tracking the news, one byte at a time

Hackers July 27, 2026: dickovers 21 Jul 2026, US Leaves Them Vulnerable, Pluralistic California’s privacy obstacle course, and more

2,518 words

|

11–16 minutes

Composite featured image for Hacker Community — 2026-W30
Audio
0%

Hacker Community

Pluralistic: Dealing with dickovers (21 Jul 2026) dickovers (Pluralistic.Net)

Summary: Cory Doctorow’s latest Pluralistic post coins and dissects the ‘dickover’—the modal popover that websites use to force unwanted interactions, particularly cookie-consent dialogs in the EU and UK. He argues these are a form of malicious compliance with GDPR, and offers a practical toolkit for users to block them, from Firefox’s Reader Mode to Adblock Plus element blocking. The post frames these tools as a form of ‘bargaining back’ against surveillance capitalism, and urges technically proficient users to help ‘normies’ reclaim their browsing experience.

Pluralistic: Dealing with dickovers (21 Jul 2026) dickovers
Image via Pluralistic.Net

Why it matters: For the hacker community, this is a field manual for reclaiming the web from hostile UX and surveillance-by-default. It’s a concrete, actionable countermeasure to the enshittification of the browser, and a reminder that the fight for user agency is fought one element at a time.

Context: The piece builds on Doctorow’s ongoing ‘enshittification’ thesis and the broader movement for user sovereignty online. It also connects to the long history of pop-up blockers, which eventually made pop-ups obsolete, suggesting a similar fate for dickovers if enough users adopt these tools.

"Today’s links – Dealing with dickovers: The web is an open platform, and that matters. – Hey look at this: Delights to delectate. – Object permanence: Broadcast’s bad week; Congress v wifi;." — PLURALISTIC.NET

Commentary: This is a classic ‘tool release’ and ‘ignored warning’ signal: the tools are the community’s answer to a systemic failure of both regulation and corporate ethics. The call to ‘seize the means of computation’ for normies is a direct challenge to the tech industry’s assumption that users are passive consumers. The piece’s practical focus—exact extensions, config toggles, and bookmarklets—makes it a workshop-ready resource, not just a polemic. It’s a reminder that the most effective resistance to surveillance capitalism is often a well-configured browser.

Date: July 21, 2026 04:49 AM ET
URL: https://pluralistic.net/2026/07/21/dickovers/
AI Sentiment Score: Negative (66%)
AI Credibility Score: 10.0/10 — High
Scores and text generated by AI analysis of the source article indicated.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now (Wired)

Summary: UC San Diego researchers found that the KARR Security System, an aftermarket car alarm installed by dealers in over 2 million US vehicles, has a critical vulnerability: a single shared authentication key lets anyone within Bluetooth range unlock cars, disable ignitions, or trigger mass chaos. The vendor, Acrisure Protection Group, took 18 months to release a patch, and many owners don’t know the device is installed. The researchers will present findings at Defcon and Usenix next month.

A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now
Image via Wired

Why it matters: This is a textbook case of security debt in the automotive supply chain: a hidden, dealer-installed component with a universal key that bypasses all the usual patching channels. It shows how aftermarket add-ons can become a backdoor into critical vehicle systems, and how the patch process fails when the affected party isn’t the buyer.

Context: The vulnerability was discovered by UCSD researchers who reverse-engineered the KARR app and extracted a shared authentication key. The device’s Bluetooth beacon also allows tracking via WiGLE, turning a car’s location into an open database for thieves.

"As modern cars have evolved into multi-ton computers on wheels, drivers are beginning to learn they need to install security updates for their vehicles’ code, just as they would for a phone." — WIRED

Commentary: The 18-month gap between disclosure and patch, plus the company’s dismissive ‘low risk’ framing, is a familiar pattern: vendors downplay until forced by conference deadlines. The real lesson is that the dealer-installed supply chain is a blind spot for security research and regulation. Expect this to become a case study in why aftermarket telematics and security devices need independent audit and a clear owner-consent model.

