home.social

#pii — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pii, aggregated by home.social.

  1. Among the latest data-breach villains: the Washington Post

    Members of the Washington Post’s extended diaspora, meaning both former employees as well as past freelancers, have begun getting an unwelcome reminder of that chapter in their professional lives: a letter from the Post, sent from an address not in the District but in West Sacramento, Calif., informing them of a “Data Security Incident.”

    That inefficient phrase is defensive legalese for “data breach,” which the letter says, in comparably defensive passive voice, happened between July 10 and Aug. 22, 2025, when “certain data was accessed and acquired without authorization” from unspecified Oracle E-Business Suite applications.

    In my case and others, to judge from reports from fellow recipients of this joyless notice, the “certain data” included names and Social Security numbers.

    The letter may not spark any more joy at Oracle, since it describes the vulnerability exploited as a “previously unknown and widespread” flaw. Oracle’s own warning red-flags it as “remotely exploitable without authentication.” But the paper’s disclosure does not address another cause of the data breach: how the Post chose to retain this sort of sensitive data long after it should have stopped being regularly business-relevant.

    Consider my example: The last time I had any ongoing transactions with the Post that should have involved my SSN was 15 years ago. I rolled over my 401(K) after leaving the paper, and Jeff Bezos buying the Post in 2013 resulted in the company transferring my pension and those of other ex-Posties to former publisher Don Graham’s firm Graham Holdings.

    For the handful of freelance pieces I’ve sold to my old shop since then (such as the Jan. 28, 2019 opinion piece headlined “Big tech firms still don’t care about your privacy”), I’ve used the Employer Identification Number I obtained shortly after I started freelancing.

    Yet apparently my SSN was still sitting unencrypted in a network-accessible database last summer, contrary to basic security advice, along with the digits of thousands of other current and former Post employees and contractors. Some had banking details compromised too.

    That’s “thousands” as in 9,720 people, per a filing the Post made with Maine’s Attorney General in November that a few security publications covered at the time. A month later, a former Post employee named Jun Hee Kim filed a class-action lawsuit against the Post on behalf of those nearly 10,000 individuals.

    I have yet to get a notice inviting me to join that class, and the Post’s letter does not mention the litigation. Instead, it offers the usual paltry remedy of a year of identity-theft monitoring, in this case from a firm called IDX.

    I know that’s the standard act of apology not only from covering data breaches but from having my data exposed in them, over and over. I know the drill well enough to have turned “Equifax” into the verb “Equifaxed” and to have frozen my credit more than once.

    So at some level, I’m not surprised at the news of the Post’s data breach so much as I’m surprised that it took this long. Throughout my time working at 15th and L, I saw the Post treat SSNs as carelessly as anybody else did decades ago–even using them as employee IDs, as seen in some of my own admin paperwork from early in this century showing the full nine digits. But it’s still stupid and sloppy that this particular data breach happened not in 2005 or 2015 but in 2025, well past the point when management at the Post should have known better.

    #Cl0p #CVE202561882 #dataBreach #dataMinimization #DataSecurityIncident #EIN #EmployerIdentificationNumber #Equifax #Equifaxed #IDX #Oracle #OracleEBusinessSuite #personallyIdentifiableInformation #PII #SocialSecurityNumber #SSN #TaxIDNumber #wapo #washingtonPost
  2. Among the latest data-breach villains: the Washington Post

    Members of the Washington Post’s extended diaspora, meaning both former employees as well as past freelancers, have begun getting an unwelcome reminder of that chapter in their professional lives: a letter from the Post, sent from an address not in the District but in West Sacramento, Calif., informing them of a “Data Security Incident.”

    That inefficient phrase is defensive legalese for “data breach,” which the letter says, in comparably defensive passive voice, happened between July 10 and Aug. 22, 2025, when “certain data was accessed and acquired without authorization” from unspecified Oracle E-Business Suite applications.

    In my case and others, to judge from reports from fellow recipients of this joyless notice, the “certain data” included names and Social Security numbers.

    The letter may not spark any more joy at Oracle, since it describes the vulnerability exploited as a “previously unknown and widespread” flaw. Oracle’s own warning red-flags it as “remotely exploitable without authentication.” But the paper’s disclosure does not address another cause of the data breach: how the Post chose to retain this sort of sensitive data long after it should have stopped being regularly business-relevant.

    Consider my example: The last time I had any ongoing transactions with the Post that should have involved my SSN was 15 years ago. I rolled over my 401(K) after leaving the paper, and Jeff Bezos buying the Post in 2013 resulted in the company transferring my pension and those of other ex-Posties to former publisher Don Graham’s firm Graham Holdings.

