Showing posts with label privacy. Show all posts
Showing posts with label privacy. Show all posts

2026-06-26

Mentality and reality

Image: Unsplash

“The mentality is shifting. Now let’s hope reality follows,” a colleague sighed. Can you guess what this conversation was about? It could have been quite a few things, I realise – healthy eating, smoking, exercise, you name it. But hey, this is the Security (b)log, after all.

The conversation was about ICT in relation to the geopolitical situation. That is a polite way of saying: we no longer find the Americans as endearing as we once did (because they are bullying us). Fair enough, it’s not just about the unpredictable behaviour of the US. Countries like China are not making things easy for us either: we can’t do without them, yet we would rather have nothing to do with them. In the ICT world, though, it is mainly American products that are visible (the Chinese products are hidden in the hardware).

The entire debate around digital sovereignty centres on the desire to be less dependent on American ICT. The sentiment in our part of the world is that ‘they’ can switch things off at any moment or snoop through our data. That does not feel particularly comfortable. Europe is becoming increasingly aware of the necessity – and the possibility – of becoming more self-sufficient. That is what my colleague meant by: “The mentality is shifting.”

And reality? We have long convinced ourselves that we cannot compete with the American tech giants and their economies of scale. But they too started from nothing. And maybe it is a little more expensive at first to store your data in a European cloud – if you have decided that things need to change, you have to be willing to pay a price for that. But it does not have to be more expensive at all. It can even be cheaper. Microsoft’s Office applications cost money, whereas LibreOffice and FreeOffice (both legally based in Germany), for example, are completely free to use.

There are many more non-American alternatives to American software. I was tipped off that an OSINT specialist collegue had put together a fine overview (OSINT = open source intelligence: gathering intelligence from publicly available sources). This colleague lists alternatives for no fewer than 21 software categories. A few examples: email, VPN, browser, search engine, AI assistant, cloud & storage, maps & navigation. For each category, he names the de facto standard, followed by various European alternatives. And he explains why his number one is his preference. It is not just a list – he actually did his research: read reviews and discussions, gathered information from websites, tried things out himself. With the help of AI, this resulted in a fine document.

The bad news is that the overview is not available online. So here are a few examples. For email, Proton Mail (from Switserland) comes in at number one as an alternative to Gmail and Outlook, “because it combines the strongest encryption with independent audits, a broad ecosystem and the widest reach”. The favourite VPN provider is Swedish Mullvad, “because it offers the strictest take on privacy: no identity required, can be paid for in cash, and repeatedly audited”. Mullvad also tops the browser category, “because it combines the fingerprint protection of Tor with the speed of a regular browser”.

For a search engine, French Qwant is your best bet: “no profiling, and usable results for everyday use”. That category also mentions Mojeek, with the advantage that it uses its own index (and therefore does not rely on Google or Bing results). For artificial intelligence, you can turn to French Mistral Le Chat/Vibe, or, if confidentiality matters, Swiss Proton Lumo. That same Proton also comes up for cloud storage, “because it combines encryption, ease of use and integration with the rest of your Proton account”. And if you want to move away from Google Maps, take a look at Organic Maps: “fast, free, offline and without any tracking”.

When I visited New York City for the first time at the end of the last century, a drunk Irishman gave a speech on the subway. His lament concerned the disappearance of a direct connection between New York and Shannon Airport, and his endlessly repeated refrain always ended with: “It’s all a matter of economics.” And so it is with our digital sovereignty: it is all economically driven. The difference is that you yourself, if you want to, can do something to become master of your own data again.

And in the big bad world…

 

 

2026-06-12

Leaky cruise

Image: Unsplash

They had just completed yet another cruise. This time too, they had managed to keep their feet dry, but as it turned out afterwards, there had been a leak after all. A data leak. And just like in the days of the Titanic, everyone acted as if nothing had happened.

They had not received a personal notification that their data had been exposed. They only found out by pure chance. In Europe, our first reaction is often to start waving the GDPR around indignantly: surely they have to tell me if my data has been leaked?! But it is not quite that simple. To begin with, the organisation responsible for the leak must determine for itself whether the incident has to be reported to the Dutch Data Protection Authority (AP). That is not required if “it is unlikely that the personal data breach will result in a risk to the rights and freedoms of data subjects”, as the AP explains. The leaked information did contain personal data (including that of my seafaring colleague), so they would probably not get away with that argument.

