AnEilifintChorcra

joined 1 year ago
[–] [email protected] 19 points 3 days ago (2 children)

https://www.bleepingcomputer.com/news/security/genetics-firm-23andme-says-user-data-stolen-in-credential-stuffing-attack/

The information that has been exposed from this incident includes full names, usernames, profile photos, sex, date of birth, genetic ancestry results, and geographical location.

The threat actor accessed a small number of 23andMe accounts and then scraped the data of their DNA Relative matches, which shows how opting into a feature can have unexpected privacy consequences.

  • Usernames Profile Photos DoB

They can be linked to other online accounts. This allows for phishing, potentially scamming or getting additonal information on them which can lead to more sophisticated/personalised scams. Older, less tech savvy users are better targets for scammers.

  • Username Sex DoB Genetic Ancestry Location data

Data aggregators can sell this info to Health Insurance Companies or any other system who can then discriminate based on genes sex age or location

  • All of this information

Can contribute to people committing fraud with their information if they collect enough information from different sources.

  • DNA relatives

Having enough information about a user to use it to target their now known relatives in personalised scams.

The people that did this probably didn't know what information they were going to get, maybe they were hoping for payment info, and settled for trying to just sell what they got.

Any information, no matter how useless it might seem, is better than no information and enough useless information in the wrong hands can be very valuable.

Theres countless data breaches every year and people will collect it all and link different accounts from different breaches until they have enough information. Most people use the same email address for every website and a lot of people reuse the same passwords, which is how this data leak occurred. Knowing that these users reuse the same email/password combination here means theres a very good chance they've reused it elsewhere.

You can check out what data breeches have occured and if your email or password has been posted in any of these dumps here https://haveibeenpwned.com/

Once the information is out there, its out there for good and what might seem trivial now to you could be valuable tomorrow to someone else

[–] [email protected] 2 points 4 weeks ago (4 children)

If your phone has a password on it then its data is going to be encrypted until you unlock the phone.

You can temporarily boot a twrp recovery image. It will let you put in your password and decrypt your storage.

You should be able to transfer the files to your PC with a cable then

[–] [email protected] 5 points 1 month ago

Around 16 TiB and I keep 3 copies of everything so 48 TiB used of around 65TiB. I encoded all my TV shows and most of my movies with AV1 and keep most of my files compressed, which saves a bunch of space so hopefully I won't need more drives any time soon

[–] [email protected] 12 points 2 months ago (1 children)

For me the issue here is, why put so much time and energy into basically rebranding an LLM. I've seen LLMs running on RPi and android phones. Why not write a blog post showing how to run LLMs locally with existing tools for the best privacy instead and put more focus on their existing services. It just seems like they're jumping on the AI bandwagon and charging a premium for an already freely available LLM.

I see some benefits of AI like quality tts when using OSM and stt when transcribing/translating audio but other things like Googles AI answers and Microsofts Copilot leave me scratching my head wondering why consumer would want this

[–] [email protected] 86 points 2 months ago (9 children)

Am I out of touch?

a writing assistant was one of the most requested features in our recent survey

Apparently, I am. People actually want this

For Proton Mail, 59% of respondents want an easier way to send end-to-end encrypted emails to non-Proton users, while 29% want a writing assistant for proofreading, grammar, and composing emails.

Nothing I hate more than not giving a link to the repo

Scribe relies on open source code and models, and is itself open source and therefore available for independent security and privacy audits

Not on their support page specifically for it either

Had to got to Reddit and look at their comments to find out they're using Mistral

https://reddit.com/comments/1e68sof/comment/ldsbs24

We built Scribe in r/ProtonMail using the open-source model Mistral AI to empower anyone in need of email productivity to use a privacy-respecting alternative to r/ChatGPT or r/GeminiAI that:
 ❌ doesn't log or save prompts
 ⛔️ doesn't use your data for training
 🔎 open-source code that anyone can inspect
 🖥️ can be run locally, so your data never leaves your device
 
See the official announcement here: https://proton.me/blog/proton-scribe-writing-assistant

https://huggingface.co/mistralai/Mistral-7B-v0.1/discussions/8

Hello, thanks for your interest and kind words! Unfortunately we're unable to share details about the training and the datasets (extracted from the open Web) due to the highly competitive nature of the field. We appreciate your understanding!

[–] [email protected] 2 points 2 months ago

You could chance it, but they probably have logs of your IP/location data or they bought your data somewhere and so they could check, if they cared enough, but if you're not an EU citizen and you live in an EU country then GDPR applies to you

[–] [email protected] 4 points 2 months ago

Every few months I like to clear out my password manager of any accounts I don't need anymore, usually just throwaway emails aliases.

I'll usually attempt to log into any services that I know I've deleted/requested to delete to make sure they're not accessible anymore and so far I haven't been able to log in to any of them so I can only assume my requests are working.

I suppose if a service had a data breach, after my information was meant to be deleted, and I found my information there then I'd make a complaint to my regulator about not deleting my data. I would have proof of my request and their acknowledgement of the request so it'd be pretty silly of them not to delete it after saying they did

I rarely use anything but email aliases and fake information anyway and I never let online retailers save my card information. And if my address in on my account I change it to P. Sherman 42 Wallabyway Sydney before I delete/request to delete my account.

[–] [email protected] 5 points 2 months ago (3 children)

I spend too much time reading emails so I try to keep mine short, especially when they're going to a generic email like support or privacy.

https://gdpr.eu/right-to-be-forgotten/

The GDPR does not specify what a valid request to erasure entails. An individual can make a request for erasure verbally or in writing. This request can also be made to any member of your organization, not just to a designated contact. As long as a request meets the conditions above, it is valid, even if it does not refer to “Request for Erasure” the “Right to be Forgotten,” Article 17, or the GDPR.

There's no template to follow for a request. Once GDPR is mentioned, they usually just email back saying that they're doing it or its done.

I haven't come across any difficult companies but I've heard some make it as hard as possible and follow the Erasure Request form template in the link above and ask for proof of I.D etc

[–] [email protected] 23 points 2 months ago (18 children)

I usually just write

Hi,

Please delete my account and all data associated with this email in accordance with Article 17 of GDPR, I'm an EU citizen

Thanks x

I just assume if they haven't made it easy to delete your account by now then they never will but these are really good points that will hopefully make companies change their policies, especially since its all things that benefit them

[–] [email protected] 5 points 2 months ago

Theres at least 4 websites in the megathread under the ROMs section that have a bunch of Switch games. 3 begin with N and 1 begins with Z. In the FAQ section of the Z website is where I got keys and firmware

[–] [email protected] 5 points 2 months ago (1 children)

Pretty sure its because of the piracy shield thingy. Secure Core might be an option as long as no Italian servers are used and you're using the VPNs DNS

https://torrentfreak.com/airvpn-stops-serving-italians-due-to-piracy-shield-blocking-requirements-240206/

“[A]ll parties in any capacity involved in the accessibility of illegally disseminated content – and therefore also, by way of example and not limitation – VPN and open DNS service providers, will have to execute the blocks requested by the Authority [AGCOM],” the notice read.

[–] [email protected] 9 points 3 months ago (1 children)

I see the Extend part of Embrace Extend Extinguish is about to start...

view more: next ›