Comcast Turns Millions Of Routers Into Motion Sensors – The Same WiFi Signals Can ID You With 99.5% Accuracy

Dear Comcast customers: The internet gateway in your living room is now a motion sensor. It’s free of charge, and the data can go to law enforcement without further notice. What’s more, researchers have already shown that these same signals can identify exactly who is in the room.

On Tuesday, Comcast unveiled Xfinity Shield, a home security platform built entirely around the WiFi network. Its centerpiece, WiFi Motion, turns the leased gateway into a motion detector at no extra charge. According to Comcast, a typical customer has roughly 36 devices connected to their WiFi.

WiFi Motion works because a human body moving through a room disturbs the signal field between the gateway and stationary connected devices, like a printer or a game console. While the feature is opt-in and – according to Comcast’s rollout materials – does not track phones or reach through WiFi extenders, those limitations are choices Comcast made in software, not limitations of the technology itself.

Comcast says WiFi Motion works “without recording video, capturing images or identifying individuals.”

The company is not shy about identification as a product. The $15-a-month tier, Xfinity Shield Select, adds AI-powered cameras that identify people, pets, packages and vehicles. The free tier’s restraint is a line drawn one product SKU away.

Keep reading

X Wins Australian Case Over Private Message Scanning Rule

Australia’s eSafety Commissioner wrote a rule requiring online services to scan what their users send each other. Not to act on reports, but to run detection systems across private messages before anyone has complained, hunting child sexual abuse and pro-terror material. Top censor, Julie Inman Grant, wrote it herself, under powers the Online Safety Act hands her, and breaching it carries penalties of up to $49.5 million.

Then she took the view that it covered social media platforms as well, because they let users send each other messages.

On August 12, the Federal Court told her it does not. The Relevant Electronic Services Standard “does not apply” to X, Justice Elizabeth Raper held, ruling for the platform in a case it brought in May 2025. It “would be rather perverse for a social media service…not to enable messaging or chat between end users,” X’s barrister had argued — on eSafety’s reading, having a DM function was enough to pull a platform into a rulebook written for something else.

The distinction is important because of who writes what. Social media services in Australia are covered by a code developed with the industry, X included. The RES Standard is not a negotiated code. It is an instrument the Commissioner drafts and enforces herself. The standard says it applies “to the exclusion of any industry code” — so reading it to cover social media would have let the instrument she controls displace the one she negotiated.

Raper said so directly. “I accept X Corp’s characterisation of the facts that the RES Standard has been made by the commissioner…as a standard applicable to participants in a different section of the online industry, that are specified…as ‘providers of relevant electronic services’,” she wrote.

Keep reading

The Right To Be Left Alone

“The makers of our Constitution undertook to secure conditions favorable to the pursuit of happiness… They conferred against the Government the right to be let alone — most comprehensive of rights and the right most valued by civilized men.” ~ Justice Louis D. Brandeis (1856-1941)

The rapid spread of public surveillance cameras represents something far more consequential than a new piece of police technology. It represents a fundamental change in the relationship between the individual and the state.

These cameras allow government agents to record, identify, catalog and retroactively track the movements of people who have committed no crime, are suspected of no wrongdoing and have done nothing to invite government scrutiny. That’s not public safety. It’s an assault upon individual privacy.

Privacy is not a privilege granted by government. It is an aspect of personal liberty that government exists to protect. It is a natural human right protected from the government in the Bill of Rights. The fact that a person leaves his home and travels upon a public road does not mean that he has surrendered that right.

There is an enormous moral and constitutional difference between a police officer who happens to observe a person in public and government surveillance that automatically and systematically records that person’s vehicle, location and movements; and stores that information for future use.

A free society doesn’t just protect people from crime; it protects them from arbitrary government. The presumption is liberty. Government is the negation of liberty. A person should not have to establish his innocence before the government leaves him alone. The burden always belongs to the government to justify all intrusions into personal liberty. Police cameras reverse that principle. They collect information about everyone the camera views and leave it to individuals to challenge the collections afterward.

The Constitution requires articulable suspicion connecting the person being surveilled to a legitimate law-enforcement objective to justify public surveillance. A vague assertion that the technology might someday help solve a crime or enhance public safety does not meet that standard.

The view that personal privacy and public safety are in equipoise — that they are merely two competing interests of equal moral and legal weight from which government officials are entitled to choose subjectively their preferred balance — is the core of authoritarianism.

