Privacy
Apple Fights Gag Order as Flock Camera Leak Exposes 1.6M Images
Apple challenges UK secrecy over an encryption backdoor demand, hackers pull 1.6 million images from a Flock camera, and the EU's digital ID wallet faces readiness doubts.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Apple and rights groups demand UK lift gag order on secret encryption backdoor
Apple, Liberty and Privacy International urged the Investigatory Powers Tribunal to lift a gag order barring the UK government from confirming it asked Apple for a backdoor into Britons’ phones. The request, made by then Home Secretary Yvette Cooper, would have allowed access to iPhone user data including photos and messages, bypassing stringent protections. Apple refused and withdrew its Advanced Data Protection feature for UK users instead. At a Thursday case-management hearing, Daniel Beard KC argued lifting restraints would let facts be deployed in the open. Ben Jaffey KC called the restrictions farcical. Home Secretary Shabana Mahmood’s lawyer, Neil Sheldon KC, said surveillance measures protect Britons from terror attacks and child abuse. The tribunal is overseeing Apple’s challenge.
Apple urges Home Office to come clean on ‘backdoor’ letting officials snoop on YOUR phone →
Tribunal hears Home Office secrecy over Apple technical capability notice is farcical
The Investigatory Powers Tribunal heard a challenge to the Home Office’s neither confirm nor deny policy over whether it issued a Technical Capability Notice to Apple. Ben Jaffey KC, for Privacy International and Liberty, called the position farcical and unsustainable. A Washington Post leak revealed the Home Office issued a TCN in January 2025 requiring access to end-to-end encrypted messages and worldwide iCloud data. Apple withdrew Advanced Data Protection for UK users rather than comply, saying it has never built a backdoor. A narrower TCN reportedly followed in October 2025. Jaffey cited public comments by US officials, including Tulsi Gabbard’s post viewed over 3 million times. Government counsel Neil Sheldon KC said departing from NCND would damage national security.
Hackers extract 1.6 million images from stolen Flock camera despite encryption claims
A hacking group called stegan0gram removed a Flock camera mounted over a roadway and analyzed its stored data, finding encryption keys on the device despite the company’s denials. Flock states its cameras use on-device encryption, require physical access to exploit, and retain images only briefly before cloud forwarding. The group accessed the camera’s Android operating system and found vendor and media partitions. The media partition contained a key unlocking another partition holding media files. The camera captured about 1.6 million images over 21 days, detecting roughly 50,200 vehicles and 11 people, and held 27,321 video clips of one to two seconds each. The group did not access the most sensitive data on the device.
EU digital ID wallet faces readiness doubts ahead of 2026 deadline
By the end of 2026, every EU country must legally offer citizens a European Digital Identity Wallet holding government ID, driving licence, diploma and other verified documents across all 27 member states. Digital rights groups warn the technology and safeguards are not ready. Thomas Lohninger of epicenter.works and EDRi says only 50-60% of needed technical standards exist. Centralising credentials raises the cost of a single security failure, and a compromised credential carries a cryptographic signature of authenticity. The regulation mandates tamper-resistant hardware, device-bound credentials, authentication for data requests, and user notification within 24 hours of revocation. Lohninger warns of over-identification and a panopticon risk, advising users to wait and demand independent audits before adopting the system.
One wallet, 27 systems: can the EU build an untraceable Digital ID? →
Brussels Data Omnibus proposal would rewrite GDPR automated decision protections
The European Commission’s Digital Omnibus, in its Data Omnibus iteration, proposes rewriting Article 22 of the GDPR, the provision giving people special protection against serious decisions driven by automated processing. The change would allow automated decision-making to be considered necessary for a contract even when a human could take the same decision, making efficiency the test rather than human involvement. Article 22 protection does not disappear merely because a human formally makes the final call. Germany’s SCHUFA holds data on around 69 million people, and the Dutch Data Protection Authority fined Uber almost 825 million euros last month for fully automated driver deactivations. The Netherlands’ SyRI system was struck down in 2020, and DUO’s fraud-risk scoring was found discriminatory. The Commission is preparing an AI tool to score EU job candidates.
‘Computer says no’: how Brussels is letting algorithmic social-scoring in by the backdoor →