Vue normale

Aujourd’hui — 18 juin 2025Flux principal
  • ✇404 Media
  • Podcast: Airlines Sold Your Flight Data to DHS—And Covered It Up
    This week we start with Joseph’s article about the U.S’s major airlines selling customers’ flight information to Customs and Border Protection and then telling the agency to not reveal where the data came from. After the break, Emanuel tells us how AI scraping bots are breaking open libraries, archives, and museums. In the subscribers-only section, Jason explains the casual surveillance relationship between ICE and local cops, according to emails he got. Listen to the weekly podcast on App
     

Podcast: Airlines Sold Your Flight Data to DHS—And Covered It Up

18 juin 2025 à 09:00
Podcast: Airlines Sold Your Flight Data to DHS—And Covered It Up

This week we start with Joseph’s article about the U.S’s major airlines selling customers’ flight information to Customs and Border Protection and then telling the agency to not reveal where the data came from. After the break, Emanuel tells us how AI scraping bots are breaking open libraries, archives, and museums. In the subscribers-only section, Jason explains the casual surveillance relationship between ICE and local cops, according to emails he got.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

Hier — 17 juin 2025Flux principal
  • ✇404 Media
  • California Cops Investigate ‘Immigration Protest’ With AI-Camera System
    📄This article was primarily reported using public records requests. We are making it available to all readers as a public service. FOIA reporting can be expensive, please consider subscribing to 404 Media to support this work. Or send us a one time donation via our tip jar here.A California police department searched AI-enabled, automatic license plate reader (ALPR) cameras in relation to an “immigration protest,” according to internal police data obtained by 404 Media. The data also shows that
     

California Cops Investigate ‘Immigration Protest’ With AI-Camera System

17 juin 2025 à 11:15
📄
This article was primarily reported using public records requests. We are making it available to all readers as a public service. FOIA reporting can be expensive, please consider subscribing to 404 Media to support this work. Or send us a one time donation via our tip jar here.
California Cops Investigate ‘Immigration Protest’ With AI-Camera System

A California police department searched AI-enabled, automatic license plate reader (ALPR) cameras in relation to an “immigration protest,” according to internal police data obtained by 404 Media. The data also shows that police departments and sheriff offices around the country have repeatedly tapped into the cameras inside California, made by a company called Flock, on behalf of Immigration and Customs Enforcement (ICE), digitally reaching into the sanctuary state in a data sharing practice that experts say is illegal. 

Flock allows participating agencies to search not only cameras in their jurisdiction or state, but nationwide, meaning that local police that may work directly with ICE on immigration enforcement are able to search cameras inside California or other states. But this data sharing is only possible because California agencies have opted-in to sharing it with agencies in other states, making them legally responsible for the data sharing. 

The news raises questions about whether California agencies are enforcing the law on their own data sharing practices, threatens to undermine the state’s perception as a sanctuary state, and highlights the sort of surveillance or investigative tools law enforcement may deploy at immigration related protests. Over the weekend, millions of people attended No Kings protests across the U.S. 404 Media’s findings come after we revealed police were searching cameras in Illinois on behalf of ICE, and then Cal Matters found local law enforcement agencies in California were searching cameras for ICE too.

  • ✇404 Media
  • The People Search Sites in the Suspected Minnesota Killer's Notebook Are a Failure of Congress
    On Monday, federal and state authorities charged Vance Boelter with the murders of Minnesota Rep. Melissa Hortman and her husband. An affidavit written by an FBI Special Agent, published here by MSNBC, includes photos of a notepad found in Boelter’s SUV which included a long list of people search sites, some of which make it very easy for essentially anyone to find the address and other personal information of someone else in the U.S. The SUV contained other notebooks and some pages included
     

The People Search Sites in the Suspected Minnesota Killer's Notebook Are a Failure of Congress

17 juin 2025 à 10:23
The People Search Sites in the Suspected Minnesota Killer's Notebook Are a Failure of Congress

On Monday, federal and state authorities charged Vance Boelter with the murders of Minnesota Rep. Melissa Hortman and her husband. An affidavit written by an FBI Special Agent, published here by MSNBC, includes photos of a notepad found in Boelter’s SUV which included a long list of people search sites, some of which make it very easy for essentially anyone to find the address and other personal information of someone else in the U.S. The SUV contained other notebooks and some pages included the names of more than 45 Minnesota state and federal public officials, including Hortman, the affidavit says. Hortman’s home address was listed next to her name, it adds.

People search sites can present a risk to citizen’s privacy, and, depending on the context, physical safety. They aggregate data from property records, social media, marriage licenses, and other places and make it accessible to even those with no tech savvy. Some are free, some are paid, and some require a user to tick a box confirming they’re only using the data for certain permitted use cases. 

Congress has known about the risk of data for decades. In 1994 lawmakers created the Driver’s Privacy Protection Act (DPPA) after a stalker hired a private investigator who then obtained the address of actress Rebecca Schaeffer from a DMV. The stalker then murdered Schaeffer. With people search sites, though, lawmakers have been largely motionless, despite them existing for years, on the open web, accessible by a Google search and sometimes even promoted with Google advertisements.

