Privacy
ChatGPT iMessage Integration Threatens Apple Encryption
OpenAI's new Mac plugin can read and analyze iMessage chats, raising alarms over end-to-end encryption and privacy for all participants.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
OpenAI Mac App Integration With iMessage Raises Encryption and Consent Concerns
OpenAI last month enabled its Mac app to integrate with Apple’s Messages, letting ChatGPT read and send messages. Security experts warn this could undermine iMessage’s end-to-end encryption, which ensures only the intended recipient can read a message. Paul Walsh, a security expert with over three decades of experience, called it the worst privacy development he has seen in 20 to 30 years, noting the integration could expose conversations to OpenAI, including messages and images from anyone who has ever used iMessage, even non-ChatGPT users.
The integration works by accessing message content through a computer access protocol, and there is no way for other conversation participants to decline ChatGPT’s access. This could include minors, ex-partners, or colleagues, and cover sensitive topics like medical issues. Walsh said the feature could give OpenAI a data-rich map of names, phone numbers, and relationships, and that data stored on OpenAI’s servers could be subpoenaed by the FBI under the CLOUD Act. Proton, the encrypted email platform, recommends users not enable the integration. Neither OpenAI nor Apple responded to requests for comment, and it is unclear if Apple was consulted on the feature.
EPIC Sues to Block Trump’s Federal Voter Database Plan
The Electronic Privacy Information Center (EPIC) filed a lawsuit Tuesday in federal court in Maryland to halt the Department of Homeland Security (DHS) and the Social Security Administration (SSA) from creating a centralized database of eligible voters. The suit, representing EPIC with Protect Democracy and Citizens for Responsibility and Ethics in Washington, argues the effort is an illegal overreach that violates the Privacy Act of 1974 and encroaches on states’ authority to administer elections. The database would compile identities, Social Security numbers, addresses, and citizenship information for every U.S. citizen, a scenario EPIC’s deputy director called a nightmare Big Brother scenario.
The Trump administration claims the lists are needed to prevent noncitizens from voting, which is already illegal and rare. The lawsuit notes DHS itself admitted the lists will contain widespread inaccuracies, risking eligible voters being erroneously removed from state rolls. A federal judge in Massachusetts blocked the directive in June, but the Supreme Court lifted that injunction last week. No court order currently bars DHS and SSA from creating the lists. In a separate case, a federal court barred DHS from offering its SAVE system for voter roll purges, citing threats to the sacred right to vote and privacy rights.
Songkick Lawsuit Alleges Tracking Persists After Cookie Rejection
A proposed class action lawsuit filed in Illinois claims concert discovery site Songkick tracked visitors even after they clicked reject all on its consent banner. Plaintiffs Zoe Barker and Charissa Baron allege the site collected data tied to searches, including artists, events, dates, IP addresses, and unique identifiers, and sold that data to third parties. The complaint says tracking fired on every page for every user, including those who explicitly opted out, and cites the Illinois Eavesdropping Act and Federal Wiretap Act. Songkick, which reaches over 155 million fans, was acquired by Warner Music Group in 2017 and by AI music generator Suno in November.
The lawsuit argues concert searches can reveal travel plans, event interests, and social or political affiliations. Barker searched for concerts around Chicago, while Baron looked for shows in Denver and San Diego, and both were tracked despite rejecting cookies. The complaint references outside tracking tools from Yahoo, Amazon, and Google on the site, calling them eavesdropping devices. The plaintiffs seek to bar tracking after cookie rejection and order deletion of any data collected that way. The proposed class includes U.S. residents who rejected cookies but were still tracked, plus a separate Illinois group.
Illinois lawsuit says Songkick tracked, sold fan data even after cookie opt-outs →
Namibia Rejects US Health Data Deal Citing Privacy and Sovereignty
The Namibian government has rejected a proposed United States health data and specimen-sharing agreement, citing constitutional privacy rights and sovereignty over biological resources. The deal, worth over N$145 million per year for HIV and tuberculosis programmes, was withdrawn by the US in November 2025 after legal scrutiny through Namibia’s attorney general’s office. Officials said the draft granted the US extensive unilateral access to medical information, bypassing mandatory requirements for export permits and prior informed consent under Namibian law. The wider question of health data remains under negotiation.
Namibia is now exploring alternatives to fund about N$730 million for its HIV-AIDS programmes, with the 2027 amount estimated at US$45 million. A US government source said negotiations did not include sharing personally identifiable data, only aggregate data, but Namibian officials remain concerned. The deal could undermine Namibia’s position in WHO pandemic agreement negotiations. Former health minister Richard Kamwi supports the rejection, stating data responsibility belongs to Namibia. The US has dismantled key donor organisations like USAID and introduced the America First Global Health Strategy, which aims to provide direct funding to foreign governments.
Namibia: Us Health Deal Faces Data Privacy Backlash in Namibia →
Amazon Listings Sell Bot Farms for Social Media Manipulation
Amazon is selling bot farm hardware, with listings offering devices for as little as $188 and an $800 kit including 20 mobile phone motherboards. The listings describe the equipment as tools to build networks of thousands of phones, evade detection by social media platforms, and achieve group control functions. One listing promotes use for TikTok, Facebook, and Google customer acquisition, virtual currency mining, and YouTube video promotion. The sellers are China-based companies with the brand name Generic, few reviews, and poor translations. Renee DiResta, a Georgetown University professor, said Amazon’s enforcement amounts to playing whack-a-mole and that Amazon doesn’t know what it sells.
Cybersecurity researcher Sergio Pastrana said bot farms can be used legitimately for research but are more often used to manipulate social media feeds in violation of platform terms, and can be used illegally for cybercrime. Selling such devices on mainstream platforms lowers the barrier to entry for building inauthentic social media armies. Recent events illustrate the broader landscape: the Pentagon tapped veterans to amplify viewpoints on X, political candidates pay influencers without disclosure, a pro-Israel website masqueraded as a think tank, OpenAI banned Russian-based accounts, and X uncovered a Chinese bot farm operating some 200,000 accounts, though Clemson researcher Darren Linvill called it a non-story with virtually no engagement. Amazon did not respond to requests for comment.
Want to manipulate hearts and minds online? Amazon sells just the bot farm you need →