<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Privacat Insights: Privacy Disasters]]></title><description><![CDATA[A special page just for privacy disasters content]]></description><link>https://insights.priva.cat/s/privacy-disasters</link><image><url>https://substackcdn.com/image/fetch/$s_!CzOc!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8a98bb-e5a1-4e4e-b3fa-bb8b2d8a2eeb_1024x1024.png</url><title>Privacat Insights: Privacy Disasters</title><link>https://insights.priva.cat/s/privacy-disasters</link></image><generator>Substack</generator><lastBuildDate>Mon, 06 Apr 2026 19:17:05 GMT</lastBuildDate><atom:link href="https://insights.priva.cat/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Privacat]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[serioustrouble@privacat.anonaddy.com]]></webMaster><itunes:owner><itunes:email><![CDATA[serioustrouble@privacat.anonaddy.com]]></itunes:email><itunes:name><![CDATA[Privacat]]></itunes:name></itunes:owner><itunes:author><![CDATA[Privacat]]></itunes:author><googleplay:owner><![CDATA[serioustrouble@privacat.anonaddy.com]]></googleplay:owner><googleplay:email><![CDATA[serioustrouble@privacat.anonaddy.com]]></googleplay:email><googleplay:author><![CDATA[Privacat]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Privacy Disasters: Microsoft, Just Because You Can ]]></title><description><![CDATA[... Doesn't mean you should. Here's why.]]></description><link>https://insights.priva.cat/p/privacy-disasters-microsoft-just-c71</link><guid isPermaLink="false">https://insights.priva.cat/p/privacy-disasters-microsoft-just-c71</guid><dc:creator><![CDATA[Privacat]]></dc:creator><pubDate>Sat, 03 Aug 2024 12:40:48 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!e6k6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e6k6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e6k6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 424w, https://substackcdn.com/image/fetch/$s_!e6k6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 848w, https://substackcdn.com/image/fetch/$s_!e6k6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 1272w, https://substackcdn.com/image/fetch/$s_!e6k6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e6k6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png" width="1245" height="1562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1562,&quot;width&quot;:1245,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2021464,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e6k6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 424w, https://substackcdn.com/image/fetch/$s_!e6k6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 848w, https://substackcdn.com/image/fetch/$s_!e6k6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 1272w, https://substackcdn.com/image/fetch/$s_!e6k6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I couldn&#8217;t help myself. What better image than the original Hollywood classic? </figcaption></figure></div><p><strong>Update:</strong> Kevin Beaumont on his <a href="https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e">Double Pulsar blog</a>, added some very useful additional context on how Recall works at a technical level, and the information security implications of Microsoft&#8217;s approach. I discussed many of the problems he identified (non-optionality,  exploitability by adversaries like hackers/governments, the fact that there&#8217;s no filtering of &#8230; anything). What I did not know was that in addition to recording everything you do on your machine as an OCR&#8217;d screenshot, it is <em>also writing that text into an easily searchable (and grabbable) SQLite database in the user&#8217;s folder. </em></p><p>Guys. I cannot begin to express how absolutely insane and bad that is. I have added Kevin&#8217;s observations below as DPIA risks in bold. He also has some very helpful suggestions for how to disable this abject nightmare, so his post is worth reading. </p><div><hr></div><p>This week, Microsoft graced the world with yet another tech idea that comes straight out of a <em><a href="https://www.imdb.com/title/tt2089050/#:~:text=In%20the%20near%20future%2C%20everyone,they%20do%2C%20see%20and%20hear.">Black Mirror</a> </em>episode: an always-on, always-recording life-logging tool that takes screenshots of everything you do on your computer. But now with AI to find things!<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> </p><p>Here&#8217;s what <a href="https://support.microsoft.com/en-us/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c">Microsoft had to say</a>: </p><blockquote><p>Search across time to find the content you need. &#8230; With Recall, you have an explorable timeline of your PC&#8217;s past. Just describe how you remember it and Recall will retrieve the moment you saw it. <strong>Any photo, link, or message can be a fresh point to continue from</strong>. As you use your PC, <strong>Recall takes snapshots of your screen. Snapshots are taken every five seconds</strong> while content on the screen is different from the previous snapshot. Your snapshots are then locally stored and locally analyzed on your PC. Recall&#8217;s analysis allows you to search for content, including both images and text, using natural language. Trying to remember the name of the Korean restaurant your friend Alice mentioned? Just ask Recall and it retrieves both text and visual matches for your search, automatically sorted by how closely the results match your search. Recall can even take you back to the exact location of the item you saw.</p></blockquote><p>This is one in a very long list of ideas that indicates two things: </p><ol><li><p>Some things are better left as half-baked &#8216;philosophical&#8217; ideas cooked up in dorm rooms when you&#8217;re high with your friends;</p></li><li><p>Tech project teams clearly like reading/watching dystopian sci-fi, but continue to ignore the &#8216;cautionary tale&#8217; aspects of said genre entirely. </p><p></p></li></ol><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!i98-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!i98-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i98-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i98-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i98-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!i98-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg" width="400" height="291.1764705882353" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:495,&quot;width&quot;:680,&quot;resizeWidth&quot;:400,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Alex Blechman @AlexBlechman Sci-Fi Author: In my book I invented the Torment Nexus as a cautionary tale Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus 5:49 PM Nov 8, 2021. Twitter Web App&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Alex Blechman @AlexBlechman Sci-Fi Author: In my book I invented the Torment Nexus as a cautionary tale Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus 5:49 PM Nov 8, 2021. Twitter Web App" title="Alex Blechman @AlexBlechman Sci-Fi Author: In my book I invented the Torment Nexus as a cautionary tale Tech Company: At long last, we have created the Torment Nexus from classic sci-fi novel Don't Create The Torment Nexus 5:49 PM Nov 8, 2021. Twitter Web App" srcset="https://substackcdn.com/image/fetch/$s_!i98-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 424w, https://substackcdn.com/image/fetch/$s_!i98-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 848w, https://substackcdn.com/image/fetch/$s_!i98-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!i98-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1309d81-330e-4607-84f4-34ee312bbb9f_680x495.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">This meme will never get old. </figcaption></figure></div><p>Recall (they really should have just called it Torment Nexus 1), is on by <em>default. </em>Any indicia of it being around is only present if you activate it with a Windows key, or were involved in the initial setup. It records everything that you do on your PC, unless you explicitly either shut the thing off, or manually exclude certain apps or websites. </p><p>Thankfully, it does filter private browsing activity and websites, but only if you&#8217;re using <a href="https://support.microsoft.com/en-us/windows/retrace-your-steps-with-recall-aa03f8a0-a78b-4b3e-b0a1-2eb8ac48701c#:~:text=What%20if%20I-,don%E2%80%99t,-want%20Recall%20to">Edge</a> (or to a lesser extent, a Chromium-based browser &#8212; get fucked, Mozilla users!) Users must <em><strong>manually</strong></em> add websites in Recall settings, because nothing exemplifies &#8216;user choice&#8217; and control like adding to cognitive load in the UX: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ufe-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ufe-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 424w, https://substackcdn.com/image/fetch/$s_!Ufe-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 848w, https://substackcdn.com/image/fetch/$s_!Ufe-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 1272w, https://substackcdn.com/image/fetch/$s_!Ufe-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ufe-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png" width="438" height="361.8914835164835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1203,&quot;width&quot;:1456,&quot;resizeWidth&quot;:438,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Screenshot of adding a website to the filter list in the Recall &amp; snaphots page in Windows settings&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Screenshot of adding a website to the filter list in the Recall &amp; snaphots page in Windows settings" title="Screenshot of adding a website to the filter list in the Recall &amp; snaphots page in Windows settings" srcset="https://substackcdn.com/image/fetch/$s_!Ufe-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 424w, https://substackcdn.com/image/fetch/$s_!Ufe-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 848w, https://substackcdn.com/image/fetch/$s_!Ufe-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 1272w, https://substackcdn.com/image/fetch/$s_!Ufe-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3a5d097-af52-4257-b8fb-0ab12b710316_1660x1371.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Manually adding a website, because this is going to happen. </figcaption></figure></div><p>But fear not: Even if you managed to disable things and block website monitoring, Microsoft still records things if you accidentally button-smash the &#8216;launch Recall&#8217; feature. As a Windows user, I have accidentally button-smashed so many things that this strikes me as less a possibility, and more an eventuality. </p><p>Snapshots are stored forever, <strong>with the text recorded into a plaintext SQLite database in the user&#8217;s AppData/CoreAIPlatform folder.