< ciso
brief />
Tag Banner

All news with #privacy engineering tag

164 articles

Brave adds disposable email aliases to improve privacy

📧 Brave 1.94 adds an Email Aliases feature that generates disposable addresses for signups, keeping users' real emails hidden while forwarding messages. The feature requires a free Brave Account and stores primary and alias addresses encrypted; forwarded messages are delivered then deleted from Brave servers within seconds. Up to five aliases are free, with a paid Premium tier planned, and forwarded mail may initially hit spam folders.
read more →

Designing Systems to Earn Customer Trust

🔒 Over years of building large-scale personalization and commerce systems, the author argues that compliance alone does not create customer trust. Real trust comes from ensuring customer intent is respected across distributed services, caches, pipelines and AI systems. The piece highlights five priorities: consistent customer intent, privacy as a distributed-systems problem, data minimization, designing for failure, and understanding AI's expanding trust boundary. Security leaders are urged to treat trust as an architectural and operational priority, with observability and metadata-driven controls.
read more →

Microsoft tests per-app privacy controls in Windows 11

🔒 Microsoft is testing new privacy controls in Windows 11 Insider Experimental Preview Build 26340.9233 that let users manage camera, microphone, and location access per desktop app. Previously, these permissions were controlled by device-wide settings. Insiders can adjust access under Settings > Privacy & security using dedicated toggles. Microsoft cautions users to grant access only to trusted apps, noting some apps may appear unsigned or under different names.
read more →

Surveillance and AI Targeting Infant Monitoring

🍼 The New York Times reports on companies developing continuous surveillance systems for infants that increasingly incorporate AI. These devices, led by vendors like Nanit, collect extensive data to monitor health, development, and behavior. Recent funding rounds, including Nanit’s $50 million, aim to expand analytics into speech, motor skills, and longer-term tracking into childhood. The article raises concerns about privacy, data use, and the implications of pervasive monitoring.
read more →

TikTok Agrees to $400M COPPA Settlement with DOJ

📢 The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliates over alleged violations of the Children’s Online Privacy Protection Act (COPPA). The suit, filed in 2024, accused TikTok of allowing users under 13 to create regular accounts outside a restricted Kids Mode, collecting and retaining personal data without parental consent, and failing to delete data upon request. The settlement resolves those allegations while acknowledging that TikTok has since made compliance and privacy changes.
read more →

OpenAI launches privacy-preserving safety layer

🔒 OpenAI introduced Private Safety Processing to detect misuse across related AI interactions while maintaining its Zero Data Retention (ZDR) commitment. The system generates narrowly defined safety signals instead of exposing prompts or responses, and can operate with customer-held encryption keys or enterprise-controlled infrastructure. It is being piloted with eligible enterprise and API customers to address risks that emerge over time rather than in single prompts. The approach shifts investigative responsibility toward customers while aiming to preserve privacy.
read more →

Police Conceal Use of Flock License Plate Cameras

🚨A usage policy for Flock automated license plate reader (ALPR) cameras in Wapello County, Iowa, instructs officers to refrain from informing vehicle occupants or routinely documenting ALPR use in reports. The document explicitly orders: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE” and to avoid mentioning it in reports unless absolutely necessary. This secrecy echoes prior law enforcement efforts to conceal surveillance tools such as IMSI-catchers.
read more →

ICO urges police to tighten facial recognition governance

🔎 The UK Information Commissioner’s Office (ICO) has called on police forces using live facial recognition (LFR) to strengthen data governance and align practice with legal requirements. Emily Keaney, deputy commissioner for regulatory policy, highlighted audits showing inconsistent compliance across five forces and urged improvements in oversight, record-keeping, training and accuracy checks. The ICO noted forces are engaging with the findings and stressed robust protections are essential to maintain public trust.
read more →

Early breach communications can destroy legal protections

🛡️ During the chaotic first 24 hours after a cyber incident, teams often communicate in ways that later become damaging evidence. Operational notes, Slack messages and emails— even if legal is copied—may not be privileged unless their predominant purpose was legal advice. Courts scrutinize whether communications were created for legal counsel or for ordinary business operations, and widespread channels or AI tools that share data externally can undermine privilege.
read more →

Venues ban Meta Ray‑Ban smart glasses over privacy

📷 Many UK restaurants, theatres and clubs are banning Meta's Ray‑Ban smart glasses amid concerns over covert recording and data handling. Venue owners and chains such as Soho House, ATG Theatres and Wetherspoons cite guest privacy and common sense as reasons for prohibiting the devices. Meta says it built privacy into the glasses with an LED and recording cutoffs, but critics remain unconvinced. Reports that footage and audio were sent to human contractors for labeling have intensified worries.
read more →

