❌

Reading view

There are new articles available, click to refresh the page.

Apple changes full-disk access permissions to curb abuse from AI agents

Apple says it is changing its macOS privacy settings to stop third-party app developers from misusing them to access message histories.

Friday's announcement comes two weeks after tech columnist Jason Aten said that Meta’s new general-purpose AI agent Muse sent him an unsolicited notification referencing a thread between him and a co-worker over Apple Messages. Aten said he never granted Muse permissions to read his messages and had assumed they were off-limits. Social media last week blew up with masses of people who agreed and said the incident showed that AI assistants given access to calendars, emails, messages, shopping accounts, and other resources are akin to a skill saw or other power tool. While potentially useful, they can do real damage if not used carefully.

He said/she said

Meta CTO David Singleton joined the fray with a rebuttal that appeared solid. For Muse to access Apple Messages, a user must manually give it two privileges. One is full-disk access, a macOS system-level permission. The other is to enable a Messages connector setting in Muse.

Read full article

Comments

© Aurich Lawson

Florida cops say they don't know who owns 11 unpermitted Flock cameras

Florida cops are facing questions after a mandate to remove all Flock cameras tracking cars on St. Lucie County roads led local police to uncover more than a dozen suspicious cameras operating without permits.

Local residents told The Washington Post that they were alarmed that no one knows who owns many of the mysterious cameras.

Of the 14 cameras found, 11 had no obvious owners, raising concerns about who has access to sensitive data that bad actors could abuse. After the cameras were discovered, St. Lucie County Commissioner James Clasby told a local news outlet that there’s “potential for non-law enforcement to have cameras out there, and I’m not OK with that.”

Read full article

Comments

© Barry Winiker | Stockbyte Unreleased

Amazon’s delivery driver smart glasses will reportedly take photos ‘almost constantly’

Amazon’s Amelia smart delivery glasses, with tinted lenses and cameras.

Amazon deliveries could soon come with a new catch: the delivery driver's smart glasses will be snapping photos of anything they see while they're in use, including people and private property. Bloomberg reports that the glasses could take "several thousand captures in a single driver's typical shift," which Amazon plans to upload to its AI Wellspring platform. When asked if customers will be able to opt-out of this, Amazon's Viraj Chatterjee told Bloomberg, "We haven't thought about that."

Chatterjee claimed Amazon's only using the data from the glasses to "enhance the delivery process," adding, "The intent has never been stuff like surve …

Read the full story at The Verge.

This study looks at how and with whom connected cars share your data

In news that should surprise very few, connected cars remain a complete privacy nightmare. But now we have a better idea of what data those cars are giving away, and to whom, thanks to a study conducted by a team of researchers at Northeastern University and Consumer Reports. Testing 21 cars from 19 different brands revealed patterns of traffic to advertisers and trackers, as well as data shared with Big Tech firms like Microsoft and Adobe. And using a car’s companion app can multiply the problem, their testing found.

In 2023, the Mozilla Foundation published a widely covered report looking at the privacy policies of more than two dozen automakers. They were appalled, writing that “cars are the worst product category we have ever reviewed for privacy.” But that analysis was conducted by sitting down and reading all the various privacy policies of each brand; today’s study involved measuring traffic from actual cars under a number of scenarios, including idling and being driven. The researchers even parked 11 cars—just the electric ones—in a Faraday tent to see if the loss of a cellular signal would push that traffic to the car’s Wi-Fi connection instead.

Attempts to actually see what was in the data packets using modified certificates failed in every case. But “the network traces still yielded valuable information, including the domains contacted via DNS traffic, Server Name Indication (SNI) in TLS handshakes, the volume and timing of transmissions, and differences in behavior across experimental scenarios,” they found.

Read full article

Comments

© Getty Images

Your car’s data privacy problems are worse than you think

hands on steering wheel in a BMW

You hear it all the time: Modern cars are basically smartphones on wheels. And just like the phone in your pocket, the car in your driveway collects vast amounts of data - tracking where you drive, how fast you accelerate, how hard you brake, how aggressively you turn, and much more.

The legality of this data harvesting remains hotly debated. Last year, the Federal Trade Commission penalized General Motors for illegally collecting and selling precise location and driving behavior data without informed consent. Other automakers, like Ford and Honda, have faced minor fines for making it overly difficult for customers to opt out. While industr …

Read the full story at The Verge.

❌