Fresh From Cache
banner
index.freshfromcache.com.ap.brid.gy
Fresh From Cache
@index.freshfromcache.com.ap.brid.gy
A newsletter with technology news, tools, and the things you need to know. Translated.

🌉 bridged from ⁂ https://www.freshfromcache.com/, follow @ap.brid.gy to interact
Private browsing keeps history, cookies, and form entries off the device you're sitting at, and that's the whole job. The websites, your internet provider, your employer's network, and any account you sign into still see you. What it's for, and what to use instead.
What incognito mode hides, and who still sees you
Every browser has a private mode. Chrome calls it Incognito, Edge calls it InPrivate, Safari and Firefox call it Private Browsing, and they all come with a dark window and a little icon that makes you feel like you've put on a disguise. The browser makers' own help pages describe something much smaller, and they all describe the same thing. Private mode keeps a record from being written on the computer or phone you're using. Chrome's page says that when the session ends, "Chrome doesn't retain site data or a record of the sites you visited." Edge lists what it clears when you close the last InPrivate window. Browsing history, download history, cookies and other site data, cached images and files, passwords, autofill form data, site permissions, and hosted app data. Safari's details of your browsing "aren't saved, and they aren't shared across your devices." That's the feature. Somebody who picks up the same device later doesn't see where you went. ## Who still sees you Chrome and Firefox name the same three watchers, and Edge names two of them. None of the three is the person you were hiding from. The websites. Chrome's own wording is that "Websites you visit, including Google sites, and organizations that manage your network, like your school, employer, or internet service provider, may be able to observe your activity in Incognito." Amazon knows you're on Amazon. Google knows you searched Google. The network. Edge's page puts it in a single sentence. "Other people using this device won't see your browsing activity, but your school, workplace, and internet service provider might still be able to access this data." Your home internet provider sees the same traffic whether the window is dark or light, and so does the IT department at work. And you. If you sign in to anything, the disguise is off for that site. Chrome only promises it "doesn't automatically sign you into your Google Account or other websites." Once you do, "This won't change how data is collected by the websites you visit and the services they use, including Google." Sign in to Google in an incognito window with Web & App Activity on, and Google saves "Searches and activities on Google products and services" to your account like any other day. Firefox's help page says the part the others dance around. "Private Browsing does not make you anonymous on the Internet." ## What it's for A shared computer. That's the use the vendors built it for, and they say so. Firefox's myths page says it "helps keep your online activity private from others who use Firefox on the same computer, but it won't make you invisible online." The gift you're shopping for on the family laptop. A second login to the same site without signing out of the first. A friend's computer, or a hotel business center, where you don't want your passwords and history left behind when you walk away. On an iPhone there's a setting that makes this one better. Since iOS 17, Safari can lock private tabs behind your face or fingerprint. On iOS 18 and later, open Settings, then Apps, then Safari, and turn on 'Require Face ID to Unlock Private Browsing' (or the Touch ID or Passcode wording on your phone). On iOS 17 the same setting sits directly under Settings, then Safari. Leave a private tab open, hand the phone to a kid, and the tab stays blurred until you come back. ## What it leaves behind Downloads and bookmarks. Chrome, Edge, and Firefox all say so. Chrome "retains bookmarks that you save and files that you download when you exit Incognito." Firefox adds the detail that catches people. A downloaded file "will remain on your computer, but it will not appear in the download manager in Firefox." The receipt PDF is in the Downloads folder for anyone to open, even though the browser has forgotten you downloaded it. One forgotten window. Everything is wiped when you close all the private windows. One left open in the background keeps the session alive, logins included. And the past. Private mode does nothing about last month. If the goal is to stop old searches from showing up in the address bar, that's a different button. On an iPhone it's Settings, then Apps, then Safari, then 'Clear History and Website Data'. ## What it isn't Edge says it in one line. "InPrivate browsing doesn't keep you safer from malicious websites or provide additional ad blocking." Firefox's myths page adds that private mode "does not protect you from malware installed on your computer." Chrome and Firefox do block third-party cookies in private windows by default, which trims some tracking. The site still sees your address on the internet and everything you type. There's also a belief that incognito gets you cheaper flights or hotel rooms. No browser maker claims it, and I couldn't find an airline that stands behind it either. A site that prices by your location or your login does it in a dark window too. On a work computer, the disguise is thinnest. A Chrome managed by an employer shows "Managed by your organization" at the bottom of its menu, and Google's page says the administrator "can set up or restrict certain features, install extensions, monitor activity, and control how you use Chrome." ## The right tool for the watcher Match the tool to who you're hiding from. For the other people in your house, private mode is the right one. For your internet provider or the network you're on, it's a VPN, with its own limits. For a shared computer where the real worry is saved passwords, it's a password manager and never saving them in the browser. For last month, it's the clear-history button. Private mode does one of those four jobs, and it does that one well. What did you think incognito was hiding? I'd like to know which of the three watchers surprised you, because I suspect for most people it's the first one. [email protected] **Sources** Google, Chrome Help, "Browse in Incognito mode" (Computer and Android tabs): "Chrome doesn't retain site data or a record of the sites you visited"; "Chrome retains bookmarks that you save and files that you download"; "Websites you visit, including Google sites, and organizations that manage your network... may be able to observe your activity in Incognito"; "Chrome doesn't automatically sign you into your Google Account or other websites"; third-party cookies blocked by default. Google, Chrome Help, "Check if your Chrome browser is managed": "Managed by your organization"; the administrator "can... monitor activity." Google Account Help, "Find & control your Web & App Activity": "Searches and activities on Google products and services." Apple, Personal Safety User Guide, "Keep your browsing history private in Safari" (February 2026), which scopes the feature to "iOS 17, iPadOS 17, macOS 14, or later": "aren't saved, and they aren't shared across your devices"; Settings > Apps > Safari > 'Require Face ID to Unlock Private Browsing'; 'Clear History and Website Data'. Apple Newsroom, "iOS 17 makes iPhone more personal and intuitive," June 5, 2023: Private Browsing "now locks when not in use." Microsoft, "Browse InPrivate in Microsoft Edge": the list of what InPrivate clears; "Other people using this device won't see your browsing activity, but your school, workplace, and internet service provider might still be able to access this data"; "InPrivate browsing doesn't keep you safer from malicious websites or provide additional ad blocking." Mozilla, "Private Browsing - Use Firefox without saving history" (updated July 4, 2026): "Private Browsing does not make you anonymous on the Internet." Mozilla, "Common Myths about Private Browsing" (updated November 3, 2025): "private from others who use Firefox on the same computer"; "does not protect you from malware"; a downloaded file "will remain on your computer, but it will not appear in the download manager." Claims and paths verified against the browser makers' own pages on September 9, 2026. Every quote, figure and menu path was then re-checked against these same sources on September 10, 2026.
www.freshfromcache.com
September 16, 2026 at 12:56 PM
Your earnings record and your direct deposit already live behind a login at ssa.gov, whether you ever made one or not. How to create the account with Login.gov, what to look at once you're in, and the separate lock for anyone who wants the online door closed entirely.
Claim your Social Security account before someone else does
You have a Social Security record. It has an address on the internet, a sign-in page, and a set of controls behind it that include where your benefit payments get deposited. None of that depends on whether you have ever logged in. Social Security lists what the account does. Request a replacement card. Change your address or direct deposit. Get your Social Security Statement. Review earnings for accuracy. Monitor for unusual activity. Those controls exist for whoever gets through the sign-in page. So the job is to be the person who gets through it. ## What changed in 2025 If you remember a Social Security username and password from years ago, that's gone. The agency's own FAQ page is specific. "Effective June 7, 2025, Login.gov and ID.me are now the only sign in options to access Social Security online services. We have removed the option to sign in using a Social Security username and password." Social Security describes no migration path. Anyone with an old username creates an account with one of the two providers instead. Login.gov's own page for SSA users puts it as needing "to transition to a new or existing Login.gov account to have continuous access to SSA online services." Login.gov is the government's own sign-in service, run by the General Services Administration, and Social Security lists it as "Best for" "Most users in the United States." ID.me is the other option, and the agency points users "inside or outside the United States" to it. You need one, not both. Social Security says so directly. "You only need an account with one of these providers." ## Creating the account You need to be 18 or older with a valid email address. Start at ssa.gov/myaccount and pick your sign-in service. Taking the Login.gov lane, here is what it asks for. An email address. Login.gov's own advice is the useful part. "We recommend a personal email address that you'll always be able to access rather than a work email address." A work address stops being yours the day you leave the job. A password of at least 12 characters, which "should not include commonly used words or phrases." This is one for the password manager. At least one authentication method. Login.gov sorts them into two tiers. Its "more secure" list is face or touch unlock on your device, a security key, and a government PIV or CAC card. Everything else, including authenticator apps and text messages, sits in the less secure list. Take one from the top tier if you can, and an authenticator app ahead of text codes otherwise, for the reason laid out in the piece on locking your phone number. Then identity verification. Login.gov asks for photos of a "U.S. Driver's license, state ID, or passport book/card," and "in some cases, you'll be asked to take a selfie to confirm that you are the owner of your ID." It then sends a code to your phone number. Two fallbacks may be available if the phone step fails. Login.gov says it "may be able to verify your address by mail instead," with a letter that takes "about 5-10 days" and a code that "will expire 21 days after" you requested it. It also says you "may also be able to verify your identity in person at a United States Post Office near you." Both are slower than finishing it while your ID is in your hand. ## What to look at once you are in Your earnings record. Social Security's own feature list includes "Review earnings for accuracy," and the reason is that your future benefit is computed from those numbers. A missing year or a wrong employer is fixable while you still have the pay stubs and the W-2. Your Statement, which shows the benefit estimates at different ages and "the estimated Social Security and Medicare taxes you've paid." If you already receive benefits, the direct deposit screen. "Sign in to your account to update your bank information. This is the fastest way to make changes," the agency says, though it adds that "depending on your benefit type, you may need to call us." Your bank can also send the new details to Social Security for you. ## Why the direct deposit part matters The direct deposit screen is why this belongs in a security column, and the reason comes from the agency's own inspector general. In a September 2025 release, the Social Security Office of the Inspector General reported on telephone direct-deposit changes it audited from late 2023. It identified 3,109 beneficiaries whose direct deposit was changed that way, and estimated that "approximately 1,197 of the 3,109 (38.5 percent) beneficiaries had benefit payments misdirected" for a total of "$2.2 million," of which about $2 million had not been recovered. That's the group the inspector general examined, rather than a rate across all beneficiaries. It was enough of a problem to change the rules. What a caller used to need was the ability to confirm information the agency already had on file. As of April 28, 2025, a phone change requires a one-time code that you generate by signing into your own my Social Security account at ssa.gov/PIN. Online changes are no longer held for 30 days, and the agency said in March 2025 that it would process every direct deposit change, in person or online, in one business day. So the phone route now runs through the online account. Holding the account is what puts you in the middle of a change somebody else tries to make. ## The calls that aren't from Social Security Since we are here, the agency's own anti-scam pages are short and useful. Social Security "will never ask for sensitive or personal information through social media, email, or text message." The inspector general's list covers the rest. "SSA and OIG will never ask you to transfer money to protect it, meet you in person to exchange cash, gift cards, crypto currency, gold bars, or require you to keep information secret or confidential." And of the agency itself, that it "will never threaten, scare, or pressure you to take an immediate action." The threat to suspend your Social Security number is on the agency's own list of scammer tactics. A real agency problem survives you hanging up and calling 1-800-772-1213 yourself. The scale is in the FTC's numbers. Americans reported losing about $920 million to government impersonators in 2025, out of $3.5 billion reported lost to imposter scams overall. Those are self-reported figures, so the real number is higher. ## If you want the door closed instead There's a second option that does the opposite. Social Security calls it Block Electronic Access, and the effect is total. Once it's on, "no one, including you, will be able to see or change your personal information on the Internet or through our automated telephone service." That includes you. Everything goes back to paper, field offices, and live phone calls. The agency aims the option at people with particular reasons to want nothing reachable online, including identity theft victims and domestic violence victims, and it can be undone by contacting Social Security and asking to unblock it. For almost everyone else, the account is the better answer, because you cannot use the account and hold the block at the same time. ## While you're at it Two neighboring moves belong to the same afternoon. The IRS will give you an Identity Protection PIN, a six-digit number that "prevents someone else from filing a tax return using your Social Security number." You opt in, you get a new one every year, and "the fastest way to receive an IP PIN is to request one through your online account." The catch is the renewal. The new number is in the account "starting in mid-January through mid-November," and anyone who enrolled online has to go get it, because the IRS will not mail it to them. And freeze your credit if you haven't. It's free, it stops new accounts being opened in your name, and it takes three separate requests, one to each bureau. ## Do it this weekend Sit down with your driver's license and your phone in front of you. Go to ssa.gov/myaccount, create the Login.gov account, verify, and then look at your earnings record while you are in there. That last part is the reason people are glad they did it, separate from the security argument. If you have an old Social Security username in a notebook somewhere, cross it out. It stopped working in June 2025. Did your earnings record match what you expected? I'd like to hear about any missing years, because I suspect they are more common than anybody thinks. [email protected] **Sources** Social Security Administration, "my Social Security": the feature list, including "Review earnings for accuracy" and "Monitor for unusual activity"; "Social Security uses Login.gov to allow you to sign in to your official my Social Security account safely and securely." SSA, "Account FAQs & Help": "Effective June 7, 2025, Login.gov and ID.me are now the only sign in options..."; "You only need an account with one of these providers." SSA, "Creating an Account": 18 or older with a valid email; Login.gov "Best for" "Most users in the United States"; ID.me for "Users inside or outside the United States"; verification takes "5 - 20 minutes." SSA, "Using Your Account": the pre-benefit and post-benefit feature lists, including the Statement and "Verify your earnings." SSA, "Update direct deposit": "Sign in to your account to update your bank information. This is the fastest way to make changes." SSA, "Block Electronic Access": "no one, including you, will be able to see or change your personal information on the Internet or through our automated telephone service"; who the option is aimed at; unblocking by contacting Social Security. SSA, press release, March 18, 2025: "Expedite processing all direct deposit change requests... to one business day"; the prior 30-day hold on online changes. SSA, "Identity proofing" (April 28, 2025): "Beginning April 28, 2025, you can change your direct deposit by calling 1-800-772-1213," after getting a one-time code at ssa.gov/PIN; no proofing required to keep getting paid at the current bank. SSA Office of the Inspector General, "SSA Beneficiaries Did Not Always Authorize Direct Deposit Changes by Telephone, Leading to Direct Deposit Diversions" , September 9, 2025: "approximately 1,197 of the 3,109 (38.5 percent) beneficiaries had benefit payments misdirected... to the amount of $2.2 million"; about $2 million unrecovered; the pre-2025 practice of confirming information already in SSA's records. SSA, "Scam Alert": "Social Security will never ask for sensitive or personal information through social media, email, or text message"; the threat to "suspend your Social Security number or account" as a scammer tactic. SSA OIG, "Scam Alert": "SSA and OIG will never ask you to transfer money to protect it, meet you in person to exchange cash, gift cards, crypto currency, gold bars, or require you to keep information secret or confidential"; "Social Security will never threaten, scare, or pressure you to take an immediate action." Federal Trade Commission, "FTC data show people reported losing $3.5 billion to imposter scams in 2025" , June 15, 2026: "$3.5 billion to imposter scams in 2025"; "about $920 million to government impersonators." Login.gov , "What is Login.gov?" login.gov/what-is-login: "a safe way to sign in to many U.S. government websites using just one account"; provided by Technology Transformation Services, an office of the General Services Administration. Login.gov , "Create an account," login.gov/create-an-account: "We recommend a personal email address that you'll always be able to access rather than a work email address"; "Passwords must be at least 12 characters"; the more-secure and less-secure authentication lists. Login.gov , "Verify your identity," login.gov/help/verify-your-identity/overview: "U.S. Driver's license, state ID, or passport book/card"; "In some cases, you'll be asked to take a selfie"; the phone code step; the mail and Post Office fallbacks. Login.gov , "Verify your address by mail," login.gov/help/verify-your-identity/verify-your-address-by-mail: "about 5-10 days"; the code "will expire 21 days after" the request. Internal Revenue Service, "Get an identity protection PIN": the six-digit PIN that "prevents someone else from filing a tax return using your Social Security number"; voluntary; a new PIN each year; the online account as the fastest route. FTC, "What to know about credit freezes and fraud alerts" (last modified September 30, 2025): "There's no cost to place or lift a credit freeze"; "While a credit freeze is in place, nobody can open a new credit account in your name"; "Contact all three of the credit bureaus." Claims and steps verified against the SSA, SSA OIG, Login.gov, IRS, and FTC pages above on September 9, 2026. The sign-in rules changed in 2025 and the agency has rewritten these pages more than once, so the labels are the thing to re-check before you follow a path. Every quote, figure and menu path was then re-checked against these same sources on September 10, 2026.