The next step is for the leaking party to notify the victims, and here comes the catch: only if the breach is likely to result in a high risk to them. Once again, the organisation must make that assessment itself, of course based on the GDPR rules. If personal data has been stolen by a hacker, the risk is fairly obvious, according to the AP.

And that is exactly the situation we are dealing with here. Last month, Carnival Corporation, the parent company of Carnival Cruise Line, sent letters to customers about a cybersecurity incident (though not to all customers, obviously). A month earlier, an attacker had gained access to Carnival’s IT systems through social engineering and copied customers’ personal data. The information involved includes names, email addresses, dates of birth, gender, and several Carnival-specific data elements.

Carnival Corporation’s headquarters are located in Miami. Aha, I can hear you thinking gloomily, that is well outside the EU, so that wonderful GDPR is of no use to me. Wrong! The GDPR has what lawyers like to call extraterritorial effect: if a company outside the EU also targets the European market, it falls under the GDPR. And when I add everything up, it seems to me that a personal notification to the affected individuals would indeed be appropriate here.

Unless... Yes, unless the data was encrypted, the breach was stopped before anything could be done with the data, or informing all victims would require a disproportionate effort on the part of the company, for example because it no longer has their contact details. In that last case, publishing a notice in a newspaper or on social media is sufficient.

In short: it is not as straightforward as it may seem. We do know how this particular case played out: it didn't. That is why my data-breached colleague asked me what you can do yourself in such a situation. The AP has put together a useful overview (in Dutch). Among other things, it states that you should change any leaked passwords; that is indeed the very first thing you should do. They also recommend changing the passwords for other accounts and apps if they use the same password as the compromised one.

This immediately shows why you should never reuse passwords: after a breach, it creates a lot of extra work. Criminals will simply take the password from website A and try it on websites B through Z. And of course, you should already have enabled multi-factor authentication wherever possible.

After a breach, you should also be extra alert to phishing attempts. Those phishing messages may be far more sophisticated than the run-of-the-mill phishing emails, because the attackers now have much more than just your email address. With all that additional information, they can make their messages look highly personal.

According to the AP, a criminal cannot do much with just a bank account number (IBAN) or a citizen service number (BSN) on its own. But be careful with combinations of data — a copy of your identity document can be a real game changer when it comes to identity fraud.

In summary: stay alert...

And in the big bad world ...

2025-02-21

In the waiting room

 

Image from Pixabay

In the rather crowded train I found myself sitting next to a man who was working on his laptop. A quick glance at the device and the open programs identified him as a colleague.

At one point he was in a phone conversation. I wasn't actively listening, but of course I heard something. And what I heard made me very happy. To start with, he spoke softly, and in short sentences. It was actually mostly listening and occasionally responding briefly. I didn't hear him give any information. Neat, colleague!

How different is the experience of a colleague who was sitting in the dentist's waiting room. Well, it wasn’t really a waiting room; in a corner of the reception there were some chairs. Behind the counter worked two assistants. One, Tasha*, was clicking through computer screens with some despair in her eyes and finally said: "I can't find Mrs. Decker's details in TND." Her colleague Cindy asked for Mrs. Decker's date of birth. "Aha," said Cindy, "she's from 1999 and that's why she's not in TND yet. What's her phone number, I’ll give her a call." Tasha read out the phone number and Cindy made the call.

“Good morning Mrs. Decker, this is Cindy, assistant to dentist Crown. I need some information from you to enter your treatment in our system. What are your initials? ABG? Great. And your social security number? Yes of course, I'll wait a moment. (...) Ah, there you are again. Yes, I'll write along. 1-1-2-7 5-5 9-5-0? Thank you. And finally, I need your address. 5 Brace Road? Great, then I have everything complete. Shall we make the first appointment for your root canal treatment right away? Can you come in on Friday at 9 o'clock? Fine. If I can also have your e-mail address, I'll send you a confirmation. marly@decker.com? Fine, then we'll see you the day after tomorrow. Have a nice day!”

Our colleague could hardly believe his ears. He now had a complete set of personal details of someone and he knew when Mrs. Decker would not be home. Thanks to the information about her treatment, he also knew that she would be away for a while.

“Great, with this information I can commit identity fraud.” Or: “Great, I’ll get my burglary tools ready.” I admit that the chance that the unintentionally shared information accidentally ends up in the ears of a cyber or physical criminal is not that great. But still: everyone feels in their bones that this never should have happened. If you hear all this, then you know that they are handling your data in the same way. You wouldn’t feel comfortable with that, would you? And imagine that our waiting colleague was an acquaintance of Mrs. Decker. He runs into her a week later: “Hey Marly, how is your tooth?” That would be strange, wouldn’t it?

Of course there is also a legal problem. The unsuspecting, well-meaning dental assistants have not only leaked personal data, but even medical data. Under the GDPR (the European General Data Protection Regulation) these have the status of special personal data, for which even stricter rules apply than for regular personal data.

Tasha and Cindy were just doing their job. They can't help it that dentist Crown thought a separate waiting room was a waste of money. They couldn't make the phone call elsewhere either, because then Cindy couldn't enter the data into the system. Data leaks are pre-programmed in this situation. Especially when people are not aware of what is happening. A data leak is just around the corner.

I also want to look at what happened on the other end of the line. What if it wasn't the dental assistant who called Mrs. Decker at all, but someone who was out to collect personal data? Of course, the chance that they would call when you’re actually suffering from an aching tooth is small. But if you leave that circumstance out, it's a different story. If someone you don't know asks for data, tell them you'll call back. Then call the general number of the company and ask for the person who just called you. If that's not possible, ask whether they actually needed data. That way, you prevent yourself from leaking your own data.

*) Of course, all personal and system data are the product of my imagination.

 

And in the big bad world…


2024-09-13

Witches and dark patterns

 

Image from Pixabay

She’s called Magica De Spell, Miss Tick, or Gundel Gaukeley, only to mention a few international names of this Disney character, and she lives on Mount Vesuvius. She is the sworn enemy of Scrooge McDuck, because she wants to steal his Number One Dime to melt it in the lava of her volcano into an amulet that should give her unprecedented powers.

The name of this cartoon character comes to mind when I hear the term dark patterns. Not only because of the similarity in color, but also because they have a similar goal: secretly taking something from you for their benefit.

You encounter dark patterns every day when you enter the internet and get one of those annoying cookie notifications. You have probably noticed that the button to agree to everything is often very prominent, while the option to deviate from it is really hard to find. Or you have to click very often because the option 'none' is missing. A dark pattern misguides the user in a certain direction and has you click on the most favorable option for that site, or entices you to make a purchase, or makes you provide more data than you should want. There are many forms of dark patterns. I will go through a few with you, and you will recognize them all. Incidentally, different sources use different names.

-        Confirshaming is a nice contraction of confirmation and shaming: when asked whether you want to order that delicious fresh food, the option 'no' is accompanied by an addition such as: "I'll have a microwave meal tonight".

-        Another great term is privacy zuckering, which of course includes a reference to Mark Zuckerberg's Facebook. This is about sharing more personal information with your network than you would actually like.

-        Maybe you wanted to download some software that you found on the internet. You clicked on that big green download button and got something completely different than what you wanted. You looked again and discovered that for the software you actually wanted, you should have clicked on a less obvious button. That's called disguised ads.

-        “Book now! Only 3 rooms left!” If you’ve ever booked a holiday, you’ll probably be familiar with this one. It’s called fake scarcity. By pretending that the offer is about to expire, they want to entice you to make a quick decision.

-        Sometimes you wonder if reviews are real. Reviews from fellow customers can help you make your choice, but if the provider himself is behind those cheering texts, then it is fake social proof.

-        I ran into Hard to Cancel when a lottery offered a guaranteed “prize” in the first month if you would subscribe. I don’t like to leave free money behind, but I had planned to cancel after the first month from the start. Unlike getting in, getting out could not be done online; I had to call them, and after a long wait I got someone on the line who reacted rather grumpily to my cancellation.

-        Another well-known form of dark patterns is called nagging. For example, you will repeatedly receive offers in an app to switch to the paid version, or to enable a certain function. Sometimes the rejection option takes the form of “maybe later”, which is like a promise on your part. The idea behind nagging is – as in real life – that you agree to something in order to get rid of it.

-        Oh yes, preselection: the option "I would like to receive your newsletter" is already conveniently checked. Often there is more behind it - such as wanting to give you the feeling that other people also choose a certain option.

All this brings us to the question: is all this allowed? Well, that depends. Sometimes it is just smart marketing, as in the example of confirshaming. The story is different if deception is evident, like with false reviews. The European Data Protection Board has published a report on this subject. Of course, the GDPR is discussed in it, because transparency is an important concept there, while the term dark patterns already indicates that transparency is hard to find. The GDPR also applies the principle of fairness: your data is processed in your interest and that is done in line with what you could reasonably expect. Privacy by default is also an important principle; all options that could infringe on your privacy must be turned off by default. The example of the newsletter is an example where they didn’t comply with this rule, just like those pages where you can set cookie preferences and where everything is turned on.

Some things are allowed, even if they are not so nice or even unethical. Maybe you did not know that this phenomenon is called dark patterns and what world lies behind it. Now that you know, you might deal with it differently in the future. I myself like to get back at someone who wants to deveice me, by doing the opposite of what they want. Magica De Spell will not get my Number One Dime!

 

And in the big bad world…

 

2024-07-12

I see, I see what you don't see

 

Image from Pixabay

It was a warm Tuesday afternoon in one of those summers that just won't break loose. Then you take what you can get, and so they sat in their Utrecht backyard enjoying that one beautiful day. Suddenly the peace was cruelly disturbed by shouting and banging on the garden gate. They jumped up in alarm.

Through the cracks in the gate they saw bits of a woman with a wild-eyed look. “Let me in, this is my house!” she screamed. Well, they weren't going to do that. Explaining that the woman was really at the wrong house, even in the wrong street, had no effect on this lady, who was clearly under the influence of something. She kept banging on the gate. Well, 'gate' sounds very solid, but in fact it was a construction of windmill wood that hung on inferior hinges, and the rightful owners feared that it would not last very long.

Time to call the police. They arrived quickly, and they soon realized that it was best to take the person with them, because in her current state reasoning with her was impossible. They stuffed her into the back of the car and drove away. The street regained its calm.

The local residents were of course both shocked and curious. Most were not at home at the time, or they were vacuuming, so they didn't hear anything. The neighbors across the street had a security camera. Maybe it recorded something? Bingo! It was all there. When the woman walked up, she even looked straight into the camera. The police action was also beautifully depicted. The video was shared in the neighborhood app group - not for sensation, but because everybody knew that that lady would be walking around freely again in no time, and because the neighborhood would like to be prepared.

If I lived on that street, I would want that information too. You want to protect your family and your property, don't you? As an ordinary citizen, I would not hesitate to share the images with neighbors. But at the same time, from my profession, I wonder: is that actually allowed? What about privacy? People who do something wrong are also entitled to their privacy. The General Data Protection Regulation (GDPR) is European legislation that regulates our privacy. Every country has a GDPR supervisor; in the Netherlands this is the Dutch Data Protection Authority (AP). The AP is the perfect source to look for the answer to my question.

I read there that you may not share images in which people are recognizable without their permission. So do not put it on the internet and do not share it via social media. But there is an exception for personal or household use: “The condition here is that this person keeps the photos and videos private or at most shares them in a very limited circle. For example in a small app group.” That 'small app group' is a bit strange, because any member of that group could further distribute the images.

There's more going on. The GDPR states that you are not allowed to film public roads. Because that would constitute an infringement of the privacy of every passer-by. They understand that sometimes there is no other option than for your camera to film a part of the street. But even then there are rules. The most obvious: zoom in on your property as much as possible, in other words: make the violation of the rules as small as possible. There is actually no need to keep images, but there appear to be no concrete rules for this, because the AP says: “Delete the images as soon as you no longer need them. For example, after 24 hours.” You also have to inform people about your camera and secure the images properly - because if you are hacked, it means a data breach.

There is a double standard in the rule that you are not allowed to film public spaces. Because if something happens on your street, the police would love to have the images from your 'illegal' camera - they can even demand those images, in other words: you are obliged to hand them over. So it's not allowed, but if you do it anyway, it might help in fighting crime.

 

And in the big bad world...

 

2024-04-12

Girls Day

 

Image from Pixabay

It was one of those rainy Thursday mornings where you have to provide the bright spots yourself. Well, I got a chance to do just that, because I was on my way to give a special presentation. Our HR people held the annual Girls Day, for 14 and 15 year old girls from the highschool next door. I was the first male (and perhaps the oldest) speaker in the history of Girls Day. One thing was clear: I shouldn't come here with a story about how we do security. My story had to be about those girls.

I wanted to show the students something about their digital footprint. And so a few weeks ago I requested the list of participants and googled the names. You should have seen their faces when I told them! Wide-eyed, exchanging anxious looks with their friends. I told them that I was not going to mention any names and that I would not put anything recognizable on the screen. That reassured them somewhat. But I did have their full attention.

My search initially yielded a fairly innocent harvest: there were quite a few sporty girls, ranging from gymnasts to horse riders (including the horse’s names). More than half of the girls didn’t show up on Google at all. However, one particular girl revealed more. She had - probably unintentionally - made her presentations for the triangular meetings public (triangular meetings are the modern form of the parents' evening, where the tutor, the parents and the student get together and the student explains how things are going). I now know that this student sometimes lacks motivation (well, who doesn't), has attended different primary schools (someone at the back of the room breathed a sigh of relief: this isn't me!), likes teacher X but has trouble with their subject and enjoys the school parties. And a few more things that I left out because they are too personal.

This student probably didn't want to give the usual PowerPoint presentation, but something flashier. Instead she used Prezi, which allows you to create a very dynamic story. However, all your presentations are public if you use the free version. Oops. And oh yes, I was able to make the match between teacher X and the difficult subject because there is a list of all teachers on the school's website.

Instagram let me demonstrate that other people also (often unintentionally) reveal information about you. I looked up the names there too. For one name, there were three accounts. Which account belonged to the student on my list? The second account had a follower that was also on my list of names. Bingo! Then I took a closer look at the followers of that account. There was a company name in there, which also contained the girl's surname (fictional example: Balloon King Johnson). It’s a safe bet that this is the student's father or mother. The bio of that company account also included the street and city name. But no house number. It was the kind of business you could imagine being based at home. If I could find that company, I would know where this girl lived.

With Google Streetview you can virtually walk through a street. And look at the houses. When I walked through that street mentioned in the account for the second time and took a good look around me, I found what I was looking for: at one house, I saw something that was a clear reference to the company (in the fictional example there would have been a balloon arch at the front door). I told my audience: “If the letters in your zip code are AL, then this is about you.” You could have heard a pin drop.

So what, you might think. But remember: I'm one of the good ones guys. There’s plenty of scum around who would love to know where a girl like that lives. With my little finger exercise I demonstrated that the solution often consists of several puzzle pieces, which you can find in different places. I also told my audience that I am only an amateur in this field, and with this video I showed how others, who approach this with a bit of professionalism, can find out much more about you.

Of course I threw away the list of names. What remains is the memory of a special morning in which I hopefully made a number of young people think.

 

 And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

2024-01-26

Drained weight

 

Image from Unsplash

It's crazy that as a citizen you have to worry about your privacy. In the past, when Roger Moore still was James Bond, you only had to worry about external interest in your doings if you were a special company or a government. But nowadays? Everything has a privacy policy these days. And that means that your privacy is at stake everywhere. Otherwise that policy would not be necessary.

Well, the tone has been set for European Privacy Day, January 28. Apparently that day is necessary, too. Witness also this musing of Omri Elisha, professor of anthropology in New York:

We memorized phone numbers.
We memorized driving directions.
No one knew what we looked like.
No one could reach us.
We were god.

In those days, as a child you played outside with your friends, randomly ringing their doorbells or finding them somewhere outside. As a boy you wore rubber boots and preferred to play at the local mud puddle. At most you had a watch and a time when your mother told you to be home (and hopefully there was time taken into account to get you to the table clean). Yes, we were those gods, we just didn't realize it.

As a parent I look at this differently. It's quite nice to have your children under the digital button - at least when they respond to you. Are you worried because they are not home yet, or do you want them to run an errand? Sending an app usually works wonders. Are they going somewhere? They can then text that they have arrived safely, or they share their live location so that you know where they are in case of emergency. It also works the other way around: if help is needed, mom and dad are easily accessible. The price for this comforting technology is privacy. But because the children of this century don't know any better, they don't miss it.

Nowadays one hardly buys any device with a power plug that is not subject to a privacy policy. If you do not agree to it, you cannot use it. Not a soul reads it, everyone blindly agrees. If only because they are always those long, tough stories. You almost wish it just said: All data that this product collects about you and your environment may be used at the sole discretion of the manufacturer and all its business partners. I know of one case where this actually happens. If you travel to the US and come from a friendly country, you do not need a visa. Instead, you can simply apply for an ESTA (Electronic System for Travel Authorization) online. If you enter that process, you will receive an unmistakable security notification, which starts as follows:

You are about to access a Department of Homeland Security computer system. This computer system and data therein are property of the US Government and provided for official US Government information and use. There is no expectation of privacy when you use this computer system. The use of a password or any other security measure does not establish an expectation of privacy.

