A complete free checklist of things you can do right now to reduce how much of your life is tracked online. no technical knowledge required.
— switch your search engine to DuckDuckGo or Brave Search. free. takes 30 seconds.
— install uBlock Origin on your browser. blocks ads and trackers. free. the most effective single extension you can install.
— turn off ACR on your smart TV. it's photographing your screen twice per second. settings vary by brand
— search "(your TV brand) disable viewing data".
— add a SIM lock to your phone number. call your carrier. stops SIM swapping.
— switch SMS two-factor to an authenticator app. Proton Authenticator. free.
— check https://t.co/ldZs2mVkgU. enter your email. see every breach your data appeared in.
— use a password manager. Bitwarden is free and open source. one strong password per site.
— check your smart TV, phone, and laptop for apps you haven't opened in a year. delete them. every unused app is a potential data leak.
— go to Google's My Activity page and delete your search history. then turn off future collection.
— on iPhone: Settings → Privacy → Tracking → toggle off "Allow Apps to Request to Track".
none of these cost money.
all of them take under 10 minutes.
start with one.
Being pro European is exhausting.
It means being insulted for trying to protect what we love. It means being accused of wanting to destroy our nations when all we want is to prevent them from becoming powerless. We are accused of wanting to erase national identities when we want to protect them. We are accused of wanting open borders when we want Europe to finally control its borders. We are accused of destroying our economies when we want our industries, jobs, capital and companies to remain in Europe.
We are accused of every failure, when so often what we are fighting for is precisely the opposite.
We want Europeans to afford homes, pay their energy bills and build a future here. We want European startups to grow in Europe instead of having to turn to America for capital. We want our industries to compete instead of disappearing. We want secure borders and controlled immigration. We want affordable energy. We want the ability to defend ourselves.
We see a Russia willing to use military force. We see a China capable of overwhelming our industries. We see an America increasingly willing to use its economic, financial and technological power in its own interests.
And we refuse to accept that Europeans should simply watch while others shape the world around us.
We do not want Europe because we despise our nations. We want Europe because we love them too much to watch them become powerless.
We want France to remain France, Germany to remain Germany, Italy to remain Italy, Poland to remain Poland. But we also understand that sovereignty means very little if, individually, we no longer have the power to exercise it.
That is perhaps the tragedy of being pro European today. We have to fight outside to defend Europe from those who can weaken it, while fighting inside against the idea that European unity is somehow the enemy of our nations.
We are not trying to erase Europe’s nations.
We are trying to make sure they still have a future.
Anthropic published The AI-Native SDLC Playbook last week saying, “code is no longer the bottleneck.” I agree.
All year long, I’ve been asking myself the questions that naturally follow:
What becomes the bottleneck next?
If models can generate code faster and faster, what actually determines whether a change is good enough to ship?
If teams are going to use multiple models and agents, what has to remain durable underneath them?
And as agents become more autonomous, how do people understand and steer what hundreds of them are doing at once?
My view: faster code generation is already exposing the next constraints. Solving them is where the next wave of value in agentic engineering will come from.
Verification, context, execution infrastructure and governance start to matter more than model choice.
Put differently: when implementation becomes abundant, trust becomes scarce.
I wrote down my view of what comes next: When Code Is Abundant
https://t.co/Dh4j2TIsJr
Chrome remote desktop is a legitimate google product.
when someone connects to your machine remotely, one thing tells you: a small notification bar at the top of your screen.
that’s it. that’s the whole user-facing security control.
researcher @5mukx traced where that bar comes from.
it’s a win32 dialog resource — IDD_DISCONNECT, id 110 — compiled into a single DLL: remoting_core.dll. the dialog has two fields that matter: cx and cy. width and height. stored as 16-bit values at byte offset +18 inside the DLGTEMPLATEEX structure.
he wrote a python script that finds every language variant of dialog 110 in the PE resource tree all 53 of them and zeros those four bytes.
windows still creates the dialog. It just has no dimensions and session stays active.
then he looked at C:\ProgramData\Google\Chrome Remote Desktop\.
host.json. contains the host’s RSA private key, the PIN hash, and the google account it’s registered to.
replace that file with one generated by your own account. the host re-registers to you.
bundle it in a modified MSI installer. MSI runs elevated by default. drops your host.json, creates the directory, starts the chromoting service automatically.
The installer an attached controlled google account gives silent persistent access to that machine.
No sketchy domain the traffic routes through google’s infrastructure the binary too is signed by google. 😉
Research: @5mukx 🫡/ zerotracelab. Link in thread
This paper gives a fancy name to a problem you can already feel in your bones
"The Tragedy of the Cognitive Commons." Checking AI output requires deep expertise. Deep expertise comes from doing grunt work for years. And grunt work is the first thing AI eats
So we're building systems that need expert supervision while dismantling the only known process for making experts
The paper calls the shared pool of human expertise the "cognitive commons." Every profession drinks from it. Nobody's refilling it.
By eliminating junior roles, each company is acting totally rationally, and the collective result: a profession that can't catch AI's mistakes anymore because it never learned to do the work in the first place
Who checks AI's homework in 15 years?
🇪🇺 Exposing the Misdirection: A Critical Analysis of the EU "Child Safety Online" Report
I've analysed the July 2026 European Commission report, Child Safety Online: Protecting and Empowering Minors in a Digital World. Behind its protective rhetoric lies a calculated campaign of misinformation, misdirection, and unprecedented scope creep.
Part I: The Illusion of Scope (The "Social Media+" Trap)
The report deliberately relies on an extraordinarily broad, feature based definition rather than identifying services by company name, category, or legal classification.
The key definition appears in the "Scope and Terminology" section, which introduces a new catch all term:
"Social media and other digital services (in short, social media+)"
The report states that "social media+" is used to:
"broadly define services that may be available to minors and contain age-inappropriate and or risky features… and or content."
It labels basic, industry standard interactive elements as "addictive and harmful features," specifically calling out:
🇪🇺 Infinite scroll
🇪🇺 Autoplay
🇪🇺 Recommendation algorithms
🇪🇺 Persistent notifications
The definition then expands aggressively to encompass:
🇪🇺 Social media and video sharing platforms
🇪🇺 Online platforms acting as intermediaries for third party content
🇪🇺 App stores
🇪🇺 AI systems and AI companions
🇪🇺 Video games
What the Report Conspicuously Omits:
💡 No limitation to traditional social networks.
💡 No limitation to user generated content platforms.
💡 No limitation to services whose primary purpose is social interaction.
By defining the regulated space via universal features like notifications, recommendation algorithms, and app distribution, they've quietly drafted a blueprint to regulate almost the entire internet.
Part II: The True Objective Behind "Chat Control"
This sweeping "social media+" definition can't be viewed in isolation. It's directly feeding into the broader legislative push for mandatory online scanning, colloquially known as "Chat Control".
While European Parliament President @EP_President and the @EPPGroup forced through Chat Control 1.0, a "voluntary" precursor designed to normalise corporate scanning, the permanent, mandatory framework of Chat Control 2.0 was authored by @PHummelgaard.
Serving as the Danish Minister of Justice and leveraging Denmark’s influential role during its EU Council Presidency, Hummelgaard designed a regime to eliminate end to end encryption. His own words expose the authoritarian philosophy driving this legislation:
"We must break with the totally erroneous perception that it is everyone's civil liberty to communicate on encrypted messaging services."
This is the ultimate goal, stated by the law's chief architect: the end of private human conversation. By treating the right to private digital communication as a "totally erroneous perception" to be corrected by the state, Hummelgaard's framework turns every personal device into a government wiretap.
Orwell warned of a world where "nothing was your own except the few cubic centimetres inside your skull." Hummelgaard’s infrastructure ensures the state controls those, too.
Part III: Key Concerns
🆔 Identity Infrastructure: The demand for "effective age assurance" is a privacy fallacy. Despite claims of "privacy preserving" tech, reliable verification ultimately depends on a government ID, biometric scan, credit card information, or deep personal data profiles. Once identity's verified, true anonymity is lost.
🌐 Expansion of Scope: Sold as a targeted restriction on social media, the broad "social media+" umbrella means citizens have got to undergo identity checks simply to download an app, play a game, query an AI, or browse a website.
❄️ Chilling Effects on Free Expression: If accessing basic digital services requires proving who you are, marginalised individuals, political dissidents, and people researching sensitive health or personal topics will self censor and avoid seeking information or support.