    For the handful of freelance pieces I’ve sold to my old shop since then (such as the Jan. 28, 2019 opinion piece headlined “Big tech firms still don’t care about your privacy”), I’ve used the Employer Identification Number I obtained shortly after I started freelancing.

    Yet apparently my SSN was still sitting unencrypted in a network-accessible database last summer, contrary to basic security advice, along with the digits of thousands of other current and former Post employees and contractors. Some had banking details compromised too.

    That’s “thousands” as in 9,720 people, per a filing the Post made with Maine’s Attorney General in November that a few security publications covered at the time. A month later, a former Post employee named Jun Hee Kim filed a class-action lawsuit against the Post on behalf of those nearly 10,000 individuals.

    I have yet to get a notice inviting me to join that class, and the Post’s letter does not mention the litigation. Instead, it offers the usual paltry remedy of a year of identity-theft monitoring, in this case from a firm called IDX.

    I know that’s the standard act of apology not only from covering data breaches but from having my data exposed in them, over and over. I know the drill well enough to have turned “Equifax” into the verb “Equifaxed” and to have frozen my credit more than once.

    So at some level, I’m not surprised at the news of the Post’s data breach so much as I’m surprised that it took this long. Throughout my time working at 15th and L, I saw the Post treat SSNs as carelessly as anybody else did decades ago–even using them as employee IDs, as seen in some of my own admin paperwork from early in this century showing the full nine digits. But it’s still stupid and sloppy that this particular data breach happened not in 2005 or 2015 but in 2025, well past the point when management at the Post should have known better.

    #Cl0p #CVE202561882 #dataBreach #dataMinimization #DataSecurityIncident #EIN #EmployerIdentificationNumber #Equifax #Equifaxed #IDX #Oracle #OracleEBusinessSuite #personallyIdentifiableInformation #PII #SocialSecurityNumber #SSN #TaxIDNumber #wapo #washingtonPost
  3. Among the latest data-breach villains: the Washington Post

    Members of the Washington Post’s extended diaspora, meaning both former employees as well as past freelancers, have begun getting an unwelcome reminder of that chapter in their professional lives: a letter from the Post, sent from an address not in the District but in West Sacramento, Calif., informing them of a “Data Security Incident.”

    That inefficient phrase is defensive legalese for “data breach,” which the letter says, in comparably defensive passive voice, happened between July 10 and Aug. 22, 2025, when “certain data was accessed and acquired without authorization” from unspecified Oracle E-Business Suite applications.

    In my case and others, to judge from reports from fellow recipients of this joyless notice, the “certain data” included names and Social Security numbers.

    The letter may not spark any more joy at Oracle, since it describes the vulnerability exploited as a “previously unknown and widespread” flaw. Oracle’s own warning red-flags it as “remotely exploitable without authentication.” But the paper’s disclosure does not address another cause of the data breach: how the Post chose to retain this sort of sensitive data long after it should have stopped being regularly business-relevant.

    Consider my example: The last time I had any ongoing transactions with the Post that should have involved my SSN was 15 years ago. I rolled over my 401(K) after leaving the paper, and Jeff Bezos buying the Post in 2013 resulted in the company transferring my pension and those of other ex-Posties to former publisher Don Graham’s firm Graham Holdings.

    For the handful of freelance pieces I’ve sold to my old shop since then (such as the Jan. 28, 2019 opinion piece headlined “Big tech firms still don’t care about your privacy”), I’ve used the Employer Identification Number I obtained shortly after I started freelancing.

    Yet apparently my SSN was still sitting unencrypted in a network-accessible database last summer, contrary to basic security advice, along with the digits of thousands of other current and former Post employees and contractors. Some had banking details compromised too.

    That’s “thousands” as in 9,720 people, per a filing the Post made with Maine’s Attorney General in November that a few security publications covered at the time. A month later, a former Post employee named Jun Hee Kim filed a class-action lawsuit against the Post on behalf of those nearly 10,000 individuals.

    I have yet to get a notice inviting me to join that class, and the Post’s letter does not mention the litigation. Instead, it offers the usual paltry remedy of a year of identity-theft monitoring, in this case from a firm called IDX.

    I know that’s the standard act of apology not only from covering data breaches but from having my data exposed in them, over and over. I know the drill well enough to have turned “Equifax” into the verb “Equifaxed” and to have frozen my credit more than once.

    So at some level, I’m not surprised at the news of the Post’s data breach so much as I’m surprised that it took this long. Throughout my time working at 15th and L, I saw the Post treat SSNs as carelessly as anybody else did decades ago–even using them as employee IDs, as seen in some of my own admin paperwork from early in this century showing the full nine digits. But it’s still stupid and sloppy that this particular data breach happened not in 2005 or 2015 but in 2025, well past the point when management at the Post should have known better.