www.freshfromcache.com
September 15, 2026 at 2:44 PM
Also: what a breach number actually counts, Ring's new encryption default, and the Snipping Tool button you have never pressed.
This week: your phone wasn't listening, but your TV is
Good morning! Cox Media Group told advertisers its Active Listening software could pick up conversations through phones, TVs and smart speakers. The FTC found no audio at all and says the service was really reselling email lists bought from data brokers and making up the geotargeting. Three of this week's six main stories got less frightening once I opened the source material. Smart TVs really do sample what's on their screens, and the piece has a table of what the setting is called on each brand and where to look for it. **In this issue:** * Cox Media Group told advertisers it was listening to you. The FTC says it never was. * Your smart TV can track what you watch. * Who is ShinyHunters, and why is that name in every breach letter? * Ring is throwing away its key to your videos * Does technology make us lonely? * Also this week: a false antivirus warning, an FTC lawsuit over Amazon's ad prices, and 19 browser add-ons gone bad * You already use the Snipping Tool. Look at what it does now. * Plus: three scams making the rounds * And the Scary Headline of the week: 39 ways to beat a passkey * * * Cox Media Group told advertisers it was listening to you. The FTC says it never was. Cox Media Group and two partners sold advertisers a service called Active Listening, pitched as software that could pick up conversations through phones, TVs and smart speakers. The FTC's case says it never collected any audio at all. What it really did was resell email lists bought from data brokers and invent the geotargeting. The $930,000 in redress goes to the small businesses that bought the service, not to anyone whose conversations were supposedly recorded. The tracking that explains the eerie ad is the ordinary kind, and there's a great deal more of it. _Learn_ * * * Your smart TV can track what you watch. The technology is automatic content recognition. Your television samples what's on its own screen, turns it into a fingerprint and matches it against a library, the way Shazam matches a song. Samsung told advertisers its sets take a sample every 500 milliseconds. Researchers at three universities found the traffic still running while a set was being used as an external display, so plugging in a cable box or a console doesn't get you out of it. Every brand calls the setting something different, and the article has a table with the names and where to find them. _Learn_ * * * Who is ShinyHunters, and why is that name in every breach letter? A hacking group claimed it took hundreds of millions of customer records. Somebody loaded the file and counted, and the number came down hard. The first figure in a breach story is almost always a count of rows in a database, and one person can be a hundred rows. Carhartt's 24.9 million came down to 12.9 million once duplicates and test accounts were taken out, and a claimed 14 million Panera records held 5.1 million unique email addresses. The breach still happened either way, and the headline number was never a count of people. _Learn_ * * * Ring is throwing away its key to your videos Ring's new encryption default destroys the company's own copy of your video keys after 24 hours, which closes a door Ring left open for years. Shared clips sit outside that arrangement. The moment a video goes through a share link, the donation tool or Neighbors, it's no longer covered. Police asking Ring for footage get less than they used to, but "Ring can't unlock it" and "police get nothing" are two different sentences. The encrypted file can still be handed over. _News_ * * * Does technology make us lonely? Loneliness gets compared to smoking fifteen cigarettes a day. The researcher behind that number keeps a page on her own website correcting the way people quote it, so I started there. The piece goes through where the figure came from, who the survey data says is loneliest, and what the evidence supports about whether a phone causes any of it. It's the longest thing I've published, and it's a sit-down-with-coffee read rather than a quick one. _Blog_ * * * Also this week: a false antivirus warning, an FTC lawsuit over Amazon's ad prices, and 19 browser add-ons gone bad A Windows pop-up telling you Microsoft Defender Antivirus is turned off is wrong, and Microsoft has confirmed the bug on its own release health page. The FTC and 22 states sued Amazon over a surcharge on ad prices that the states say reaches shoppers; Amazon says there's no evidence of that. Nineteen Chrome and Edge extensions were caught carrying a wallet drainer and a keylogger, five of them bought from their original developers and turned bad in an update. Android 17 adds two network protections, including a carrier-side 2G shutoff aimed at the fake towers behind scam texts. _News_ * * * **If you only read one:** the smart TV piece. It's the one with something to go change tonight, and the control is filed under a different name on every brand. * * * ### 5-Minute Tech Tip Windows key + Shift + S dims the screen and lets you drag a box around anything, and the picture goes onto the clipboard ready to paste. That part hasn't changed in years. What's new is the row of buttons across the top of the Snipping Tool: a shape menu that captures one whole window cleanly, a timer for catching a menu before it closes, a Text actions button that pulls the words out of a picture and reads QR codes, and Quick redact, which blacks out email addresses and phone numbers. Windows warns that redact misses street addresses and account numbers, and that warning is correct. * * * ### Fresh Trouble **The MyChart results email.** An email says your test results are ready, with a sign-in button that opens a copy of the MyChart login page. Epic says a later version tells you to press Windows and R and paste something to unlock the "full report," which installs malware instead. Open the portal from your provider's own site or app. (MyChart) **The parking meter QR code.** A sticker carrying somebody else's QR code is pasted over the real one on the meter and sends you to a fake payment page. (FTC) **The dealership with no record of your order.** Scammers are copying car dealership websites, taking the deposit, and leaving the buyer to find out at the counter. (FTC) * * * ### Scary Headline of the Week _"39 New Methods That Compromise Passkey Authentication"_ I've told you to set up passkeys, so a headline counting 39 ways to beat them deserves an answer. The research is real. A company called Token collected 39 published techniques for getting into an account protected by a passkey. None of the 39 breaks the cryptography, and the report says so directly. The attacks go after what stands around it: the browser, the password manager, the service that syncs your passkey between devices, the account recovery process, and the person clicking Approve. Most of them are also aimed at corporate logins with an IT department behind them. Token sells dedicated hardware authenticators, and the report recommends dedicated hardware. The findings stand on their own, and you should know who is making the recommendation. **Verdict:** 39 ways to beat a passkey is still not a reason to go back to passwords. Somebody can phish a password out of you in one message, and every one of these 39 needs control of something you own first. Set up passkeys. Then look at how each account lets you recover it, because recovery is the door this research keeps walking through. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. * * * ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, there are two ways to help. Forward this email to one person who might want it, and if it was forwarded to you, subscribe to get your own copy every Tuesday. And if you would rather chip in a few dollars, there is a support page now. Thank you for your support. * * * Did you go looking for that setting on your TV, and could you find it? Hit reply. Joel
www.freshfromcache.com
September 8, 2026 at 3:00 PM
Windows will grab any part of your screen with two keys. The same tool also reads the words out of the picture, opens QR codes, and blacks out an email address before you send it: https://www.freshfromcache.com/windows-screenshot-shortcut/
September 6, 2026 at 7:32 PM
Two keys, drag a box, and the picture is on your clipboard. That part hasn't changed. What's new is everything sitting behind the buttons across the top, and most people have never pressed any of them.
You already use the Snipping Tool. Look at what it does now.
There is one tool on Windows that I find extremely useful. It's a tool I use every single day. In my professional life and in my personal life. It's probably a tool you've heard of, and it's probably a tool you've used. It's the Windows Snipping Tool. You might have been using it for years. It's recently added a lot of new features to make life easier. Hold down the Windows key and Shift, then press S, or search "Snip". Your screen dims, a small toolbar appears at the top, and you drag a box around whatever you want to capture. From there it goes into an email, a text, a document, or a Facebook comment. ## Where the picture goes Think of it as a pair of scissors for the screen. You cut out the part you want, and the cutting is the same as copying or using Ctrl+C. It waits there until you paste it somewhere with Ctrl+V. It's on the clipboard, and it sits there until you paste it or until you capture something else on top of it. Windows keeps a history of that pocket as well, which is one of a handful of shortcuts most people never go looking for. Three steps. 1. Windows key + Shift + S 2. Drag a box around the part you want 3. Go where the picture belongs and press Ctrl+V This is the Snipping Tool you may have used before. However, there have been some improvements. ## The four shapes The shape button sits next to the camera icon, and clicking the little arrow beside it opens the list. **Rectangle** is the default and the one you'll use nearly every time. Drag a box, let go. **Window** captures one whole window on its own, without the desktop behind it. Hover over the window you want and click it. This is the one for sending somebody an entire error box or an entire browser window with clean edges. **Full screen** takes everything on the display in one click, taskbar and all. **Freeform** lets you draw any shape you like with the mouse. ## Marking it up before you send it After a capture, a notification slides into the corner. It tells you what it just did with the picture, and it has a Markup and share button on it. Click that and the Snipping Tool opens with your picture already in it. Along the top are a pen, a highlighter, and an eraser, plus a crop button and a shapes button. The shapes button is the one to go find, because it holds a square, a circle, a line, and an arrow. An arrow drawn around the button you want somebody to click will save you a paragraph of explaining. If you need more than that, the Edit in Paint button opens the same picture in Paint for resizing and adding text. ## Where it gets saved The picture goes on the clipboard every time. That's the copy you paste. Windows 11 also writes a file. Open the Snipping Tool, click See More (the three dots at the top right), then Settings, and the switch is called Automatically save original screenshots. Underneath it the folder is spelled out, along with a Change button if you want it somewhere else. Take a look even if you never change anything, because that folder is often inside OneDrive rather than on the computer itself, and people go hunting in the wrong place. For a copy somewhere specific, Save as puts it where you choose. Ctrl+S saves and Ctrl+C copies without reaching for the mouse. ## Three ways to grab the whole screen The Full screen shape on the snipping toolbar sends the whole display to the clipboard. Pressing PrtSc on its own does the same thing, and nothing appears to happen when you do it. Paste it somewhere to see it. Windows key + PrtScn saves the whole screen as a file, in Pictures then Screenshots, and the screen dims for a moment so you know it worked. Microsoft notes that a keyboard without a PrtScn key can use Fn + Windows key + Space bar instead. ## Copying the words out of a picture Take a snip of anything with writing in it, then click the Text actions button. Hover over it and the tooltip calls it Scan text, which is the better name for what it does. The tool reads the words in the image and offers to copy all of them, or to copy them as a table if it's looking at rows and columns. Good for a confirmation number, an error message, or an address on a page that won't let you select it. Microsoft says the reading happens on your own device. Your phone will pull text out of a photograph the same way, which is its own trick. It reads QR codes too. Snip one and the address inside it appears right on top of the code, so you don't have to point your phone at your own monitor. ## When the thing you want keeps disappearing Menus close the moment you click anywhere else, which makes them hard to capture. Open the Snipping Tool, click the arrow next to the timer icon, and pick a delay. Press New, open the menu you're after, and wait. When the screen goes gray the countdown is done, and you can drag your box with the menu still sitting open. ## Recording instead of a picture Windows key + Shift + R starts a screen recording. Drag a box around the area, then a small bar appears with a Start button, a timer, and a microphone toggle if you want to talk over it. Do the thing, press Stop. Recordings save to Videos then Screen Recordings. ## What else is in the picture A screenshot catches everything inside the box you drew. Your email address up in the corner. The titles of every tab across the top. The name of the document you had open behind it. Somebody's phone number sitting in the message underneath. You meant to send one line of an error and you sent your inbox. Most of the time the solution is to just draw a better box. Windows 11 has a button for it as well. Open the snip, choose Text actions, then Quick redact, and it blacks out email addresses and phone numbers it finds in the image. Windows puts up its own warning right after it does this, and the warning is the correct one. Quick redact covers email addresses and phone numbers. It has no idea what a street address or an account number looks like, so read the picture yourself before you send it. ## Two things it won't do It can't follow a long page down as you scroll. Microsoft says so plainly in its own FAQ, and says a full scrolling page needs a different tool. Take two or three snips instead. And if the keys do nothing at all, Microsoft's own answer is to check Settings > Accessibility > Keyboard, and to make sure another program hasn't claimed that shortcut for itself. ## One more pass through the buttons Open it once and press New, then work your way across the row along the top. Every one of those icons does something, and none of them are hidden. They arrived a few at a time without much announcement, and most people are still using the tool the way they used it in 2019. If you find something in there I skipped, write back and tell me. I only started using half of these myself this year. **Sources** The tool itself: Microsoft Support, Use Snipping Tool to capture screenshots (the shortcut, the snip shapes, the editing buttons, Text actions and Quick redact, and the separate Windows 10 instructions) What is new and what it needs: Microsoft, How to use Snipping Tool on Windows 11 (February 26, 2026; where screenshots and recordings are saved, the scrolling-capture limit, and the Settings check when the shortcut does nothing) The whole-screen keys: Microsoft Support, Keyboard shortcut for print screen (Windows logo key + PrtScn, and the Fn + Windows logo key + Space bar alternative) Paths and screenshots verified on Windows 11, September 6, 2026.
www.freshfromcache.com
September 6, 2026 at 3:59 PM
Your smart TV may be keeping track of what's on the screen.