</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a><strong> </strong>At least until you run out of disk space, and then it follows a first in, first out process. Data is also encrypted at rest using <a href="https://support.microsoft.com/en-au/windows/privacy-and-control-over-your-recall-experience-d404f672-7647-41e5-886c-a3c59680af15#:~:text=a%20new%20snapshot.-,Snapshot,-storage%3A%20content%20stays">Bitlocker or Device Encryption</a>, which is better than nothing.  You do not need to run as admin to see this file. <em>I cannot even begin to explain again, how bad this is. </em></p><p>There&#8217;s no indicator (as far as I can tell) showing users whether Recall has been activated. There&#8217;s also no logic built in to prevent storage of things <a href="https://x.com/GossiTheDog/status/1792827607781867972">like financial or credential information in a snapshot</a>, sensitive materials like your nudes or private conversations. Though, of course, it being a Microsoft product, there are controls against storing DRMed materials. </p><p>So, needless to say, if you sit down to use someone else&#8217;s computer to say, check your bank account or whatever, congrats, they now have access to everything. They won&#8217;t be able to see that Kindle book you&#8217;re reading though. As Kevin notes on his blog, the actual database &#8220;<strong>compresses well, several days working is around ~90kb. </strong><em><strong>You can exfiltrate several months of documents and key presses in the space of a few seconds with an average broadband connection</strong></em><strong>.&#8221; </strong> </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!NI_n!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!NI_n!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 424w, https://substackcdn.com/image/fetch/$s_!NI_n!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 848w, https://substackcdn.com/image/fetch/$s_!NI_n!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 1272w, https://substackcdn.com/image/fetch/$s_!NI_n!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!NI_n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png" width="1456" height="368" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:368,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:254776,&quot;alt&quot;:&quot;Current situation: InfoStealer malware, stealing your saved passwords.  Coming situation: CoPilot Recall malware, where it steals everything you&#8217;ve ever typed or viewed as it&#8217;s in an already assembled database.   Thanks, Microsoft, for your service to enabling malicious hackers.&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Current situation: InfoStealer malware, stealing your saved passwords.  Coming situation: CoPilot Recall malware, where it steals everything you&#8217;ve ever typed or viewed as it&#8217;s in an already assembled database.   Thanks, Microsoft, for your service to enabling malicious hackers." title="Current situation: InfoStealer malware, stealing your saved passwords.  Coming situation: CoPilot Recall malware, where it steals everything you&#8217;ve ever typed or viewed as it&#8217;s in an already assembled database.   Thanks, Microsoft, for your service to enabling malicious hackers." srcset="https://substackcdn.com/image/fetch/$s_!NI_n!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 424w, https://substackcdn.com/image/fetch/$s_!NI_n!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 848w, https://substackcdn.com/image/fetch/$s_!NI_n!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 1272w, https://substackcdn.com/image/fetch/$s_!NI_n!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab67cf91-df27-41cd-957a-9952e50bfecf_2571x650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screenshot from @GossiTheDog reminding us that the venn diagram between invasive malware/spyware and this is &#8230; basically a circle.  </figcaption></figure></div><p>About the only good thing about this version of the Torment Nexus, compared to a previous version of this that was released with far less fanfare in <a href="https://betanews.com/2018/05/02/use-windows-10-timeline/">Windows 10</a> (h/t to  themudman.bsky.social for pointing that out!), is that everything is stored &amp; processed locally instead of being sent to the cloud. At least for now.  </p><p>Unsurprisingly, regulators immediately noticed, and the ICO, which is the UK&#8217;s data protection regulator, announced days after launch that they had <a href="https://www.bbc.com/news/articles/cpwwqp6nx14o">initiated an investigation</a>. I&#8217;m sure Ireland as Microsoft&#8217;s lead regulator, as well as Germany, France, and other countries data protection regulators will soon follow.  <strong>Update: According to Cianan Brennan over at the Irish Examiner, the <a href="https://www.irishexaminer.com/opinion/commentanalysis/arid-41404820.html">DPC is allegedly looking into it</a>.  </strong></p><p>Alright, so that&#8217;s the background. Let&#8217;s get to the fun part (for me at least) of the Privacy Disasters series: pointing out the risks that Microsoft <em>should </em>have identified if they&#8217;d done any sort of data protection impact assessment (DPIA) before launching this eldritch horror. </p><h1>The DPIA that Microsoft Should Have Done</h1><p>First, a little legal reminder of why this needs to happen, as this wasn&#8217;t apparently clear to anyone at Microsoft.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> Under Article 35 of the General Data Protection Regulation (GDPR), a controller<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> must perform a data protection impact assessment when certain &#8220;high risk&#8221; processing activities occur. The <a href="https://www.dataprotection.ie/sites/default/files/uploads/2018-11/Data-Protection-Impact-Assessment.pdf">Irish DPC helpfully provides a list</a> of high-risk processing activities. For purposes of the Recall product, Microsoft probably should have done a DPIA given that the processing its doing is high-risk for one or more of the following reasons:  </p><ul><li><p><strong>Using innovative new technological or organisational solutions</strong> (like AI and creepy always-on life-logging tools);</p></li><li><p><strong>Processing used for the purpose of systematically monitoring, tracking or observing individuals&#8217; location or behaviour</strong> <strong>(</strong>like what websites they visit, what apps they use, and who they communicate with);</p></li><li><p><strong>Processing that concerns vulnerable data subjects (</strong>for example, children, folks with limited or impaired capacity, people in abusive situations);</p></li><li><p><strong>Undertaking large-scale processing of personal data </strong>(for example, law enforcement would <em>love </em>this information to go after baddies, employers to track employees, and domestic abusers to stalk their victims).</p></li></ul><p>The Recall tool also arguably processes personal data on a large-scale for a purpose(s) other than that for which it was initially collected, especially if the tool is on by default and the privacy notice fails to identify every processing activity that Recall can be used for. The large-scale in this case is looking at Recall in aggregate (it&#8217;s going to be on by default on all CoPilot+ laptops apparently unless users disable it).<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a></p><p>Now that I&#8217;ve got the <em>why DPIA</em> out of the way, let&#8217;s look at some of the questions and risks that I&#8217;d probing the product team &amp; engineers about. That is, after I got all the swearing out of the way: </p><ul><li><p><strong>Transparency: </strong>How are users being informed of the processing that&#8217;s happening here? Is it buried in a 20-page privacy notice that nobody is going to read? What about users on shared machines like family computers, or shared terminals at a public library? Right now it looks very much &#8216;one and done&#8217;, which means Recall is likely to catch a whole lot of users off-guard.</p></li><li><p><strong>Consent of users/third parties: </strong>Currently, users are only notified when a fresh install of Windows 11 occurs. If someone else installs Windows for you and selects the default options, have you, as the actual user<em> </em>provided informed, meaningful consent? If I&#8217;m in an abusive relationship and my abuser cheerfully acts as my tech support and turns this on by default to monitor my search and website activity, what then? </p><p></p><p>What about third parties? If I use Recall, anyone I interact with online (on chat, or in a video) has no clue they&#8217;re being recorded. While screenshots and video logging exist today, the <em>frequency </em>and likelihood of any specific interaction being recorded and accessed again is tiny. Most people aren&#8217;t taking screenshots of <em>every single change at 5-second intervals</em>. That frequency gets much higher when we&#8217;re talking about every Windows 11 system. As of 2019, Windows is installed on over <a href="https://www.zdnet.com/article/microsoft-says-windows-10-is-now-on-more-than-800-million-devices/">800 million devices</a>, and<a href="https://gs.statcounter.com/os-market-share"> currently (as of April 2024) represents 30% of the entire OS market share</a> in the world, with <a href="https://gs.statcounter.com/os-version-market-share/windows/desktop/worldwide">Windows 11 making up 26% of that</a>. That&#8217;s an awful lot of devices potentially recording everything.  </p></li><li><p><strong>Proportionality: </strong>This leads in nicely to my next concern. Recall is monitoring <em>almost everything </em>a user does on their PC. Every chat. Every website click. Every draft email. </p><p></p><p>Our collective expectations of privacy are that most people we chat with aren&#8217;t invasively recording our every comment, utterance, or intimate moment. We assume that our early, roughly drafted emails disappear into the ether after we send the final, polished piece. We assume a modicum of control over what we share with others. If we share something or post something, we usually can delete it later. Or we can set a timer to delete messages after a certain period of time (like on Signal or SnapChat). But these assumptions no longer hold with an always-recording and instantly searchable life-logging tool like Recall. <br><br><strong>Also, deleting the physical contents being &#8216;recalled&#8217; does not delete the stored details in the database. That sticks around </strong><em><strong>indefinitely. </strong></em></p></li><li><p><strong>Children: </strong>What about kids? Most data protection laws, including the GDPR, have heightened standards for consent in relation to children. And while many kids have learned the value of deleting web browser activity, they may not know that mom &amp; dad turned this thing on and are monitoring everything they do on the family computer, like whether they looked for information on sexual health, bullying, gender identity, spoke to a friend about family abuse, recorded a suggestive selfie, or did other things they probably don&#8217;t want the parental units to know about. <br><br>Windows is also