California Grocery Stores Use Facial Recognition Technology To Combat Theft

Faced with a shoplifting epidemic that has battered California retailers for years, Grocery Outlet is fighting back with technology.

Customers are not thrilled about it.

The Emeryville-based discount grocery chain has begun installing facial recognition software called SAFR at a handful of Bay Area stores, including its Pleasant Hill “Bargain Market” location, CBS News San Francisco reported.

Customers walking through the doors will find signs warning them the system is in use, a disclosure the company says is meant to keep shoppers informed.

The rollout comes as California tries to combat a shoplifting problem that has spiraled out of control.

FBI data cited by CBS shows theft in the state has jumped 50 percent since the COVID-19 pandemic, a surge that has forced retailers from big-box chains to neighborhood grocers to spend millions on security measures, or in some cases, shutter stores altogether.

For June Guerrero, who spent years managing a retail store, the new technology is a welcome and overdue response to a problem she saw firsthand.

“I worked for years as a manager of a store and the theft was just unbelievable,” Guerrero told CBS News. “I agree with it.”

Not every customer sees it that way. Barbara Jackson told the outlet she’s uneasy about having her face scanned every time she shops for groceries.

“I do understand, but invading my privacy with my picture, I don’t agree on that,” Jackson said. “You gotta find a better way.”

Shopper Steve Burdette raised a different concern: the risk of the system misidentifying innocent customers as thieves.

“It could lead to a lot of problems, I think for companies and businesses and people,” he said.

SAFR president Charisse Jacques pushed back on the notion that the technology amounts to mass surveillance. She said the company does not maintain a database of every customer who walks through the door, retains information on suspected shoplifters only for a limited window, and does not share data with outside agencies — including U.S. Immigration and Customs Enforcement, according to the New York Post.

Keep reading

Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing

Microsoft has publicly acknowledged the existence of the Global Device Identifier (GDID), a device-specific ID assigned to Windows installations, in a federal complaint filed by US prosecutors against an alleged member of the Scattered Spider hacking group.

The ID is generated when Windows is set up with a Microsoft Account, persists through Windows updates, and cannot be disabled without affecting Windows activation and Microsoft Store apps.

Microsoft briefly mentioned GDID in the Azure Monitor documentation, describing it only as “an identifier used by Microsoft internally.” The complaint cites a Microsoft representative describing GDID as “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device such as a mobile phone or laptop or a virtual machine, across certain Microsoft services and scenarios.”

What the Windows Global Device Identifier Is and How the FBI Used It

The Global Device Identifier (GDID) is a permanent ID assigned when Windows provisions against a Microsoft Account. It is generated by a chain of Windows services.

The wlidsvc service requests a Device PUID from login.live.com, which is then registered into Microsoft’s Device Directory Service by the Connected Devices Platform.

Delivery Optimization reports the GDID back to Microsoft when the PC shares or downloads updates. This identifier is stored in the Windows registry under HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties and formatted with a lowercase “g” prefix followed by a decimal number.

It is reported to Microsoft servers and remains persistent across Windows updates, but it is not retained after a clean reinstall. Microsoft has acknowledged that one user can have multiple GDIDs linked through their account, OneDrive, and activation history.

The FBI used the GDID to track Peter Stokes, alleged member of Scattered Spider, across VPN connections, proxy servers, and through four countries over roughly eight months.

According to the complaint, the GDID g:6755467234350028 was recorded visiting the ngrok signup page at the same time an account used in the attack was created via a Tzulo VPN proxy. Three hours later, the same GDID accessed a victim retailer’s website through the same proxy.

The device was cross-referenced with IP addresses linked to Stokes’s accounts on Snapchat, Facebook, Apple, and Ubisoft across Estonia, New York, Thailand, and other locations. Stokes’s public Snapchat photos matched hotel bookings, locations, and travel timelines associated with the GDID.

The persistent nature of the GDID across VPN sessions proved a key investigative asset. While VPN IP addresses change frequently, the underlying Windows installation continued reporting the same identifier, aiding investigators in their tracking efforts.

Keep reading

Jack Smith team read messages between Trump officials, dozens of lawmakers of both parties: ‘Ran roughshod over the Constitution’

More than 40 members of Congress had their text messages viewed by former special counsel Jack Smith’s team amid a probe into President Trump, a move that Republicans say “ran roughshod over the Constitution.”

The Department of Justice released records to Senate Judiciary Committee Chairman Chuck Grassley (R-Iowa) on Tuesday revealing that the special counsel’s office had accessed communications between Trump White House personnel and 44 lawmakers from both parties.

Sen. Cory Booker (D-NJ); Rep. Adam Smith (D-Wash.), the current ranking member of the House Armed Services Committee; current Los Angeles mayor and former Rep. Karen Bass (D-Calif.); and former Rep. Lee Zeldin (R-NY), now the head of the Environmental Protection Agency, were just some of the new names whose messages were seen.

Grassley himself, Sen. Susan Collins (R-Maine), Sen. Tom Cotton (R-Ark.), House Majority Leader Steve Scalies (R-La.) and Rep. Elise Stefanik (R-NY) were also targeted.

Asked during a December 2025 congressional deposition whether his team looked at “the content of text messages” during his twin probes into the 45th and 47th president, Smith answered, “No.”

Keep reading

Jack Smith’s Team Spied On 44 Lawmakers’ Texts, Built A Case On Them, And Misled Congress: Grassley

Former special counsel Jack Smith’s investigators blew past the Justice Department’s own privilege safeguards to directly access text messages between Trump White House officials and 44 members of Congress – then had the FBI match the phone numbers to lawmakers’ names, according to DOJ records released Tuesday.

Assistant Attorney General Patrick Davis told Senate Judiciary Committee Chairman Chuck Grassley (R-IA) in a letter accompanying the records that Smith’s team “bypassed the Filter Team and directly accessed these text messages.” The FBI then worked out which senators and House members had sent or received them, Davis wrote.

The filter unit existed for one purpose: to screen messages pulled from the National Archives for privileged material before line investigators ever laid eyes on them.

All communication to/from the Filter Team must go through the Coordinator,” one internal protocol document states – adding that nothing was to reach the investigative team without a filter attorney’s sign-off.

The messages, sent between October 2020 and Jan. 20, 2021, ran between a bipartisan roster of lawmakers and Trump White House figures including chief of staff Mark Meadows, Dan Scavino, Ivanka Trump, Stephen Miller, Peter Navarro, now-CIA Director John Ratcliffe and now-FBI Director Kash Patel, the records show.

Keep reading

Under Israeli pressure, US seizes Max Blumenthal’s devices on return from Tehran reporting trip


On July 10, 2026, American journalist Max Blumenthal was traveling back to the United States from Iran, which he had visited to report on the funeral of Ayatollah Ali Khamenei, the largest gathering in human history. While in Iran, Blumenthal interviewed members of Iran’s negotiation team, top political officials, academics and average citizens for a series of video and print reports for this news outlet, which he founded.

He also documented several US and Israeli war crimes from the ground, including the destruction of an entire neighborhood in Eastern Tehran which left at least 40 civilians dead.

Upon reentering the country at Dulles International Airport, Customs and Border Patrol (CBP) interrogated Blumenthal about his trip, searched his belongings, and demanded that he provide access to his smart phones. When he refused to open his phones, CBP officers forced him to turn them over for detention. Other journalists and travelers have been threatened with the loss of their passports for a month for failing to hand over their devices.

Blumenthal entered Iran exactly as reporters working for establishment media outlets like CNN and NBC did – on a press visa granted by the Iranian Foreign Ministry. While in Tehran, he participated in official press events alongside those mainstream reporters, who were also in the country to cover the Ayatollah’s funeral. When journalists from CNN, NBC, and other American outlets returned to the US, however, they were not subjected to the same harassment Blumenthal experienced, nor were they required to give the US government their electronic devices.

Blumenthal is a widely recognized journalist in American independent media, with a record of reporting spanning 25 years. He is the author of four books, including a New York Times bestselling volume, and numerous widely viewed documentary films. Having reported from numerous countries and conflict zones around the world, he is the winner of several awards, including the Online Journalism Award and, most recently, the Pierre Sprey Award for Defense Reporting and Analysis.

Keep reading

Waymo Robotaxi “Snitches” On Two 15-Year-Olds Drinking & Shooting Orbeez Guns In Bay Area

Two 15-year-old boys were detained in San Mateo Monday afternoon after the Waymo robotaxi they were riding in reported them to police – for drinking alcohol and firing a gel-bead blaster out of the moving car – then pulled itself over so officers could collect them.

Waymo’s remote monitors spotted the behavior on the vehicle’s interior cameras and called the San Mateo Police Department around 2:10 p.m. with the car’s exact location. The company then disabled the vehicle near 20th Avenue and El Camino Real, telling the pair the car was having trouble – a ruse that bought officers time to get into position.

Because the initial report described what looked like a real firearm, police conducted a high-risk stop, approaching with guns drawn and a police dog deployed. No one was hurt. Inside, officers found an Orbeez-style gel blaster – painted over to pass for the real thing – and open alcohol.

The teens cooperated, were detained, and were released to their parents. The case has been forwarded to the San Mateo County District Attorney’s office for review of possible charges, including underage drinking, and police say they plan to pull the Waymo’s interior video.

“Parents do you know where your teens are? @waymo does!” The department wrote on Facebook: “After calling us and stopping the car, we were able to safely remove both subjects and determined they were shooting Orbeez from the car as they sipped on afternoon libations while being chauffeured around town in the driverless vehicle.”

“While there was some ingenuity to this scheme, toy guns, water guns, and BB guns all pose real dangers, especially to an untrained eye… Shooting projectiles at speed can cause real damage. And lest not forget the underage drinking. All bad ideas today for these two. Well, the Waymo might have been the smartest idea yet, because driving impaired would’ve made this so much worse.”

Keep reading

Anthropic Removes “Scary” Secret Claude Tracker After Developer Stumbles Across It

Anthropic has removed hidden detection code from its Claude Code tool after a developer reverse-engineered the binary and exposed how the company was subtly monitoring users in China.

The code, which Anthropic described as an experiment launched in March, used a form of prompt steganography to signal information about a user’s environment back to Anthropic’s servers. It was designed to help detect unauthorized resellers and attempts by other organizations to distill Claude’s capabilities into their own models.

How The Detection Worked

The mechanism was first spotted by a Reddit user known as LegitMichel777, who stumbled on it while trying to restore a disabled feature in Claude Code. A separate developer known as Thereallo independently confirmed the finding the same day, June 30, publishing a technical breakdown of exactly how it worked.

The checks only ran in one specific situation: when a user pointed Claude Code at a different server instead of Anthropic’s own – something companies commonly do when they route their traffic through internal systems or third-party gateways. From there, it checked two things:

  • Whether the user’s computer was set to a Chinese time zone (Shanghai or Urumqi).
  • Whether the new server address matched a hidden list of Chinese AI companies (including well-known names like DeepSeek, Zhipu, and Moonshot) or known resale and proxy services.

If either check came back positive, Claude Code would quietly tweak a line of text called the “system prompt” – background instructions the app automatically sends to the AI model with every request, invisible to the person typing. Specifically, it changed how the date was written in that line:

  • If the user was in a Chinese time zone, the date switched from using dashes to slashes (e.g., 2026/06/30 instead of 2026-06-30).
  • The apostrophe in the phrase “Today’s date is…” was swapped for one of three lookalike characters, each one a different signal, depending on which combination of checks the session had triggered.

None of this was visible to users, or likely even to the AI model itself in normal use – the characters look identical on screen. But Anthropic’s servers could read the difference instantly. The lists of flagged domains and keywords were also scrambled inside the app’s code using a basic encryption trick, so they wouldn’t show up if someone just opened the file and searched for them.

Thereallo called the approach “prompt steganography” – hiding a signal inside ordinary-looking text – and noted it let Anthropic sort and flag sessions without needing any separate, visible tracking system.

Anthropic’s Explanation

Last Tuesday, Anthropic engineer Thariq Shihipar, who works on the Claude Code team, confirmed the feature on X:

This is an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation. The team has landed stronger mitigations since then and we’ve actually been meaning to take this down for a while. We merged the PR and this should be fully rolled back in tomorrow’s release.”

Anthropic has stated that unauthorized resellers have been selling access to Claude accounts and subscriptions at steep discounts in certain markets. The company has also publicly documented large-scale efforts by Chinese AI labs to distill its models by querying them at high volume through proxies and fraudulent accounts.

Anthropic removed the detection logic shortly after it became public.

Keep reading

New York Bodega Owners to City: Drop Dead!

It’s been more than 50 years since the New York Daily News reported that President Gerald Ford would veto any bailout for the city’s endless red ink with the headline, “Ford to City: Drop Dead.” Ford never said exactly that, of course, but the headline created such a backlash that Ford backed down a few months later, putting his signature on $2.3 billion worth of emergency loans. That’s about $14.3 billion in 2026 money — a very nice little bailout, indeed.

Today, New York City bodega owners know that nobody will bail them out when the city’s Commie-Islamist Mayor Zohran Mamdani puts them out of business, which is why they just silently told him to drop dead.

Or at least that’s the impression I got from a Monday morning New York Post exclusive detailing the showdown between Gracie Mansion and local retailers threatened by Mamdani’s campaign promise to build and operate city-run grocery stores.

“Business owners gripe that city officials are only now seeking their input — and seemingly as an afterthought — after sparking alarms in April with a surprise plan to build a public grocery store in East Harlem at La Marqueta,” the Post reported. “That store will cost a whopping $30 million to build – and threatens the livelihood of more than a dozen existing stores nearby.”

All of that is to be expected. The city can throw Other People’s Money at its socialist stores until it runs out, while typical grocers operate on razor-thin 2% profit margins. Considering the services they provide and the complexity of their operations, the real crime is how little money they make.

But I digress, as I usually do.

What I love about this story — and what makes it so newsworthy — is the sheer gall of the Mamdani administration. 

“We met with bodega owners so they could help us plan and ensure that we take into account their challenges and their role as a part of the food ecosystem,” Julie Su, deputy mayor for “economic justice,” told the Post in a statement. But what really happened was that bodega owners reported to City Hall last week at Su’s invitation for a roundtable discussion, “only to get barraged with ‘intrusive’ questions about their businesses,” according to the Post’s source.

The questionnaire bodega owners were expected to fill out included questions like, “What items are sold the most at your stores?” and “Where is your profit margin the greatest?” 

The correct answer to questions like those is, “Get stuffed.” The polite answer is, “Try running a bodega and figure it out for yourself, or get stuffed.”

Instead, an anonymous bodega owner who spoke to the Post said, “They wanted us to share proprietary information with them but they don’t answer our questions and that’s why there is distrust.”

“Tell us how to run you out of business with your hard-won institutional knowledge and your tax dollars” is pretty much the height of gall, I thought. But then I read the part where Su told the Post, “One of the questions we wanted to understand is whether there are key products bodegas sell and rely on that we should not sell. That’s how serious we are about not undercutting them.”

Keep reading

Meta pauses an AI training program that tracks employees’ keystrokes after an internal leak

Meta is pausing an internal AI training program after sensitive data was accessible across the entire company, according to screenshots obtained by Business Insider.

A screenshot showed that the leak exposed employees’ private conversations, performance data, and transcriptions. The incident was classified as a SEV 2 on a scale of 0 to 5, with 0 being the most severe.

A Meta spokesperson confirmed the incident and said the company is investigating.

“We have carefully designed this program with privacy safeguards, and while we have no indication at this time that any data was improperly accessed by Meta employees, we’re pausing it while we investigate,” the spokesperson said.

In April, Meta announced the AI training program, called the Model Capability Initiative (MCI), which was intended to improve the company’s AI models by using its staff’s keystrokes and mouse movements as training data. The program, which is mandatory for most staff, sparked a backlash from employees who felt uncomfortable with their data being recorded, Business Insider previously reported.

This leak is causing frustration within Meta, according to screenshots seen by Business Insider, with employees critical that data wasn’t locked down from the start.

“I am incensed,” one employee wrote on Monday about the recent leak in an internal group, according to a screenshot obtained by Business Insider.

Keep reading

Missouri AG Catherine Hanaway Launches Lawsuit Against Baby Monitors and Home Cameras Company ‘Lorex’ Over Concealed CCP and Chinese Military Ties

Missouri Attorney General Catherine Hanaway is taking aim at a major surveillance technology company over what she says are hidden ties to the Chinese Communist Party and the Chinese military.

Hanaway announced legal action against Lorex, a popular manufacturer of baby monitors, home security cameras, and surveillance systems sold by major American retailers including Costco, Best Buy, and Amazon.

“Families and retailers like Costco, Best Buy, and Amazon are being lied to,” Hanaway wrote. “Lorex, a leading manufacturer of baby monitors and home cameras, is concealing material ties to the CCP and Chinese military. We’re taking them to court.”

The company’s products have maintained deep ties to Dahua, its former owner and ongoing supplier of critical components, even after Dahua was designated a Chinese Military Company that poses a direct threat to U.S. national security. Researchers found Lorex firmware routing straight back to Dahua servers, giving the Chinese Communist Party potential real-time access to the most intimate moments inside American homes.

These are the cameras watching babies breathe in their cribs. Recording children’s voices. Capturing family life in bedrooms and living rooms across Missouri and the country. Sold at Costco, Best Buy, Amazon, Staples, Menards, Micro Center, Office Depot, and directly through Lorex’s own site.

“The hand that rocks the cradle rules the world,” Attorney General Hanaway said in a statement. “Missouri will not allow the CCP to put its hand on our cradles. Parents place these cameras over cribs and in bedrooms to protect their children, not to invite a foreign adversary into their homes.”

“Lorex tells families its video cameras are ‘private by design’ while concealing ties to a Chinese military company,” she continued. “These cameras watch our babies breathe, capture our children’s voices, and record families’ most intimate moments. When companies won’t tell the truth about their connection to hostile foreign governments, my office will step in to protect families.”

The lawsuit, brought under Missouri’s Merchandising Practices Act, seeks up to $1,000 in restitution for every Missouri consumer who purchased a Lorex camera in the last five years, plus more than $1.8 million in damages and a court order barring the company from continuing its deceptive practices.

Keep reading