AI tutors for children: benefits and concerns

📘 AI tutoring tools are expanding rapidly and promise tailored learning, but they carry notable risks for children. Parents should distinguish between simple chatbots and structured Intelligent Tutoring Systems, and be aware of cognitive, psychosocial, privacy and security issues. Careful selection, oversight and data-protection checks are essential to minimize harm and ensure productive learning outcomes.
read more →

Privacy-first medical AI with MedPerf and Google Cloud

🔒 Google Cloud and MLCommons’ MedPerf use Confidential Computing to benchmark medical AI on real patient data while preserving privacy. The collaboration runs evaluations inside hardware-isolated Trusted Execution Environments, extending protection across CPUs and GPUs with A3 VMs and NVIDIA H100 GPUs. This approach enables federated evaluation for initiatives like Federated Tumor Segmentation, revealing site-specific performance gaps and improving trust in clinical AI.
read more →

WebKit proxy bypasses can expose real IPs

🔒 Researchers disclosed that features in Apple's WebKit can bypass configured proxies and reveal users' real IP addresses, affecting iCloud Private Relay. The flaw stems from DNS prefetching, WebAuthn related origin requests, and WebTransport, which send traffic outside the relay. A PoC site demonstrates the leak, and Apple says it is investigating while the issue also impacts macOS and other WebKit-based browsers.
read more →

Adversarial Clothing and the Limits of Anti‑Surveillance

🧥 Many companies now sell adversarial clothing that claims to confuse facial recognition systems. While these designs may introduce noise into algorithms and serve as a visible protest, experts caution they are largely untested and may offer limited protection. Without rigorous, ongoing evaluation, there is no guarantee the garments will remain effective as recognition systems evolve. Consumers should not assume reliable privacy from these products.
read more →

DefCon bans smart glasses with recording features

🕶️ DefCon has added smart glasses to its banned list, prohibiting audio- or video-recording eyewear because organizers say there is no reliable way to tell if they are recording, which undermines trust and privacy. Attendees are required to wear non-smart corrective lenses if needed. The ban supplements strict photography rules that limit group shots and encourage portrait settings to blur backgrounds. Growing market activity from Google, Samsung, and Apple has heightened concerns among conferences and CISOs about privacy and data security.
read more →

Madison Square Garden’s Facial Recognition Practices

🔒 Madison Square Garden reportedly deploys facial recognition on all entrants and flags certain activists opposing the technology. The system was notably disabled for Taylor Swift’s wedding, raising questions about selective surveillance and privilege. Activist Evan Greer highlighted the irony of celebrities using similar tools for personal protection while others are surveilled. Reportedly, privacy measures for the wedding were effective, as no photos have leaked.
read more →

Prosecution Over Phone Wipe Raises Border Search Questions

🔐 The prosecution of an American who provided a code that wiped his GrapheneOS-powered Pixel phone highlights tensions at the U.S. border. The feature in GrapheneOS deliberately erases device contents when a specific passcode is entered, and the defendant’s phone ran this OS. The case probes constitutional protections at the border and the government’s stance that border zones are not subject to the same rights until entry is authorized. GrapheneOS maintains the feature is legal and constitutionally protected.
read more →

Microsoft GDID's role in a Scattered Spider indictment

📰 The criminal complaint against Peter Stokes, an alleged Scattered Spider member, revealed the role of Microsoft’s Global Device Identifier (GDID) in correlating a Windows installation with ngrok signup activity and other telemetry. Experts stress GDID was one piece of a broader chain that included provider logs, IP history, and timestamps. The indictment raised privacy concerns about how persistent device identifiers are collected, retained, and disclosed to investigators.
read more →

Palo Alto Networks Earns Global CBPR and PRP Certifications

🔒 Palo Alto Networks announces attainment of the Global Cross-Border Privacy Rules (CBPR) and the Global Privacy Recognition for Processors (PRP) certifications following independent third-party audits. These credentials, rooted in the APEC Privacy Framework and expanded by the Global CBPR Forum, validate that the company's data privacy practices meet international standards. This achievement supplements its existing privacy and security certifications and underscores an ongoing commitment to responsible cross-border data protection.
read more →

Axon adds to license-plate surveillance debate

📷 Municipalities are replacing some Flock license-plate reader arrays with Axon cameras, but the swap may offer little privacy benefit. Vendors claim differences, yet Axon systems still collect extensive personal data beyond plate numbers. Switching brands can be superficial if surveillance capabilities and data use remain similar. The article argues that changing suppliers doesn't necessarily reduce citizen privacy loss.
read more →