Safety is one of the legitimate purposes for which government exists. Privacy is among the personal liberties that government exists to protect. It cannot be taken away without judicial approval. Government cannot justify violating a natural right merely by asserting that doing so might make people safer. If that were so, there would be no meaningful boundary on any governmental power.

There is a profound difference between investigating a specific crime through constitutionally authorized surveillance and constructing a permanent infrastructure of suspicionless surveillance. The former begins with evidence and seeks information relevant to a particular governmental purpose. The latter begins with everyone and waits for the evidence.

When 7,000 American police departments have these systems with no legislative approvals, we have the police making policy judgments. They are deciding that the government should possess a new capacity to observe innocent people, what information should be collected, how long it should be retained, who should have access to it and what purposes may justify searches; all this irrespective of the Constitution.

Those are not merely administrative questions. They are questions about personal liberty.

If elected legislators believe that such surveillance is necessary, they should publicly debate it, enact specific legislation mandating warrants, establish meaningful limitations and accept responsibility before the voters. The decision should not be buried in a police procurement process or treated as an ordinary equipment purchase.

Liberty cannot depend upon the benevolence, restraint or good intentions of government employees. The premise of the Constitution is that government power must be limited, checked and divided because government officials are human beings who possess power and will inevitably have incentives to abuse it.

The answer is not better government surveillance. The answer is what the Fourth Amendment requires: No government surveillance without search warrants.

The constitutional question cannot be reduced to whether someone was physically standing in a public place. A police officer seeing a car pass by is one thing. A government database capable of reconstructing months of a person’s movements is something fundamentally different.

The difference is the difference between observation and surveillance.

Keep reading

Meta Faces Criminal Complaint in Germany for Its AI-Glasses, Accused of Violating Privacy Laws

Who wants to be filmed all the time?

The struggle between new, useful tech gadgets and the objections that these new capabilities raise is a field expected to grow in the next few years, and make many lawyers very wealthy.

One such example is the Meta AI-Glasses.

In principle, it seems a great idea to pack so much computing power in a pair of glasses for our benefit.

But once you start to compute the legal and ethical objections that this gadget raises, it becomes a much less clear question.

Today (12), a German advocacy group took matters into their own hands, and filed a criminal complaint against Meta and other companies, ‘arguing the devices violate privacy laws’.

Reuters reported:

“Digital rights group HateAid said in a statement on Wednesday that the launch of the devices, the Ray-Ban Meta Wayfarer in particular, broke German digital privacy laws, in the latest sign of legal scrutiny in a nation where the right to privacy is highly valued.

‘There’s no place to escape from smart glasses. You have to expect at any moment to be filmed and then exposed on the internet’, said HateAid managing director Josephine Ballon.

The organization reported the management of Meta, units of spectacles maker EssilorLuxottica including Ray-Ban, as well as retailers Fielmann, Apollo-Optik, Mister Spex and MediaMarkt to the Frankfurt-based digital crime prosecution unit ZIT.”

The complaint is based on Germany’s federal digital data protection law, which prohibits the sale of communication devices designed to film people without them noticing.

Keep reading

He Spoke at a Town Meeting. Then Flock Cameras Started Tracking His Car.

A resident steps up to the mic at a town council meeting, says something inconvenient, then drives home — unaware that somewhere in a police database, that license plate just became a person of interest. No warrant. No probable cause. Just an officer with a grievance and a subscription service the town approved at a meeting most residents never knew about.

That scenario isn’t hypothetical anymore. In 2026, it’s documented — from Georgia to Rhode Island.

How Flock Works – and How It Can Be Weaponized

The system was built to catch criminals; the problem is there’s nothing reliable stopping it from being aimed at everyone else.

Flock Safety sells automated license-plate reader (ALPR) networks to police departments nationwide. The pitch is straightforward: catch criminals faster by searching vehicle movement data after incidents occur. What the system doesn’t include is a reliable filter between a legitimate investigation and a personal score to settle. Unlike federal wiretap law, no federal statute currently governs ALPR data retention periods or inter-agency sharing agreements, leaving oversight entirely to municipal contracts.