Senator Ron Wyden said in a statement “The accused Minneapolis assassin allegedly used data brokers as a key part of his plot to track down and murder Democratic lawmakers. Congress doesn't need any more proof that people are being killed based on data for sale to anyone with a credit card. Every single American's safety is at risk until Congress cracks down on this sleazy industry.”

This notepad does not necessarily mean that Boelter used these specific sites to find Hortman’s or other officials’ addresses. As the New York Times noted, Hortman’s address was on her campaign website, and Minnesota State Senator John Hoffman, who Boelter allegedly shot along with Hoffman’s wife, listed his address on his official legislative webpage.

The sites’ inclusion shows they are of high interest to a person who allegedly murdered and targeted multiple officials and their families in an act of political violence. Next to some of the people search site names, Boelter appears to have put a star or tick.

Those people search sites are:

A spokesperson for Atlas, a company that is suing a variety of people search sites, said “Tragedies like this might be prevented if data brokers simply complied with state and federal privacy laws. Our company has been in court for more than 15 months litigating against each of the eleven data brokers identified in the alleged shooter’s writings, seeking to hold them accountable for refusing to comply with New Jersey’s Daniel’s Law which seeks to protect the home addresses of judges, prosecutors, law enforcement and their families. This industry’s purposeful refusal to comply with privacy laws has and continues to endanger thousands of public servants and their families.” 

404 Media has repeatedly reported on how data can be weaponized against people. We found violent criminals and hackers were able to dox nearly anyone in the U.S. for $15, using bots that were based on data people had given as part of opening credit cards. In 2023 Verizon gave sensitive information, including an address on file, of one of its customers to her stalker, who then drove to the address armed with a knife.

404 Media was able to contact most of the people search sites for comment. None responded.

Update: this piece has been updated to include a statement from Atlas. An earlier version of this piece accidentally published a version with a different structure; this correct version includes more information about the DPPA.

À partir d’avant-hierFlux principal
  • ✇404 Media
  • I Tried Pre-Ordering the Trump Phone. The Page Failed and It Charged My Credit Card the Wrong Amount
    On Monday the Trump Organization announced its own mobile service plan and the “​​T1 Phone,” a customized all-gold mobile phone that its creators say will be made in America. I tried to pre-order the phone and pay the $100 downpayment, hoping to test the phone to see what apps come pre-installed, how secure it really is, and what components it includes when it comes out. The website failed, went to an error page, and then charged my credit card the wrong amount of $64.70. I received a confirm
     

I Tried Pre-Ordering the Trump Phone. The Page Failed and It Charged My Credit Card the Wrong Amount

16 juin 2025 à 12:36
I Tried Pre-Ordering the Trump Phone. The Page Failed and It Charged My Credit Card the Wrong Amount

On Monday the Trump Organization announced its own mobile service plan and the “​​T1 Phone,” a customized all-gold mobile phone that its creators say will be made in America. 

I tried to pre-order the phone and pay the $100 downpayment, hoping to test the phone to see what apps come pre-installed, how secure it really is, and what components it includes when it comes out. The website failed, went to an error page, and then charged my credit card the wrong amount of $64.70. I received a confirmation email saying I’ll receive a confirmation when my order has been shipped, but I haven’t provided a shipping address or paid the full $499 price tag. It is the worst experience I’ve ever faced buying a consumer electronic product and I have no idea whether or how I’ll receive the phone.

“Trump Mobile is going to change the game, we’re building on the movement to put America first, and we will deliver the highest levels of quality and service. Our company is based right here in the United States because we know it’s what our customers want and deserve,” Donald Trump Jr., EVP of the Trump Organization, and obviously one of President Trump’s sons, said in a press release announcing Trump Mobile

  • ✇404 Media
  • Behind the Blog: Advertising and Aircraft
    This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss advertising, protests, and aircraft.EMANUEL: On Thursday Meta announced that it has filed a lawsuit in Hong Kong against Joy Timeline HK Limited, the company that operates a popular nudify app called Crush that we have covered previously. Meta’s position is that it hasn’t been able to prevent Crush from advertising its nudify app on its pla
     

Behind the Blog: Advertising and Aircraft

13 juin 2025 à 11:58
Behind the Blog: Advertising and Aircraft

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss advertising, protests, and aircraft.

EMANUEL: On Thursday Meta announced that it has filed a lawsuit in Hong Kong against Joy Timeline HK Limited, the company that operates a popular nudify app called Crush that we have covered previously

Meta’s position is that it hasn’t been able to prevent Crush from advertising its nudify app on its platform despite it violating its policies because Crush is “highly adversarial” and “constantly evolving their tactics to avoid enforcement.” We’ve seen Crush and other nudify apps create hundreds of Meta advertising accounts and different domain names that all link back to the same service in order to avoid detection. If Meta bans an advertising account or URL, Crush simply creates another. In theory, Meta always has ways of detecting if an ad contains nudity, but nudify apps can easily circumvent those measures as well. As I say in my post about the lawsuit, Meta still hasn’t explained why it appears to have different standards for content in ads versus regular posts on its platform, but there’s no doubt that it does take action against nudify ads when it’s easy for it do so, and that these nudify ads are actively trying to avoid Meta’s moderation when it does attempt to get rid of them. 