popular with schools, and I don&#8217;t even want to begin to imagine how Recall would be used in that situation. </p></li><li><p><strong>Expanding Purposes: </strong>Microsoft is effectively installing a <a href="https://en.wikipedia.org/wiki/Keystroke_logging">keystroke-logging</a> / spyware tool on everyone&#8217;s CoPilot+ enabled machine. While Recall currently processes and stores things on-device (including AI processing, yay), what assurances do users have that it will stay that way? What if Microsoft strikes a really neat deal with OpenAI or an advertiser, that shifts processing or storage to the cloud in order to &#8216;improve user experience&#8217; or &#8216;provide more targeted ads&#8217;? <br><br>What if Microsoft is compelled by the US or an adversarial government to monitor criminal behavior, report &#8216;grooming&#8217; behavior, or target members of a disfavored group, like journalists? </p></li></ul><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!inCB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!inCB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 424w, https://substackcdn.com/image/fetch/$s_!inCB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 848w, https://substackcdn.com/image/fetch/$s_!inCB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 1272w, https://substackcdn.com/image/fetch/$s_!inCB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!inCB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png" width="1456" height="1294" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1294,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1308441,&quot;alt&quot;:&quot;VX-Underground: \&quot;tl;dr Microsoft introduces 24/7 surveillance functionality for the NSA and/or CIA but markets it as a feature that you'll like\&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="VX-Underground: &quot;tl;dr Microsoft introduces 24/7 surveillance functionality for the NSA and/or CIA but markets it as a feature that you'll like&quot;" title="VX-Underground: &quot;tl;dr Microsoft introduces 24/7 surveillance functionality for the NSA and/or CIA but markets it as a feature that you'll like&quot;" srcset="https://substackcdn.com/image/fetch/$s_!inCB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 424w, https://substackcdn.com/image/fetch/$s_!inCB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 848w, https://substackcdn.com/image/fetch/$s_!inCB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 1272w, https://substackcdn.com/image/fetch/$s_!inCB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47d687ce-ba09-4ea8-9a0a-7cbf98de7f21_1748x1553.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Vx-Underground is brutal.</figcaption></figure></div><p></p><ul><li><p><strong>Surveillance &amp; Retaliation: </strong>Recall isn&#8217;t just for end-users &#8212; Microsoft envisions this tool being widely used by <a href="https://learn.microsoft.com/en-us/windows/client-management/manage-recall">businesses as well</a>. For the enterprise, policies are set at the group level, which means that individual employees won&#8217;t be able to opt out and disable always-on workplace monitoring, though they may be able to delete snapshots, and filter websites &amp; apps. It&#8217;s honestly a bit unclear. Once again, this creates a &#8216;consent&#8217; issue. The regulators are pretty clear that the employment relationship is lopsided and imbalanced making reliance on consent a non-starter in most employment contexts. </p><p></p><p>Remember that draft email I mentioned in the proportionality section? Now imagine that it&#8217;s an early draft of an email you wrote to your boss because he ticked you off that day. How many of us have written an initial draft email in anger or frustration, only to sit on it for an evening, pet a cat, cool down and draft something more measured and reasonable in the morning? I doubt it&#8217;s just me, although I do have rage issues. <br><br>But now, if you&#8217;re at work and Recall is on, your boss will also be able to find out that your seemingly-measured response started out as an angry, profanity-laden rant where you insulted your bosses&#8217; mom, and told him he sucked as a human being. Your initial frustration (which was never sent, mind you!) might cost you your job.    </p></li><li><p><strong>Exfiltration &amp; Data Breaches: <a href="https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e">Kevin went into great detail about the threats from exfiltration of data, and how </a></strong><em><strong><a href="https://doublepulsar.com/recall-stealing-everything-youve-ever-typed-or-viewed-on-your-own-windows-pc-is-now-possible-da3e12e9465e">easy it is</a>. </strong></em><strong>&#8220;I have automated exfiltration, and made a website where you can upload a database and instantly search it.&#8221; While he hasn&#8217;t made this live, what this means is that if he figured it out, a whole load of people will be able to easily do the same once this hits go-live. <br><br>There is also an API for searching user activity, and third party apps can plug in to &#8216;enrich&#8217; or view stored data.</strong>  <br><br>As Kevin observed we&#8217;re going to see an explosion in data breaches &#8212; both in frequency (because it&#8217;s on-by-default and most people won&#8217;t know), and severity. <br><br>&#8221;<em>&#8230; if people have used a Windows device with Recall to access the service/app/whatever, hackers can see everything and assemble data dumps without the company who runs the service even being aware. The data is already consistently structured in the Recall database for attackers.</em></p><p><em><br>So prepare for AI powered super breaches. Currently credential marketplaces exist where you can buy stolen passwords &#8212; soon, you will be able to buy stolen customer data from insurance companies etc as the entire code to do this has been preinstalled and enabled on Windows by Microsoft.&#8221; </em></p></li><li><p><strong>Compliance Hell: </strong>That leads me to a related concern &#8212; all of this newly collected, stored, and searchable data means a whole lot more compliance hell. If businesses think access, rectification and deletion requests suck ass now, <em>multiply that by every single snapshot, on every employee&#8217;s device, for every single change ever made. </em>And let&#8217;s not even get started on litigation holds! <em> </em> </p></li><li><p><strong>Controllership: </strong>This, IMHO is huge, and is likely to be overlooked until it creeps up in a lawsuit somewhere or gets called out by a regulator. Right now, it appears that Microsoft assumes that there&#8217;s no real GDPR or data protection issues at play because Recall is under the &#8216;control&#8217; of end users/individuals, and processing activities done by individuals are generally out of scope for GDPR purposes since they are considered a &#8216;purely personal or household activity&#8217;.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-6" href="#footnote-6" target="_self">6</a>  </p><p></p><p>Ignoring the business use case I mentioned above, I think there&#8217;s an interesting question of whether the use of Recall by an individual user is in fact always a &#8216;purely personal or household activity.&#8217; The GDPR explains (in Recital 18) that the &#8216;household exception&#8217; applies when an individual is processing (aka, doing stuff with) personal data for personal reasons, with no &#8216;connection to a professional or commercial activity.&#8217; <br><br>The intent of the exception (which was drafted in the early days of the internet) was pretty simple: the EU didn&#8217;t want to make every type of private communication or use of personal data a giant assache. The Commission reasoned that nobody wanted to require Joe Random User to post a transparency notice or set up a data processing agreement when he emailed grandma, or posted his group selfie on Twitter. And no regulators wanted to enforce against Joe Random, because that would <em>suck</em>.  </p><p></p><p>But the household exemption isn&#8217;t absolute, and over the years, there have been a few cases clarifying when it applies (correspondence, and communications with friends) and when it doesn&#8217;t (<a href="https://gdprhub.eu/index.php?title=CJEU_-_C-212/13_-_Franti%C5%A1ek_Ryne%C5%A1">CCTV recording of public spaces outside of a home</a>, <a href="https://gdprhub.eu/index.php?title=CJEU_-_C-101/01_-_Bodil_Lindqvist">publication of personal details of others on a blog</a>). It turns out, that the &#8216;purely&#8217; bit in &#8216;purely personal or household activity&#8217; is really important, actually. It&#8217;s not enough, in other words, that processing is done for a personal reason &#8212; it has to be <em>only </em>for a personal or household use. When you start adding others to the mix and sharing that information, things get messy.  </p><p></p><p>One aspect that I think damns Microsoft here (and potentially many individuals who use Recall) is that Microsoft envisions that app developers may create and interface with Recall to provide <a href="https://learn.microsoft.com/en-us/windows/ai/apis/recall">enhanced user experiences</a> &#8212; for example, the ability to jump back into a task that has been &#8216;recalled&#8217;. I&#8217;m not sure that an interface that allows say, some random Microsoft app to pull up your Recall logs qualifies as a purely household activity anymore, especially if that application is doing different things with the data (like harvesting it for content/AI training). </p><p></p><p>Nor is the deeply troubling use-case that <a href="https://bsky.app/profile/did:plc:kw4kcuzwirhgox25tq3uvkfk/post/3kt2uoh7zlp2z">Evacide</a> reminded me of: what happens when a domestic abuser uses Recall to stalk their partner? <em>Did the European Commission really intend to legitimize or at least exempt stalking as a household activity?</em> <br><br>And if the household exception doesn&#8217;t hold, does that make us all controllers? Imagine trying to help your neighbor with an access request. Or going through mom&#8217;s Recall snapshots to delete every time she said something nasty about Timmy down the street. Or filing a data breach notification when someone manages to break into your machine. </p></li></ul><p>There&#8217;s more I could include here, but I&#8217;m at the email limit. Suffice to say, Recall, as it exists now, represents a privacy disaster. Maybe it could be improved. Certainly Microsoft could do better. As it stands though, I suspect Microsoft will face lots of regulatory ire, and it&#8217;s appropriate. They should have talked to me first. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://insights.priva.cat/subscribe?"><span>Subscribe now</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/p/privacy-disasters-microsoft-just-c71/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://insights.priva.cat/p/privacy-disasters-microsoft-just-c71/comments"><span>Leave a comment</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/p/privacy-disasters-microsoft-just-c71?