Privacy

US Judge Rules Flock Search Was Mass Surveillance. Bernie Sanders Proposes 'Ban Flock Act' (msn.com) 2

Flock's cameras offer "indiscriminate mass surveillance," a U.S. federal judge wrote in a ruling Thursday, as does any system with "continuously updated" location histories for all the vehicles filmed by automated license plate-reading cameras.

The judge's ruling included italics for emphasis when describing "the question of why is it the government's business where everyone goes all the time?" Judge Hill: We might reasonably expect our friends and family to tell us something like: "Hey, I saw you out driving by the store last week." But we do not expect people we know — let alone strangers, and especially not law enforcement — to randomly approach us to say: "Hey, I have been following your car for the last 30 days, and here is a detailed log of every place your vehicle has been with supporting photographic evidence. I am also going to share this information with law enforcement throughout the country so they know your whereabouts, too...."

Cell phones also move in public places where people can see you in plain view. But it becomes constitutionally problematic when law enforcement can indiscriminately and passively catalog your whereabouts over an extended period of time and then use that information for any purpose whenever convenient... [I]t is also consequential that we are not just dealing with stationary cameras. The cameras on [police officer] Alaniz's vehicle itself feed information into these systems... It is also no longer difficult to imagine law enforcement using a fleet of drones hovering over an entire city so they don't miss the movement of a single vehicle.

Officer Alaniz had used Flock's travel history for a car when deciding to pull over its driver, which eventually led to a vehicle search and charges of possessing drugs with intent to distribute. But the judge wrote that because this violated reasonable expectation of privacy, "all evidence obtained after Alaniz initiated the ALPR search must be suppressed as fruit of the poisonous tree." The judge granted a motion to "suppress all evidence obtained as a result of these unconstitutional searches and seizures."

The Washington Post got this comment from a Flock spokesperson about the judge's ruling: "we expect it will be appealed and ultimately overturned." (Flock's spokesperson added that the ruling "does not set controlling precedent and does not affect law enforcement agencies' continued use of these important public safety technologies.")

But meanwhile, on Friday U.S. Senator Bernie Sanders introduced the Ban Flock Act. The proposed bill bans federal agencies in America from using automated license plate reader systems "without explicit statutory authorization". The bill also lets certain federal agencies (including the Homeland Security Department) withhold grant money from State and local governments that use automatic license plate readers.

TechCrunch reports: Despite its title, the bill doesn't call out Flock in the text and covers any and all ALPR systems. The bill allows exceptions only for toll collection and for uses that Congress approves in future legislation, which would have to limit data retention to no longer than 48 hours.... Representative Alexandria Ocasio-Cortez (D-N.Y.) and Senator Jeff Merkley (D-Ore.) are co-sponsors.
The Almighty Buck

New Mexico Wants Meta To Pay $40 Billion In Penalties For Cambridge Analytica Scandal (yahoo.com) 31

An anonymous reader quotes a report from Reuters: The state of New Mexico asked a judge on Thursday to order Meta Platforms to pay between $35 billion and $40 billion in penalties after a jury found the company had misled consumers about the privacy of their data on Facebook in a case that came out of the Cambridge Analytica scandal.

Attorneys for New Mexico made the request at a hearing in a lawsuit brought following revelations that the British political consulting firm, which worked on Donald Trump's 2016 presidential campaign, harvested personal data from as many as 87 million Facebook users through a third-party app without their consent. The jury returned its verdict on September 25. Judge Francis Mathew, who oversaw the trial in Santa Fe, will decide how much Meta must pay in financial penalties. [...] State law allows the judge to decide how much to fine Meta per violation, up to $5,000. At the hearing on Thursday, Randi McGinn, a lawyer for New Mexico, said applying the full $5,000 penalty to the number of violations would create too large of a penalty under the US Constitution's protections on due process. But the judge should order a significant payment that will impact the company, McGinn said.