It's called automatic content recognition. Researchers found it still ran on Samsung and LG sets when the picture was coming in over HDMI from a laptop or a game console.

You can turn it off […]

[Original post on freshfromcache.com]
September 5, 2026 at 4:54 PM
Your TV can recognize what is on its own screen, including whatever comes in over HDMI. What the setting is called on each brand, and where to find it.
Your smart TV can track what you watch.
Your television can recognize what's playing on its own screen. On several major brands that includes whatever arrives over HDMI, so the cable box and the game console are covered too. Whether yours is doing it right now comes down to one setting. There is no standard name for it and no standard place to find it. ## The name on your TV is not the name in the news The technology is automatic content recognition, ACR for short. What the setting is called depends on the television. Your TV | What to look for ---|--- **Samsung**| Viewing Information Services **LG**| Viewing Information (it feeds a feature named Live Plus) **Vizio**| Viewing Data **Roku TV** , including Roku-powered TCL, Hisense, Philips and onn sets| Automatic Content Recognition (ACR); on older software, Use Info from TV Inputs **Sony BRAVIA**| Samba Interactive TV (run by an outside company, Samba TV) **Hisense sets on VIDAA**| Enhanced Viewing **Amazon Fire TV**| No ACR control; separate Fire TV privacy settings Samsung described the mechanism to advertisers in a 2022 Samsung Ads guide. In its own words, "Our proprietary ACR technology takes glass-level screenshots every 500 milliseconds on our opted-in Samsung TVs, converts them into 'unique patterns,' and compares these visual snapshots against others in the matching server." A diagram in the same guide is labeled "Image captured every 500ms." That's Samsung's sampling rate, not an industry standard. The researchers below note that LG's own documentation puts its sets at every 10 milliseconds. The television isn't sending a normal image file of the screen. It turns the sample into a fingerprint and sends that for matching. Sony's support page says so for the Samba system on its sets. "No image from the TV screen is captured and sent from your BRAVIA TV." The comparison the researchers use is Shazam. A short fingerprint travels, gets matched against a large library, and comes back with a name. Roku's page adds that a fingerprint with no match in its catalog comes back as nothing, so a home video is not recognized as anything. ## HDMI is not a way around it Researchers from University College London, UC Davis and Universidad Carlos III de Madrid put Samsung and LG sets in a lab and watched the network traffic across six ways of using a television. They found ACR traffic while the sets showed linear broadcast, and while the sets were being used as external displays over HDMI. Plugging in a laptop or a game console doesn't turn the television into a dumb monitor. They didn't find ACR traffic while third-party apps such as Netflix and YouTube were running on the tested sets. In the United States, they did see it during the manufacturers' own free channels, Samsung TV Plus and LG Channels, where the UK sets showed none. They also separated how often the screen gets sampled from how often anything leaves the house. On their sets, LG contacted its ACR servers about every fifteen seconds and Samsung about once a minute. The samples pile up locally and travel in batches. ## Where the data goes Vizio's current Viewing Data policy says the company licenses that data "to advertisers, ad agencies, analytics companies, media companies, and other ad technology companies." The same policy says it may be combined with material bought elsewhere: "demographic data, smartphone location, web history, and purchasing history." In 2017 the FTC and New Jersey settled with Vizio over viewing data taken from 11 million televisions, and the complaint describes demographics attached to the viewing history: * Sex * Age * Income * Marital status * Household size * Education level * Home ownership * Household value Vizio paid $2.2 million and agreed to ask permission going forward. The feature had been called Smart Interactivity, and Vizio told buyers it "enables program offers and suggestions." Walmart owns Vizio now. The policy offers you "an additional choice about whether Walmart can link your Viewing Data to the Walmart account logged in to those devices." ## Why TV makers want this data A good 65-inch television costs less than the phone in your pocket now, and the reason is written in the makers' own account books. In the spring of 2024, Vizio's Device business took in $267.9 million and returned $900,000 in gross profit. Its Platform+ business, which sells advertising and viewing data, took in $169.4 million and returned $98.6 million. Across the first half of that year, Device gross profit was negative $6.3 million. Device covers sound bars as well as televisions, and Platform+ covers more than advertising, so neither number is a clean read on TVs alone. Roku's is cleaner. For all of 2025, Devices took in $592 million at a gross margin of negative 14 percent. Platform took in $4.145 billion at 52 percent. Roku told investors to expect device margins in the negative mid-teens again in 2026. A television can keep earning after it leaves the store. Those platform businesses are wider than advertising, and ACR is one of the systems feeding them what happens on the screen. ## Texas sued five TV makers On December 15, 2025, Texas sued Sony, Samsung, LG, Hisense and TCL over ACR under the state's Deceptive Trade Practices Act. Two days later a court issued a temporary restraining order against Hisense, barring it from collecting or sharing ACR data about Texans while the case runs. Samsung reached an agreement with the state on February 26, 2026, promising not to collect ACR viewing data from Texans without express consent and to make its disclosures clear and conspicuous. LG followed on May 11, agreeing to a pop-up disclosure and a clear way to opt out. Neither agreement, as the attorney general described it, carries a dollar figure. Texas said on May 11 that its cases against Sony, Hisense and TCL remained ongoing. None of the allegations against those three has been decided on the merits. The Hisense restraining order is a court order, but it settles nothing about whether the claims are true. ## The companies have an answer Samsung's advertiser guide describes the feature as opt-in and reversible. "If a user does not opt in to these services, or if they subsequently withdraw their consent, their use of the Smart TV is not affected." Vizio's policy says each television gets a notice and a choice before any Viewing Data is collected, and that turning it off will not affect how the set performs. Sony says Samba Interactive TV runs only if you accept Samba TV's terms. Roku's own ACR policy describes collection starting "when you enable Smart TV Experience during device set up." LG spells out the split. Its TVs began showing a User Agreements screen after the company updated its Terms of Use on August 28, 2026, and LG's support page says the Terms of Use and Privacy Policy are required to use smart services such as Netflix and YouTube, while "all other agreements are optional." Its own FAQ is more direct. "Agreements related to viewing information, voice features, and personalized ads are optional and are not required to use basic smart services." You can change any of them later under Settings, then Privacy & Terms, then User Agreements. Consumer Reports tested 2025 sets and found LG's viewing agreements off by default until accepted, and Sony's Bravia data options off by default too. The researchers checked the other half of the promise. After opting out on their Samsung and LG sets, they found "a complete absence of communication with any previously identified ACR domains." The controls did what they said. So there is a decent chance the setting on your television is already off, but no way to know without looking. The permission gets collected during setup, in a stack of agreements, alongside the ones you have to accept to use the apps at all. ## "I don't care if somebody knows I watch football" What you watch is not the whole picture. Vizio's policy describes what makes viewing history valuable, and it's more specific than a hypothetical. A data partner can identify another device sharing the television's IP address, a phone with location turned on, and check whether that phone later turned up at a store. The viewing history becomes one more signal attached to a household that already has a file with a data broker. ## Turning it off Menus move between model years and software updates, so look for the name of the control rather than the exact path. If yours doesn't match, search your model number plus the name. **Samsung.** Settings, then All Settings, then General & Privacy, then Terms & Privacy. Uncheck Viewing Information Services. On many current models the same control also appears under Privacy Choices, in the same General & Privacy area. Older Samsung sets may put the control under Terms and Policy, or use older SyncPlus or Interactive Marketing wording for the same choices. **LG.** Settings, then All Settings, then Support, then Privacy & Terms, then User Agreements. Decline Viewing Information. On older webOS sets, User Agreements may sit under General, or under About This TV. **Vizio.** All Settings, then Privacy & Legal, then Viewing Data. Older sets use All Settings, then Admin & Privacy. Vizio publishes both paths, so try the other one if the first is missing. **Roku, including Roku-powered TCL, Hisense, Philips and onn sets.** Settings, then Privacy, then Smart TV Experience. On current software, uncheck Automatic Content Recognition (ACR) and Viewing Information Disclosure. On older software the same control is a single line called Use Info from TV Inputs. Roku's More Ways to Watch suggestions run on this technology, so turning it off turns those off too. **Sony.** Look for Samba Interactive TV by name. Sony's own pages put it under System Preferences on many models, including Google TV sets. Consumer Reports found it just below Privacy in All Settings on 2025 models. Sony itself says the location varies by model. **Hisense sets running VIDAA, Hisense's own system.** Hisense calls its service Enhanced Viewing, and its own privacy notice describes it as an optional service. Its manuals say the feature runs only after you choose Yes, Enable Enhanced Viewing during setup. The control sits in a Privacy or Legal section under Settings, then System or Support, and the wording moves between model years, so on this brand especially, search your model number. **Amazon Fire TV sets.** Different situation. Amazon told Consumer Reports that Fire TV doesn't use ACR and doesn't read a cable box or other non-Amazon device plugged into the set. It does collect what you watch over an antenna and through apps. Amazon's own privacy FAQ names the controls, all under Settings, then Preferences, then Privacy Settings: Device Usage Data, Collect App Usage Data, Interest-based Ads, and on Fire TV televisions, Over-the-air Viewing Data. Newer software adds Manage Sharing From Apps, where Share App Viewing and Content Info stops supported apps sending viewing information to Amazon. Consumer Reports found the toggles on by default. Vizio's control goes further than the others. Turning Viewing Data off "will trigger the deletion of historical logs of Viewing Data for the VIZIO OS product from VIZIO's database," and a factory reset returns the setting to off rather than on. Roku's policy says the opposite about history. Data collected while the feature was on "will be retained by Roku and may still be shared with third parties" after you turn it off. What the control stops is the panel reading the screen. It isn't an off switch for advertising, and Vizio says as much in its own policy: after you turn Viewing Data off, "for a period of time you may continue to see tailored ads on other devices that were targeted based on Viewing Data that was shared before you turned off collection." What you give up going forward is recommendations and ad targeting built on what the set saw. ## What it does not turn off Netflix still knows what you watch on Netflix. Turning off ACR stops the television from reading the screen but does nothing to the apps, which keep their own records. The platform account keeps a log too. Vizio says it plainly: disabling Viewing Data "will not, however, affect or limit Activity Data collection," which is the record of what you open and search in the TV's own menus. On a Google TV set, Google's terms are a separate agreement you can't decline and still have a smart TV, and Google says the Google TV platform itself doesn't run ACR, though the brand on the front may. Your internet provider still sees the traffic leaving the house. And the television is not the only appliance with a second job. Your router is watching motion and your car is grading your driving on the same idea. A streaming stick plugged into a television that never joins wifi keeps the TV maker's ACR out of it. The stick then has its own account, its own telemetry and its own advertising ID. You will have at least moved the tracking to a company you picked. ## What to do today Find the control on your set and look at it before you decide anything. It may already be off. If it's on, turn it off, then check it again after the next factory reset. Then read the price tag on your next set differently. The same reading works on a laptop. ## Sources * Anselmi, Vekaria, D'Souza, Callejo, Mandalari and Shafiq, "Watching TV with the Second-Party: A First Look at Automatic Content Recognition Tracking in Smart TVs," ACM Internet Measurement Conference 2024 * Samsung Ads, "Understanding Automatic Content Recognition (ACR)," guide for advertisers, Canada, 2022 * Samsung support, "Samsung Smart TV Automatic Content Recognition (ACR) Feature," article ANS10010616 * VIZIO Viewing Data Supplement to the VIZIO Privacy Policy * VIZIO Holding Corp., Q2 2024 earnings release, August 7, 2024 * Roku, Inc., Q4 and Full Year 2025 Shareholder Letter, February 12, 2026 * Federal Trade Commission, "VIZIO to Pay $2.2 Million to FTC, State of New Jersey," February 6, 2017 * Texas Attorney General, suit against five TV makers, December 15, 2025 * Texas Attorney General, temporary restraining order against Hisense, December 17, 2025 * Texas Attorney General, agreement with Samsung, February 26, 2026 * Texas Attorney General, agreement with LG, May 11, 2026 * Sony support article 00182856, "Information about Samba TV," last modified February 10, 2026 * Roku, "Automatic Content Recognition, Smart TV Experience, and TV Ads Measurement Service Policy" * Roku support, "Using 'More Ways to Watch' on your Roku TV" * Amazon, "Privacy Settings FAQs for Fire TV Products, Fire Tablets and Kindle E-readers" * Amazon, "Manage Sharing of Viewing Information from Apps on Fire TV" * Hisense USA, "Enhanced Viewing Service Privacy Notice," effective March 1, 2025 * LG USA support, "How to Accept the Updated User Agreements on Your LG TV," page-dated September 2, 2026 * Consumer Reports, "How to Turn Off Smart TV Snooping Features," updated October 19, 2025
www.freshfromcache.com
September 5, 2026 at 4:29 PM
Five real browser extensions were bought by criminals and turned into malware. Chrome installed the update for 70,000 people. Check your add-ons this weekend.