📈 Mission Creep: History proves surveillance powers are never contained. Telecommunications metadata and financial monitoring systems were introduced under narrow, exceptional mandates and later expanded into permanent, everyday tracking tools.
🪪 De Facto Digital ID: Age estimation is highly inaccurate. The stricter regulators demand age assurance to be, the more pressure there's to rely on government backed, identity linked verification. This creates an unavoidable path toward mandatory, digital identity wallets.
🏛️ Centralisation of Power: The framework strips parents and individuals of agency, placing government regulators in charge of deciding which ideas, features, and platforms are "appropriate" for citizens.
⚠️ Weaponisation under Future Regimes: Technology outlives the politicians who build it. The turnkey surveillance state built by today’s well meaning policymakers will eventually be inherited by administrations with vastly different views on speech, privacy, and political opposition.
🔄 A Contradictory Standard: The report demands that platforms restrict child access while simultaneously requiring providers to prove their services are "safe by design" for minors. If children are legally barred from entry, forcing platforms to reconstruct their entire architecture to accommodate them is a logical paradox.
🔒 Regulatory Capture: Tech giants can easily absorb the massive compliance and verification costs of these regulations. Smaller competitors, open source projects, and startups can't, effectively locking in the monopoly of the dominant platforms.
About the Author (Me)
👨👦👦 Father of 3: I’m a father of 3, but that doesn't qualify my expert opinions. Being a parent drives my passion, but it doesn't dictate my understanding of what’s technically possible, what’s not, what’s actually feasible, or the severe cost of getting it wrong. There’s always a delicate, necessary play between security and privacy, and getting it wrong destroys both.
👤 AOL Child Safety Pioneer: I was first introduced to child safety tech and content moderation in 1996, when I led the new technologies team at AOL and helped launch AIM.
🌐 W3C Standard Creator: I cofounded the W3C standard for Content Labelling and URI Classification in 2004, which formally replaced PICS in 2009. I'm also one of the seven founders of the Mobile Web Initiative at the W3C where I was tasked with rewriting Tim Berners-Lee's vision of "One Web".
🪪 Co-Inventor of Account Verification: I co invented the concept of user account classification on the internet, the foundational idea behind features like Twitter Verified, though it's not really implemented as well as I'd imagined. While I'm an advocate for platforms offering optional identity verification, I've got zero tolerance for any government enforcing it on citizens to access software and services on the web.
🧠 Trust and Human Behaviour Expert: I've spent my career studying human behavior around online trust, reputation, and visual indicators because psychology and technology go hand in hand.
📱 Deep Security: I've designed some of the most intrusive security services for mobile devices, including custom Android firmware that intercepted every HTTPS request inside every app. I've built API services for mobile device OEMs, browser extensions for computers, and custom web browsers for iPad and iPhone.
📜 Deep Security Patents: Most leading security companies benefit from my patents for in app security, a proprietary portfolio covering 65 distinct categories of URI lookup, including malware, phishing, disinformation, child safety, identity, child abuse, and pornography.
🏛️ Strategic Government Advisor: I've advised both the IWF and NCMEC, the very organisations the EU constantly references to justify Chat Control. I've also hosted coordination calls between NCMEC and the DOJ on how to implement proactive monitoring on the web for child exploitation. In 2012, I advised the UK government during its original parliamentary inquiry into online safety, where I pushed for new controls, but allow parents can turn on for their children rather than blanket state mandates. They went ahead anyway and it has failed to keep teens off porn sites for 10+ years. No need to look at the failures in Australia.
🛡️ The App vs. Content Distinction: We must recognise that content filtering on social networks is an entirely different conversation that requires a completely different approach and set of solutions.
The truth is that most big tech companies don't care enough to build tools that allow people to easily avoid what they don't want to see on their platforms. But blocking or restricting entire apps and websites at the infrastructure layer is a vastly different, far more dangerous beast that threatens the architecture of the open internet.
I fixed it.
We need age-appropriate restrictions on platforms.
This is not about children.
It is about when the government can access our children and their parents, and everyone they know.
For state controlled access to information, money, travel, and speech for everyone ↓
Ursula von der Leyen has confirmed that everyone in the EU will need to use the EU's app for identity authentication before being able to access or post on social media websites.
🇪🇺 As an expert in online child safety, I am here to expose the misinformation and misdirection in von der Leyen's statements.
Today von der Leyen said:
"This is not about whether children can access social media, it is about whether social media can access our children".
💡The first part is true. This isn't about children. It's about surveillance and combating political dissent. A state that can't control its own citizens is more dangerous than a state rife with criminals. The second part is a PR soundbite that politicians are using like a campaign slogan straight out of 1984.
🇪🇺"The question is no longer if children face risks online, but what can we do to give children a safer start online".
💡No. You can't give children a "safer start" online any more than you can offline. In the offline world, the government doesn't enforce curfews or ban children from entering liquor stores, bars or restaurants. That's a parent's responsibility. The digital world should be no different.
🇪🇺"The age verification app is one of the tools to get it done".
💡This is a contradiction because she also said "It won't be foolproof".
🇪🇺"It's easy to use, it is privacy preserving and it is open source".
💡The app was compromised as soon as it was released. "Privacy-preserving" age verification is an oxymoron. You can't verify a person's age without verifying their identity. Where or how that age is shared afterwards is irrelevant.
🇪🇺"This is basically about putting back the power into the hands of parents".
💡More from 1984. The EU is doing the opposite. Parents are having their authority stripped by politicians who think they know better. Many parents are capable and unaffected by peer pressure, and they know how to use parental controls to block any app classified as 13+. Some teens are safe, their parents trust them, and the state has no business overruling that trust.
🇪🇺"We don't give our children keys to the car before they have their licence"
💡Comparing an app to a car is a false equivalence used to justify mass surveillance. Governments don't decide when a young person is ready for car keys, guardians do.
💡Forcing every adult and child into a biometric checkpoint just to use an app or website is not licensing drivers. It's the state seizing everyone's keys, locking the garage, and forcing every driver to ask a private company for permission to take a drive.
💡 This is a gross, unethical overreach that strips authority from parents while imposing state sanctioned identity verification on every adult who doesn't even have a child.
💡Additionally, people who pass a test, obtain a licence and drive a car aren't forced to use an app to constantly authenticate their suitability to drive.
🇪🇺"We do not let them buy alcohol until they are legally allowed"
💡False equivalence. We don't force every person to show ID at a shopping mall entrance just because a few people might buy alcohol with a meal at a restaurant. Some parents are okay with their 12 year-old going to the mall with friends while others aren't. Either way, it's their choice. Whatever irresponsible decisions some parents might make, every adult in the country shouldn't be forced to pay the price.
🇪🇺"It won't be foolproof"
💡This is all the proof we need to show that the EU and every government know that banning social media for teens won't protect them. When pressed by journalists about VPNs being used to circumvent a ban, politicians always state the ban isn't a silver bullet and will take time. The Mayor of London, Sadiq Khan went as far as to say "we know it's not the solution".
💡Either age verification works, or it doesn't. As a technical expert in this space, I can tell you there are no additional steps to take and no progress to be made. Either the approach does what it is supposed to do, or it's not fit for purpose. If they claim a bulletproof solution is coming, it can only mean one thing. They intend to ban or restrict VPNs to people who verify their identity.
🇪🇺"It will take time to invite the cultural change that is already taking shape in our society, just as it took time to outlaw drink driving, just as it took time to use seatbelts in the cars. Great change never happens overnight, but when it comes to our safety it is always worth it".
💡Comparing a social media ban and age verification to seatbelts is a completely broken analogy. Seatbelts are a safety feature that protects children while allowing them to travel in a car. A ban doesn't give kids a seatbelt. It kicks them out of the car entirely.
💡Instead of supporting parents who want to guide their own children through the digital world, this heavy-handed law strips away parental authority by banning the apps and websites that many parents are perfectly fine with and actively monitor.
💡Furthermore, enforcing these bans requires biometric age verification, which means forcing millions of adult citizens to scan their IDs, faces or credit cards just to browse the internet. That isn't a common-sense traffic law.
💡It's a digital checkpoint on every street. True safety means teaching kids how to navigate the digital world safely with real guardrails and parental guidance, not burning down digital spaces for everyone under the guise of protection.
🇪🇺☠️ The EU wants to ban teens from social media so every person is forced to verify their identity before they can read, share or post anything online. In their words, this is to protect children from dangerous content.
🇪🇺☠️ The EU wants to enforce "Chat Control" so every app has to monitor everything people say privately inside it, including apps with end-to-end encryption. In their words, this is to protect children from dangerous criminals.
💡Where this ends
🇪🇺 "If you want a picture of the future, imagine a boot stamping on a human face - forever".
George Orwell, 1984.
Russia's steady collapse will eventually drive them to the negotiating table.
When that happens, we must prepare for an ugly wave of Western cowardice, as weak leaders try to force Ukraine to accept Russian terms based on tiny Russian compromises. Ukraine deserves much better.
Russia is trapped in a downward spiral, both economically and militarily. Even though it might take time to fully manifest, this deterioration will eventually force Moscow to start offering compromises. Unfortunately, a massive wave of political cowardice is waiting to happen in Western capitals.
The moment Russia begins pretending to negotiate, many Western governments will immediately pivot and try to pressure Ukraine into a bad deal. They will want to end or freeze the conflict at any price and return to business as usual, completely ignoring the fact that a premature and bad deal only helps the aggressor.
Ukraine cannot accept a forced peace, and they should not have to. The sovereignty of Ukraine means that they alone decide when to negotiate (and what to accept).
The non-cowardly governments in the West must break ranks with the appeasers and give Ukraine full diplomatic and military cover to reject bad-faith deals.
If we want a safe and stable Europe, we must finish the job. Russian imperialism is a permanent threat for as long as we allow it to survive. This is our best opportunity to defeat it once and for all. We must show resolve, stand with Ukraine, and ignore the cowards who want to surrender
Ubisoft CEO is today having an "invitation-only" meeting with the European Commission, hosted by VGE, 2 weeks before the EC planned answer to our ECI.
SKG was not invited.
Thus, we publish an Open Letter, that we invite everyone of you to read it and share it for visibility.
On May 4th, a Swedish privacy lawyer caught Google Chrome silently installing a 4 GB AI model on every desktop computer it could reach.
If you delete the file, Chrome treats the deletion as a temporary error and downloads it again at the next opportunity.
The file is called weights.bin. It lives in a folder called OptGuideOnDeviceModel inside the Chrome user profile directory. It is the weights for Gemini Nano, Google's on-device large language model.
Hundreds of millions of devices now carry it. Two thirds of every desktop browser in the world is Chrome. Alexander Hanff, the Swedish privacy lawyer, installed a clean copy of Chrome on a fresh Mac, ran a script that visited a hundred webpages with no human input, and watched the system logs as Chrome silently wrote 4 GB to his disk.
Chrome 147 ships with an "AI Mode" pill rendered in the address bar. A reasonable user, knowing Chrome just installed an on-device AI model, would assume that visible AI Mode feature uses the model sitting on their hard drive. Local query. Local processing. Local privacy. Every part of that assumption is wrong.
The visible AI feature ships your queries to Google's servers. The 4 GB file on your hard drive does nothing visible. It powers obscure features buried in right-click menus that almost no Chrome user has ever clicked. The invisible binary sits on your disk and waits for the version that does.
Chrome is the most-installed surveillance product of all time. Two billion users. Every URL you visit, every search you type, every form you fill out, every site you stay on, every site you leave. The advertising model that pays for Chrome requires every one of those signals.
Chrome holds 64% of the global desktop browser market. Two-thirds of every reader of this sentence is reading it through software that just took 4 GB of their hard drive without asking.
Until last year, Chrome's surveillance ended at what you typed into the address bar and what your activity log showed. The model can now read the page you have open, the text you have selected, the draft you are writing inside a Gmail tab before you have decided whether to send it.
Google's "Help me write" feature requires that capability by definition. Help me write means read what I am writing. Locally. In real time. Pre-send.
It's time to switch browsers. The cartel cannot watch the screen it is not running on.
Chrome users last week were shocked to learn that a 4GB local AI model had been added to their browsers.
The good news is that this can be easily uninstalled.
Google being Google, it's not something they're just going to tell you; so let's look at the steps involved...
1/3