home.social

#privacyengineering — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #privacyengineering, aggregated by home.social.

fetched live
  1. Enrollment is now open for InfoQ's AI Security & Privacy Engineering program - a 5-week online cohort for senior engineers and architects.

    Facilitated by Katharine Jarmul, author of Practical Data Privacy

    🗓️ Two cohorts this year: August 26 & October 14. (Limited seating!)

    👉 Learn more and register: bit.ly/4f3jVLp

    #AISecurity #AIEngineering #SoftwareArchitecture #InfoQ #PrivacyEngineering

  2. Enrollment is now open for InfoQ's AI Security & Privacy Engineering program - a 5-week online cohort for senior engineers and architects.

    Facilitated by Katharine Jarmul, author of Practical Data Privacy

    🗓️ Two cohorts this year: August 26 & October 14. (Limited seating!)

    👉 Learn more and register: bit.ly/4f3jVLp

  3. Privacy infrastructure has historically prioritized neutrality — encrypted traffic flows without inspection.
    However, a new initiative involving ExpressVPN and the Internet Watch Foundation introduces a different architectural approach to restrict known CSAM domains.
    The mechanism relies on OpenBoundary, a DNS-level filtering technology designed to block only domains verified by IWF.
    Technical characteristics include:
    • DNS resolver-level domain verification
    • No deep packet inspection
    • No encryption termination
    • No traffic logging or user identification
    If a requested domain appears on the IWF verified list, the connection is dropped at the network boundary.

    The initiative - “Not on My Network” - is also encouraging adoption across the privacy infrastructure ecosystem, including CyberGhost VPN, Private Internet Access.
    For security engineers, this raises an important architectural question:
    Can network-level safeguards address exploitation risks without weakening encryption guarantees?

    Source: expressvpn.com/blog/not-on-my-

    Share your technical perspective in the comments.
    Follow us for more cybersecurity engineering insights and threat intelligence discussions.

    #Infosec #Cybersecurity #PrivacyEngineering #DNS #NetworkSecurity #Encryption #VPNInfrastructure #ThreatPrevention

  4. Privacy infrastructure has historically prioritized neutrality — encrypted traffic flows without inspection.
    However, a new initiative involving ExpressVPN and the Internet Watch Foundation introduces a different architectural approach to restrict known CSAM domains.
    The mechanism relies on OpenBoundary, a DNS-level filtering technology designed to block only domains verified by IWF.
    Technical characteristics include:
    • DNS resolver-level domain verification
    • No deep packet inspection
    • No encryption termination
    • No traffic logging or user identification
    If a requested domain appears on the IWF verified list, the connection is dropped at the network boundary.

    The initiative - “Not on My Network” - is also encouraging adoption across the privacy infrastructure ecosystem, including CyberGhost VPN, Private Internet Access.
    For security engineers, this raises an important architectural question:
    Can network-level safeguards address exploitation risks without weakening encryption guarantees?

    Source: expressvpn.com/blog/not-on-my-

    Share your technical perspective in the comments.
    Follow us for more cybersecurity engineering insights and threat intelligence discussions.

    #Infosec #Cybersecurity #PrivacyEngineering #DNS #NetworkSecurity #Encryption #VPNInfrastructure #ThreatPrevention

  5. Policy shift with technical implications.
    The European Parliament endorsed an opinion proposing:
    • Social media ban under 13
    • Parental consent under 16
    • Privacy-preserving age assurance mechanisms
    • Expanded regulation under the Digital Fairness Act

    Security and engineering considerations:
    Zero-knowledge proof-based age verification?
    On-device age estimation vs centralized ID checks?

    Data minimization vs compliance logging requirements?

    AI-driven manipulation detection standards?
    Age verification at EU scale introduces non-trivial architectural challenges - particularly around privacy-by-design and cross-border enforcement.

    From a security architecture perspective:
    Can platforms implement robust age controls without increasing identity exposure risks?
    Engage below.

    Source: therecord.media/eu-lawmakers-p

    Follow @technadu for cybersecurity, AI governance, and digital compliance analysis.
    Repost to inform the security community.

    #Infosec #AgeVerification #PrivacyEngineering #DigitalPolicy #EURegulation #AIgovernance #PlatformSecurity #DataMinimization #CyberCompliance #OnlineSafety

  6. Policy development with cybersecurity implications.

    Florida’s proposed HB 945 would establish a state-level operational intelligence unit with authority extending into threat identification and counterintelligence.

    Risk dimensions:
    • Expansion of state-run surveillance infrastructure
    • Ideology-based scrutiny concerns
    • Potential inter-state policy replication
    • Oversight ambiguity and governance design challenges
    • Broader digital monitoring implications
    Security professionals understand that surveillance architecture, once normalized, rarely contracts.

    From a risk modeling perspective:
    What controls, auditability mechanisms, and transparency frameworks would be required to prevent mission creep?

    Source: theguardian.com/commentisfree/

    Engage below.
    Follow TechNadu for cybersecurity law, digital rights, and governance analysis.
    Repost to elevate the discussion within the security community.

    #Infosec #CyberPolicy #SurveillanceRisk #Governance #PrivacyEngineering #SecurityArchitecture #DigitalRights #FirstAmendment #NationalSecurity #Compliance #ThreatModeling #PublicSectorSecurity

  7. IoT privacy compliance development.
    Samsung will revise ACR data practices after legal action by the Texas Attorney General.

    Key elements:
    • Real-time viewing habit collection under scrutiny
    • Enhanced disclosure & consent flow promised
    • Emphasis on consumer transparency
    • Broader regulatory pressure on smart device telemetry

    ACR data monetization highlights a persistent tension:
    Device intelligence vs user autonomy
    Advertising revenue vs explicit consent
    Convenience vs continuous telemetry
    As regulatory enforcement increases, IoT vendors may face stricter consent design expectations.
    Question for security & privacy professionals:
    Should connected consumer devices require periodic re-consent for telemetry collection?

    Source: therecord.media/samsung-update

    Engage below.
    Follow TechNadu for privacy law, IoT security, and compliance updates.
    Repost to broaden awareness.

    #Infosec #PrivacyEngineering #ACR #IoTSecurity #DataGovernance #ConsumerPrivacy #RegulatoryCompliance #SmartDevices #CyberLaw #SecurityAwareness #DigitalRights

  8. Regulatory Enforcement Brief:
    Entity: Reddit
    Regulator: Information Commissioner's Office
    Penalty: £14.47M
    Issue: Inadequate age assurance mechanisms
    Findings:
    • Over-reliance on self-declared age
    • Alleged unlawful processing of children’s data
    • Lack of early DPIA (Data Protection Impact Assessment)
    • Enforcement under Age Appropriate Design Code
    Core tension:
    Privacy-by-minimization vs. identity-based compliance controls.
    Expect broader enforcement trends targeting platforms relying solely on self-attestation models.
    Source: therecord.media/reddit-childre

    Follow @technadu for regulatory intelligence.
    Add your compliance or security insights below.

    #Infosec #DataProtection #ICO #Reddit #PrivacyEngineering #Compliance #CyberLaw #AgeVerification #ChildSafety #RiskManagement #DigitalGovernance #SecurityNews

  9. Incident Overview:
    Victim: Odido
    Threat Actor: ShinyHunters (alleged)
    Impact: 6.2M customers confirmed
    Claimed Records: ~21M

    Vector: Customer contact system access
    Exposed data (varies per user):
    • PII, contact details
    • IBANs
    • Limited ID metadata

    Denied exposure:
    • Passwords
    • Billing data
    • SSNs
    ShinyHunters’ known TTPs include vishing, SSO hijack, OAuth device code abuse, targeting platforms tied to Microsoft, Google, and Okta.
    Identity remains the breach multiplier.
    Source: bleepingcomputer.com/news/secu

    Follow TechNadu for threat-focused reporting,
    Add your technical insights below.

