❌

Normal view

There are new articles available, click to refresh the page.
Yesterday β€” 24 January 2026Main stream
Before yesterdayMain stream

TikTok Is Now Collecting Even More Data About Its Users

By: BeauHD
23 January 2026 at 19:02
An anonymous reader quotes a report from Wired: When TikTok users in the U.S. opened the app today, they were greeted with a pop-up asking them to agree to the social media platform's new terms of service and privacy policy before they could resume scrolling. These changes are part of TikTok's transition to new ownership. In order to continue operating in the U.S., TikTok was compelled by the U.S. government to transition from Chinese control to a new, American-majority corporate entity. Called TikTok USDS Joint Venture LLC, the new entity is made up of a group of investors that includes the software company Oracle. It's easy to tap "agree" and keep on scrolling through videos on TikTok, so users might not fully understand the extent of changes they are agreeing to with this pop-up. Now that it's under U.S.-based ownership, TikTok potentially collects more detailed information about its users, including precise location data. Here are the three biggest changes to TikTok's privacy policy that users should know about. TikTok's change in location tracking is one of the most notable updates in this new privacy policy. Before this update, the app did not collect the precise, GPS-derived location data of U.S. users. Now, if you give TikTok permission to use your phone's location services, then the app may collect granular information about your exact whereabouts. Similar kinds of precise location data is also tracked by other social media apps, like Instagram and X. [...] Rather than an adjustment, TikTok's policy on AI interactions adds a new topic to the privacy policy document. Now, users' interactions with any of TikTok's AI tools explicitly fall under data that the service may collect and store. This includes any prompts as well as the AI-generated outputs. The metadata attached to your interactions with AI tools may also be automatically logged. [...] This change to TikTok's privacy policy may not be as immediately noticeable to users, but it will likely have an impact on the types of ads you see outside of TikTok. So, rather than just using your collected data to target you while using the app, TikTok may now further leverage that info to serve you more relevant ads wherever you go online. As part of this advertising change, TikTok also now explicitly mentions publishers as one kind of partner the platform works with to get new data.

Read more of this story at Slashdot.

US Judge Rules ICE Raids Require Judicial Warrants, Contradicting Secret ICE Memo

23 January 2026 at 17:24
The ruling in federal court in Minnesota lands as Immigration and Customs Enforcement faces scrutiny over an internal memo claiming judge-signed warrants aren’t needed to enter homes without consent.

French Crypto Tax Platform Waltio Hit by 50,000-User Data Breach

23 January 2026 at 17:37

French authorities have opened a preliminary investigation into a data breach at Waltio, a cryptocurrency tax reporting platform used by tens of thousands of investors.

This occurred when hackers reportedly got access to sensitive user information and tried to blackmail the company.

The event has brought up new issues regarding the exposure of personal data in the crypto industry, as target fraud and physical attacks against holders are becoming more and more frequent in France.

Authorities Link Waltio Breach to Shiny Hunters’ Extortion Attempt

In a statement released this week, French cybersecurity institutions confirmed that, via its cybercrime division, the Paris Public Prosecutor’s Office had issued an order to the National Cyber Unit of the Gendarmerie to establish the extent of the breach and identify exposed users.

Source: Paris Public Prosecutor’s Office

Officials advised that users whose information might have been stolen should be wary of scammers who claim to be genuine service providers or other officials and force them to give up their digital assets using the stolen information.

The law enforcement agencies reported that some more recent fraudsters posed as crypto businesses, bank anti-fraud units, or even law enforcement officers and magistrates.

French newspaper Le Parisien stated that the attack at Waltio was associated with a ransom demand by a hacking organization called Shiny Hunters.

The group purportedly had obtained personal information of approximately 50,000 Waltio users, most of whom reside in France, and said it had samples of the stolen information as proof.

Waltio later filed a complaint of attempted extortion and unauthorized access to the automated data system.