Three more in this week's roundup:

https://www.freshfromcache.com/also-this-week-2026-09-04/
September 4, 2026 at 3:17 PM
A Windows pop-up is wrong about your antivirus. The FTC says Amazon padded its ad prices. Nineteen browser add-ons turned on their users. Android 17 shuts a door scammers use.
Also this week: a false antivirus warning, an FTC lawsuit over Amazon's ad prices, and 19 browser add-ons gone bad
I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week. ## A Windows pop-up says your antivirus is off, and Microsoft says the pop-up is wrong After a recent update to Microsoft Defender, Windows can put up a notice reading "Microsoft Defender Antivirus is turned off," with a prompt to tap or click to turn it back on. On August 28 Microsoft confirmed the notice is a bug. Its release-health page says the antivirus "is functioning correctly and all settings show it as active," that the notice can appear when Windows starts and again at random after that. It also keeps coming even if you switch notifications off. Every supported version of Windows is on the affected list, Windows 10 included. The fix arrives in a future Defender update. No date yet. Here's how to check for yourself. Open the Start menu, type Windows Security, and open it. Click Virus & threat protection. If that page says no action is needed and Real-time protection is on, the pop-up is the bug and you can close it. Defender is the antivirus we said was enough on August 13, and this changes nothing about that. The real notice comes from Windows Security itself, looks like every other Windows notification, and never gives you a phone number or asks you to install anything. A web page that says your antivirus is off and wants you to call someone is a scam. Sources: Microsoft and BleepingComputer ## The FTC says Amazon hid a surcharge behind its Sponsored search results When you search on Amazon, some of the products mixed into the results are labeled Sponsored. Brands bid for those spots in an auction, and for years Amazon told them it ran a "second price" auction, where the winner pays one cent more than the next highest bid. On August 31 the FTC and 22 state attorneys general, Washington and Idaho among them, sued Amazon in federal court in Seattle. The complaint says that starting in 2019 Amazon added an undisclosed charge it called a "soft reserve price" internally, that by 2024 advertisers were paying their full bid about 80 percent of the time, and that the surcharge was turned up ahead of Prime Day and Black Friday. Amazon's own documents, as quoted in the complaint, describe "a surcharge hidden in it" and an "invented auction participant." The FTC puts the take at tens of billions of dollars from more than a million brands and sellers, over 500,000 of them small and mid-size businesses. Amazon calls the suit "misguided" and says "in no scenario does an advertiser pay more than their bid." It also says the complaint cites no evidence of higher prices for shoppers, and that its average cost per click was flat, adjusted for inflation, from 2019 to 2024. The FTC's chairman said the higher costs "were largely passed on to American consumers." Nobody has put out a number on that, and a complaint filed August 31 is a long way from a verdict. Amazon's own advertiser page says Sponsored products can appear at the top of, alongside, or within shopping results, so scrolling past the first few doesn't get you to a clean list. Look for the Sponsored label on each result before you compare prices. This is the second Amazon money story in a row; last week it was the crossed-out prices on Amazon's own devices. Sources: Federal Trade Commission, Amazon and Amazon Ads ## Nineteen browser add-ons turned on the people who installed them A security firm called Socket published the details on August 27. Nineteen extensions for Chrome and Edge, most of them small utilities like SEO checkers, crypto price tickers and a tool for re-enabling right-click on pages that block it, were carrying the same malware kit. Once installed, it stripped the security rules from every page you visited, slipped its own code in, and pulled down modules to do the actual work. The ones Socket watched drained cryptocurrency wallets, recorded whatever you typed into password fields on any site, and put up a fake "Chrome update available" page that tells you to paste a command into your computer. Fourteen of the nineteen were built to be malicious, published clean, then updated with the malware once they had users. The other five were real extensions, written by real developers, that the criminals bought. The biggest, a right-click enabler sold under the name Enable Right Click & Copy, had about 70,000 Chrome users when the bad update went out. Chrome updates extensions on its own, and nobody is told when an extension changes hands. Socket says one with 10,000 users can be bought for under $2,000. Google removed the Chrome listings. The Edge listing was still live when the report came out, with a fresh update from August 14, and was gone by September 3. In Chrome, type chrome://extensions in the address bar. In Edge, edge://extensions. Remove anything you don't recognize or haven't used in months. If one of the extensions on Socket's list was installed, treat every password you typed in that browser as exposed and change them, starting with email and banking; a password manager makes that an afternoon instead of a month. Our Chrome and Edge settings walkthrough covers the rest of that page. Sources: Socket and BleepingComputer ## Android 17 hides site names from the network and lets your carrier close a 2G scam door On August 27 Google described four network protections in Android 17, which is on Pixel phones now and reaching other brands through the rest of the year. The first is a scam fix. Crooks have been using portable fake cell towers called SMS blasters, priced from about $3,000, to force nearby phones off 5G and LTE onto old 2G, where the carrier's spam filters cannot see the text that follows. Android 12 added a manual switch to turn 2G off. Android 17 lets your carrier turn it off for you, by default, with no setting to find. Google hasn't said which carriers are participating. The second is called Encrypted Client Hello. Even on a locked-padlock HTTPS connection, the site's name can still be readable to whoever runs the network, whether that's your internet provider or the coffee shop's Wi-Fi. Android 17 hides that name from the start of the connection, and Google calls it the first major phone system to do so broadly. The catch, in Google's own words, is that it works "for supported websites and apps," so the protection grows as sites adopt it, and it does nothing about the sites you log into selling what they know. Two smaller ones round it out. Apps now have to ask before they scan your home Wi-Fi for your TV and cameras, and website certificates have to appear in a public log, which makes a forged one easier to catch. The only thing to do is take the Android 17 update when your phone offers it. Sources: Google and 9to5Google That's the week. If you are new here, Start Here collects the pieces worth reading first, and the Tuesday email carries the whole week in one place.
www.freshfromcache.com
September 4, 2026 at 11:00 AM
You say something out loud, and hours later there's an ad for it.

Cox Media Group told advertisers it could hear that. The FTC looked and found the service never collected any voice data. It was reselling broker email lists at a markup.

The ad still […]

[Original post on freshfromcache.com]
September 3, 2026 at 12:17 PM
The FTC fined Cox Media Group and two partners $930,000 over Active Listening, a service they said could pick up conversations from phones, TVs and smart speakers. It never collected a second of audio, and the tracking that really explains those eerie ads is duller and harder to escape.
Cox Media Group told advertisers it was listening to you. The FTC says it never was.
> "My phone must be listening to me." We've all said it. You talk about some obscure product. A few hours later you're seeing an ad for the exact thing you talked about. You didn't Google it. You didn't look it up. You only said it out loud. So the phone must be listening. But is it? For years the answer has been a shrug and a stack of studies. Then a company came along and sold the thing everybody was afraid of. ## "Where do you want us to listen?" Cox Media Group, a Georgia media company, started selling small businesses a product called Active Listening in 2023, and the pitch was not subtle. Its own website told customers that a smartphone "is technically always listening." Voice data goes further than search data, the page argued, so "every casual conversation between two consumers becomes a tool for you to target, retarget, and retain customers." One line read, "Creepy? Sure. Great for marketing? Definitely." In sales presentations the company said Active Listening used AI "to detect pertinent conversations via smartphones, smart tvs, smart speakers and other devices." It offered territories in ten and twenty mile radiuses. Prospective customers were asked, in writing, "Where do you want us to listen?" When a small business owner pushed back and asked whether any of this was legal, the FTC says the company doubled down. Employees were coached to name Alexa, Google, OpenTable and Samsung as sources, and to point out that almost every app and device people buy asks for microphone access. What the company was actually selling was email addresses. It was buying lists of them from data brokers, the same lists any advertiser can buy, and reselling them at a markup. Smart devices weren't sending voice data to Cox Media Group. There was no algorithm sorting anybody's conversations. The geography was fake too. A business paying to reach people within ten miles of Orlando got a list of people scattered across the country, with only a fraction of them anywhere nearby. The Federal Trade Commission announced the proposed settlements in May and finalized the orders on August 27. Cox Media Group is paying $880,000. MindSift in New Hampshire and 1010 Digital Works in Wisconsin, the two smaller firms that supplied the sales materials, are paying $25,000 each. Underneath the frightening name, this was the ordinary data-broker business. We've written that one up separately, in what a data broker is and what they have on you. ## The strange part is who counts as the victim The FTC's order sends that money to Cox Media Group's customers, meaning the small businesses that bought the service. That follows from what the agency found. If no microphone ever turned on, the businesses are the only ones out any money, and what they lost was an ad budget. Sit with that for a second. The businesses in line for redress are the ones who read "Where do you want us to listen?" and reached for a credit card. They paid for a product sold on that promise. They were lied to as well, and that matters. They were told the eavesdropping was legal because customers had agreed to it in an app's terms. Nobody knows how many of them believed that and how many just liked the sound of the product. But the people supposedly overheard at their own kitchen tables were never customers and were never recorded, so in the eyes of this case they were never the ones wronged. They were the product being described. ## Clicking accept is not consent The companies also told advertisers that consumers had opted in to all of this. Their evidence was the terms of service you accept when you set up a phone or install an app. Cox Media Group put it this way to customers: "You may not realize it, but when you download apps, set up new devices you 'accept' the terms, and those terms include allowing them to access your microphone." Clicking through mandatory terms of service, the agency said, doesn't amount to opt-in consent for a service that invasive or for voice data from inside somebody's home. Then it went a step further. If Active Listening had worked the way it was advertised, that collection and use of voice data without adequate consent would itself have broken the law. So the fine is for lying about the product. The regulator still went out of its way to say that building it for real would have broken the law. ## Why you saw the ad One company's sales pitch doesn't settle the bigger question. Nobody at the FTC opened up your iPhone, or Meta's ad system, or the thousands of apps sitting on your phone. So here is what the wider evidence does and doesn't cover. Researchers have gone looking. The best known attempt gathered more than 17,000 Android apps from four app stores and put them through a mix of code inspection and live testing on real devices. In the live tests, nothing sent audio out. They were upfront about what that could miss. It was a slice of the app store, run for short sessions, on Android only, and audio turned into text before it left the phone wouldn't have shown up. That doesn't prove it can't happen. It means people went looking in thousands of apps and didn't find it. Meanwhile the ordinary machinery keeps working, and any one ad usually has dozens of possible explanations behind it. Your phone carries an advertising ID, a long string that identifies the device across apps. Purchases, app activity, loyalty programs and location patterns get attached to a profile. Data brokers buy and sell the results. Advertisers then bid to reach people who match a description, and you match a lot of descriptions. Two people in the same house already share plenty of signals. Same home address, same Wi-Fi, overlapping location history, probably some of the same stores and services. One person starts shopping for a leaf blower. The other person fits the audience too. Two people in the same house look like one audience. Photo: Getty Images via Unsplash And we notice the hits. We don't remember all the ads that had nothing to do with anything we said that afternoon. If this system sounds familiar, it's the same one behind why two people can see different prices for the same item. ## What your microphone does hear There's one real exception, and it isn't a secret. Voice assistants record. That's their job. They listen on the device for a wake word, then start recording when they think they hear one. Sometimes they're wrong, which is how clips of people who never said "Hey Google" ended up in company hands. That's what Google's $68 million settlement was about, and Apple's $95 million Siri settlement before it. Neither settlement found that those recordings were used for advertising, and both companies say they weren't. A speaker waiting for its wake word. This is the one device in the story that really does record, and it says so on the box. Photo: Bence Boros via Unsplash ## See who used your microphone Both phone platforms will now tell you which apps used the microphone and when. * **On an iPhone,** open Settings, tap Privacy & Security, scroll down to App Privacy Report and turn it on. It only starts collecting from the moment you switch it on, so give it a few days, then come back and look at Data & Sensor Access. * **On Android,** open Settings, tap Security and Privacy or Privacy, then Privacy dashboard, then Microphone. It shows the last seven days on Android 13 and up, the last 24 hours on Android 12. Some phone makers rename these, so if Privacy dashboard isn't there, look one menu deeper under Privacy. * **Watch the dot.** On an iPhone, an orange dot at the top of the screen means an app is using the microphone, and a green one means the camera, or the camera and microphone together. On Android it's a green indicator in the top right corner, and tapping it tells you which app. While you're in there, take the microphone away from anything with no business having it. A flashlight app doesn't need one. Then change one setting that has nothing to do with the microphone. On an iPhone it's Settings, Privacy & Security, Tracking, and turning off "Allow Apps to Request to Track." On Android it's deleting the advertising ID under Settings, Privacy, Ads. Neither is a cure, and neither empties a profile that already exists. Both do more about the ad than anything you can do to the microphone. One company sold that exact eavesdropping service to small businesses for two years, and when the government opened it up, there was nothing inside but purchased email addresses. The ad still found you. It found you through a profile you helped build, using permissions you agreed to, sold on by companies you've never heard of, and none of it needed a microphone. Go turn on App Privacy Report tonight. In a week you'll know what your phone has really been up to. **Sources:** * Federal Trade Commission, "FTC Finalizes Orders with Cox Media Group, Two Other Firms Settling Charges They Deceived Customers About 'Active Listening' AI-Powered Marketing Service," August 27, 2026 * Federal Trade Commission, "FTC to Require Cox Media Group, Two Other Firms to Pay Nearly $1 Million to Settle Charges They Deceived Customers," May 21, 2026 * Federal Trade Commission, Complaint, In the Matter of CMG Media Corporation, Docket 242-3029 * Federal Trade Commission, Decision and Order, CMG Media Corporation * Pan, Ren, Lindorfer, Wilson and Choffnes, "Panoptispy: Characterizing Audio and Video Exfiltration from Android Applications," Proceedings on Privacy Enhancing Technologies, 2018 * Electronic Frontier Foundation, "Is My Phone Listening To Me?" * Apple, "About App Privacy Report" * Apple, "About the orange and green indicators in your iPhone status bar" * Google, "Manage permissions from the privacy dashboard" * Google, "Check if your Android camera or microphone is on or off"
www.freshfromcache.com
September 3, 2026 at 11:11 AM
A stolen data dump got counted twice. The first automated pass found almost 25 million email addresses. After the test records and duplicates came out, 12.9 million belonged to real people. The breach was real anyway:

https://www.freshfromcache.com/who-is-shinyhunters/
September 2, 2026 at 12:18 PM
A hacking group said it took millions of customer records. Somebody opened the file and counted. The first big number in a breach story is a count of rows, not people.
Who is ShinyHunters, and why is that name in every breach letter?
ShinyHunters says it took about 284 million patient-related records from McKesson, a major American pharmaceutical distributor. McKesson has confirmed a cybersecurity incident. Its filing with the SEC says the company found it on August 25, that the investigation is in its early stages, and that it has not determined the incident is material. A notice to customers says intruders reached third-party applications and took data. Over the weekend the company added that the stolen data belonged to a subset of customers in two of its business units, the ones covering cancer care and medical supplies, that it has cut off the access, and that it will give the people affected free credit monitoring. It still has not said what data was taken, how many people are involved, or who did it. The 284 million is the group's own figure, and early coverage read it as 284 million patients. It is not that. ShinyHunters told BleepingComputer the number is a raw count of records, or lines, and that it has not finished going through the data and does not know how many people are in there. Carhartt shows what usually happens to a number like that. On August 13 the same group put Carhartt on its leak site and said it was holding more than 50 gigabytes of the company's data. Carhartt did not pay, and the data was published. Then somebody opened it. Troy Hunt runs Have I Been Pwned, the free service that tells you when your email address turns up in a breach. He downloaded the dump and ran his usual extractor over it, which pulled 24,876,077 unique email addresses. That figure is a machine count of every address in the files, and it is roughly what went into the first round of coverage. Hunt kept hunting. A large share of those addresses sat in folders named for TPC-DS, a standard test dataset companies use to benchmark their analytics systems. Fake customers, generated for load testing. The individual records looked plausible, but the pile did not. Nearly every email domain appeared exactly one time. Birth years ran flat from 1924 to 1992, about 1,100 people a year with no bump anywhere. There were more customers born in Montenegro than in the United States. He pulled the benchmark records, then duplicate Microsoft 365 addresses, then deactivated accounts and internal test domains. What he loaded into Have I Been Pwned was 12,933,413 addresses. Just under half the original count. The recount, after the benchmark records and duplicates came out. ## Carhartt still looks breached The data left after the cleanup still carries Carhartt's fingerprints. Hunt found 15,057 employee addresses ending in carhartt.com, internal system aliases nobody outside the company would know existed, and roughly 1,150 people who had tagged their own email address with "+carhartt" when they signed up. His conclusion was that Carhartt was almost certainly breached, and that the test records were most likely sitting beside the real ones when the attackers took everything. Carhartt has not put out a public statement about any of it. Hunt also says he has reviewed close to a hundred leaks on this group's site and has yet to find one where the data was invented. He allows that the criminals may not be the ones who got this number wrong either. A real theft picked up a pile of benchmark records that were sitting in the same place. An automated tool counted them faithfully. Nobody further down the line opened the files. As Hunt puts it, "the truth is in the data." ## Fourteen million records, 5.1 million people Panera Bread ran into the same problem in January. ShinyHunters claimed more than 14 million records. Have I Been Pwned processed the leaked files and found about 5.1 million unique email addresses. Both numbers are accurate. One person occupies several database rows. Old accounts stay in the table. Internal aliases count separately. The smaller figure is still a lot of people. Of the Carhartt addresses Hunt loaded, 83 percent had already turned up in earlier breaches. ## Arrests have not stopped it The name ShinyHunters has been in the news since 2020 and people attached to it have been arrested more than once. Sebastien Raoult, a French member of the original crew, was extradited to the United States and sentenced in January 2024 to three years and more than $5 million in restitution. French police arrested four more people in June 2025 over the running of BreachForums, one of them using the ShinyHunters handle. The name was back in operation within weeks of both. The FBI still calls ShinyHunters a cyber criminal group in its own advisories. Google's threat intelligence team is more cautious. It now tracks recent ShinyHunters-branded activity under three separate labels, partly to follow shifting partnerships and partly, in its own words, to "account for potential impersonation activity." In May, Google documented one of those cases. It found that a separate crew it tracks as UNC6671 had used the ShinyHunters name at least once to make its own threats more credible. Google assesses that the two operations are independent, on the basis of different negotiation channels, different domain registration habits, and UNC6671's own leak site. ## It often starts with a phone call For the cloud-account campaigns that put this name in so many breach stories this year, the entry point has been ordinary. Someone at the company gets a call from a person claiming to be IT support. The caller sends them to a login page built to look like the company's own, at an address like companyname-sso.com, and talks them through signing in. The page captures the password and the multi-factor code. Google says none of that comes from a security hole in the vendors' products. You have met this call. It is the fake fraud department or the fake tech-support call, directed at somebody's work account instead of their bank account. We wrote about the phone call itself back in June. Not every attack under this name works that way. In June, Google's Mandiant team tied a separate campaign to a previously unknown flaw in Oracle PeopleSoft, the software many universities run their student, payroll and finance records on. Oracle put out an emergency patch after the attacks had already started. No phone call in that one, and universities took the worst of it. Your information ends up in a dump because a company you dealt with kept it. The person who answered the phone may never have touched your account. ## The email that follows is its own scam The FBI put out an advisory about this group in May. Two things in it should stay with you. The first is the wording. It says these actors use "real or exaggerated claims" about the sensitive information they hold to pressure people into paying. A sender can have real stolen data and still exaggerate what it proves. Photo: Justin Morgan via Unsplash The second is what else has been happening. The FBI has seen threatening texts and calls aimed at victims and their families, fake emergency calls sent to their homes, and claims about compromising photos or videos that in many cases never existed. There is a whole side industry of scammers sending extortion emails under this brand, quoting a real leaked email address as their proof. ## What you can do Once your information is in a breach, what matters is what somebody can do with it next. * **Turn on breach notifications at Have I Been Pwned.** It is free, and it tells you when your address turns up in a dataset somebody has actually processed, rather than one somebody has advertised. * Freeze your credit if a breach you were caught in exposed your Social Security number or similar identity details. It blocks new accounts in your name and does nothing else, which is exactly what it is for. * **Expect the follow-up.** A leaked phone number, address or old password is what makes the next approach convincing. Our guides on spotting a phishing email and what to do after a scam both apply. * **Use a different password everywhere and turn on multi-factor.** A password manager handles the first part. For the second, read the prompt before you approve it, because approving one push notification is how a security company got broken into this month. * **Do not treat an email address or an old password as proof that somebody has photos, video or access to your computer.** If an extortion message knows your address, your phone number or an old password, those details may already be circulating from an earlier breach. ## If you are in one of these Look past the group name and the first big number, and find out which fields were exposed next to your account. A leaked email address is a different problem than a leaked password, and both are a different problem than a leaked Social Security number. What was exposed next to your name decides what you do today. **Sources:** * BleepingComputer, "McKesson discloses breach after ShinyHunters claims patient data theft," August 28, 2026 * McKesson, Form 8-K filed with the SEC, August 2026 * McKesson, Customer Cybersecurity Information Center * Troy Hunt, "A Cautionary Tale About Data Breach Claims, Verification and Carhartt," August 26, 2026 * Have I Been Pwned, Carhartt breach entry * BleepingComputer, "Panera Bread data breach impacts 5.1 million accounts, not 14 million customers," February 2026 * Google Threat Intelligence Group, "Vishing for Access: Tracking the Expansion of ShinyHunters-Branded SaaS Data Theft," January 30, 2026 * Google Threat Intelligence Group, "Welcome to BlackFile: Inside a Vishing Extortion Operation," May 16, 2026 * Google Threat Intelligence Group, "The Cost of a Call: From Voice Phishing to Data Extortion," June 4, 2025 * The Hacker News, "ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE-2026-35273) to Breach Universities," June 11, 2026 * Help Net Security, "Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert," June 11, 2026 * FBI Internet Crime Complaint Center, PSA I-051526-PSA, May 15, 2026 * US Department of Justice, Western District of Washington, "Member of Notorious International Hacking Crew Sentenced to Prison," January 2024. * The Record, "French police arrest four suspects tied to BreachForums," June 25, 2025.
www.freshfromcache.com
September 2, 2026 at 11:00 AM
Also: laptop specs, slow Wi-Fi, GTA VI malware, plus Google watching Search for your address.
This week: a price built just for you
Good morning! The personalized-pricing story is the one I want you to read this week. Stores can use information about you to decide the price you see. The FTC is now considering what they have to tell you when they do it. Most of the usual advice about clearing cookies barely touches the ways a store can recognize you. **In this issue:** * Are you paying a different price than your neighbor? * What laptop specs actually matter in 2026? * Why is my Wi-Fi slow? * The GTA VI leak. How big leaks become bait. * Also this week: pricier Amazon devices, a $17 billion Meta settlement, and a check from Disney * Google will tell you when your address shows up in its search results * Plus: three scams making the rounds * And the Scary Headline of the week: the Android app that scans for nudity * * * Are you paying a different price than your neighbor? Personalized pricing, sometimes called surveillance pricing, is when a business uses information about you to decide what you pay. Two shoppers can look at the same thing and be shown different prices because the store knows or guesses something different about each of them, often through the account or loyalty number they hand over themselves. The FTC says the practice is not automatically illegal, but hiding a personalized price can be deceptive or unfair. The article tests the usual advice, says what works instead, and walks you to the FTC docket before the comment window closes September 18. _Learn_ * * * What laptop specs actually matter in 2026? If you are shopping for a Windows laptop for everyday use, start with 16GB of memory and a 512GB SSD. Look for a 1080p or better IPS screen. Take the full processor model off the tag and search it before you buy, because Core 5 or Ryzen 5 tells you the tier but not how old the chip is. Wi-Fi 7, TOPS numbers and an "AI PC" label matter much less than the memory, storage, processor and screen. _Learn_ * * * Why is my Wi-Fi slow? Run a speed test next to the router, then run it again where things are slow. If it is already slow next to the router, the problem is probably not coverage. If it drops only in the bad room, move the router out of the cabinet or off the floor before you price a mesh kit. The article walks through six checks, including bufferbloat when a big upload ruins the internet for everyone else. _Learn_ * * * The GTA VI leak. How big leaks become bait. The leaked GTA VI clips were real, which made the fake downloads easier to sell. Malwarebytes found sites pretending to host footage or demos that delivered the Vidar password stealer, while another supposed 113GB leak archive was mostly empty data wrapped around a small program that disabled Windows Defender. If somebody in your house wants to see the leak, let them watch the clips on a normal video site. The full Extended Look aired August 27 on Netflix and YouTube, so the real thing is a click away. They do not need a ZIP file, ISO, installer or special player to watch a video. _News_ * * * Also this week: pricier Amazon devices, a $17 billion Meta settlement, and a check from Disney Amazon raised the list prices on several of its own devices, but as of Thursday most of the actual sale prices were still below those new numbers. Meta agreed to pay up to $17 billion over ten years to settle the multistate teen social-media case, with new limits planned for users under 18 in participating states. Disney's $50 million YouTube TV and DirecTV Stream settlement has a September 8 claim deadline. The CPSC also says owners of a KH158 plug-in gas and carbon-monoxide alarm sold under 18 brand names should stop using it because it can fail to sound during a real leak. _News_ * * * **If you only read one:** the personalized-pricing piece. It explains what surveillance pricing is, how a store can recognize you without relying on cookies, and what works instead of the usual advice. * * * ### 5-Minute Tech Tip Google's Results about you tool can watch Search for your home address, phone number, email address, driver's license number or Social Security number. Start by searching your own name and town in a private window so you can see what someone else sees. Then set up Results about you with the names and contact information you want Google to watch. When Google finds a match, you can request removal from Search. The original page can still keep the information, so a people-finder listing may need a second removal request at the source. * * * ### Fresh Trouble **The Amazon job text.** A text from an "Amazon Remote Recruitment Team" offers $100 to $600 a day for about an hour of work and tells you to text another number. Look up any real opening on Amazon's own jobs site instead. (Malwarebytes) **The veterans postcard.** A postcard says you or your spouse may qualify for a "Veterans Savings Program," but the FTC says the program does not exist. Benefit questions go to the VA at 1-800-827-1000, not the number on the card. (FTC) **Disaster donation asks.** After a hurricane, flood or earthquake, fake charities show up quickly. Find the charity yourself before you donate, and walk away from anyone demanding a gift card, wire transfer or cryptocurrency. (FTC) * * * ### Scary Headline of the Week _"Dystopian Android's nude-scanning app keeps reinstalling itself, and Google is opening access to other developers"_ SafetyCore is real. Google pushed it to Android phones through Google Play without a normal app install, and it has no icon sitting in your app drawer. Cybernews also reports that some people who removed it later found it installed again. The function is narrower than the headline makes it sound. SafetyCore provides an on-device classifier that Google Messages can use when Sensitive Content Warnings is turned on. Google says the classification stays on the phone. Its Play listing says SafetyCore itself collects no data and shares no data with third parties. GrapheneOS has looked at the component too. Its developers say SafetyCore has no way to report your images or its classification result to a service. An app sends content to the local model, gets a classification back, then decides what to do with it. Google is now building an Android API that lets other apps use the same kind of on-device content classification. That means the same kind of warning can start showing up in other apps. Those apps still need their normal permission to get at the photo or message in the first place. I still think Google created its own trust problem. A background component that examines sensitive content showed up on people's phones with almost no explanation. When Google wanted a video of your face as an account-recovery backup, setup was optional. You had to turn it on yourself. **Verdict:** "nude-scanning app" makes this sound like Google is secretly uploading your photo library. The evidence does not support that. The silent install is fair criticism, and opening the classifier to more apps deserves scrutiny. Seen a headline this week that scared you? Reply and send it. It might get next week's verdict. * * * ### Help Fresh From Cache grow This newsletter is free and written by one person. If it earns its spot in your inbox, two ways to help: forward this email to one person who might want it, and if it was forwarded to you, subscribe to get your own copy every Tuesday. And if you would rather chip in a few dollars, there is a support page now. Thank you for your support! * * * Have you ever caught a price changing on you, and did you figure out why? Hit reply. Joel
www.freshfromcache.com
September 1, 2026 at 4:25 PM
Ring's next encryption default destroys its copy of your video keys after 24 hours. That closes a door Ring left open for years. It stops at the moment an owner shares a clip.
Ring is throwing away its key to your videos
Ring is changing who can open old recordings from its doorbells and cameras. A new encryption mode starts rolling out in September. Ring says it will become the default worldwide once the rollout finishes. The name tells you what it does. TAKE stands for Throw Away the Key Encryption. Every recording gets an encryption key, the digital equivalent of a key to a locked box. A new one takes over every five minutes. Ring keeps a copy inside a hardened section of its cloud so features like Smart Alerts and Video Search can do their work. Then Ring throws that copy away. The deletion runs continuously rather than on a daily deadline. Each key gets destroyed once it passes 24 hours old, through a one-way process Ring says cannot be reversed, in a database configured with no backups. Your phones, tablets, and browsers keep their own keys the whole time. Play a week-old clip and your app hands Ring a temporary key so it can prepare the video. Ring's cloud cannot ask for one on its own. ## What changes for you In practice, after about a day nobody at Ring can open your old video unless your app hands over the key. Not a support agent, not an engineer, not a contractor. That last one matters. In 2023 the Federal Trade Commission alleged Ring had given employees and contractors broad access to customer video without adequate controls. Ring settled, paid $5.8 million, and agreed to a privacy and security program. TAKE leaves a window open at the front end. Ring's services can still decrypt video during the first 24 hours to run the features on your account. The change is what happens afterward. Once Ring's copy of the key is destroyed, that access stops being a matter of policy and becomes impossible. I have been skeptical of Ring for years and I still am. But a company that destroys its own keys has given something up. Policies get rewritten in an afternoon. A destroyed key is gone. ## Ring can still send police a locked file Ring's U.S. guidelines say non-content information, meaning things like your name, address, and email, can be produced under a subpoena. Video counts as content, and Ring says content requires a valid search warrant. Ring updated those guidelines four days ago. They now say Ring only has access to videos that are not protected by TAKE or end-to-end encryption. The word doing the work there is access. Ring told Gizmodo something the guidelines never spell out. It may still turn over the encrypted video file when valid legal process requires it. So the file can still leave Ring. Ring says it cannot open one. Ring also says it notifies the account owner before handing anything over, unless it is barred from doing so. ## The person on the sidewalk The keys belong to the camera owner. Everyone else in frame is along for the ride. Ring's own white paper draws that line in a footnote. The architecture covers video stored on Ring's infrastructure. Anything the owner chooses to share falls outside it, and Ring names the examples itself: share links, the video donation tool, and Neighbors. Once a clip gets passed along, the design stops applying to it. There is no consent prompt for the delivery driver or the neighbor walking a dog. It is the same gap that runs through Flock cameras. Rules about storage and search can limit misuse after the fact. There is still no way to opt out beforehand. That fight is already in court. A Virginia man who has never owned a Ring sued Amazon in June over Familiar Faces, Ring's opt-in facial recognition feature, saying his face was scanned while he was visiting friends who do. The allegations are unproven. Ring built a way for you to lock up your own footage. Whether anybody else in the frame wanted to be there is a question the settings page never asks. Two ways to lock your video, and what each one costs. ## What to check when TAKE reaches you * **Wait for the invitation.** Ring says it will notify you when your account is eligible to enroll. Your current setting stays exactly where it is until then. * **Decide camera by camera.** End-to-end encryption is set per camera now, so you can run TAKE on the doorbell and end-to-end on the back yard. Switching modes only covers new recordings, and old clips stay under whatever was running when the camera recorded them. * **Know what end-to-end costs.** It removes Ring's cloud from the group, which takes Video Search, Smart Video Descriptions, cloud Smart Alerts, and Shared Users with it. Live View and playback keep working. Some older cameras encrypt only once the video reaches Ring's cloud, and those support TAKE but cannot do end-to-end at all. * **Write down the passphrase.** Enrollment generates a twelve-word recovery phrase and Ring does not keep a copy. Lose every recovery method and your old video is gone permanently. * **Look at camera-based recovery.** Under TAKE, Ring stores a recovery key on the camera itself and turns this on by default. Using it requires standing next to the camera. You can switch it off and keep the other recovery methods. Find it under Control Center, then Video Encryption, then Enrolled Cameras. ## What Ring has not shown yet TAKE is built on Messaging Layer Security, an open standard published by the Internet Engineering Task Force as RFC 9420. Anybody can read that spec and go looking for holes in it. That is a real advantage over a scheme only Amazon can see. Everything layered on top is Ring's own. The white paper describes sealed hardware that holds the keys, a key database with no backups, and a deletion process that runs one direction only. It also mentions two features most of the coverage skipped. You can cryptographically confirm that your devices are the only ones with access, and every change to that list goes into a log nobody can edit without leaving a mark. The paper contains no independent audit. Every claim in it is Ring describing Ring. Ring also acknowledges a limitation directly. Think of the enclave as a vault. The keys get made inside it and stay inside it, and Ring says its own staff cannot get in there. The vault does not do the work, though. When a feature like Smart Alerts needs to look at your video, the key has to come out of the vault and go over to the service doing the looking. That service runs on ordinary Ring infrastructure. Ring says the key sits in memory there, never gets written to a disk, and gets erased the moment the job finishes. That is a promise enforced by code, and it is a step down from the vault. Moving those services into vaults of their own is work Ring says it is still exploring. Until that happens, the strongest protection covers the keys while they sit still, and something weaker covers the moment they get used. Until the invitation shows up, your camera is still running whatever you have today. Open Control Center, tap Video Encryption, and go see what that is. ## Sources * **Ring:** Introducing TAKE encryption (August 26, 2026) * **Ring:** Throw Away the Key Encryption and End-to-End Encryption white paper (August 26, 2026) * **Ring:** Privacy and law-enforcement guidelines * **Gizmodo:** Ring says its new encryption system could make it harder for police to access videos (August 26, 2026) * **TechCrunch:** Amazon faces class action lawsuit over Ring facial-recognition feature (June 2, 2026) * **Federal Trade Commission:** Ring privacy and security case
www.freshfromcache.com
September 1, 2026 at 11:01 AM
Researchers pooled six trials of digital programs built to fight loneliness in older adults. One control group got a binder with printed pages in it. The binder did about as well.

