<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Short Lived</title>
    <description>The latest articles on DEV Community by Short Lived (@shortlivedage).</description>
    <link>https://dev.to/shortlivedage</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png</url>
      <title>DEV Community: Short Lived</title>
      <link>https://dev.to/shortlivedage</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/shortlivedage"/>
    <language>en</language>
    <item>
      <title>The FBI Warned About This Threat for a Decade. It's Never Happened.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Thu, 27 Aug 2026 13:05:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/the-fbi-warned-about-this-threat-for-a-decade-its-never-happened-5ban</link>
      <guid>https://dev.to/shortlivedage/the-fbi-warned-about-this-threat-for-a-decade-its-never-happened-5ban</guid>
      <description>&lt;h2&gt;
  
  
  What the warnings say, and what the record shows
&lt;/h2&gt;

&lt;p&gt;The FBI, the FCC, and the TSA have all issued public warnings about juice jacking, a theoretical attack where a compromised public USB charging port or cable steals data or installs malware while your phone charges. The term dates back to 2011, when security researchers first demonstrated the concept at the DEF CON hacker conference. Since then, researchers have built working proof-of-concept attacks from time to time, including a 2013 Georgia Tech demonstration that installed malware on an iPhone within one minute.&lt;/p&gt;

&lt;p&gt;The record doesn’t match the warnings. An Ars Technica investigation found no documented cases of juice jacking on modern iOS or Android devices, and Apple told the outlet it was unaware of any real-world attacks. A separate review of police records, court cases, and cybersecurity incident reports turned up zero confirmed juice jacking cases outside of controlled research demonstrations. The FCC itself has said it hasn’t found any real-world attacks since it started tracking the issue in 2019.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why a real capability produced no real victims
&lt;/h2&gt;

&lt;p&gt;The gap here isn’t that juice jacking is fake. Researchers have proven the technique works in a lab. The gap is between technical possibility and practical exploitation. A malicious charging station would need to sit undetected in a public location, and if it started compromising phones at scale, security researchers would likely spot it fast, given how much attention the concept already gets. Apple and Google have also added protections over the years: modern phones now require you to confirm data access when a USB connection is made, a step that blocks the simplest version of this attack outright.&lt;/p&gt;

&lt;p&gt;That said, the arms race hasn’t stopped. A 2025 study on a technique called ChoiceJacking demonstrated a way around those confirmation prompts, restoring at least part of the original threat on unpatched devices. Researchers keep finding new angles. None of those angles have yet produced a documented victim.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;You don’t need to treat every airport charging station like a trap, but the fix costs little enough that there’s not much reason to skip it. Carry your own charging cable and a wall adapter, or a small USB data blocker that only allows power through, and plug into an outlet instead of a public USB port when you can. Keeping your phone’s operating system updated matters too, since that’s where the newer protections against techniques like ChoiceJacking get patched in.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Absence of documented cases doesn’t guarantee absence of risk going forward, given researchers keep finding new bypass techniques. But it’s a real reason to worry less than a decade of headlines might suggest, and to treat this as a low-cost precaution rather than an emergency.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Communications of the ACM, “Juice Jacking.” &lt;a href="https://cacm.acm.org/news/juice-jacking/" rel="noopener noreferrer"&gt;https://cacm.acm.org/news/juice-jacking/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Malwarebytes, “Juice jacking warnings are back, with a new twist.” &lt;a href="https://www.malwarebytes.com/blog/news/2025/06/juice-jacking-warnings-are-back-with-a-new-twist" rel="noopener noreferrer"&gt;https://www.malwarebytes.com/blog/news/2025/06/juice-jacking-warnings-are-back-with-a-new-twist&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Wikipedia, "Juice jacking." &lt;a href="https://en.wikipedia.org/wiki/Juice_jacking" rel="noopener noreferrer"&gt;https://en.wikipedia.org/wiki/Juice_jacking&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;PwnDefend, "A threat to sanity, Cyber Myth: Juice Jacking." &lt;a href="https://www.pwndefend.com/2025/10/16/a-threat-to-sanity-cyber-myth-juice-jacking/" rel="noopener noreferrer"&gt;https://www.pwndefend.com/2025/10/16/a-threat-to-sanity-cyber-myth-juice-jacking/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;ESET, "Juice Jacking: Real Threat or Cybersecurity Myth?" &lt;a href="https://www.eset.com/blog/en/home-topics/privacy-and-identity-protection/juice-jacking-real-or-myth/" rel="noopener noreferrer"&gt;https://www.eset.com/blog/en/home-topics/privacy-and-identity-protection/juice-jacking-real-or-myth/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>cybersecurity</category>
      <category>practicaltech</category>
      <category>travelsafety</category>
    </item>
    <item>
      <title>The More You Share Online, the Safer It Starts to Feel. That's the Problem.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Wed, 26 Aug 2026 13:00:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/the-more-you-share-online-the-safer-it-starts-to-feel-thats-the-problem-6bl</link>
      <guid>https://dev.to/shortlivedage/the-more-you-share-online-the-safer-it-starts-to-feel-thats-the-problem-6bl</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2024 study combining a qualitative interview phase with a survey of 1,597 people found that the more someone engages in self-disclosure on social media, the less risky they perceive their own online activity to be. Higher engagement also came with a stronger sense of control over personal information, which itself predicted lower risk perception. The direction of that loop matters. Sharing itself appears to lower how risky the activity feels afterward, not just the other way around, creating a cycle where each post makes the next one feel a little safer than it is.&lt;/p&gt;