    #Cl0p #CVE202561882 #dataBreach #dataMinimization #DataSecurityIncident #EIN #EmployerIdentificationNumber #Equifax #Equifaxed #IDX #Oracle #OracleEBusinessSuite #personallyIdentifiableInformation #PII #SocialSecurityNumber #SSN #TaxIDNumber #wapo #washingtonPost
  4. Among the latest data-breach villains: the Washington Post

    Members of the Washington Post’s extended diaspora, meaning both former employees as well as past freelancers, have begun getting an unwelcome reminder of that chapter in their professional lives: a letter from the Post, sent from an address not in the District but in West Sacramento, Calif., informing them of a “Data Security Incident.”

    That inefficient phrase is defensive legalese for “data breach,” which the letter says, in comparably defensive passive voice, happened between July 10 and Aug. 22, 2025, when “certain data was accessed and acquired without authorization” from unspecified Oracle E-Business Suite applications.

    In my case and others, to judge from reports from fellow recipients of this joyless notice, the “certain data” included names and Social Security numbers.

    The letter may not spark any more joy at Oracle, since it describes the vulnerability exploited as a “previously unknown and widespread” flaw. Oracle’s own warning red-flags it as “remotely exploitable without authentication.” But the paper’s disclosure does not address another cause of the data breach: how the Post chose to retain this sort of sensitive data long after it should have stopped being regularly business-relevant.

    Consider my example: The last time I had any ongoing transactions with the Post that should have involved my SSN was 15 years ago. I rolled over my 401(K) after leaving the paper, and Jeff Bezos buying the Post in 2013 resulted in the company transferring my pension and those of other ex-Posties to former publisher Don Graham’s firm Graham Holdings.

    For the handful of freelance pieces I’ve sold to my old shop since then (such as the Jan. 28, 2019 opinion piece headlined “Big tech firms still don’t care about your privacy”), I’ve used the Employer Identification Number I obtained shortly after I started freelancing.

    Yet apparently my SSN was still sitting unencrypted in a network-accessible database last summer, contrary to basic security advice, along with the digits of thousands of other current and former Post employees and contractors. Some had banking details compromised too.

    That’s “thousands” as in 9,720 people, per a filing the Post made with Maine’s Attorney General in November that a few security publications covered at the time. A month later, a former Post employee named Jun Hee Kim filed a class-action lawsuit against the Post on behalf of those nearly 10,000 individuals.

    I have yet to get a notice inviting me to join that class, and the Post’s letter does not mention the litigation. Instead, it offers the usual paltry remedy of a year of identity-theft monitoring, in this case from a firm called IDX.

    I know that’s the standard act of apology not only from covering data breaches but from having my data exposed in them, over and over. I know the drill well enough to have turned “Equifax” into the verb “Equifaxed” and to have frozen my credit more than once.

    So at some level, I’m not surprised at the news of the Post’s data breach so much as I’m surprised that it took this long. Throughout my time working at 15th and L, I saw the Post treat SSNs as carelessly as anybody else did decades ago–even using them as employee IDs, as seen in some of my own admin paperwork from early in this century showing the full nine digits. But it’s still stupid and sloppy that this particular data breach happened not in 2005 or 2015 but in 2025, well past the point when management at the Post should have known better.

    #Cl0p #CVE202561882 #dataBreach #dataMinimization #DataSecurityIncident #EIN #EmployerIdentificationNumber #Equifax #Equifaxed #IDX #Oracle #OracleEBusinessSuite #personallyIdentifiableInformation #PII #SocialSecurityNumber #SSN #TaxIDNumber #wapo #washingtonPost
  5. »The French Administrative Supreme Court ruled in favour of La Quadrature du Net, French Data Network (FDN), Franciliens.net and Fédération FDN by recognising that the #Hadopi law’s surveillance system that aims to combat illegal files sharing breaches fundamental rights protected by the European Union. The government has been ordered to repeal the key provisions of this decree.«

    edri.org/our-work/hadopi-law-2

    #privacy #PII

  6. »The French Administrative Supreme Court ruled in favour of La Quadrature du Net, French Data Network (FDN), Franciliens.net and Fédération FDN by recognising that the #Hadopi law’s surveillance system that aims to combat illegal files sharing breaches fundamental rights protected by the European Union. The government has been ordered to repeal the key provisions of this decree.«

    edri.org/our-work/hadopi-law-2

    #privacy #PII #surveillance

  7. Ich denke jetzt schon ne Weile ueber eine mir privat wie beruflich wichtige Frage nach, aber vielleicht gibt es hier intelligente Menschen, die eine Antwort haben:
    - Sind verschluesselte Backups von PII Daten auch PII Daten?
    - Sind sie es auch, wenn ich den Schluessel NICHT habe?

