• 3 posts
  • 16 comments
Joined 8 months ago
Cake day: February 17th, 2026
  • Good question, maybe I spoke too quick. I think they might be since they extend credit and deal with connections to the banking system. But I’m NAL. At least they are going to require a real world identity when giving out credit card numbers, which is also true of traditional card companies.

    Mostly I’m OK with them knowing my IRL identity, and proving that to them. But I’m not OK with sending a digital photo of my DL to some 3rd party identity broker who tends to leak those a lot.

  • That alone is very likely enough to identify you,

    I believe you are right.

    Which cuts to something else. I do not think most ppl have an intuition, for just how little info is sufficient to ID them. It isn’t much! That unfortuntely, makes life hard for we who value privacy. And easy for those who attack privacy.

    Mathematically it isn’t an impossible fight for us. But it is an up hill fight.

  • Jurisprudence changes VERY slowly, and for good reasons. But I believe there is movement in a good direction about location data privacy.

    For a long time, the thinking was, there is no expectation of privacy in public so your location in public is not 4A protected. That was kinda reasonable 50 years ago, before massive scale data aggregation. In recent years the courts are slowly recognizing that indescriminate aggregation of loc history creates a difference in kind. The “entirety of your movements” should enjoy 4A protection, even tho a single observation of your loc is not protected.

    The courts are not a monolith. There are hundreds of thousands of judges each with their own views. The system changes slowly. There are judges still adhering to the “no expectation of privacy in public” idea. But there is a shift happening. Even SCOTUS has started to recognize that dragnet loc surveilence is a problem.

I made up the title b/c the URL is to the court’s finding. Doesn’t have a title per se.

TLDR (ruling is 38 pages, so this is BRIEF gd!)

Driver was stopped for following too close. Officer gave warning, but no citation. Officer ran ALPR history, then searched car based on ALPR. Driver admitted to having marijuana in the vehicle, which officer said he didn’t care about, and was only after hard drugs. ALPR history had driver driving a long distance for a short visit to the state.

Court ruled:

  1. Traffic stop was legal and justified by observed violation. Officer had reasonable basis to stop driver.

  2. The subsequent search was NOT constitutional, since officer did not have a warrant for ALPR data, and had no reasonable suspicion of criminal activity.

Result from ruling,

(Driver) has a reasonable expectation of privacy in the location data which tracked her movements over several weeks. … The ALPR search was an unreasonable governmental intrusion of protected privacy rights.

Vehicle search result was quashed.

There’s lots more nuance in the linked filing. Also citations. It’s really good IMO. It balances the privacy of the driver’s vehicle with the legit justification for the stop. It also notes how “persistent, dragnet surveilence” differs from other kinds. Kudos to judge Sara Hill for really digging in and understanding the privacy issues, esp around pg 28+ of the ruling.

It’s long but totally worth a read. The case does not set a binding precedent.

The legal situation is FAR from perfect. But I hope just once we can have a thread where a ton of ppl don’t immediately go, “this good privacy news is useless b/c it does not solve every single problem every single time!” It is evidence in favor of a slow but meaningful shift in ALPR jurisprudence. It stands along side recent SCOTUS rulings that also boost location data privacy, like Chatrie v United States and Carpenter v United States.

  • Ppl have been accused of crimes for pointing out, in a 100% white-hat way, that a site lets you access other ppl’s accounts just by incrementing a number in the URL. No verification against it.

    If someone abuses that maliciously? Sure, go after them. But these were honest security white-hats trying to warn, before scammers exploited it.

    To be fair, being accused for that is exceptional, not normal. But it has happened. More than once!

  • Grab llama.cpp. Self-host on your machine in a VM that has GPU permission but not network. Presto, no big-tech data collection. No fingerprinting. No profiling. No ads.

    I’ve used it like that for language translation. Sometimes I wanna read a German, Japanese or w/e page. Or say a few words to someone in their own language. Which my human brain can’t do. Local models do a more than acceptable job for me.