    #Infosec #ThreatIntel #DataBreach #ShinyHunters #Odido #IAM #SSO #MFA #CyberExtortion #PrivacyEngineering #SecurityOperations

  10. Incident Overview:
    Victim: Odido
    Threat Actor: ShinyHunters (alleged)
    Impact: 6.2M customers confirmed
    Claimed Records: ~21M

    Vector: Customer contact system access
    Exposed data (varies per user):
    • PII, contact details
    • IBANs
    • Limited ID metadata

    Denied exposure:
    • Passwords
    • Billing data
    • SSNs
    ShinyHunters’ known TTPs include vishing, SSO hijack, OAuth device code abuse, targeting platforms tied to Microsoft, Google, and Okta.
    Identity remains the breach multiplier.
    Source: bleepingcomputer.com/news/secu

    Follow TechNadu for threat-focused reporting,
    Add your technical insights below.

    #Infosec #ThreatIntel #DataBreach #ShinyHunters #Odido #IAM #SSO #MFA #CyberExtortion #PrivacyEngineering #SecurityOperations

  11. Mullvad Campaign Blocked in UK Amid Surveillance Debate
    Mullvad VPN says its “And Then?” campaign criticizing UK surveillance measures was rejected from TV broadcast.

    The debate intersects with:
    • The Online Safety Act
    • Proposed VPN identity verification
    • Client-side scanning discussions
    • Expanded regulatory oversight

    Security implications:
    • Increased compliance pressure on privacy tools
    • Regulatory scrutiny of encryption services
    • Chilling effects on anti-surveillance advocacy
    Is this a policy enforcement issue - or a warning sign for privacy discourse?

    Source: mullvad.net/en/and-then/uk

    Engage below.
    Follow @technadu for analysis on encryption policy and digital governance.

    #Infosec #EncryptionPolicy #MassSurveillance #VPN #CyberLaw #DigitalRights #PrivacyEngineering #ThreatModeling #UKPolicy #SecurityDebate

  12. Mullvad Campaign Blocked in UK Amid Surveillance Debate
    Mullvad VPN says its “And Then?” campaign criticizing UK surveillance measures was rejected from TV broadcast.

    The debate intersects with:
    • The Online Safety Act
    • Proposed VPN identity verification
    • Client-side scanning discussions
    • Expanded regulatory oversight

    Security implications:
    • Increased compliance pressure on privacy tools
    • Regulatory scrutiny of encryption services
    • Chilling effects on anti-surveillance advocacy
    Is this a policy enforcement issue - or a warning sign for privacy discourse?

    Source: mullvad.net/en/and-then/uk

    Engage below.
    Follow @technadu for analysis on encryption policy and digital governance.

    #Infosec #EncryptionPolicy #MassSurveillance #VPN #CyberLaw #DigitalRights #PrivacyEngineering #ThreatModeling #UKPolicy #SecurityDebate

  13. The UK is moving toward mandatory proactive detection of nonconsensual intimate images.

    Under proposals backed by Keir Starmer, platforms must:
    • Remove flagged content within 48 hours
    • Prevent reuploads using hash matching
    • Deploy proactive detection “at source”
    • Face fines up to 10% of global revenue

    Regulator Ofcom is accelerating its decision on requiring technical enforcement mechanisms.
    Technical considerations:
    - Hash collision and false-positive risks
    - Cross-platform hash database coordination
    - Encryption vs scanning tradeoffs
    - Abuse-report automation workflows
    - AI-generated image detection accuracy
    Is mandatory proactive scanning the future of online content governance?

    Source: therecord.media/united-kingdom

    Drop your technical analysis below.

    Follow @technadu for advanced cybersecurity and policy reporting.

    #Infosec #DetectionEngineering #AIsecurity #HashMatching #ContentModeration #DigitalForensics #CyberPolicy #OnlineSafety #DeepfakeDetection #PrivacyEngineering #ThreatModeling #SecurityArchitecture

  14. ShinyHunters has listed a 1.67 GB JSON dataset allegedly containing 600K+ customer records tied to Canada Goose.
    Reported by BleepingComputer.

