» Tag
privacy
51 postsPopular ModHeader Chrome Extension Exfiltrates User Data
Reverse engineering reveals ModHeader, a 1.6M-install Chrome extension, secretly exfiltrates encrypted browsing data via a hidden AES-GCM pipeline.
Chrome Extension Secretly Exfiltrates AI Prompts to Vendor Servers
A Chrome extension silently captures and exfiltrates AI prompts and responses from 9 platforms, contradicting its own privacy store declaration.
A schema-only classifier that finds personal data without reading it
A rule-based classifier maps personal data from database schema alone, never reading values, with published benchmarks and honest failure modes.
CommitBrief — AI code reviews, right in your terminal
A provider-agnostic, local-first CLI that reviews your staged changes, a historic range, or a whole GitHub pull request. Zero telemetry, no server. Free and open source.
commitbrief.comHow to Build a 3-Tier On-Device AI Concierge
Learn to set up a 3-tier AI chat widget running on the visitor's browser at zero cost.
Reverse-Engineering Apple's Find My Friends API on Linux
How a developer reverse-engineered Apple's undocumented Find My Friends API on Linux, covering MobileMe tokens, IDS registration, and APNs anisette headers.
OONI Finds 6 Italian ISPs Blocking Abortion Info Sites via DNS
OONI's report reveals DNS tampering by six Italian ISPs blocking abortion information sites Women on Web and Women Help Women since February 2026.
Shark Vacuum AWS Cert Flaw Lets One Key Hijack an Entire Fleet's Root Shell
A stolen AWS certificate lets attackers run root commands on any Shark robot vacuum in the same cloud region, exposing cameras and Wi-Fi credentials.
AI Coding CLI Uploads Entire Git History, Bypassing Privacy Opt-Out
An AI coding CLI was found silently uploading full Git history and secrets to vendor storage, bypassing the privacy opt-out users trusted.
NilaMind: A Fully On-Device 1.5B LLM for Mental Health Support
NilaMind runs Qwen2.5-1.5B via llama.cpp fully offline on Android, with crisis safety enforced by a deterministic, model-independent gate.
Claude Code's Hidden Telemetry Sparks China NVDB Warning
Claude Code quietly sent user location and identity data without consent in its April-June 2026 builds. China's NVDB flagged it; Anthropic is rolling the mechanism back.