HeadFlash

Privacy

OpenAI Cookie Links ChatGPT Accounts to Browsing on 936 Ad Pixels

OpenAI's ad collector ties your ChatGPT account to what you do on Chewy, Wayfair and hundreds of other sites, while Reform UK pledges to scrap GDPR.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

OpenAI’s ad collector sets a cookie called __obi, scoped to .openai.com and tied to a ChatGPT account, which ordinary websites send back to OpenAI when they load its ad code. A reproduction verified with two capture methods and months of traffic found 936 distinct advertiser pixels across 1,029 hostnames, with one __obi value sent from 12 commercial sites including Chewy, Wayfair, HelloFresh and Coursera. The SDK also harvests identity from advertiser pages: scraped data outnumbered advertiser-supplied data 685 events to 255, and the tag-manager bus was the largest source of email. OpenAI classified __obi as an analytics cookie and did not answer questions about the classification.

ChatGPT now knows what you do on other websites via ad collector →

Reform UK pledges to repeal GDPR in contract with 5.7 million small firms

Reform UK published a 20-page policy document titled Contract with Small Business in August 2026, pledging to repeal the UK’s retained GDPR and replace it with a New Zealand-style privacy law if it forms a government. The document, signed by Nigel Farage, Richard Tice and Robert Jenrick, says the UK’s 5.7 million small and medium enterprises employ 16.9 million people, and cites research claiming GDPR cut European tech venture investment by 25% and halved new apps added to Google Play from Europe. It is a policy pledge, not a bill: Reform UK would need to win a general election and legislate. The document does not set a repeal timeline or address the ePrivacy regime.

Reform UK contract for 5.7 million small firms pledges to repeal GDPR →

EDPS conditions Europol’s OSINT platform on oversight as Commission seeks expanded powers

The European Data Protection Supervisor published its prior consultation opinion on Europol’s Internet-Facing Operational Environment — Quick Reaction Area on January 13, 2026, conditioning the platform on oversight requirements. The EDPS found the IFOE-QRA risks becoming a parallel environment to Europol’s regular systems, where staff could conduct fishing expeditions without any nexus to an ongoing criminal investigation. Statewatch published the full opinion on September 18, 2026. On June 24, 2026, the European Commission proposed expanding Europol’s powers with a €3 billion budget for 2028 to 2034, letting it proceed with sensitive processing without prior EDPS approval when it deems the matter urgent.

EU Watchdog: Europol’s Internet Surveillance Tool Cannot Launch Without Oversight Conditions →

InjectEave pulls audio from headphones at up to 30 meters, bypassing encryption

Researchers at the Hong Kong University of Science and Technology in Guangzhou and Hong Kong Polytechnic University developed InjectEave, which uses injected radio signals to extract audio from headphones, phones and smart-home devices. Presented at USENIX Security 2026, the technique transmits an electromagnetic signal between 0 MHz and 9 MHz toward a device, where nonlinear components mix it with low-frequency activity and re-emit a readable signal. Tests on 11 commercial products, including Sony, HP, Philips and Apple devices, worked at more than two meters and through walls, with device-specific ranges of one to six meters. With an RF amplifier, intelligible headphone audio was recovered from up to 30 meters. The researchers say encryption, masking and randomization cannot stop it because leakage comes from the analog path.

Researchers found a way to eavesdrop on headphones from 30 meters away, and encryption can’t stop it →

ChemSec: AI data center cooling drives PFAS production expansion

A ChemSec report found most of the world’s largest PFAS producers are expanding capacity because of demand from AI infrastructure, as newer data center cooling systems use fluorinated chemicals instead of water. Daikin, Arkema and Chemours are increasing PFAS production, driven by data center cooling, semiconductor manufacturing and lithium-ion battery materials. ChemSec’s 2023 analysis estimated the biggest PFAS makers earned roughly $4 billion in profit in 2022 against $17.5 trillion a year in societal costs. In July, 17 environmental organizations urged the EPA to reject Chemours’ application to fast-track Opteon 2P50, a new PFAS chemical for data center cooling. Chemours denied the concerns, saying the system operates as a closed loop.

Data centers are swapping water for forever chemicals to keep AI cool →

Meta CTO defends glasses as report points to camera-free Luna model

Meta CTO Andrew Bosworth used an Instagram AMA to argue that discussion of Meta’s glasses is shaped by a small number of bad actors, citing the recording indicator light and anti-tampering measures. A software update closed a loophole where a wearer could start recording, wait, then cover the light, and bricked cameras on units where the light had been drilled out; Meta said that covered fewer than one in a thousand glasses ever sold, which on seven million pairs is a large number. The Information reported Meta is preparing a camera-free version codenamed Luna with six microphones, pointing to a Connect unveiling on 23 September. Paris prosecutors have opened a criminal inquiry into sexual harassment linked to smart glasses.

Meta’s CTO says the glasses problem is a small number of bad actors. His company is reportedly about to launch a version without a camera. →

FTC sues Hims & Hers as telehealth health-data cases mount

The Federal Trade Commission’s latest lawsuit alleges telehealth pioneer Hims & Hers disclosed customers’ health data, signed them up for hard-to-cancel subscriptions and bypassed real-time consultations with doctors. Hims disputed the claims. The FTC has filed similar cases against more than a half-dozen telehealth companies, including BetterHelp and GoodRx, where regulators said health data was shared with Meta and Google without permission. HIPAA generally does not cover telehealth companies offering prescriptions, counseling and DNA tests, so the FTC relies on its broader authority over deceptive business methods. An analysis of nearly 50 telehealth companies selling GLP-1 drugs found less than a third required real-time video or audio consultation, and some prescriptions were approved within minutes.

Telehealth companies keep exposing their customers’ medical data. What should they do? →

EU citizens’ initiative seeks one million signatures against mandatory digital ID

A European Citizens’ Initiative opposing mandatory digital identity and age checks online has opened for signatures as the EU expands digital verification. Called Stop Killing The Internet: No Digital ID & No Age Verification, it seeks to protect internet access without requiring identification, and organisers have up to a year to collect at least one million signatures across the EU. Success would bring a public hearing in the European Parliament, and the European Commission would have to formally respond. The campaign originates in Stop Killing Games, which collected more than one million signatures against publishers making games unplayable after ending support. Member states are expected to have European Digital Identity Wallets ready by the end of 2026.

One million signatures sought to stop mandatory online ID and age checks - EU Perspectives →

EDRi: EU age-verification blueprint leaves linkability and security gaps

The European Commission will present a legislative proposal for a social media ban at the State of the European Union address, relying on an EU age-verification app that Ursula von der Leyen announced in July 2026 as technically ready. EDRi notes the Commission had published only a blueprint plus a demo app nicknamed the mini-wallet, based on the eID Wallet each government must provide residents by the end of 2026. The blueprint uses the optional SHOULD for Zero-Knowledge Proofs rather than the mandatory SHALL, and recommends that an attestation provider also act as the age-verification app provider, centralising issuance and presentation. An independent security review found serious basic security problems in the demo app, and 438 researchers warned of privacy disasters on breach, subpoena or malicious action.

Why the EU age-verification tool does not solve privacy concerns - European Digital Rights (EDRi) →

RSA-896 factored with Claude as AI-assisted cryptanalysis sets second record in 16 days

On September 19, 2026, Anthropic engineer Stephen A. Weis published the prime factorization of RSA-896, a 270-decimal-digit semiprime from RSA Security’s RSA Factoring Challenge, accomplished with help from Claude. The result moves the public integer-factorization record from 862 bits to 896 bits, sixteen days after Eric Lu of Cognition set the prior record with RSA-260 on September 3 using the Devin AI coding agent. Weis used the General Number Field Sieve built on CADO-NFS, tasked Claude with porting it to GPUs, and peaked at 2,048 GPUs consuming roughly 30 GPU-years over about ten days. Weis stated no new algorithmic improvements were made and no new threats to deployed keys exist; RSA-1024 remains unfactored publicly.

