Sunday, August 30, 2026

Electronic Frontier Foundation tools

 

The Electronic Frontier Foundation (EFF) maintains several well-known privacy and security tools, along with its Surveillance Self-Defense (SSD) project, which recommends and teaches the use of privacy-enhancing technologies.

EFF's Main Technology Tools

1. Privacy Badger

A browser extension that automatically blocks online trackers and invasive advertising networks.

What it does:

Learns which domains are tracking you across websites.

Blocks trackers automatically.

Sends Global Privacy Control (GPC) signals to participating websites.

Helps reduce behavioral advertising and data collection.

Best for: Everyday web browsing privacy.

2. Cover Your Tracks

An online testing tool that evaluates how uniquely identifiable your browser is.

What it does:

Tests for browser fingerprinting.

Checks tracker blocking effectiveness.

Shows how easily websites may distinguish your browser from others.

Best for: Understanding your privacy exposure online.

Privacy and Security Tools Recommended by EFF SSD

EFF's Surveillance Self-Defense guide recommends several tools and provides tutorials for them. These include:

Signal

End-to-end encrypted messaging and calls.

Considered one of the strongest consumer messaging apps.

Tor Browser

Routes traffic through the Tor network.

Helps hide your IP address and browsing activity.

WhatsApp

Uses end-to-end encryption for messages.

Recommended with an understanding of its privacy tradeoffs.

Password Managers

Generate and store strong unique passwords.

Reduce password reuse.

VPNs

Encrypt traffic between your device and VPN server.

Can help against local network surveillance.

Two-Factor Authentication (2FA)

Adds a second verification step beyond passwords.

Device Encryption Tools

Windows BitLocker

macOS FileVault

Android and iPhone encryption features

These are covered in EFF's tool guides and security tutorials.

Surveillance Self-Defense (SSD)

SSD isn't a single tool. It's EFF's comprehensive security education platform that includes:

Security planning guidance

Privacy tutorials

Threat modeling

Secure communications advice

Tool installation guides

Security scenarios for activists, journalists, and everyday users

For most people today, EFF would typically recommend starting with:

Privacy Badger

Signal

A password manager

Two-factor authentication

Tor Browser (when extra anonymity is needed)





Monday, August 17, 2026

 Apple Updates A lot



AI advances in Wellness

 






Life Long Learners

 

If you're looking for college-level online courses for lifelong learners, these are among the best options:

For Adults 50+ (Discussion-Based, Non-Credit)

UT Austin Osher Lifelong Learning Institute (OLLI)

College-level lectures and seminars taught by university and community experts.

Online, on-campus, and recorded options.

Designed specifically for adults 50+.

https://olli.utexas.edu/

LLI Austin

Non-credit courses covering history, science, literature, current events, and more.

Affordable and community-oriented.

Some courses may be offered online depending on the semester.

https://www.lliaustin.org/

University-Level Online Courses

edX

Courses from Harvard, MIT, UT System schools, and many other universities.

Audit many courses for free; pay only if you want a certificate.

Subjects include AI, computer science, art history, economics, philosophy, and more.

https://www.edx.org/

Coursera

University courses from institutions such as Stanford, Yale, Duke, and the University of Michigan.

Offers individual courses, certificates, and degree programs.

https://www.coursera.org/

Technology Courses

AI and Generative AI

Data Science

Cybersecurity

Programming (Python, JavaScript)

Cloud Computing

Available through:

https://www.edx.org/

https://www.coursera.org/

https://continue.austincc.edu/lifelong-learning

Arts and Humanities Courses

Art History

Drawing and Painting

Photography

Music Appreciation

Literature and Creative Writing

Available through:

https://olli.utexas.edu/

https://programs.austincc.edu/arts-digital-media-and-communications/art/

https://www.edx.org/

 

Friday, May 8, 2026

Millions of student & educators personal data solen Instructure the company that runs Canvas learning management systems

 Canvas is used by 7000+ universities, K-12 school districts world wide. The parent company Instructure disclosed the data breach May 5, 2026. Data included names, email addresses, student ID numbers and private messages between users.
 The criminal extorsion group ShinyHunters has claimed responsibility for the attack. The private messages could contain medical and mental health information to advisors.

