你的经期追踪应用(很可能)正在监视你。

qimuai 发布于 阅读:42 一手编译

你的经期追踪应用(很可能)正在监视你。

内容来源:https://www.wired.com/story/security-news-this-week-your-period-tracker-is-probably-spying-on-you/

内容总结:

旧金山警方无人机监控视频大量泄露,城市监控进入“颗粒度”时代

旧金山警察局大量无人机监控视频近日在公开网络上曝光,揭示了城市监控已进入一个极其精细且影响深远的新时代。与此同时,旧金山市检察官办公室本周向苹果和谷歌发出停止侵权函,要求这两家科技巨头从其应用商店中删除13款AI“脱衣”换脸应用,这些应用几乎 exclusively 被用于针对女性及女童。

Meta面部识别系统真相扑朔迷离,高管表态前后矛盾

自《连线》杂志6月首次报道Meta的“NameTag”面部识别系统以来,该公司高管对该功能是否真实存在一直做出模糊且矛盾的表述。我们梳理了关于这一真实系统的相关说法与事实。

特朗普继续坚称2020大选存在“干预”,所公布文件却自相矛盾

在周四的讲话中,美国总统唐纳德·特朗普继续推动关于2020年大选遭受干预的未经证实且早已被推翻的说法。他甚至承诺白宫网站公布的一批文件将包含重大内幕,但相关文件并未证实其主张,部分内容甚至与他自己的说法相矛盾。

AI工具快速普及,Anthropic推动美国各州监管AI

随着AI工具的采用范围迅速扩大且能力不断增强,科技巨头Anthropic继续推动美国各州对人工智能进行监管。谈及去年加州和纽约州的AI透明度要求,Anthropic美国州及地方政府关系主管塞萨尔·费尔南德斯本周告诉《连线》杂志:“2025年的透明度安全法案是一个非常重要的开端,但随着AI系统能力的快速提升,政策应对也必须跟上。”

更多安全与隐私新闻速览

每周我们都会汇总未能深度报道的安全与隐私新闻。点击标题阅读完整报道。祝您平安。

Mozilla为经期追踪应用隐私评分,仅一款获满分

根据BBC报道,Mozilla基金会联合哈佛大学伯克曼·克莱因中心对六款热门经期追踪应用进行的审计结果显示,占星主题的经期追踪应用Stardust将用户的生殖健康细节(如避孕类型、怀孕状态、情绪以及乳房胀痛、胃痉挛等具体症状)发送给了其隐私政策中未提及的一家数据公司。Stardust在10分制中仅得2分,为表现最差者。Mozilla研究员发现,该应用在用户输入任何信息前,自打开起就向第三方追踪器发送数据;用户记录症状的瞬间,相关信息便连同持久性用户ID一同发送给分析公司RudderStack,且应用内无法关闭该共享功能。RudderStack还能将数据进一步转发至Mozilla无法监测的目的地。该应用还向Facebook提供了广告标识符,以便将应用内行为与平台现有用户画像关联。该公司对TechCrunch表示,从未收到过关于用户数据的法律要求。

由非营利组织运营的追踪应用Euki则获得满分10分:无需注册账户,健康数据永不离开手机,用户可设置PIN码、定时自动删除,或在手机被强迫解锁时调出伪装界面。其唯一弱点是内置的用于浏览教育页面的浏览器会加载常规网络追踪器,但每次访问后标识符会被重置。

俄罗斯联邦安全局因网络攻击波兰基础设施遭制裁

俄罗斯联邦安全局(FSB)长期以来以高度复杂的网络间谍活动闻名,而将破坏性网络攻击留给总参情报总局(GRU)的黑客。但本周欧盟和英国的制裁,以及美国网络安全和基础设施安全局、FBI和NSA的联合公告,将一起针对波兰电网的网络攻击直接归咎于FSB第16中心。这是该克里姆林宫机构罕见地实施网络攻击并险些导致波兰电力及水务设施中断的案例。波兰政府称该攻击“非常接近”造成大规模停电。此次攻击最初被网络安全公司Dragos和ESET认定为GRU下属的“沙虫”组织所为,但波兰计算机应急响应团队随即反驳了这一结论,并将攻击归因于FSB,该结论现已获得西方各国政府的广泛共识。这一事件表明,FSB可能正逐渐展现出其GRU同僚那种不计后果、高度激进的攻击风格和打击目标。