&lt;p&gt;A separate 2024 survey of 192 students focused on a narrower, more concrete problem: incidental data, private information that shows up in a post by accident rather than on purpose, a house number visible in a photo background, a reflection in a window, a recognizable landmark that reveals a location no one meant to share. Up to 21.88 percent of participants said they’d publish a posting containing this kind of accidental detail, and two-thirds of them recognized it as privacy-compromising even as they said they’d still post it. A related study by the same lead researcher showed how little effort it takes to exploit this: two hours of manual searching was enough to piece together private personal information a person never meant to make public.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why awareness alone doesn’t fix this
&lt;/h2&gt;

&lt;p&gt;Both findings point to the same underlying gap. Knowing sharing carries risk and feeling that risk in the moment are different things, and the feeling is what drives behavior. The first study shows why the feeling keeps shrinking over time: each post that doesn’t result in visible harm reinforces the sense that sharing is safe, regardless of what’s happening with that data behind the scenes. The second study shows the risk isn’t limited to what you choose to share on purpose. A caption you write with care can still sit next to a photo that gives away far more than you intended.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Before posting a photo, scan the background for things you wouldn’t say out loud: an address, a license plate, a work badge, a school uniform, a recognizable location tied to your routine. This is a different check than deciding whether to share the main content of a post. It’s a second pass looking for what’s riding along with it unnoticed. Given how fast incidental details can be pieced together by anyone motivated to look, treating background details with the same scrutiny as the caption itself is a reasonable habit, not an excessive one.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Neither study suggests people are careless by nature. The pattern described here is a normal psychological response to repeated low-harm experiences, not a personal failing. That’s part of what makes it worth naming instead of relying on people to notice it in themselves.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Fejes-Vékássy, L., Ujhelyi, A., Lantos, N. A. “I don’t care, I share! The importance of self-disclosure overwrites the risks of sharing on Social Media.” Current Psychology, 2024. &lt;a href="https://doi.org/10.1007/s12144-024-06496-2" rel="noopener noreferrer"&gt;https://doi.org/10.1007/s12144-024-06496-2&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Kutschera, S., et al. “Incidental Data: A Survey towards Awareness on Privacy-Compromising Data Incidentally Shared on Social Media.” Journal of Cybersecurity and Privacy, 2024. &lt;a href="https://doi.org/10.3390/jcp4010006" rel="noopener noreferrer"&gt;https://doi.org/10.3390/jcp4010006&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>practicaltech</category>
      <category>socialmedia</category>
      <category>techtalks</category>
    </item>
    <item>
      <title>A Fake Extension Passed Chrome's Review Process on the First Try</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Tue, 25 Aug 2026 13:00:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/a-fake-extension-passed-chromes-review-process-on-the-first-try-1i23</link>
      <guid>https://dev.to/shortlivedage/a-fake-extension-passed-chromes-review-process-on-the-first-try-1i23</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2024 study built a working extension designed to access sensitive fields like passwords and card numbers, then submitted it through the normal Chrome Web Store review process. It passed. The same researchers scanned over 160,000 existing extensions on the store and found 28,000 held permission to access sensitive input fields, with 190 caught storing password values in their own variables. A separate check of the top 10,000 website login pages found that 1,000 of them, including Google.com and Cloudflare.com, stored passwords in plain, unencrypted text within the page source itself, readable in full by any extension with basic access.&lt;/p&gt;

&lt;p&gt;A 2025 study measuring data minimization across about 200,000 extensions found 38 percent collected personal data reaching beyond what their stated functionality required. Another 2023 study cross-checked 47,200 extensions against their own published privacy policies and found 820 of them moving user data in ways that contradicted what they’d told users they do, with 525 pairs of privacy statements that contradicted each other within the same extension’s disclosures.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why store review doesn’t catch most of this
&lt;/h2&gt;

&lt;p&gt;Extension stores review submissions before publishing them, but the researchers behind a 2025 study of the Chrome Web Store’s own detection systems found a term for what happens next: concept drift. Malicious extensions evolve their behavior fast enough that classifiers trained on last year’s threats miss a meaningful share of this year’s. The same study found that commercial detection tools, the kind of scanner most people assume would catch this, did a poor job against known malicious extensions already confirmed by Google itself. Out of a fresh batch of over 35,000 extensions with no established history, the researchers still identified 68 that had already slipped past the vetting process undetected.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Extension count matters less than permission scope. Before installing anything, check what access it requests: an extension that wants to “read and change all your data on all websites you visit” carries reach into everything you type, including on your banking site. Open your browser’s extension list from time to time and remove anything you installed once and forgot about. An old, abandoned extension with broad permissions is the kind of thing that keeps working in the background long after you stopped thinking about it.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;None of this means extensions are unsafe by nature. Most serve their stated purpose without incident. The issue is that store review and commercial scanning tools both have documented blind spots, which means the responsibility for checking permissions before installing sits with the user more than most people assume.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Nayak, A., et al. “Experimental Security Analysis of Sensitive Data Access by Browser Extensions.” Proceedings of the ACM Web Conference, 2024. &lt;a href="https://doi.org/10.1145/3589334.3645683" rel="noopener noreferrer"&gt;https://doi.org/10.1145/3589334.3645683&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Ling, Y., et al. “Essential or Excessive? MINDAEXT: Measuring Data Minimization Practices among Browser Extensions.” IEEE International Conference on Software Analysis, Evolution and Reengineering, 2024. &lt;a href="https://doi.org/10.1109/saner60148.2024.00104" rel="noopener noreferrer"&gt;https://doi.org/10.1109/saner60148.2024.00104&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Rosenzweig, B., et al. “It’s Not Easy: Applying Supervised Machine Learning to Detect Malicious Extensions in the Chrome Web Store.” ACM Transactions on the Web, 2025. &lt;a href="https://doi.org/10.1145/3770852" rel="noopener noreferrer"&gt;https://doi.org/10.1145/3770852&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>browserextensions</category>
      <category>privacy</category>
      <category>practicaltech</category>
      <category>techtalks</category>
    </item>
    <item>
      <title>Clearing your cookies feels like starting fresh.

Researchers tracking 150,000 people for two years found your browsing habits give you away again in under a minute.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Mon, 24 Aug 2026 13:04:20 +0000</pubDate>
      <link>https://dev.to/shortlivedage/clearing-your-cookies-feels-like-starting-fresh-researchers-tracking-150000-people-for-two-23g2</link>
      <guid>https://dev.to/shortlivedage/clearing-your-cookies-feels-like-starting-fresh-researchers-tracking-150000-people-for-two-23g2</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/shortlivedage/clearing-your-cookies-buys-you-about-60-seconds-of-anonymity-o83" class="crayons-story__hidden-navigation-link"&gt;Clearing Your Cookies Buys You About 60 Seconds of Anonymity&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/shortlivedage" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" alt="shortlivedage profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/shortlivedage" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Short Lived
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Short Lived
                
                
              
              &lt;div id="story-author-preview-content-4470548" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/shortlivedage" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Short Lived&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/shortlivedage/clearing-your-cookies-buys-you-about-60-seconds-of-anonymity-o83" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 24&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/shortlivedage/clearing-your-cookies-buys-you-about-60-seconds-of-anonymity-o83" id="article-link-4470548"&gt;
          Clearing Your Cookies Buys You About 60 Seconds of Anonymity
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag crayons-tag--filled  " href="/t/techtalks"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;techtalks&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/privacy"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;privacy&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/browsertracking"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;browsertracking&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/practicaltech"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;practicaltech&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
            &lt;a href="https://dev.to/shortlivedage/clearing-your-cookies-buys-you-about-60-seconds-of-anonymity-o83#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Clearing Your Cookies Buys You About 60 Seconds of Anonymity</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Mon, 24 Aug 2026 13:00:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/clearing-your-cookies-buys-you-about-60-seconds-of-anonymity-o83</link>
      <guid>https://dev.to/shortlivedage/clearing-your-cookies-buys-you-about-60-seconds-of-anonymity-o83</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2025 study analyzed behavioral fingerprinting, identifying users by habitual patterns in how they browse rather than by cookies or device details, tracking over 150,000 people across two years. The researchers found that after a privacy-protecting action like clearing cookies or switching networks, a user loses an average of 78 to 85 percent of their anonymity within the first 60 seconds of browsing, and 90 percent within 10 minutes, canceling out most of the protection the action was supposed to provide.&lt;/p&gt;

&lt;p&gt;A separate 2024 study built a tool called FP-tracer to measure how often websites fingerprint visitors using techniques like canvas and audio analysis. It found high-intensity fingerprinting on 8 percent of the domains tested, with more moderate activity present on up to 75 percent, and confirmed that fingerprinting shows up close to five times more often in third-party scripts than first-party ones. The same research checked whether standard cookie consent banners offer any real protection against this specific technique. They don’t.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why clearing cookies misses the real problem
&lt;/h2&gt;

&lt;p&gt;Cookies and fingerprinting solve the same tracking problem in different ways. A cookie is a file stored on your device, delete it and the identifier is gone. Fingerprinting works by reading characteristics your browser and behavior already expose: screen resolution, installed fonts, typing rhythm, scroll patterns, browsing habits, none of which a cleared cookie touches. Deleting cookies removes one tracking method while leaving a second, less visible one intact.&lt;/p&gt;

&lt;p&gt;A 2025 study went further, showing that modern CSS styling code alone, with no JavaScript running at all, could distinguish 97.95 percent of over 1,100 tested browser and operating system combinations. This works even inside restrictive settings like email clients that block scripts for the specific purpose of preventing this kind of tracking.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Cookie deletion is worth doing, but treat it as one layer, not a full reset. Browser extensions built to resist fingerprinting, and privacy-focused browsers that randomize or standardize the technical details fingerprinting relies on, address a gap that cookie clearing alone leaves wide open. If a service claims deleting cookies makes you anonymous again, that claim doesn’t hold up against how tracking works today.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;This research measured technical capability and real-world prevalence, not what any specific company does with fingerprinting data right now. The tools exist and are already in use. Individual sites still vary in what they do with what they collect.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Crichton, K., et al. “Rethinking Fingerprinting: An Assessment of Behavior-based Methods at Scale and Implications for Web Tracking.” Proceedings on Privacy Enhancing Technologies, 2025. &lt;a href="https://doi.org/10.56553/popets-2025-0158" rel="noopener noreferrer"&gt;https://doi.org/10.56553/popets-2025-0158&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Boussaha, S., et al. “FP-tracer: Fine-grained Browser Fingerprinting Detection via Taint-tracking and Entropy-based Thresholds.” Proceedings on Privacy Enhancing Technologies, 2024. &lt;a href="https://doi.org/10.56553/popets-2024-0092" rel="noopener noreferrer"&gt;https://doi.org/10.56553/popets-2024-0092&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Trampert, L., et al. “Cascading Spy Sheets: Exploiting the Complexity of Modern CSS for Email and Browser Fingerprinting.” Network and Distributed System Security Symposium, 2025. &lt;a href="https://doi.org/10.14722/ndss.2025.230238" rel="noopener noreferrer"&gt;https://doi.org/10.14722/ndss.2025.230238&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>browsertracking</category>
      <category>practicaltech</category>
      <category>techtalks</category>
    </item>
    <item>
      <title>$3 billion lost last year. No malware. No stolen password. No breach in the technical sense at all.

Just an email asking someone to send money to the wrong place.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sun, 23 Aug 2026 13:18:20 +0000</pubDate>
      <link>https://dev.to/shortlivedage/3-billion-lost-last-year-no-malware-no-stolen-password-no-breach-in-the-technical-sense-at-59c4</link>
      <guid>https://dev.to/shortlivedage/3-billion-lost-last-year-no-malware-no-stolen-password-no-breach-in-the-technical-sense-at-59c4</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/shortlivedage/one-email-cost-businesses-3-billion-last-year-it-didnt-need-a-single-hacking-tool-59a8" class="crayons-story__hidden-navigation-link"&gt;One Email Cost Businesses $3 Billion Last Year. It Didn't Need a Single Hacking Tool.&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/shortlivedage" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" alt="shortlivedage profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/shortlivedage" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Short Lived
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Short Lived
                
                
              