RSA-896 Cracked with Claude AI, Second Factoring Record in Sixteen Days →

Canada bill would fine firms 5% of global revenue for re-identifying data

Canada’s proposed Protecting Privacy and Consumer Data Act would let courts fine an organisation up to C$25 million or 5% of its gross global revenue, whichever is greater, for knowingly re-identifying de-identified personal information, failing to report a data breach or obstructing the new privacy regulator. Bill C-36 received first reading on June 15, 2026, and returns to the parliamentary agenda when the House of Commons reconvenes on September 21, 2026. The administrative penalty regime caps penalties at the greater of C$10 million and 3% of gross global revenue, with a ceiling per investigation rather than per violation. Re-identification under section 75 is handled as a potential criminal offence when done knowingly.

Firms could face 5% revenue fines for re-identifying data in Canada →

Edelson Lechtzin investigates Edenred Pay breach exposing Social Security numbers

Edelson Lechtzin LLP is investigating data privacy claims arising from a breach at GlobalvCard LLC, doing business as Edenred Pay, a corporate payments company headquartered in Bonita Springs, Florida, and a U.S. subsidiary of the Edenred Group. Edenred Pay disclosed the breach to the Massachusetts Office of Consumer Affairs and Business Regulation on September 15, 2026, and has begun notifying affected individuals. The notification did not state when the breach occurred, when it was discovered, or how many people were affected. Names, mailing addresses and Social Security numbers may have been compromised. Edenred Pay said it revoked compromised access credentials, secured impacted systems and implemented enhanced monitoring. The firm is offering free case evaluations and advises enrolling in Cyberscout monitoring before the 90-day deadline.

EDENRED PAY DATA BREACH: Edelson Lechtzin LLP Launches Investigation Into Exposure of Social Security Numbers →

Amazon SES tracking requires explicit opt-in under CNIL and ePrivacy guidance

Multiple data protection authorities, including in the EU and Canada, have issued guidance requiring explicit opt-in consent before deploying open tracking pixels or click link wrapping in email. Amazon SES enables open and click tracking only when explicitly configured, inserting a 1×1 pixel served from awstrack.me or rewriting links to redirect through it. Tracking activates only when an event destination includes OPEN or CLICK, and per-request overrides through the ConfigurationOverrides object take precedence over the configuration set. France’s CNIL recommends collecting tracking consent at the point of email address collection via a clearly labeled, unchecked checkbox separate from marketing consent, stored with a timestamp and source. Once an email is delivered with a tracking pixel, it cannot be retroactively deactivated.

Achieving CNIL/EU ePrivacy compliance for email tracking with Amazon SES →

Mozilla review finds all 25 car brands failed privacy standards

Chinese connected cars are not uniquely worse for privacy than Western models, though they add a second layer of risk, as brands including Jaecoo, Omoda, Great Wall Motor and BYD gain UK market share. A 2023 Mozilla review found all 25 car brands examined, among them BMW, Ford, Toyota, Tesla, Kia and Nissan, failed consumer privacy standards, with some collecting facial expressions, weight, health status and location history. Mozilla privacy expert Jen Caltrider called the vehicles information-collecting monstrosities. The US Federal Trade Commission issued a five-year ban prohibiting General Motors from selling customer location and driving telemetry to data brokers, and Australia’s privacy watchdog launched formal investigations into Toyota and Hyundai.

‘Information-collecting monstrosities’ — Are Chinese connected cars really worse for your privacy? →

Residents push back on Flock license plate cameras as cities cancel contracts

Residents across the U.S. are pushing back against Flock automated license plate readers through mapping, records requests, petitions and public meetings. Volunteers with DeFlock Maps document readers and add locations to OpenStreetMap, while the EFF’s Atlas of Surveillance lets users search by city or police agency. In Saranac Lake, New York, trustees voted 4–1 to cancel the contract after dozens filled the room. In Syracuse, New York, Central Current found the department had granted other agencies access to data the contract said would stay internal, and searches reached Syracuse’s data nearly 4.4 million times over roughly a year. In Winona, Minnesota, all eight police-operated Flock cameras were stolen.

How people are fighting back against Flock cameras →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches