Peter James writes about his discovery that asking Meta's Muse agent to archive the files visible in its session resulted in a massive data export containing much of its internal runtime environment. The resulting 6.8 GB unpacked archive included Ubuntu system files, documentation for unreleased features like "Meta Home Link," various skill instructions, and sensitive-looking configuration files such as SSH keys and agent logs. While James reported the findings to Meta's bug bounty program, the company marked the report as "Not Applicable."
- The export contained a 68-skill directory covering services from Google Workspace to travel and shopping.
- Documentation revealed an experimental hardware integration called Meta Home Link using ESP32-C5 chips for Wi-Fi and Bluetooth LE access.
- Muse utilizes a nightly "dream" process that reviews conversations to update user guidance in files like ALIGNMENT_SYNTHESIS.md.
- Memory is managed via plain Markdown files, with an hourly background job extracting claims into searchable Postgres databases using embeddings.
Rich Edmonds writes about transitioning from subscription-based smart home services like Ring to a self-hosted local NVR system using Frigate. By moving video storage and AI detection onto his own hardware instead of relying on third-party clouds, he eliminated annual fees while gaining greater control over privacy and data retention.
- The author saved $85 per year by ditching Reolink ($35) and Ring ($50) subscriptions.
- A self-hosted setup using an old PC with Frigate can provide much longer video retention than cloud services.
- Building a custom NVR is not entirely free; the author's dedicated server consumes about 160 watts of power.
- Home Assistant integration allows for advanced features like Alarmo and LLM vision analysis via local models.
The East Palo Alto City Council has upheld a three-year contract with surveillance company Flock for automated license plate readers, despite recommendations from city staff and police to adopt shorter terms. The decision comes amid significant community opposition regarding data privacy, potential immigration enforcement implications, and the lack of an early cancellation clause without financial penalty.
Key points:
* Council rejected a recommendation for a one-year contract intended to ensure financial autonomy.
* Flock representatives reportedly withdrew the option to cancel the three-year agreement without paying the full remainder.
* Local residents and advocates expressed concerns over data security and unauthorized information sharing with outside agencies.
* Police leadership maintains the technology is vital for solving crimes amid staffing shortages.
Mozilla has introduced Thunderbolt, a new AI client designed to serve as a front-end for users and businesses wanting to manage their own self-hosted AI infrastructure. Built on the open-source Haystack framework, Thunderbolt functions as a sovereign AI client that allows integration with various ACP or OpenAI-compatible APIs while maintaining control over data privacy.
Key features and details:
* Designed for decentralized, self-hosted AI ecosystems rather than standalone proprietary models.
* Supports modular AI pipelines via the Haystack framework.
* Integrates locally stored enterprise data using open protocols and offline SQLite databases.
* Offers security through optional end-to-end encryption and device-level access controls.
* Compatible with Windows, Mac, Linux, iOS, Android, and web platforms.
* Managed by MZLA Technologies as part of Mozilla's broader push for open-source AI agency.
Researchers have demonstrated that large language models (LLMs) can identify pseudonymous users across different social media platforms with high accuracy, potentially undermining online privacy and opening users up to risks like doxxing and targeted advertising. The study highlights the growing capability of AI to deanonymize individuals based on their online activity, even with limited information.
The recent security issues with Jack Dorsey's BitChat, a messaging app built on Nostr, underscore a broader trend of prioritizing 'vibe coding' – rapid development based on enthusiasm – over robust security practices in the tech world. The article details how BitChat's lack of end-to-end encryption and reliance on centralized servers created vulnerabilities, allowing researchers to intercept messages. This highlights a concerning pattern where developers rush to market with minimal security considerations, potentially jeopardizing user data and privacy.
This article explores how to run an agent on a federated learning architecture, discussing the benefits, challenges, and steps involved.
A drive for the United States' first major data privacy legislation has bipartisan support in the divided Congress ahead of a House of Representatives committee hearing on Thursday, though it faces criticism from businesses and privacy advocates.