ノーマルビュー

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

著者: BeauHD
2026年8月21日 02:05

🤖 AI Summary

クラリティチェックという人物検索サービスのセキュリティ研究者ジェレミア・フォウラーは、同社がアマゾンS3バケットに約900万枚の画像ファイルを公開しており、逆画像検索機能が「プライベートで安全」と宣伝されていましたことを発見しました。フォウラーによると、漏洩したクラリティチェックデータベースには450GBもの画像(主に成人や青少年、子供のプロフィール写真など)が含まれており、これらの画像は公開されているAmazon S3バケット内に未承認で保管されていました。

さらに、クラリティチェックのAPI設定ミスにより、任意の名前を入力することでメールアドレス、住所、電話番号などの情報を取得することができました。クラリティチェックはWIREDが7月に同社を連絡した後、この情報は閉じましたが、フォウラーは問題点を指摘したにもかかわらず、同社との交渉に成功していませんでした。

同社は公開された情報を基にしており、「一般的なパブリックメンバーはそれを見つけ出すことができない」と主張しています。しかし、研究者は「特に不変のバイオメトリックデータ(顔画像など)にとって大きなリスク」だと警告しています。
Security researcher Jeremiah Fowler found that people-search service ClarityCheck left more than 9 million image files accessible in an unsecured Amazon S3 bucket, despite advertising its reverse-image search as "private and secure." A separate misconfiguration also exposed email addresses, phone numbers, and other personal information. Wired reports: Overall, according to findings from independent security researcher Jeremiah Fowler, the exposed ClarityCheck database contained roughly 450 GB of images, including what appeared to be profile images, screenshots, and other photographs of adults, teenagers, and children. All of the images were stored in an unsecured Amazon S3 bucket, with files in folders named "faces" and "profiles," which could be accessed by anyone online through a URL included in the company's publicly available website code. ClarityCheck is one of a number of so-called people-finder tools that have appeared online in recent years. These websites broadly claim to be able to search the web, public records, and other databases to identify individuals. ClarityCheck's website says it can run searches on phone numbers, email addresses, vehicle identification numbers, and names. Its photo-search page says it can help "identify anyone in a photo" and find social media profiles "in seconds." While ClarityCheck secured the giant image database after WIRED contacted the company in July, Fowler warns that it was seemingly exposed for months, and his initial efforts to flag the problem to the company were unsuccessful. Accidental data exposures create risk for any personal information, but particularly for sensitive and unchangeable biometric data like face images. [...] In addition to the face data, ClarityCheck had also misconfigured its APIs such that its website URLs could be manipulated to reveal data about people simply by entering names; anyone using any consumer browser could have done this. Entering a name into one of the URLs would return multiple potential email addresses, physical addresses, and phone numbers for people with that name. After WIRED contacted the company, the URLs were secured. The ClarityCheck spokesperson said in the statement that the details displayed were "sourced from publicly available information and licensed third-party data providers." A spokesperson for ClarityCheck said in a statement: "Once this was drawn to the attention of the appropriate teams, we acted immediately to restrict access." The company disputed any characterization that the data was "exposed," saying that an "ordinary member of the public" would not have come across it. "We do not accept that data in the temporary storage location was 'publicly exposed,' which implies large-scale public access," the spokesperson says. "Access required knowledge of a specific, unindexed URL that was not discoverable through ordinary use of the ClarityCheck service or a general web search."

Read more of this story at Slashdot.

Sainsbury's Store Pauses Facial Recognition After False Shoplifting Claim

著者: BeauHD
2026年8月18日 20:00

🤖 AI Summary

サインスバリーは、ある顧客が誤って窃盗容疑者として特定され強制退去された事例を受け、AIによる顔認識技術の使用を一時停止した。

エドゥリッチに所在する店舗でコメディパーソンのマット・アールトン(46)は、Nectarカードと商品をスキャン後、従業員2名から窃盗疑いを告げられ、退去させられた。その際、天井のCCTVモニターには自身の顔が赤い枠で囲まれた警告が表示された。

アールトンは友人が即座に支払いを行うために待機していることを説明し、買い物を手放さずにいたが、スタッフは慎重な対応を見せず、「店員は瞬時に反応してはいなかったし、窃盗容疑者がこの行動をとるとは考えていなかったようだった」と述べている。

サインスバリー本社はアールトンに謝罪し、AI補助の「Facewatch」技術の使用を一時停止し、調査を行っている。一方でアールトンは、「誰もが誤認される可能性があり、そのうち誰か脆弱な人々や精神的な問題がある人間が影響を受けてしまうのは避けられない」と述べている。