              &lt;div id="story-author-preview-content-4464895" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/shortlivedage" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Short Lived&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/shortlivedage/one-email-cost-businesses-3-billion-last-year-it-didnt-need-a-single-hacking-tool-59a8" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 23&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/shortlivedage/one-email-cost-businesses-3-billion-last-year-it-didnt-need-a-single-hacking-tool-59a8" id="article-link-4464895"&gt;
          One Email Cost Businesses $3 Billion Last Year. It Didn't Need a Single Hacking Tool.
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/technology"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;technology&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cybersecurity"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cybersecurity&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/fraud"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;fraud&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/practicaltech"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;practicaltech&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/shortlivedage/one-email-cost-businesses-3-billion-last-year-it-didnt-need-a-single-hacking-tool-59a8" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt;&amp;nbsp;reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/shortlivedage/one-email-cost-businesses-3-billion-last-year-it-didnt-need-a-single-hacking-tool-59a8#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>One Email Cost Businesses $3 Billion Last Year. It Didn't Need a Single Hacking Tool.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sun, 23 Aug 2026 13:00:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/one-email-cost-businesses-3-billion-last-year-it-didnt-need-a-single-hacking-tool-59a8</link>
      <guid>https://dev.to/shortlivedage/one-email-cost-businesses-3-billion-last-year-it-didnt-need-a-single-hacking-tool-59a8</guid>
      <description>&lt;h2&gt;
  
  
  What the data shows
&lt;/h2&gt;

&lt;p&gt;The FBI’s Internet Crime Complaint Center logged $3.046 billion in losses from business email compromise in 2025, from 24,768 reported complaints, making it the second most damaging crime type in the entire report by dollar amount, behind only investment fraud. The number climbed from $2.77 billion the year before, continuing a trend that hasn’t slowed despite years of warnings.&lt;/p&gt;

&lt;p&gt;BEC is unusual among cybercrimes for what it doesn’t require. It doesn’t rely on malware, a stolen password, or breaking into a system. An attacker impersonates someone the victim already trusts: an executive, a vendor, a lawyer handling a transaction, and asks for a wire transfer or sensitive information through a well-written email. The FBI’s own report describes a real case: a senior citizen closing on a property received a compromised email appearing to come from the title company, containing wire instructions for over $1.3 million to a fraudulent account.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why speed makes this hard to undo
&lt;/h2&gt;

&lt;p&gt;The vast majority of BEC losses move through wire transfer or ACH payment, methods built for speed rather than reversibility. Once funds land in a fraudulent account, they’re moved again within hours in many cases, often routed through several accounts or converted to cryptocurrency before a victim even realizes something went wrong. Unlike a stolen credit card, where a bank can often reverse a charge after the fact, a completed wire transfer has very little built-in recovery mechanism.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Any request to change payment details, wire funds, or send sensitive information, especially one that arrives by email and carries urgency, deserves a verification step outside that same email thread. Call the person at a phone number you already have on file, not one provided in the message. This applies as much to real estate closings and vendor payments as it does to a request that appears to come from a company executive. If a fraudulent transfer has already happened, the FBI’s Recovery Asset Team can sometimes freeze funds before they move further, but only if a complaint gets filed at IC3.gov fast, within the first hours if possible.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;BEC now often uses AI-generated writing to eliminate the awkward phrasing and typos that used to serve as warning signs. A well-written, professional-sounding email is no longer meaningful evidence that a request is legitimate.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Reference
&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;Federal Bureau of Investigation, Internet Crime Complaint Center. “2025 Internet Crime Report.” &lt;a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf" rel="noopener noreferrer"&gt;https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>technology</category>
      <category>cybersecurity</category>
      <category>fraud</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>You can change a stolen password in minutes.

Federal guidelines quietly admit you can't do the same for a stolen face, and they built a rule around it.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sat, 22 Aug 2026 23:56:05 +0000</pubDate>
      <link>https://dev.to/shortlivedage/you-can-change-a-stolen-password-in-minutes-federal-guidelines-quietly-admit-you-cant-do-the-3e7g</link>
      <guid>https://dev.to/shortlivedage/you-can-change-a-stolen-password-in-minutes-federal-guidelines-quietly-admit-you-cant-do-the-3e7g</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/shortlivedage/you-can-change-a-stolen-password-you-cant-change-a-stolen-face-39g8" class="crayons-story__hidden-navigation-link"&gt;You Can Change a Stolen Password. You Can't Change a Stolen Face.&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/shortlivedage" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" alt="shortlivedage profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/shortlivedage" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Short Lived
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Short Lived
                
                
              
              &lt;div id="story-author-preview-content-4457715" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/shortlivedage" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Short Lived&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/shortlivedage/you-can-change-a-stolen-password-you-cant-change-a-stolen-face-39g8" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 22&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/shortlivedage/you-can-change-a-stolen-password-you-cant-change-a-stolen-face-39g8" id="article-link-4457715"&gt;
          You Can Change a Stolen Password. You Can't Change a Stolen Face.
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/biometrics"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;biometrics&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/technology"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;technology&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/digitalsafety"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;digitalsafety&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/practicaltech"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;practicaltech&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/shortlivedage/you-can-change-a-stolen-password-you-cant-change-a-stolen-face-39g8" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt;&amp;nbsp;reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/shortlivedage/you-can-change-a-stolen-password-you-cant-change-a-stolen-face-39g8#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>You Can Change a Stolen Password. You Can't Change a Stolen Face.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sat, 22 Aug 2026 17:00:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/you-can-change-a-stolen-password-you-cant-change-a-stolen-face-39g8</link>
      <guid>https://dev.to/shortlivedage/you-can-change-a-stolen-password-you-cant-change-a-stolen-face-39g8</guid>
      <description>&lt;h2&gt;
  
  
  What official guidance says
&lt;/h2&gt;

&lt;p&gt;The National Institute of Standards and Technology sets the federal government’s own digital identity standards, and its guidelines are clear on this point: biometrics may be used only as part of multi-factor authentication, paired with something you hold in your hand, not as a stand-alone login method. That’s a real constraint on a technology most people already treat as sufficient on its own to unlock a phone or approve a payment.&lt;/p&gt;

&lt;p&gt;The reasoning traces back to a property biometrics can’t escape. A password that leaks can be changed in minutes. A fingerprint or a face template that leaks can’t be reissued, because you only get one face and ten fingerprints for life. Security researchers have already demonstrated the real-world version of this problem. In 2025, researchers showed that local device access could let an attacker tamper with stored biometric templates so the system accepts a fingerprint or face that isn’t the real one.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why convenience and security pulled in opposite directions here
&lt;/h2&gt;

&lt;p&gt;Biometric login exists to remove friction: no code to remember, no password to type, only a glance or a touch. That convenience is real, and it’s part of why adoption spread so fast. But the same design that removes friction also removes a layer of protection a password has by default: you can’t reset a face the way you reset a password, and a compromised biometric stays compromised everywhere it was ever used.&lt;/p&gt;

&lt;p&gt;Implemented well, biometrics raise the bar against casual theft and shoulder-surfing in ways a weak password never could. The lesson is to treat “I unlock with my face” as one piece of a system, the way NIST’s own framework does, rather than the whole system.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Keep biometric unlock enabled, but check that a second factor still guards anything that matters: financial accounts, email, anything tied to recovery access for other services. Most phones already default to this: biometric unlock backed by a PIN as fallback, which is close to the NIST model people don’t realize they’re already using. The gap shows up more in third-party apps that let biometrics serve as the entire login with no second factor behind it. Check settings on banking and financial apps in particular. That’s where a stand-alone biometric login carries the most real risk.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Biometric spoofing (fake fingerprints, AI-generated video used to defeat facial recognition) is an active and evolving area of attack. Liveness detection has improved, but no biometric system available today is unbeatable in every scenario, which is the exact gap a second factor exists to cover.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Reference
&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;National Institute of Standards and Technology. “Digital Identity Guidelines: Authentication and Authenticator Management (SP 800-63B).” &lt;a href="https://pages.nist.gov/800-63-4/sp800-63b.html" rel="noopener noreferrer"&gt;https://pages.nist.gov/800-63-4/sp800-63b.html&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>biometrics</category>
      <category>technology</category>
      <category>digitalsafety</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>The FTC opened a formal inquiry into AI companion chatbots.

One question sits at the center of it. What actually happens to everything you type in.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sat, 22 Aug 2026 00:45:26 +0000</pubDate>
      <link>https://dev.to/shortlivedage/the-ftc-opened-a-formal-inquiry-into-ai-companion-chatbots-one-question-sits-at-the-center-of-163</link>
      <guid>https://dev.to/shortlivedage/the-ftc-opened-a-formal-inquiry-into-ai-companion-chatbots-one-question-sits-at-the-center-of-163</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/shortlivedage/your-ai-chatbot-conversations-dont-stay-between-you-and-the-screen-40j7" class="crayons-story__hidden-navigation-link"&gt;Your AI Chatbot Conversations Don't Stay Between You and the Screen&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/shortlivedage" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" alt="shortlivedage profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/shortlivedage" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Short Lived
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Short Lived
                
                
              
