» Tag
privacy
64 postsPopular ModHeader Chrome Extension Exfiltrates User Data
Reverse engineering reveals ModHeader, a 1.6M-install Chrome extension, secretly exfiltrates encrypted browsing data via a hidden AES-GCM pipeline.
File-Notification APIs Leak User Activity Across Linux, Android, Windows, macOS
CCS 2026 research shows file-notification APIs on Linux, Android, Windows, and macOS leak user activity by bypassing intended permission boundaries.
UAP: An Open Ad Protocol That Can't Touch LLM Answers
UAP is an open, vendor-neutral protocol letting any LLM provider sell ads without altering answers or leaking conversation context.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comChrome Extension Secretly Exfiltrates AI Prompts to Vendor Servers
A Chrome extension silently captures and exfiltrates AI prompts and responses from 9 platforms, contradicting its own privacy store declaration.
A schema-only classifier that finds personal data without reading it
A rule-based classifier maps personal data from database schema alone, never reading values, with published benchmarks and honest failure modes.
How to Build a 3-Tier On-Device AI Concierge
Learn to set up a 3-tier AI chat widget running on the visitor's browser at zero cost.
Reverse-Engineering Apple's Find My Friends API on Linux
How a developer reverse-engineered Apple's undocumented Find My Friends API on Linux, covering MobileMe tokens, IDS registration, and APNs anisette headers.
CacheTracer Exposes Hidden Dependencies in LLM API Reseller Chains
CacheTracer uses prefix-cache side channels to reveal hidden dependencies among LLM API resellers, finding shared cache reach in 37% of tested pairs.
OONI Finds 6 Italian ISPs Blocking Abortion Info Sites via DNS
OONI's report reveals DNS tampering by six Italian ISPs blocking abortion information sites Women on Web and Women Help Women since February 2026.
Shark Vacuum AWS Cert Flaw Lets One Key Hijack an Entire Fleet's Root Shell
A stolen AWS certificate lets attackers run root commands on any Shark robot vacuum in the same cloud region, exposing cameras and Wi-Fi credentials.