サインスバリー側は「この事案は人間のミスによるものでなく、顔認識技術自体に問題はない」とし、「システムが誤ってアラートを出した後でもその後の対応に人が誤りを犯しただけだ」としている。
Bruce66423 shares a report from The Guardian: Sainsbury's has paused the use of AI face scanning in one of its stores after a customer was wrongly identified as a shoplifter and ejected from the shop. "I was embarrassed, mortified even, and felt quite humiliated and powerless," Matt Arnold, 46, said of his ordeal. The comedy promoter was buying supplies in the store in East Dulwich, in south-east London, for a standup event at Dulwich Hamlet football club when, after scanning his items and a Nectar card, he was approached by two managers who told him he could not be served owing to an earlier incident. He was then asked to leave and they tried to escort him from the store. As he left, he saw an overhead CCTV monitor alert with a red circle surrounding his face. He asked the shop staff to keep his shopping in the trolley so his friend could come and pick up the supplies for the comedy night happening soon next door. "I think they were quite confused by this, understandably, but agreed and my colleague Dave went in to pay for and pick up the shop about five minutes later. There was no pause for thought from the staff, no suggestion that they understood this is not how a shoplifter would behave. Just blindly following the machine's orders." Sainsbury's head office apologised to Arnold the next day and has paused use of its AI-assisted Facewatch technology in the store while an investigation takes place. Arnold says the facial recognition tech should be paused in all stores. "Anyone could be falsely accused and at some point that will be someone vulnerable, someone with mental health issues like anxiety. It's inevitable," said Arnold. "Also, I would worry about the confidence-destroying effect of it happening to a younger person or someone less willing or able to stand up for themselves as I have done." A Sainsbury's spokesperson said: "We have contacted Mr Arnold to apologise for his experience at our Dulwich superstore. The incident was caused by human error, not the facial recognition technology. Customers can be reassured that the Facewatch system has a 99.98% accuracy rate, and every match is reviewed by a trained manager." A Facewatch spokesperson said their technology was not at fault in this case. "A correct alert was sent to the retailer, but was subsequently subject to human error in the way it was handled in store," they said.

Read more of this story at Slashdot.

OpenAI Ditches Recall-Style Screenshot Surveillance For Friendly Keylogging

著者: BeauHD
2026年8月18日 00:00

🤖 AI Summary

OpenAIは、以前のスクリーンショット監視方式から、「Computer History」という友好的なキーロギングシステムに切り替えた。この機能はユーザーがアプリやウェブサイトでの操作を記録し、時系列で整理できるようにするものだ。これはChatGPT応答の改善や自動化の機会の発見、作業の継続性の向上を目的としている。

OpenAIのドキュメンテーションによると、「Computer History」は許可されたアプリとウェブサイトからの入力イベントから相互作用のストリームを作成する。これらのイベントにはクリック、タイピング、キーボードショートカット、アプリの切り替え、macOSのアクセシビリティシステムを通じて公開されるコンテキストが含まれる。48時間(またはそれ以上)にわたり、このデータはローカルで未暗号化で保管され、その後OpenAIのサーバーに転送される。

ただし、OpenAIは警告を掲載しており、「Computer Historyファイルには機密情報が含まれている可能性があります。これらは「Computer History」によって暗号化されておらず、他のユーザーが実行しているプログラムによってアクセスされる可能性がある」と述べている。

この機能を使用する際は、個人的な会話中には使用を停止し、本人の明示的同意を得る必要があるとOpenAIは注意を促す。また、医療情報や財務情報を含むアプリについては一時的に停止または除外することも検討されるべきだ。

ChatGPTとCodexはローカルに保存された「Computer History」の相互作用イベントを48時間後まで保持し削除するが、OpenAI側では生成された記憶データは長期保存され、将来的なチャットで再利用される可能性がある。
An anonymous reader quotes a report from The Register: If you want to record whatever you do on a computer, send those records to OpenAI, use more ChatGPT tokens, and increase your vulnerability to prompt injection, then OpenAI has something for you. It's called Computer History, an opt-in way to record your computer interactions across apps and websites as memories organized on a timeline. Why would you want to do so? Maybe you found Chronicle, the predecessor of Computer History which compiled similar histories using screenshots, a bit too intrusive but don't mind Computer History's approach -- recording input events and storing them unencrypted locally for 48 hours (or more), with a brief visit to OpenAI's servers. Maybe you're not bothered by the warning OpenAI includes in its documentation: "Computer History files can contain sensitive information. They are not encrypted by Computer History, and other programs running as your macOS user may be able to access them." Perhaps, having given OpenAI's Codex and GPT Work the run of your computer, you're already sold on the suggestion that storing your computer activity in memory files and arranging those interactions in a timeline will improve ChatGPT responses, surface opportunities for automation, and make it easier to resume prior work. Computer History is, to put it bluntly, a keylogging and event capture system. "Computer History creates an interaction-event stream from allowed apps and websites," OpenAI's documentation explains. "Events can include clicks, typing, keyboard shortcuts, app switches, and context that macOS exposes through its accessibility system. Computer History periodically turns these events into text summaries and local memory files." OpenAI says the feature doesn't capture screen images, microphone input, or system audio. It also doesn't record private-mode browsing. "Turn it off during communications with other people unless you have their prior express consent," the company advises, perhaps in acknowledgement of legal risk. "Consider pausing it or excluding apps that contain sensitive health, financial, or personal information." ChatGPT and Codex delete locally stored Computer History interaction events after 48 hours, but data sent to OpenAI to generate memories may be retained locally longer and reused in future chats.

Read more of this story at Slashdot.

Bipartisan 'Uprising' Against Flock Cameras: a Larger Fight Against Big Tech and Surveillance?

著者: EditorDavid
2026年8月17日 12:04

🤖 AI Summary

文章はFlockカメラの撤廃がアメリカ合衆国の多くの地域で進展し、これは政治家とテクノロジー寡占企業に対するより大きな反抗の前兆だと述べています。

主要なポイントは以下の通りです:

1. 超党派的な反対:20以上の地方自治体が7月にFlockカメラを使用停止またはその手続きを開始しました。これはデフロックという活動家のグループによって追跡されており、2021年以来最多の撤廃数です。

2. 公共安全に対する不信:一部の地方行政官は、「公共安全への貢献は期待ほどではなかった。実用性から見ても有用だったとは言えない」と述べています。

3. 高度な人工知能とデータセンター建設に続く技術革命の反対運動:Flockカメラは、テクノロジー企業による監視国家化への懸念を象徴すると指摘されています。また、これにより市民が反抗の手段を見出すことができる可能性も示唆されています。

4. 東電フロンティア基金会の10か月間の調査:地元警察がFlockカメラを使用して反対集会参加者を追跡し、その情報を全国的に共有していることが明らかになりました。

5. 公衆に対する反抗:デストローズは「Flockカメラ反乱」は公衆理解の一環であり、テクノロジー企業の支配を阻止するための動きだと説明しています。また、「猫とマウスゲーム」が市民の関心を集めるようになっています。

これらの点から、この運動は単なるFlockカメラへの不満ではなく、より広範なテクノロジー企業に対する批判に代表される公共の反抗を示唆しています。
Politico notes that over 20 local jurisdictions in America "either stopped using Flock cameras or began the process of doing so in July, according to a tracker maintained by DeFlock, an activist group that has been mapping the company. It's the highest amount in a single month since they began tracking in 2021." Some local officials said the public safety promises weren't worth the cost. The cameras "didn't help us with anything. From a utility aspect, they were just kind of not useful," said Eric Couture, a Democratic first selectman in Killingworth, Connecticut, another city that recently canceled its contract with Flock. "I'd say it was a net negative." And their article adds that it's a bipartisan pushback that "runs parallel to sprawling fights over the future of technology in American life, including the rise of increasingly advanced artificial intelligence tools and the construction of massive data centers needed to power them." Salon even argues Flock's cameras "have become a symbol of growing anger over the efforts by technology oligarchs to impose their dystopian fantasies on the country, replacing liberal democracy with a surveillance state... People are sick of tech billionaires trying to control our lives"" By targeting Flock cameras, activists are building momentum for a larger rebellion against the tech industry — and against political leaders who are complicit in their assault on our freedoms. Flock Safety embodies the dishonesty that has been the prevailing theme of tech corporate communications and marketing for at least the past decade. While the cameras are sold to the public as a banal traffic safety measure, they have prompted an outpouring of stories about how they're being used to violate civil liberties and undermine democracy... According to an exhaustive 10-month analysis by Electronic Foundation Frontier, a nonprofit dedicated to defending civil liberties in our digital age, local police were using the cameras to track protesters, such as those at No Kings rallies, who were then put in a national database to be used across all jurisdictions. Despite claims that the cameras only record license plates, the technology-focused outlet 404 Media found that the database is also being used to collect information on individual people whom cops can then search for using descriptions of clothing, race, gender and body type. The Flock uprising, though, is the stirrings of public understanding that none of this inevitable — and we have the right to fight back... Along with protests against data centers, it's a sign that the public is desperate for a way to fight back against not just AI, but also the anti-democratic forces fueling this latest tech wave. Salon's writer also adds that "what stands out about the burgeoning public rebellion against Flock security cameras is just how fun it all is," citing "a national cat-and-mouse game between vandals and cops that is being merrily followed on social media, mostly by people rooting for the vandals." City council meetings in which citizens swarm to protest paying for the cameras are the new must-see TV. In Huntington, West Virginia, a small city in the heart of Appalachia, one man became an internet folk hero when he stood up at a city council meeting and said, "I'm not gonna waste your time; I'm kinda hungry. But one last thing: Every single Flock camera has about 2-3 pounds of copper and about 1-2 grams of gold. Do with that information what you will." He then walked off in triumph.

Read more of this story at Slashdot.

How Accurate Are Flock's AI-Powered License-Reading Cameras?

著者: EditorDavid
2026年8月10日 16:34

🤖 AI Summary

### FlockのAI活用型車両認証カメラの精度について

Futurismは、404 MediaがLos Angeles Police Department(LAPD)の警備員監視官事務局によって実施された7月10日の検査で発見された結果を報じている。ALPR(Automatic License Plate Recognition)カメラは2ヶ月間で161件の「盗難車両」誤通知を出し、その大半が無辜な運転者に注意を引き起こしている。LAPDの誤通知率は32.3%であり、警備員は3回の検索のうち1回目が無罪の運転者に対するチェックになる。

FlockのCEO Garrett Langleyは、NCIC(FBIのNational Crime Information Center)の古びた構造を批判している。Langleyによると、NCICにはフィードバックループメカニズムがないため、静的なカンマ区切りファイルの形式しかないという。Flockでは「抑制」機能を使用し、例えばアトランタのような地域は特定の州の盗難車両の警報を一年間無効化できるが、他機関を強制する手段はない。

Roseville(カリフォルニア)での最悪事例では、Flockのカメラが同一台の車に6回誤通知し、盗まれた車両や犯罪現場とされた。Flockのソフトウェアは運転者のナンバープレート上の「9」を間違って「8」と認識した。警察当局はドライバーがナンバープレートカバーを外すことを提案した。

Flockのカメラは最適な状況でも車両番号の96%以上を正しく読み取れるという主張があるが、ローズビル警察署の記録によると、71%以上の通知が誤認識であり、映像は曇っていて、ナンバープレートや州名が誤って認識されている。警備局は、カメラ設置の特殊性と古いハードウェアを使用したことにより誤認識が増えた。

トーラード(オハイオ)での例では、ドライバーのブランダン・アップチャーチが車両番号「7」を「2」と誤認識され、警備犬に噛まれて重傷を負い、職を失った。彼は警備局と警察官を相手に35,000ドルの訴訟で和解した。