              &lt;div id="story-author-preview-content-4448814" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/shortlivedage" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Short Lived&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/shortlivedage/your-ai-chatbot-conversations-dont-stay-between-you-and-the-screen-40j7" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 21&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/shortlivedage/your-ai-chatbot-conversations-dont-stay-between-you-and-the-screen-40j7" id="article-link-4448814"&gt;
          Your AI Chatbot Conversations Don't Stay Between You and the Screen
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ai"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ai&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/privacy"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;privacy&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/practicaltech"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;practicaltech&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/digitalsafety"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;digitalsafety&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/shortlivedage/your-ai-chatbot-conversations-dont-stay-between-you-and-the-screen-40j7" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt;&amp;nbsp;reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/shortlivedage/your-ai-chatbot-conversations-dont-stay-between-you-and-the-screen-40j7#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
    <item>
      <title>Your AI Chatbot Conversations Don't Stay Between You and the Screen</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Fri, 21 Aug 2026 14:00:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/your-ai-chatbot-conversations-dont-stay-between-you-and-the-screen-40j7</link>
      <guid>https://dev.to/shortlivedage/your-ai-chatbot-conversations-dont-stay-between-you-and-the-screen-40j7</guid>
      <description>&lt;h2&gt;
  
  
  What the FTC is looking into
&lt;/h2&gt;

&lt;p&gt;In September 2025, the Federal Trade Commission issued formal orders to seven companies operating consumer-facing AI chatbots, using its authority under Section 6(b) of the FTC Act. The orders demand detailed information about how these companies collect, store, use, and monetize the personal information people share during conversations. The inquiry is a broad research effort, not tied to a specific lawsuit, and the fact that the FTC felt it needed one signals something worth noticing: regulators don't have clear visibility into standard industry practice here.&lt;/p&gt;

&lt;p&gt;The FTC’s stated concern centers on how AI chatbots are built to simulate human-like relationships, communicating like a friend or confidant in a way that encourages people to trust them and share more than they might with a system they know is automated.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why “just a chat” undersells what’s happening
&lt;/h2&gt;

&lt;p&gt;A chatbot conversation feels private in the way texting a friend feels private, contained, temporary, only between you and the interface. The actual mechanics work in a different way. Conversations get stored on a server, can be used to train future versions of the system, and get reviewed by human staff in some cases for safety or quality purposes. Deleting a conversation from your screen doesn’t guarantee it’s gone from every place it’s been stored or copied. Legal holds tied to investigations or litigation can also override a company’s normal deletion timeline, keeping conversations around well past what a privacy policy might otherwise promise.&lt;/p&gt;

&lt;p&gt;None of this makes chatbots more dangerous than other online services. It does mean the sense of privacy the conversation format creates doesn’t match how the data gets handled behind it.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Treat anything you type into an AI chatbot with the same caution you’d apply to a public forum post, not a private conversation. Skip sharing financial account details, medical specifics, legal situations, or anything you wouldn’t want stored for years or reviewed by another person. Most major platforms offer a setting to opt out of having your conversations used for model training, separate from deleting individual chats. That setting is worth finding and checking, since it isn’t the default in most cases.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Regulatory scrutiny here is active and ongoing rather than settled. The disclosure requirements for these companies, and what changes as a result, are still unfolding as the FTC's inquiry proceeds.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Reference
&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;Federal Trade Commission. “FTC Launches Inquiry into AI Chatbots Acting as Companions.” 2025. &lt;a href="https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions" rel="noopener noreferrer"&gt;https://www.ftc.gov/news-events/news/press-releases/2025/09/ftc-launches-inquiry-ai-chatbots-acting-companions&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>privacy</category>
      <category>practicaltech</category>
      <category>digitalsafety</category>
    </item>
    <item>
      <title>Ransomware touched 44% of breaches last year.

The fix isn't outsmarting attackers. It's a copy of your data they can't reach.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Thu, 20 Aug 2026 07:07:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/ransomware-touched-44-of-breaches-last-year-the-fix-isnt-outsmarting-attackers-its-a-copy-7e7</link>
      <guid>https://dev.to/shortlivedage/ransomware-touched-44-of-breaches-last-year-the-fix-isnt-outsmarting-attackers-its-a-copy-7e7</guid>
      <description>&lt;div class="ltag__link--embedded"&gt;
  &lt;div class="crayons-story "&gt;
  &lt;a href="https://dev.to/shortlivedage/ransomware-hit-44-of-breaches-last-year-one-habit-beats-it-cold-1ja9" class="crayons-story__hidden-navigation-link"&gt;Ransomware Hit 44% of Breaches Last Year. One Habit Beats It Cold.&lt;/a&gt;


  &lt;div class="crayons-story__body crayons-story__body-full_post"&gt;
    &lt;div class="crayons-story__top"&gt;
      &lt;div class="crayons-story__meta"&gt;
        &lt;div class="crayons-story__author-pic"&gt;