Waltio said its initial internal assessment showed that the attackers accessed tax reports for the 2024 period. These documents included users’ email addresses, information on crypto profits or losses, and asset balances at the end of the year.

The company stated that banking details, administrative records, and tax identification data were not affected and that its core infrastructure was not compromised.

Waltio added that its services remain operational and that client funds are not at risk.

France Tightens Oversight After Crypto Data Breach Amid Rise in Kidnapping Cases

Waltio was founded in France and is headquartered in Clermont-Ferrand. It serves roughly 150,000 users and focuses on simplifying crypto tax compliance for European investors, particularly in France, Spain, and Belgium.

The platform aggregates transaction data from more than 700 exchanges, wallets, and blockchains to calculate capital gains, losses, and staking income, and generates tax-compliant reports for local filings.

The investigation comes amid heightened scrutiny of crypto-related data leaks in France.

In the last year, police have attributed a number of home invasions, kidnappings, and attempted kidnappings to the criminals who intended to use the knowledge of the victims having digital assets.

Although the leakage of data has not been directly linked to these crimes, the investigation teams have not eliminated the chances of the data being used to establish potential targets.

πŸ‡«πŸ‡· Masked gunmen steal crypto USB in France as prosecutors reveal tax official sold government database access identifying crypto investors to criminal gangs for 800 euros per operation.#Crypto #Attack #Francehttps://t.co/GmfOkwsE6E

β€” Cryptonews.com (@cryptonews) January 9, 2026

Fraud victims have been cautioned to keep evidence, report to the police, and address the data protection authority in France in instances where they feel that their personal data has not been sufficiently safeguarded.

The Waltio incident is not the first case of data exposure in the crypto industry in the past.

Hardware wallet manufacturer Ledger announced earlier this month that a breach of a third-party payment processor, Global-e, took place, exposing the data of its customers.

Last month, crypto tax software developer Koinly also notified users of a potential email data breach related to the use of a third-party analytics platform.

The post French Crypto Tax Platform Waltio Hit by 50,000-User Data Breach appeared first on Cryptonews.

Ethereum Founder Vitalik Buterin Ditches Big Tech: His 2026 β€œSelf-Sovereign” Stack Reveals Surprising Changes

23 January 2026 at 11:19

Ethereum cofounder Vitalik Buterin has outlined a personal shift away from Big Tech platforms, framing 2026 as a pivotal year for what he calls β€œcomputing self-sovereignty.”

This is a concept that extends beyond blockchain and into how individuals use everyday software, communication tools, and artificial intelligence.

2026 is the year we take back lost ground in computing self-sovereignty.

But this applies far beyond the blockchain world.

In 2025, I made two major changes to the software I use:

* Switched almost fully to https://t.co/caFP0K5fYF (open source encrypted decentralized docs)
*…

β€” vitalik.eth (@VitalikButerin) January 22, 2026

In a post shared on X, Buterin described a series of changes he has made across his devices to reduce reliance on centralized, data-intensive services.

Vitalik Buterin Replaces Google, Telegram With Privacy-Focused Alternatives

He claimed that the process started in 2025 when he transferred nearly completely to the open-source and encrypted and decentralized document platform Fileverse, which is purported to be a privacy-focused alternative to Google Docs.

At roughly the same period, he reported having changed to Signal as his main messaging application, abandoning Telegram.

Signal supports end-to-end encryption on all conversations by default and only retains a little metadata, whereas Telegram encrypts messages only in optional so-called secret chats.

He further stated that it otherwise stores messages and metadata on its servers, a design that has attracted increased attention due to an increase in law enforcement requests in some jurisdictions.

πŸ”’ Telegram CEO Pavel @Durov has issued a statement reaffirming the platform’s commitment to user privacy.#privacy #telegramhttps://t.co/ZPIeUno9K1

β€” Cryptonews.com (@cryptonews) April 21, 2025

The changes made in 2026 included more extensive ones, which were due to those initial adjustments.