    Frage bezieht sich konkret darauf, verschluesselte Backups dezentral zu speichern.

    #FragFedi #PII #GDPR

  8. Ich denke jetzt schon ne Weile ueber eine mir privat wie beruflich wichtige Frage nach, aber vielleicht gibt es hier intelligente Menschen, die eine Antwort haben:
    - Sind verschluesselte Backups von PII Daten auch PII Daten?
    - Sind sie es auch, wenn ich den Schluessel NICHT habe?

    Frage bezieht sich konkret darauf, verschluesselte Backups dezentral zu speichern.

    #FragFedi #PII #GDPR

  9. I don't know if my complaints made a difference. But I'd like to think they did.

    Here's my call to action: make a fuss when someone violates your privacy. Every voice that cries foul helps all of us.

    #Privacy
    #Surveillance
    #PII

  10. I don't know if my complaints made a difference. But I'd like to think they did.

    Here's my call to action: make a fuss when someone violates your privacy. Every voice that cries foul helps all of us.

    #Privacy
    #Surveillance
    #PII

  11. Well here we are a year later, and I am happy to report I was able to attend without the privacy violation they demanded a year ago.

    I purchased my ticket online, didn't have to upload a picture, and didn't have to submit to a photograph to enter the facility. A staff member scanned my ticket, asked for my ID, they glanced at it, and let me in.

    This is how it should be. No one ever needs to harvest your data to verify your identity.

    #Privacy
    #Surveillance
    #PII

  12. Well here we are a year later, and I am happy to report I was able to attend without the privacy violation they demanded a year ago.

    I purchased my ticket online, didn't have to upload a picture, and didn't have to submit to a photograph to enter the facility. A staff member scanned my ticket, asked for my ID, they glanced at it, and let me in.

    This is how it should be. No one ever needs to harvest your data to verify your identity.

    #Privacy
    #Surveillance
    #PII

  13. I begrudgingly admitted defeat. But I didn't give them my photo. I had a difficult choice to make. Right or wrong, I chose privacy over watching my kid. I was pissed about it then, and I'm still mad about it now.

    As a parting shot, I email some links to a few articles on Eff.org and ACLU.org in the hopes they might do some reading and come to realize how wrong they were. And then I tried to let it go.

    #Privacy
    #Surveillance
    #PII

  14. I begrudgingly admitted defeat. But I didn't give them my photo. I had a difficult choice to make. Right or wrong, I chose privacy over watching my kid. I was pissed about it then, and I'm still mad about it now.

    As a parting shot, I email some links to a few articles on Eff.org and ACLU.org in the hopes they might do some reading and come to realize how wrong they were. And then I tried to let it go.

    #Privacy
    #Surveillance
    #PII

  15. Then I emailed 11 folks with the Orange County Convention Center (it's a county government building and a public space, after all).

    Though slightly more sympathetic, they told me the OCCC doesn't take a stance and that as long as the event organizers are following all state and local laws, they defer to the organizers of each event to determine and implement their own access rules and procedures.

    #Privacy
    #Surveillance
    #PII

  16. Then I emailed 11 folks with the Orange County Convention Center (it's a county government building and a public space, after all).

    Though slightly more sympathetic, they told me the OCCC doesn't take a stance and that as long as the event organizers are following all state and local laws, they defer to the organizers of each event to determine and implement their own access rules and procedures.

    #Privacy
    #Surveillance
    #PII

  17. Their response was a hysterical "It's for your safety and protection!", which came across about as disingenuous and fallacious as if they had said "Won't someone please think about the children!"

    But my complaints fell on deaf ears and they essentially told me to pound sand.

    #Privacy
    #Surveillance
    #PII

  18. Their response was a hysterical "It's for your safety and protection!", which came across about as disingenuous and fallacious as if they had said "Won't someone please think about the children!"

    But my complaints fell on deaf ears and they essentially told me to pound sand.

    #Privacy
    #Surveillance
    #PII

  19. About a year ago, I was denied entry to the Orange County Convention Center (Florida, U.S.) to watch my kiddo play in a volleyball tournament.

    Their requirement was that all attendees had to upload a picture of their face or allow the tournament organizers to photograph an attendee's face upon arrival. I asked to opt out, but to no avail.

    I emailed about 8 folks with the non-profit group that organized the tournament (AAUSports.org) and voiced my displeasure.

    #Privacy
    #Surveillance
    #PII

  20. About a year ago, I was denied entry to the Orange County Convention Center (Florida, U.S.) to watch my kiddo play in a volleyball tournament.

    Their requirement was that all attendees had to upload a picture of their face or allow the tournament organizers to photograph an attendee's face upon arrival. I asked to opt out, but to no avail.

    I emailed about 8 folks with the non-profit group that organized the tournament (AAUSports.org) and voiced my displeasure.

    #Privacy
    #Surveillance
    #PII

  21. Как я разработал легковесный Guardrails для русского языка

    В этой статье расскажу о том как я воплотил в реальность свою идею разработать легковесный prodaction guardrails. Расскажу что такое Guardrails, далее поделюсь основными компонентами lite-guardrails, его архитектурой, этапами разработки, настройкой observability, а также созданием документации по проекту. 🔥 Начинаем 🔥

    habr.com/ru/articles/1056866/

    #guardrails #python #guard #llm #pii #nsfw

  22. @geerlingguy this paints the consumer more as a victim, maybe the real corp overeach is admitting they are basically proxies for gov't surveillance - willing profiteers, maybe almost as bad as the ai industry
    #red shirt harms and impacts #tort law #ip #pii #license #osint #data brokers #secret america #who's who in america

    Bright Data (formerly Luminati Networks) is a global technology company that offers web data collection and proxy services.

  23. @geerlingguy this paints the consumer more as a victim, maybe the real corp overeach is admitting they are basically proxies for gov't surveillance - willing profiteers, maybe almost as bad as the ai industry
    #red shirt harms and impacts #tort law #ip #pii #license #osint #data brokers #secret america #who's who in america

    Bright Data (formerly Luminati Networks) is a global technology company that offers web data collection and proxy services.

  24. @thegibson hashing, masking, or obfuscating or all 3? #pii

  25. @thegibson hashing, masking, or obfuscating or all 3? #pii

  26. Does #DeleteMe Actually Get Your Info off the Internet? I Tried It

    Everyone is sick of #spam calls and creeper sites that show weirdos where you live—but can any service solve it?
    #privacy #security #pii

    wired.com/story/i-tried-delete

  27. Does #DeleteMe Actually Get Your Info off the Internet? I Tried It

    Everyone is sick of #spam calls and creeper sites that show weirdos where you live—but can any service solve it?
    #privacy #security #pii

    wired.com/story/i-tried-delete

  28. 📰 Black's Insurance and Financial Services Discloses Data Breach Affecting SSNs

    📄 Black's Insurance and Financial Services has reported a data breach that compromised customer Social Security numbers. The full scope is not yet known. Attorneys are investigating a potential class-action lawsuit. #DataBreach #Insurance #Finance #PII

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/bl

  29. DATE: June 24, 2026 at 04:05PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Stryker Seeks to Dismiss Class Action Lawsuit in #Cyberattack t.co/7OeJOMmr6B #HIPAA #PII #PHI

    Here are any URLs found in the article text:

    t.co/7OeJOMmr6B

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  30. DATE: June 24, 2026 at 04:05PM
    SOURCE: HEALTHCARE INFO SECURITY

    Direct article link at end of text block below.

    #Stryker Seeks to Dismiss Class Action Lawsuit in #Cyberattack t.co/7OeJOMmr6B #HIPAA #PII #PHI

    Here are any URLs found in the article text:

    t.co/7OeJOMmr6B

    Articles can be found by scrolling down the page at healthcareinfosecurity.com/ under the title "Latest"

    -------------------------------------------------

    Private, vetted email list for mental health professionals: clinicians-exchange.org

    Healthcare security & privacy posts not related to IT or infosec are at @HIPAABot . Even so, they mix in some infosec with the legal & regulatory information.

    -------------------------------------------------

    #security #healthcare #doctors #itsecurity #hacking #doxxing #psychotherapy #securitynews #psychotherapist #mentalhealth #psychiatry #hospital #socialwork #datasecurity #webbeacons #cookies #HIPAA #privacy #datanalytics #healthcaresecurity #healthitsecurity #patientrecords @infosec #telehealth #netneutrality #socialengineering

