The DJI Romo robovac had security so poor, this man remotely accessed thousands of them | The Verge

He could remotely control them, and look and listen through their live camera feeds, he tells me, saying he tested that out with a friend. He could watch them map out each room of a house, generating a complete 2D floor plan. He could use any robot’s IP address to find its rough location.

Dutch authorities allegedly seize VPN server without a warrant — company claims that law enforcement will return it after analyzing the device fully | Tom’s Hardware

Dutch authorities allegedly seize VPN server without a warrant — company claims that law enforcement will return it after analyzing the device fully | Tom’s Hardware Something to consider when…

Researcher finds Chinese KVM has undocumented microphone, communicates with China-based servers — Sipeed’s nanoKVM switch has other severe security flaws and allows audio recording, claims researcher | Tom’s Hardware

The researcher says the device’s software stack exposes weak points from the moment it boots. Early units arrived with a pre-set password and open SSH access, a problem the researcher reported to Sipeed and which the company later corrected. The web interface still lacks basic protections, including CSRF defence and any mechanism to invalidate active sessions.

High-performance mice can be used as a microphone to spy on users thanks to AI — Mic-E-Mouse technique harnesses mouse sensors, converts acoustic vibrations into speech | Tom’s Hardware

The processing works like this: the raw audio data is run through digital signal processing using a Wiener Filter, where you can start to hear some information. This is then further cleared up through a neural model, giving the researchers clear audio.

23andMe is potentially selling more than just genetic data – the personal survey info it collected is just as much a privacy problem

When customers originally signed up for 23andMe, they agreed to terms and conditions and a privacy notice that allows the company to use their information for research and development as well as share their data, in aggregate, with third parties. If consumers consented to additional research, which the vast majority did, the company can additionally share their individual information with third parties. 23andMe has also been clear that if it is involved in a bankruptcy or sale of assets, consumer information might be sold or transferred.

As 23andMe goes bankrupt, millions of people’s DNA data is up for sale

“Folks have absolutely no say in where their data is going to go,” said Tazin Khan, CEO of the nonprofit Cyber Collective, which advocates for privacy rights and cybersecurity for marginalized people. 

7 Accounts You Must Always Protect With Two-Factor Authentication

Two-factor authentication adds an extra layer of security and keeps your account protected even if your password is compromised. While it’s advisable to enable two-factor authentication on all accounts that support it, here are some accounts that should always have this extra layer of protection.

Google Docs, look out—there’s a new private alternative in town | TechRadar

Proton Docs comes as a way to ensure that document creation and collaboration are both secure and user-friendly. As with all its products, Docs is completely free to use.

Your phone’s secret network activity: 10 times worse than DNS logs reveal | Cybernews

Many data brokers may use that data for behavior profiling, analytics, and advertising, and it may also be sold to third parties. Commercial spyware, such as Pegasus, used to track journalists, political dissidents, and others, could be delivered via ad networks or other legitimate infrastructure your apps rely on.

VPNs Aren’t Bulletproof: 7 Common Misunderstandings About VPN Security

First, both the website and your ISP probably know that you’re using a VPN, and they also know the time and session length of your visit. Second, your actual activity on those sites can easily reveal your identity, since there are cookies on your local system, and if you log in to any accounts then obviously the target site knows who you are.