The documented abuse cases are piling up:

  • The Electronic Frontier Foundation identified more than 50 agencies running hundreds of Flock searches tied to protest activity
  • CNN report from July 2026, citing an Institute for Justice tally, found at least two dozen cases where officers resigned or were arrested for allegedly using Flock to stalk romantic partners
  • A police chief in Braselton, Georgia, was arrested for allegedly using ALPR cameras to stalk and harass private citizens
  • Court documents show searches conducted far outside officers’ jurisdictions, according to a 2026 investigation republished by Yahoo
  • Flock told 404 Media it was “aware of 15 incidents of abuse” — a figure critics argue the platform’s design makes structurally impossible to trust

Keep reading

Princeton Study Shows How Bad Actors Can Exploit Georgia Elections To Expose How You Voted

A new analysis from Princeton University’s Center for Information Technology Policy shows that a capable analyst — or even an ordinary AI model — can reconstruct the order in which most Georgia ballots were scanned and, by combining that order with other ordinary election records, determine how individual voters cast their ballots.

Using publicly available data from the state’s May 2026 primary, researcher Max Springer demonstrated the technique at scale, recovering the scanning order of roughly 1.5 million ballots (98.9 percent of in-person ballots) across 139 counties. In smaller example jurisdictions, the linkage was nearly complete: in Heard County every one of the 650 early in-person voters could be tied to a specific ballot, and in Ball Ground (Cherokee County) all 1,860 early voters were matched. In other words, the supposedly secret ballot is not nearly as secret as the public has been told.

Early voting compounds the vulnerability. Voters at vote centers come from multiple precincts and often use different ballot styles with different candidate choices. Those differences create additional data points that can improve the ability to isolate individuals inside the Cast Vote Records (the electronic files that list every candidate choice marked on each ballot). Match confidence will vary — some linkages can be made with near certainty, others with lower confidence — but a talented programmer or AI user can still perform substantial voter profiling.

In small towns and close-knit communities, the risks of exposure are obvious. Parents could identify teachers’ ballots. Employees could face pressure from employers, or bias from potential employers. Even people who never face overt pressure could still experience quiet discrimination.

Some voters already avoid primaries because they do not want their party preference known. The ability to reverse-engineer candidate choices in a general election would only increase the potential for intimidation and could open the door to a whole new form of doxing.

Many people assume election officials are supposed to be able to know how individuals voted. They are not. Georgia law requires “absolute secrecy” of the ballot. While election officials must handle anonymous ballots, the system also must not allow anyone — including poll officials, election boards, or the state’s vendors — to determine how any particular voter cast his ballot.

The ability to reconstruct individual voting choices — and potentially disclose them — raises serious legal concerns under Georgia law, but also carries substantial commercial and political value. In an era when major campaigns routinely spend hundreds of millions of dollars, the ability to know how specific voters actually cast their ballots could be worth millions.

When that information can be assembled across multiple election cycles, the ability to build detailed, long-term voter profiles only grows stronger. That kind of data is useful to campaigns, advocacy groups, and anyone building sophisticated micro-targeting models. An insider at the state or county level with access to the original internal data files could face a clear temptation. The creation of traceable ballots must stop — while preserving the ability to audit the election.

Those concerns are heightened by the fact that Georgia’s Secretary of State’s office has already experienced multiple serious data exposures and breaches. In 2015, the office distributed voter files containing Social Security numbers, driver’s license numbers, and birth dates for more than 6 million voters (the “PeachBreach”). In 2016-2017, a server at Kennesaw State University that handled statewide election preparation was found exposed to the internet, containing millions of voter records with personal identifying information, election databases, and supervisor passwords.

Additional web portal vulnerabilities in later years have repeatedly risked or briefly exposed personal voter data. Combined with ordinary internet security risks, the traceable ballot-level data that remains inside official systems cannot be treated as securely walled off from potential misuse.

Keep reading

What in the Actual? Mamdani Doxxes NYC’s Wealthy by Publishing Their Names and Addresses

New York City Mayor Zohran Mamdani (D) just made it a whole lot easier for anyone to look up the names and home addresses of wealthy New Yorkers who own second properties in the city.

How? By publishing a searchable database of properties that could fall under the new pied-à-terre tax, complete with the owners’ full names and addresses.

The list covers unoccupied, non-primary residences worth more than $1 million across the five boroughs.

The New York Post reports that the move by the administration is “effectively doxxing thousands of wealthy New Yorkers.”

I’m almost certain that those individuals are thrilled to have their potentially empty homes’ addresses advertised to unhinged “tax the rich” leftists.

For property owners who already felt targeted by the city’s new tax push, having their personal information posted online is only pouring fuel on the fire, which is the intent, really. Mamdani is literally trying to drive wealthy individuals out of the city that serves as the economic engine of the nation.