    You have to be really, really super careful about confabulation, sycophancy & other probs. Do not get into the habit of asking a q to the model and believing it. And don’t use it agentically. But for page translations? Other low-importance tasks? Useful.

    changes the fingerprint each session going to help

    It’s gonna be super hard to totaly defeat fingerprinting. And you’ll never know if you really have. Local model + deny network, you can be almost totally confident. “Almost”, b/c nothing is 100% perfect, ever. But you go from almost 100% chance of surveilence, to almost 0% chance of surveilence.

  • I’ve always thought having javascript totally disabled / on a whitelist basis makes you identifiable more.

    It’s complicated. That can be true. But it is often not true.

    For a total JS disable, that almost certainly makes you less identifiable. I.e, improves your privacy. It is true that JS-disable is a fingerprint. But it gives the -log2(%-who-do-that) bits of identifying info. If you prevent more bits than that from being obtained via JS, it is a net win. And JS has very powerful ways to fingerprint, and collect more bits than that log2(%) value. Thus, it is normally a privacy win to fully disable JS. Despite it putting you into a small cohort. That cohort is still bigger than the cohort the JS can bucket you into.

    But your other case, disabling some JS, that might make you more ID-able. If you disable the same subset as most other ppl, it won’t. But if the set you disable is specific to you, then that can provide enough signal to overwhelm the improvement. In that case it can hurt your privacy.

    There is not a simple yes/no answer. Which everyone wants to have. “It’s true!” “No it’s not!” “Yes it it!” Really, it depends. We must consider the factors, to know the answer. Which will vary for each person and circumstance.

  • It will depend on the site.

    Some sites you can totally disable JS, and they work fine. Often better! It can avoid the annoyware in so many sites now.

    Other sites require JS for basic functionality. But also have tons of tracking JS. On those you can disable the tracking JS and run only what is required.

    Yet other sites are such a clusterfuck from many 100’s of demains and it can be hard or impossible to unravel what is needed. Those I try to avoid the site if I can.

    Someone always will say disabling JS is a fingerprint too. Which is true, but misleading, b/c you can reduce the bits of info more by disabling JS than the bits obtained by the site seeing you disabled JS.

TLDR: Flock is moving beyond fixed roadside cameras, into drone surveilance.

With a fixed camera, you might be able to alter your travels to avoid it. In practice that is hard due to how many there are. But you can try. A drone can be anywhere. You prob won’t even know it is present most of the time. You cannot change your routes to avoid it.

We now know that Flock does not log only plates. It also IDs pedestrians and cyclists, ppl on scooters or skateboards. It seeks to build a complete picture of the movements of a whole population.

  • One day, I logged into FB and it was suggesting my co-workers as friends.

    Yah… they do that. B/c they are sleaze weasels. FB has… (pinky to mouth) one meeellllion ways to figure out your social graph.

    You ever got lunch with a co-worker? Your phone and theirs were at the same table in the same restaurant. Boom. You know that person. Or a 3rd person adds both you as friends? Boom. Or someone took a photo and you and other person were both in it? Boom. Or they buy phone call data from a data broker? Your phone called their phone. Boom.

    It’s all but impossible to stop it. I never, NEVER, had a FB account in my whole life. I never have even loaded their page, and I block all their 3rd party scripts. I have a friend who also never had. I’m 100% sure FB knows we are friends. It maintains “shadow profiles” for ppl without accounts. Our mutual friends have linked us, and FB knows that. It still gathers enough data to link us. Despite we both did everything we could.

I bet most ppl here do not use Meta products. But some may have to for w/e reason. Or you may know ppl who do. Also in the bigger world, it sitll has billions of users, 2.1B every day. This is Meta improving your experience unless you know how to opt out.

I just threw up in my mouth a little bit writing that.

Meta is planning to use the data shared by other businesses to personalize your feed and its AI responses. In a blog post on Tuesday, Meta explains that it already uses your off-platform activity, like the games you play or your purchases on other websites, to serve you ads. But now it’s expanding the scope of the content it personalizes across Facebook and Instagram.

For example, Meta says if you bought a tent online recently, you might see camping-related videos in your Reels feed. “We aren’t collecting any new data as part of this update,” the blog post says. “This is about using information that businesses already send to us to further improve your experience.”