IPVM(独立研究機関)がFlockのナンバープレート読み取りシステムのテスト結果によると、10回の読み取りのうち約1回が州名誤認識し、車両タイプやメーカーも間違えることが多かった。これらの不正はFlockがIPVMの購入を停止したことに繋がった。

この記事はFlockのAI活用型カメラの精度についての懸念と課題を浮き彫りにし、警備員と運転者双方への影響を示している。
Futurism reports: 404 Media revealed that a July 10 audit by the Los Angeles Police Department Office of the Inspector General caught the department's ALPR cameras generating 161 false stolen-vehicle alerts in just two months — each one ending with officers pulling over an innocent driver. Factoring in 337 alerts which "resulted in the recovery of stolen vehicles," the LAPD's cameras carry an error rate of 32.3 percent, effectively giving officers a one-in-three chance at pulling an innocent person over. "The biggest issue remains this national database at the FBI called NCIC," Flock's CEO Garrett Langley recently told The Drive, complaining about "how archaic its structure is." Flock CEO: There's no feedback loop mechanisms; it's really just a static comma-separated file. We've tried to build around it. We have this concept called "suppression." A local agency — let's take Atlanta, where I live — might see that there's a stolen plate out of California, but it's already been resolved because it's a rental car or a dealer car. They can, in Flock, suppress that: "Never alert us on that for the next year." That's to get around the fact that they can't force another agency to remove it from NCIC. Ideally, the way it would work is if enough agencies — let's call it one, two, or three — flag a tag as no longer valid or a bad entry, it should just get removed. Or at least it should get pushed more aggressively by the FBI... I'm hopeful that they'll see there's an opportunity to make something like NCIC, which is an important tool not just for companies like Flock, but for police departments to work together, start to make some enhancements to modernize what's a central part of our policing system. Later in the interview he says "It's less than one in a million alerts that an officer says, 'I'm not sure if that's right.' Less than one in a million." A recent report from Business Insider shares a worst-case scenario. In the summer of 2024 a Sacramento police officer said Flock's cameras had sent six false alerts for the same vehicle, wrongly saying it had been stolen or used in a felony crime in the nearby suburb of Roseville: Roseville police could see that Flock's software kept confusing the "9" on the man's license plate for an "8." The car owner said he would take off his license plate cover. Soon after, it happened again. It's "easier at this point we have it memorized," a dispatch supervisor in Roseville wrote in an email to a colleague. Flock says that in optimal conditions, its cameras accurately read more than 96% of license plate characters. Hundreds of pages of records from the Roseville Police Department show a different picture. In 2023 and 2024, Flock sent 1,427 alerts to Roseville police, flagging vehicles as stolen or used in a felony after they passed one of the city's Flock cameras. An analysis by the police department found that in 71% of those alerts, Flock's machine-learning software incorrectly read the license plates... The cameras regularly missed vehicles, captured blurry images, misread license plate characters and states, and sent delayed alerts to police about vehicles possibly connected to crimes, the records show... A factor that contributed to the misread problems in Roseville was the "particularly unique deployment" that the city requested, a Flock spokeswoman said. Roseville said it has its cameras configured so that they capture only the backs of vehicles, a setup intended to avoid capturing personally identifiable information like faces. Roseville's setup included older hardware and placement of cameras higher and further from vehicles than the company typically recommends, Flock added... In Toledo, Ohio, driver Brandon Upchurch was mauled by a police dog after a Flock camera misread the "7" on his license plate as a "2." As a result of his injuries, he said, he lost his job and was evicted from his home. He settled a lawsuit against the city and police officer for $35,000. None of the incorrect Flock alerts in Roseville resulted in a traffic stop or arrest, a department spokesman said. Roseville requires police officers to verify that a license plate is stolen or have independent reasonable suspicion of a crime before making a traffic stop... Flock said Roseville's camera performance has significantly improved, which the police department disputed... Flock's cameras also missed vehicles altogether... At one point, Flock's product director for machine learning suggested that officers ask drivers to remove license plate frames that made it "very difficult for the machine vision to tell it is actually a 'E' and not an 'F.'" Roseville told Flock at the time that it wouldn't do so, according to the department spokesman. Flock in 2024 shared an analysis with Roseville's police department, outlining reasons for the misreads. Vehicles far from a camera were sometimes blurry. Plates were cut off by trees or license plate frames. And Flock's software confused similar characters, mistaking an "N" for a "V", or a "1" for a "4...." Roseville isn't the first organization to flag inaccuracies in Flock's technology. In 2021, the research firm IPVM independently tested Flock's license plate readers, concluding that Flock misidentified the state in about one of 10 reads, and that the system regularly misclassified vehicles' type and make. IPVM said that Flock subsequently blocked it from purchasing its cameras for testing. Thanks to long-time Slashdot reader Cognitive Dissident for sharing the article.

Read more of this story at Slashdot.

Privacy Backlash Explodes Against Meta's Smart Glasses

著者: EditorDavid
2026年8月10日 10:59

🤖 AI Summary

Metaのスマートグラスが70%以上の市場占有率を持つ一方で、プライバシー関連の批判が高まっています。一部の人々はこれらのガラスを使って他人を無断で録画し、SNSに共有しています。特に女性に対して行われているという報告があります。これらの行動により、人々はジムや性行為中でも無防備に撮影される可能性があると警戒しており、Metaはプライバシー関連の懸念に対応するためのアップデートを実施しました。

さらに、SNSでの動画投稿やコメディアンによる批判、「5ポイントカフェ」のようなビジネスからの禁止措置などにより、スマートグラスに対する不安が拡大しています。インスタグラムは、そのようなハラスメント違反の投稿を取り下げています。

プライバシーアプリケーションも人気を得ており、160万ダウンロード以上の利用があります。このアプリ作成者は、「個人のプライバシーを重視しない社会」「私たちは他人を利用するために正当化する」と指摘しています。また、アメリカ市民権連盟はMetaに対して顔認証機能をスマートグラスから削除することを求めていますが、Metaからは「最終決定はまだない」という回答でした。
With nearly 70% of the market, "Meta wants its smart glasses to be a big hit," writes the Los Angeles Times. But after some users found ways to disable the light that warns people they're being filmed, "the high-tech specs have also turned into a liability, as some are calling the gadget 'pervert glasses...'" Some people are using the glasses — which look like a pair of regular spectacles — to record people without their knowledge and publish the videos on social media. The users secretly videotape and share what happens when they try to pick up women. Now, a growing number of people are worried they could be covertly recorded at the gym or even during sex. The backlash has prompted Meta to update its glasses to address privacy concerns, and some places have banned them, adding to the angst surrounding technology that's rapidly evolving... Concern about the glasses has exploded as more videos of interactions with people who don't know they're being recorded go viral on social media. On Instagram, some videos depict people getting approached in malls and grocery stores and on college campuses and sidewalks. While the videos are portrayed as jokes, the people filmed don't appear to know they're being recorded and sometimes seem uncomfortable, telling the strangers to leave them alone or stop harassing them. The outcry has spread beyond social media, with comedian Jimmy Kimmel calling the Meta devices "pervert glasses" on national television and singer Lorde telling concertgoers that smart glasses are "not sexy..." Instagram, which is owned by Meta, has been disabling accounts and taking down some of these pickup or prank videos for violating the platform's rules against harassment and bullying... Businesses are making their own calls about smart glasses. The 5 Point Cafe in Seattle, which banned Google Glass in the past, has banned Meta glasses from its diner and dive bar. "Leave your Meta-SpyBan Display at home, they are officially Ray-Ban-ned from all of our restaurants. We serve privacy, not side-eye surveillance," a 2025 Instagram post from the business states. An Android app that warns people if they're being recorded has roughly 110,000 downloads in the last six months, according to the article. The app's creator says it's a "social problem" that "we don't value privacy, that we feel entitled to use others for our entertainment or our private gain, and technology amplifies that." The American Civil Liberties Union and more than 70 organizations even sent a letter urging Meta to promise they'd leave facial recognition features out of their smart glasses, according to the article. But a Meta spokesperson said "no final decision has been made."

Read more of this story at Slashdot.

Flock Camera Vandalism Continues Around America, While 100 Communities Reject ALPRs

著者: EditorDavid
2026年8月9日 20:34

🤖 AI Summary

記事は米国各地でフロックカメラの破壊行為が続けられている一方、100以上のコミュニティが自動車登録 Plates 認識システム(ALPRs)を拒否していることを伝えています。具体的な事例として、テキサス州ダラスやユタ州、ミネソタ州ウィノナなどでのカメラの破壊、そしてウェストバージニア州で逮捕された20歳の男性によるフロックカメラへの複数の破損事件が紹介されています。これらの事例は、米国全体で広がっているフロックカメラに対する反感を示しています。

一方で、アリゾナ州の sherif は自動車登録 Plates 認識システムの使用を見送り、市民の日常生活に関する詳細なデータ収集につながる可能性があると指摘しました。さらに、一部の住民は AI 技術を利用して政府官僚や家族の動向を監視する計画を持ち出したとも報告されています。

記事はまた、フロックシステムの導入を推進する都市と禁止しようとする都市との間で行われている「静かな戦争」についても言及しています。これは政府の責任性に対する懸念が背景にあると考えられます。
Dozens of Flock cameras have been vandalized around Dallas Texas in the last six months, reports a local news station. In Utah, ABC News reports, a county sheriff's office even said Wednesday a Flock camera was even vandalized within days of its being installed. And in the Minnesota city of Winona, "Every Flock license plate reader camera operated by the Winona Police Department has been sawed off and stolen in what investigators believe was a coordinated theft," according to local media: All eight cameras were taken August 1, according to the Winona Police Department. A patrol officer first noticed the cameras had not sent any alerts in 24 hours. When officers checked the locations, they found the cameras had been cut from their poles and taken. The poles were left behind. Two additional Flock cameras on the Mississippi River Bridge, owned by Buffalo County, were also stolen in the same manner... The thefts are part of a broader national trend. Flock cameras have been vandalized and cut down in communities across the country. When someone in Florida filmed a damaged Flock camera lying in the grass in Florida, their footage attracted 980,000 views on social media, according to a local news report, with the uploader saying "Most of the people that are commenting are against Flock cameras." But that report adds it's one of at least five cameras recently damaged just in Florida: - In another incident, investigators "found the black camera and its pole lying on the ground." - Two days later, sheriff's deputies found a camera destroyed "with pieces scattered on the ground. Deputies reported the damage appeared to have been caused by a blunt object." - On July 31, "Police said two camera poles had been intentionally cut in half, causing an estimated $10,000 in damage to the system." In West Virginia 20-year-old Wesley Jackson has been arrested for allegedly vandalizing Flock cameras, with another 20-year-old (a university student) now arrested for being his accomplice, according to a local news report. Ironically, Jackson's arrest was made possible partly by information from... automated license plate readers. But the Washington Post notes there's now a flood of Facebook commenters jokingly offering to provide a fake alibi: "Couldn't have been him — we were out counting blades of grass," said one of the 29,000 commenters on a post about the arrest from the local news station WDTV. Others attested that the man, Wesley Jackson, had been helping them "replace the roof on a homeless shelter," "playing halo 2," "changing the tires" on their car or giving their "doggie a treat" at the time the cameras were destroyed. Meanwhile, the anti-surveillance group DeFlock reports 100 communities have now rejected automated license plate readers. Wednesday an Arizona county sheriff explained to his local Board of Supervisors why he will not renew his office's contract with Flock when it expires next month. Local Arizona media reports: "We have a camera system that can do facial recognition technology and can start building a data set on what our citizens are doing on a day-to-day basis," Teeple told supervisors. "That, in my training and experience, is a huge Fourth Amendment violation." Recently an Arizona man even told his city council he'd be launching AI-powered satellites to monitor "where government officials go, where they stop, who they meet with, and when they return home," reports 404 Media: It would be no different than how the city monitors its citizens using Flock cameras, he said... He said he'd already started compiling profiles on their vehicles, spouses vehicles, children's vehicles, and planned to combine that data with Bluetooth signals, advertising IDs, and commercial data sources, "so our authorized users can replay the movements of every government official and their immediate family," he said. Local businesses would be invited to join the network, to "protect" officials while they shop, eat at restaurants, and move around the city. And CNET reports "a quiet battle is happening across the US" between "towns working to adopt Flock Safety systems and those trying to ban them entirely." From major cities like Los Angeles canceling its Flock contract to towns wrapping Flock AI cams in plastic bags because Flock won't take them down, it's a wild time for surveillance and questions about government accountability.

Read more of this story at Slashdot.

Woman Pulled From Car at Gunpoint By Police After Mistaken Flock Alert - Twice

著者: EditorDavid
2026年8月8日 16:00

🤖 AI Summary

警察が誤って flock ライセンス Plate Reader 技術の警告を受け取った結果、黒人女性が金曜日に車から拉致され、拳銃を抜き命を脅かされました。この件は週に二度起きました。最初の出来事ではミルウォーキー警察が彼女を強制的に車から降りさせ、車両は Tow 被収容しましたが、理由も説明されず放って去了りました。

女性は「トラウマ」になり、睡眠障害を抱えています。再び拉致される恐れがあると理解した彼女の娘も同じような不安を感じています。地元の警察は「これは flock カメラ自体の問題ではなく、データ入力ミスによるもの」と述べたものの、女性は「皆が失敗した」と反論しました。

この事件は flock のシステムを使用する際のデータ管理上の課題を浮き彫りにし、その安全性に対する懸念を強調しています。
The police surrounded her car Thursday, "drew their guns, and told her to come out with her hands up," reports a local news station. The police thought they were pulling over a murder suspect, but "It turns out it was a mistake by another department with the Flock license plate reader technology." The black woman says she'd wanted to call her mother, "but I'm like, if I make a sudden move, it's going to be over. It's going to end my life." And amazingly, the same thing happened Monday, according to the local news report. "Milwaukee police pulled her over with guns drawn. She says officers never explained why, towed her car, and let her go." She now describes herself as "traumatized," recalling her second detention by police on Thursday. "After they put us in cuffs, they walked us to the car. I'm not knowing what's going on. I'm scared. All you see is people in their cars recording." She now says she's scared to drive her car, and so is her daughter. "Because she doesn't know if the police are going to pull us over and do it again..." "I haven't been to sleep since this happened. Every time I close my eyes, all I can see is guns." She wants an apology, since the local police would only say it wasn't their fault, it was the fault of the Milwaukee police department that failed to remove the alert from Flock's system. "Milwaukee police emphasized this was not a Flock camera issue, it was a data entry mistake," according to the local news report. The woman's response? "Y'all failed. Y'all failed the system. Y'all failed me. Y'all failed everybody."

Read more of this story at Slashdot.

Framework Notifies 'All Customers' of a Data Breach Via Compromised Metabase BI Service

著者: BeauHD
2026年8月8日 04:00

🤖 AI Summary

フレームワークは、メタベースのBIサービスを通じたゼロデイ攻撃による限定的なデータ漏洩を顧客に通知しています。通知された情報には、顧客名、メールアドレス、電話番号、住所が含まれています。メタベースは自身もハッキングされ、未知のセキュリティ欠陥(ゼロデイ)を使って顧客のデータベースへのアクセスを得たと報告しました。フレームワークは、この事件にビジネス向け製品の顧客も含むか調査中です。会社側は、「すべての顧客」が影響を受けると発表していますが、具体的な数字を明示していません。

フレームワークのエリック・シュマイチャー報道官はテクノクロスに対し、データ漏洩に至るまでの詳細を拒否しました。メタベースの公式的ウェブサイトで公開されたブログでは、「フレームワークのクラウドインスタンスがハッカーによってアクセスされた」と報告されています。フレームワークは自社調査を行い、顧客の個人情報は漏えいしたものの、支払い情報には該当しなかったと述べています。

この事件は、フレームワークという比較的小規模な製品だが、約10万台を販売しているとの推定もあります。
"Framework has been sending out email notifications to customers alerting of a limited data breach in which customer information was accessed through a Metabase BI service zero-day exploit," writes Slashdot reader DuoDreamer. Data includes customer names, email addresses, phone numbers, and physical addresses. "Framework is investigating whether or not this included Framework for Business customers as well." TechCrunch reports: Framework's spokesperson Eric Schumacher told TechCrunch that the breach affected "all customers," but declined to specify a specific number. Framework computers are relatively niche products, but some estimates say the company sold hundreds of thousands of devices. Metabase disclosed its own breach in a blog post on its official website, where it said that it was hacked by someone using an unknown security flaw, a so-called zero-day. The company said the hackers exploited the bug to give them the ability to access customers' databases stored on Metabase's cloud servers. In its email to customers, Framework also included the email Metabase sent to the company, which says hackers accessed Framework's cloud instance. The computer maker said it investigated the incident and found that hackers had stolen its customers' personal data, but did not include their payment information.

Read more of this story at Slashdot.

'Tower Dump' Warrants Ruled Unconstitutional

著者: BeauHD
2026年8月7日 07:00

🤖 AI Summary

タイトル:「タワー・ダンプ」検索許可証は憲法違反と判決

作者:BeauHD

サマリ:
ミシシッピ州で連邦裁判所が、「タワー・ダンプ」検索許可証を憲法違反として判断しました。これにより、政府が一連の暴力犯罪捜査に関し、法務官から複数の「タワー・ダンプ」検索許可証を求めた事態は逆転しませんでした。「タワー・ダンプ」は特定の基地局に接続された全ての携帯電話の時間と場所データを警察機関に提供することです。

去年、ジャクソン地域でのギャングに関連する犯罪捜査の一環として、警察がこれらの検索許可証を求めたとされましたが、法務官は「タワー・ダンプ」は不適切な一般検索であると判断。地裁も同意しました。判決文では、最高裁判所の最近の判例「チャトリー対米国」が参照されており、地理的範囲検索許可証には憲法上のプライバシー保護が必要との見解が述べられています。

「この情報があれば、政府は全ての潜在的な容疑者を特定できるだろう」と、カルトン・リーヴス判事は30ページの判決文で述べています。「それでもなお、警察は数多くの人々の携帯電話記録にもアクセスすることになる。その大半はただ場所にいただけの人々である。これは第四修正条項違反となる」と結論付けました。
alternative_right shares a report from The Hill: A federal judge in Mississippi ruled Wednesday that "tower dump" warrants are unconstitutional, declining to reverse a lower court decision refusing the government's request to obtain the search warrants in a series of violent crime investigations. A "tower dump" involves cellphone companies providing law enforcement with access to the time and location data of all mobile devices connected to specific cell towers during a designated time window. Law enforcement had sought approval for several of these search warrants as part of criminal investigations into gang-related activity in the Jackson, Miss., area last year, arguing the data could help identify all those potentially involved, particularly in incidents with unknown suspects. A magistrate judge denied the applications, holding that "tower dumps" are impermissible general warrants. The district judge agreed. The order repeatedly referenced the Supreme Court's recent decision in Chatrie v United States, in which the majority held that geofence warrants require constitutional privacy protections. "With this information, the Government asserts that it will be able to identify all potential suspects," Judge Carlton Reeves wrote in a 30-page order (PDF). "Even so, law enforcement would also have access to the cellular records of countless individuals, the vast majority of whom were merely passing by a location at the 'wrong' time." "That is an unreasonable search under the Fourth Amendment," the judge concluded.

Read more of this story at Slashdot.

Apple's 'Private Relay' Is Exposing Users' Real IP Addresses

著者: BeauHD
2026年8月6日 05:00

🤖 AI Summary

Appleの「プライバシーリレ」がユーザーの実際のIPアドレスを露出している可能性に関するセキュリティ研究者の報告について説明します。研究者Tommy MyskとTalal Haj Bakryは、iCloud Private Relayを使用していても、一部のパスキー関連のリクエストがSafariやそのプロキシ保護機能を绕過していることを発見しました。これにより、ユーザーの実際のIPアドレスが露出される可能性があります。

この問題は、パスキーがWebAuthn標準に基づく安全な代替手段であるにもかかわらず、デバイスからブラウザ外でリクエストを行うため、プライバシーリレの保護を逃れる可能性があるという特異性により引き起こされます。研究者たちは、ユーザーの実際のIPアドレスが漏洩するかどうか確認できるサイトを作成しました。

Appleはこの問題を「重大」と評価し、研究者に公開することを許可しましたが、具体的な解決時期は明かしていません。
Security researchers found that Apple's iCloud Private Relay can expose users' real IP addresses because some passkey-related requests bypass Safari and its proxy protections at the operating-system level. "In short: any website that supports, or pretends to support, passkeys can see the user's real IP address despite having iCloud Private Relay on," security researcher Tommy Mysk, who discovered the issue along with Talal Haj Bakry, told 404 Media. The flaws also affect OnionBrowser, an iOS app for browsing the web through the Tor anonymity network. It does not, however, impact the official Tor Browser itself. From the report: The researchers developed a site that lets Private Relay users check if the issues impact them. In 404 Media's tests, the site did return the real IP address of a user that was supposed to be protected by Private Relay. [...] In a quirk of how passkeys work -- a broadly secure alternative to usernames and passwords which use the WebAuthn standard -- a user's device makes a web request outside of the browser itself. Meaning, that request essentially bypasses Private Relay and exposes a user's real IP address, even though to them it may look like they are simply interacting with a website as normal. "Because the fetch is issued by the operating system's credential service rather than by Safari, it never enters Private Relay's proxied path. The destination server sees the device's real IP address either way," the researchers write in their research. [...] "We have already informed them. They said the issue was âdire,' but they let us disclose the issue. They didn't provide any time when they will address this," Mysk said.

