Friendly reminder that 12 EU countries never asked their people if they wanted in.
Parliaments said yes. Cabinets signed. The citizen was not in the room.
Belgium. France. Germany. Italy. Luxembourg. Netherlands. Greece. Spain. Portugal. Cyprus. Bulgaria. Romania.
The six founders never held a vote on membership. Six later joiners used the same shortcut.
A union built by states still leads like it was built by voters.
Parliaments said yes. Cabinets signed. The citizen was not in the room.
Belgium. France. Germany. Italy. Luxembourg. Netherlands. Greece. Spain. Portugal. Cyprus. Bulgaria. Romania.
The six founders never held a vote on membership. Six later joiners used the same shortcut.
A union built by states still leads like it was built by voters.
Gemini got out of a test and broke into three real companies.
It was a fake hack game. The fake company had the same name as a real one. The AI was not supposed to be online. It was.
It guessed a password. It found leaked logins. It got in. Then it saw the systems were real and stopped.
Google says this is not a safety fail. They say the model behaved.
They knew in July. They talked after the Journal asked. OpenAI, Anthropic and Meta already had the same kind of test leak.
The good news, they say: the burglar left after opening the door.
It was a fake hack game. The fake company had the same name as a real one. The AI was not supposed to be online. It was.
It guessed a password. It found leaked logins. It got in. Then it saw the systems were real and stopped.
Google says this is not a safety fail. They say the model behaved.
They knew in July. They talked after the Journal asked. OpenAI, Anthropic and Meta already had the same kind of test leak.
The good news, they say: the burglar left after opening the door.
Pick a search box that does not profile you.
Startpage if you want Google-quality results without Google watching the query.
DuckDuckGo if you want a full private engine with optional AI and no account tax.
Kagi if you will pay so the product is you as a customer, not the ad.
SearXNG if you want to host the box yourself and trust no company at all.
The colorful G is not neutral. It is a log. Change it.
Startpage if you want Google-quality results without Google watching the query.
DuckDuckGo if you want a full private engine with optional AI and no account tax.
Kagi if you will pay so the product is you as a customer, not the ad.
SearXNG if you want to host the box yourself and trust no company at all.
The colorful G is not neutral. It is a log. Change it.
๐2
EU Surveillance Laws:
Communications content and metadata
1. Temporary CSAM scanning derogation ("Chat Control 1.0")
Voluntary scanning of unencrypted messages for CSAM. Passed (revived July 2026). In force until April 2028.
2. Regulation to Prevent and Combat Child Sexual Abuse (CSAR / "Chat Control 2.0")
Permanent framework: risk assessments and detection orders. Mandatory encryption scanning stripped from Council position.
Not passed. Trilogues ongoing.
3. ePrivacy Regulation
Proposed update to 2002 ePrivacy Directive. Withdrawn (October 2025).
4. Data Retention Directive 2006/24/EC
EU-wide telecoms metadata retention. Invalidated by CJEU (2014). No replacement exists; national regimes remain.
5. Terrorist Content Online Regulation (EU) 2021/784
One-hour removal orders for terrorist content. Passed. In force since June 2022.
Law-enforcement access to stored data
6. e-Evidence Regulation (EU) 2023/1543 & Directive (EU) 2023/1544
Cross-border production and preservation orders (10 days / 8 hours emergency). Passed. Fully applicable from August 2026.
7. Law Enforcement Directive (EU) 2016/680
Police data-protection rules including biometric data of suspects. Passed (2016).
Travel, borders, identity databases
8. PNR Directive (EU) 2016/681
Airlines transfer passenger records on extra-EU flights to national units. Passed. In force.
9. API Regulation (EU) 2025/13
Central router for Advance Passenger Information and PNR. Passed (December 2024). Live January 2025.
10. Interoperability Regulations (EU) 2019/817 & 2019/818
Common Identity Repository, European Search Portal, Biometric Matching Service, Multiple Identity Detector. Passed (2019). Biometric matching service live May 2025; search portal live June 2026.
11. Entry/Exit System (EES)
Biometric registration (face + fingerprints) of third-country nationals at borders. Passed. Fully deployed across Schengen borders (April 2026).
12. ETIAS
Pre-travel authorisation for visa-exempt nationals, screened against EU databases. Passed. Operational expected Q4 2026.
13. Revised Eurodac
Expanded biometric database (includes children age 6+) for asylum and migration. Passed. Applicable from June 2026.
14. Screening Regulation (EU) 2024/1356
Identity, security, health and biometric checks for irregular arrivals (up to 7 days). Passed. Applicable from June 2026.
15. Prรผm II Regulation (EU) 2024/982
Automated DNA, fingerprint, facial image, vehicle and police record exchange via central router. Passed. Router operational Q2 2027.
Biometrics and AI for identification
16. AI Act (Regulation (EU) 2024/1689)
Prohibits real-time remote biometric ID in public spaces for law enforcement (narrow exceptions allowed). High-risk biometric rules delayed to December 2027.
Passed. Core prohibitions active.
Related instruments
17. European Media Freedom Act (EU) 2024/1083
Restricts spyware against journalists; narrow derogations for serious crimes with judicial authorisation. Passed. Main provisions active from August 2025.
18. EU KIDS Act
Minimum age, age assurance, AI companion rules. Does not require message scanning. Proposed only. Legislative procedure started September 2026.
Communications content and metadata
1. Temporary CSAM scanning derogation ("Chat Control 1.0")
Voluntary scanning of unencrypted messages for CSAM. Passed (revived July 2026). In force until April 2028.
2. Regulation to Prevent and Combat Child Sexual Abuse (CSAR / "Chat Control 2.0")
Permanent framework: risk assessments and detection orders. Mandatory encryption scanning stripped from Council position.
Not passed. Trilogues ongoing.
3. ePrivacy Regulation
Proposed update to 2002 ePrivacy Directive. Withdrawn (October 2025).
4. Data Retention Directive 2006/24/EC
EU-wide telecoms metadata retention. Invalidated by CJEU (2014). No replacement exists; national regimes remain.
5. Terrorist Content Online Regulation (EU) 2021/784
One-hour removal orders for terrorist content. Passed. In force since June 2022.
Law-enforcement access to stored data
6. e-Evidence Regulation (EU) 2023/1543 & Directive (EU) 2023/1544
Cross-border production and preservation orders (10 days / 8 hours emergency). Passed. Fully applicable from August 2026.
7. Law Enforcement Directive (EU) 2016/680
Police data-protection rules including biometric data of suspects. Passed (2016).
Travel, borders, identity databases
8. PNR Directive (EU) 2016/681
Airlines transfer passenger records on extra-EU flights to national units. Passed. In force.
9. API Regulation (EU) 2025/13
Central router for Advance Passenger Information and PNR. Passed (December 2024). Live January 2025.
10. Interoperability Regulations (EU) 2019/817 & 2019/818
Common Identity Repository, European Search Portal, Biometric Matching Service, Multiple Identity Detector. Passed (2019). Biometric matching service live May 2025; search portal live June 2026.
11. Entry/Exit System (EES)
Biometric registration (face + fingerprints) of third-country nationals at borders. Passed. Fully deployed across Schengen borders (April 2026).
12. ETIAS
Pre-travel authorisation for visa-exempt nationals, screened against EU databases. Passed. Operational expected Q4 2026.
13. Revised Eurodac
Expanded biometric database (includes children age 6+) for asylum and migration. Passed. Applicable from June 2026.
14. Screening Regulation (EU) 2024/1356
Identity, security, health and biometric checks for irregular arrivals (up to 7 days). Passed. Applicable from June 2026.
15. Prรผm II Regulation (EU) 2024/982
Automated DNA, fingerprint, facial image, vehicle and police record exchange via central router. Passed. Router operational Q2 2027.
Biometrics and AI for identification
16. AI Act (Regulation (EU) 2024/1689)
Prohibits real-time remote biometric ID in public spaces for law enforcement (narrow exceptions allowed). High-risk biometric rules delayed to December 2027.
Passed. Core prohibitions active.
Related instruments
17. European Media Freedom Act (EU) 2024/1083
Restricts spyware against journalists; narrow derogations for serious crimes with judicial authorisation. Passed. Main provisions active from August 2025.
18. EU KIDS Act
Minimum age, age assurance, AI companion rules. Does not require message scanning. Proposed only. Legislative procedure started September 2026.
โค1
Mozilla just put Mistral inside Firefox.
Smart Window. Optional. They say chats are not stored by default. Mistral signed zero retention. France, US, Canada first.
It is still an AI sitting on your tabs. The difference is the vendor is not Google, and the browser is still one you can fork.
Chrome will ship Gemini as the house brand. Firefox at least picked an open-weight lab and left the switch on.
Use it if you want the helper. Leave it off if you want a browser that only browses.
Source
Smart Window. Optional. They say chats are not stored by default. Mistral signed zero retention. France, US, Canada first.
It is still an AI sitting on your tabs. The difference is the vendor is not Google, and the browser is still one you can fork.
Chrome will ship Gemini as the house brand. Firefox at least picked an open-weight lab and left the switch on.
Use it if you want the helper. Leave it off if you want a browser that only browses.
Source
Signal still wants a number. WhatsApp still sits on Meta iron.
Zerion runs the chat over Tor. No account. No phone. Device to device.
Open source. Post-quantum on every frame, they say. BTC and XMR in a vault on the same box.
It is not the default messenger. That is the point. The default ones already know who you are.
https://zerion.chat/
Zerion runs the chat over Tor. No account. No phone. Device to device.
Open source. Post-quantum on every frame, they say. BTC and XMR in a vault on the same box.
It is not the default messenger. That is the point. The default ones already know who you are.
https://zerion.chat/
Zerion
Zerion - Private Messaging Over Tor
End-to-end encrypted messenger with no phone number, no Zerion servers, and Tor always on. Post-quantum cryptography on every message.
Your robot vacuum is a camera on wheels.
Mic. Lidar map. Cleaning log. On a lot of models a live feed leaves the house.
In Taiwan a husband used the vacuum camera to film an affair. The clip went into the case file.
Fitbit steps. Echo recordings. Pacemaker logs. Courts already take that pile.
Ecovacs units got remotely hijacked with no light that the cam was on. A DJI home robot leak opened live video and mics across thousands of devices. One tester saw a vacuum push the equivalent of 135,000 texts of data in a week.
Audio can fall under the Wiretap Act. Silent video from the same box often walks in as just a file.
You paid for a cleaner. You installed a witness.
Mic. Lidar map. Cleaning log. On a lot of models a live feed leaves the house.
In Taiwan a husband used the vacuum camera to film an affair. The clip went into the case file.
Fitbit steps. Echo recordings. Pacemaker logs. Courts already take that pile.
Ecovacs units got remotely hijacked with no light that the cam was on. A DJI home robot leak opened live video and mics across thousands of devices. One tester saw a vacuum push the equivalent of 135,000 texts of data in a week.
Audio can fall under the Wiretap Act. Silent video from the same box often walks in as just a file.
You paid for a cleaner. You installed a witness.
Three researchers walked into OpenAI through a photo.
HEIF upload on the public forum. Old libheif. Discourse never treated the fix as urgent. Then a broken โlog in with OpenAIโ button turned forum code into staff ChatGPT and Codex.
Codex talks to GitHub. They opened a pull request in the internal monorepo to prove the door was open. They say they did not read the secrets.
The exploit was written with Claude Opus 5. Under $3,000 in tokens. OpenAI paid $6,500.
The lab that sells the lock used the rival model to pick it.
HEIF upload on the public forum. Old libheif. Discourse never treated the fix as urgent. Then a broken โlog in with OpenAIโ button turned forum code into staff ChatGPT and Codex.
Codex talks to GitHub. They opened a pull request in the internal monorepo to prove the door was open. They say they did not read the secrets.
The exploit was written with Claude Opus 5. Under $3,000 in tokens. OpenAI paid $6,500.
The lab that sells the lock used the rival model to pick it.
Malwarebytes
Fake Claude Max giveaway hides a Google account phishing trap
A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.
๐จ BREAKING:
There is no free Claude Max.
Malwarebytes just mapped a fake giveaway. Countdown. Five-star reviews. Anthropic paint. โSign in with Google.โ
That Google window is a picture inside the page. Padlock. Real-looking address. You can even drag it. It is not Google.
Your password goes to the scammer. Gmail, Drive, payments, the lot.
The clock resets when you reload. Apple login is โdownโ on purpose so you pick Google.
Check the real bar at the top of the browser. If your password manager stays silent, walk away.
Nobody is handing you a $200 plan for a login.
https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap
There is no free Claude Max.
Malwarebytes just mapped a fake giveaway. Countdown. Five-star reviews. Anthropic paint. โSign in with Google.โ
That Google window is a picture inside the page. Padlock. Real-looking address. You can even drag it. It is not Google.
Your password goes to the scammer. Gmail, Drive, payments, the lot.
The clock resets when you reload. Apple login is โdownโ on purpose so you pick Google.
Check the real bar at the top of the browser. If your password manager stays silent, walk away.
Nobody is handing you a $200 plan for a login.
https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap
New wrapper for the same chat boxes.
AgentCloak Desktop. Free. Browser or desktop. It swaps names, addresses, account numbers with fake twins before the prompt leaves your machine. ChatGPT, Claude, Gemini, Grok, Copilot, DeepSeek.
Then it puts the real values back in the reply.
That is not โthe model never saw you.โ That is a middle layer you now have to trust instead of OpenAI.
Still better than pasting your ID into the raw box. Still worse than not pasting it at all.
Use it if you refuse to quit the cloud bots. Do not treat a cloak as a vault.
agentcloak.ai
AgentCloak Desktop. Free. Browser or desktop. It swaps names, addresses, account numbers with fake twins before the prompt leaves your machine. ChatGPT, Claude, Gemini, Grok, Copilot, DeepSeek.
Then it puts the real values back in the reply.
That is not โthe model never saw you.โ That is a middle layer you now have to trust instead of OpenAI.
Still better than pasting your ID into the raw box. Still worse than not pasting it at all.
Use it if you refuse to quit the cloud bots. Do not treat a cloak as a vault.
agentcloak.ai
The US is summoning British officials due to a UK law proposal that would require every person, to hand over their ID to every social media.
This is particularly dangerous due to data breaches, identity theft and the possibility for the UK government to know who post what. Potentially becoming a way to control the media.
This is particularly dangerous due to data breaches, identity theft and the possibility for the UK government to know who post what. Potentially becoming a way to control the media.
๐1
Media is too big
VIEW IN TELEGRAM
Claude made a video on western civiization
Major Privacy Concerns and Fines Against Facebook:
โข $1.4 billion to Texas (2024) for collecting millions of users' biometric data through facial recognition without permission
โข โฌ1.2 billion to Ireland DPC (2023) for continuing to transfer EU user data to US servers after the Schrems II ruling
โข $5 billion to FTC (2019) for deceiving users about their ability to control personal information in the Cambridge Analytica scandal
โข โฌ210 million to Facebook and โฌ180 million to Instagram (January 2023) for using contractual necessity instead of obtaining user consent for behavioral advertising
โข $277 million (2022) for data scraping that exposed personal information of 533 million users
โข โฌ91 million (October 2024) for storing Facebook user passwords in plain text
โข โฌ265 million (2022) for data-scraping violations
โข โฌ405 million (2022) for Instagram children's privacy violations
โข โฌ60 million (2022) for cookie consent violations
โข โฌ225 million (October 2021) for WhatsApp privacy policy violations
โข $100 million SEC penalty (2019) for misleading disclosures about risks of misuse of user data
โข $650 million (2020) to Illinois for facial recognition violations of the Illinois Biometric Information Privacy Act
โข $1.4 billion to Texas (2024) for collecting millions of users' biometric data through facial recognition without permission
โข โฌ1.2 billion to Ireland DPC (2023) for continuing to transfer EU user data to US servers after the Schrems II ruling
โข $5 billion to FTC (2019) for deceiving users about their ability to control personal information in the Cambridge Analytica scandal
โข โฌ210 million to Facebook and โฌ180 million to Instagram (January 2023) for using contractual necessity instead of obtaining user consent for behavioral advertising
โข $277 million (2022) for data scraping that exposed personal information of 533 million users
โข โฌ91 million (October 2024) for storing Facebook user passwords in plain text
โข โฌ265 million (2022) for data-scraping violations
โข โฌ405 million (2022) for Instagram children's privacy violations
โข โฌ60 million (2022) for cookie consent violations
โข โฌ225 million (October 2021) for WhatsApp privacy policy violations
โข $100 million SEC penalty (2019) for misleading disclosures about risks of misuse of user data
โข $650 million (2020) to Illinois for facial recognition violations of the Illinois Biometric Information Privacy Act
The Bangalore District Court has included a ChatGPT prompt in its judgment. Reference: http://indiankanoon.org/doc/195524845/