Automobile Camouflage to Hide from Flock Cameras
Not sure it’s practical, but it’s certainly striking.
Not sure it’s practical, but it’s certainly striking.









First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be.
California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027. Operating systems set up before that date in California will need to do the same by July 1, 2027.
Operating systems will categorize people into four age brackets: under 13, 13–15, 16–17, and 18+. They will then be able to send a non-identifying age signal to app developers. Developers must request that signal from the operating system provider or app store when someone downloads and launches an app. This makes them legally aware of the person’s age bracket.
California wants to stop children from doing things that could hurt them. Kids shouldn’t be able to download apps containing mature content meant only for adults, for example. Age assurance also goes hand in hand with social media restrictions, and Meta recently agreed to put time limits on kids’ social network use as part of a massive court settlement. Another California bill, AB1709, would restrict addictive social media features for children under 16. Measures like these need some form of age assurance to function.
This makes digital rights activists unhappy. The Electronic Frontier Foundation (EFF) isn’t a fan of age verification. It accused California of “outsourcing censorship to developers” through the DAAA rather than focusing on privacy.
The EFF was also uncomfortable with the effect of all this on open-source systems. Age verification requires time and effort from operating system developers. That’s fine if you’re Microsoft, Apple, or Google with a massive development budget. But it’s more problematic for operating systems developed by volunteers, such as Linux distributions. Those that don’t have the resources to comply, or don’t like the privacy implications, might prefer to avoid the Golden State altogether.
GrapheneOS, a privacy-focused mobile operating system that strips Android of its surveillance functions, took that option. In March, it said that it wouldn’t implement age verification, and would happily forego sales of devices running its software in certain regions, if necessary.
Assembly member Buffy Wicks, who introduced the original DAAA, has been listening. She tweaked the legislation with Bill AB1856, which would amend the law to exempt certain open-source operating system providers. California lawmakers passed the bill in late August, and it is now awaiting the governor’s decision.
AB1856 would exempt software that follows open-source rules, allowing it to be reused and built upon by others. This includes software distributed under common licenses such as GPL, MIT, BSD, and Apache. Not one single lawmaker voted against it.
California isn’t alone in mandating the collection of age brackets. Colorado’s SB26-051, now law, does something similar. Legislators there also added parallel open-source exemptions after lobbying by Linux hardware maker System76. Illinois has also passed age assurance legislation, and New York has a bill in the works.
Exempting open-source operating systems from California and Colorado will please privacy-conscious users, but it’s worth noting that some Linux distributions are going ahead with age assurance anyway. Many have drawn a line in the sand, others, like Fedora, are reportedly planning to do it anyway.
In any case, those using more mainstream operating systems can expect a “How old are you?” or “What’s your birthdate?” question sometime soon. If you’d rather avoid that, consider an open-source operating system instead. Just check with your distribution’s maintainers to see what their plans are.
From reporting threats to removing them.
Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.
A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards.
The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports.
The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise.
The FBI’s New Orleans field office has opened an investigation into an apparent breach involving identity verification provider IDScan.net. The company said it was investigating.
IDScan.net advertises as follows:
“We provide simple, secure solutions to help dispensaries reduce liability and protect their licenses by validating IDs, including a customer’s age, in a matter of seconds.”
The allegedly exposed records were especially concerning because some included more than a basic photo of an ID. KrebsOnSecurity found records containing front-and-back images, as well as infrared and ultraviolet scans, with timestamps that appeared to align with the holders’ travel or car-rental activity.
That matters because a driver’s license is far more useful to an identity thief than a password. You can reset a password. You cannot easily replace your face, date of birth, address, or license number, particularly when they’re accompanied by high-resolution images of your government-issued ID.
Age verification has become a common justification for asking people to upload an ID, take a selfie, or submit both to a third-party identity verification provider.
We have previously warned about the privacy and security trade-offs in age-verification systems, particularly those that require people to submit copies of government-issued ID. Such systems can turn a request to access a website into a decision to share an enduring identity document with a company the user may never have heard of.
In our opinion, that is a disproportionate risk. Once someone uploads an ID, the service or its vendor can potentially link the visit to their identity. If the provider is breached, the consequences can extend well beyond unwanted marketing or an exposed email address.
The reported Nexus dataset illustrates a broader concern: Identity documents are collected in many places that people may not connect with one another. Each individual collection may be presented as routine, but together they create an ever-expanding ecosystem of organizations, contractors, software platforms, cloud services, and privacy policies.
