Privacy
AI Providers Share One Encryption Key, Researchers Decode 315K Reasoning Blocks
A single encryption key across OpenAI, Anthropic, and Google exposed hidden AI reasoning, 182 credentials recovered, and 62 live API keys found.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
AI Providers Share One Encryption Key, Researchers Decode 315K Reasoning Blocks
A team of researchers from MATS Research, the ELLIS Institute Tübingen, the Max Planck Institute for Intelligent Systems, and security firm Snyk discovered that Anthropic, OpenAI, and Google all use a single global encryption key for AI reasoning tokens. By decoding 315,320 reasoning blocks scraped from public GitHub and Hugging Face repositories, the researchers recovered 182 credentials, including 62 live API keys, 33 passwords, and 30 personal email addresses. The flaw is architectural: instead of binding each encrypted reasoning block to a specific user, session, or model, all three providers use a single, provider-wide encryption key across their entire ecosystem.
‘Inner Thoughts’ of Every Major AI Model Exposed in Massive Exploit →
Signal Launches Automatic Key Verification to Stop Server-Level Wiretapping
Signal introduced Automatic Key Verification on Tuesday, a feature enabling its estimated 70 to 100 million users to confirm that encrypted messages reach the intended recipient without an in-person meeting. The feature addresses a structural vulnerability in Signal’s architecture: the requirement to trust that Signal’s servers have always provided the correct encryption key for every phone number. The existing Safety Numbers system required users to meet in person to compare a verification string or scan a QR code, a check that was rarely completed. The threat it was designed to catch is a man-in-the-middle attack at Signal’s key directory, where an attacker with access to Signal’s infrastructure could substitute a different public key for a target’s account and route messages to themselves.
Signal Launches Automatic Key Verification to Stop Server-Level Wiretapping →
Private Intelligence Firms Sell Dossiers on AI and Data Center Critics
Private intelligence firms are selling dossiers about critics of artificial intelligence and the data centers powering them, including attempting to peddle them to federal regulators, according to documents obtained by The American Prospect. The corporate intelligence company RANE Network sent a product offering to the Federal Energy Regulatory Commission in March 2025, proposing a tailored report on the threat posed by anti-tech sentiment. In May 2025, RANE offered a webinar on the coming anti-tech backlash, where analysts described the threat posed to technology companies by rising animosity toward Silicon Valley, citing protests from creatives, environmental groups, labor unions, and employees.
Campaigns Are Buying Your Data Right Now. So Is Everyone Else.
Political groups paid data brokers $23 million for voter profiles in 2020, with files including names, addresses, phone numbers, shopping habits, estimated income, and religious beliefs. With midterms three months out, campaigns are again purchasing such data. Campaigns use the files for targeting; scammers use them to impersonate campaigns. The data does not expire on election day and is resold, reused, and repurposed, including by fraudsters running fake donation pages and voter registration scams. The same brokers have sold personal data to predatory lenders, stalkers, and operations pushing targeted disinformation.
Campaigns Are Buying Your Data Right Now. So Is Everyone Else. →
Trump Admin Delays TANF Data Sharing Plan Opposed by Blue States
This development marks a pause in the administration’s push to centralize welfare data, which privacy advocates had warned could expand government surveillance of low-income families. The opposition from blue states centered on concerns about data security and the potential for misuse of sensitive beneficiary information. The delay suggests the administration is recalibrating its approach in the face of resistance, though the underlying proposal has not been withdrawn.
Trump admin delays TANF data sharing plan opposed by blue states →