It fits a clear pattern of taunting. RedState’s Nick Arama detailed how Mamdani recently mocked second-home owners online by gloating that notification letters for the new pied-à-terre tax were already in the mail and that “you’ve got mail.”

Arama accurately described the derisive message as “gross,” which might as well be an evergreen description going forward for Mamdani’s economically illiterate reign.

Keep reading

GrapheneOS Wipe at Airport Leads to Federal Charge in Atlanta

The Justice Department is asking a federal court in Atlanta to treat a man’s erasure of his own phone as destruction of property, in the first known US prosecution built on a phone’s duress password.

Samuel Tunick faces one count under Title 18, Section 2232(a), a statute covering the destruction of property to stop the government from taking it. Prosecutors say he handed Customs and Border Protection officers a passcode that deleted the contents of his Google Pixel instead of unlocking it. His lawyers appeared before the court for the first time on Monday, arguing that officers ran a custodial interrogation without Miranda warnings, denied him a lawyer, and searched him unlawfully. They want everything obtained from the encounter suppressed.

CBP pulled Tunick into secondary inspection at Hartsfield-Jackson on January 24, 2025, as he returned from the Dominican Republic. An FBI Joint Terrorism Task Force officer and an FBI special agent had coordinated with CBP in advance to question and search him on arrival. The account comes from the defense filing, which draws on the government’s own reports. Officers from CBP’s Tactical Terrorism Response Team opened by telling him they were “looking for people who are pedophiles.”

Officers never read Tunick his Miranda rights. He said early in the interview that he did not want to keep talking without a lawyer, then asked to call one repeatedly. Questioning continued. One officer told him his refusal to talk gave them authority to go through his phone. When he asked again about his attorney, an officer told him customs and immigration work was a different matter, “and we have search authority, we don’t need a warrant.”

Tunick eventually provided a password for his phone and his e-reader. The screen “went blank, flashed several times and the phone appeared to restart,” according to the government’s report. Officers seized the devices anyway and told him they would be returned after thirty days. A third officer took him to another room for a pat-down that was not recorded. A DHS agent then told him he was free to leave once the other agents were finished with him.

The government’s reports contain no indication that anyone suspected Tunick of carrying illegal images, his lawyers wrote. The reports record an interest in his association with Defend the Atlanta Forest, the movement opposing the clearing of the South River Forest for the Atlanta Public Safety Training Center. Opponents call the 85-acre, $115 million police facility Cop City. Federal documents label the movement an “Anti-Government, Anti-Authority Violent Extremist Group.” Tunick has not been charged with any offense connected to it.

Eleventh Circuit precedent favors the government. Its 2018 ruling in United States v. Touset permits forensic searches of electronic devices at the border with no warrant, no probable cause, and no individualized suspicion. Tunick’s lawyers cite decisions from the First, Fourth, and Ninth Circuits going the other way, including a Fourth Circuit holding that warrantless border searches of devices cannot be used to hunt for evidence of domestic crime. They also argue that surrendering a passcode is testimonial, relying on a 2012 Eleventh Circuit decision that decrypting and producing the contents of a hard drive triggers Fifth Amendment protection.

Courts allow suspicionless border searches to keep contraband out of the country. The accusation here is that data left a phone rather than entered the United States, and digital files move across borders over the internet anyway. A ruling on the motion is not expected before the end of October.

GrapheneOS, the hardened Android build that replaces the stock software on Pixel devices, lets an owner set a second PIN or password that irreversibly wipes the device and any installed eSIMs when entered at a credential prompt. No confirmation dialog appears, and nothing distinguishes it from a normal unlock.

Bill Budington, senior staff technologist at the Electronic Frontier Foundation, and Runa Sandvik, founder of the security firm Granitt, both said they had seen no comparable prosecution. Sandvik said she had discussed the scenario with activists and journalists for years and advised travelers to leave sensitive data off devices they carry across borders rather than count on wiping it. Christophe Boutry told the Guardian the prosecution “sends the message that [GrapheneOS] is criminal by default.”

Matthew Dodge, an assistant federal public defender on Tunick’s legal team, said the statute is rarely seen in an indictment. Tunick was arrested about ten months after the airport stop. His crowdfunding page says he was pulled over for a purported tail light fault and cuffed by FBI and DHS officers when he stepped out of the car. He has pleaded not guilty. The single-count indictment  accuses him of acting to delete the digital contents of a Google Pixel to impair the government’s lawful authority to take it, in violation of Title 18 of what the document calls the “Untied States Code.”

Keep reading

India Orders GitHub to Block BitChat

India’s Cyber Crime Coordination Centre last night ordered GitHub to disable access to BitChat, the peer-to-peer messaging app backed by Jack Dorsey. The order, Notice No. 11072601011432, went out at 11:16 pm under Section 79(3)(b) of the Information Technology Act, 2000, read with Rule 3(1)(d) of the IT Rules, 2021.

It named three repositories, including the Android application and its release files, and gave GitHub three hours to take them down. It warned that failure would cost the platform its safe harbor and open it to criminal prosecution.

The government did not publish the order. The public learned of it from a post by Jack Dorsey, whose team develops BitChat, who wrote that “the government of India does not like technologies like BitChat and wants it taken down.”

BitChat is open source and uncensorable, and is one of Reclaim The Net’s recommended messaging apps for situations where the internet may be cut off. It carries messages from phone to phone over Bluetooth, hopping between nearby devices, with “no internet, servers, phone numbers, or accounts.” It keeps working when the mobile network does not.

Around this protest, the government, getting increasingly brazen with its blocking orders, has switched the mobile network off. Since July 17 the Ministry of Home Affairs has suspended mobile internet around Jantar Mantar in New Delhi about five times.

The most recent suspension ran from 4 pm to midnight on July 23, inside a 1.5-kilometer radius that takes in Janpath and part of Connaught Place. People at the site reported signal jammers, and walking two kilometers before a phone found a signal.

Inside that radius, a student separated from her group during a detention sweep could not send a message to say where she was.

The protesters are students. Tens of thousands have camped at Jantar Mantar since June, demanding accountability for the leak of the NEET medical entrance exam and the resignation of Education Minister Dharmendra Pradhan. Their march to Parliament was refused. Metro stations near the site were closed.

When the shutdowns cut the network, protesters turned to BitChat and other Bluetooth mesh apps to reach each other inside the dead zone.

The order did not name a single message sent on BitChat. It just objected to what the app can do. In the agency’s words, BitChat “significantly impedes lawful interception, attribution, and investigation,” and could be used during “public disorder, riots, terrorism, organized crime, or internet shutdowns.”

The order lists internet shutdowns among the dangers. The government has imposed one at Jantar Mantar. BitChat kept working inside it.

The order used Section 79(3)(b) to demand the block. In 2015, in Shreya Singhal v. Union of India, the Supreme Court held that Section 79(3)(b) lets the government require a takedown only through a court order, or a notice confined to the grounds in Article 19(2) of the Constitution.

India has a separate law for blocking an app, Section 69A, which requires a hearing and reasons set down in writing. The order against GitHub used neither. It went out through the Home Ministry’s Sahyog portal, the channel Indian High Courts are now hearing constitutional challenges against.

The order says the repositories hold information prohibited under law. It names none. It points instead to what the app is “capable of” enabling.

It reaches into criminal law as well. Alongside Section 43 of the IT Act, a civil compensation provision, it invokes conspiracy and abetment under the Bharatiya Nyaya Sanhita of 2023, against a platform that hosts code.

Keep reading

‘VPNs are lawful technical tools,’ says EU Court in landmark Anne Frank copyright ruling

In a major victory for digital rights and common sense, the Court of Justice of the European Union (CJEU) has officially categorized Virtual Private Networks (VPNs) as “lawful technical tools” while establishing new boundaries for online copyright disputes.

The landmark judgment — handed down in July 2026 — stems from a complex legal battle over the online publication of Anne Frank’s historical manuscripts. At its core, the case forced Europe’s top judges to answer a highly technical question: if a publisher actively tries to block visitors from a specific country, are they still breaking the law if a user sneaks past the digital border using circumvention software?

According to the CJEU, the answer is no. As long as a website employs “state-of-the-art” geo-blocking technology, the publisher cannot be held liable for copyright infringement simply because a determined reader decides to fire up the best VPN to bypass the restrictions.

The ruling sets a massive precedent. It confirms that copyright holders cannot point to the mere existence of VPNs to claim a website’s security measures are completely ineffective.

More importantly for privacy advocates, the court firmly pushed back against the demonization of privacy software, cementing the legitimate status of VPN providers across the European Union.

Keep reading