Facial images and ID copies can be reused. Criminals may use them to make scams more convincing, pass weak identity checks, or assemble detailed victim profiles from records obtained from separate breaches. An attacker who knows your name, address, date of birth, email address, and license details has a useful foundation for fraud.
This is why “we only need to verify your age” should not automatically mean “please upload your driver’s license” or another form of ID.
When an ID check is required to use an online service, ask a basic question: Why does this company need a copy of my identity document, and what happens to it afterward? The scale of the data reportedly offered through Nexus shows why the answer matters.
Consumers cannot always refuse an ID check, particularly where it is legally required or necessary for a regulated service. But you can reduce unnecessary exposure:
Let’s face it, an incognito window can only do so much.
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance.
Comcast has added motion detection as a feature to its wireless routers:
The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app also lets users see live motion activity and a feed of recent activity.
Comcast acknowledges that the system has some limitations. Home size, layout, building materials, and the placement of the router and connected devices can all affect its ability to detect motion. Comcast says it does not guarantee its performance.
Sounds like a great surveillance tool. And also:
But the biggest privacy concern comes directly from Comcast’s own support page, which says information generated by WiFi Motion may be shared with third parties.
“Comcast may disclose information generated by your WiFi Motion to third parties without further notice to you in connection with any law enforcement investigation or proceeding, any dispute to which Comcast is a party, or pursuant to a court order or subpoena,” the page reads.
Android 17 becomes the first major mobile OS to enable Encrypted Client Hello (ECH) by default, hiding visited website names from ISPs and network eavesdroppers.
Related Posts:
The post Android 17 Enables Encrypted Client Hello by Default to Hide Website Names appeared first on Daily CyberSecurity.


Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety.
It’s a neat phrase, except I don’t like to see “compromise” and “privacy” that close together.
“When people talk about just one of these, privacy or safety, they’re prioritizing the wrong thing, and what we have to prioritize as a country is compromise.”
Langley call for compromise comes as the company faces intensifying resistance to its automated license plate reader (ALPR) network. The opposition has begun to affect Flock commercially and operationally, with agencies disabling cameras or canceling contracts.
The problem is that the public has already been doing the compromising: People’s movements have been routinely captured, stored, searched, and, in some cases, shared far beyond the communities that installed the cameras.
Flock’s ALPRs collect detailed records of where vehicles travel, then make that data available to law enforcement for investigations. Langley now says the company wants more regulation and accountability. Flock says it’s reducing its recommended default retention period to seven days and will require case codes for law enforcement and an audit tool designed to flag suspicious access by the end of the year.
Those are welcome concessions, but they do not resolve the underlying concern: A rapidly expanding, privately operated surveillance network can turn ordinary travel into searchable historical data.
The opposition has not faded; it has intensified. NPR reports that cameras have been vandalized in at least 36 states. Vandalism is neither a productive nor lawful answer, but its spread offers a useful measure of how profoundly many people feel excluded from decisions about surveillance in their communities.
A genuine compromise would not start with the assumption that widespread collection is inevitable and then negotiate the retention period. It would begin with democratic consent, strict limits on how the data can be used, independently enforceable access controls, public reporting, meaningful opt-outs where possible, and a clear requirement that surveillance be necessary and proportionate.
Calls to meet halfway are also harder to take seriously when the CEO has been accused by 404 Media of misleading police about the outlet’s reporting on an abortion-related case. According to 404 Media, his account is contradicted by court records and police reports. That accusation makes his public calls for compromise much harder to accept.
Flock is right about one thing: There needs to be accountability. But calling for “compromise” after the cameras are already up sharply limits the choices left to communities. Privacy is not a bargaining chip to be surrendered whenever surveillance vendors promise safety.
Browse like no one’s watching.
Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free →
A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports.
The post Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers appeared first on TechRepublic.
Ring’s new TAKE encryption limits video-key retention while keeping cloud AI features, Ring Verify, and optional end-to-end encryption in play.
The post Ring’s New TAKE Encryption Deletes Video Keys Without Giving Up AI Features appeared first on TechRepublic.
A smart monitor can do far more than display a PC. Built-in apps, ACR, and advertising systems can introduce additional privacy considerations.
The post Do Smart Monitors Track You? What Buyers Should Know appeared first on TechRepublic.
OpenAI banned Russian ChatGPT accounts tied to a covert influence campaign involving copied research, fake attribution and coordinated social posts.
The post OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign appeared first on TechRepublic.