The World Health Organization went looking for the loneliest people and […]

[Original post on freshfromcache.com]
August 31, 2026 at 12:08 PM
Loneliness gets compared to smoking fifteen cigarettes a day. The researcher behind that number keeps a page on her own website correcting how people quote it. Here is where it came from, who is loneliest, and what the evidence says about your phone.
Does technology make us lonely?
My family is either hours away or a plane ride. My job moves me between buildings, so I can go a whole week without seeing the same face twice. Most of my social life happens on a screen. Every few months a headline tells me that is a problem. If your family is a flight away, or you are homebound, or the town you live in does not have many of your people in it, you may have been reading the same thing for years. So I went and read the research instead of the headlines about the research. Some of it surprised me. The number that gets repeated has been bent out of shape. Loneliness and isolation get talked about as one thing when they are two. And the fight over whether phones are doing this has no clear winner. ## The line you have probably heard > Loneliness is as bad for you as smoking fifteen cigarettes a day. That claim has a study behind it. It comes from a 2010 paper by Julianne Holt-Lunstad and her colleagues, who pooled 148 studies covering more than 300,000 people followed for seven and a half years on average. People with stronger social relationships had about a 50 percent greater likelihood of survival over that stretch. The authors then measured that effect against other risks we already take seriously. Smoking was one of them. So were alcohol, inactivity, and obesity. That set a benchmark. It was not an experiment. Lonely people were not put in one room and smokers in another and then compared. Holt-Lunstad keeps a page on her own website correcting how the claim gets used. Her careful phrasing is that lacking social connection is comparable to smoking up to fifteen cigarettes a day. The original measure combined several different counts. How big somebody's social network was, how much support they had, how isolated they were. The feeling of loneliness was only one part of it. The U.S. Surgeon General's 2023 advisory put the comparison front and center. That is why it stuck. Andrea Wigfield, who runs the Centre for Loneliness Studies at Sheffield Hallam University, wrote with two colleagues that the comparison could be called sensationalist, and that it can add to the burden and the stigma already carried by lonely people. Telling somebody who already feels alone that they are doing the equivalent of a pack a day is not information that helps them. That same 2010 paper put the risk in the range of heavy drinking and above inactivity or obesity, and nobody ever quotes those. Everybody already agrees cigarettes are bad for you. Nothing else on that list is that simple, and none of it makes as good a headline. ## The loneliest people are not who you think Loneliness and social isolation get treated like one word. They are two different measurements. Loneliness is the feeling that your relationships fall short of what you need. Social isolation is a count of how much contact you have. You can have plenty of one and none of the other. In June of last year the World Health Organization's Commission on Social Connection published its first global report. About one in six people worldwide are affected by loneliness, and the Commission estimates it contributes to roughly 871,000 deaths a year. The highest rates were among adolescents and young adults. Social isolation goes the opposite direction, and reaches up to one in three older adults. Young people report the feeling more. Older people have less of the contact. Those are two separate findings, and they get quoted as if they were one. Two questions, two different answers. The pandemic changed how much contact older adults had. It barely changed how they felt about it. When somebody says lonely, I picture an older person by themselves in a house, and I suspect you might too. That picture fits isolation, but not necessarily loneliness. In the United States, a University of Michigan poll of adults 50 to 80 found 33 percent felt lonely at least some of the time in 2024, against 34 percent in 2018. Six years with no real movement. ## Does the phone cause it? Nobody knows. I would like to give you a cleaner answer than that. There isn't one. In 2019, Amy Orben and Andrew Przybylski went at three enormous datasets covering more than 350,000 young people. They ran the numbers every defensible way instead of picking the ones that made a good headline. Technology use accounted for at most 0.4 percent of the variation in wellbeing. To show what an effect that size looks like, they lined it up against other questions in the same surveys. Eating potatoes was almost as bad for teenage wellbeing as screen time. Wearing glasses was worse. The effect everybody argues about, sitting next to effects nobody argues about. Jean Twenge, Jonathan Haidt and their colleagues tell a different story. Their study of more than a million 15- and 16-year-olds found loneliness at school rising between 2012 and 2018 in 36 of 37 countries, alongside spreading smartphone access. The paper says plainly that those patterns cannot prove causation. Haidt has since argued the causal case at book length. The mechanism they propose is displacement. A day has only so many hours. Time on a phone has to come from somewhere. The picture everyone has in mind. The data underneath it is messier. Twenge's own displacement paper, covering 8.2 million young Americans, found the trade happening at the level of a generation and not at the level of a person. College-bound high school seniors in 2016 spent about an hour a day less with other people than seniors in the late 1980s. But within any given year, the kids using the most social media were also the kids seeing their friends the most. Something took that hour. Nobody has shown it was the phone. Instead of watching what people already do, some researchers take social media away on purpose and measure what happens. Two teams have now pooled that same rough pile of experiments and come to different conclusions. Christopher Ferguson's 2024 analysis put the average benefit of cutting social media close enough to zero that he could not rule zero out. A 2025 meta-analysis by Kaitlyn Burnell and her colleagues, covering 32 randomized trials and 5,544 people, found a real improvement in wellbeing from restricting social media. The improvement measured 0.17, which is small. Burnell's team also found the benefit did not depend on how long the restriction lasted, or on the age or makeup of the group. And every one of those trials ran on college students and adults, average age 23, so none of it tells you much about a twelve-year-old. Candice Odgers at UC Irvine argues that some young people may use social media differently because they were already struggling. Her evidence is about youth mental health rather than loneliness, so I will not stretch it further than that. It is still a warning about how little a correlation can tell you about which one caused the other. The reason nobody can give you a clear answer is that the experiment it would take is not one anybody can run. Ten thousand children, half given phones and half given none, followed for fifteen years. Short of that, everyone is arguing over which imperfect substitute to believe, and two careful people can read the same studies and walk away with opposite conclusions. ## What does hold up Time by itself is a weak measure. The number of hours tells us very little. For a while the research offered a tidier replacement. Passive use meant scrolling, watching, keeping tabs on people. Active use meant talking to somebody. Passive was supposed to hurt through comparison, active was supposed to help through support. That model has not survived intact. A 2024 meta-analysis of 141 studies found most of those associations were negligible. The effects that did turn up shifted by age, by outcome, and by context. The authors warned against the neat rule that active is good and passive is bad. My read is that warm back-and-forth contact with somebody who already knows you matters more than counting hours. A sister, an old friend, the coworker you like. Not an audience you are performing for. A product is not neutral about which of those you get. Most apps open on a feed. Scrolling is already in front of you. Talking to one person means leaving it. Both are available, but only one is the default. An AI companion goes a step past that. On a feed, the app decides what is easy, and there are still real people somewhere on the other end. With a companion app, the product is the other end. There is nobody there. I wrote a piece on what we knew about AI companions and mental health, and the evidence has changed since. A Stanford team published a study this month of 1,131 people who use Character.AI, with nearly half a million of their real messages alongside the survey answers. The people using chatbots out of curiosity or to get work done reported better wellbeing than average. The lower wellbeing showed up among people with small social networks who were using the chatbot for company. It was worse with heavier use, and worse again among the people who told it more personal things. The researchers are careful that this is an association and that it is not uniform. But the people using it for companionship were the ones reporting the worst outcomes. A chatbot agreeing with you can feel a lot like being understood. If you are already short on people who understand you, agreement is an easy thing to accept instead. And it is built to agree with you, which is a product decision and not a personality. ## You cannot hand somebody a group and call it connection In 2021 a team led by Syed Ghulam Sarwar Shah pooled the trials of digital programs built to reduce loneliness in older adults. Six studies, 646 people, average age in the seventies. Four of the six were randomized, and every program ran at least three months. They were social networking platforms built for seniors, and web-based group discussion programs. No significant reduction in loneliness at three months, at four, or at six. The evidence ran from very low to moderate quality. One of those trials handed its control group a binder instead of the software. Printed pages, the same sort of material the program delivered on a screen, sitting in a three-ring binder on a table. It did about as well. The reviewers had a theory about why. A program like this may not reach loneliness unless it also deals with what sits underneath it, which is often mistrust, low self-esteem, and a fear of rejection. That fits the wider research. The interventions with the largest measured effect work on how a lonely person thinks about other people, rather than on adding names to a list. Putting a lonely person on a platform with a group to join does not reliably help. That is a narrower claim than technology doing nothing for older adults, and it would be a mistake to read it that way. Technology is not social media. A hearing test that came with the earbuds already in the drawer is technology. So is the magnifier already in your phone. So is a video call with your own daughter. Those are tools doing one specific job for one specific person, and none of them were in that study. One device, one job, one person on the other end. Each one removes a barrier between people who were already trying to reach each other. ## Where this leaves me I remember a little of life before the internet, but by ten I could not get enough of AIM and MSN Messenger. Online I can say what I mean, and I get a second to work out what that is. In person I am shy for a long time before I am me. One night out with a group and I need the next day to recover. Stay up late talking to people online and I am fine by morning. There is a number that cuts against me. The WHO found its highest loneliness rates among adolescents and young adults, the most online-native people alive. That might be a warning about growing up with smartphones and social media. It might also be that adolescence has always been hard and we are only now measuring it. In-person contact is not optional or lesser. It is different, and the difference matters. Bonds form easier face to face and you get a truer picture of who somebody is. But if your family is a flight away, or you are homebound, or the town you live in does not have your people in it, you have spent years being told that the technology keeping you tethered could be hurting you. The research does not support that. It also does not promise you that every hour online is good for you. What it does say is that the hours are a poor measure, and that who you are talking to tells you far more than how long you were there. So use the tool for the relationship you want. If you opened the app because you miss somebody, message them. If the group chat leaves you feeling closer to your friends, stay in it. If the feed leaves you feeling worse, close the feed rather than treating the timer as the problem. If the room where your people are happens to be on a screen, that counts. Nobody ever told me that and I wish somebody had. * * * _This piece is about ordinary loneliness, which is not the same thing as a crisis. If yours is sitting heavier than that, the 988 Suicide and Crisis Lifeline is free, always open, and takes calls and texts._ ## Sources Every study named in this piece, in the order it appears. Where a paper sits behind a paywall, the link goes to the abstract and the figures. 1. Holt-Lunstad, J., Smith, T. B., & Layton, J. B. (2010). Social relationships and mortality risk: a meta-analytic review. _PLoS Medicine_ , 7(7). Link 2. Holt-Lunstad, J. “15 Cigarettes” — the author’s own page correcting how the comparison gets quoted. Link 3. Office of the Surgeon General (2023). _Our Epidemic of Loneliness and Isolation_. U.S. Department of Health and Human Services. Link 4. Wigfield, A. and colleagues (2023). Is loneliness really as damaging to your health as smoking 15 cigarettes a day? _The Conversation_. Link 5. World Health Organization Commission on Social Connection (2025). First global report on social connection. Link 6. World Health Organization (30 June 2025). Social connection linked to improved health and reduced risk of early death. Link 7. University of Michigan National Poll on Healthy Aging (2024). Loneliness and social isolation among adults 50 to 80. Link 8. Orben, A., & Przybylski, A. K. (2019). The association between adolescent well-being and digital technology use. _Nature Human Behaviour_ , 3(2), 173–182. Link 9. Twenge, J. M., Haidt, J., and colleagues (2021). Worldwide increases in adolescent loneliness. _Journal of Adolescence_. Link 10. Twenge, J. M., Spitzberg, B. H., & Campbell, W. K. (2019). Less in-person social interaction with peers among U.S. adolescents in the 21st century and links to loneliness. _Journal of Social and Personal Relationships_ , 36(6), 1892–1913. Link 11. Ferguson, C. J. (2024). Meta-analysis of social media reduction experiments. Link 12. Burnell, K., Meter, D., Andrade, F., Slocum, A., & George, M. (2025). The effects of social media restriction: meta-analytic evidence from randomized controlled trials. _SSM – Mental Health_ , 7, 100459. Link 13. Odgers, C. (2024). The great rewiring: is social media really behind an epidemic of teenage mental illness? _Nature_. Link 14. Godard, R., & Holtzman, S. (2024). Are active and passive social media use related to mental health, wellbeing, and social support outcomes? A meta-analysis of 141 studies. _Journal of Computer-Mediated Communication_ , 29(1). Link 15. Zhang, Y. and colleagues (2026). Interaction with AI companions and psychological well-being. _Nature Human Behaviour_. Link 16. Shah, S. G. S., Nogueras, D., van Woerden, H. C., & Kiparoglou, V. (2021). Evaluation of the effectiveness of digital technology interventions to reduce loneliness in older adults. _Journal of Medical Internet Research_ , 23(6), e24712. Link 17. Masi, C. M., Chen, H. Y., Hawkley, L. C., & Cacioppo, J. T. (2011). A meta-analysis of interventions to reduce loneliness. _Personality and Social Psychology Review_ , 15(3), 219–266. Link
www.freshfromcache.com
August 31, 2026 at 11:00 AM
Have you ever Googled yourself? Come on, yes you have.

