Privacy

September 2025

September 2025


Vol. 8, Iss. 37
Robin’s Newsletter #378
Vol. 8, Iss. 37

JLR says data taken as supply chain worries grow. US wraps up is disinformation cooperation centre. Switzerland considering ID requirements for VPNs.

July 2025

July 2025


Vol. 8, Iss. 30
Robin’s Newsletter #371
Vol. 8, Iss. 30

SharePoint shells for China. Clorox's $380M help desk lawsuit. And massive surges in UK VPN signups following Online Safety Act checks come into effect.

June 2025

June 2025


Vol. 8, Iss. 23
Robin’s Newsletter #364
Vol. 8, Iss. 23

More retail cyber attack news. Meta, Yandex caught de-anonymising Android users. Vendors to collaborate on threat actor naming.


Vol. 8, Iss. 22
Robin’s Newsletter #363
Vol. 8, Iss. 22

German authorities ID Trickbot, Conti ringleader. Australia passes law requiring ransom payment notifications. Vietnam blocks Telegram.

February 2025

February 2025


Vol. 8, Iss. 5
Robin’s Newsletter #346
Vol. 8, Iss. 5

DeepSeek buzz, bans, breaches. NAO says UK gov won't achieve 2025 cyber pledge.

January 2025

January 2025


Vol. 8, Iss. 4
Robin’s Newsletter #345
Vol. 8, Iss. 4

Trump administration dismisses CSRB, halts cyber dimplomacy efforts. Impact of PowerSchools breach still unknown. EU power grid vulnerabilities.

January 2024

January 2024


Vol. 7, Iss. 4
Robin’s Newsletter #293
Vol. 7, Iss. 4

Australia names Medibank attacker. Microsoft comes under criticism for config blunder that let Russia snoop on mailboxes.

December 2023

December 2023


Vol. 6, Iss. 51
Robin’s Newsletter #287
Vol. 6, Iss. 51

Russian group claims responsibility for knocking out Ukraine's largest telco. National Grid removing Chinese tech from electricity network. PSNI breach expected to cost over £20M.

October 2023

October 2023


Vol. 6, Iss. 43
Robin’s Newsletter #279
Vol. 6, Iss. 43

Five Eyes security chiefs warn of espionage threat. Two ransomware gangs taken out. Thousands of Cisco devices compromised.

August 2023

August 2023


Vol. 6, Iss. 33
Robin’s Newsletter #269
Vol. 6, Iss. 33

UK Elections watchdog comopromsed two years ago. Detials of Northern Ireland police staff accidentally published. Zoom backtracks on AI training in terms of service.

July 2023

July 2023


Vol. 6, Iss. 29
Robin’s Newsletter #265
Vol. 6, Iss. 29

EU and US adopt new privacy framework for personal data transfers. Microsoft email systems breached by Chinese APT group. Poisoned AI models and disinformation.

June 2023

June 2023


Vol. 6, Iss. 23
Robin’s Newsletter #259
Vol. 6, Iss. 23

Kaspersky says it was compromised using zero-click iMessage exploit. Russia blames the NSA. Amazon settles Ring2 'lax privacy' case.

May 2023

May 2023


Vol. 6, Iss. 22
Robin’s Newsletter #258
Vol. 6, Iss. 22

Meta fine €1.2 billion. US-China cyber tensions. Brute-forcing biometric authentication. Insider threat fail.


Vol. 6, Iss. 20
Robin’s Newsletter #256
Vol. 6, Iss. 20

Russian APT malware disabled. MSI compromise included important crypto keys. EU CSAM plans may be unlawful.

March 2023

March 2023


Vol. 6, Iss. 11
Robin’s Newsletter #247
Vol. 6, Iss. 11

BlackLotus malware can circumvent Secure Boot, infect UEFI. The FBI has been buying US citizen's location data. People are better at identifying fake news if you pay them.