Date: July 21, 2026 06:00 AM ET
URL: https://wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now
AI Sentiment Score: Negative (83%)
AI Credibility Score: 10.0/10 — High
Scores and text generated by AI analysis of the source article indicated.

Pluralistic: California’s privacy obstacle course (23 Jul 2026) (Pluralistic.Net)

Summary: California’s new DROP (Delete Request and Opt-out Platform) tool, launching next month, requires residents to navigate a Kafkaesque authentication gauntlet—Login.gov ID, selfies, driver’s license photos, VINs, and mobile ad identifiers—just to request deletion from data brokers. Cory Doctorow argues the process is deliberately obstructive, designed to maintain the fiction that surveillance is consensual, and contrasts it with the zero-step process for data brokers to collect and sell data. The piece frames DROP as a ‘malicious compliance’ outcome of states avoiding the obvious solution: banning data brokers outright.

Pluralistic: California's privacy obstacle course (23 Jul 2026)
Image via Pluralistic.Net

Why it matters: For the hacker community, DROP is a case study in how well-meaning privacy regulations can be weaponized into bureaucratic friction, effectively preserving the status quo. It highlights the gap between policy intent and implementation, and the need for technical workarounds or advocacy for simpler, default-opt-out systems.

Context: The piece is part of Doctorow’s ongoing critique of surveillance capitalism, following his earlier coverage of the CFPB’s ban on data brokers (reversed under Trump) and the broader ‘enshittification’ framework. It also echoes his long-standing argument that privacy should be the default, not an opt-out privilege.

"Today’s links – California’s privacy obstacle course: Malice or incompetence (why not both?). – Hey look at this: Delights to delectate. – Object permanence: Continuous partial attention, TSA is the worst; Trump’s." — PLURALISTIC.NET

Commentary: The DROP process is a textbook example of ‘security theater’ applied to privacy rights, where the burden of proof is placed on the individual rather than the data broker. The requirement to provide a mobile ad identifier—the very thing that enables tracking—is a particularly cruel irony, forcing users to dig through settings or install a permission-hungry app to retrieve it. This is a signal for the hacker community: the fight isn’t just about building tools, but about exposing and dismantling these bureaucratic obstacles. Expect to see community-built guides or scripts that automate the DROP process, or even a push for a ‘DROP-as-a-service’ that handles the paperwork for users.

Date: July 23, 2026 06:27 AM ET
URL: https://pluralistic.net/2026/07/23/drop-a-dime/
AI Sentiment Score: Negative (91%)
AI Credibility Score: 10.0/10 — High
Scores and text generated by AI analysis of the source article indicated.

The Corrupt, Xenophobic Hysteria Behind The ‘TikTok Ban’ Will Soon Be Mirrored Across U.S. AI Policy (Techdirt)

Summary: Techdirt argues that the U.S. government’s handling of TikTok—marked by protectionism, xenophobia, and a disregard for actual privacy or security—is now being replicated in AI policy. The Trump administration is signaling potential bans on Chinese AI models, which could extend to open-source and on-device alternatives, as U.S. tech giants struggle to compete with cheaper, often open-weight Chinese models. The piece highlights how companies like DoorDash are already adopting Chinese models for cost and quality, and warns that such bans will not stop global adoption but will harm U.S. innovation and market competitiveness.

The Corrupt, Xenophobic Hysteria Behind The ‘TikTok Ban’ Will Soon Be Mirrored Across U.S. AI Policy
Image via Techdirt

Why it matters: For the hacker community, this signals a direct threat to open-source AI and the ability to run models locally, which are core to the movement’s ethos of decentralization and user control. A ban on open-weight models would be a major regulatory overreach, potentially criminalizing the very tools that many in the community build upon.

Context: The article follows the pattern of the TikTok saga, where national security rhetoric was used to justify a forced sale to politically connected buyers. It now sees the same playbook being applied to AI, with the administration already signaling bans on Chinese models, and the press likely to parrot the same flawed arguments.

