ノーマルビュー

Woman Pulled From Car at Gunpoint By Police After Mistaken Flock Alert - Twice

著者: EditorDavid
2026年8月8日 16:00

🤖 AI Summary

警察が誤って flock ライセンス Plate Reader 技術により犯人として警戒していたと知った後、黒人の女性は木曜日に車から出され、手を挙げて立っていた。ミルウォーキーの警察も月曜日にも同様の行動を取ったが、理由を説明しなかった。女性は traumatized になっており、再び警察に捕まられる恐れがあるため、彼女と娘は車を使うことを避けるようになった。「毎晩眠れない。目を閉じると、銃が頭の中に浮かぶ」。地元の警察は自身の過失ではなくミルウォーキー警署のデータ入力ミスだと主張したが、女性は「全ての人が失敗した」と批判している。
The police surrounded her car Thursday, "drew their guns, and told her to come out with her hands up," reports a local news station. The police thought they were pulling over a murder suspect, but "It turns out it was a mistake by another department with the Flock license plate reader technology." The black woman says she'd wanted to call her mother, "but I'm like, if I make a sudden move, it's going to be over. It's going to end my life." And amazingly, the same thing happened Monday, according to the local news report. "Milwaukee police pulled her over with guns drawn. She says officers never explained why, towed her car, and let her go." She now describes herself as "traumatized," recalling her second detention by police on Thursday. "After they put us in cuffs, they walked us to the car. I'm not knowing what's going on. I'm scared. All you see is people in their cars recording." She now says she's scared to drive her car, and so is her daughter. "Because she doesn't know if the police are going to pull us over and do it again..." "I haven't been to sleep since this happened. Every time I close my eyes, all I can see is guns." She wants an apology, since the local police would only say it wasn't their fault, it was the fault of the Milwaukee police department that failed to remove the alert from Flock's system. "Milwaukee police emphasized this was not a Flock camera issue, it was a data entry mistake," according to the local news report. The woman's response? "Y'all failed. Y'all failed the system. Y'all failed me. Y'all failed everybody."

Read more of this story at Slashdot.

Framework Notifies 'All Customers' of a Data Breach Via Compromised Metabase BI Service

著者: BeauHD
2026年8月8日 04:00

🤖 AI Summary

Framework社は顧客に電子メール通知を送り、Metabase BIサービスのゼロデイ攻撃を通じた限定的なデータ漏洩について警告しました。流出情報には顧客名、メールアドレス、電話番号、住所が含まれます。Frameworkはビジネス向け製品も含む「すべての顧客」に影響があったと説明していますが、具体的な数字は明らかにしていません。

Metabaseは自身のウェブサイトブログで自社が未知のセキュリティ欠陥(ゼロデイ)を使用してハッキングされたことを報告し、攻撃者は顧客のデータベースにアクセスできるようにすることができたと述べています。Frameworkは顧客の個人情報を窃取したものの、支払い情報には及ばなかったと伝えています。

この件に関してFrameworkは調査を進めているが、Framework for Businessユーザーにも影響があったかどうかは未確認です。( BeauHD による)
"Framework has been sending out email notifications to customers alerting of a limited data breach in which customer information was accessed through a Metabase BI service zero-day exploit," writes Slashdot reader DuoDreamer. Data includes customer names, email addresses, phone numbers, and physical addresses. "Framework is investigating whether or not this included Framework for Business customers as well." TechCrunch reports: Framework's spokesperson Eric Schumacher told TechCrunch that the breach affected "all customers," but declined to specify a specific number. Framework computers are relatively niche products, but some estimates say the company sold hundreds of thousands of devices. Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers' databases stored on Metabase's cloud servers. In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework's cloud instance. The computer maker said it investigated the incident and found that hackers had stolen its customers' personal data, but did not include their payment information.

Read more of this story at Slashdot.

'Tower Dump' Warrants Ruled Unconstitutional

著者: BeauHD
2026年8月7日 07:00

🤖 AI Summary

タイトル:「タワー・ダンプ」検索許可証は憲法違反と判決

作者:BeauHD

サマリ:
ミシシッピ州で連邦裁判所が、「タワー・ダンプ」検索許可証を憲法違反として判断しました。これにより、政府が一連の暴力犯罪捜査に関し、法務官から複数の「タワー・ダンプ」検索許可証を求めた事態は逆転しませんでした。「タワー・ダンプ」は特定の基地局に接続された全ての携帯電話の時間と場所データを警察機関に提供することです。

去年、ジャクソン地域でのギャングに関連する犯罪捜査の一環として、警察がこれらの検索許可証を求めたとされましたが、法務官は「タワー・ダンプ」は不適切な一般検索であると判断。地裁も同意しました。判決文では、最高裁判所の最近の判例「チャトリー対米国」が参照されており、地理的範囲検索許可証には憲法上のプライバシー保護が必要との見解が述べられています。

「この情報があれば、政府は全ての潜在的な容疑者を特定できるだろう」と、カルトン・リーヴス判事は30ページの判決文で述べています。「それでもなお、警察は数多くの人々の携帯電話記録にもアクセスすることになる。その大半はただ場所にいただけの人々である。これは第四修正条項違反となる」と結論付けました。
alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations. A "tower dump" involves cellphone companies providing law enforcement with access to the time and location data of all mobile devices connected to specific cell towers during a designated time window. Law enforcement had sought approval for several of these search warrants as part of criminal investigations into gang-related activity in the Jackson, Miss., area last year, arguing the data could help identify all those potentially involved, particularly in incidents with unknown suspects. A magistrate judge denied the applications, holding that "tower dumps" are impermissible general warrants. The district judge agreed. The order repeatedly referenced the Supreme Court's recent decision in Chatrie v United States, in which the majority held that geofence warrants require constitutional privacy protections. "With this information, the Government asserts that it will be able to identify all potential suspects," Judge Carlton Reeves wrote in a 30-page order (PDF). "Even so, law enforcement would also have access to the cellular records of countless individuals, the vast majority of whom were merely passing by a location at the 'wrong' time." "That is an unreasonable search under the Fourth Amendment," the judge concluded.

Read more of this story at Slashdot.

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

著者: BeauHD
2026年8月6日 05:00

🤖 AI Summary

Appleの「プライバシーリレ」がユーザーの実際のIPアドレスを露出している可能性に関するセキュリティ研究者の報告について説明します。研究者Tommy MyskとTalal Haj Bakryは、iCloud Private Relayを使用していても、一部のパスキー関連のリクエストがSafariやそのプロキシ保護機能を绕過していることを発見しました。これにより、ユーザーの実際のIPアドレスが露出される可能性があります。

この問題は、パスキーがWebAuthn標準に基づく安全な代替手段であるにもかかわらず、デバイスからブラウザ外でリクエストを行うため、プライバシーリレの保護を逃れる可能性があるという特異性により引き起こされます。研究者たちは、ユーザーの実際のIPアドレスが漏洩するかどうか確認できるサイトを作成しました。

Appleはこの問題を「重大」と評価し、研究者に公開することを許可しましたが、具体的な解決時期は明かしていません。
Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay. [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal. "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Read more of this story at Slashdot.

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

著者: BeauHD
2026年8月4日 20:00
A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals. A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector. [...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Read more of this story at Slashdot.

Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool

著者: EditorDavid
2026年8月3日 11:05
A woman found her police officer ex-boyfriend had used Flock's camera system 600 times to look up the location of her and her daughter, reports the Washington Post (Alternate URL here). (She found out through Have I Been Flocked, described as "a website that aggregates police search logs made available through public records.") But it turns out dozens more police officers have also misused Flock... Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found. In 26 of these cases, police investigators and prosecutors said the officers used the technology to spy on their wives, their girlfriends, their exes, their exes' new partners or women they wanted to meet. In other cases, police or prosecutors have not specified the alleged surveillance targets. Flock's system was used in 46 of the cases analyzed by The Post, while the other cases involved competing products... After The Post relayed its findings to Flock, the company said in a statement it "will soon be announcing better filters and tools to stop abuse before it happens...." In April, the company rolled out a new voluntary "audit assistance" feature, which agencies can choose to enable, that automatically scans officers' searches for suspicious activity, such as queries repeatedly targeting the same vehicle or run by officers off the clock. In an interview with The Post, Flock chief executive Garrett Langley said misuse of its systems is inevitable and that the company is focused on providing tools to catch perpetrators after the fact... "We're not going to change humans, and humans make bad decisions," Langley said. "What we can do is make sure that they know if you use this tool, you will be held accountable...." Through automated license-plate reader systems, or ALPRs, officers could trace the rhythms and travels of their subjects' daily lives, leading in some instances to violent confrontations, moments of psychological manipulation, and threats of coercion and control, the analysis found. - In Wisconsin, a police officer allegedly used Flock to check whether his ex-girlfriend had gone to an abortion clinic, according to a police affidavit for a case set for trial this month. - In Kansas, a police chief who tracked his ex through Flock sneaked up on her while she was intimate with another man, a state police certification body alleged, leading to his firing. - In Florida, a deputy speeding to stop a young actress he'd added to a watch list for a license-plate tool called Guardian nearly caused a head-on crash, according to a police report and video from his dashboard camera. The deputy was arrested in March, and his attorney declined to comment. - And in California, prosecutors said a former deputy, Alexander Vanny, used Flock as part of a months-long campaign of "stalking" and "humiliating" his former fiancée that also involved following her around town and installing a hidden camera in her roommate's bathroom, according to a sentencing brief... While some of the searches resulted in officers' firings, prosecutions and prison sentences, police departments in other cases allowed officers to continue using the systems even after receiving warnings that they were being misused... An array of privacy advocates has argued that Flock could deter bad actors by making simple changes to its product, such as requiring officers to label every search with a criminal case number. Some policing experts also warned that agencies' inconsistencies in developing and enforcing standard procedures for license-plate readers could lead to further misconduct. With no federal laws governing use and only a patchwork of state laws, many of the country's roughly 18,000 police agencies are left to decide their rules on their own... Langley, Flock's chief, has dismissed pushes by activists for the company to further limit how officers use its product. "No one elected me the police chief of America," he told Forbes last year, adding, "I don't think it's our job to police the police." The Post also got this quote from an officer was fired and sentenced to probation after pleading no contest to charges of computer-system misuse, stalking and battery. "Pretty much everybody uses that computer system" improperly in the department, he said, and "they don't audit it [nearly] as much as they should." Flock told The Post it now has over 120,000 cameras in more than 6,000 communities, recording 20 billion license plate scans every month.

Read more of this story at Slashdot.

❌