HeadFlash

Privacy

Fake VPNs Flood Chrome Store; FTC Targets Personalized Pricing

Hundreds of fake VPN extensions hit Chrome users, while the FTC warns companies on personalized pricing and OpenAI tests new abuse detection.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Hundreds of Fake VPN Extensions Flood Chrome Web Store, Researchers Find

Socket’s threat research team identified 737 suspicious Chrome extensions claiming to offer VPN and SOCKS5 proxy services, published by 40 developer accounts with 75,486 total installs. Detailed code analysis of 525 extensions, accounting for 58,318 active installs, revealed that 274 plagiarized branding from 66 reputable VPN platforms including Proton VPN, Surfshark, NordVPN, ExpressVPN, CyberGhost, and TunnelBear. Two extensions specifically impersonated AmneziaVPN and AntiZapret, tools used to bypass internet censorship.

The fake extensions routed all traffic through a fixed SOCKS5 proxy without split tunneling, and 104 used DNS-over-HTTPS evasion to bypass Chrome’s blocklists. Many advertised paid tiers with private servers in Japan, Singapore, Canada, Australia, and Turkey, but those servers did not exist, and premium subscriptions had no internal license verification. One extension, Burёnka VPN, routed no traffic at all and was a fake UI. Developers studied Chrome’s review procedures and evaded rejections through trial and error; opening a new developer account costs $5, so publishing over 700 fake extensions across 40 accounts cost under $200. Most targeted Russian citizens seeking to bypass regional censorship, limiting outside reporting.

Hundreds of Fake VPNs Are Flooding the Chrome Web Store →

FTC Warns Companies on Personalized Pricing, Demands Clear Disclosure

The Federal Trade Commission issued a bulletin Wednesday putting companies on notice over their use of personal consumer data to set individualized prices. The FTC said businesses must clearly disclose when they use detailed information about a consumer to generate a personalized price offer, including the types of data used. The agency said it cannot ban personalized pricing under its current authority, but it will pursue enforcement action against companies that fail to meet its disclosure requirements.

The FTC cited examples: a food-delivery company would need to disclose if it charges a consumer more based on personal data, and a ride-share company would face the same requirement if it increases a fare because it knows a customer does not have a competing app installed. The practice differs from traditional discounts offered to broad groups, such as students or senior citizens. The FTC found that companies could use personal data to charge more when shoppers appear unfamiliar with a market, including new parents and first-time car buyers. Some Democrats and consumer advocates say the FTC’s action does not go far enough, with Sen. Elizabeth Warren criticizing dynamic pricing. States have taken a more direct approach: New York last year required companies to disclose their use of personalized pricing, while Maryland prohibited algorithms from changing food prices at the individual level.

The FTC is cracking down on companies that charge you a “personalized price” →

OpenAI Introduces Private Safety Processing for API Customers

OpenAI introduced Private Safety Processing on August 19, a system designed to detect suspicious behavior across multiple interactions while preserving Zero Data Retention (ZDR) for eligible API customers. OpenAI stated that its existing ZDR safeguards evaluate requests individually, making patterns spread across several interactions harder to detect. Private Safety Processing aims to fill that gap without giving OpenAI employees access to the underlying prompts or responses. The system is currently being tested with early customers and is aimed at enterprise and API customers rather than individual ChatGPT subscribers.

Instead of inspecting one request at a time, the system can look for suspicious patterns across related interactions. When it detects possible misuse, OpenAI receives a limited signal about the activity rather than the customer’s underlying content. With ZDR deployments, that content stays on infrastructure controlled by the customer. OpenAI is also developing another setup where encrypted content can live on its infrastructure while customers hold the encryption keys. There is an explicit exception: images flagged as potential child sexual abuse material can still be retained for legally required manual review and reporting. OpenAI plans to begin rolling out Private Safety Processing and publish a technical white paper in September.

OpenAI wants to monitor AI abuse without forcing customers to hand over their data →

Poll Shows 75% of Americans Now Oppose AI Data Centers in Their Area

A poll released Thursday by Embold Research and published by Heatmap Pro found that 75% of Americans now oppose building AI data centers in their area, with 61% registering strong opposition. One year earlier, 42% of Americans opposed AI data centers in their areas, while 43% expressed support. The pollsters found the collapse in support was uniform across demographics, with data centers 43 points underwater with Republicans, 65 points underwater with independents, and 75 points underwater with Democrats.

Heatmap executive editor Robinson Meyer described the drop as a swift, massive shift in US public opinion on a scale he wouldn’t have thought possible. Adam Carlson of Zenith Polls said he doesn’t think he’s ever seen public opinion shift this quickly on an issue, and Justin Slaughter of Paradigm said he’s never seen this, noting data center opponents are converting supporters not just to neutral but to opposition. President Donald Trump on Wednesday touted data centers as a great source of jobs, though the facilities employ very few people relative to their size once completed. Max Steele of Everytown said the tech sector had managed to unite a deeply divided country.

‘I’ve Never Seen This’: Massive Collapse in Support for AI Data Centers Captured in New Poll →

Privacy Groups File Complaint Against Data Brokers in Maryland

A coalition of privacy and civil rights groups filed a consumer complaint Wednesday calling on Maryland Attorney General Anthony G. Brown to investigate and take enforcement action against specific data brokers for allegedly violating state privacy law by collecting and selling Marylanders’ geolocation data and selling information to federal immigration authorities. The complaint was authored by Georgetown University Law Center’s Technology Law Clinic on behalf of We Are CASA and 11 other organizations including the Center for Democracy & Technology and the Electronic Privacy Information Center.

The complaint alleges Penlink, Thomson Reuters, Motorola, Insight LPR, LexisNexis, Flock Safety and others are collecting and selling personal information and location data on Maryland residents to law enforcement customers. Penlink sells cell phone location data through its Webloc program, while the other companies sell car location data captured by license plate readers. Several named companies have contracts with ICE, including Penlink. The complaint calls on Brown to use the full force of the state’s privacy laws and take immediate action to rein in agencies’ use of commercially purchased data that enables mass surveillance of Americans without judicial, legislative, or public oversight.

Thomson Reuters denied the allegations, stating confidence in compliance with all applicable laws, and Penlink also denied violating state law. Maryland’s law defines precise geolocation data as information that can identify a location within a radius of 1,750 feet. Under current Maryland law, data brokers are barred from collecting or sharing state residents’ sensitive data, including location data, unless it is to deliver a product or service the consumer requested, or in response to certain law enforcement demands. Data brokers are barred from selling or sharing Marylanders’ location data unless law enforcement has obtained a subpoena or warrant, and from selling information to agencies that enforce immigration law unless required by law or with a warrant. The Maryland attorney general’s office declined to comment on the complaint.

Privacy advocates call on Maryland to investigate data brokers →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches