[MEDIUM]
|
Federal Trade Commission
FTC finalizes a 20-year order: GM and OnStar collected and sold drivers' precise location and driving-behavior data without clear consent
From Chapter 48
D-
Connected Cars
Privacy Nightmares on Wheels
"Your car knows where you go, how fast you drive, who you call, what you listen to, and where you park. And it shares that data with the manufacturer, your insurance company, and data brokers you've never heard of."
Avery's note
Your car records where you go and how you drive, then passes it on. An ordinary commute becomes a profile that can follow you all the way to your insurer.
60-second move
Open your car's infotainment Settings, find Data Privacy or Connected Services, and turn off driving-data and location sharing. GM owners: opt out of Smart Driver. Then ask the automaker in writing for a copy of your data and request deletion. The order now requires them to honor that.
[MEDIUM]
|
Federal Trade Commission
FTC bans data broker Kochava from selling sensitive location data without a consumer's affirmative consent
From Chapter 34
F
Weather Apps
Forecasting More Than Just Rain
"You check the weather every morning. So do hundreds of millions of other people. And most weather apps are collecting far more than your zip code. They're selling your precise GPS coordinates before you've finished your coffee."
Avery's note
Your location history is a map of your whole life: home, work, the doctor, who you visit. Sold cheaply to brokers, it is one of the easiest things to buy and the hardest to take back.
60-second move
iOS: Settings -> Privacy & Security -> Location Services. Set weather, shopping, and utility apps to Never or While Using, and turn Precise Location off. Android: Settings -> Location -> App permissions, do the same. While you are there, reset your Advertising ID so the old trail stops linking to the new one.
[MEDIUM]
|
Federal Trade Commission
FTC: OkCupid shared nearly 3 million user photos plus location and demographic data with an outside company, contrary to its privacy promises
Avery's note
These platforms make money by knowing your habits better than you do. The defaults are tuned for them, not for you, until you go in and change them.
60-second move
On every dating and social app, open Settings -> Privacy and revoke photo, location, and contacts access, then delete old photos and matches you no longer need. Where the app offers it, submit a data-deletion request. Assume any photo you ever uploaded may have already left the building.
[MEDIUM]
|
BleepingComputer
Hims & Hers disclosed a breach of its Zendesk support platform: names and contact details in support tickets were exposed (the company says medical records were not)
From Chapter 49
D
Wearables & Health Apps
When Your Body Data Stops Being Yours
"Your fitness tracker knows your heart rate, your sleep patterns, your menstrual cycle, your stress levels, and your exercise habits. That's not fitness data. That's a medical record you're voluntarily sharing with a tech company."
Avery's note
You never signed up with the vendor that got breached, and that is the point. Your data leaks through companies you have never heard of, so the safe assumption is that it is already out there.
60-second move
Treat any support or refill email about your prescriptions as suspect for the next few months. Do not click links in them; open the app directly. Turn on two-factor authentication on your pharmacy and telehealth accounts, and flag any order or refill confirmation you did not request.
[HIGH RISK]
|
ABC7 Chicago
Harvey, Illinois expands police surveillance network with Flock camera technology as privacy concerns persist
Avery's note
When records like these leak, the danger is not one bad day. It is someone quietly opening accounts in your name for years, long after the headline fades.
60-second move
Pull your three credit reports today. Freeze all three bureaus. Set fraud alerts. Eleven minutes if you stay focused.
[HIGH RISK]
|
Healthcare Finance News
Clover Health faces four class-action lawsuits over data breach
From Chapter 43
TOOLKIT
Advanced Overwatch
Becoming the Guardian of Your Digital Life This chapter isn't for casual readers. This is for the person who wants to become the guardian ... the one who knows how everything works and can protect the people around them. Someone in your family is going to become the person who understands this stuff. The one who checks the settings, reads the policies, and knows when something doesn't look right. This chapter is for that person. It might be you. Every family has one. Every friend group has one. Every office has one. The person who gets the call when someone's account gets hacked. The person who sets up the new Wi-Fi router at Thanksgiving because nobody else knows how. The person who says things like "don't click that link" and "you should really turn on two-factor authentication" and gets a polite nod followed by absolutely no action. If you've read this far, congratulations. You're becoming that person. This chapter is your field manual. Advanced Overwatch isn't paranoia. It's the difference between hoping nothing bad happens and actually knowing how to prevent it. Most people lock their front door at night. This chapter teaches you to check the windows, the garage, the smart doorbell that's streaming to a server in another country, and the baby monitor that's using a default password of "admin." The Five Pillars of Advanced Overwatch Pillar 1: Identity Compartmentalization 266 This is the single most powerful thing you can do for your digital privacy, and almost nobody does it. The concept is simple: stop using one identity for everything. Right now, most people use the same email address for their bank, their Netflix account, their online shopping, their social media, and the random website they signed up for once to download a coupon. When one of those gets breached ... and statistically, at least one will ... the attacker has the key that connects everything. Compartmentalization means creating separate identities for separate contexts. At minimum, you want one email for financial accounts, a different one for social media and entertainment, a third for shopping and subscriptions, and a throwaway for anything you'd rather not associate with your real name. Yes, this means managing multiple email addresses. It's mildly annoying. You know what's more annoying? Having your bank account compromised because the coupon website stored your email in plaintext and a teenager in another country found it. Use a password manager. Seriously. If you take one thing from this chapter, make it this. A password manager generates unique, complex passwords for every account and remembers them so you don't have to. The human brain was not designed to remember forty-seven different passwords. Stop pretending yours can. Pillar 2: Device Hardening Your phone has approximately three hundred settings, and about two hundred and ninety of them are configured to benefit the manufacturer, not you. Device hardening means going through those settings with intention. Start with permissions. Open your phone's privacy settings and look at which apps have access to your location, your microphone, your camera, your contacts, and your photos. You will be surprised. That flashlight app does not need access to your contacts. That QR code scanner does not need your location. Revoke everything that doesn't make sense, and set the rest to "While Using App" instead of 267 "Always." Then tackle authentication. SMS-based two-factor authentication is better than nothing, but it's not good. SIM-swapping attacks can intercept your text messages. Use an authenticator app like Google Authenticator, Authy, or a hardware key like YubiKey for anything that matters ... especially email, banking, and cloud storage. If someone gets into your email, they can reset passwords on everything else. Disable Bluetooth and Wi-Fi when you're not actively using them. Your phone constantly broadcasts probe requests looking for known networks, and those requests can be intercepted to track your movement. It's a small thing. It matters. Pillar 3: Network Safety Your home Wi-Fi network is probably running on default settings with a password you set three years ago and have shared with every guest who's ever visited. That network is the gateway to every device in your house. Change the default admin password on your router. Seriously, go do it right now. I'll wait. The default credentials for most routers are publicly documented, and anyone within range can access your network if you haven't changed them. Enable WPA3 encryption if your router supports it. WPA2 is acceptable. WEP is not ... if you're still running WEP, you might as well post your browsing history on a billboard. If you have smart home devices ... and Chapter 47 explains why you should think carefully about that ... put them on a separate network. Most modern routers support guest networks. Use one for your smart devices and keep your computers and phones on the main network. That way, when your smart light bulb gets compromised (and yes, that happens), the attacker can't pivot to your laptop. On public Wi-Fi, use a VPN. Always. The coffee shop Wi-Fi is not your friend. Neither is the airport, the hotel, or the conference center. A VPN encrypts your traffic between your device and the VPN server, which means anyone 268 snooping on the local network sees encrypted gibberish instead of your banking credentials. Pillar 4: Digital Footprint Purge You've been online for years. Probably decades. In that time, you've created accounts on websites you don't remember, posted things you've forgotten about, and left data scattered across the internet like digital confetti. It's time to clean up. Start with old accounts. Use a service like JustDeleteMe or Mine to find and delete accounts you no longer use. Every dormant account is a potential breach vector. That Myspace account from 2006? Still has your data. That forum you joined to ask one question about fixing a dishwasher? Still has your email and password hash. Search your name. Google yourself. Look at what comes up. Check image results, too. You might be surprised what's publicly accessible. If you find information you want removed, most platforms have removal request processes. Google has a specific tool for requesting removal of personal information from search results. Review your social media history. Go back through your posts on Facebook, Instagram, Twitter, Reddit ... wherever you've been active. Delete anything you wouldn't want a future employer, a stalker, or a data broker to find. Social media posts are routinely scraped by data aggregators. If it's public, it's being collected. Pillar 5: Threat Monitoring Privacy isn't a set-it-and-forget-it proposition. You need ongoing awareness of when your data shows up where it shouldn't. Enable breach notifications. Services like Have I Been Pwned will alert you when your email address appears in a known data breach. It's free. Sign up for it today. If you discover your credentials were exposed, change the password immediately ... and if you reused that password anywhere else (you shouldn't have, but we all know you did), change it there too. 269 Monitor your financial accounts. Set up transaction alerts on every bank account and credit card. If someone charges $3.47 at a gas station in a state you've never visited, you want to know about it in real time, not when you review your statement next month. Consider a credit freeze. If you're not actively applying for loans or credit cards, freezing your credit with all three bureaus prevents anyone from opening accounts in your name. It's free, it takes ten minutes, and it's the single most effective defense against identity theft. You can temporarily lift it whenever you need to. Who Needs Advanced Overwatch Everyone benefits from basic privacy hygiene. But Overwatch-level protection is essential for specific groups: journalists and their sources, activists and organizers, anyone going through a divorce or custody dispute, domestic abuse survivors, public figures and content creators, high-net-worth individuals, teenagers being cyberbullied, and anyone who's ever been doxxed or stalked. If you're in any of those categories, the basics aren't enough. You need compartmentalization, device hardening, and active monitoring. Not because you're paranoid, but because someone has a specific reason to target you. Trust your instincts. If something feels wrong with your accounts, your devices, or your digital life ... act on that feeling immediately rather than waiting for confirmation. Red Flags That Overwatch Is Necessary Now Pay attention if you notice repeated password-reset emails you didn't request, login alerts from devices or locations you don't recognize, strangers contacting you with information they shouldn't have, ads that reference private conversations or locations with eerie specificity, or mail arriving at your address for accounts you didn't create. These aren't coincidences. They're indicators. Act on them immediately: change passwords, enable two-factor authentication, freeze credit, and document everything. 270 Data-Naked Moment "I thought privacy was defensive. Something you hide behind. Overwatch taught me it's proactive. Something you build. The difference between hoping you're safe and knowing you are." If you've made it this far, you know more about digital privacy than most professionals. But before we close, there's one more thing to say. 271
"Advanced Overwatch: Becoming the Guardian of Your Digital Life This chapter isn't for casual readers. This is for the person who wants to become the guardian ... the one who knows how everything works and can protect the people around..."
Avery's note
A breach at a clinic, store, or agency you trusted puts your most sensitive records in a stranger's hands. The cleanup lands on you, not on them.
60-second move
iOS Settings -> General -> VPN and Device Management. Android Settings -> Apps -> Special Access. Remove anything you did not install.