"This court should speak to Meta in the only language it understands, which is money, and the value of its stock price," McGinn said. She said $35 billion to $40 billion, which represents about 20% of the possible penalties that could be awarded under state law from the verdict, would impact the stock price while complying with Meta's right to due process under the Constitution. At the hearing on Thursday, Matt Nicholson, a lawyer for Meta, called the state's request an "astronomical penalty that would obviously violate a host of constitutional provisions." In court filings, Meta urged Mathew to cap the penalties at $3.45 billion. The jury may have said it found Meta's statements misleading, but the evidence shows that Meta does not sell user data and New Mexico did not prove that any consumer had actually been misled, the company said in court filings. The judge said he expected to issue a ruling later this month.

Data Storage

Apple Tightens macOS 'Full Disk Access' Controls As AI Agents 'Substantially' Increase Risk (techcrunch.com) 39

Apple says it will tighten macOS Full Disk Access controls as increasingly capable AI agents raise the risks of apps gaining broad access to users' files, messages, mail, and browsing history. TechCrunch reports: Days after a journalist claimed that Meta's Muse app on Mac read their private messages -- a claim that Meta disputed -- Apple announced that it's introducing additional controls around a setting called "Full Disk Access" on macOS. The feature was designed to allow backups to function properly, but AI agents have now increased "the risks associated with this level of access," Apple said. [...] In Muse's case, the AI optionally allows users to enable Full Disk Access. This setting, Apple explains, gives an app permission to access files, mail, messages, and even browsing history.

"Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems... without users' full knowledge and understanding," Apple said in a new blog post aimed at developers. The company says that, going forward, it will introduce new controls aimed at ensuring that users who "genuinely wish to grant an app this extraordinary level of access" can do so only with "every explicit user action."

"Addressing this is critical. As AI agents become increasingly capable and autonomous, the risks associated with this level of access will grow substantially. We are committed to ensuring users clearly understand these risks before granting such access, so they can make informed decisions about their own data and privacy," Apple wrote.

Google

Judge Dismisses Chegg and Penske Antitrust Lawsuits Targeting Google AI Search (arstechnica.com) 5

A federal judge has dismissed antitrust lawsuits from Chegg and Penske Media accusing Google of harming publishers by using their content in AI Overviews and other AI search features without compensating them or providing a meaningful opt-out. Ars Technica reports: The lawsuits were filed in 2025, and Google requested a dismissal earlier this year. Chegg, an education and learning platform, claimed in its lawsuit that Google illegally scraped its educational content. This allowed Gemini models to essentially recreate that content and reduce the site's traffic. Penske, which owns publications like Rolling Stone and Variety, filed a similar case that alleged lost traffic. Specifically, the publisher claimed it was unfair that sites indexed for organic search would also have their content harvested for AI answers, with no way to opt out.

These arguments did not sway the judge, who noted that Google's implicit agreement with websites is not legally relevant. "Plaintiffs have pleaded only that they have an 'expectation' that Google will send them search "traffic if they make their content available for free," wrote Mehta. "But an expectation is not an agreement. It is simply how a general search engine works."

Since Google never had a formal arrangement with either Chegg or Penske, antitrust law doesn't apply. And Mehta is aware of the legal issues surrounding search. He also heard the DOJ's long-running search antitrust case against Google, eventually finding that Google violated the law. However, the government didn't get the harsh penalties it wanted in that case.

Software

Russian-Owned Snooping Software Used By US Secret Service (telegraph.co.uk) 19

Bruce66423 shares a report from The Telegraph: British police forces, including specialist units within the Metropolitan Police, have used Oxygen Forensics software to break into the phones of suspects during live investigations, public documents show. The Virginia-based company behind the software has been accused in the US of having hidden its Russian ownership to avoid sanctions, before it was awarded government contracts. Its American chief executive and a Russian national were arrested last week after a US investigation found the company had sought to hide its ownership in an alleged attempt to avoid sanctions and scrutiny.

