HeadFlash

Privacy

Apple Flaw, Brain Data Law, Coupang's River Dive

This week: Apple's Hide My Email still leaks real addresses, Connecticut protects brainwaves, and a US firm dives for a laptop in China.

Listen

Apple ‘Hide My Email’ Vulnerability Exposes Real Addresses Despite Year-Long Fix Attempts

In limited tests with volunteers, 100% of Hide My Email addresses were exploitable, according to Murphy. The exact technical details are withheld because the vulnerability remains live. Apple did not respond to multiple requests for comment. Hide My Email is part of the paid iCloud+ service, generating random addresses ending in @icloud.com. The flaw threatens the core promise of the feature: shielding a user’s personal inbox from third parties. The disclosure raises serious questions about Apple’s vulnerability management process and the trust users place in its privacy tools.

Apple ‘Hide My Email’ Vulnerability Reveals Peoples’ Real Email Addresses →

The law covers raw brainwave readings from consumer EEG devices like the Muse headband, Emotiv EPOC X, and NextSense Smartbuds, but does not explicitly cover machine-learning inferences such as stress scores — a gap flagged by scholars at the Future of Privacy Forum. Enforcement falls to the Connecticut Attorney General’s office, with no guaranteed cure period and fines up to $5,000 per infraction. Connecticut joins California, Colorado, and Montana as the fourth U.S. state to protect neural data. The neurotechnology market is projected to reach $17 billion in 2026, and advocates warn that brain data collected for wellness could be used by employers, insurers, or law enforcement.

Connecticut Classifies Brain Data as Sensitive Starting July 1: New Rights for EEG Wearable Users →

California DMV to Share Driver License Data Amid Immigration Fears, Despite New Safeguards

More than 1 million immigrants with California driver’s licenses are potentially affected, as the system records the last five digits of a Social Security number and uses “99999” for those without one. Advocates fear the data could be used by federal immigration enforcement, calling the plan “a betrayal.” While the new legislation includes guardrails, critics like Ed Hasbrouck of the Identity Project argue they won’t prevent law enforcement from obtaining court orders for bulk data. The ACLU and other groups thanked lawmakers for the protections but urged an audit before 2030, saying more work remains.

CA to share driver license data despite immigration fears - CalMatters →

Alameda County Extends Flock Safety Contract by One Year Amid Surveillance Concerns

The Alameda County Board of Supervisors approved a one-year, $2.4 million contract extension for Flock Safety surveillance technologies with the Sheriff’s Office, passing in a 3-2 vote. Opponents warned of contract loopholes that could put the region’s immigrant community at risk. Sheriff Yesenia Sanchez defended the value of surveillance technologies for law enforcement. The extension continues the use of automated license plate readers and cameras in a county with a large immigrant population, reigniting debates over privacy and potential data sharing with federal authorities.

Alameda County extends Flock Safety contract amid worries over surveillance network →

Anthropic Rolls Back Covert Surveillance in Claude Code That Flagged Chinese Users

Anthropic employee Thariq Shihipar described the feature as “an experiment we launched in March that was meant to prevent account abuse from unauthorized resellers and protect against distillation.” He said the team had since shipped stronger mitigations and merged a pull request to fully roll back the check in the next release. The incident sparked outrage over user trust, especially given Claude Code’s full filesystem and shell access. Anthropic does not offer its models in China for national security reasons, and has previously accused Chinese AI labs of using Claude outputs without permission.

Hidden code in Claude Code secretly flagged Chinese users →

US-Based Coupang Forced to Recover Laptop from Chinese River in Clampdown, House Report Says

The December 2025 mission followed a massive data breach affecting 33 million customers, for which South Korea’s Personal Information Protection Commission fined Coupang $410 million in June — nearly twice its profit. The NIS told Coupang that its agents could not operate in China, so a company representative collected a desktop PC, hard drives, and a confession, then hired divers to recover a laptop tossed into the river. The recovered materials were handed to a waiting NIS official. The report concludes South Korea “weaponized digital laws” against an American company. Secretary of State Marco Rubio warned of targeting that has affected trade talks, and a former acting U.S. Trade Representative called it the worst treatment of a U.S. company in 30 years.

US-based ‘Amazon of South Korea’ forced to recover laptop from bottom of Chinese river in bizarre data privacy clampdown: report →