Google Chrome 4GB AI LLM file

 Many stories on the Internet concerning Google Chrome downloading a large file to support AI with a local LLM model. This can improve security and privacy.
If you are low on disk space and want to remove this file AND disable Google from reloading it:



✅ Step 1: Check if the AI file is even on your computer

First, don’t assume it’s there.

On Windows

Press Windows + R

Paste this and hit Enter: %LOCALAPPDATA%\Google\Chrome\User Data

Look for a folder named something like:

OptimizationGuideModelStore

OptGuideOnDeviceModel

Inside those folders, look for a large file:

Often named weights.bin

✅ If you see it and it’s several GB → that’s the AI model
❌ If you don’t see it → nothing to worry about


On Mac

Open Finder

Press Command + Shift + G

Paste: ~/Library/Application Support/Google/Chrome

Look for the same folders mentioned above


✅ Step 2: Turn OFF Chrome AI features (very important)

Do this FIRST—otherwise the file may come back.

In Chrome:

Go to: chrome://settings

Search for**“AI” or “Gemini”**

Turn OFF:

Gemini / AI assistant

Writing help (“Help me write”)

Page content sharing

👉 These features are what trigger the model download


Also remove the AI sidebar/button

If you see a Gemini icon:

Right‑click → Unpin

Or go to: chrome://settings/ai/gemini → turn everything OFF


✅ Step 3: Disable AI Mode (search/chat button)

In Chrome, open: chrome://flags

Search for: ai mode

Set these to Disabled:

AI Mode Omnibox entrypoint

Omnibox Allow AI Mode Matches

Restart Chrome

👉 This prevents Chrome pushing AI features again


✅ Step 4: Delete the AI file (if present)

Once AI features are OFF:

Go back to the folder from Step 1

Delete:

weights.bin

Or the entire AI model folder

👉 If AI is disabled, Chrome should not re-download it


✅ Step 5: (Optional) Verify it stays gone

Restart your computer

Reopen Chrome

Check if the folder/file is gone


⚠️ Important notes

Chrome may try to reinstall the file if:

AI features get re-enabled

Chrome updates reset settings

“chrome://flags” settings are temporary and may revert after updates [oilprice.com]


🧠 Simple summary

You’re doing 3 things:

Turn OFF AI features ✅

Disable hidden AI switches ✅

Delete the file ✅


✔ After this, Chrome should:

Stop using AI features

Stop downloading the large model

Free up that storage space

Friday, May 1, 2026

Most Windows 11 machines are updating automatically

 

What is happening now

Microsoft is actively forcing feature updates on unmanaged Windows 11 PCs (Home and most Pro machines not controlled by IT):


What is not happening

Managed / work devices are NOT all updating automatically:

  • Enterprise‑managed PCs (Intune, Autopatch, Group Policy, SCCM, etc.) do not get forced feature upgrades
  • IT controls:
    • Which version
    • When it deploys
    • Whether it’s phased, blocked, or delayed
      using Windows Update rings and feature update policies [learn.microsoft.com]

So if your Windows 11 machine is:

  • Enrolled in Intune
  • Part of a corporate domain
  • Managed by Autopatch or update rings

…then it only updates when IT allows it, not because Microsoft says “now.”


Why it feels like “everything is updating”

A few things are overlapping right now:

  • Multiple Windows 11 versions hitting end‑of‑service windows
  • A mandatory April 2026 security update (KB5083769) that installs on supported versions [cybersecur...tynews.com]
  • Microsoft expanding automatic upgrades to “all unmanaged Home + Pro devices” in April–May 2026 [pureinfotech.com], [notebookcheck.net]

That combination makes it look like every Windows 11 PC is updating — but the split is really unmanaged vs. managed.