涉俄国家背景黑客被曝曾任职于卡巴斯基

多年来,俄罗斯网络安全公司卡巴斯基一直被指与俄政府有联系,美国官员甚至禁止美国政府内部乃至最终全面禁止美国客户使用该公司产品。然而,相关关系的公开证据一直匮乏。据路透社报道,一名在波士顿面临黑客指控的俄罗斯人丹尼斯·奥布雷兹科,其涉嫌参与名为“Void Blizzard”或“Laundry Bear”的黑客组织,并曾在卡巴斯基工作过两年。美国检方称,在卡巴斯基任职后,他加入了另一家网络安全公司Yutek-NN,期间参与了该组织的黑客行动,窃取了多个北约国家政府及至少11家美国公司的数据和通讯。在加入卡巴斯基之前,奥布雷兹科还涉嫌曾在FSB工作,其在卡巴斯基的任职生涯恰好被两段为俄情报部门工作的经历所“包裹”。奥布雷兹科对黑客指控拒不认罪。卡巴斯基在声明中回应称,“所控罪行与该人在卡巴斯基任职期间的职务或职责无关”。

美国国土安全部真实数据泄露两度被误判为“误报”

一起足以让所有负责评估可疑网络活动的人深感焦虑的事件发生:美国国土安全部(DHS)官员曾两次将“国土安全信息网络”(HSIN)平台遭黑客入侵的迹象判定为“误报”,而事实上这是一次真实的入侵。据Nextgov/FCW报道,两个月前,用于在州、地方、联邦机构及外国伙伴间共享非机密数据的HSIN平台遭黑客入侵。联邦紧急事务管理署的分析师在5月中旬就发现了黑客活动迹象——修改文件和代码、劫持合法网络服务器、删除行为日志——但这些发现被当作“误报”驳回。数周后,黑客再次入侵并再次被发现,却再次被忽视。目前尚不清楚为何入侵迹象被误判,但这可能反映出联邦分析师在检测“离地攻击”技术时面临的日益严峻的挑战——这种技术利用网络本身的合法功能访问目标资产,而非使用更易被发现的恶意软件。尽管HSIN仅存储非机密数据,但参议院情报委员会副主席马克·华纳在声明中表示,这些信息“高度敏感”,“其泄露危及国家安全”。

黑客入侵AI音乐生成器,曝光其“爬取”内幕

据404 Media报道,AI音乐初创公司Suno通过从YouTube Music、Deezer、Genius以及一系列音频素材库中“爬取”了数百万首歌曲、歌词和播客内容来训练其模型。报道依据的是一份由入侵该公司的黑客提供的内部数据。此次入侵还暴露了数十万客户的账户信息,包括电子邮件、电话号码及Stripe支付记录。源代码中标注为2023年和2024年的数据集显示,仅YouTube Music的音频就达113,879小时,此外还有来自Pond5、Deezer等平台的数万小时音频——总计相当于数十年的音乐。其他文件显示,Suno通过Bright Data代理进行YouTube爬取,并使用PodcastIndex锁定约100万小时的播客内容。化名ellie.191的黑客称,他们通过使用“沙虫”蠕虫病毒入侵了一名员工的设备而实现突破。这些文件似乎证实了唱片行业的核心指控:Suno直接从YouTube抓取歌曲。该公司辩称其训练行为属于“合理使用”,并于去年11月与华纳音乐集团达成和解。该公司表示,此次入侵涉及的是过时代码,不包含敏感个人信息——然而,其数据出现在向404 Media分享的样本中的客户表示,从未收到过相关通知。

中文翻译:

旧金山警察局数小时的无人机监控视频在开放网络上曝光,揭示了一个极其细致且影响深远的城市监控新时代。与此同时,旧金山市检察官办公室本周向苹果和谷歌发送了停止侵权函,要求这两家科技巨头从其应用商店中删除13款“换脸”型AI脱衣应用,这些应用几乎专门针对女性和女孩。

自《连线》杂志六月首次报道Meta的名牌人脸识别系统以来,该公司高管对该功能是否真实存在一直发表着模糊且矛盾的说法。我们退一步梳理了关于这一真实系统的各种说法与事实。

在周四的一次演讲中,美国总统唐纳德·特朗普继续推动关于2020年美国大选受到干预的毫无根据且已被彻底推翻的说法。他甚至承诺将在白宫网站上发布的一批文件中进行大量披露,但这些文件并未证明他的主张——在某些情况下甚至与特朗普的说法相矛盾。

随着人工智能工具的采用迅速扩大且其能力不断增强,科技巨头Anthropic继续推动美国各州对AI进行监管。Anthropic美国州及地方政府关系负责人塞萨尔·费尔南德斯本周就去年加州和纽约州的AI透明度要求告诉《连线》杂志:“2025年以透明度为重点的安全法案是一个非常重要的开端,但随着AI系统能力持续快速进步,政策应对措施也需要跟上。”