[...] By September 2024, the US Secret Service had awarded Oxygen a five-year contract for its software. In December 2022, and in October 2023, Oxygen's chief executive told the US government that Oxygen Forensics had "no immediate or highest-level owner." By September 2024, the US Secret Service had awarded Oxygen a five-year contract for its software. In March, Mr Reiber allegedly told the US government that there had been no Russians involved in developing the software and that no one in Russia had access to the environment in which it was built. US prosecutors say this was false. If convicted, both Mr Reiber and Mr Davydov could face a sentence of 20 years in prison.

Privacy

Cops Can Bypass iPhone's Automatic Reboot To Get Into Locked Phones (404media.co) 41

An anonymous reader quotes a report from 404 Media: A company that makes phone hacking devices claims to have developed a solution that freezes iPhones in a state that lets cops more easily access sensitive data inside them, according to a video obtained by 404 Media. [...] The new technology to get around inactivity reboot was developed by Magnet Forensics, the company behind GrayKey, a popular tool sold to law enforcement agencies that allows them to unlock and access data stored in iPhones and Android smartphones. Magnet has developed a new device called GrayKey Preserve and a feature for its regular GrayKey devices called Evidence Preservation Mode, according to the video.

"This is an absolute game changer for iOS forensics and a function that I wish we had years ago," a Magnet employee says in the leaked video, specifically mentioning that the solution is targeted at the iPhone's inactivity reboot feature and the data it makes unavailable. GrayKey Preserve and Evidence Preservation Mode are also designed to combat another iPhone feature that automatically deletes certain data -- such as cached locations, and recently deleted photos and iMessages -- after a certain number of days. "We're gonna be able to preserve that data for an infinite amount of time."

[...] 404 Media shared a transcript of the video with Jiska Classen, a researcher at the Hasso Plattner Institute who studies iPhone security. While Classen said that it's impossible to know for sure how Magnet's new feature works based on the video, she posited some theories and agreed that it is "quite a game changer" or "at least puts things back to where they were before inactivity reboot." She thinks Magnet has found a way to manipulate the iPhone's clock, effectively "slowing down time" or even "stopping the clock from ticking, even after a reboot." Most likely, according to her, the GrayKey may disable the iPhone tasks that set data to expire.
The "inactivity reboot" feature mentioned above was added to iOS in November 2024 and automatically restarts iPhones that have not been unlocked for 72 hours, making them harder for police to access using forensic tools.
United States

Pentagon Creates 'Autowarcom' to Expand AI and Drone Capabilities (reuters.com) 48

Longtime Slashdot reader ThurstonMoore shares a report from Reuters: U.S. Defense Secretary Pete Hegseth on Wednesday announced the creation of a new military command that would be dedicated to building and providing autonomous and robotic capabilities across the U.S. military. The command, which Hegseth said would be called "Autonomous Warfare Command," highlights the rapidly changing nature of warfare and the need to make progress on systems like drones and the use of artificial intelligence.

Speaking in front of hundreds of junior officers and enlisted personnel at Quantico, Virginia, in a speech peppered with attacks on the media, Hegseth said the command would be led by a four-star officer. "The pace of war is changing faster than the process to support it," Hegseth said in a speech called the "State of the Force," in which he announced other changes, including the creation of the office of religious affairs. "Cheap compute, superintelligence, and advanced commercial manufacturing have enabled the proliferation of low-cost, high-precision strike," Hegseth added.

[...] The United States has long relied on its vast military budget to field some of the world's most expensive weapons systems. But there is an increasing realization within the Pentagon that this is not sustainable. "Today we need both quality and quantity," Hegseth said.

AI

FTC Is Investigating OpenAI, Anthropic and Other AI Companies Over Product Risks 19

The Federal Trade Commission has opened an investigation into OpenAI, Anthropic and other AI companies over potential consumer and safety risks posed by their products, with the agency reportedly preparing requests for documents and executive testimony. CNBC reports: OpenAI stunned the industry in July when it disclosed that its agents broke out of a testing environment and hacked into open-source platform Hugging Face. [...] Earlier this month, Anthropic CEO Dario Amodei rocked the tech sector by urging AI companies to slow how quickly they improve their most advanced models and calling for stronger government oversight. He published a three-step proposal aimed at tempering the pace of development without "sacrificing commercial advantage or the United States' lead in AI."