"You might recall how the press and a bipartisan coalition of lawmakers suffered a four-year embolism about the purported privacy and national security threat of TikTok, before “fixing” the problem by ultimately." — TECHDIRT

Commentary: This is a classic ignored-warning signal: the same playbook that failed on TikTok is being reloaded for AI, but the stakes are higher because open-weight models are not a single app but a distributed infrastructure. The hacker community should watch for attempts to criminalize the use of certain models, which would be a direct attack on the right to tinker. The real battle will be over the definition of ‘open’ and whether the U.S. government can effectively ban a file format without breaking the internet.

Date: July 22, 2026 08:29 AM ET
URL: https://www.techdirt.com/2026/07/22/the-corrupt-xenophobic-hysteria-behind-the-tiktok-ban-will-soon-be-mirrored-across-u-s-ai-policy/
AI Sentiment Score: Negative (80%)
AI Credibility Score: 10.0/10 — High
Scores and text generated by AI analysis of the source article indicated.

iPhone exploit legal fight is really about who owns security research (Appleinsider)

Summary: A federal judge ordered the removal of the usbliter8 iPhone exploit publication after Magnet Forensics argued it was stolen trade secrets, not independent research. The injunction targets former Magnet engineer Mario Del Gaudio and Paradigm Shift, requiring deletion of the article and code. The case hinges on whether Del Gaudio’s knowledge was confidential or general expertise, and it raises unresolved questions about zero-day disclosure versus stockpiling.

iPhone exploit legal fight is really about who owns security research
Image via Appleinsider

Why it matters: This case tests whether security researchers can publish exploits that overlap with corporate zero-day capabilities, and whether trade-secret law will chill independent disclosure. The outcome will shape how forensic vendors and researchers handle vulnerability discovery, and whether courts side with secrecy or public disclosure.

Context: Magnet sells forensic tools to law enforcement; the exploit targets SecureROM on A12/A13 iPhones, requiring physical access. The judge’s preliminary injunction is a rare legal move against public exploit publication, and the case is being watched for its implications on security research and zero-day policy.

"A federal judge has ordered a public iPhone exploit taken offline after Magnet Forensics argued it wasn’t independent security research at all, but instead a stolen trade secret. U.S. District Judge Victoria." — APPLEINSIDER

Commentary: This is a classic ignored-warning signal: the exploit was published with Apple notified, but the legal system is now being used to suppress it. The judge’s refusal to grant forensic access suggests a narrow ruling, but the injunction itself is a chilling effect for researchers. The real fight is over whether a researcher’s memory and skills can be claimed as trade secrets—a question that could reshape the boundaries of independent research. Watch for whether Magnet’s case survives discovery, as the lack of source-code comparison weakens their claim.

Date: July 24, 2026 12:40 PM ET
URL: https://appleinsider.com/articles/26/07/24/iphone-exploit-legal-fight-is-really-about-who-owns-security-research
AI Sentiment Score: Negative (87%)
AI Credibility Score: 10.0/10 — High
Scores and text generated by AI analysis of the source article indicated.

DOJ Withdraws NY Times Subpoenas After Judge Notices It Never Bothered To Follow The Rules For Subpoenaing Reporters (Techdirt)

Summary: The Trump DOJ withdrew subpoenas targeting NY Times journalists after Judge Arun Subramanian exposed a cascade of procedural failures, including overbroad requests that swept in reporters’ relatives’ phone records and a failure to notify the issuing judge that the targets were journalists. The DOJ initially defended the subpoenas as ‘properly’ issued, then blamed ‘inadvertent errors’ and ‘trying to move quickly’ before capitulating. The judge openly considered sanctions, and the DOJ responded with a public statement attacking the judge and vowing to continue the leak investigation.

DOJ Withdraws NY Times Subpoenas After Judge Notices It Never Bothered To Follow The Rules For Subpoenaing Reporters
Image via Techdirt

Why it matters: For the hacker community, this is a concrete case of government overreach in surveillance-adjacent subpoena power, showing how procedural shortcuts can be caught and rolled back—but only when a judge is willing to do the work. It also underscores the fragility of press protections when the executive branch treats rules as optional.