Quick rule of thumb

  • Personal / home PC → ✅ likely updating or will soon
  • Company‑owned / IT‑managed PC → ❌ only updates per IT policy

Chrome and Firefox Browser Updates to address security issues

Chrome version 147 has 30 fixes for security issues.
The latest version of Chrome is 147.0.7727.138
Firefox version 150.0.1 fixes 4 security issues.
Chromium based browsers should follow these fixes soon.

Monday, April 27, 2026

ADT Confirms Data Breach

  ADT confirmed a data breach detected on April 20, 2026, involving unauthorized access to certain cloud‑based environments. The incident has been publicly linked to the ShinyHunters extortion group, which threatened to leak stolen data unless a ransom was paid.

About 5.5 million individuals had data exposed, according to analysis by Have I Been Pwned after reviewing the leaked data.
  • Names
  • Phone numbers
  • Physical addresses

In a small percentage of cases:

  • Dates of birth
  • Last four digits of Social Security numbers or Tax IDs

Not accessed:

  • Credit card or bank information
  • Customer alarm or monitoring systems

Based on standard guidance cited in coverage of the breach:

  • Watch for phishing calls, texts, or emails referencing ADT
  • Monitor credit reports and accounts for unusual activity
  • Take advantage of ADT’s identity‑protection services if offered
  • Check whether your email appears in this breach via Have I Been Pwned


Tuesday, April 21, 2026

Microsoft Patch Tuesday statistics

 

  • The April 14, 2026 Patch Tuesday addressed 167 flaws, including 2 zero‑day vulnerabilities (one actively exploited). 
  • It’s widely reported as one of Microsoft’s largest Patch Tuesday releases to date.
  • Monday, April 20, 2026

    Maryland bans Surveillance pricing

     

    Maryland banned using your personal data to secretly charge you more for groceries than someone else — a first in the U.S.

    Under the Protection from Predatory Pricing Act, Maryland will become the first U.S. state to outlaw this practice in the grocery sector. The law:

    Prohibits

    • Using personal or surveillance data to set individualized grocery prices
    • Charging different people different prices for the same grocery item based on who they are
    • Real‑time price changes driven by consumer profiling

    Requires

    • Grocery prices generally remain fixed for at least one business day, limiting sudden price spikes from digital tag
       

       
       

    Tuesday, April 14, 2026

    Booking.com data breach April 14, 2026

      Customers began receiving notifications April 12-13

    According to Booking.com’s own notifications and follow‑up reporting, the exposed information may include:

    • Names
    • Email addresses
    • Phone numbers
    • Postal addresses
    • Reservation details (dates, property info, itinerary)
    • Messages or notes shared with accommodation providers

    Booking.com has repeatedly stated that payment and credit‑card data were not accessed.

    Booking.com reports it:

    • Reset reservation PIN codes tied to affected bookings
    • Contacted impacted customers directly by email
    • Advised customers to be vigilant for phishing attempts
    • Stated the incident is now “under control”, though investigations are ongoing

    The company has not disclosed:

    • How many customers were affected
    • Exactly when the breach occurred
    • Technical details of how the access happened
    • While no financial data was taken, experts warn that the combination of personal info + travel details makes this breach particularly dangerous. Attackers can craft highly convincing phishing messages (email, SMS, WhatsApp, or phone calls) that reference real bookings.

      Reports already show customers receiving scam contacts pretending to be Booking.com or their hotel, asking for “verification” or payments.

       

      Booking.com has emphasized that it will never:

      • Ask for credit‑card details
      • Request bank transfers
      • Ask for personal information via email, phone, text, or WhatsApp

      Customers are strongly advised not to click links in unsolicited messages claiming to be from Booking.com or properties. 

       

      Based on Booking.com’s guidance and security reporting:

      • ✅ Treat unexpected messages about bookings as suspicious
      • ✅ Verify any issue by logging directly into Booking.com (not via links)
      • ✅ Be cautious of urgent payment or “verification” requests
      • ✅ Monitor email and messaging apps for phishing attempts
       

    Sunday, April 12, 2026

    Anthropic Mythos

      AI giant Anthropic announced a new model called Mythos..
    Mythos finds security flaws in software. Windows, MacOS, Linux, browsers, aps, ANYTHING.

     This prompted a urgent meeting with the Treasury Secretary, the Federal Reserve, and Wall Street executives.

     Given the scope of this tool  it might be good to use more acceptance to offered patching.

    UPDATE:

    Mythos has not produced named patches but has fundamentally accelerated vulnerability discovery, compressed patch timelines, and forced an industry‑wide shift toward faster, more coordinated defensive updates.
     

    Industry‑wide updates attributable to Mythos (Claude Mythos Preview)

    1. Step‑change in vulnerability discovery capability (industry level)

    Anthropic has publicly documented that Claude Mythos Preview autonomously identified thousands of previously unknown (“zero‑day”) vulnerabilities across:

    • All major modern operating systems
    • Major web browsers
    • Widely deployed open‑source libraries

    Interesting to note  some major browsers have had back-to-back updates recently.

     

    WARNING from FBI, NSA, CISA and Department of Energy - Ireanian hackers

     Collective alarm from US government agencies citing Iranian attacks in US Critical Infrastructure via exploits in Programmable Logic Controllers (PLCs).

     Mutually Assured Disruption

    A report cites 5,200 device reachable on the Internet.

     

    Russia spy agency reported to be hacking into home and small business routers

     As a follow on to the recent blog post of  March 30 where the FCC has banned almost all consumer grade routers not made in the United States - a Russian spy agency was recently found to be hacking into TP-Link and MicroTik routers with known vulnerabilities to route victim's Internet traffic to servers under the control of Russian hacking unit known as Fancy Bear.

     The intent is to steal passwords and OAuth tokens to gain access th those accounts.

     The FBI has secured a court order allowing them to effectively hack into the affected routers and remove the dodgy DNS records.
     

     

    Tuesday, March 31, 2026

    ClickFix exploits on the rise

     

    ClickFix tricks users into running malicious commands themselves by pretending they’re “fixing” a problem or completing a verification.

    Why ClickFix is so dangerous

    • ✅ Bypasses security tools – the action looks legitimate
    • ✅ Cross‑platform – Windows, macOS, and Linux are all targeted
    • ✅ No vulnerability required – exploits human behavior instead
    • ✅ Very fast – compromise can happen in seconds

    Microsoft and other vendors report ClickFix has surpassed traditional phishing in some environments as an initial access method

    Common ClickFix disguises you’ll see

    • Fake “I am not a robot” CAPTCHA
    • Fake Cloudflare verification
    • Fake Windows Update screen
    • “Browser error – fix required”
    • “Document failed to load – run this to fix”
    • Fake IT support instructions 

      Legitimate websites will NEVER ask you to paste commands into Terminal, PowerShell, or Run to verify or fix something.
       

    Monday, March 30, 2026

    FCC recent ban on all foreign made routers

     

    In March 2026, the Federal Communications Commission (FCC) added all foreign‑made consumer‑grade routers to its “Covered List”, which means new router models that are made (or even partially made) outside the U.S. can no longer be approved for sale or import in the United States.

    This is implemented through the FCC’s equipment authorization process—if a device can’t get FCC authorization, it can’t legally be imported or sold.No existing routers  

    No existing routers are banned, consumers may continue to use them, firmware updates can continue.

    BUT, this may make us more insecure s consumers may continue to use older routers

    https://www.malwarebytes.com/blog/news/2026/03/new-fcc-router-ban-could-leave-home-networks-less-secure