CEO Jensen Huang, argued that individual companies should be responsible for ensuring the safety of their products. President Donald Trump convened top executives from Alphabet, Meta, SpaceX, Nvidia, Palantir, Anthropic, OpenAI and other companies on Tuesday to discuss the issue. The group signed a short voluntary, nonbinding accord, which says that "every company is responsible for developing its own technology safely and in a way that builds trust with customers and the public."
Privacy

Hackers Stole Millions of US Military Personnel Records During Months-Long Data Breach (techcrunch.com) 70

A months-long breach of the Defense Manpower Data Center exposed personal information belonging to roughly 2.8 million living current and former U.S. military personnel and staff, plus records for nearly 300,000 deceased people. Attackers reportedly exploited a file-sharing vulnerability between October 2025 and July 2026, accessing unencrypted records that included Social Security numbers, dates of birth, demographic information, and military service details. TechCrunch reports: The DMDC may not be widely known to the general public, but serves as one of the Department of Defense's records-keeping units. The DMDC maintains over 60 million records for U.S. military and civilian staff and their family members to help determine benefits and entitlements, such as healthcare and retirement. The unit also provides a critical service as the military's "leading identity management provider," which links active service members, employees, and contractors to credentials, such as smart cards and passwords. These are used to access Pentagon computer systems, buildings, and bases.

"We make sure that the right people get access and the wrong people don't: security of identity information is paramount," the DMDC's website reads. The Department of Defense, which oversees the DMDC, said it does not have any indication that the information was misused, but did not say how it reached that conclusion. TechCrunch contacted a Pentagon spokesperson to ask if officials had any communications from the hackers, whose identities are not known, but we did not hear back.

Government

Singapore Pilots a Government-Built Dating Service (mashable.com) 188

Longtime Slashdot reader AmiMoJo shares a report from Mashable: Singapore's government is trying its hand at matchmaking again. The country's Government Technology Agency (GovTech) has launched FirstDate, a pilot dating service for singles aged 21 to 35. For now, it's open only to public officers, according to the service's website. Applications close Oct. 5. FirstDate is designed as an alternative to endless swiping.

Instead of browsing a stream of profiles, users fill out a questionnaire about their interests, habits, values, and preferences. The service then sends them one match per cycle (the time it takes to mutually accept and presumably meet up). Each match includes a compatibility score, a brief description of the person, and a personal note. [...]

The pilot arrives as Singapore's birth rate hits a new low, according to the Singaporean newspaper The Straits Times. The country's total fertility rate fell to 0.87 children per woman in 2025, down from 1.24 a decade earlier. In April, the government announced a new workgroup tasked with addressing falling birth rates, which is expected to report its findings by early 2027, The Straits Times reported.
The service relies on the Gale-Shapley algorithm, a well-known mathematical method that solves the stable matching problem by pairing two sets of participants based on their ranked preferences.

Once matched, users have 72 hours to mutually accept before contact details are shared, with optional "Date Quests" and post-date surveys designed to encourage and assess in-person meetups. Accounts are verified through Singapore's Singpass digital ID system to reduce fake profiles, and profiles are only visible to assigned matches. GovTech says user data is protected under government security standards, is not sold to third parties, and can be deleted upon request.
The Internet

Trump Administration Launches New AI-Powered 'America.gov' Website 115

fahrbot-bot shares a report from CNN: President Donald Trump on Tuesday unveiled America.gov, a government website meant to serve as a one-stop shop for people trying to accomplish basic tasks like renewing a passport, enrolling in Medicare or applying for disaster relief. The site, which launched with some basic functions ahead of a full rollout next year, is designed to serve as an AI-powered guide through the thicket of government agencies that Trump officials pledged would ultimately save people a whole lot of frustration.

The administration's new initiative aims to allow Americans to access dozens of federal websites through a single point, making America.gov akin to a search tool that pulls information from across the government. And in the same way that people increasingly use AI models like ChatGPT or Google Gemini to compile information and provide customized answers, Trump officials claimed that America.gov would be able to do the same for people's interactions with the federal government.

Enrolling in Medicare, for example, will become a matter of typing the request into the America.gov AI tool and following its step-by-step instructions. The same goes for applying to a government job -- the new tool will now let people upload their resume directly to the site -- or answering questions about federal benefits, publicly available documents or other necessities that fall under the federal government's vast umbrella.

"Our vision is that one day, this type of convenience and simplicity will be across every government service," said Joseph Gebbia, who leads the government's National Design Studio. But the reality is that the most advanced actions won't be available until some point in 2027, raising questions about how long it will take for the administration to revamp the way the people interact with the government's websites. The current version of America.gov can only do "answers."
U.S. Chief Design Officer Joe Gebbia said the new chatbot is powered by Google's Gemini and Elon Musk's Grok. "We have great partners behind the scenes," Gebbia told CNBC's "Squawk Box" shortly before the site, America.gov, went live around 10 a.m. ET.

"Google is proud to be named a technology partner in this vital initiative, leveraging Gemini to help more than 100 million people access critical public resources with greater speed and ease," the company said in a blog post. "By supporting the administration's vision for digital modernization, we are committed to making these everyday public services seamless, accessible, and responsive for all Americans."
Crime

Dutch Police Arrest 'Reformed' Hacker In Shiny Hunters Investigation (krebsonsecurity.com) 13

An anonymous reader quotes a report from KrebsOnSecurity: Authorities in the Netherlands have arrested a 24-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. According to three sources familiar with the matter, the Dutch man arrested by authorities this month is Pepijn van der Stap, a convicted cybercriminal from Almere and Lelystad in the Netherlands. Van der Stap was previously convicted in 2023 in connection with a string of data thefts and extortions that prosecutors said earned between 1.5 million euros and 2.7 million euros.

At his trial in late 2023, van der Stap admitted that he lived a Dr. Jekyll and Mr. Hyde existence, secretly using the hacker handle "Umbreon" to extort victims and post their data on English language hacking communities like the now-defunct RaidForums and Breached. By day, however, van der Stap was working as a software engineer at the Amsterdam-based cybersecurity startup Hadrian, while volunteering at the Dutch Institute for Vulnerability Disclosure (DIVD), a nonprofit security research group. Van der Stap confessed to his data theft and extortion activity, and was sentenced to four years in prison (one of which was suspended).
Van der Stap had publicly presented himself as a "reformed hacker" after serving prison time for data theft and extortion. In a Sept. 9 interview, KrebsOnSecurity said he claimed he was trying "to turn his life around and make a positive contribution to society," while working in offensive security and attempting to make amends to former victims.
United Kingdom

500K Facial Recognition Scans at UK Stations Yield Zero Arrests, One False Positive (theguardian.com) 48

A six-month British Transport Police trial of live facial recognition at London railway stations scanned more than 500,000 faces, cost over 320,000 pounds, and produced just one alert with no arrests directly resulting from the technology. That one alert ended up being a false positive.

Despite those results, BTP has extended the pilot through November and expanded it to selected Underground stations. The Guardian reports: British Transport Police said that since the extension there had been three positive confirmed alerts of people who were subsequently confirmed to be complying with sexual harm prevention orders or other imposed court conditions. When Transport for London announced its support for the extension of the trial, it said LFR technology "will target and identify people on police watchlists at key stations chosen for maximum impact" and would "specifically tackle violence against women and girls, whose travel behaviors are shaped by experiences of sexual harassment and sexual offenses."