          &lt;a href="/shortlivedage" class="crayons-avatar  crayons-avatar--l  "&gt;
            &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" alt="shortlivedage profile" class="crayons-avatar__image"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
        &lt;div&gt;
          &lt;div&gt;
            &lt;a href="/shortlivedage" class="crayons-story__secondary fw-medium m:hidden"&gt;
              Short Lived
            &lt;/a&gt;
            &lt;div class="profile-preview-card relative mb-4 s:mb-0 fw-medium hidden m:inline-block"&gt;
              
                Short Lived
                
                
              
              &lt;div id="story-author-preview-content-4439075" class="profile-preview-card__content crayons-dropdown branded-7 p-4 pt-0"&gt;
                &lt;div class="gap-4 grid"&gt;
                  &lt;div class="-mt-4"&gt;
                    &lt;a href="/shortlivedage" class="flex"&gt;
                      &lt;span class="crayons-avatar crayons-avatar--xl mr-2 shrink-0"&gt;
                        &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png" class="crayons-avatar__image" alt=""&gt;
                      &lt;/span&gt;
                      &lt;span class="crayons-link crayons-subtitle-2 mt-5"&gt;Short Lived&lt;/span&gt;
                    &lt;/a&gt;
                  &lt;/div&gt;
                  &lt;div class="print-hidden"&gt;
                    
                      Follow
                    
                  &lt;/div&gt;
                  &lt;div class="author-preview-metadata-container"&gt;&lt;/div&gt;
                &lt;/div&gt;
              &lt;/div&gt;
            &lt;/div&gt;

          &lt;/div&gt;
          &lt;a href="https://dev.to/shortlivedage/ransomware-hit-44-of-breaches-last-year-one-habit-beats-it-cold-1ja9" class="crayons-story__tertiary fs-xs"&gt;&lt;time&gt;Aug 20&lt;/time&gt;&lt;span class="time-ago-indicator-initial-placeholder"&gt;&lt;/span&gt;&lt;/a&gt;
        &lt;/div&gt;
      &lt;/div&gt;

    &lt;/div&gt;

    &lt;div class="crayons-story__indention"&gt;
      &lt;h2 class="crayons-story__title crayons-story__title-full_post"&gt;
        &lt;a href="https://dev.to/shortlivedage/ransomware-hit-44-of-breaches-last-year-one-habit-beats-it-cold-1ja9" id="article-link-4439075"&gt;
          Ransomware Hit 44% of Breaches Last Year. One Habit Beats It Cold.
        &lt;/a&gt;
      &lt;/h2&gt;
        &lt;div class="crayons-story__tags"&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/cybersecurity"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;cybersecurity&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/ransomware"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;ransomware&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/databackup"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;databackup&lt;/a&gt;
            &lt;a class="crayons-tag  crayons-tag--monochrome " href="/t/practicaltech"&gt;&lt;span class="crayons-tag__prefix"&gt;#&lt;/span&gt;practicaltech&lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="crayons-story__bottom"&gt;
        &lt;div class="crayons-story__details"&gt;
          &lt;a href="https://dev.to/shortlivedage/ransomware-hit-44-of-breaches-last-year-one-habit-beats-it-cold-1ja9" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left"&gt;
            &lt;div class="multiple_reactions_aggregate"&gt;
              &lt;span class="multiple_reactions_icons_container"&gt;
                  &lt;span class="crayons_icon_container"&gt;
                    &lt;img src="https://assets.dev.to/assets/sparkle-heart-5f9bee3767e18deb1bb725290cb151c25234768a0e9a2bd39370c382d02920cf.svg" width="18" height="18"&gt;
                  &lt;/span&gt;
              &lt;/span&gt;
              &lt;span class="aggregate_reactions_counter"&gt;1&lt;span class="hidden s:inline"&gt;&amp;nbsp;reaction&lt;/span&gt;&lt;/span&gt;
            &lt;/div&gt;
          &lt;/a&gt;
            &lt;a href="https://dev.to/shortlivedage/ransomware-hit-44-of-breaches-last-year-one-habit-beats-it-cold-1ja9#comments" class="crayons-btn crayons-btn--s crayons-btn--ghost crayons-btn--icon-left flex items-center"&gt;
              

              &lt;span class="hidden s:inline"&gt;Add&amp;nbsp;Comment&lt;/span&gt;
            &lt;/a&gt;
        &lt;/div&gt;
        &lt;div class="crayons-story__save"&gt;
          &lt;small class="crayons-story__tertiary fs-xs mr-2"&gt;
            2 min read
          &lt;/small&gt;
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
  &lt;/div&gt;
&lt;/div&gt;

&lt;/div&gt;


</description>
    </item>
  </channel>
</rss>
