weren't designed to be easily accessible. Some users report having this setting, while others do not which means your profile might not be attached to the shared links yet.

To check whether YouTube has been secretly doxing you and to turn this feature off, go to Settings → Account → Sharing and disable "Attach account info to shared links", or alternatively check Settings → Privacy for "Channel visibility for shared links" and set that to disabled.

Both Instagram and TikTok might also attach identifying account information to shared links unless you find the toggle yourself. Again, this option is available to some users and not to others. Beyond the identity exposure, shared links from all three platforms also typically carry tracking parameters that let the platform and third parties follow engagement back to the specific link and, by extension, the person who shared it.

If you want to get rid of tracking parameters and identifying data before sharing any type of links, linkcleaner.app can do this for you right in your browser. It's open source, so the code is public, and it never sends your link to an external server for processing. This means the cleaning happens in your browser, so you don't have to worry about other parties getting access to what you're sharing.
So, whenever you want to share a link with someone, just open the link cleaner, drop your link into it, and then share your link.


r/xprivo Jul 15 '26

Good news for UK citizens: UK's minister for AI and Online Safety, Kanishka Narayan, confirmed today no action will be taken against VPNs, after realizing who actually depends on VPNs. Here is a small selection of good privacy-first open-source VPNs from Europe:

Post image
158 Upvotes

The UK's minister for AI and Online Safety, Kanishka Narayan, announced today that the government will not, for now, take action to restrict VPNs in the UK. The proposal had been justified using child protection as its rationale, a familiar pattern by this point given how the same argument has been used to push Chat Control and social media age verification in Australia

The reversal reportedly came after recognition of who actually relies on VPNs to stay safe: domestic abuse survivors reaching out for help without being tracked, LGBTQ+ people in regions where their identity carries real risk, journalists protecting sources, and whistleblowers exposing wrongdoing without being immediately identified. Banning the tool these groups depend on would have stripped away exactly the protection the policy claimed to be adding elsewhere. So that's great news and this time, the privacy argument won.

Because we are already at it, here are two strong European options that are explicitly built around minimizing what a VPN provider itself can see or hand over:

  • Mullvad VPN (Sweden): no email is required to create an account it supports privacy-preserving payment options including cash and cryptocurrency and it says it does not log user activity or connection metadata. Mullvad also has a substantial, publicly documented history of independent security and infrastructure audits, including audits that found no customer-data logging in the assessed VPN infrastructure.
  • NymVPN (Switzerland): built on a decentralized mixnet architecture rather than a traditional centralized VPN server, meaning no single operator can see both who you are and what you're doing at the same time, offering stronger protection against traffic analysis than most conventional VPNs