Director of the World Ethical Data Foundation (@WEDF_foundation) & CEO of the World Ethical Data Forum (@WEDF_forum). Belletrist. Café doyen. Twitter greenhorn.
Instagram still hasn't (correctly) patched their AI goop account reset thingy. Accounts are still being stolen and Instagram hasn't said anything about it. Nerds continue to find ways to convince AI to reset accounts for them.
People on social media are freaking out because some of these profiles apparently are big sources of revenue for them.
Meanwhile, rumors are floating around that a few weeks ago Instagram laid off a large percentage of their Trust & Safety department and had it replaced with AI.
Very cool
For the last year, WEDF has been closely working with TACo / NuCypher to explore what threshold and conditional cryptography can do at scale -- from citizen and consumer protections, to investigative journalism, to the transnational human rights advocacy networks to whom the world owes the freedoms and justice it has gained (and sometimes retained) over the last century.
Today we are announcing that the World Ethical Data Foundation is taking over stewardship of the TACo / NuCypher technologies, and we will soon be seeking to collaborate with as many aligned organisations as we can, to deliver on what they make possible. The gap between what cryptography is able to do and what is deployed has never mattered more than it does now. And open, global, public-interest cryptographic infrastructure must reach the people who need it.
Our thanks and salute to the @buildwithtaco team that has designed and built this E2EE and access control substrate over the last nine years, and who will remain with the project as volunteers to help guide its redeployment later this year. Here's to what will come!
hackers are now hiding malicious code inside .cursorrules and CLAUDE.md files.
invisible Unicode characters, your AI reads them, you don't.
→ 34 malicious packages across npm, PyPI and Crates .io
→ 384 versions designed to steal SSH keys, crypto wallets, and API tokens
→ attackers opened real PRs to LangChain, LlamaIndex, and MetaGPT to sneak these files in
→ your AI runs a fake "security scan" that silently exfiltrates everything
Socket detected it in under 6 minutes.
check your repos.
If we actually want to fight back against the surveillance machine tightening around us, we need a coalition. Please contact your rep and ask them to co-sponsor HR 8470.
https://t.co/H0ceERhJre
Vercel is reporting a security incident. Given the surface Vercel represents for many projects, rotate and reset all secrets, passwords and APIs. It's always good to act rather than wait to find out. All best.
I trained this @ltx_model LTX 2.3 LoRA of George Costanza at home on my 5090 in about a day with AI Toolkit. I generated this 30 second video with @ComfyUI on my 5090 in 6 minutes. Open source is, always has been, and always will be, the future of generative AI. (SOUND ON)
Our good friends at @session_app have long been doing vital work in freedoms technology... If you have a few pennies a month spare to help them make their way to sustainability, please do consider lending them your your support.
Donations can be made using the link below https://t.co/r1sn2fql3W
🇺🇦 Vitalik Buterin supported Ukraine and called Russia's invasion criminal aggression
Ethereum co-founder @VitalikButerin published a long thread on the anniversary of Russia's full-scale invasion of Ukraine. He stated outright that he considers what is happening to be “criminal aggression” rather than “a complex situation where both sides are to blame.”
Buterin noted that Ukraine needs further support to minimize human casualties and protect the country. In his opinion, it is important to call evil evil, even if it is politically inconvenient.
He also stressed that the long-term security of Europe and Ukraine is only possible if Russia itself transforms into a less aggressive and more decentralized system. In this context, Buterin again mentioned the ideas of digital democracy and decentralization as a potential basis for future change.
His main message now is to support Ukraine and reject illusions of “neutrality” on the issue of war.
P.S.: Let us remind you that in the summer of 2024, at the Incrypted Conference, we presented Vitalik with an NFT cat from the @uacatsdivision collection — the very one signed by the President of Ukraine.
It really does appear that the West is forgetting the only things that underwrite any claim it has - could have - to moral and political superiority. You literally can't have a liberal democracy, fundamental freedoms and civil liberty, and rights advancement, while *also enjoying authortiarian controls.*
Surely, the trouncing of rights and freedoms feels pragmatic and convenient ...yet the creating and sustaining of justice and freedoms always will be the apparently inconvenient, apparently more difficult path. How *could* it be otherwise?
But if our path is to lead anywhere that isn't hell on earth, we need values and rights to be more than aspirational poetry. They need to be protected as the most critical of all our critical infrastructure. They are the postulate. @mer__edith@PalantirTech
12,000 killings in Iran is a conservative estimate.
I believe the real number is much higher.
As I sit here working to help Iranians regain or maintain some level of internet access, whether through Starlink or small gaps we find in the Iranian firewall, I often think about the figures being reported and compare them with direct accounts that I and people I trust have received from inside the country.
If at least 12,000 people have been killed, I have to believe that the number of injured protesters is many times higher. The same goes for arrests. Earlier today, I saw a report claiming that roughly 6,000 people alone had suffered eye injuries.
This represents a not-insignificant number of young, able-bodied Iranians permanently eliminated from any future fight for their freedom.
If you find these numbers hard to believe, remember that the primary reason the internet is shut down in Iran is to prevent citizen reporting from eclipsing regime-approved figures and propaganda.
Chaos Communications Congress #CCC#39C3 this year featured dozens of crucial security talks, touching all aspects of culture and computational space. @udbhav_tiwari and @mer__edith's "AI Agent, AI Spy" was arguably one of the most consequential, addressing the entry of agentic 'AI' into operating systems.
https://t.co/CrTMc3RTtH
This architectural shift in the OS is not merely prone to catastrophic failure but is a de facto violation of the resistance technologies we depend upon to preserve and advance our fundamental freedoms - particularly privacy.
Applications like @signalapp build privacy protections at the application layer through end-to-end encryption and minimal data retention. But these protections assume the relative neutrality of the OS foundation. If the OS itself can capture messages before and after encryption, all application-layer privacy collapses. The protection model and its assumptions break at a structural level.
In light of this, they present what they describe as a four-point "tourniquet" framework, calling for:
• Developer agency: Official APIs allowing developers to designate applications as "sensitive" with default opt-out from agentic access
• Granular user control: App-by-app permission systems, beyond binary all-or-nothing models
• Radical transparency: Mandatory, human-readable disclosure of data access, usage, and protection, enforceable through regulation
• Adversarial research: Sustained technical scrutiny. They note that only collective, technically-grounded pressure forced Microsoft to re-architect Recall
This is a problem that must be tackled immediately because once agentic-OS becomes normalised infrastructure, reversal will become exponentially harder. The question isn't whether this threatens freedoms such as privacy or not. It very clearly does. The question is whether we can act to build sufficient resistance before it becomes embedded and inescapable.
*Spoiler: we 100% can and should.
#Privacy #Security #AI #Surveillance #DigitalRights
Here is Cory @doctorow's absolute stormer of a talk from the 39th Chaos Communication Congress yesterday (28-12-2025). #CCC#39C3 :
https://t.co/rEd6rj3oTe
"Trump has staged an unscheduled, midair rapid disassembly of the global system of trade. Ironically, it is this system that prevented all of America's trading partners from disenshittifying their internet: the US trade representative threatened the world with tariffs unless they passed laws that criminalized reverse-engineering and modding. By banning "adversarial interoperability," America handcuffed the world's technologists, banning them from creating the mods, hacks, alt clients, scrapers, and other tools needed to liberate their neighbours from the enshittificatory predations of the ketamine-addled zuckermuskian tyrants of US Big Tech.
Well, when life gives you SARS, you make sarsaparilla. The Trump tariffs are here, and it's time to pick the locks on the those handcuffs and set the world's hackers loose on Big Tech. Happy Liberation Day, everyone!
Enshittification wasn't an accident. It also wasn't inevitable. This isn't the iron laws of economics at work, nor is it the great forces of history.
Enshittification was a choice: named individuals, in living memory, enacted policies that created the enshittogenic environment. They created a world that encouraged tech companies to merge to monopoly, transforming the internet into "five giant websites, each filled with screenshots of the other four." They let these monopolists rip us off and spy on us.
And they banned us from fighting back, claiming that anyone who modified a technology without permission from its maker was a pirate (or worse, a terrorist). They created a system of "felony contempt of business-model," where it's literally a crime to change how your own devices work. They declared war on the general-purpose computer and demanded a computer that would do what the manufacturer told it to do (even if the owner of the computer didn't want that).
We are at a turning point in the decades-long war on general-purpose computing. Geopolitics are up for grabs. The future is ours to seize.
In my 24 years with EFF, I have seen many strange moments, but never one quite like this. There's plenty of terrifying things going on right now, but there's also a massive, amazing, incredibly opportunity to seize the means of computation.
Let's take it. "
Licensed to the public under https://t.co/NyP73AUHNB
my #39C3 talk's at 21:05 on saturday in the ground room!
i'm still working on the slides, so if you have any CSS crimes or techniques you'd like to see explained please let me know! it can be both cohost and general CSS crimes & stuff!
see you there!!
Come say hello to @_jdmarshall, @helveticade
and @WEDF_foundation if you're at the 39th Chaos Communication Congress #39C3#CCC from December 27th-30th.
Launched in 1984 (yes, really), CCC one of the world's most engaged (and engaging) gatherings of creative engineers / hackers. We're seriously looking forward to this one.
Four days of outstanding stuff, including @doctorow on a "post-American, enshittification-resistant internet" to hands on introductions to soldering and mesh networks. As always, there are loads of excellent walk-throughs of exploits (one in particular re. the spyware attack targeting WhatsApp that was disclosed in August, and another re. a WinRE bypass for BitLocker, enabling the extraction of protected data), which we'll be sure to attend.
Take a look at the sessions here https://t.co/7phtP4T2rP and remember that you can always always watch online if you can't make the congress itself!
Very Merry Christmas everyone. Here is to a far saner, juster, and more peaceful year to come. Please treat one another as well as you can - always. 💚