Try it today. Do it in a private window, so you are not seeing results shaped by your own search history, and put your town along with your name.

For most of us that first page is people-finder sites […]

[Original post on freshfromcache.com]
August 30, 2026 at 3:49 PM
Google's Results about you tool watches Search for your address, your phone number, and since February your driver's license and Social Security numbers. Here is what it pulls down and what it will not touch.
Google will tell you when your address shows up in its search results
Google your own name sometime. Not for vanity. Search it the way somebody trying to find you would, with your town added, and see what comes back. Do it in an incognito or private window, so you are not looking at results shaped by your own account and your own search history. For most of us it's a page of those people-finder sites. They sometimes list your age, the street you live on, the names of your relatives and a phone number that may or may not still work. None of it is secret, exactly. It's just been collected and stacked up in one place where anybody can read it. Google has a tool that watches for that on your behalf. It's called "Results about you," it's free, and you set it up once. Google says more than 10 million people have used it. The tool doesn't scrub the internet. It watches Google's own search results for details you tell it to look for, tells you when it finds them, and gives you a button to ask for the result to be taken out of Search. Watching is one thing, but it's blurrier when you request removal. ## Setting it up 1. Go to goo.gle/resultsaboutyou, or open the Google app, tap your profile picture, and choose "Results about you." The hub also lives at myactivity.google.com/results-about-you. 2. Add what you want watched. Google takes your name plus a nickname or a maiden name, and it takes more than one of each contact detail. So put in every phone number, home address, and email address you have used. 3. Add your government ID numbers too. Since February, Google also monitors for a driver's license, a passport, or a Social Security number showing up in Search. 4. Turn notifications on. Google says matches show up within a few hours of setup, and after that it emails you or pings the Google app when something new appears. Google asks for every name somebody might look you up under. Add another takes a nickname or a maiden name. Then you wait, and the results come to you. When one arrives you open it, look at what the page is actually showing, and hit "Request to remove" on the ones you want gone. Google reviews each request against its policy and emails you what it decided. Once monitoring is on, Google says the first check usually finishes in under six hours. You can also start a request straight from a search result. Tap the three dots next to it, open "About this result," and choose "Remove result." From a search result, the three-dot menu opens this panel. Remove result is the one you want. ## What it will actually take down Google's removal policy is broader than most people expect. Home address, phone number, and email address are the obvious ones. It also covers government ID numbers, bank and credit card numbers, pictures of your signature or your ID, medical records, and login credentials. A removal comes in two strengths. Google can pull the result out of every search, or it can pull it only out of searches for your name, which leaves the page findable by other means. Google says the first one is what happens most of the time. The narrower one turns up when the page also carries something Google considers valuable to the public, or somebody else's details sitting alongside yours. It is still useful. Nobody is typing your bank account number into Google. They are typing your name. Requests and their outcomes stack up under Removal requests. This one, against a people-finder site, came back approved. ## What it can't touch Google says it plainly on its own announcement page. "Removing this information from Google Search doesn't remove it from the web entirely." The people-finder site still has your file. It still sells it. Anyone who goes to that site directly, or uses a different search engine, finds exactly what they found before. What gets removed is the shortcut. There is a second limit that catches people. Google will not remove results from pages owned by educational institutions, government institutions, or newspapers. It treats those as public interest. So a county property record or a story in the local paper stays put. For a real fix you need to go after the source, which means opting out at the data brokers themselves. That is slower and it is work. Do this one first anyway. It takes the results off the page where people actually look, and it keeps watching after. ## Go look first Before you set anything up, run the search. Your name, your town, in a private window. Whatever comes back on that first page is the list you're working from, and it's the same list somebody looking for you will find. What came up for you that you did not expect to be public? I'm curious which category surprises people most. [email protected] **Sources** How the tool works: Google Search Help, Find and remove personal info in Google Search results (the hub at myactivity.google.com/results-about-you; nickname, maiden name, and multiple phone numbers, addresses and email addresses; notification within a few hours; "Request to remove" in the hub and "Remove result" from a search result; removal from every query is what happens most of the time; the educational, government and newspaper exclusions) What can come down: Google Search Help, Remove my private info from Google Search (the full list of removable information types, and removal from all searches versus searches for your name) The February change: Google, Stay in control of your personal information online (February 10, 2026; driver's license, passport, Social Security number; goo.gle/resultsaboutyou; "Removing this information from Google Search doesn't remove it from the web entirely") The 2025 redesign: Google, Protect your personal information and easily take action on outdated content in Search results (proactive monitoring, removal from the three-dot menu on a result, and the refresh request) Paths and claims re-verified against Google's own pages August 28, 2026. The 10 million figure is Google's own, from the February 10, 2026 announcement. Screenshots: Joel Folgner.
www.freshfromcache.com
August 30, 2026 at 11:00 AM
Congress never gave the FTC the power to ban personalized pricing. What it can do is make stores admit to it, and it is taking comments until September 18.
Are you paying a different price than your neighbor?
You add something to a cart, look again the next day, and the number has changed. So you look it up, and the internet has an answer ready. The store is watching you and charging what it thinks you will pay. Then comes the advice. Clear your cookies. Shop in a private window. Try a different ZIP code. Turn on a VPN. Most of that does very little. The Federal Trade Commission published its own take on August 19, and it says more about your grocery loyalty card than about your cookies. ## What the FTC said in August The Commission published a proposed enforcement policy statement on personalized pricing. That's a price set from your personal data and what a company concludes from it, including how much it thinks you will pay and whether it thinks you will shop around. The statement is blunt about the limits. "Congress has not given the Commission the authority to prohibit personalized pricing in all circumstances," it says. What the FTC can do is treat a hidden personalized price as deceptive or unfair under the FTC Act. If shoppers reasonably expect that a price does not change according to their personal data, the Commission says a business should clearly disclose that the price is personalized, the basis for it, and the kind of data behind it. Leaving that out, the statement says, is likely to break the law. The vote to publish was 2 to 0. The Commission says the extent to which businesses currently use personalized pricing "is not well understood," and that the effects on shoppers are unclear. It also declines to say whether some personalized pricing would still be unfair even when a company discloses it. This is a warning about hiding the practice rather than a finding that it is everywhere. The examples the statement gives are illustrations rather than accusations, but they are specific: * A grocery chain charging a delivery customer more for milk based on data showing several children live in the household. * A hotel charging more to someone it believes is traveling for a funeral. * A retailer charging more on its website when the data says the shopper is standing inside its own store or parking lot. Prices change all the time for reasons that have nothing to do with who is looking at them. ## Three reasons the price changes Only one of them is about you. Same item, three shoppers. Only the third price was built for a person. **Supply and demand.** Airfare, hotel rooms, rideshare surge, produce after a bad harvest. The price moves for everyone looking at that moment. **Where you are.** Prices differ between stores, regions, and delivery zones. Prices change for taxes, rent, competition, and shipping. Everyone shopping in that store still sees the same price on the shelf. **Who you are.** A price built from what a company knows or guesses about you personally. This is what people mean by surveillance pricing, and it is the hardest of the three to spot. A price displayed for you looks exactly like a price displayed for everybody. Insurance and credit belong in a category of their own. They have always been priced per person, and the FTC statement carves them out for that reason. If your car insurance quote depends on your driving record, you have been buying a personalized price for years. ## What has been caught The clearest case in American grocery shopping came from Consumer Reports and Groundwork Collaborative in December 2025. They recruited 437 volunteers who shopped Instacart at the same moment for the same list of items from the same stores. In one test at a Seattle Safeway, 39 shoppers put the same 20 products in a cart at the same time. Instacart showed them five different basket totals. The totals ranged from $114.34 to $123.93, a spread of $9.59. Only 8 percent of the group got the cheapest cart. Across the investigation, about 75 percent of the products checked had more than one price. Per-item gaps ranged from 7 cents to $2.56 and reached 23 percent on some items. Consumer Reports estimated that kind of swing could add up to roughly $1,200 a year for a family of four. Instacart says the tests assigned shoppers at random by product category and location, and denies using personal or demographic data to set them. Consumer Reports looked and reported that it found no evidence otherwise, while noting that its sample was too small to rule it out. The price differences are documented. Whether particular people were singled out remains unproven. In January 2025, FTC staff reported on documents from six pricing middlemen, including Mastercard, Accenture and McKinsey, who between them worked with at least 250 clients. Staff found the data used to tailor prices can include precise location, demographics, browsing history, shopping history, what you leave sitting in a cart, and even mouse movement on a page. The report's examples of how that data gets used are hypotheticals rather than case files because the underlying documents are confidential. Kroger has acknowledged using demographic data and purchase history in the promotions and discounts it offers loyalty members. That is disclosed, and it arrives as a discount, but it runs on the same machinery. What nobody has shown is a grocery store charging you a different shelf price than the person standing next to you because of who you are. Digital shelf labels are spreading, and they make prices easy to change quickly. Evidence that a store used them to personalize a shelf price has not appeared. ## Your account determines your price A store has to know it is you before it can price you. Here is what it can use, starting with the hardest to avoid. * **The account you sign into.** You hand it over on purpose, every visit. * **Your loyalty number.** The same thing at the register, with a discount attached to make it easy. * **The email address or phone number you type at checkout.** These match you to your account even when you never signed in. * **The store's app.** It sees more than a browser does, including your location if you allowed it. * **Your device fingerprint.** Your screen size, fonts, and settings, combined into something close to a name tag. * **Cookies and your IP address.** The bottom of the list, and the only two the usual advice seems to talk about. Clearing your cookies and hiding your address is the standard advice. Everything above them on that list survives the cleanse. Three checks out of twenty-one. The advice reaches the bottom two rows. The FTC's own document gives an example of what it considers an adequate disclosure. The example is a price based on "previous purchases from the same retailer through the same login account." Our browser privacy piece told you to block third-party trackers in Chrome and Edge, and that advice stands. It cuts the tracking that follows you between unrelated websites and feeds ad targeting. It does very little about a price attached to your account at a store you signed into. ## The usual advice, tested **A private or incognito window.** Does almost nothing on its own. It hides that session from other people using your computer. The store still sees your IP address, your device, and your account the moment you sign in. **Clearing cookies.** Same problem, with a cost. It signs you out of things, but fingerprinting can recognize you anyway. **One browser for looking, another for buying.** Does nothing if you sign in on both, which is what most people do at checkout. **Changing your ZIP code or using a VPN.** This one can move a price because location is a real input. It can also cost you money. Shipping and tax follow the address you actually enter, and some sites block VPN traffic outright. A wrong ZIP code on a delivery order gets you a failed delivery. A VPN only moves where you appear to be. Signing in gives you away. **Shopping signed out or as a guest.** This one does help because your account is the strongest thing a store has on you. It also costs you the member price at most stores, so you are trading one for the other. **Leaving it in the cart and waiting.** Sometimes it produces a discount email, which is the same system working in your favor. It is also how the store learns that you hesitate. ## What works **Compare across sellers.** Whether you are likely to comparison shop is itself something these systems try to estimate. A price directed at you only works if you do not look anywhere else. If you live somewhere with one grocery store and one internet provider, that advice does not work as well. Which is why the account and loyalty items below matter more for you. **Buy it in the store.** Consumer Reports stated directly that shopping in person will usually mean paying what everyone else pays. **Do the coupon math.** A targeted offer is a real discount when it beats the shelf price and beats the store down the road. Check both. **Run the two-phone test.** Same store, same item, same time. Sign into your account on one phone and stay signed out on the other. Change one thing at a time so you know what made the difference. **Use the rights Oregon already gave you.** The Oregon Consumer Privacy Act lets you ask a business that holds your data for: * a copy of what it has on you * a list of the specific companies it gave your data to * a correction to anything wrong * deletion of what it holds * an opt out of selling your data or using it for targeted ads Since January 1, 2026, covered businesses also have to honor a browser opt-out request. That request is a setting called Global Privacy Control, and it tells every site you visit not to sell your data. Firefox has it under "Tell websites not to sell or share my data." Brave and DuckDuckGo turn it on for you. Chrome and Edge need an add-on. If a business ignores a request, the Oregon Department of Justice takes complaints through its privacy complaint form. Its consumer hotline is 1-877-877-9392. New York has required since November 2025 that companies label an algorithmic price with a specific line: "THIS PRICE WAS SET BY AN ALGORITHM USING YOUR PERSONAL DATA." Several other states have gone further with grocery-specific rules. Oregon Senator Jeff Merkley introduced a bill with Senator Ben Ray Luján this year that would ban surveillance pricing in grocery stores outright, but it has not passed. ## You have until September 18 to comment The FTC is taking public comments on this policy statement, and the docket is open now. 1. Go to regulations.gov and search for docket **FTC-2026-1057**. 2. Open the docket and choose the comment button. 3. Write a few sentences about what you shop for, what you have seen, and what you want the agency to require. No account needed. 4. Submit it. You get a tracking number. Comments close **September 18, 2026, at 11:59 p.m. Eastern**. As of this week, 112 people had filed. One warning before you write. Comments are public. Your text, along with any name or contact information you put in the box, can be posted where anyone can read it. You cannot take it back afterward. Keep your address, phone number, and account numbers out of it. One comment from one shopper will not decide this. Volume and specifics do get read. The rest of the time, the best advice is old advice. Check another store before you buy. ## Sources * Federal Trade Commission, proposed enforcement policy statement on personalized pricing (File No. P034101), August 19, 2026 * Federal Trade Commission, “FTC Seeks Comment on Enforcement Policy Statement Regarding Personalized Pricing,” August 19, 2026 * Regulations.gov, docket FTC-2026-1057 (the comment docket) * Federal Trade Commission, surveillance pricing staff findings, January 17, 2025 * Consumer Reports and Groundwork Collaborative, “Instacart’s AI-Enabled Pricing Experiments May Be Inflating Your Grocery Bill,” December 2025 * Oregon Department of Justice, Consumer Privacy * Office of Senator Jeff Merkley, Stop Price Gouging in Grocery Stores Act of 2026
www.freshfromcache.com
August 29, 2026 at 11:00 AM
Reposted by Fresh From Cache
A laptop tag will call it a 2K touchscreen and the spec sheet on the same page says 1920 by 1200. Four numbers on that tag decide whether you still like the machine in five years, and one of them is usually not printed:

https://www.freshfromcache.com/how-to-read-a-laptop-price-tag/
August 26, 2026 at 12:34 PM
Reposted by Fresh From Cache
The video buffers every night around eight. The back bedroom has never had a signal. Slow Wi-Fi is five different problems that all feel the same, and six free checks tell you which one is yours:

https://www.freshfromcache.com/why-is-my-wifi-slow/
August 27, 2026 at 12:31 PM
Disney owes YouTube TV and DirecTV Stream subscribers part of a $50 million settlement. No receipts needed. The form closes September 8.

Three more in this week's roundup:

https://www.freshfromcache.com/also-this-week-2026-08-28/
August 28, 2026 at 12:24 PM
Amazon raised the list price on its own devices. Meta settled the teen social media case for $17 billion. Disney owes streaming subscribers a check by September 8. And a gas alarm sold under 18 names on Amazon can stay silent.
Also this week: pricier Amazon devices, a $17 billion Meta settlement, and a check from Disney
I can't write a full piece on everything that happens in tech every week, and you don't have time to read one anyway. So on Fridays I point you at the handful of stories that actually matter to everyday people, tell you in a sentence or two why you should care, and send you to someone who reported it well. Four this week. ## Amazon raised prices on the Echo Dot, the Kindle and the Fire TV Stick Sometime overnight on August 20 the prices on Amazon's own devices changed, with no announcement. Fortune noticed and got a statement out of Amazon: "The consumer electronics industry is facing significant increases in memory and storage component costs. After absorbing these increases for as long as we could, we recently adjusted pricing across our product lines." Memory chips are short because AI data centers are buying them first. Apple and Nintendo have raised prices this month for the same stated reason. Device| Old price| New price| On the shelf, Aug 27 ---|---|---|--- **Echo Dot**| $49.99| $79.99| $54.99, on sale **Kindle 16 GB**| $109.99| $149.99| $149.99, at list **Kindle Paperwhite 16 GB**| $159.99| $199.99| $199.99, at list **Fire TV Stick HD**| $34.99| $39.99| $17.99, on sale **Fire TV Stick 4K Max**| $59.99| $84.99| $49.99, on sale **Fire TV Cube**| $139.99| $199.99| $109.99, on sale **Mac mini (Apple)**| $799 ($599 at launch)| $899| orders open, ships Sept 22 **Switch 2 (Nintendo)**| $449.99| $499.99 from Sept 1| $449.99 through Aug 31 Amazon prices read off the live listings on August 27. The "new price" is the list price, the crossed-out number next to a sale price. Look at that last column. The new prices are list prices, and as of August 27 almost none of them is what Amazon is charging. The Echo Dot shows $54.99 with the $79.99 crossed out, five dollars more than the old list. The Fire TV Stick 4K Max is selling ten dollars under its old list. Amazon said in the same statement that it "will also offer promotions across its lineup throughout the year." A higher list price makes every one of those promotions look better. It also raises the floor for the weeks when nothing is on sale. We went through this on laptop price tags on August 26, and here it is on Amazon's own shelf five days later. The same squeeze is coming for phones. So if the thing you want is on sale, the sale price is real and the crossed-out number is decoration. If it is sitting at list, wait. Amazon told you itself that the promotions are coming. Sources: Fortune, Apple and Nintendo ## Meta agreed to pay $17 billion to settle the teen social media case Last week's roundup left off with four states in an Oakland courtroom trying Meta on behalf of a 29-state coalition. On August 25 the head of Instagram, Adam Mosseri, was on the stand being shown his own December 2021 blog post, which said more than 90 percent of teens kept the "Take a Break" reminder turned on. The internal number the states put next to it was 1.8 percent of teens actually using it. He agreed that figure was never made public. The next morning, at about 6 a.m., a settlement was filed. Meta will pay up to $17 billion over ten years to attorneys general from more than 45 states and territories. About $5 billion of that arrives only if YouTube and TikTok adopt the same restrictions. Texas was never in the multistate case and settled on its own the same day, for more than $1 billion, on the same terms. California's share is at least $1.5 billion. Meta's announcement spells out what changes for anyone under 18 on Instagram and Facebook in the participating states. All of it is on by default: * a two-hour daily limit that "teens can only turn off with a parent's permission" * a block from both apps between midnight and 6 a.m. * notifications muted during school hours, 8 a.m. to 3 p.m. * a reminder after every 15 minutes of continuous use * no like or reaction counts, on their own posts or anyone else's * no cosmetic-surgery or extreme-makeup filters * the option to make a non-personalized feed the default, and to turn off autoplay The states' agreement adds two more: a reporting channel where Meta has to answer 90 percent of teens' harm reports within six hours, and an independent auditor. There is also a second, stricter tier. If YouTube and TikTok sign on, the daily limit drops to one hour and the overnight block grows to 10 p.m. through 7 a.m., and that is where the last $5 billion comes from. Meta published an open letter asking YouTube and TikTok to join, on the grounds that "when teens are restricted on one app, they simply move to another." Neither had answered as of August 27. Judge Yvonne Gonzalez Rogers told the courtroom that morning that a document arriving at 6 a.m. deserved "a closer look." By the afternoon, according to court records reported by NPR and CBS, she had approved the deal. Nobody has said when the restrictions actually switch on. Meta says "pending judicial approval." California says "within months." Neither is a date. Florida stayed out entirely; its attorney general called the money "peanuts" and said, "We'll see them at trial." Zuckerberg never took the stand. Last week's block, if you want the setup. Sources: California Attorney General, Meta, NPR and The San Francisco Standard ## Disney owes YouTube TV and DirecTV Stream subscribers a check by September 8 Disney is paying $50 million to settle a class action called Biddle v. The Walt Disney Company. The suit accused Disney of using its ESPN carriage deals to push up what YouTube TV and DirecTV Stream charged everybody, whether or not they ever watched a game. Disney denies it, and settling means the case ends without a court ever deciding who was right. The settlement site's own dates. Screenshot: onlinetvsettlement.com, August 27. You are owed if you paid for either of these at any point between April 1, 2019 and March 31, 2026: * YouTube TV * DirecTV Stream, including the years it was sold as DirecTV Now or AT&T TV Now You do not need receipts. The administrator checks claims against the providers' own records. Filing online at onlinetvsettlement.com takes the Unique ID and PIN printed on the notice you got by mail or email. If you never got a notice or lost it, email the administrator at [email protected] and ask. Otherwise you can print the claim form and mail it. Either way, you say how long you subscribed and sign it under penalty of perjury. Payments are pro rata, which means everyone splits the pot in proportion to how long they subscribed, and the size depends on how many people file. Nobody has published a per-person estimate. Filing online starts with the Unique ID and PIN from your notice. Screenshot: onlinetvsettlement.com, August 27. Claims are due September 8, 2026. Online is the safer route this close to the deadline, because the mailing instructions say the form has to be in the administrator's hands by September 8, not just postmarked. Then nothing happens for a while. The final approval hearing is January 14, 2027, and money moves only after that and after any appeals. The administrator is Epiq, at 1-877-704-2517, which is a recorded line. Filing is free and there is no fee to release your money, so anyone who asks for one is running a different business. Source: Online TV Settlement ## A gas alarm sold under 18 names on Amazon can stay silent in a real leak On August 20 the Consumer Product Safety Commission told people to stop using a plug-in natural gas and carbon monoxide detector sold as model KH158. The agency has 91 reports of the unit failing to sound during a real leak. Consumer Reports, which flagged the detector to Amazon back in April, counts four hospitalizations in those reports, two of them children. About 377,000 were sold between June 2024 and July 2026, for anywhere from $13 to $140, on Amazon, eBay, AliExpress, Micro Center's website and snapklik.com. The maker is a Chinese company called Shenzhen Kanghua Shengshi Industrial, which does business as KH Alert, but you will not find that name on most of the listings. Here is what to check for: Check for model KH158 * White, gray or black plastic plug-in with a digital display * A button on the front marked SELF-TEST * Three lights left of the button: POWER (green), FAULT (yellow), ALARM (red) Sold under these 18 brand names * ARIKON * ELECOIN * FLUNGSKY * HAOKESITE * Hembisen * JNHCD * KAKIMENT * KH Alert * KOABBIT * NICGOL * NORJAN * OUMEBIU * Sooguard * Vilfet * Vzmcov * WESHLGD * XLA Alert * YOJOCK This is a warning, not a recall. The manufacturer has not agreed to take the product back, so there is no official refund and no fix coming. CPSC's instruction is to unplug it, throw it away, and put up a detector that meets the UL 2034 standard. Consumer Reports says Amazon pulled the listings, and that if yours came from Amazon you should put it through a return and ask for the refund. We wrote up the difference between a warning and a recall, and this is the case that post was describing. If you bought a plug-in combination alarm online in the last two years and cannot remember the brand, check your order history for the model number, then look at the front of the unit. Replace it with something carrying a UL mark. Sources: CPSC and Consumer Reports That's the week. If you are new here, Start Here collects the pieces worth reading first, and the Tuesday email carries the whole week in one place.
www.freshfromcache.com
August 28, 2026 at 11:00 AM