Fraser Sampson, a former biometrics and surveillance camera commissioner for the UK, said the police needed to show that the use of the technology was proportionate. "There many variables and all need to align: the choice of location, times of day, make up of the watchlist and likelihood of people being present and many more." Sampson, who is now a non-executive director of Facewatch, a company that operates facial recognition systems in shops, added: "We know the technology works, but using it in supermarkets to deter shoplifters and prevent attacks on staff is very different from deploying it to catch people on a public transport network."

"Success in a shop means no such people coming in. Success for the police trying to catch people means people being caught. In that respect the trial doesn't appear to have been very fruitful. Everything depends on the police watchlists; if you're not on a watchlist, the live FRT cameras do not "see" you and they don't retain your image in the same way as CCTV cameras. However, they are processing special category personal data and the technology must be used in a way that is appropriate, proportionate and necessary. It's for the police to show how any deployment meets those criteria and -- as the ICO [information commissioner's office] has recently reported -- for their oversight boards to hold them firmly to account in doing so."

The Courts

Florida Invokes Extinction Fears In Legal Bid To Halt OpenAI Development 49

An anonymous reader quotes a report from Ars Technica: The state of Florida is seeking a temporary injunction to stop OpenAI from continuing to develop what it calls a "reckless, unacceptably risky product" without the deployment of "third-party approved safety guardrails." The new legal motion (PDF), filed Monday morning, is part of a civil lawsuit the state of Florida originally filed in June, arguing that ChatGPT represented "a threat to the public safety of Floridians," specifically by preying on vulnerable populations like children and violent or delusional adults. [...] In arguing for this injunction, the state points to the Hugging Face incident as well as recent high-profile misalignment cases involving unintended and unauthorized attempts to access Australian and US government servers. Florida also cites AI industry leaders, including many from OpenAI, in arguing that the AI industry is literally asking for this kind of outside regulation.

The motion points to statements from Paul Christiano, who said on joining the company's board this month that he believes "there is a meaningful risk that rapid acceleration in AI capabilities leads to catastrophic and irreversible loss of control in the very near term." The motion also points to OpenAI's own "An Alien Mind" essay and an open letter from 1,300 AI industry employees, both of which call for enforced slowdowns on frontier AI development, if necessary. Citing laws that allow the state to exercise control over companies that are a "public nuisance," Florida argues that OpenAI is "the greatest public nuisance ever created by the hand of man, capable of laying waste to global civilization."
"It is only by the grace of the Almighty that one of Defendants' AI agents hasn't compromised a water supply or shut down a power grid -- yet," the state writes in the motion.
Social Networks

TikTok to Pay Alabama $100 Million, Limit Teen Use In First State Settlement (theguardian.com) 19

TikTok has agreed to pay Alabama at least $100 million and adopt new restrictions for teenage users, including a two-hour daily limit, overnight access restrictions, stronger age verification, a ban on beauty filters, and an option for a non-personalized feed. The settlement could grow to as much as $300 million if enough other state attorneys general join similar agreements. The Guardian reports: A trial had been set to begin on Monday in the southern US state over claims by Alabama that TikTok misled parents about tools meant to shield children from harmful content. [...] Attorney general Steve Marshall hailed Friday's settlement as "a great day for Alabama parents." He said: "Tonight, they can rest easier knowing real protections are in place to shield their children from the dangers of social media addiction."

Under the settlement, TikTok will send $100m to Alabama and could possibly pay up to $300m in total if 40 other attorneys general sign similar agreements with the company within a specified timeframe. In addition, the Alabama deal includes a conditional restriction that Meta also agreed to: expanding the night-time shutdown period to 10pm to 7am if other platforms also commit to do the same.

"TikTok's priority has always been fostering a safe and positive space where people can be creative, discover what they love, and connect with their community," a company spokesperson told AFP. "This builds on our commitment and core objective to continually enhance our robust safety tools to protect teens," the spokesperson added. More than a dozen other states, including California and New York, still have suits against TikTok.

Slashdot Top Deals