  31. A Free Tool [DeFlock] Maps The License Plate Readers On Your Route [Flock, Etc], Then Lets You Slide Right Past Them
    (Drivers can compare standard routes against camera-free alternatives with DeFlock’s growing surveillance database)
    --
    carscoops.com/2026/06/deflock- <-- shared technical media article
    --
    maps.deflock.org <-- shared (free) DeFlock webmap/resource
    --
    deflock.org/ <-- shared DeFlock overview web page, avoiding Flock Automated License Plate Readers
    --
    youtu.be/vU1-uiUlHTo?si=zXeNzw <-- shared YouTube video. “This Flock Camera Leak is like Netflix For Stalkers”, including lack of security and ready exposure of private & personal data
    --
    kunc.org/news/2026-06-19/fort- <-- shared media article, example, City Of Fort Collins, CO dropping contract and getting Flock cameras removed
    --
    “…
    • DeFlock can generate routes that avoid known [Automated License Plate Readers] ALPR cameras entirely.
    • Users can choose how far they want to stay from surveillance cameras.
    • The tool arrives as scrutiny of license plate readers continues to grow.
    For years, automated license plate readers have quietly spread across America. They sit on utility poles, at intersections, near shopping centers, and along roads most drivers use every day. The overwhelming majority of motorists never notice them. A free website called DeFlock changes that by showing where many of those cameras are located and, more importantly, helping users avoid them if they choose. In a world where surveillance is often invisible, that’s a surprisingly powerful feature…”
    --
    “Automated License Plate Readers (ALPRs or LPRs) are AI-powered cameras that capture and analyze images of all passing vehicles, storing details like your car's location, date, and time. They also capture your car's make, model, colour, and identifying features such as dents, roof racks, and bumper stickers, often turning these into searchable data points.
    These cameras collect data on millions of vehicles regardless of whether the driver is suspected of a crime. These systems are marketed as indispensable tools to fight crime, but they ignore the powerful tools police already have to track criminals, such as cell phone location data, creating a loophole that doesn't require a warrant…”
    #DeFlock #PII #monitoring #automated #LicensePlateReaders #ALPR #LPR #cameras #avoid #camerafree #opendata # #invasionofprivacy #stalking #security #datasecurity #data #routing #webmap #free
    #tracking #surveillance #surveillancestate #licenseplate #police #ICE #lawenforcement #warrantless #warrantlessSurveillance #warrantless_surveillance #flock #dystopia

  32. A Free Tool [DeFlock] Maps The License Plate Readers On Your Route [Flock, Etc], Then Lets You Slide Right Past Them
    (Drivers can compare standard routes against camera-free alternatives with DeFlock’s growing surveillance database)
    --
    carscoops.com/2026/06/deflock- <-- shared technical media article
    --
    maps.deflock.org <-- shared (free) DeFlock webmap/resource
    --
    deflock.org/ <-- shared DeFlock overview web page, avoiding Flock Automated License Plate Readers
    --
    youtu.be/vU1-uiUlHTo?si=zXeNzw <-- shared YouTube video. “This Flock Camera Leak is like Netflix For Stalkers”, including lack of security and ready exposure of private & personal data
    --
    kunc.org/news/2026-06-19/fort- <-- shared media article, example, City Of Fort Collins, CO dropping contract and getting Flock cameras removed
    --
    “…
    • DeFlock can generate routes that avoid known [Automated License Plate Readers] ALPR cameras entirely.
    • Users can choose how far they want to stay from surveillance cameras.
    • The tool arrives as scrutiny of license plate readers continues to grow.
    For years, automated license plate readers have quietly spread across America. They sit on utility poles, at intersections, near shopping centers, and along roads most drivers use every day. The overwhelming majority of motorists never notice them. A free website called DeFlock changes that by showing where many of those cameras are located and, more importantly, helping users avoid them if they choose. In a world where surveillance is often invisible, that’s a surprisingly powerful feature…”
    --
    “Automated License Plate Readers (ALPRs or LPRs) are AI-powered cameras that capture and analyze images of all passing vehicles, storing details like your car's location, date, and time. They also capture your car's make, model, colour, and identifying features such as dents, roof racks, and bumper stickers, often turning these into searchable data points.
    These cameras collect data on millions of vehicles regardless of whether the driver is suspected of a crime. These systems are marketed as indispensable tools to fight crime, but they ignore the powerful tools police already have to track criminals, such as cell phone location data, creating a loophole that doesn't require a warrant…”
    #

  33. 📰 ShinyHunters Leaks 234GB of Data from DentaQuest, Affecting 2.6 Million People

    ⚠️ MAJOR DATA BREACH: ShinyHunters leaks 234GB of data from DentaQuest, exposing sensitive personal & health info of 2.6 MILLION people. The leak includes names, addresses, and government IDs. #DataBreach #ShinyHunters #Healthcare #PII

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/de

  34. PII-Shield: режем персональные данные в логах до того, как они доехали до ELK

    Сначала хотелось просто скрывать случайные токены по энтропии. Потом выяснилось, что UUID, trace id и номера карт ломают эту идею, и пришлось собирать более честный фильтр логов.

