devtake.dev

#privacy

RSS
Brave Origin promotional graphic from Brave's announcement blog
Web·

Brave's browser got bloated with crypto and AI. Origin strips it back for $60

Brave released Origin, a paid version of its browser that compiles out Leo AI, the crypto wallet, Rewards, Tor, and the VPN. A one-time $59.99 buys it, and Linux is free.

A consumer M.2 solid-state drive, the kind of storage the FROST attack times from a browser tab
Web·

A browser SSD timing trick can fingerprint your browsing, and cookies won't stop it

Graz researchers built FROST, a browser side-channel that times SSD activity to guess which sites and apps you're running. Here's how it works and what helps.

Mozilla *Privacy Not Included graphic illustrating a car as a privacy nightmare, with data flowing out of the vehicle.
Security·

Your car logs every hard brake, and the FTC just banned GM from selling it for five years

Connected cars collect location, driving behavior, in-cabin audio, and synced contacts, then route it to automaker clouds, brokers, and insurers. Here's how to stop it.

US military personnel walking with smartphones, illustrating phone location data exposure
Policy·

Adversaries are tracking US troops with the same phone-location data advertisers buy

A Wired investigation and a CENTCOM letter to Senator Wyden confirm enemies are tracking US troops through commercial phone location data. Here's how the broker pipeline works.

DuckDuckGo's 'No AI' search promotion, the page the company points users to when they want AI features turned off.
Web·

Google said people love AI search. DuckDuckGo's installs jumped 30% the next week.

DuckDuckGo's US downloads climbed about 30% and its no-AI search page saw 28% more visits the week after Google's I/O push. The backlash is now measurable.

Apple Newsroom illustration for end-to-end encrypted RCS messaging beta.
Apple·

iOS 26.5 brings encrypted texting between iPhone and Android. Group chats and metadata still leak.

Apple and Google began rolling out end-to-end encrypted RCS on May 11. The MLS-based encryption rides on GSMA Universal Profile 3.0, but EFF says the rollout leaves real gaps.

Abstract illustration of health data and digital privacy
Policy·

Palantir contractors are getting 'unlimited access' to NHS patient data before it's anonymized

NHS England created an admin role giving Palantir staff access to identifiable patient data. The £330M contract's break clause arrives in March 2027.

Abstract illustration representing VPN connections and digital privacy
Policy·

The EU called VPNs 'a loophole that needs closing.' Proton's UK signups rose 1,800%.

An EU Parliament briefing and Executive VP Henna Virkkunen both flagged VPN circumvention of age verification. The UK's attempt to solve it backfired into record VPN adoption.

Abstract visualization of data exposure through code
Security·

380,000 vibe-coded apps are sitting on the open web. 5,000 of them are leaking real data.

RedAccess found that AI coding tools like Lovable, Base44, and Replit default to public hosting, leaving medical records, bank internals, and corporate secrets indexed by Google.

Instagram app feature illustration
Policy·

Meta pulled encryption from Instagram DMs today. WhatsApp and Messenger keep theirs.

End-to-end encryption is gone from Instagram DMs as of May 8. Meta cited low adoption for a feature it never turned on by default.

A padlock on a chain, illustrating credential security.
Security·

Microsoft Edge keeps every saved password in cleartext memory. Microsoft calls it 'by design'.

A researcher showed Edge decrypts the entire password vault at launch and leaves it in process memory. Chrome decrypts on demand. Microsoft says it's intentional.

A padlock chained to a smartphone displaying a lock icon, illustrating data privacy.
AI·

OpenAI's Privacy Filter is a 1.5B PII redactor that ships under Apache 2.0. Here's what it actually does.

OpenAI released Privacy Filter on April 22 as an open-weight on-device model for masking eight types of PII. F1 of 96%. Runs in a browser. Here's the catch.