    Dataset reportedly includes:
    • checkout_id, cart_token schema indicators
    • Shipping lines & order values
    • IP telemetry
    • Device/browser metadata
    • Partial PAN (BIN + last four)
    • Authorization metadata
    No full card numbers observed in samples.

    Canada Goose states no evidence of breach of its own systems; attackers claim third-party processor origin.
    Security implications:
    • BIN + last four enable targeted card fraud attempts
    • Order value profiling identifies high-value targets
    • IP/device metadata aids social engineering
    • Historical datasets still carry active fraud potential
    Is vendor risk management keeping pace with SaaS-based commerce stacks?

    Source: bleepingcomputer.com/news/secu

    Engage below.
    Follow @technadu for advanced threat analysis.

    #ThreatIntel #DataLeak #VendorRisk #RetailSecurity #FraudPrevention #Infosec #CloudSecurity #DataExposure #ShinyHunters #CyberDefense #PrivacyEngineering

  15. Running code in the cloud usually means trusting the landlord not to peek.

    At #FOSSASIA2026, Peter Membrey (ExpressVPN) is releasing an open source framework for Secure GPU Workloads in Enclaves.

    It allows you to cryptographically verify the hardware and treat the cloud provider as an adversary. Confidential Computing is now available to everyone, not just the hyperscalers.

    rolandturner.com/The%20cloud%2 @fossasia

    #ConfidentialComputing #GPU #PrivacyEngineering #TrustNoOne #OpenSource #FOSSASIA

  16. Running code in the cloud usually means trusting the landlord not to peek.

    At #FOSSASIA2026, Peter Membrey (ExpressVPN) is releasing an open source framework for Secure GPU Workloads in Enclaves.

    It allows you to cryptographically verify the hardware and treat the cloud provider as an adversary. Confidential Computing is now available to everyone, not just the hyperscalers.

    rolandturner.com/The%20cloud%2 @fossasia

    #ConfidentialComputing #GPU #PrivacyEngineering #TrustNoOne #OpenSource #FOSSASIA

  17. Saudi Arabia’s Vision 2030 is accelerating AI adoption — but also reshaping data governance expectations across the GCC.

    Key realities for businesses:

    • Saudi PDPL is already enforced (not emerging)
    • data sovereignty expectations are growing
    • infrastructure decisions increasingly intersect with regulation

    Expansion into the region requires architectural planning, not just compliance checklists.

    #DataPrivacy #Vision2030 #AIgovernance #GCC #PrivacyEngineering

  18. Saudi Arabia’s Vision 2030 is accelerating AI adoption — but also reshaping data governance expectations across the GCC.

    Key realities for businesses:

    • Saudi PDPL is already enforced (not emerging)
    • data sovereignty expectations are growing
    • infrastructure decisions increasingly intersect with regulation

    Expansion into the region requires architectural planning, not just compliance checklists.

    #DataPrivacy #Vision2030 #AIgovernance #GCC #PrivacyEngineering

  19. Bitwarden introduces “Cupid Vault” — a 2-user shared Organization vault available on the free plan.

    Security considerations:
    • End-to-end encryption
    • Vault isolation from personal storage
    • Fingerprint phrase verification (anti-ATMIT enrollment control)
    • Bidirectional sharing
    • Revocable access

    Limitations: 2 users, 2 collections. No RBAC granularity (reserved for paid tiers).

    Question for practitioners:
    Is secure shared vault architecture preferable to federated identity or delegated access models for small trust groups?

    Source: bleepingcomputer.com/news/secu

    Join the discussion below.
    Follow @technadu for actionable security insights.

    #InfoSec #PasswordManagement #ZeroTrust #Encryption #AccessControl #CyberDefense #Authentication #SecurityArchitecture #BlueTeam #PrivacyEngineering

  20. Bitwarden introduces “Cupid Vault” — a 2-user shared Organization vault available on the free plan.

    Security considerations:
    • End-to-end encryption
    • Vault isolation from personal storage
    • Fingerprint phrase verification (anti-ATMIT enrollment control)
    • Bidirectional sharing
    • Revocable access

    Limitations: 2 users, 2 collections. No RBAC granularity (reserved for paid tiers).

    Question for practitioners:
    Is secure shared vault architecture preferable to federated identity or delegated access models for small trust groups?

    Source: bleepingcomputer.com/news/secu

    Join the discussion below.
    Follow @technadu for actionable security insights.

    #InfoSec #PasswordManagement #ZeroTrust #Encryption #AccessControl #CyberDefense #Authentication #SecurityArchitecture #BlueTeam #PrivacyEngineering

  21. The alleged ANPS breach underscores a recurring issue: legacy systems acting as high-impact failure points, especially in organizations handling sensitive personal data.

    Even when core systems are modernized, forgotten infrastructure can expose identities, medical context, and operational details - triggering GDPR risk and reputational damage.

    Source: haveibeenpwned.com/Breach/ANPS

    💬 How should security teams prioritize legacy system remediation?
    🔔 Follow TechNadu for threat-focused cybersecurity reporting

    #DataBreach #LegacySystems #GDPR #PrivacyEngineering #CyberRisk #TechNadu

  22. Spain’s response to Telegram founder Pavel Durov’s mass message underscores a growing policy-security intersection.

    Governments argue that platform scale and minimal moderation architectures can enable misuse, while platform leaders warn that expanded liability and age verification may weaken privacy, anonymity, and open discourse. Similar regulatory pressure is emerging across Europe and other regions.

    For security professionals, the issue raises questions around governance, identity systems, moderation tooling, and compliance design.

    How can platforms improve harm reduction without introducing systemic privacy risks?

    Source: theguardian.com/world/2026/feb

    Share insights and follow @technadu for grounded coverage at the intersection of security and policy.

    #Infosec #PlatformGovernance #OnlineSafety #DigitalPolicy #TechNadu #PrivacyEngineering #CyberRisk

  23. Mullvad VPN has expanded supported currencies for credit card payments, adding AED, MXN, and TRY.

    The update improves regional payment accessibility without changing its fixed €5/month pricing model or existing support for cash and cryptocurrency payments.

    From a privacy services perspective, the move highlights usability improvements rather than policy or security changes.

    Source: mullvad.net/en/blog/addition-o

    💬 How important is payment flexibility in privacy-focused services?

    ➕ Follow TechNadu for unbiased infosec and privacy coverage.

    #MullvadVPN #PrivacyEngineering #DigitalPayments #VPN #Infosec #OnlinePrivacy

  24. Surfshark has updated its website safety settings to surface risk indicators directly in Google Search results, rather than post-navigation.

    The extension flags potential data breaches, malware presence, and phishing indicators, enabling earlier decision-making in the browsing workflow. The update is limited to Chrome and Google Search environments.

    This approach aligns with a preventative security model, emphasizing early-stage user awareness rather than reactive alerts.

    💬 Do early indicators reduce real-world risk or just shift user behavior?
    ➕ Follow TechNadu for unbiased infosec coverage

    #BrowserSecurity #Surfshark #ThreatAwareness #OnlineSafety #Infosec #PrivacyEngineering

  25. SoundCloud’s December 2025 breach has been added to HIBP, confirming exposure of ~29.8M user accounts.

    The incident stemmed from unauthorized access to an internal service dashboard that enabled correlation of email addresses with public profile data. No credentials or financial information were compromised, but the case highlights how internal tooling can expand the attack surface.

    What practical controls help reduce correlation risk in large platforms?
    Source: cyberinsider.com/soundcloud-br

    Share insights and follow TechNadu for independent InfoSec coverage.

    #InfoSec #SoundCloud #HIBP #DataExposure #PrivacyEngineering #CyberRisk #SecurityOperations

  26. A technical disclosure this week detailed a conditional server-side authorization issue affecting Instagram’s mobile web interface.

    Under specific backend states and header conditions, private media metadata and CDN links were reportedly returned without authentication.

    The issue was patched silently, but the lack of formal root-cause acknowledgment has sparked discussion within the security community.

    This case underscores how partial-impact vulnerabilities can be harder to detect - and potentially more concerning - than global failures.

    How do you approach disclosure confidence when fixes arrive without explanation?

    Source: cybersecuritynews.com/instagra

    Join the discussion and follow @technadu for practitioner-focused security coverage.

    #AppSec #Authorization #BugBounty #PrivacyEngineering #Infosec #TechNadu

  27. ExpressVPN’s winter pricing highlights a broader industry trend: aggressive discounts on multi-year VPN plans paired with security-first messaging.

    From a technical standpoint, notable components include:
    • Lightway protocol for fast session establishment
    • AES-256 encryption
    • TrustedServer (RAM-only, audited) architecture
    • Private DNS and optional parental controls
    • Identity monitoring features in specific regions

    As always, pricing is only one variable - threat models, jurisdiction, and operational transparency remain key when assessing VPN services.

    What do you personally prioritize most when assessing a commercial VPN?

    Source: expressvpn.com/start/special-d

    Join the discussion and follow @technadu for neutral security analysis.

    #InfoSec #VPNArchitecture #NetworkSecurity #PrivacyEngineering #CyberSecurity #TechNadu

  28. SegurCaixa Adeslas disclosed a breach affecting personal identity and banking data of policyholders in Spain’s Extremadura region.

    Health data and billing platforms were reportedly not accessed, and no fraud has been observed so far.

    The incident reinforces the importance of secure data retention, breach containment, and clear post-incident communication to reduce secondary risks like phishing and impersonation.

    How do you assess disclosure quality in incidents like this?

    Source: hoy.es/extremadura/segurcaixa-

    Share insights and follow @technadu for objective InfoSec coverage.

    #InfoSec #DataProtection #BreachDisclosure #CyberRisk #PrivacyEngineering #SecurityOperations

  29. SegurCaixa Adeslas disclosed a breach affecting personal identity and banking data of policyholders in Spain’s Extremadura region.

    Health data and billing platforms were reportedly not accessed, and no fraud has been observed so far.

    The incident reinforces the importance of secure data retention, breach containment, and clear post-incident communication to reduce secondary risks like phishing and impersonation.

    How do you assess disclosure quality in incidents like this?

    Source: hoy.es/extremadura/segurcaixa-

    Share insights and follow @technadu for objective InfoSec coverage.

    #InfoSec #DataProtection #BreachDisclosure #CyberRisk #PrivacyEngineering #SecurityOperations

  30. Ireland plans legislation to formally permit law enforcement use of spyware, with court authorization and stated safeguards.

    The move reflects a wider trend of governments updating interception laws to match modern technology, while attempting to preserve oversight and proportionality.

    How should security professionals evaluate such frameworks from a risk and governance perspective?

    Source: therecord.media/ireland-plans-

    Share your view and follow @technadu for neutral cybersecurity and policy insights.

    #InfoSec #CyberPolicy #Surveillance #PrivacyEngineering #DigitalGovernance #LawfulInterception

  31. Recent research into sleeper browser extensions across Chrome, Edge, and Firefox highlights a persistent issue: delayed-activation threats.

    By embedding code inside images and activating only after updates, these extensions avoided early detection while maintaining prolonged access to browser data.

    The findings reinforce the importance of continuous monitoring, extension inventory management, and permission reviews - especially for widely used consumer tools.

    Follow @technadu for objective, research-driven cybersecurity reporting.

    Source: malwarebytes.com/blog/news/202

    Thoughtful discussion welcome.

    #InfoSec #ThreatIntelligence #BrowserSecurity #PrivacyEngineering #ExtensionRisk #CyberDefense #SecurityResearch #DigitalTrust

  32. The Victorian school data breach underscores how context matters in impact assessment. Even when highly sensitive fields remain untouched, exposure of identity-linked student data can carry downstream safety implications.

    Education environments combine large datasets, third-party dependencies, and vulnerable populations - making incident response as much about communication and long-term monitoring as containment.

    This case reinforces why breach severity can’t be judged solely by data categories.

    Source: 7news.com.au/news/concerns-dom

    Follow TechNadu for measured, practitioner-focused cybersecurity reporting.

    Professional discussion encouraged.

    #InfoSec #DataProtection #EducationSecurity #RiskAssessment #PrivacyEngineering #CyberResilience

  33. Eurail B.V. has disclosed a data breach affecting personal and sensitive traveler information, with investigations still ongoing.

    Potentially accessed data may include:
    • Identity and contact details
    • Passport or national ID records
    • Limited financial or health-related data for specific EU program participants

    The company reports that affected systems were secured, credentials reset, and customers advised to watch for phishing or identity-related abuse.

    This incident underscores the risks associated with centralized identity and travel databases, especially in cross-border environments.

    What security controls should be considered baseline for platforms handling high-value identity data?

    Source: helpnetsecurity.com/2026/01/15

    Share your insights, engage with the discussion, and follow @technadu for objective InfoSec coverage.

    #InfoSec #DataBreach #PrivacyEngineering #IdentitySecurity #CyberRisk #TechNadu #DataProtection

  34. The FTC finalized a consent order limiting GM and OnStar’s ability to share geolocation and driving behavior data and requiring explicit consent, access rights, and opt-out controls.

    While not a breach scenario, the case is relevant to InfoSec and privacy teams as it reflects:
    - Regulatory expectations for telemetry and behavioral data
    - Risks tied to secondary data use
    - Growing scrutiny of embedded and IoT-style data collection

    How should security and privacy teams approach data governance in connected systems?

    Source: bleepingcomputer.com/news/secu

    Follow @technadu for grounded reporting at the intersection of security, privacy, and regulation.

    #InfoSec #PrivacyEngineering #ConnectedSystems #DataGovernance #TechNadu

  35. Even small behaviors can leak data.
    Whonix protects against behavioral fingerprinting with mouse movement anonymization.

  36. Gen Digital researchers have disclosed GhostPairing, a technique that leverages WhatsApp’s multi-device functionality via social engineering to enable persistent, low-noise access to user communications.

    The case highlights how legitimate features can become attack surfaces when paired with deception rather than technical exploitation.

    Open discussion: how can platforms mitigate abuse of trusted workflows without degrading user experience?

    Follow TechNadu for objective threat analysis and security research updates.

    Source: techrepublic.com/article/news-

    #InfoSec #ThreatResearch #SocialEngineering #MessagingSecurity #PrivacyEngineering #CyberRisk

  37. Complaints filed in Europe allege cross-app data tracking involving sensitive personal data categories protected under GDPR, raising questions about consent, transparency, and third-party data brokers.

    While no regulatory findings have been issued yet, the case highlights ongoing challenges in enforcing privacy-by-design principles across complex app ecosystems.

    How should organizations better operationalize GDPR transparency and data access rights?

    Share your insights and follow TechNadu for responsible InfoSec and privacy reporting.

    #InfoSec #PrivacyEngineering #GDPRCompliance #DataGovernance #AdTech #UserConsent #TechNadu

  38. Für Dr. Aleksandra Sowa ist klar: Privacy-Enhancing Technologies (#PET) sind ein Wettbewerbsvorteil. Trotzdem fehlt es nach wie vor an Wissen und Forschung zur konkreten Umsetzung in realen Anwendungskontexten. Zentrales Stichwort: #PrivacyEngineering.

    Diese Punkte brachte die Forscherin und Vertreterin der GI-Fachgruppe PET heute morgen beim Strategiegipfel Cybersecurity ein.

    Mehr über die Aktivitäten der Fachgruppe gibts hier: fg-pet.gi.de/

    #Privacy #WirSindInformatik

  39. Think of online anonymity as being one person in a vast crowd. Every piece of personal information you reveal reduces the size of that crowd, the group of people you could plausibly be. For example, revealing your gender cuts the number of potential identities roughly in half.

    One way to regain some anonymity is through deliberate disinformation. Suppose you share \(n\) independent yes/no facts about yourself, but intentionally flip \(k\) of them (without the attacker knowing which). In that case, you increase the number of identities consistent with your answers by a factor of \(C(n,k)\).

    #OnlinePrivacy #DigitalAnonymity #InformationSecurity #CyberAwareness #PrivacyMatters #DigitalFootprint #DataProtection #InformationTheory #Anonymity #PrivacyEngineering #DataAnonymization #Disinformation #Combinatorics #SecurityResearch #ThinkBeforeYouShare #OnlineIdentity #PrivacyByDesign #DigitalEthics #ProtectYourData #InternetSafety #Privacy #CyberSecurity #Infosec #DataPrivacy #OnlineSafety #SecurityMindset

  40. Join us Friday at 10:15 in the
    @AppSecVillage
    for our "Context & Cringe: a privacy threat modeling" workshop with memes 😺, a brand new card game 🃏, and hands-on LINDDUN GO 🚗.

    #DEFCON33 #AppSec #PrivacyEngineering

  41. DeadSwitch improves in the shadows.

    Builds secure systems.
    Private solutions.
    No boxes from the shelves.
    No templates.

    Custom. Hardened. Ghost-forged.

    #DeadSwitch #OPSEC #CyberGhost #CustomSecurity #NoTemplates #PrivacyEngineering #DigitalIndependence #SignalNotNoise

  42. Master Privacy Engineering at OWASP Global AppSec 2025 EU in Barcelona!

    2-Day Training | May 27-28, 2025
    Level: Intermediate | Trainers: Kim Wuyts & Avi Douglen

    Led by Kim Wuyts and Avi Douglen, you'll gain hands-on experience tackling privacy challenges while addressing the growing skills gap in privacy engineering.

    owasp.glueup.com/event/123983/

    #Barcelona #OWASPGlobalAppSecEU2025 #PrivacyEngineering #AppSec #Cybersecurity #DevSecOps #Infosec #PrivacyByDesign

  43. I thoroughly enjoyed tag teaming with Safia Kazi to discuss the key findings of the ISACA State of Privacy Survey - Check out the podcast and let me know what you think! bit.ly/41LnIpN #privacy #security #dataprotection #regulations #privacyengineering #AI #digitaltrust

  44. Veranstaltungstipp für alle, die sich für Privacy Enhancing Techniques interessieren: Noch bis 9. März läuft die Anmeldung zur PETCon 2025.1 in #Dresden. Das Team unserer Fachgruppe PET freut sich über Beiträge (gerade auch von Studis, @iFSR) und die Anmeldung ist kostenlos!

    Alle Infos 👉 pet-con.de

    #Privacy #PrivacyEnhancingTechniques #PET #PrivacyEngineering #WirSindInformatik #TUDresden

  45. Imagine living in a digital age where every click feels like a trail of breadcrumbs. AI-driven Privacy Engineering can revolutionize data protection! 🚀🌟 Join the movement for a safer online space. Follow for insights! #PrivacyEngineering #AI #DataProtectionmedium.com/@falitroke/the-futu

  46. #CaseStudy – learn how #DoorDash proactively embeds privacy into its products.

    #PrivacyEngineering, an overlooked #SoftwareArchitecture practice, provides an example of geomasking users' address data to better protect their privacy.

    More on #InfoQ: bit.ly/3NF8CLg

    #Security

  47. Happy to announce that after finishing an assignment this week I now have some availability if anyone is looking for a #privacy #dataprotection or #cybersecurity consultant, external #dpo, #expert in #privacybydesign and #privacyengineering or needs some advice on the development of their privacy programme or #training.

    My calendar tends to fill up quite quickly so if you are interested please get in touch as soon as possible.