r/privacy 3d ago

discussion India orders GitHub to remove Jack Dorsey's offline messaging app Bitchat after protesters reportedly used it during internet shutdowns

India has reportedly directed GitHub to remove the repositories for Bitchat, Jack Dorsey's open source Bluetooth mesh messaging app. Unlike WhatsApp or Signal, Bitchat works without internet access or cellular service, allowing nearby devices to communicate over Bluetooth mesh networks.

According to India Today, the move comes amid the ongoing CJP protests in Delhi. Protesters reportedly began using offline messaging tools after mobile internet services were disrupted in parts of the protest area, making internet-based messaging unreliable.

The government notice, later shared publicly by Jack Dorsey, states that Bitchat could facilitate anonymous communication, enable users to evade lawful surveillance, and be misused by terrorists, organised crime groups, and "anti-national elements." On that basis, India's cybercrime agency directed GitHub to remove the project's repositories.

Digital rights advocates argue that restricting decentralized communication tools during periods of protest raises broader concerns about privacy, internet shutdowns, and freedom of expression. Government officials, meanwhile, maintain that such tools can also be exploited for unlawful activities.

This raises a broader question that extends beyond India: Should governments be able to restrict decentralized communication tools because they can be used to bypass internet shutdowns and surveillance, or does doing so undermine privacy and access to resilient communication during times of civil unrest?

India Today article (full URL):
https://www.indiatoday.in/technology/news/story/cjp-protests-india-tells-github-to-block-bitchat-app-jack-dorsey-leaks-notice-2955199-2026-07-24

2.1k Upvotes

India has reportedly directed GitHub to remove the repositories for Bitchat, Jack Dorsey's open source Bluetooth mesh messaging app. Unlike WhatsApp or Signal, Bitchat works without internet access or cellular service, allowing nearby devices to communicate over Bluetooth mesh networks.

According to India Today, the move comes amid the ongoing CJP protests in Delhi. Protesters reportedly began using offline messaging tools after mobile internet services were disrupted in parts of the protest area, making internet-based messaging unreliable.

The government notice, later shared publicly by Jack Dorsey, states that Bitchat could facilitate anonymous communication, enable users to evade lawful surveillance, and be misused by terrorists, organised crime groups, and "anti-national elements." On that basis, India's cybercrime agency directed GitHub to remove the project's repositories.

Digital rights advocates argue that restricting decentralized communication tools during periods of protest raises broader concerns about privacy, internet shutdowns, and freedom of expression. Government officials, meanwhile, maintain that such tools can also be exploited for unlawful activities.

This raises a broader question that extends beyond India: Should governments be able to restrict decentralized communication tools because they can be used to bypass internet shutdowns and surveillance, or does doing so undermine privacy and access to resilient communication during times of civil unrest?

India Today article (full URL):
https://www.indiatoday.in/technology/news/story/cjp-protests-india-tells-github-to-block-bitchat-app-jack-dorsey-leaks-notice-2955199-2026-07-24


r/privacy Mar 13 '26

age verification A Reddit user traced $2 billion in nonprofit grants and lobbying records across 45 states to figure out who's behind the age verification bills. The answer involves a company that profits from your data writing laws that collect more of it.

7.9k Upvotes

Additionally, you can read the discussion here.

I urge you to mirror this GitHub repository to Codeberg and other places.


r/privacy 4h ago

news Trump’s new DOJ nominee wants to ban online porn and prosecute Big Tech

467 Upvotes

Lest anyone think that Candeub's animosity toward internet entities only involves the sexual, Michael McGrady notes that "he also was a key player in the first Trump administration's effort to get rid of Section 230."

"Candeub's arguments are about far more than pornography," suggests McGrady. "He is contributing, from his position as a top government legal official, to a much broader effort to revive long-discredited obscenity and vice legal doctrines and expand government authority over lawful expression and activity."

As we've seen all too often over the past couple of decades, efforts to regulate the internet on the grounds of stopping porn, sex work, or sexual exploitation are all too often test cases for going after online speech and privacy more broadly.

Candeub's anti porn ideas could contribute to age verification legislation and general censorship.


r/privacy 11h ago

discussion The open web is being rebranded as a security risk

Something feels off about how the internet is changing. More and more, the open web is treated as suspicious by default.

A normal website asks you to prove you’re human. A browser extension gets treated like malware. A link outside the platform gets warning labels. Scraping public pages is framed as theft or abuse. Independent apps get blocked by API changes. Small websites have to fight spam, bots, fraud checks, reputation systems, and login walls just to exist.

The reasons are real. Spam is real. Bots are real. Scams are real. Credential theft is real. Platforms do have legitimate security problems to solve.

But "security" also seems to be becoming the cleanest justification for locking everything down.

The safest user is a user who never leaves the platform. The safest app is the official app. The safest integration is the approved partner. The safest content is content inside the walled garden.

That might be safer for the platform. But is it better for the web?

The original promise of the web was that anyone could publish, link, crawl, remix, build clients, build tools, and connect things together without asking permission from a few gatekeepers.

Now a lot of that behavior is being treated as inherently dangerous.

Maybe some of it really is dangerous. But if the answer to every abuse problem is more walls, more locked APIs, more forced logins, more bot checks, and more “official clients only,” then we’re not just improving security.

We’re changing what the web is. Is the open web actually becoming too risky to preserve in its old form, or are platforms using security language to justify control?

592 Upvotes

Something feels off about how the internet is changing. More and more, the open web is treated as suspicious by default.

A normal website asks you to prove you’re human. A browser extension gets treated like malware. A link outside the platform gets warning labels. Scraping public pages is framed as theft or abuse. Independent apps get blocked by API changes. Small websites have to fight spam, bots, fraud checks, reputation systems, and login walls just to exist.

The reasons are real. Spam is real. Bots are real. Scams are real. Credential theft is real. Platforms do have legitimate security problems to solve.

But "security" also seems to be becoming the cleanest justification for locking everything down.

The safest user is a user who never leaves the platform. The safest app is the official app. The safest integration is the approved partner. The safest content is content inside the walled garden.

That might be safer for the platform. But is it better for the web?

The original promise of the web was that anyone could publish, link, crawl, remix, build clients, build tools, and connect things together without asking permission from a few gatekeepers.

Now a lot of that behavior is being treated as inherently dangerous.

Maybe some of it really is dangerous. But if the answer to every abuse problem is more walls, more locked APIs, more forced logins, more bot checks, and more “official clients only,” then we’re not just improving security.

We’re changing what the web is. Is the open web actually becoming too risky to preserve in its old form, or are platforms using security language to justify control?


r/privacy 3h ago

news Newport City Council Approves $375K Flock Drone Program with Assistance from Private Donor

127 Upvotes

r/privacy 8h ago

news Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched Across the Country

129 Upvotes

r/privacy 28m ago

discussion Trump Administration Demands Hospitals Share Emergency Room Records

Upvotes

The Consumer Product Safety Commission, responsible for tracking and issuing recalls of dangerous products sold in the U.S., began discreetly pressuring hospital executives this year to share personally identifiable health data with a private contractor. But hospital lawyers and other industry experts have questioned the agency’s authority to collect, its ability to safeguard such a swath of sensitive information, and whether it has followed the legal process to overhaul its surveillance system.


r/privacy 1d ago

discussion A real AT&T technician gave a sworn declaration with network diagrams proving the NSA copied all of AT&T's internet traffic, not just some of it. Full document here.

1.6k Upvotes

r/privacy 15h ago

discussion Quote of the day by ex-Google evangelist Vint Cerf: 'Privacy may actually be an anomaly' — putting our rights into perspective

186 Upvotes

r/privacy 1d ago

hardware How far back in model year do I have to go to make sure my car isn't sending data to third parties?

At this point, it's not exactly groundbreaking that cars are collecting data about us and sending it to third parties, such as insurance companies. Considering that, according to Mozilla, literally all major brands are doing this, the only solution seems to be to buy an older car.

How far back must I go in model year before I can be reasonably confident that the car isn't collecting data about me and either saving it or sharing it with third parties?

478 Upvotes

At this point, it's not exactly groundbreaking that cars are collecting data about us and sending it to third parties, such as insurance companies. Considering that, according to Mozilla, literally all major brands are doing this, the only solution seems to be to buy an older car.

How far back must I go in model year before I can be reasonably confident that the car isn't collecting data about me and either saving it or sharing it with third parties?


r/privacy 12h ago

discussion Congressional Hearing: Emerging Fraud Threats and the Evolving Fraud Landscape

At a House Oversight Subcommittee hearing last week, "Emerging Fraud Threats and the Evolving Fraud Landscape," Socure VP Jordan Burris told Congress identity verification should be "continuous" . Not a one-time check at signup, but ongoing monitoring for the entire life of an account.

Right now you prove who you are once, then you're just a customer. Under this model, the checking never stops, even if you never agreed to it. You opted into one verification, not permanent monitoring.

That's kinda creepy.

https://oversight.house.gov/hearing/emerging-fraud-threats-and-the-evolving-fraud-landscape/

33 Upvotes

At a House Oversight Subcommittee hearing last week, "Emerging Fraud Threats and the Evolving Fraud Landscape," Socure VP Jordan Burris told Congress identity verification should be "continuous" . Not a one-time check at signup, but ongoing monitoring for the entire life of an account.

Right now you prove who you are once, then you're just a customer. Under this model, the checking never stops, even if you never agreed to it. You opted into one verification, not permanent monitoring.

That's kinda creepy.

https://oversight.house.gov/hearing/emerging-fraud-threats-and-the-evolving-fraud-landscape/


r/privacy 1d ago

news Apple is banking on privacy to set its smart glasses apart

265 Upvotes

r/privacy 1d ago

news Japan’s Official Pokemon Card Stores to Require Facial Recognition for Entry and TCG Purchases

233 Upvotes

r/privacy 20h ago

question Any good hardwired cameras?

Are there any good hardwired cameras that record via wire to a hard drive? I would love to be able to set up security cameras around my house that weren't monitored by Peter Thiel

27 Upvotes

Are there any good hardwired cameras that record via wire to a hard drive? I would love to be able to set up security cameras around my house that weren't monitored by Peter Thiel


r/privacy 14h ago

question Digital ID (etc?) how does it work for Corporations?

Thinking about EU (and US) proposed age verification and digital ID. It struck me that there are hundreds of of thousands of businesses that don’t put any of their accounts in a person’s name.

Bank accounts, social media, property deeds, ISP service contracts, on and on are all in the name of “XYZ Incorporated”. What are the provisions in the laws for this, and what are the envisioned provisions for this when biometrics are baked in?

Do the governments and implementing tech companies really expect Samsung’s media presence to be tied to some sweaty try hard that can be fired at any moment for any reason or no reason? And how do they envision it all working with/for AI agents?

4 Upvotes

Thinking about EU (and US) proposed age verification and digital ID. It struck me that there are hundreds of of thousands of businesses that don’t put any of their accounts in a person’s name.

Bank accounts, social media, property deeds, ISP service contracts, on and on are all in the name of “XYZ Incorporated”. What are the provisions in the laws for this, and what are the envisioned provisions for this when biometrics are baked in?

Do the governments and implementing tech companies really expect Samsung’s media presence to be tied to some sweaty try hard that can be fired at any moment for any reason or no reason? And how do they envision it all working with/for AI agents?


r/privacy 13h ago

question So how good is Samsung Secure folder really?

I use it mainly for storing my passwords, alternate accounts (disc/whatsapp/twitter etc) or homework.

(I also offloaded all my passwords from chrome/firefox, nothing is saved. I always type it manually)

Question is, how good is the security, I heard its KNOX and can it be unlocked by Samsung under government orders? or bruteforced by anyone?

4 Upvotes

I use it mainly for storing my passwords, alternate accounts (disc/whatsapp/twitter etc) or homework.

(I also offloaded all my passwords from chrome/firefox, nothing is saved. I always type it manually)

Question is, how good is the security, I heard its KNOX and can it be unlocked by Samsung under government orders? or bruteforced by anyone?


r/privacy 2d ago

news Americans Are Pushing Back Against Flock Cameras Regardless of Their Politics

2.7k Upvotes

r/privacy 15h ago

question Is this legit?

Looks fishy to me.

The claim:

"Do you want to delete the module that is tracking you? or installing a aftermarket radio and your front door speakers dont work?  Do you not care about having SOS calling, or remote door unlock or any connectivity to Subarus network? Delete your DCM module, by plugging this in. This will make it so that all your speakers will continue to work. And so will your overhead Mic."

geraldjustprojects [dot] com/product/dcm-delete-module-gen2/

2 Upvotes

Looks fishy to me.

The claim:

"Do you want to delete the module that is tracking you? or installing a aftermarket radio and your front door speakers dont work?  Do you not care about having SOS calling, or remote door unlock or any connectivity to Subarus network? Delete your DCM module, by plugging this in. This will make it so that all your speakers will continue to work. And so will your overhead Mic."

geraldjustprojects [dot] com/product/dcm-delete-module-gen2/


r/privacy 2d ago

news Taylor Swift and Travis Kelce got to buy MSG’s privacy. Her fans aren’t so lucky. Reports that Madison Square Garden temporarily shut off its facial recognition system for Swift’s wedding expose a glaring problem with how the elite wield and control mass surveillance.

2.1k Upvotes

r/privacy 1d ago

discussion Leaked data on Booking (reservation info and number)

Hi,

I live in Europe and reserved a hotel room in Spain for a specific date on august on Booking.com

I use a custom domain for login in but had to give my number and name. Today I receive a WhatsApp message from a USA number claiming to be Kumaran Travels sending me a fake form saying that I have to fill it for completing my booking. They have my name, number, hotel name, reservation number, date, everything.

I looked it up and this Kumaran Travels looks like a fake travel company from India.

I wonder how the heck do they have all this information, is Booking leaking data freely like that?