It's that simple: don’t expect any privacy when using this system. Even security measures that might give the impression of privacy are not there for your privacy. It reminds me of the greeting of the Borg in Star Trek (see this Security (b)log). Fortunately, how different things are with our own government, where people generally do their utmost to guarantee our privacy.

I recently wanted to return a product. The webshop was to send me a DHL shipping label. I received an email from DHL containing not only my shipping label, but also those of a few other customers. The webshop itself had not received those labels. It’s just a small thing, but it does indicate how easily personal data can leak.

The drained weight is stated on vegetable jars - how many grams of vegetables are in it, without the liquid? Perhaps websites should also place such a notice: given our security level, there is a 5/25/50/75/100% chance that your data will go down the drain.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

2023-11-03

Betrayed by your phone

 

Image from Pixabay

Last Tuesday I was in the auditorium of a hotel in Venlo. Standing on the presenter’s side in a lecture hall is a bit intimidating, but after four presentations to groups of colleagues about the risks of their online existence, it fit me like a glove.

An important part of those risks has to do with your privacy. While you can use all kinds of apps for free, most apps also do something on their own: they collect data about you. And they sell that information to advertising companies, who use this information to create profiles. Your name is not necessarily linked to this: mobile devices work with an advertising ID that is linked to your device. Is your privacy well protected by this feature? Meh.

As is often the case in information security, it is all about who you are, or sometimes also what you are. Take phishing for example. This can be done in two ways: the criminals use a dragnet and are fine with whatever they catch, or they use a spear to catch exactly the one fish they want. For example, because they know that that person has access to the company's money and is therefore a good target to receive an email 'from the CEO', stating that he must immediately transfer a nice amount of money to a certain bank account. This form of phishing is called spear phishing; you now understand why.

Back to the advertising world. As we saw, profiles are created for advertising purposes, but who says those profiles can only be used for that purpose? Suppose you have a collection of profiles. You could then create a map showing all the devices in a certain area. You don't know who they belong to, you just see the advertising IDs. Then you could single out one of those IDs and turn the question around, so to speak: where has this device been? That may provide a clue of places where the device is often found. And that in turn offers the opportunity to find out where someone works and where he lives.

For most of us, that's not a threat – we're not interesting enough for that. But what if you’re a criminal and therefore the police are looking for you? By using information, which is actually intended for placing advertisements, they may be able to get close to you. Unfortunately, it also works the other way: what if you’re in law enforcement and you have to deal with criminals that also have access to that kind of information? Of course either side also needs specialized software for this. Reputable companies that could make something like this would probably only supply such a product to law enforcement. Unfortunately, organized crime is also becoming smarter and moreover, they have plenty of money to have something like that built. That could be a serious threat. In the context of personnel care, the Dutch financial crimes unit kindly requested this blog post on the matter. But of course it can also be relevant for other colleagues and for people outside our organization.

You can do something about this quite easily. The advertising ID of your device can be turned off. This makes you invisible on the map, and your device will not appear if someone asks the question: which devices are present around this office building around eight in the morning and five in the afternoon? Advertising companies such as Google and Meta will inform you that you will then see 'less relevant' advertising. So what! I brush aside the advertising for strollers as easily as I would the advertising for running shoes. And remember, if you also have your private phone in your pocket while at work, you want to kill the advertising ID on that device as well. Here is a brief description of how to do this in iOS/IpadOS and in Android. And in this video, John Oliver explains again how trading your data works. The entire video is interesting; fast forward to 10:10 if you just want to see the part about phone location.

The above tips are of course only intended for people on the right side of the law. It is advisable for criminals not to follow the tips, because that could have all kinds of unpleasant consequences.

 

And in the big bad world...

This section contains a selection of news articles I came across in the past week. Because the original version of this blog post is aimed at readers in the Netherlands, it contains some links to articles in Dutch. Where no language is indicated, the article is in English.

 

 

Ants and lemons

Image: Unsplash Like soldiers on a mission, they marched across the kitchen counter of that holiday home in Croatia. Ants. They were also ro...