  • ✇404 Media
  • CBP Confirms It Is Flying Predator Drones Above Los Angeles To Support ICE
    Customs and Border Protection (CBP) has confirmed it is flying Predator drones above the Los Angeles protests, and specifically in support of Immigration and Customs Enforcement (ICE), according to a CBP statement sent to 404 Media. The statement follows 404 Media’s reporting that the Department of Homeland Security (DHS) has flown two Predator drones above Los Angeles, according to flight data and air traffic control (ATC) audio.The statement is the first time CBP has acknowledged the existe
     

CBP Confirms It Is Flying Predator Drones Above Los Angeles To Support ICE

11 juin 2025 à 15:28
CBP Confirms It Is Flying Predator Drones Above Los Angeles To Support ICE

Customs and Border Protection (CBP) has confirmed it is flying Predator drones above the Los Angeles protests, and specifically in support of Immigration and Customs Enforcement (ICE), according to a CBP statement sent to 404 Media. The statement follows 404 Media’s reporting that the Department of Homeland Security (DHS) has flown two Predator drones above Los Angeles, according to flight data and air traffic control (ATC) audio.

The statement is the first time CBP has acknowledged the existence of these drone flights, which over the weekend were done without a callsign, making it more difficult, but not impossible, to determine what model of aircraft was used and by which agency. It is also the first time CBP has said it is using the drones to help ICE during the protests.

  • ✇404 Media
  • Our New FOIA Forum! 6/18, 1PM ET
    It’s that time again! We’re planning our latest FOIA Forum, a live, hour-long or more interactive session where Joseph and Jason (and this time Emanuel too maybe) will teach you how to pry records from government agencies through public records requests. We’re planning this for Wednesday, 18th at 1 PM Eastern. That's in just one week today! Add it to your calendar! So, what’s the FOIA Forum? We'll share our screen and show you specifically how we file FOIA requests. We take questions from the
     

Our New FOIA Forum! 6/18, 1PM ET

11 juin 2025 à 12:22
Our New FOIA Forum! 6/18, 1PM ET

It’s that time again! We’re planning our latest FOIA Forum, a live, hour-long or more interactive session where Joseph and Jason (and this time Emanuel too maybe) will teach you how to pry records from government agencies through public records requests. We’re planning this for Wednesday, 18th at 1 PM Eastern. That's in just one week today! Add it to your calendar! 

So, what’s the FOIA Forum? We'll share our screen and show you specifically how we file FOIA requests. We take questions from the chat and incorporate those into our FOIAs in real-time. We’ll also check on some requests we filed last time. This time we're particularly focused on Jason's and Emanuel's article about Massive Blue, a company that helps cops deploy AI-powered fake personas. The article, called This ‘College Protester’ Isn’t Real. It’s an AI-Powered Undercover Bot for Cops, is here. This was heavily based on public records requests. We'll show you how we did them!

If this will be your first FOIA Forum, don’t worry, we will do a quick primer on how to file requests (although if you do want to watch our previous FOIA Forums, the video archive is here). We really love talking directly to our community about something we are obsessed with (getting documents from governments) and showing other people how to do it too.

Paid subscribers can already find the link to join the livestream below. We'll also send out a reminder a day or so before. Not a subscriber yet? Sign up now here in time to join.

We've got a bunch of FOIAs that we need to file and are keen to hear from you all on what you want to see more of. Most of all, we want to teach you how to make your own too. Please consider coming along!

Our New FOIA Forum! 6/18, 1PM ET
  • ✇404 Media
  • Podcast: Feds Flew Predator Drones Over The LA Protests
    Much of this episode is about the ongoing anti-ICE protests in Los Angeles. We start with Joseph explaining how he monitored surveillance aircraft flying over the protests, including what turned out to be a Predator drone. After the break, Jason tells us about the burning Waymos. In the subscribers-only section, we talk about the owner of Girls Do Porn, a sex trafficking ring on Pornhub, pleading guilty. Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid sub
     

Podcast: Feds Flew Predator Drones Over The LA Protests

11 juin 2025 à 09:00
Podcast: Feds Flew Predator Drones Over The LA Protests

Much of this episode is about the ongoing anti-ICE protests in Los Angeles. We start with Joseph explaining how he monitored surveillance aircraft flying over the protests, including what turned out to be a Predator drone. After the break, Jason tells us about the burning Waymos. In the subscribers-only section, we talk about the owner of Girls Do Porn, a sex trafficking ring on Pornhub, pleading guilty.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  • ✇404 Media
  • DHS Flew Predator Drones Over LA Protests, Audio Shows
    The Department of Homeland Security (DHS) flew two high-powered Predator surveillance drones above the anti-ICE protests in Los Angeles over the weekend, according to air traffic control (ATC) audio unearthed by an aviation tracking enthusiast then reviewed by 404 Media and cross-referenced with flight data.The use of Predator drones highlights the extraordinary resources government agencies are putting behind surveilling and responding to the Los Angeles protests, which started after ICE age
     

DHS Flew Predator Drones Over LA Protests, Audio Shows

10 juin 2025 à 11:49
DHS Flew Predator Drones Over LA Protests, Audio Shows

The Department of Homeland Security (DHS) flew two high-powered Predator surveillance drones above the anti-ICE protests in Los Angeles over the weekend, according to air traffic control (ATC) audio unearthed by an aviation tracking enthusiast then reviewed by 404 Media and cross-referenced with flight data.

The use of Predator drones highlights the extraordinary resources government agencies are putting behind surveilling and responding to the Los Angeles protests, which started after ICE agents raided a Home Depot on Friday. President Trump has since called up 4,000 members of the National Guard, and on Monday ordered more than 700 active duty Marines to the city too.

“TROY703, traffic 12 o'clock, 8 miles, opposite direction, another 'TROY' Q-9 at FL230,” one part of the ATC audio says. The official name of these types of Predator B drones, made by a company called General Atomics, is the MQ-9 Reaper.

On Monday 404 Media reported that all sorts of agencies, from local, to state, to DHS, to the military flew aircraft over the Los Angeles protests. That included a DHS Black Hawk, a California Highway Patrol small aircraft, and two aircraft that took off from nearby March Air Reserve Base.

DHS Flew Predator Drones Over LA Protests, Audio Shows
ATC Audio Mentioning TROY and Q-9s
0:00
/21.577142857142857
  • ✇404 Media
  • Airlines Don't Want You to Know They Sold Your Flight Data to DHS
    📄This article was primarily reported using public records requests. We are making it available to all readers as a public service. FOIA reporting can be expensive, please consider subscribing to 404 Media to support this work. Or send us a one time donation via our tip jar here.This article was produced with support from WIRED.A data broker owned by the country’s major airlines, including Delta, American Airlines, and United, collected U.S. travellers’ domestic flight records, sold access to the
     

Airlines Don't Want You to Know They Sold Your Flight Data to DHS

10 juin 2025 à 09:00
📄
This article was primarily reported using public records requests. We are making it available to all readers as a public service. FOIA reporting can be expensive, please consider subscribing to 404 Media to support this work. Or send us a one time donation via our tip jar here.
Airlines Don't Want You to Know They Sold Your Flight Data to DHS

This article was produced with support from WIRED.

A data broker owned by the country’s major airlines, including Delta, American Airlines, and United, collected U.S. travellers’ domestic flight records, sold access to them to Customs and Border Protection (CBP), and then as part of the contract told CBP to not reveal where the data came from, according to internal CBP documents obtained by 404 Media. The data includes passenger names, their full flight itineraries, and financial details. 

CBP, a part of the Department of Homeland Security (DHS), says it needs this data to support state and local police to track people of interest’s air travel across the country, in a purchase that has alarmed civil liberties experts.

The documents reveal for the first time in detail why at least one part of DHS purchased such information, and comes after Immigration and Customs Enforcement (ICE) detailed its own purchase of the data. The documents also show for the first time that the data broker, called the Airlines Reporting Corporation (ARC), tells government agencies not to mention where it sourced the flight data from.

  • ✇404 Media
  • A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account
    This article was produced with support from WIRED.A cybersecurity researcher was able to figure out the phone number linked to any Google account, information that is usually not public and is often sensitive, according to the researcher, Google, and 404 Media’s own tests.The issue has since been fixed but at the time presented a privacy issue in which even hackers with relatively few resources could have brute forced their way to peoples’ personal information.“I think this exploit is pretty
     

A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account

9 juin 2025 à 10:00
A Researcher Figured Out How to Reveal Any Phone Number Linked to a Google Account

This article was produced with support from WIRED.

A cybersecurity researcher was able to figure out the phone number linked to any Google account, information that is usually not public and is often sensitive, according to the researcher, Google, and 404 Media’s own tests.

The issue has since been fixed but at the time presented a privacy issue in which even hackers with relatively few resources could have brute forced their way to peoples’ personal information.

“I think this exploit is pretty bad since it's basically a gold mine for SIM swappers,” the independent security researcher who found the issue, who goes by the handle brutecat, wrote in an email. SIM swappers are hackers who take over a target's phone number in order to receive their calls and texts, which in turn can let them break into all manner of accounts.

In mid-April, we provided brutecat with one of our personal Gmail addresses in order to test the vulnerability. About six hours later, brutecat replied with the correct and full phone number linked to that account.

“Essentially, it's bruting the number,” brutecat said of their process. Brute forcing is when a hacker rapidly tries different combinations of digits or characters until finding the ones they’re after. Typically that’s in the context of finding someone’s password, but here brutecat is doing something similar to determine a Google user’s phone number. 

  • ✇404 Media
  • DHS Black Hawks and Military Aircraft Surveil the LA Protests
    Over the weekend in Los Angeles, as National Guard troops deployed into the city, cops shot a journalist with less-lethal rounds, and Waymo cars burned, the skies were bustling with activity. The Department of Homeland Security (DHS) flew Black Hawk helicopters; multiple aircraft from a nearby military air base circled repeatedly overhead; and one aircraft flew at an altitude and in a particular pattern consistent with a high-powered surveillance drone, according to public flight data reviewe
     

DHS Black Hawks and Military Aircraft Surveil the LA Protests

9 juin 2025 à 09:33
DHS Black Hawks and Military Aircraft Surveil the LA Protests

Over the weekend in Los Angeles, as National Guard troops deployed into the city, cops shot a journalist with less-lethal rounds, and Waymo cars burned, the skies were bustling with activity. The Department of Homeland Security (DHS) flew Black Hawk helicopters; multiple aircraft from a nearby military air base circled repeatedly overhead; and one aircraft flew at an altitude and in a particular pattern consistent with a high-powered surveillance drone, according to public flight data reviewed by 404 Media.

The data shows that essentially every sort of agency, from local police, to state authorities, to federal agencies, to the military, had some sort of presence in the skies above the ongoing anti-Immigration Customs and Enforcement (ICE) protests in Los Angeles. The protests started on Friday in response to an ICE raid at a Home Depot; those tensions flared when President Trump ordered the National Guard to deploy into the city.

  • ✇404 Media
  • Behind the Blog: Activism and Evangelism
    This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss the phrase "activist reporter," waiting in line for a Switch 2, and teledildonics.JOSEPH: Recently our work on Flock, the automatic license plate reader (ALPR) company, produced some concrete impact. In mid-May I revealed that Flock was building a massive people search tool that would supplement its ALPR data with other information in order
     

Behind the Blog: Activism and Evangelism

6 juin 2025 à 12:24
Behind the Blog: Activism and Evangelism

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss the phrase "activist reporter," waiting in line for a Switch 2, and teledildonics.

JOSEPH: Recently our work on Flock, the automatic license plate reader (ALPR) company, produced some concrete impact. In mid-May I revealed that Flock was building a massive people search tool that would supplement its ALPR data with other information in order to “jump from LPR to person.” That is, identify the people associated with a vehicle and those associated with them. Flock planned to do this with public records like marriage licenses, and, most controversially, hacked data. This was according to leaked Slack chats, presentation slides, and audio we obtained. The leak specifically mentioned a hack of the Park Mobile app as the sort of breached data Flock might use.

After internal pressure in the company and our reporting, Flock ultimately decided to not use hacked data in Nova. We covered the news last week here. We also got audio of the meeting discussing this change. Flock published its own disingenuous blog post entitled Correcting the Record: Flock Nova Will Not Supply Dark Web Data, which attempted to discredit our reporting but didn’t actually find any factual inaccuracies at all. It was a PR move, and the article and its impact obviously stand.

  • ✇404 Media
  • Apple Gave Governments Data on Thousands of Push Notifications
    Apple provided governments around the world with data related to thousands of push notifications sent to its devices, which can identify a target’s specific device or in some cases include unencrypted content like the actual text displayed in the notification, according to data published by Apple. In one case, that Apple did not ultimately provide data for, Israel demanded data related to nearly 700 push notifications as part of a single request.The data for the first time puts a concrete fig
     

Apple Gave Governments Data on Thousands of Push Notifications

4 juin 2025 à 12:59
Apple Gave Governments Data on Thousands of Push Notifications

Apple provided governments around the world with data related to thousands of push notifications sent to its devices, which can identify a target’s specific device or in some cases include unencrypted content like the actual text displayed in the notification, according to data published by Apple. In one case, that Apple did not ultimately provide data for, Israel demanded data related to nearly 700 push notifications as part of a single request.

The data for the first time puts a concrete figure on how many requests governments around the world are making, and sometimes receiving, for push notification data from Apple. 

The practice first came to light in 2023 when Senator Ron Wyden sent a letter to the U.S. Department of Justice revealing the practice, which also applied to Google. As the letter said, “the data these two companies receive includes metadata, detailing which app received a notification and when, as well as the phone and associated Apple or Google account to which that notification was intended to be delivered. In certain instances, they also might also receive unencrypted content, which could range from backend directives for the app to the actual text displayed to a user in an app notification.” 

  • ✇404 Media
  • Podcast: Anti-Porn Laws' Real Target Is Free Speech
    We start this week with Sam's dive into a looming piece of anti-porn legislation, prudish algorithms, and eggs. After the break, Matthew tells us about the open source software that powered Ukraine's drone attack against Russia. In the subscribers-only section, Emanuel explains how even pro-AI subreddits are dealing with people having AI delusions. Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to
     

Podcast: Anti-Porn Laws' Real Target Is Free Speech

4 juin 2025 à 06:00
Podcast: Anti-Porn Laws' Real Target Is Free Speech

We start this week with Sam's dive into a looming piece of anti-porn legislation, prudish algorithms, and eggs. After the break, Matthew tells us about the open source software that powered Ukraine's drone attack against Russia. In the subscribers-only section, Emanuel explains how even pro-AI subreddits are dealing with people having AI delusions.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  • ✇404 Media
  • Flock Decides Not to Use Hacked Data in People Search Tool
    The surveillance company Flock told employees at an all-hands meeting Friday that its new people search product, Nova, will not include hacked data from the dark web. The announcement comes a little over a week after 404 Media broke the news about internal tension at the company about plans to use breached data, including from a 2021 Park Mobile data break.Immediately following the all-hands meeting, Flock published details of its decision in a public blog post it says is designed to "correct
     

Flock Decides Not to Use Hacked Data in People Search Tool

30 mai 2025 à 14:07
Flock Decides Not to Use Hacked Data in People Search Tool

The surveillance company Flock told employees at an all-hands meeting Friday that its new people search product, Nova, will not include hacked data from the dark web. The announcement comes a little over a week after 404 Media broke the news about internal tension at the company about plans to use breached data, including from a 2021 Park Mobile data break.

Immediately following the all-hands meeting, Flock published details of its decision in a public blog post it says is designed to "correct the record on what Flock Nova actually does and does not do." The company said that following a "lengthy, intentional process" about what data sources it would use and how the product would work, it has decided not to supply customers with dark web data.

"The policy decision was also made that Flock will not supply dark web data," the company wrote. "This means that Nova will not supply any data purchased from known data breaches or stolen data."

Flock Nova is a new people search tool in which police will be able to connect license plate data from Flock’s automated license plate readers with other data sources in order to in some cases more easily determine who a car may belong to and people they might associate with.

404 Media previously reported on internal meetings, presentation slides, discussions, and Slack messages in which the company discussed how Nova would work. Part of those discussions centered on the data sources that could be used in the product. “You're going to be able to access data and jump from LPR to person and understand what that context is, link to other people that are related to that person [...] marriage or through gang affiliation, et cetera,” a Flock employee said during an internal company meeting, according to an audio recording. “There’s very powerful linking.”

In meeting audio obtained by 404 Media, an employee discussed the potential use of the hacked Park Mobile data, which became controversial within the company

“I was pretty horrified to hear we use stolen data in our system. In addition to being attained illegally, it seems like that could create really perverse incentives for more data to be leaked and stolen,” one employee wrote on Slack in a message seen by 404 Media. “What if data was stolen from Flock? Should that then become standard data in everyone else’s system?”

In Friday’s all-hands meeting with employees, a Flock executive said that it was previously “talking about capabilities that were possible to use with Nova, not that we were necessarily going to implement when we use Nova. And in particular one of those issues was about dark web data. Would Flock be able to supply that to our law enforcement customers to solve some really heinous crimes like internet crimes against children? Child pornography, human trafficking, some really horrible parts of society.”

“We took this concept of using dark web data in Nova and explored it because investigators told us they wanted to do it,” the Flock executive said in audio reviewed by 404 Media. “Then we ran it through our policy review process, which by the way this is what we do for all our new products and services. We ran this concept through the policy review process, we vetted it with product leaders, with our executive team, and we made the decision to not supply dark web data through the Nova platform to law enforcement at all.”

Flock said in its Friday blog that the company will supply customers with "public records information, Open-Source intelligence, and license plate reader data." The company said its customers can also connect their own data into the program, including their own records management systems, computer-aided dispatch, and jail records "as well as all of the above from other agencies who agree to share that data." 

As 404 Media has repeatedly reported, the fact that Flock allows its customers to share data with a huge network of police is what differentiates Flock as a surveillance tool. Its automated license plate readers collect data, which can then be shared as part of either a searchable statewide or nationwide network of ALPR data. 

  • ✇404 Media
  • Behind the Blog: Lighting Money on Fire and the Meaning of Vetting
    This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss an exciting revamp of The Abstract, tech betrayals, and the "it's for cops" defense.EMANUEL: Most of you already know this but we are expanding The Abstract, our Saturday science newsletter by the amazing Becky Ferreira. The response to The Abstract since we launched it last year has been very positive. People have been writing in to let us
     

Behind the Blog: Lighting Money on Fire and the Meaning of Vetting

30 mai 2025 à 12:56
Behind the Blog: Lighting Money on Fire and the Meaning of Vetting

This is Behind the Blog, where we share our behind-the-scenes thoughts about how a few of our top stories of the week came together. This week, we discuss an exciting revamp of The Abstract, tech betrayals, and the "it's for cops" defense.

EMANUEL: Most of you already know this but we are expanding The Abstract, our Saturday science newsletter by the amazing Becky Ferreira. The response to The Abstract since we launched it last year has been very positive. People have been writing in to let us know how much they appreciate the newsletter as a nice change of pace from our usual coverage areas and that they look forward to it all week, etc. 

First, as you probably already noticed, The Abstract is now its own separate newsletter that you can choose to get in your inbox every Saturday. This is separate from our daily newsletter and the weekend roundup you’re reading right now. If you don’t want to get The Abstract newsletter, you can unsubscribe from it like you would from all our other newsletters. For detailed instructions on how to do that, please read the top of this edition of The Abstract

  • ✇404 Media
  • A Texas Cop Searched License Plate Cameras Nationwide for a Woman Who Got an Abortion
    Earlier this month authorities in Texas performed a nationwide search of more than 83,000 automatic license plate reader (ALPR) cameras while looking for a woman who they said had a self-administered abortion, including cameras in states where abortion is legal such as Washington and Illinois, according to multiple datasets obtained by 404 Media.The news shows in stark terms how police in one state are able to take the ALPR technology, made by a company called Flock and usually marketed to in
     

A Texas Cop Searched License Plate Cameras Nationwide for a Woman Who Got an Abortion

29 mai 2025 à 13:35
A Texas Cop Searched License Plate Cameras Nationwide for a Woman Who Got an Abortion

Earlier this month authorities in Texas performed a nationwide search of more than 83,000 automatic license plate reader (ALPR) cameras while looking for a woman who they said had a self-administered abortion, including cameras in states where abortion is legal such as Washington and Illinois, according to multiple datasets obtained by 404 Media.

The news shows in stark terms how police in one state are able to take the ALPR technology, made by a company called Flock and usually marketed to individual communities to stop carjackings or find missing people, and turn it into a tool for finding people who have had abortions. In this case, the sheriff told 404 Media the family was worried for the woman’s safety and so authorities used Flock in an attempt to locate her. But health surveillance experts said they still had issues with the nationwide search. 

“You have this extraterritorial reach into other states, and Flock has decided to create a technology that breaks through the barriers, where police in one state can investigate what is a human right in another state because it is a crime in another,” Kate Bertash of the Digital Defense Fund, who researches both ALPR systems and abortion surveillance, told 404 Media. 

  • ✇404 Media
  • Podcast: ICE's 'Backdoor' Into a Nationwide AI Surveillance Network
    This week is a bumper episode all about Flock, the automatic license plate reading (ALPR) cameras across the U.S. First, Jason explains how we found that ICE essentially has backdoor access to the network through local cops. After the break, Joseph tells us all about Nova, the planned product that Flock is making which will make the technology even more invasive by using hacked data. In the subscribers-only section, Emanuel details the massive changes AI platform Civitai has made, and why it'
     

Podcast: ICE's 'Backdoor' Into a Nationwide AI Surveillance Network

28 mai 2025 à 09:00
Podcast: ICE's 'Backdoor' Into a Nationwide AI Surveillance Network

This week is a bumper episode all about Flock, the automatic license plate reading (ALPR) cameras across the U.S. First, Jason explains how we found that ICE essentially has backdoor access to the network through local cops. After the break, Joseph tells us all about Nova, the planned product that Flock is making which will make the technology even more invasive by using hacked data. In the subscribers-only section, Emanuel details the massive changes AI platform Civitai has made, and why it's partly in response to our reporting.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  • ✇404 Media
  • The CIA Secretly Ran a Star Wars Fan Site
    “Like these games you will,” the quote next to a cartoon image of Yoda says on the website starwarsweb.net. Those games include Star Wars Battlefront 2 for Xbox; Star Wars: The Force Unleashed II for Xbox 360, and Star Wars the Clone Wars: Republic Heroes for Nintendo Wii. Next to that, are links to a Star Wars online store with the tagline “So you Wanna be a Jedi?” and an advert for a Lego Star Wars set.The site looks like an ordinary Star Wars fan website from around 2010. But starwarsweb.n
     

The CIA Secretly Ran a Star Wars Fan Site

26 mai 2025 à 09:00
The CIA Secretly Ran a Star Wars Fan Site

“Like these games you will,” the quote next to a cartoon image of Yoda says on the website starwarsweb.net. Those games include Star Wars Battlefront 2 for Xbox; Star Wars: The Force Unleashed II for Xbox 360, and Star Wars the Clone Wars: Republic Heroes for Nintendo Wii. Next to that, are links to a Star Wars online store with the tagline “So you Wanna be a Jedi?” and an advert for a Lego Star Wars set.

The site looks like an ordinary Star Wars fan website from around 2010. But starwarsweb.net was actually a tool built by the Central Intelligence Agency (CIA) to covertly communicate with its informants in other countries, according to an amateur security researcher. The site was part of a network of CIA sites that were first discovered by Iranian authorities more than ten years ago before leading to a wave of deaths of CIA sources in China in the early 2010s.

  • ✇404 Media
  • Hacker Conference HOPE Says U.S. Immigration Crackdown Caused Massive Crash in Ticket Sales
    Hackers On Planet Earth (HOPE), the iconic and long-running hacking conference, says far fewer people have bought tickets for the event this year as compared to last, with organizers believing it is due to the Trump administration’s mass deportation efforts and more aggressive detainment of travellers into the U.S.“We are roughly 50 percent behind last year’s sales, based on being 3 months away from the event,” Greg Newby, one of HOPE’s organizers, told 404 Media in an email. According to hac
     

Hacker Conference HOPE Says U.S. Immigration Crackdown Caused Massive Crash in Ticket Sales

22 mai 2025 à 10:30
Hacker Conference HOPE Says U.S. Immigration Crackdown Caused Massive Crash in Ticket Sales

Hackers On Planet Earth (HOPE), the iconic and long-running hacking conference, says far fewer people have bought tickets for the event this year as compared to last, with organizers believing it is due to the Trump administration’s mass deportation efforts and more aggressive detainment of travellers into the U.S.

“We are roughly 50 percent behind last year’s sales, based on being 3 months away from the event,” Greg Newby, one of HOPE’s organizers, told 404 Media in an email. According to hacking collective and magazine 2600, which organizes HOPE, the conference usually has around 1,000 attendees and the event is almost entirely funded by ticket sales. “Having fewer international attendees hurts the conference program, as well as the bottom line,” a planned press release says.

  • ✇404 Media
  • Podcast: AI Slop Summer
    We start this week with Jason's couple of stories about how the Chicago Sun-Times printed a summer guide that was basically all AI-generated. Jason spoke to the person behind it. After the break, a bunch of documents show that schools were simply not ready for AI. In the subscribers-only section, we chat all about Star Wars and those funny little guys. Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content an
     

Podcast: AI Slop Summer

21 mai 2025 à 09:00
Podcast: AI Slop Summer

We start this week with Jason's couple of stories about how the Chicago Sun-Times printed a summer guide that was basically all AI-generated. Jason spoke to the person behind it. After the break, a bunch of documents show that schools were simply not ready for AI. In the subscribers-only section, we chat all about Star Wars and those funny little guys.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

  • ✇404 Media
  • License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows
    Flock, the automatic license plate reader (ALPR) company whose cameras are installed in more than 5,000 communities in the U.S., is building a product that will use people lookup tools, data brokers, and data breaches to “jump from LPR [license plate reader] to person,” allowing police to much more easily identify and track the movements of specific people around the country without a warrant or court order, according to internal Flock presentation slides, Slack chats, and meeting audio obtai
     

License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows

14 mai 2025 à 09:55
License Plate Reader Company Flock Is Building a Massive People Lookup Tool, Leak Shows

Flock, the automatic license plate reader (ALPR) company whose cameras are installed in more than 5,000 communities in the U.S., is building a product that will use people lookup tools, data brokers, and data breaches to “jump from LPR [license plate reader] to person,” allowing police to much more easily identify and track the movements of specific people around the country without a warrant or court order, according to internal Flock presentation slides, Slack chats, and meeting audio obtained by 404 Media.

The news turns Flock, already a controversial technology, into a much more invasive tool, potentially able to link a vehicle passing by a camera to its owner and then more people connected to them, through marriage or other association. The new product development has also led to Flock employees questioning the ethics of using hacked data as part of their surveillance product, according to the Slack chats. Flock told 404 Media the tool is already being used by some law enforcement agencies in an early access program.

💡
Do you know anything else about Nova or similar tools? I would love to hear from you. Using a non-work device, you can message me securely on Signal at joseph.404 or send me an email at joseph@404media.co.

Flock’s new product, called Nova, will supplement license plate data with a wealth of personal information sourced from other companies and the wider web, according to the material obtained by 404 Media. “You're going to be able to access data and jump from LPR to person and understand what that context is, link to other people that are related to that person [...] marriage or through gang affiliation, et cetera,” a Flock employee said during an internal company meeting, according to an audio recording. “There’s very powerful linking.” One Slack message said that Nova supports 20 different data sources that agencies can toggle on or off.

  • ✇404 Media
  • Podcast: AI Avatar of Killed Man Testifies in Court
    We start this week with Jason and Matthew's story about an AI avatar that testified in court. It might be a sign of things to come. After the break, well, well, well, Meta is developing facial recognition for its smart glasses. In the subscribers-only section, Jason tells us all about AI in baseball. Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subsc
     

Podcast: AI Avatar of Killed Man Testifies in Court

14 mai 2025 à 09:00
Podcast: AI Avatar of Killed Man Testifies in Court

We start this week with Jason and Matthew's story about an AI avatar that testified in court. It might be a sign of things to come. After the break, well, well, well, Meta is developing facial recognition for its smart glasses. In the subscribers-only section, Jason tells us all about AI in baseball.

Listen to the weekly podcast on Apple Podcasts, Spotify, or YouTube. Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid subscriber, check your inbox for an email from our podcast host Transistor for a link to the subscribers-only version! You can also add that subscribers feed to your podcast app of choice and never miss an episode that way. The email should also contain the subscribers-only unlisted YouTube link for the extended video version too. It will also be in the show notes in your podcast player.

❌
❌