RC RANDOM CHAOS

data privacy

7 posts

Microsoft called it theft; the crawler maps your attack surface
Article

Microsoft called it theft; the crawler maps your attack surface

AI crawlers copied your public data into training sets you can't reach. The real security risk is data you can never delete or recall.

Gemini 3.8 Live broke two security assumptions
Article

Gemini 3.8 Live broke two security assumptions

Gemini 3.8 Live and Extended Thinking make ambient audio and video an untrusted AI input, reshaping prompt injection, logging, and privacy risk.

Keep the two claims apart
Article

Keep the two claims apart

Consumer AI trains on your chats by default. How to tell the real consent problem from unprovable 'secret breakthrough' claims - and what you can control.

Grok packed your home folder into an API request
Article

Grok packed your home folder into an API request

How AI assistants with filesystem access end up transmitting your home directory to vendor servers - and the concrete steps to scope, verify, and contain it.

Train the AI or Samsung erases your health record
Article

Train the AI or Samsung erases your health record

Samsung deletes your health data unless you let it train AI. That is not consent. It is coercion recorded as authorization.

A single rubber stamp guards the transatlantic data pipe
Article

A single rubber stamp guards the transatlantic data pipe

The EU-US Data Privacy Framework authorised transfers on an adequacy premise the Commission never controlled. That is a failed control, not a blowup.

five dollars is the instrument
Article

five dollars is the instrument

A five dollar demand to return images is a rights-framed extortion probe exploiting unenforced consent governance, not ransomware.