    habr.com/ru/articles/1045422/

    #PII #персональные_данные #маскирование_логов #Kubernetes #sidecar #Kubernetes_operator #Go #секреты #токены #DevSecOps

  35. 📰 Strategic Education Data Breach Exposes SSNs, Passports of Over 100,000

    🎓 DATA BREACH: Strategic Education (parent of Strayer & Capella University) discloses breach affecting 100k+ individuals. Stolen data includes SSNs, driver's licenses & passport numbers. ⚠️ #DataBreach #Education #PII #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/st

  36. 𝐒𝐢𝐧𝐠𝐢𝐧𝐠 𝐑𝐢𝐯𝐞𝐫 𝐇𝐞𝐚𝐥𝐭𝐡 𝐒𝐲𝐬𝐭𝐞𝐦: 𝐁𝐞𝐭𝐰𝐞𝐞𝐧 𝐑𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞, 𝐋𝐞𝐠𝐚𝐥 𝐃𝐢𝐬𝐩𝐮𝐭𝐞𝐬, 𝐚𝐧𝐝 𝐑𝐞𝐜𝐮𝐫𝐫𝐢𝐧𝐠 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐢𝐞𝐬

    Just over two years after the devastating ransomware attack attributed to the Rhysida group, Singing River Health System (SRHS) has once again fallen victim to cybercrime. This time, the Anubis ransomware group has claimed responsibility for compromising the healthcare organization’s IT systems, stating that it stole sensitive data belonging to patients and employees before encrypting the infrastructure.

    suspectfile.com/singing-river-

    #Anubis #Data_Breach #HIPAA #PII #PHI #Ransomware #Rhysida #Singing #SRHS

  37. 𝐒𝐢𝐧𝐠𝐢𝐧𝐠 𝐑𝐢𝐯𝐞𝐫 𝐇𝐞𝐚𝐥𝐭𝐡 𝐒𝐲𝐬𝐭𝐞𝐦: 𝐁𝐞𝐭𝐰𝐞𝐞𝐧 𝐑𝐚𝐧𝐬𝐨𝐦𝐰𝐚𝐫𝐞, 𝐋𝐞𝐠𝐚𝐥 𝐃𝐢𝐬𝐩𝐮𝐭𝐞𝐬, 𝐚𝐧𝐝 𝐑𝐞𝐜𝐮𝐫𝐫𝐢𝐧𝐠 𝐕𝐮𝐥𝐧𝐞𝐫𝐚𝐛𝐢𝐥𝐢𝐭𝐢𝐞𝐬

    Just over two years after the devastating ransomware attack attributed to the Rhysida group, Singing River Health System (SRHS) has once again fallen victim to cybercrime. This time, the Anubis ransomware group has claimed responsibility for compromising the healthcare organization’s IT systems, stating that it stole sensitive data belonging to patients and employees before encrypting the infrastructure.

    suspectfile.com/singing-river-

    #Anubis #Data_Breach #HIPAA #PII #PHI #Ransomware #Rhysida #Singing #SRHS

  38. (8/n)

    ...#Twitter, #Musk already controls a huge part of the #Western #Narrative, not only on #SocialMedia.
    Empowered by the #OrangePeril, he raided each and every #US government agency in 2025, while being in charge of #DOGE, in effect stealing secret #PII on most #US citizens. Having the #SocialSecurityNumber|s as well as the mail addresses, he is able to join all data, creating a utterly transparent human datapoint.
    This is today.

    Now image him controlling... @appassionato @mina @si_irini

  39. (8/n)

    ...#Twitter, #Musk already controls a huge part of the #Western #Narrative, not only on #SocialMedia.
    Empowered by the #OrangePeril, he raided each and every #US government agency in 2025, while being in charge of #DOGE, in effect stealing secret #PII on most #US citizens. Having the #SocialSecurityNumber|s as well as the mail addresses, he is able to join all data, creating a utterly transparent human datapoint.
    This is today.

    Now image him controlling... @appassionato @mina @si_irini

  40. 📰 Bomco Data Breach Exposes SSNs, Financial, and Health Data of Over 800 Individuals

    Bomco Inc., an aerospace manufacturer, discloses a data breach from June 2025. The incident, which took nearly a year to report, exposed SSNs, financial data, and health records of over 800 people. #DataBreach #PII #PHI #CyberSecurity

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/bo

  41. 📰 DocketWise Data Breach Exposes Sensitive Personal, Financial, and Medical Data of 143,000 People

    ⚖️ Data breach at legal platform DocketWise impacts 143,000 individuals. A threat actor cloned partner repos containing a data pipeline, exposing SSNs, financial, and medical data. #DataBreach #DocketWise #PII #SupplyChain

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/do

  42. GLiNER Guard (GLiGuard): один schema-driven энкодер вместо зоопарка LLM-гардрейлов

    Деплоите LLM? Значит, обвешиваете её гардами. Сначала safety, потом PII, потом prompt injection, потом toxic BERT - и в один прекрасный день обнаруживаете, что у вас 5 классификаторов на каждой ноде и 20 forward-ов на один пользовательский запрос. GLiNER Guard (GLiGuard) - возможность схлопнуть этот стек в единый schema-driven энкодер. И да, его можно тоже промптить: через zero-shot + description.

    habr.com/ru/companies/raft/art

    #GLiNER_Guard #GLiGuard #GLiNER_2 #guardrails #PII #zeroshot #безопасность_LLM #обработка_ПД #модерация #schemadriven

  43. Punkte-Event mit Pii in Pokémon Café ReMix gestartet

    Eine neue Chance auf Pii als Mitarbeiter-Pokémon ist wieder da.

    Zur News: news.bisafans.de/12748

    #Event #IOS #Android #NintendoSwitch #Pii #PokémonCaféReMix #PunkteEvent

  44. Wisconsinites Can Keep Watching #Porn After Governor Vetoes #AgeVerification Bill

    Evers wrote that the bill doesn’t prevent platforms from giving collected personal data to third parties, such as the government or #dataBrokers. “This is a violation of personal privacy,” he wrote.
    #privacy #pii #security #wisconsin #veto

    404media.co/wisconsin-age-veri

  45. Wisconsinites Can Keep Watching #Porn After Governor Vetoes #AgeVerification Bill

    Evers wrote that the bill doesn’t prevent platforms from giving collected personal data to third parties, such as the government or #dataBrokers. “This is a violation of personal privacy,” he wrote.
    #privacy #pii #security #wisconsin #veto

    404media.co/wisconsin-age-veri

  46. #EURail went off the rails with its data #security incident: eurail.zendesk.com/hc/en-001/s

    Personally identifiable information (name, gender, birth date, passport number, residence...) got stolen and went up for sale on the dark web.

    In a recent email, EU Rail is recommending that clients take extra precaution by updating passwords and don't talk to strangers on the interwebs.

    Why is EU Rail 1) storing 2) unencrypted #pii? Why can't users remove pii from their account after intended use?

  47. Как маскировать персональные данные на изображениях: наш эксперимент с OCR и NER

    Всем привет! Меня зовут Андрей Иванов, я NLP-исследователь в R&D red_mad_robot. Мы разрабатываем систему Guardrails для защиты персональных данных (PII) и фильтрации небезопасного контента. В этой статье расскажу, как мы решали задачу точечного маскирования PII на картинках без обучения специальных визуальных детекторов. Разберём связку оптического распознавания символов (OCR) с NER-моделью, покажем метрики на реальных данных, раскроем ограничения подхода и наши решения для их преодоления.

    habr.com/ru/companies/redmadro

    #ai #llm #ocr #ner #pii #computer_vision #маскирование_данных #обработка_изображений #nlp #rnd

  48. [en] Is #AI "#supercharged #surveillance" #legal? (#USA)

    "... answer is not straightforward."

    "... huge amount of information that the #government can #collect on Americans that is not itself regulated ... by the #Constitution .. #Fourth #Amendment ..."

    "... the government can purchase commercial data ... which can include #sensitive personal information like #mobile #location and web #browsing records."

    "What AI can do is it can take a lot of information, none of which is by itself sensitive, and therefore none of which by itself is #regulated, and it can give the government a lot of powers ...".

    "AI can aggregate ... information to spot patterns, draw inferences ... at massive scale ... law has not caught up with #technological reality".

    technologyreview.com/2026/03/0

    #privacy #pii

  49. [en] Is #AI "#supercharged #surveillance" #legal? (#USA)

    "... answer is not straightforward."

    "... huge amount of information that the #government can #collect on Americans that is not itself regulated ... by the #Constitution .. #Fourth #Amendment ..."

    "... the government can purchase commercial data ... which can include #sensitive personal information like #mobile #location and web #browsing records."

    "What AI can do is it can take a lot of information, none of which is by itself sensitive, and therefore none of which by itself is #regulated, and it can give the government a lot of powers ...".

    "AI can aggregate ... information to spot patterns, draw inferences ... at massive scale ... law has not caught up with #technological reality".

    technologyreview.com/2026/03/0

    #privacy #pii