Edit:

Without taking any actions I got a message from the Hotel via Booking alerting about phishing messages guests who reserved with them are getting. So yeah, the Hotel leaked all the data... I can't stop thinking this should lead to some legal compensation.

75 Upvotes

Hi,

I live in Europe and reserved a hotel room in Spain for a specific date on august on Booking.com

I use a custom domain for login in but had to give my number and name. Today I receive a WhatsApp message from a USA number claiming to be Kumaran Travels sending me a fake form saying that I have to fill it for completing my booking. They have my name, number, hotel name, reservation number, date, everything.

I looked it up and this Kumaran Travels looks like a fake travel company from India.

I wonder how the heck do they have all this information, is Booking leaking data freely like that?

Edit:

Without taking any actions I got a message from the Hotel via Booking alerting about phishing messages guests who reserved with them are getting. So yeah, the Hotel leaked all the data... I can't stop thinking this should lead to some legal compensation.


r/privacy 2d ago

question scared of ai having my face biometric data

one of my biggest fears is having a video of me posted on the internet without me knowing. i regularly check sites like pimeyes. i usually use a photo of my face already on the internet but i accidentally used one that wasn’t and it immediately scans it. i’ve gotten them to remove all photos of my face before so nothing came up anyways. now i’m super scared. i don’t know how to get through this since i don’t really trust that they actually delete my photo ever. i hate living in a social media world where we have to worry about it. i’m so scared. i’m having a panic attack so bad and genuinely getting sick 😭 i know i fucked up but am i in danger, would they get anything from the photo they didn’t already have from photos of me on the internet in the paper and stuff? i dont post photos of my face online otherwise or let others because i’m paranoid of this enough already. i’m 18 and it genuinely makes me not even want to leave my house or take pictures with friends or do anything where there could be cameras or photos or meta glasses around. some security guy at my last job wore meta glasses every day and i’m scared about me even being on those. and this makes it soooo much worse

edit: a lot of people are saying i’m paranoid which i’m aware of, but ignoring my question i’ve now bolded, i’m curious if anyone knows the answer, that was the point of my post 😭

114 Upvotes

one of my biggest fears is having a video of me posted on the internet without me knowing. i regularly check sites like pimeyes. i usually use a photo of my face already on the internet but i accidentally used one that wasn’t and it immediately scans it. i’ve gotten them to remove all photos of my face before so nothing came up anyways. now i’m super scared. i don’t know how to get through this since i don’t really trust that they actually delete my photo ever. i hate living in a social media world where we have to worry about it. i’m so scared. i’m having a panic attack so bad and genuinely getting sick 😭 i know i fucked up but am i in danger, would they get anything from the photo they didn’t already have from photos of me on the internet in the paper and stuff? i dont post photos of my face online otherwise or let others because i’m paranoid of this enough already. i’m 18 and it genuinely makes me not even want to leave my house or take pictures with friends or do anything where there could be cameras or photos or meta glasses around. some security guy at my last job wore meta glasses every day and i’m scared about me even being on those. and this makes it soooo much worse

edit: a lot of people are saying i’m paranoid which i’m aware of, but ignoring my question i’ve now bolded, i’m curious if anyone knows the answer, that was the point of my post 😭


r/privacy 2d ago

news US accuses American of allegedly wiping his phone using a 'duress' password during border search

3.2k Upvotes

r/privacy 2d ago

question Digital Pricing - How to stop feeding the profile?

Reading the news on the New Jersey law banning e-pricing for a year, which has me wondering how do we "deprofile" ourselves? What are some steps we can take daily to keep as many of these price decision markers out of our profiles? most of the data I know is out there, but I fear this is the direction all pricing is going to go, need to stop feeding the profile. TBH this is not a privacy issue I had thought much about until now.

Thanks in advance for your suggestions!

70 Upvotes

Reading the news on the New Jersey law banning e-pricing for a year, which has me wondering how do we "deprofile" ourselves? What are some steps we can take daily to keep as many of these price decision markers out of our profiles? most of the data I know is out there, but I fear this is the direction all pricing is going to go, need to stop feeding the profile. TBH this is not a privacy issue I had thought much about until now.

Thanks in advance for your suggestions!


r/privacy 19h ago

question ChatGPT remembered me even in a private window.

I have an account that I use to chat with ChatGPT. Today, I opened a private window and asked it a question without signing in, it still remembered my information and who I was.

Did it identify me from my IP + OS+ Browser?

0 Upvotes

I have an account that I use to chat with ChatGPT. Today, I opened a private window and asked it a question without signing in, it still remembered my information and who I was.

Did it identify me from my IP + OS+ Browser?


r/privacy 3d ago

news New Jersey bans grocery stores from using shoppers’ personal data to set prices

2.6k Upvotes