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://insights.priva.cat/p/privacy-disasters-microsoft-just-c71?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p></p><p></p><p> </p><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>And for more historical nerds, <a href="https://en.wikipedia.org/wiki/As_We_May_Think">Vannevar Bush</a>&#8217;s 1945 essay, <em><a href="https://www.theatlantic.com/magazine/archive/1945/07/as-we-may-think/303881/">As We May Think</a>. </em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Kevin linked to a video where one of the Microsoft engineers demonstrated how to access that file. Which is stored in unencrypted plaintext on your machine if you&#8217;re logged in. https://cyberplace.social/system/media_attachments/files/112/535/509/719/447/038/original/7352074f678f6dec.mp4 </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Or it was, and the advice was simply ignored by the product team and senior leadership, to which I say, <em>listen to your fucking DP team next time. </em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Controllership will be tricky here because of the local storage aspects which I discuss below, but for purposes of the larger DPIA exercise, I&#8217;m treating Microsoft as a controller. They&#8217;re at least deciding the &#8216;means and purposes&#8217; of the tool, including the fact that it&#8217;s on by default.  </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>I&#8217;m less confident in this compared to the others, as everything will be stored and processed locally. Provided Microsoft isn&#8217;t lying and shipping everything to the cloud (or shipping the learning outputs to the cloud) it may not meet the large-scale threshold at an individual use level. Large scale monitoring would apply if organizations turn this on to say, monitor their employees though. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-6" href="#footnote-anchor-6" class="footnote-number" contenteditable="false" target="_self">6</a><div class="footnote-content"><p>Under Article 2 GDPR, the data protection laws do not apply to a person processing data for personal or &#8216;purely household&#8217; activities that have no connection to a &#8216;professional or commercial activity.&#8217;  Examples of personal/household activities include correspondence, posting on a social media site, sending an email to your friend, or say, recording videos of your cat. However, the GDPR still applies to controllers or processors who <em>provide</em> the service to end users. </p><p>For example, I am not a controller when I use Twitter, but Twitter remains a controller/ processor governed by the GDPR.  </p></div></div>]]></content:encoded></item><item><title><![CDATA[Privacy Disasters: AI Spy-Wearables, and the Scourge of Competing Friendants ]]></title><description><![CDATA[Wherein, I break down why 'always-on' wearable tech is a blight on humanity, and share a mock DPIA covering two competing 'Friend' Pendants.]]></description><link>https://insights.priva.cat/p/privacy-disasters-ai-spy-wearables-e4e</link><guid isPermaLink="false">https://insights.priva.cat/p/privacy-disasters-ai-spy-wearables-e4e</guid><dc:creator><![CDATA[Privacat]]></dc:creator><pubDate>Sat, 03 Aug 2024 12:38:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0D8E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h1>A Three-Way Torment Nexus</h1><p>My body has a bad habit as of late. Despite taking melatonin, I consistently wake up at about 4:50am every morning. I&#8217;m not <em>up-up</em>, but I&#8217;m up enough that I can mindlessly scroll on my phone, where I catch up on all of the latest privacy disasters, discourse and outrage that occurred during the four hours of sleep I was able to manage. Yesterday, I was greeted with this on my <a href="https://x.com/AviSchiffmann/status/1818284595902922884">Twitter timeline</a>: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0D8E!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0D8E!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 424w, https://substackcdn.com/image/fetch/$s_!0D8E!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 848w, https://substackcdn.com/image/fetch/$s_!0D8E!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 1272w, https://substackcdn.com/image/fetch/$s_!0D8E!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0D8E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png" width="478" height="668.7319461444308" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1143,&quot;width&quot;:817,&quot;resizeWidth&quot;:478,&quot;bytes&quot;:952248,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0D8E!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 424w, https://substackcdn.com/image/fetch/$s_!0D8E!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 848w, https://substackcdn.com/image/fetch/$s_!0D8E!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 1272w, https://substackcdn.com/image/fetch/$s_!0D8E!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa3cecb48-85d1-4fd7-bd07-ab9fa3156303_817x1143.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">*chef&#8217;s kiss* to Marques Brownlee for that brilliant dig. </figcaption></figure></div><p>The video features four vignettes of Gen Zers living their best lives, wearing what looks like a slightly thicker and more glowy Apple AirTag around their necks<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> The first scene features a 20-something woman, exerting herself on a solitary hike in the woods, the next a frustrated guy playing a video game with trash-talking friends, the third a woman messily eating a falafel in her non-descript apartment, and the fourth is what I can only describe as an extremely awkward date on someone&#8217;s rooftop. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Pi0P!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Pi0P!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Pi0P!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Pi0P!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Pi0P!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Pi0P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg" width="1456" height="845" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:845,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;This looks like a glowing Apple AirTag on a chain&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="This looks like a glowing Apple AirTag on a chain" title="This looks like a glowing Apple AirTag on a chain" srcset="https://substackcdn.com/image/fetch/$s_!Pi0P!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Pi0P!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Pi0P!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Pi0P!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F76437088-3c9e-4566-9f62-b0861dab9cda_2496x1448.jpeg 1456w" sizes="100vw"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And regardless of whether the characters are alone or with other actual humans, all are sporting this goofy-looking pendant, known as the &#8216;Friend&#8217; (or possibly &#8216;Emily&#8217;?) that is recording in real-time their lives and feeding all of that to a large language model (LLM).  </p><p>The noble goal of this always-on friend, according to the device&#8217;s founder, Avi Schiffmann in a recent <em>Wired </em>article, is to <a href="https://www.wired.com/story/friend-ai-pendant/">stave off loneliness</a> by offering AI-based companionship. I liken it to what happens if the AI chatbot Replika had a three-way with Microsoft&#8217;s Recall, and the failed <a href="https://www.wired.com/story/humane-ai-pin-700-dollar-smartphone-alternative-wearable/">Humane pin</a>. </p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;dc37c5dd-dee5-411b-9146-92009ffae9e0&quot;,&quot;caption&quot;:&quot;Update: Kevin Beaumont on his Double Pulsar blog, added some very useful additional context on how Recall works at a technical level, and the information security implications of Microsoft&#8217;s approach. I discussed many of the problems he identified (non-optionality, exploitability by adversaries like hackers/governments, the fact that there&#8217;s no filtering of &#8230; anything). What I did not know was that in addition to recording everything you do on your machine as an OCR&#8217;d screenshot, it is&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;size&quot;:&quot;sm&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;Privacy Disasters: Microsoft, Just Because You Can &quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:116041592,&quot;name&quot;:&quot;Carey Lening&quot;,&quot;bio&quot;:&quot;Desperately trying to make sense of the mess we've gotten ourselves into. An extremely jaded, yet still hopeful, person. Lover of cats. &quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7def9c2-36f5-4f6c-bb3e-7905a3364bce_1024x1024.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2024-05-22T19:25:32.685Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0e792bfd-4e1f-467c-8103-42c9451fb3c7_1245x1562.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://insights.priva.cat/p/privacy-disasters-microsoft-just&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:144866562,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:3,&quot;comment_count&quot;:0,&quot;publication_id&quot;:null,&quot;publication_name&quot;:&quot;Privacat Insights&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6e8a98bb-e5a1-4e4e-b3fa-bb8b2d8a2eeb_1024x1024.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p>According to the <em>Wired </em>piece:</p><blockquote><p><em>The Friend purely offers companionship. It&#8217;s meant to develop a personality that complements the user and is always there to gas you up, chat about a movie after watching it, or help analyze how a bad date went awry. Not only does Schiffmann want the Friend to be your friend, he wants it to be your best friend&#8212;<strong>one that is with you wherever you go, listening to everything you do</strong>, and being there for you to offer encouragement and support. He gives an example, where he says he recently was hanging out, playing some board games with friends he hadn&#8217;t seen in a while, and was glad when his AI Friend chimed in with a quip.</em></p></blockquote><p>There&#8217;s very little information about the pendant, which I will be referring to as the Friendant on the friend.com website, beyond the fact that it connects to the user&#8217;s mobile device via Bluetooth, that it&#8217;s always listening and processing what it hears, it only works on iOS devices for now and communicates by sending chat messages, presumably in a dedicated Friend.com app. Also that it&#8217;s $99 and won&#8217;t be available until Q1 2025. </p><p>Also, in a move that feels very reminiscent of early 2000s pre-crash internet exuberance, Schiffmann told the Wired folks that he purchased the friend.com domain for a cool $1.8 million, after raising $2.5 million <a href="https://techcrunch.com/2024/07/30/friend-is-an-ai-companion-backed-by-founders-of-solana-perplexity-and-zfellows/#:~:text=Schiffmann%20has%20raised%20%242.5%20million,Singer%2C%20who%20works%20on%20AI">in VC-backed funding</a> over two rounds. </p><p>Now, I&#8217;m not a venture capitalist or anything, but I&#8217;ve been around the block a bit. Hell, I even lived in the Valley for a few years and if I learned anything, it&#8217;s that if you&#8217;re going to build a successful product, you really should be laser focused on the product itself. That means prioritizing product development (programming &amp; UX), identifying a good market fit, and offering a catchy tagline on why people should actually buy the thing you&#8217;re hawking. If you&#8217;re a seasoned founder, you might also be thinking sensibly about longer-term risks, like potential legal &amp; regulatory issues, especially if you&#8217;re creating some sort of &#8216;disruptive tech&#8217;. </p><p>What you should not do is spend most of that budget on a fucking domain name.  </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Privacat Insights is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber. My cats will thank you.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h1>A Privacy Notice That Isn&#8217;t</h1><p>With the product details out of the way, let&#8217;s get to the good stuff &#8212; me lambasting the Friendant&#8217;s privacy notice. </p><p>To start, the Privacy <s>Policy </s>Notice is, unsurprisingly, scant on details. The controller (MyTabAI) includes the barest information on processing and use of personal data. What little is there only touches on information collected through the website, or through pre-orders via the Stripe link. The notice says <em>nothing</em> about what the Friend device itself will be collecting, how it&#8217;s sharing this with Claude.ai, how long data is stored on device (or on Anthropic servers), what the context window is, how it somehow remembers user context, etc.    </p><p>And guess what guys. If you were wondering if the notice mentioned anything at all about sensitive data, well, rest assured, it does.  </p><blockquote><p><em>We do not process sensitive information. All personal information that you provide to us must be true, complete, and accurate, and you must notify us of any changes to such personal information.</em></p></blockquote><p>Uh huh. </p><p>It&#8217;s clear that Schiffmann and his team were laser focused on having a beautiful, albeit potentially legally-problematic design, registering the cleverest domain name they can, and launching it on World Friendship Day (30/07/2024). They were far less concerned with the annoying legal and data protection technicalities, or those pesky questions around autonomy, choice, consent, etc.  </p><p>Funnily enough, the notice also gives away the fact that before Schiffmann started calling it the Friend(ant) in mid-May, he was referring to the device as the <a href="https://mytab.ai/">Tab</a>. There&#8217;s even a <a href="https://www.youtube.com/watch?v=6xNss6BZ5kc">YouTube video</a> with that name that was released 9 months ago.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a> That YouTube video, btw, is both illuminating and deeply, deeply cringe.  </p><p>In it, Schiffmann describes the Friend (<em>nee</em> Tab) as a &#8216;context aware&#8217; device, that ingests the contents of the wearer&#8217;s life so that they don&#8217;t have to provide context every time. It&#8217;s unclear <em>how </em>that happens exactly, beyond the fact that the Friend is constantly listening (for up to 15 hours) and shunting queries to Anthropic AI&#8217;s <a href="https://www.anthropic.com/news/claude-3-5-sonnet">Claude 3.5</a> large language model. Between jokey scenes where Schiffmann is reading a book on ChatGPT prompts, he volunteers that he&#8217;s spent some months developing custom prompts, presumably so that Claude can provide vaguely relevant responses to everything the device is listening to. </p><h1>But Wait&#8230; We Have Competing Disasters!</h1><p>I need to stop and take a beat before I activate Angry DPIA mode to inform everyone reading that this is actually the <em>second </em>AI-based wearable pendant called Friend that is available on the market right now, because this is the cursed world we now live in. </p><p>This other Friendant is an open-source jobber created by Nik Shevchenko, a &#8216;Thiel Foundation Fellow&#8217; (vomit) and CEO of <a href="https://basedhardware.com/">BasedHardware</a>. This Friendant is more about traditional productivity, like the <a href="https://www.youtube.com/watch?v=TitZV6k8zfA">Humane</a> &amp; <a href="https://www.youtube.com/watch?v=NPOHf20slZg">Rabbit R1</a> wearables, not staving off loneliness like Schiffmann&#8217;s creation. Despite offering more whizz-bang AI features, including syncing with all the apps and storing and processing locally on-device, <em>this</em> Friend is available for pre-order for the low, low price of $70, with a Q3 2024 delivery date.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> </p><p>The BasedHardware Friendant has a slightly better <a href="https://basedhardware.com/pages/privacy">privacy notice</a>, but it&#8217;s still pretty bad. Recorded audio is processed using <a href="https://deepgram.com/">Deepgram</a> for transcription, and transcriptions are vectorized using Pinecone. Only the vector representations are stored, and all storage is on-device. Allegedly, ChatGPT also runs on-device as well, and it still manages to boast a <a href="https://apps.apple.com/us/app/friend-ai-wearable/id6502156163">24-hour battery life</a> somehow. </p><p>Truthfully, this sounds like privacy-washing bullshit. Especially if you understand how these services work and how computationally expensive all of this is. Oh, and there&#8217;s also this contradiction in terms: </p><blockquote><p><em>None of the data is transmitted to our servers or any third-party servers, except for the services mentioned (Deepgram, Chat GPT, Pinecone), <strong>which also operate locally</strong>.</em></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!plq2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!plq2!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 424w, https://substackcdn.com/image/fetch/$s_!plq2!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 848w, https://substackcdn.com/image/fetch/$s_!plq2!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 1272w, https://substackcdn.com/image/fetch/$s_!plq2!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!plq2!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif" width="320" height="440.72727272727275" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:303,&quot;width&quot;:220,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;What Are You Talking About Huh GIF&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="What Are You Talking About Huh GIF" title="What Are You Talking About Huh GIF" srcset="https://substackcdn.com/image/fetch/$s_!plq2!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 424w, https://substackcdn.com/image/fetch/$s_!plq2!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 848w, https://substackcdn.com/image/fetch/$s_!plq2!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 1272w, https://substackcdn.com/image/fetch/$s_!plq2!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e6961d3-dfb5-4a6c-a5c2-87cc9834b6bf_220x303.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Even the Dude is confused. </figcaption></figure></div><p>I mean, look at this thing? It&#8217;s the size of an anal suppository, and you mean to tell me that it&#8217;s got all of that complex GPU and storage-hungry stuff running all the time and the battery life is better than my phone, and somehow this doesn&#8217;t overheat to the point of catching fire? </p><p>Anyway, I haven&#8217;t looked at the code yet, because I&#8217;m tired. Maybe it does do all of that, IDK &#8212; <a href="https://github.com/BasedHardware/Friend">here&#8217;s the Github</a> link if you&#8217;re curious. To his credit, at least Shevchenko open sourced his work so it can be assessed more easily. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-oZy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-oZy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 424w, https://substackcdn.com/image/fetch/$s_!-oZy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 848w, https://substackcdn.com/image/fetch/$s_!-oZy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 1272w, https://substackcdn.com/image/fetch/$s_!-oZy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-oZy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png" width="1446" height="1043" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c215802c-23db-439e-a415-c092f12c9c80_1446x1043.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1043,&quot;width&quot;:1446,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:384709,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-oZy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 424w, https://substackcdn.com/image/fetch/$s_!-oZy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 848w, https://substackcdn.com/image/fetch/$s_!-oZy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 1272w, https://substackcdn.com/image/fetch/$s_!-oZy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc215802c-23db-439e-a415-c092f12c9c80_1446x1043.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Finally, I would be remiss if I didn&#8217;t mention that Shevchenko, the founder and CEO of a real-life company hoping to secure actual VC money was mad enough about Schiffmann poaching the Friend name that he posted a <a href="https://twitter.com/i/status/1818452878018646369">diss track on Twitter</a>, as well as <a href="https://x.com/kodjima33/status/1818465978952597776">challenging Schiffmann to fight</a> him. In light of this, I would suggest that Shevchenko rename his product Frenemy. But this is not legal advice.  </p><h1>If Only They Hired Me</h1><p>Now then, on with the fun that you&#8217;re all waiting for. Namely, what these lads would have considered if they&#8217;d been smart enough to hire me as a consultant before releasing these things into the world. Hell, here&#8217;s the kinds of questions <em><strong>any spy-wearable</strong></em><strong> </strong>should probably look into at least. Again, not legal advice &#8212; it&#8217;s just basic common sense. </p><p>For the sake of my sanity, I&#8217;m going to refer to the Schiffmann&#8217;s wearable as the <strong>Friendant</strong>, and Schevchenko&#8217;s wearable as the <strong>Frenemy, </strong>because  </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Tci9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Tci9!,w_424,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 424w, https://substackcdn.com/image/fetch/$s_!Tci9!,w_848,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 848w, https://substackcdn.com/image/fetch/$s_!Tci9!,w_1272,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 1272w, https://substackcdn.com/image/fetch/$s_!Tci9!,w_1456,c_limit,f_webp,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Tci9!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif" width="498" height="278" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:278,&quot;width&quot;:498,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cartman I Do What I Want GIFs | Tenor&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cartman I Do What I Want GIFs | Tenor" title="Cartman I Do What I Want GIFs | Tenor" srcset="https://substackcdn.com/image/fetch/$s_!Tci9!,w_424,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 424w, https://substackcdn.com/image/fetch/$s_!Tci9!,w_848,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 848w, https://substackcdn.com/image/fetch/$s_!Tci9!,w_1272,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 1272w, https://substackcdn.com/image/fetch/$s_!Tci9!,w_1456,c_limit,f_auto,q_auto:good,fl_lossy/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd947c413-48aa-487d-ae76-f15bf6ec56c5_498x278.gif 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>First, a quick reminder. Under Article 35 of the General Data Protection Regulation (GDPR), a controller must perform a data protection impact assessment when certain &#8220;high risk&#8221; processing activities occur. The <a href="https://www.dataprotection.ie/sites/default/files/uploads/2018-11/Data-Protection-Impact-Assessment.pdf">Irish DPC helpfully provides a list</a> of high-risk processing activities. For purposes of these wearables, a DPIA is a good idea because it seems likely that both trigger <strong>at least one</strong> of these conditions apply: </p><ul><li><p>use of innovative new technological or organizational solutions;</p></li><li><p>systematic monitoring of publicly-accessible areas on a large scale (since users will be wearing them everywhere); </p></li><li><p>processing of sensitive data of a highly personal nature (if you&#8217;re gonna treat it as your bestie and wear it around constantly, it&#8217;s going to pick up all sorts of juicy details about you and anyone you interact with);</p></li><li><p>collection of personal data about vulnerable individuals (this one depends heavily on context. It&#8217;s less a problem if the founders stick to targeting Bay Area GenZers, much more of a concern if it targets grandparents with Alzheimer&#8217;s or kids). </p></li></ul><p>Now that I&#8217;ve got why a DPIA is important out of the way, let&#8217;s look at some of the questions and risks that I&#8217;d want answers to.  </p><ul><li><p><strong>Transparency: </strong>There is absolutely no transparency here in the privacy notices. While the Frenemy at least goes into some detail<em>, </em>it&#8217;s still all very vague, and I doubt either of the privacy/transparency statements meet the letter and spirit of most US state privacy notice laws, much less the rigor of the GDPR.  How are users being informed of the processing that&#8217;s happening here? Where is the data being stored? How is it being shared with Anthropic / OpenAI? What are you guys doing with all that data? Is it going overseas? Is it being secured? What&#8217;s the lawful basis?</p></li><li><p><strong>Consent of users/third parties: </strong>Currently, only the wearer consents. Because these wearables are always on, the only way I as an innocent bystander can object or opt-out from being recorded by someone wearing these pendants is by asking them to turn it off and hoping they do, walking away, or ripping the damn thing off their neck and chucking it into oncoming traffic. I can see some regulators getting mighty miffed about that. And that presumes I <em>know </em>that these pendants are always recording spy-wear, not just weird jewelry.   <br><br>And how does withdrawal of consent even work here? Say I&#8217;m fine with this at first, but I decide later I don&#8217;t want your Friendant to know about all the deep thoughts I shared with you. How does the owner of the Friendant/Frenemy delete that information? Can users purge information stored on Anthropic/OpenAI servers? </p></li><li><p><strong>Proportionality: </strong>Both wearables monitor and record every interaction, every intimate conversation, and all those deep thoughts shared out loud. As I&#8217;ve mentioned before, most of us are still not cool with having our lives constantly being recorded all the time. Notwithstanding the ubiquity of CCTV and facial recognition in public spaces, I think many people would still freak out if they knew that their casual conversations with someone were being recorded and shared with Anthropic or OpenAI, these guys, and god-knows-who-else, all for a little user convenience. Just look at how we collectively reacted to <a href="https://www.youtube.com/watch?v=F7hfibCOq5E">Google Glass</a>. Or how quickly Recall was withdrawn by Microsoft. </p><p><br>Remember, it&#8217;s not just recording the wearer&#8217;s voice and personal information, but any voice and details shared by those interacting with the pendant-wearer. <br>Just imagine you&#8217;re a 20 or 30-something person, going out to some douchey bar in the Bay Area looking for love. You spy a cute potential paramour in the distance, who seems to be wearing a shiny piece of jewelry that glows weirdly for no reason. Now you have to wonder if what they&#8217;re wearing is some sort of repurposed AirTag, or if it&#8217;s a Friendant talking shit about you or sharing snarky observations at your expense. Who wants that? </p></li><li><p><strong>Children: </strong>What about kids? Most data protection laws impose heightened standards for consent in relation to children. With the rise of laws specifically designed to protect kids&#8217; privacy gaining traction in the US and elsewhere (including the <a href="https://abcnews.go.com/Politics/senate-poised-pass-package-bills-aimed-protecting-kids/story?id=112388921">Kids Online Safety Act and the Children And Teens Online Privacy Protection Act, which recently passed with overwhelming support in the US Senate</a>), having an always recording wearable seems like a recipe for regulatory scrutiny. And everybody wants to protect the children, so that&#8217;s something that crosses party lines.  </p></li><li><p><strong>Exfiltration &amp; Data Breaches: </strong>While I haven&#8217;t looked at the Frenemy&#8217;s code base (yet), I suspect that security was &#8230; not exactly a priority for either of these companies. Given that both interact via Bluetooth via mobile devices, and Bluetooth is vulnerable to eavesdropping and other man-in-the-middle attacks, I could see someone finding an exploit in a matter of weeks here. Just like people found with Recall. It&#8217;s a goldmine for criminals.  <br><br>Points to Frenemy for allegedly keeping some of this data on-device, which is better. Minus points for writing all of this in very vague and contradictory language, though.  </p></li><li><p><strong>Controllership: </strong>Holy shit is this one a dumpster fire. So, ordinarily data protection laws treat data that normal people use for personal reasons differently than say, data collected by Meta or Google. That makes sense: Nobody wants to police Grandma&#8217;s collection of photographs of her grandkids, you recording your friend doing something stupid, or all those dick pics sent between people on WhatsApp. Generally speaking, if it&#8217;s not processing for a professional or commercial use, all the baggage of data protection laws generally will not apply.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> <br><br>But these personal use exceptions are usually construed narrowly. It&#8217;s not enough that processing is done for a personal reason &#8212; it has to be <em>only </em>for a personal or household use. When you start adding others to the mix and sharing that information, things get messy. In the EU for example, if you say, set up a CCTV camera to film all your neighbors for your personal jollies, that might be a use for personal reasons, but it&#8217;s not a personal or household activity under the law. In fact, a 2014 decision by the Court of Justice of the European Union said as much: <br><br><em>To the extent that video surveillance &#8230; covers, even partially, a public space and is accordingly directed outwards from the private setting of the person processing the data in that manner, it cannot be regarded as an activity which is a purely &#8216;personal or household&#8217; activity &#8230;</em><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>   <br><br>I see no reason to believe that this would be different just because it&#8217;s a life-logging device that only records audio. That makes life fun both for the creators of these tools AND anyone foolish enough to wear them. If anyone needs help with handling data subject requests, HMU.</p></li><li><p><strong>Two-Party/All-Party Consent Laws &amp; Eavesdropping: </strong>Many countries have some form of eavesdropping law on the books. While many target telephone communications and most only require a single party to consent, some apply to electronic communications generally. According to the <a href="https://www.rcfp.org/introduction-to-reporters-recording-guide/">Reporters Committee for Freedom of the Press</a>, 11 states have what are known as two-party, or &#8216;all-party&#8217; consent requirements for recording, including <a href="https://www.rcfp.org/reporters-recording-guide/california/">California</a>, <a href="https://www.rcfp.org/reporters-recording-guide/delaware/">Delaware</a>, <a href="https://www.rcfp.org/reporters-recording-guide/florida/">Florida</a>, <a href="https://www.rcfp.org/reporters-recording-guide/illinois/">Illinois</a>, <a href="https://www.rcfp.org/reporters-recording-guide/maryland/">Maryland</a>, <a href="https://www.rcfp.org/reporters-recording-guide/massachusetts/">Massachusetts</a>, <a href="https://www.rcfp.org/reporters-recording-guide/michigan/">Michigan</a> (at least for recordings made by a third party who is not involved in the conversation), <a href="https://www.rcfp.org/reporters-recording-guide/montana/">Montana</a>, <a href="https://www.rcfp.org/reporters-recording-guide/new-hampshire/">New Hampshire</a>, <a href="https://www.rcfp.org/reporters-recording-guide/pennsylvania/">Pennsylvania</a> and <a href="https://www.rcfp.org/reporters-recording-guide/washington/">Washington</a>. Other states (including Oregon and Missouri) require all-party consent for in-person recordings of conversations. <br><br>While laws vary on how consent is obtained and whether implicit consent suffices, the assumption is that recording must be overt and obvious enough to the other people being recorded, and can&#8217;t look like an innocuous piece of jewelry around someone&#8217;s neck. <br><br>This is more likely to impact the wearer than the Friendant/Frenemy creators, but imagine the lawsuits that would occur if Bay Area techbros start get arrested for recording their dates or whatever without consent. Or cops. Lol.  </p></li><li><p><strong>The Data Act: </strong>There&#8217;s a separate and very interesting question about whether these sorts of devices (or other AI spy-wearables) might qualify as connected products under <a href="https://www.eu-data-act.com/Data_Act_Article_1.html">Article 1 of the Data Act</a>. Obviously, more questions would need to be asked &#8212; namely, what kind of product data and related service data is collected. Interestingly, I don&#8217;t know if this triggers much additional review under the AI Act. </p></li><li><p><strong>Various Biometric laws: </strong>Both Texas and Illinois have fairly robust biometric privacy laws that protect individuals from having their biometric data (including voiceprints) collected for commercial purposes. If I was doing a more robust DPIA, I&#8217;d want to interrogate whether and how voice recordings of participants are used. Clearly some processing is occurring. The answer is how much and for what specific purposes.    </p><p></p></li></ul><p> Yeah, so this isn&#8217;t an exhaustive assessment, and it&#8217;s theoretically possible that some or all of these concerns have been addressed and the founders simply haven&#8217;t informed anyone yet. It&#8217;s possible, but in the way that time-travel is possible, or me winning a Ms America pageant is possible, which is to say, not freaking likely.</p><p>So yeah. Maybe one or both of the Friendant/Frenemy creators will reach out and we can dig into how these things aren&#8217;t the stuff of dystopian nightmares. Hope springs eternal. <br><br>But for now, I won&#8217;t be holding my breath. As always, if you&#8217;ve got a thought/observation or think I missed something, leave a comment or send me an email.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/p/privacy-disasters-ai-spy-wearables-e4e/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://insights.priva.cat/p/privacy-disasters-ai-spy-wearables-e4e/comments"><span>Leave a comment</span></a></p><div class="directMessage button" data-attrs="{&quot;userId&quot;:116041592,&quot;userName&quot;:&quot;Carey Lening&quot;,&quot;canDm&quot;:null,&quot;dmUpgradeOptions&quot;:null,&quot;isEditorNode&quot;:true}" data-component-name="DirectMessageToDOM"></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/p/privacy-disasters-ai-spy-wearables-e4e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://insights.priva.cat/p/privacy-disasters-ai-spy-wearables-e4e?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>I&#8217;m pretty sure that was by design, and I&#8217;m also pretty sure Apple will complain. Whether they&#8217;re successful depends on the scope of their design patents and trademarks, of course. <a href="https://www.macrumors.com/2020/10/22/apples-airtags-revealed-in-newly-published-patents/">https://www.macrumors.com/2020/10/22/apples-airtags-revealed-in-newly-published-patents/</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>This video is fucking insane, BTW. To his credit, Schiffmann has not developed the hardened edge of a typical tech founder, and shares an unfiltered, unguarded view of his entire thought process. He even likens the tech startup scene to the Roman Empire. Instead of raising armies to conquer lands, he asserts, now you raise capital to conquer markets. Or something. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>Absolutely none of these guys are going to make any money if these spy-wearables do half of what&#8217;s promised. Assuming, of course, this isn&#8217;t all vaporware. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>See: Article 2 GDPR. In the US, most state privacy laws like the California Consumer Privacy Act set threshold requirements (e.g., processing of personal information of 100k or more consumers within the state, though others like Texas&#8217; law, are broader, or specifically exclude household/personal uses, like the laws in Delaware, Iowa, Illinois, etc. The IAPP has a very handy guide in this state laws report: <a href="https://iapp.org/media/pdf/resource_center/us_state_privacy_laws_report_2024.pdf">https://iapp.org/media/pdf/resource_center/us_state_privacy_laws_report_2024.pdf</a>.</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>See: <em>Ryne&#353; v. &#218;&#345;ad pro ochranu osobn&#237;ch &#250;daj&#367;, </em>C-212/13, Court of Justice of the EU at: <a href="https://curia.europa.eu/juris/document/document.jsf?text=&amp;docid=160561&amp;pageIndex=0&amp;doclang=en&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=12270020">https://curia.europa.eu/juris/document/document.jsf?text=&amp;docid=160561&amp;pageIndex=0&amp;doclang=en&amp;mode=lst&amp;dir=&amp;occ=first&amp;part=1&amp;cid=12270020</a>. In <em>Ryne&#353;, </em>the court assessed the household activity exception in the context of the older Data Protection Directive, but nothing material changed with passage of the GDPR, so I think this is still good law. </p></div></div>]]></content:encoded></item><item><title><![CDATA[Privacy Disasters: A Depressingly Regular Series]]></title><description><![CDATA[A friend on Bluesky shared the Calmera app with me on Bluesky, and now I am raging internally.]]></description><link>https://insights.priva.cat/p/privacy-disasters-a-depressingly</link><guid isPermaLink="false">https://insights.priva.cat/p/privacy-disasters-a-depressingly</guid><dc:creator><![CDATA[Privacat]]></dc:creator><pubDate>Sat, 03 Aug 2024 12:26:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_E32!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><strong>Heads up:</strong> In less than 10 months of occasional posting, I am <strong>now at over 100 subscribers</strong> <strong>on priva.cat and over 1400 subscribers on LinkedIn</strong>&#8212; If you like my snark, analysis, and insights, and aren&#8217;t already a subscriber, please consider subscribing, or sharing this with a friend. </p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share Privacat Insights&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://insights.priva.cat/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share Privacat Insights</span></a></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://insights.priva.cat/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://insights.priva.cat/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><p>So there&#8217;s lots of terrible tech out there, and loads of it relies on AI. I simply don&#8217;t have the <a href="https://en.wikipedia.org/wiki/Spoon_theory">spoons to process, much less respond to all of them</a>. Still, sometimes a shitty idea is <em><strong>so very extra bad </strong></em>that I feel morally obligated as a public servant of privacy to share why the inventors are not only staggeringly wrong, but why the product they have released is toxic to humanity.  And today ladies, and particularly gentlemen, I&#8217;m going to talk about the sheer unmitigated disaster that is Calmara. </p><p><strong>CW:</strong> There will be terrible dick-related jokes throughout, and a cat. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_E32!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_E32!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 424w, https://substackcdn.com/image/fetch/$s_!_E32!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 848w, https://substackcdn.com/image/fetch/$s_!_E32!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 1272w, https://substackcdn.com/image/fetch/$s_!_E32!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_E32!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png" width="863" height="812" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:812,&quot;width&quot;:863,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:333552,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_E32!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 424w, https://substackcdn.com/image/fetch/$s_!_E32!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 848w, https://substackcdn.com/image/fetch/$s_!_E32!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 1272w, https://substackcdn.com/image/fetch/$s_!_E32!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F36993a40-032f-4b55-aaca-95b6a7d1b9a9_863x812.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">First shared by Ella Dawson on Bluesky: https://bsky.app/profile/brosandprose.bsky.social/post/3ko2nlch5yb2r</figcaption></figure></div><p>According to its website, <a href="https://www.calmara.ai/">Calmara</a> is an app that uses AI to detect whether your soon-to-be-lover is laden with a sexually transmitted infection or not. It&#8217;s basically <a href="https://www.youtube.com/watch?v=vIci3C4JkL0">hot dog/not hot dog</a>, but for penises and STIs. It goes like this: </p><ol><li><p>You (or the person you&#8217;re planning to have sex with) download the app. </p></li><li><p>You take a picture of your penis (or their penis, if you get their explicit but totally unverified consent) and upload it on their app.</p></li><li><p>Some pre-processing occurs (to control for lighting and other confounding issues).<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p></li><li><p>That image gets sent to &#8230; AWS somewhere, and an AI model assesses whether the image is full of STIs or not.  </p></li></ol><p>The site claims a 90% accuracy rate, with no cited sources, and is full of cutesy language that tries to make it seem cool and secure. However, there&#8217;s no actual data on what&#8217;s going on under the hood. Oh and it&#8217;s available in the EU (and everywhere else on earth, apparently) because absolutely nobody sat these lads down and told them that maybe this might run into legal/privacy/ethical/cultural/pornography/CSAM issues. After all, who needs a buzz-kill lawyer, when you&#8217;ve got AI, amirite?!?!</p><p>The <s>Cofefe</s> Calmara <a href="https://www.calmara.ai/privacy-policy">Privacy Policy</a> (ugh) and <a href="https://www.calmara.ai/terms-conditions">Terms and Conditions of Use</a> indicate that they clearly never bothered talking to anyone familiar with HIPAA, or data protection laws generally. By the looks of it, they avoided interacting with a lawyer entirely. Their terms of use statement is littered with the kind of language that lay people think will cover their ass but usually don&#8217;t. For example, the always fun, &#8216;<em>The Service is intended for informational purposes and is not a substitute for professional medical advice</em>&#8217;  and obligations to obtain explicit consent, and a full release of liability if the user fails to do so: <em>&#8216;HeHealth Inc. will not be liable for any claims, damages, or legal actions resulting from the submission of images without proper consent, including but not limited to privacy infringements or violations of any law.&#8217;</em></p><p>To test this, I downloaded the app, and &#8230; yeah this is not how any of this works. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SV_f!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SV_f!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 424w, https://substackcdn.com/image/fetch/$s_!SV_f!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 848w, https://substackcdn.com/image/fetch/$s_!SV_f!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 1272w, https://substackcdn.com/image/fetch/$s_!SV_f!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SV_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png" width="342" height="758.8617511520737" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/eb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:963,&quot;width&quot;:434,&quot;resizeWidth&quot;:342,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;The consent screen is a jokey set of text partly written in comic sans, that includes 'Yes, I have their consent.' against a bright pink background. These folks have dark pattern magic all over the place. &quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="The consent screen is a jokey set of text partly written in comic sans, that includes 'Yes, I have their consent.' against a bright pink background. These folks have dark pattern magic all over the place. " title="The consent screen is a jokey set of text partly written in comic sans, that includes 'Yes, I have their consent.' against a bright pink background. These folks have dark pattern magic all over the place. " srcset="https://substackcdn.com/image/fetch/$s_!SV_f!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 424w, https://substackcdn.com/image/fetch/$s_!SV_f!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 848w, https://substackcdn.com/image/fetch/$s_!SV_f!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 1272w, https://substackcdn.com/image/fetch/$s_!SV_f!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Feb37bbf1-c0a7-48ed-94a3-0c61ba0b4d4c_434x963.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">I uploaded a picture of my pussy(cat), clicked yes, and it errored out.</figcaption></figure></div><p>It&#8217;s the legal equivalent of magic pixie dust, and if <strong>I were the California Attorney General</strong>, I&#8217;d be hopping on this D(isaster) like a porn star.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>  </p><p>The <s>Calmerror</s> Calmara website also claims that there is an age verification process, and despite my effort to try this out with cat pictures, I never saw it. </p><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_9sG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_9sG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_9sG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_9sG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_9sG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_9sG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg" width="380" height="214" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:214,&quot;width&quot;:380,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Cat's Tail is Shaved For Surgery, Netizens Say it Looks Like a Penis (Watch Viral Video)&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Cat's Tail is Shaved For Surgery, Netizens Say it Looks Like a Penis (Watch Viral Video)" title="Cat's Tail is Shaved For Surgery, Netizens Say it Looks Like a Penis (Watch Viral Video)" srcset="https://substackcdn.com/image/fetch/$s_!_9sG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_9sG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_9sG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_9sG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F500a5eb8-f38c-4fb1-9c9e-8855d81ddd25_380x214.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">This looked very convincing, but their AI is good enough to tell that this is not a hot dog. Source: https://www.latestly.com/social-viral/cats-tail-is-shaved-for-surgery-netizens-say-it-looks-like-a-penis-watch-viral-video-1358856.html</figcaption></figure></div><p>Also, their TOS and FAQs include a general disclaimer that absolves them of liability if an underage person uploads an image. <em>Guys, in many jurisdictions, there is no get-out-of-jail-free-card for child porn</em>, and an underage person&#8217;s peen is probably gonna get you into trouble, no matter what the TOS says. </p><p>Their privacy policy is equally bad, and it doesn&#8217;t include any details on how images are used (beyond to deliver services and to &#8216;enhance and innovate our service offerings&#8217;), their legal reasons for processing data beyond the image itself, how long images are kept, how these very intimate images are secured, how data is shared and with whom. The sum total of their sharing statement is: </p><blockquote><p><em>To provide you with seamless service, we share your information with service providers and partners who assist in service operation, including data hosting, analytics, marketing, payment processing, and security. These collaborations are vital for a seamless and secure service experience.</em></p></blockquote><p>Given that the only personal data/information they admit to collecting is images, cookies, and &#8216;user behaviors&#8217; and their statement is <strong>extremely vague about what they do with this data</strong>, it seems entirely reasonable to assume that they are mass-blasting dick pics and everything else with all parties involved. Congrats guys, your dicks might end up on marketing collateral! </p><p>Also, their FAQ claims that because they use AWS to store and do the AI magicks, that makes their app HIPAA compliant. </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DAJt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DAJt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 424w, https://substackcdn.com/image/fetch/$s_!DAJt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 848w, https://substackcdn.com/image/fetch/$s_!DAJt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 1272w, https://substackcdn.com/image/fetch/$s_!DAJt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DAJt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png" width="1456" height="577" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a759e133-0913-4713-bc25-4676c35c3174_1615x640.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:577,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:142759,&quot;alt&quot;:&quot;Text reads: Is the data safe and confidential?  with more text. &quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Text reads: Is the data safe and confidential?  with more text. " title="Text reads: Is the data safe and confidential?  with more text. " srcset="https://substackcdn.com/image/fetch/$s_!DAJt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 424w, https://substackcdn.com/image/fetch/$s_!DAJt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 848w, https://substackcdn.com/image/fetch/$s_!DAJt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 1272w, https://substackcdn.com/image/fetch/$s_!DAJt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa759e133-0913-4713-bc25-4676c35c3174_1615x640.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Please, make it stop. </figcaption></figure></div><h1>A Momentary Interlude While I Drink and Check Out Their IP</h1><p>The company behind <s>Calimari</s> Calmara trades under the name <a href="https://www.hehealth.ai/">HeHealth Inc</a>.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>  HeHealth, which launched in 2022, offers a flashier version of the same technology, called Hehealth.ai, which is basically a paid version of the app, with a bonus doctor&#8217;s review. No idea about which <a href="https://www.hehealth.ai/science">one of these dudes</a> is actually reviewing the images, or whether any are actually licensed/certified in proctology, but hey, somehow that&#8217;s slightly better than the free <s>Calzone </s>Calmara version, which is doing medical diagnosis entirely by AI. According to the HeHealth app, 31,129 people have allegedly scanned their weens and uploaded them to an AWS server somewhere. </p><p>HeHealth.ai is based on <a href="https://ppubs.uspto.gov/dirsearch-public/print/downloadPdf/11721023">patented</a> technology, which can allegedly detect 10 different STIs according to the website (though the patent and <a href="https://arxiv.org/abs/2403.08417">pre-print validation study</a> only seem to show detection for genital warts, herpes eruption, cancer, candidiasis, and syphilis). It uses a trained AI model that is augmented with a small number of actual <a href="https://arxiv.org/abs/2403.08417">healthy/unhealthy penises (&lt;240), and potentially synthetic images</a>, if I read the patent details correctly. </p><p>I&#8217;ll admit, I&#8217;m happy that there&#8217;s science behind it. But that doesn&#8217;t stop this whole affair from being a massive privacy disaster.  </p><h1>Lads: Just Go See a Doctor</h1><p>Guys. Fellas. Gents. I get that sometimes the urge to get down may overwhelm better judgment. That privacy and data protection might not be top of mind when you&#8217;re getting ready to get dirty. Still, don&#8217;t let your little head get ahead of your bigger one on this. If you&#8217;re worried, or if things don&#8217;t look right down there, just go see a doctor.</p><p>Right now, based on everything provided on the Calmara and HeHealth websites, I&#8217;m unconvinced that they&#8217;re thinking of your interests. Based on what&#8217;s being presented, this app looks rushed and hoping to cash in on the AI hype. While it may be well-meaning, it seems to lack any consideration for the kinds of things I would expect to see out of a<a href="https://www.hhs.gov/hipaa/for-professionals/special-topics/health-apps/index.html"> legitimately-compliant mobile health app</a>, which is what it should be, because this app is offering you <em>medical advice</em>. Specifics and details are light. Testing seems limited and it took me effort to find it. Everything is far too cutesy, and really, do you want cutesy when you&#8217;re uploading images of your dick to god-knows-where? </p><p>Hell, I&#8217;m not even convinced that the AI can do much more than detect if your peen is not exactly right (whatever that means). For (literal) fuck&#8217;s sake: just go see a doctor. </p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>This is at least the takeaway I got by reviewing the associated patent: <a href="https://ppubs.uspto.gov/dirsearch-public/print/downloadPdf/11721023">US 11,721,023 B1</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>I am not the California AG though, and in the interests of avoiding a defamation lawsuit, will note that I&#8217;m not a regulator of any sort. I&#8217;m at best a snarky privacy blogger. </p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>According to <a href="https://pitchbook.com/profiles/company/530899-03#investors">Pitchbook</a>, HeHealth is a VC-backed startup that has secured at least $1.5M in funding from 2 VC firms I&#8217;ve never heard of before, and the incubator arm of Singapore Management University&#8217;s Institute of Innovation &amp; Entrepreneurship. </p><p><strong>PS</strong>: For the curious, I enjoyed the <a href="https://untappd.com/b/otterbank-brewing-and-blending-gimp-mask-2023/5215991">Otterbank Brewing &amp; Blending Gimp Mask 2022</a>. It felt appropriate given the context. </p></div></div>]]></content:encoded></item></channel></rss>