还有更多内容。每周,我们都会汇总我们未深入报道的安全与隐私新闻。点击标题阅读完整报道。祝大家安全上网。

Mozilla对经期记录应用进行隐私评分,仅一款获得满分

根据英国广播公司报道,以占星术为主题的经期记录应用Stardust将用户的生殖健康详情——避孕方式、怀孕状态、情绪以及诸如乳房胀痛和胃痉挛等具体症状——发送给其隐私政策中未提及的一家数据公司。该报道最初源于Mozilla基金会与哈佛大学伯克曼克莱因中心合作对六款热门经期记录应用进行的审计结果。

Stardust在十分制中仅得两分,是表现最差的一款。Mozilla研究员肖莎娜·沃丁斯基发现,该应用在用户输入任何内容之前,从打开那一刻起就开始向第三方跟踪器发送信号;她记录一个症状的瞬间,这些详情连同持久性用户ID就发往分析公司RudderStack,且应用内没有任何关闭该共享方式的功能。RudderStack的设计目的是将数据继续转发至Mozilla无法观察到的目的地。Stardust还向Facebook传递了一个广告标识符,将应用内行为与该平台现有的用户档案关联起来。该公司告诉TechCrunch,它从未收到过任何针对用户数据的法律要求。

由非营利组织运营的Euki则获得了满分十分:无需账户,健康数据从不离开手机,用户可以设置PIN码、安排自动删除,或是在有人强制解锁手机时调出伪装界面。它唯一的弱点是一个用于查看教育页面的内置浏览器,该浏览器会加载常规的网络跟踪器,但也会在每次访问之间重置标识符。

俄罗斯联邦安全局因针对波兰基础设施的网络攻击受到制裁

俄罗斯联邦安全局长期以来以其高度复杂的网络间谍活动而闻名,通常将破坏性网络攻击留给其同属俄罗斯格鲁乌军事情报机构的黑客同行。但本周欧盟和英国的制裁,以及美国网络安全和基础设施安全局、联邦调查局和国家安全局的建议,将针对波兰电网的一次网络攻击归咎于俄罗斯联邦安全局第16中心,这是克里姆林宫这一机构实施网络攻击的罕见案例,该攻击几乎导致波兰电力和水务系统瘫痪。波兰政府称此次攻击“非常接近”造成大停电。网络安全公司Dragos和ESET最初将其归因于“沙虫”——即格鲁乌74455部队,鉴于该部队在俄罗斯对乌克兰长期网络战中的活跃角色,它通常是基础设施黑客行为的更常见嫌疑人。但波兰的计算机应急响应小组当时对这一结论提出异议,并将此次攻击与俄罗斯联邦安全局联系起来,这一结论如今得到了西方各国政府的广泛共识。该事件表明,俄罗斯联邦安全局可能正在表现出其格鲁乌同事的一些鲁莽且极具侵略性的倾向及攻击目标。

一名涉嫌受俄罗斯政府支持的黑客曾在卡巴斯基工作

多年来,俄罗斯网络安全公司卡巴斯基一直被指与俄罗斯政府有联系,包括美国官员曾禁止在政府内部使用其产品,并最终禁止所有美国客户使用。然而,这些联系的公开证据一直很少。据路透社报道,在波士顿面临黑客指控、涉嫌属于名为“虚空暴雪”或“洗衣熊”的黑客组织的俄罗斯男子丹尼斯·奥布雷兹科,曾在卡巴斯基工作过两年。他在卡巴斯基任职后,随即加入了另一家网络安全公司Yutek-NN,据美国检方称,他在那里参与了该组织的黑客行动,窃取了众多北约政府及至少11家美国公司的数据和通信。在加入卡巴斯基之前,奥布雷兹科据称也曾在俄罗斯联邦安全局工作,这使得他在该公司的任职时间恰好与为俄罗斯情报机构工作的经历无缝衔接。

奥布雷兹科对黑客指控拒不认罪。卡巴斯基在一份给路透社的声明中回应称:“所控罪行与该个人在卡巴斯基任职期间的角色或职责无关。”

一起真实的国土安全部入侵事件曾两次被误判为误报

在一件会让任何负责评估可疑网络活动的人感到焦虑的事件中,美国国土安全部官员两次裁定其数据共享平台“国土安全信息网络”上存在黑客入侵迹象的情况为误报,而事实上这些迹象正是一次真实入侵的证据。据Nextgov/FCW报道,HSIN用于在州、地方和联邦机构以及外国合作伙伴之间共享非机密数据,两个月前遭到黑客入侵。联邦紧急事务管理局的分析师在五月中旬发现了黑客活动的迹象——修改文件和代码、劫持合法网络服务器以及删除其行为日志——但这些发现被当作误报而忽略。

在随后的几周里,黑客再次返回,再次被检测到,并再次被当作幻觉而否定。目前尚不清楚这些入侵迹象为何被误判,但这些事件可能反映出联邦分析师在检测“就地取材”黑客技术方面面临的日益严峻的挑战。此类技术利用网络自身的合法功能来访问目标资产,而非植入更容易被发现的恶意软件。尽管HSIN仅存储非机密数据,但这些信息“高度敏感”,参议院情报委员会副主席马克·华纳在入侵事件报道后的一份声明中表示:“其泄露会危及国家安全。”

黑客入侵曝光AI音乐生成器的数据抓取秘密

据404 Media报道,AI音乐初创公司Suno从YouTube Music、Deezer、Genius以及一系列库存音频库中抓取了数百万首歌曲、歌词和播客,用于训练其模型。404 Media审查了一名入侵该公司的黑客提供的内部数据。此次入侵还曝光了数十万客户的账户信息,包括电子邮件、电话号码以及Stripe支付记录。

源代码中似乎来自2023年和2024年的数据集记录显示,仅YouTube Music的音频就达113,879小时,另加来自Pond5、Deezer和其他音频库的数万小时——总计数十年时长的音乐。其他文件显示,Suno通过Bright Data代理服务器路由其YouTube抓取活动,并使用PodcastIndex定位了大约100万小时的播客内容。化名ellie.191的黑客表示,他们是通过使用Shai-Hulud蠕虫病毒入侵一名员工的账户而突破系统的。

这些文件似乎证实了唱片业的核心指控,即Suno直接从YouTube下载歌曲。该公司辩称其训练行为属于合理使用,并于去年11月与华纳音乐集团达成和解。该公司表示,此次入侵涉及的是过时代码,并未泄露敏感个人信息——然而,其数据出现在与404 Media共享的样本中的客户表示,他们从未收到过通知。

英文来源:

Hours of San Francisco Police Department drone video footage exposed on the open web illustrates a new era of incredibly granular—and consequential—urban surveillance. Meanwhile, the San Francisco City Attorney’s Office sent cease-and-desist letters to Apple and Google this week demanding that the tech giants delete 13 AI nudifying “face-swap” apps from their app stores that are almost exclusively used to target women and girls.
Since WIRED first reported in June about Meta’s NameTag face-recognition system, company executives have made opaque and conflicting comments about whether the feature even exists. We took a step back to lay out both the claims and the facts about the very real system.
In a speech on Thursday, President Donald Trump continued to push unsubstantiated and thoroughly debunked claims about interference in the 2020 US election. He even promised massive revelations in a trove of documents posted to the White House website, but the files did not prove his assertions—and in some cases actually contradicted Trump’s claims.
As adoption of AI tools rapidly expands and their capabilities increase, the tech giant Anthropic continued a push to get US states to regulate AI. Speaking about AI transparency requirements in California and New York from last year, Anthropic’s head of US state and local government relations, Cesar Fernandez, told WIRED this week, “The transparency-focused safety bills of 2025 were a really important start, but as the capabilities of AI systems continue to advance quickly—the policy responses need to match.”
And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there.
Mozilla Graded Period Trackers on Privacy. Only One Aced It
The astrology-themed period tracker Stardust sends users’ reproductive health details—birth control type, pregnancy status, moods, and symptoms as specific as tender breasts and stomach cramps—to a data firm not named in its privacy policy, according to the BBC, which first reported a Mozilla Foundation audit of six popular trackers produced in partnership with Harvard's Berkman Klein Center.
Stardust scored 2 out of 10, the worst of the group. Mozilla researcher Shoshana Wodinsky found the app pings third-party trackers from the moment it opens, before a user enters anything; the instant she logged a symptom, the details went to analytics firm RudderStack alongside a persistent user ID, with no in-app way to shut the sharing off. RudderStack is built to route data onward to destinations Mozilla couldn't observe. Stardust also hands Facebook an ad identifier that ties in-app behavior to the platform's existing profiles. The company told TechCrunch it has never received a legal demand for user data.
Euki, a nonprofit-run tracker, earned a perfect 10: no account required, health data never leaves the phone, and users can set a PIN, schedule automatic deletion, or pull up a decoy screen if someone forces the phone open. Its one soft spot is an in-app browser for educational pages that loads the usual web trackers, but it also resets identifiers between visits.
Russia’s FSB Sanctioned for Cyberattack on Polish Infrastructure
Russia’s FSB has long had a reputation for highly sophisticated cyberespionage, leaving disruptive cyberattacks to its fellow hackers in the country’s GRU military intelligence agency. But sanctions from the EU and UK this week, along with an advisory from the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA, pinned a cyberattack against the Polish electric grid on Center 16 of the FSB, a rare example of the Kremlin agency carrying out a cyberattack that nearly caused outages in the country’s electric and water utilities. The attack, which the Polish government has said came “very close” to causing a blackout, was initially attributed by cybersecurity firms Dragos and ESET to Sandworm, also known as Unit 74455 of the GRU, a more usual suspect in infrastructure hacking given its active role in Russia’s long-running cyberwar against Ukraine. But the Polish computer emergency response team at the time disputed that finding and tied the attack to the FSB, a conclusion now supported by a wide consensus of Western governments. The incident suggests that the FSB may be taking on some of the reckless, highly aggressive tendencies—and targeting—of its GRU coworkers.
An Alleged Russian State-Sponsored Hacker Worked for Kaspersky
For years, the Russian cybersecurity firm Kaspersky has been alleged to have ties to the Russian government, including by US officials who banned use of the company’s products within the US government and eventually by all American customers. Yet overt evidence of those connections has been scarce. Now Reuters reports that Denis Obrezko, a Russian man facing hacking charges in Boston and an alleged member of a hacker group known as Void Blizzard or Laundry Bear, spent two years working at Kaspersky. His stint at the company took place just before he joined another cybersecurity company, Yutek-NN, where he allegedly took part in the group’s hacking campaign that stole data and communications from numerous NATO governments and at least 11 US companies, according to US prosecutors. Prior to Kaspersky, Obrevko also allegedly worked at the FSB, neatly bookending his time at the company with apparent work for Russia’s intelligence services.
Obrevko has pleaded not guilty to the hacking charges. Kaspersky responded in a statement to Reuters that “the offenses charged cannot be related to the individual’s role or responsibilities during the employment at Kaspersky.”
A Real DHS Breach Was Twice Ruled a False Positive
In an incident that will induce anxiety in anyone responsible for assessing suspicious network activity, DHS officials ruled—twice—that signs of a hacker breach in its data-sharing Homeland Security Information Network platform were false positives when they were, in fact, signs of a very real intrusion. HSIN, used for sharing unclassified data between state, local, and federal agencies, as well as foreign partners, was breached by hackers two months ago, according to reporting from Nextgov/FCW. Analysts at the Federal Emergency Management Agency spotted signs of hacker activity in mid-May—altering files and code, hijacking a legitimate web server, and deleting logs of their behavior—but the findings were dismissed as a false positive.
In the weeks that followed, the hackers returned, were again detected, and were again dismissed as a mirage. It’s not clear why the signs of the breach were misjudged, but the incidents may represent federal analysts’ increasing challenges in detecting “living off the land” hacking techniques that use legitimate features of networks to access target assets on a network rather than planting more easily spotted malware. While the HSIN houses only unclassified data, the information is “highly sensitive,” Senate Intelligence Committee vice chair Mark Warner said in a statement following the report of the breach, and “its exposure risks national security.”
Hack Exposes an AI Music Generator’s Scraping Secrets
The AI music startup Suno scraped millions of songs, lyrics, and podcasts from YouTube Music, Deezer, Genius, and a string of stock-audio libraries to train its models, according to 404 Media, which reviewed internal data provided by a hacker who breached the company. The intrusion also exposed account information for hundreds of thousands of customers, including emails, phone numbers, and Stripe payment records.
Dataset notes in source code apparently from 2023 and 2024 tally 113,879 hours of YouTube Music audio alone, plus tens of thousands more from Pond5, Deezer, and other libraries—decades of music in total. Other files show Suno routing its YouTube scraping through Bright Data proxies and using PodcastIndex to target roughly 1 million hours of podcasts. The hacker, who goes by ellie.191, says they broke in by compromising an employee with the Shai-Hulud worm.
The files seemingly corroborate the record industry’s central allegation that Suno pulled songs directly from YouTube. The company, which argues that its training qualifies as fair use and settled with Warner Music Group last November, said the breach involved outdated code and no sensitive personal information—though customers whose data appeared in a sample shared with 404 Media said they were never notified.

连线杂志AI最前沿

文章目录


    扫描二维码,在手机上阅读