Buterin claimed to have substituted Google Maps with OpenStreetMap, with Organic Maps on mobile phones, citing the advantage of local and offline use that restricted the volume of location data sent to third parties.

He also left Gmail for Proton Mail, citing encrypted messaging as a more powerful tool to use for confidential communication.

Simultaneously, he claimed to have started giving priority to decentralized social media and still tests the idea of running large language models locally, as opposed to using cloud-based AI services.

Buterin Sees Local AI as the Future of User Privacy

The rationale of these decisions is not purity in ideology but practicality, as Buterin wrote.

According to him, it is not necessary to send big amounts of personal information to centralized services, as there are tools that can be used to minimize this exposure.

He admitted that local AI systems still have usability and integration issues, especially for translation, transcription, and document search, but noted that there has been a lot of improvement in the last year.

He explained a more ambitious long-term vision where local models are integrated with cryptographic schemes like zero-knowledge proofs, trusted execution environments, and local data filtering to restrict the information that ever leaves a user’s device.

Rising AI Demand Puts Self-Sovereign Computing Back on the Map

The remarks made by Butterin come amidst the wider revival of interest in self-sovereign computing, which is a model that highlights the importance of individualized controls of data, identity, and computing resources.

The idea integrates identity systems based on decentralization, personal servers, and privacy-by-design software with the aim of minimizing reliance on platforms that are controlled by corporations.

Privacy activists, including Naomi Brockwell, have long held the position that the most consistent approach to ensuring autonomy is to run software and AI models in place.

The most private way to use AI is to host it locally, but you're limited by your own hardware. There are AI platforms that allow you to access more powerful models & also respect your privacy. Planning to update this video soon to include newcomers like https://t.co/ueOskOEx0g. pic.twitter.com/WlB6PUxlpA

β€” Naomi Brockwell priv/acc (@naomibrockwell) January 19, 2026

The time also stands out due to the re-evaluation of the strategic value of computing infrastructure by governments and corporations.

Analysts believe that 2026 will be the year of a change in the treatment of AI data centers, energy-backed compute and GPU capacity.

πŸ‘€ Governments are expected to start treating AI data centers and energy-backed computing power as strategic infrastructure in 2026, similar to how oil reserves are managed.#AI #Energy #TokenizedDollars #Cryptohttps://t.co/DUYrsqn7iI

β€” Cryptonews.com (@cryptonews) January 13, 2026

With the demand of large-scale AI continuing to outpace its supply, compute and energy are becoming viewed as a source of geopolitical power.

In that environment, the appeal of local and decentralized computing models has grown, particularly as concerns mount over surveillance, data residency, and platform dependence.

The post Ethereum Founder Vitalik Buterin Ditches Big Tech: His 2026 β€œSelf-Sovereign” Stack Reveals Surprising Changes appeared first on Cryptonews.

Millions of people imperiled through sign-in links sent by SMS

21 January 2026 at 18:22

Websites that authenticate users through links and codes sent in text messages are imperiling the privacy of millions of people, leaving them vulnerable to scams, identity theft, and other crimes, recently published research has found.

The links are sent to people seeking a range of services, including those offering insurance quotes, job listings, and referrals for pet sitters and tutors. To eliminate the hassle of collecting usernames and passwordsβ€”and for users to create and enter themβ€”many such services instead require users to provide a cell phone number when signing up for an account. The services then send authentication links or passcodes by SMS when the users want to log in.

Easy to execute at scale

A paper published last week has found more than 700 endpoints delivering such texts on behalf of more than 175 services that put user security and privacy at risk. One practice that jeopardizes users is the use of links that are easily enumerated, meaning scammers can guess them by simply modifying the security token, which usually appears at the right of a URL. By incrementing or randomly guessing the tokenβ€”for instance, by first changing 123 to 124 or ABC to ABD and so onβ€”the researchers were able to access accounts belonging to other users. From there, the researchers could view personal details, such as partially completed insurance applications.

Read full article

Comments

❌
❌