Context: The subpoenas were part of a leak investigation into reporting on security flaws in a 747 ‘gift’ from Qatar. The DOJ’s pattern of aggressive subpoena use against journalists has been a recurring issue, but this instance is notable for the judge’s explicit frustration and the DOJ’s public defiance after withdrawal.

"Here’s hoping we start seeing more lawyers getting referred to the Bar. There needs to be actual consequences to this level of incompetence, malice, and/or illegality. DOJ Withdraws NY Times Subpoenas After." — TECHDIRT

Commentary: This is a rare instance where the judicial process actually caught the DOJ’s overreach in real time, but the DOJ’s post-hearing statement suggests the lesson is not learned—it’s just a tactical retreat. For those who build or rely on secure communications, the takeaway is that legal protections are only as strong as the judge’s patience and the reporter’s willingness to fight. The ‘inadvertent errors’ framing is a reminder that institutional incompetence can be as dangerous as malice, especially when the state has the power to demand metadata.

Date: July 24, 2026 06:14 PM ET
URL: https://www.techdirt.com/2026/07/24/doj-withdraws-ny-times-subpoenas-after-judge-notices-it-never-bothered-to-follow-the-rules-for-subpoenaing-reporters/
AI Sentiment Score: Negative (75%)
AI Credibility Score: 10.0/10 — High
Scores and text generated by AI analysis of the source article indicated.

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required (Eff)

Summary: The Fourth Circuit ruled in U.S. v. Belmonte Cardozo that manual searches of electronic devices at the border are ‘routine’ and require no suspicion, while forensic searches still require individualized suspicion. The court distinguished manual from forensic searches based on human involvement, breadth, data recovery, and record permanence, but ignored that both access the same intimate data. EFF, which filed an amicus brief, warns that officers can now sidestep higher standards simply by choosing to search by hand. The court’s reliance on the two-minute duration of the search leaves open the possibility that longer manual searches might trigger higher scrutiny.

The Fourth Circuit Says Border Agents Can Search Your Phone By Hand, No Suspicion Required
Image via Eff

Why it matters: For hackers and privacy advocates, this creates a clear loophole: border agents can manually scroll through a phone’s contents—including messages, photos, and app data—without any suspicion, undermining the Fourth Amendment protections that Riley established for digital devices. It also signals a judicial willingness to treat the method of search as more important than the privacy impact, which could embolden similar reasoning in other circuits.

Context: The Fourth Circuit previously held in Kolsuz (2018) and Aigbekaen (2019) that forensic device searches at the border require individualized suspicion or a warrant, but left manual searches unresolved. This decision now creates a circuit split with the Ninth Circuit, which has applied a warrant requirement for all border device searches, and sets the stage for potential Supreme Court review.

"The court’s holding hinged on four differences between manual and forensic searches: (1) in a manual search, a person does the searching, not a machine; (2) a manual search’s breadth depends on the officer’s time and energy, while forensic searches are comprehensive; (3) manual searches reveal only what a user can typically access, while forensic searches can uncover deleted files, cached fragments, metadata, and more; and (4) manual searches are subject to an officer’s fading memory or imperfect notes, while forensic searches create a permanent copy." — EFF

Commentary: This is a classic ignored-warning signal: the court’s technical distinctions are cosmetic, not substantive—the privacy invasion is identical whether an agent’s thumb or a forensic tool does the scrolling. The two-minute search rationale is a ticking clock: as native search functions improve, manual searches can extract the same data in seconds, making the time-based distinction meaningless. Expect border agents to adopt manual searches as the default workaround, and watch for a Supreme Court petition that could finally resolve the circuit split—but don’t hold your breath for a privacy-friendly outcome.

Date: July 22, 2026 06:30 PM ET
URL: https://www.eff.org/deeplinks/2026/07/fourth-circuit-says-border-agents-can-search-your-phone-hand-no-suspicion-required
AI Sentiment Score: Negative (75%)
AI Credibility Score: 10.0/10 — High
Scores and text generated by AI analysis of the source article indicated.

Post ID: 92ca4e17