December 2022

December 2022


Vol. 5, Iss. 49
Robin’s Newsletter #233
Vol. 5, Iss. 49

UK managed security businesses to be regulated. Medibank attackers release data. Anker's Eufy smart camera 'local only' claims disputed.

September 2022

September 2022


Vol. 5, Iss. 36
Robin’s Newsletter #220
Vol. 5, Iss. 36

The US gov simultaneously using, and suing a provider of, commercial geolocation data. Uncovering Russian agents in hacktivist data breaches.

July 2022

July 2022


Vol. 5, Iss. 31
Robin’s Newsletter #215
Vol. 5, Iss. 31

Facial recognition use at Co-Op convenience stores and 'secret blacklists' challenged in the UK. The opportunity cost in action bias. And protestware, the 'insider threat' of hacktivism.


Vol. 5, Iss. 28
Robin’s Newsletter #212
Vol. 5, Iss. 28

Apple's extreme 'Lockdown Mode' to protect against NSO Group. Apparent breach of 1 billion Chinese citizens data. Bad week for NPM ecosystem.

June 2022

June 2022


Vol. 5, Iss. 26
Robin’s Newsletter #210
Vol. 5, Iss. 26

Infosec 2022 thoughts and trends. Privacy and reproductive rights. Cyber-warefare and lessons from the Ukraine conflict. Plus Cyber 911?

May 2022

May 2022


Vol. 5, Iss. 18
Robin’s Newsletter #202
Vol. 5, Iss. 18

Conti ransomware gang targets Costa Rica following election. Timeline of Russian cyberatacks against Ukraine. Facebook doesn't know where your data flows.

June 2021

June 2021

WWDC21: Death. Taxes. Privacy. Tech. Law. And Economics.

Making a Twitter thread from earlier in the week a little easier to digest. There are some interesting new privacy features from Apple at their World Wide Developers Conference this week: Mail Privacy Private Relay Hide My Email On-device Siri App Privacy Report I’ve seen lots written on 1-3, less on the latter, plus the potential hidden amongst the announcements. First up, the solutions here aren’t new tech: Voice Control has been in iPhone for alarms, music, etc for… 7(?


Vol. 4, Iss. 24
Robin’s Newsletter #156
Vol. 4, Iss. 24

EA games source code stolen. Apple's news privacy and security features. The FBI ran An0m encrypted comms app. Ransomware thinking.

April 2021

April 2021


Vol. 4, Iss. 15
Robin’s Newsletter #147
Vol. 4, Iss. 15

Facebook's *ahem* 'data scraping' incident sets the stage for debate on responsible design and engineering. AWS bomb threat. Censorship by QoS. TUI's algorithm gender bias led to 'serious incident' calculating takeoff loads.

January 2021

January 2021


Vol. 4, Iss. 3
Robin’s Newsletter #135
Vol. 4, Iss. 3

WhatsApp bungles privacy policy update; U.K. police unintentionally delete 213,000 records; and 'imposing costs' the 'Brexit means Brexit' or cyber.

October 2020

October 2020


Vol. 3, Iss. 42
Robin’s Newsletter #122
Vol. 3, Iss. 42

British Airways fined £20M for data breach; Businesses exploiting contact tracing data; Microsoft's trademark takedown of TrickBot.

May 2020

May 2020


Vol. 3, Iss. 19
Robins Newsletter #99
Vol. 3, Iss. 19

Contact tracing apps, password reuse stats, law firm ransomware, and the integrity of systems

March 2020

March 2020

Introducing Phased Array

A privacy-focussed list of tracker domains that have been identified by DuckDuckGo’s Tracker Radar for use in ad blocker solutions like pi-hole. At present this is a particularly blunt tool, blocking entire domains, rather than individual trackers. This may result in ‘undesirable behaviour’, i.e. your favourite website/app may stop working. Project website: https://github.com/rto/phased-array Find out more about Tracker Radar at: https://spreadprivacy.com/duckduckgo-tracker-radar/ https://github.com/duckduckgo/tracker-radar Find out more about Pi-hole at: