In this golden age of surveillance, making E2EE chat normal and expected has been privacy's biggest win. I hate to see it getting rolled back. https://thehackernews.com/2026/03/meta-to-shut-down-instagram-end-to-end.html
evacide
mastodon
4.5.7
Director of Cybersecurity
@EFF
/ Co-founder of
@stopstalkerware
/ These are my opinions, not my employers’ / I did a TED talk once
Posts
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Every day in this terrible timeline, I am forced to read extremely cursed sentences. Today's cursed sentence is: Travis Kalanick Plots New Self-Driving Venture with Levandowski, Uber .
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
I have been invited to a Matrix-themed party and I simultaneously have nothing to wear and could probably wear anything that is currently in my closet.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
For all the people saying that Grammarly should be sued over its "expert review" feature, here is the Grammarly class action lawsuit, alleging violation of the right to privacy and the right of publicity: https://prf-law.com/current-cases/class-action-alleges-that-grammarly-misappropriated-the-names-of-journalists-and-authors-through-its-expert-review
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
When the hacker expressed disgust at the child abuse images on the server and threatened to report them to the FBI, agents had to get into a video chat with the hacker to convince him they WERE the FBI.
We continue to live in the stupidest possible timeline.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
There isn't a blog post I can link to, but apparently "experts" who have written to Grammarly about its new "expert review" feature have been told that they are rolling it back and rethinking it. I hope they rethink it right into the ground.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Attribution is hard. And there is a difference between getting a contractor on the record attributing the toolkit and a bunch of infosec dudes sitting around pontificating about how "everyone knows."
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Pakistan's main APT group has switched from off-the-shelf low quality malware tools to vibe-coded custom malware.
I've been expecting to see this shift for a while and it is interesting to see it actually starting to happen.
https://businessinsights.bitdefender.com/apt36-nightmare-vibeware
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Do you work in fundraising? Do you want a job that isn't evil? Signal is hiring a director of major gifts: https://jobs.lever.co/signal/68f75269-fe43-4d25-8d82-69439351f14d
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
I aspire to one day have a fraction of the confidence of a mediocre white man sitting down to do an interview with Isaac Chotiner.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
The data from your Meta Ray Bans is used to train Meta's AI, which most people don't understand means that humans are looking at the most intimate details of their lives. https://www.svd.se/a/K8nrV4/metas-ai-smart-glasses-and-data-privacy-concerns-workers-say-we-see-everything
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
When we talk about the problems with Bluetooth-enabled physical trackers, we usually talk about AirTags, but let us save some rage for Tile, powered by this paper discussing Tile's privacy, security, and accountability problems: https://arxiv.org/abs/2510.00350v1
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
I have come away from my last conference cautiously optimistic about how useful AI can be in reversing malware and extremely scared about all of the new attack surface being created in the use and deployment of AI tools.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
I'm just a girl, incrementing the counter on the number of times I have been sent a plaintext email from a Protonmail user telling me that the message is encrypted.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Anonymously threatening a security researcher seems like a shooting-yourself-in-the-dick level bad decision. Kudos to Allison Nixon for not taking any shit.
https://www.technologyreview.com/2026/02/16/1132526/allison-nixon-hackers-security-researcher
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
How do you organize safely and effectively in the golden age of surveillance? I have some thoughts and Wired does too: https://www.wired.com/story/how-to-organize-safely-in-the-age-of-surveillance/
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
The most monstrous lie that I regularly tell myself is "I'll get that work done while I'm on the plane."
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
This story is unhinged, especially given that the Trump administration cut funding for censorship circumvention technology that actually works.
"...the site had no content but showed the National Design Studio's logo, the words "fly, eagle, fly" and a log-in form."
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
It's nice to see that when #DEFCON says "Don't support rapists" they really mean it. https://techcrunch.com/2026/02/18/hacking-conference-def-con-bans-three-people-linked-to-epstein/
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
You may be tempted to roll your eyes and say that this was obvious, but there is a substantive difference between pointing out there is a slippery slope and having solid evidence that Ring's CEO is planning to expand Search Party beyond lost pets. Kudos to 404 Media.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
If you're a journalist who covers law enforcement, don't let their claims about slick and effective technology go unchallenged.
https://www.eff.org/document/selling-safety-journalists-guide-covering-police-technology
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
I can be angry about rising fascism and also angry about facial recognition built into surveillance glasses at the same time, not only because these things are directly related, but because I contain fucking multitudes and all them are mad all the goddamn time.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Meta thinks now is a great time to launch facial recognition surveillance tech in their creepy glasses because EFF will be too distracted by fascism to notice.
We noticed.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Russia fully blocks WhatsApp and encourages Russians to use home-grown surveillance-compliant Max: https://thehill.com/policy/international/5736203-russia-blocks-whatsapp-meta/
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
A hacktivist has scraped more than half-a-million payment records from a provider of consumer-grade stalkerware apps, because stalkerware makers don't give a shit about the security of their products.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
I've spent the last year learning Spanish just so I could understand Bad Bunny lyrics.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Trying to explain compartmentalization to activists, but the biggest stumbling block is that most people become activists by accident, so their activism is deeply enmeshed with all of their existing accounts, platforms, and devices.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Hey, remember that time I said that pointing out that AI is giving bad data to ICE is missing the point because ICE doesn't actually care if the data is good? Check out how right I am.
https://www.wired.com/story/cbp-ice-dhs-mobile-fortify-face-recognition-verify-identity/
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Every once in a while, someone gets the genius idea of impersonating me online and I spend an afternoon looking for the most chaotic way to make them regret that choice.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Notepad++ publishes a blog post saying they caught a probably-Chinese state actor hijacking their product in an attack against highly-selective targets that began last June: https://notepad-plus-plus.org/news/hijacked-incident-info-update/
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
The StopICE plot thickens. It would be nice if Austin would release evidence to back up his claims: https://www.risky.biz/risky-bulletin-stopice-blames-hack-on-a-cbp-agent-here-in-socal/
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
EFF will be closed Friday, Jan. 30 as part of the national shutdown in opposition to ICE and CBP and the brutality and terror they and other federal agencies continue to inflict on immigrant communities and any who stand with them.
https://www.eff.org/deeplinks/2026/01/eff-close-friday-solidarity-national-shutdown
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
Project Zero releases a 0-click exploit chain for the Pixel 9. This one targets the Pixel, but the 0-click bug and exploit techniques used also apply to most other Android devices.
https://projectzero.google/2026/01/pixel-0-click-part-1.html
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
It is an extremely important to time to support independent journalism. You may notice that I repost Techdirt's content all the damn time. That's because Mike Masnick is usually right and I think you should know about it.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
I regret not buying a My Marxist Feminist Dialectic Brings All the Boys to the Yard poster because I have some free wall space next to my It's a Slow Apocalypse, You'll Work Through It poster.
Director of Cybersecurity @EFF / Co-founder of @stopstalkerware / These are my opinions, not my employers’ / I did a TED talk once
No amount of complicity is going to save you from fascism, so you might as well fight.