Read more of this story at Slashdot.

Russia-Linked 'Midnight Blizzard' Group Hijacks Hotel Wi-Fi With CaptiveCrunch

著者: BeauHD
2026年8月4日 20:00
A Russia-linked group tracked as Midnight Blizzard has compromised hotel and conference Wi-Fi portals worldwide, redirecting guests to phishing pages and fake software updates that steal credentials, session tokens, and other sensitive data. Microsoft says the campaign, dubbed CaptiveCrunch, "targets traveling employees generally rather than a particular sector," reports iTNews. From the report: Midnight Blizzard, tracked internally by Microsoft under its earlier codename NOBELIUM, is attributed by the US and UK governments to Russia's SVR (Sluzhba Vneshney Razvedki) foreign intelligence service. Microsoft's technical analysis said compromises occurred in "several countries" without naming them, and it did not give a total number of affected venues, organisations or individuals. A related investigation published earlier in July by security firm ReliaQuest, and which Microsoft cited in its report, found compromised captive portal gateways across multiple United States cities as well as in India and Saudi Arabia, mostly at hotels. ReliaQuest said the traffic it observed came from organizations across financial services, professional services, legal, health care, energy and retail, suggesting the campaign targets traveling employees generally rather than a particular sector. [...] Where attackers gained a foothold, Microsoft said they deployed two main tools: CornFlake, a Windows remote access trojan (RAT) written in Go capable of keylogging, screenshot and webcam capture, audio surveillance and credential and session token theft. They would also drop ChocoShell, an in-memory PowerShell infostealer targeting browser cookies, saved passwords, Microsoft 365 single sign-on (SSO) tokens and wi-fi credentials. Microsoft also said it has seen indications the attackers might be targeting Android devices with similar prompts urging victims to download and install an APK file.

Read more of this story at Slashdot.

Rogue Police Officers Have Turned Flock's Nationwide Camera Network Into a Stalking Tool

著者: EditorDavid
2026年8月3日 11:05
A woman found her police officer ex-boyfriend had used Flock's camera system 600 times to look up the location of her and her daughter, reports the Washington Post (Alternate URL here). (She found out through Have I Been Flocked, described as "a website that aggregates police search logs made available through public records.") But it turns out dozens more police officers have also misused Flock... Authorities have charged or accused at least 50 law-enforcement officers of using license-plate readers for unauthorized purposes, including to stalk women without their knowledge or consent, a Post analysis of police and court records found. In 26 of these cases, police investigators and prosecutors said the officers used the technology to spy on their wives, their girlfriends, their exes, their exes' new partners or women they wanted to meet. In other cases, police or prosecutors have not specified the alleged surveillance targets. Flock's system was used in 46 of the cases analyzed by The Post, while the other cases involved competing products... After The Post relayed its findings to Flock, the company said in a statement it "will soon be announcing better filters and tools to stop abuse before it happens...." In April, the company rolled out a new voluntary "audit assistance" feature, which agencies can choose to enable, that automatically scans officers' searches for suspicious activity, such as queries repeatedly targeting the same vehicle or run by officers off the clock. In an interview with The Post, Flock chief executive Garrett Langley said misuse of its systems is inevitable and that the company is focused on providing tools to catch perpetrators after the fact... "We're not going to change humans, and humans make bad decisions," Langley said. "What we can do is make sure that they know if you use this tool, you will be held accountable...." Through automated license-plate reader systems, or ALPRs, officers could trace the rhythms and travels of their subjects' daily lives, leading in some instances to violent confrontations, moments of psychological manipulation, and threats of coercion and control, the analysis found. - In Wisconsin, a police officer allegedly used Flock to check whether his ex-girlfriend had gone to an abortion clinic, according to a police affidavit for a case set for trial this month. - In Kansas, a police chief who tracked his ex through Flock sneaked up on her while she was intimate with another man, a state police certification body alleged, leading to his firing. - In Florida, a deputy speeding to stop a young actress he'd added to a watch list for a license-plate tool called Guardian nearly caused a head-on crash, according to a police report and video from his dashboard camera. The deputy was arrested in March, and his attorney declined to comment. - And in California, prosecutors said a former deputy, Alexander Vanny, used Flock as part of a months-long campaign of "stalking" and "humiliating" his former fiancée that also involved following her around town and installing a hidden camera in her roommate's bathroom, according to a sentencing brief... While some of the searches resulted in officers' firings, prosecutions and prison sentences, police departments in other cases allowed officers to continue using the systems even after receiving warnings that they were being misused... An array of privacy advocates has argued that Flock could deter bad actors by making simple changes to its product, such as requiring officers to label every search with a criminal case number. Some policing experts also warned that agencies' inconsistencies in developing and enforcing standard procedures for license-plate readers could lead to further misconduct. With no federal laws governing use and only a patchwork of state laws, many of the country's roughly 18,000 police agencies are left to decide their rules on their own... Langley, Flock's chief, has dismissed pushes by activists for the company to further limit how officers use its product. "No one elected me the police chief of America," he told Forbes last year, adding, "I don't think it's our job to police the police." The Post also got this quote from an officer was fired and sentenced to probation after pleading no contest to charges of computer-system misuse, stalking and battery. "Pretty much everybody uses that computer system" improperly in the department, he said, and "they don't audit it [nearly] as much as they should." Flock told The Post it now has over 120,000 cameras in more than 6,000 communities, recording 20 billion license plate scans every month.

Read more of this story at Slashdot.

❌