<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Short Lived</title>
    <description>The latest articles on DEV Community by Short Lived (@shortlivedage).</description>
    <link>https://dev.to/shortlivedage</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061997%2F943046b8-a38c-47e6-9dbd-cb9058a607da.png</url>
      <title>DEV Community: Short Lived</title>
      <link>https://dev.to/shortlivedage</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/shortlivedage"/>
    <language>en</language>
    <item>
      <title>Your Smart TV May Be Screenshotting Your Screen Every Half Second</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sat, 12 Sep 2026 17:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/your-smart-tv-may-be-screenshotting-your-screen-every-half-second-45h4</link>
      <guid>https://dev.to/shortlivedage/your-smart-tv-may-be-screenshotting-your-screen-every-half-second-45h4</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2024 study by researchers at UC Davis, University College London, and Universidad Carlos III de Madrid audited the network traffic leaving Samsung and LG smart TVs, examining a tracking method called Automatic Content Recognition, or ACR. ACR works like Shazam for your television, capturing what’s displayed on screen or heard through the speakers at set intervals and matching it against a content database to identify what’s being watched. The researchers found ACR stayed active no matter the source: live broadcast, a streaming app, or a separate device like a game console or laptop connected through HDMI. Treating the TV as an external monitor changed nothing. Samsung TVs sent this data to company servers about once a minute. LG TVs sent it about every 15 seconds. The researchers also found that opting out meant working through several separate advertising and tracking settings across different menus, and that data requests made to the companies under privacy law came back vague, not matching the volume of data the researchers had observed being sent.&lt;/p&gt;

&lt;p&gt;Regulators have acted on the same underlying issue since. Texas Attorney General Ken Paxton sued five major manufacturers (Samsung, Sony, LG, Hisense, and TCL) in December 2025, alleging ACR captures screenshots of a user’s display every 500 milliseconds. Samsung settled in February 2026, agreeing to stop collecting ACR data without a user’s informed consent and to add clear disclosure screens. LG reached a similar settlement in May 2026. Cases against the remaining three manufacturers are still open.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why this reaches further than typical app tracking
&lt;/h2&gt;

&lt;p&gt;Most tracking people are used to lives inside an app or a website, contained to whatever service they’re using in the moment. ACR sits at the device level, below any single app, which means it isn’t limited to what you watch through the TV’s own smart features. A laptop, a gaming console, a cable box: anything displayed through the TV’s screen gets captured the same way. That’s a wider net than most people assume when they think about what their smart TV tracks.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Check your TV’s settings menu for terms like “viewing data,” “interest-based advertising,” or the brand’s own name for its ACR feature (LG calls its version “Live Plus”) and turn off each one, since a single master toggle often isn’t enough. If your TV supports it, connecting only through HDMI without ever using its built-in smart features and internet connection cuts ACR off from sending anything home, since the tracking still runs on the device but has nowhere to send what it captures. Following the settlements, check your specific TV brand’s current consent screens, since manufacturers are updating disclosure requirements as more state actions move forward.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/r6BX6IFFJWU" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Settlement terms and available opt-out settings are shifting as more state actions play out, and what applies to one brand doesn’t apply to another. Checking your specific TV model’s current privacy settings is a better bet than assuming a rule for one manufacturer holds across the board.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Anselmi, G., Vekaria, Y., D’Souza, A., Callejo, P., Mandalari, A. M., Shafiq, Z. “Watching TV with the Second-Party: A First Look at Automatic Content Recognition Tracking in Smart TVs.” Proceedings of the 2024 ACM Internet Measurement Conference. &lt;a href="https://dl.acm.org/doi/10.1145/3646547.3689013" rel="noopener noreferrer"&gt;https://dl.acm.org/doi/10.1145/3646547.3689013&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Office of the Texas Attorney General. “Attorney General Paxton Secures Major Agreement with Samsung to Ensure that Texans are Protected from Smart TVs Collecting Their Data Without Their Knowledge.” &lt;a href="https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-secures-major-agreement-samsung-ensure-texans-are-protected-smart-tvs" rel="noopener noreferrer"&gt;https://www.texasattorneygeneral.gov/news/releases/attorney-general-paxton-secures-major-agreement-samsung-ensure-texans-are-protected-smart-tvs&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>privacy</category>
      <category>resources</category>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>Researchers Tested 5 Major AI Models on 361,000 Resumes. None of Them Scored Fair.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Mon, 07 Sep 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/researchers-tested-5-major-ai-models-on-361000-resumes-none-of-them-scored-fair-2ikd</link>
      <guid>https://dev.to/shortlivedage/researchers-tested-5-major-ai-models-on-361000-resumes-none-of-them-scored-fair-2ikd</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2025 study in PNAS Nexus tested five widely used large language models: OpenAI’s GPT-3.5 Turbo and GPT-4o, Google’s Gemini 1.5 Flash, Anthropic’s Claude 3.5 Sonnet, and Meta’s Llama 3-70b, in a randomized experiment scoring about 361,000 entry-level job resumes with randomly assigned social identities attached. Across the board, the models awarded higher scores to female candidates with the same work experience, education, and skills as their male counterparts, while giving lower scores to Black male candidates with comparable qualifications to other groups. The researchers estimate this played out as hiring probability differences of about 1 to 3 percentage points for otherwise identical candidates, a pattern that held steady across different job positions and subsamples tested.&lt;/p&gt;

&lt;p&gt;The direction and size of the bias varied model to model, but each model tested showed a measurable bias in one direction or another. None of the five scored candidates in a way that stayed neutral to identity once other qualifications were held equal.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why holding qualifications equal is what makes this finding matter
&lt;/h2&gt;

&lt;p&gt;Bias studies that compare resumes that differ in the real world always leave room for a defense: maybe the more favored group’s resumes were a bit stronger in some way the comparison missed. This study closes that door by design: the same experience, education, and skills were tested across different assigned identities, with only the name and demographic signal changed. Whatever difference in scoring showed up came from the identity attached to the resume, not the substance of it. That’s the part that makes this a bias finding rather than an ambiguous pattern with another possible explanation.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why this matters even if you’re not a hiring manager
&lt;/h2&gt;

&lt;p&gt;AI resume screening is in active use across hiring pipelines, filtering thousands of applications down to the ones a human recruiter sees. If you’ve applied for a job and gotten no response with no clear reason why, an automated screening step is a plausible part of that pipeline, and this research says that step isn’t neutral. It’s a documented property of systems that function close to how they’re already used in hiring today, not a hypothetical concern about some future use of AI.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;If you’re on the hiring side, treat AI resume screening as a tool that needs active auditing for bias, not something to deploy and trust by default, and consider periodic checks using matched, identity-varied test resumes similar to how this study was designed. If you’re job hunting, this is one more reason a resume that reads as strong on paper doesn’t guarantee a fair first look, a frustrating reality but not one you can fix through how you write a resume alone.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/CkfZoHt5iEY" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;This research tested specific model versions at a specific point in time. AI companies update and retrain their models often, and a model’s behavior on this exact test could shift with newer versions. The consistent pattern across five different companies’ systems, rather than any single model’s specific numbers, is the part of this finding most likely to hold up over time.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Reference
&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;An, J., Huang, D., Lin, C., Tai, M. “Measuring gender and racial biases in large language models: Intersectional evidence from automated resume evaluation.” PNAS Nexus, 2025. &lt;a href="https://doi.org/10.1093/pnasnexus/pgaf089" rel="noopener noreferrer"&gt;https://doi.org/10.1093/pnasnexus/pgaf089&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>resources</category>
    </item>
    <item>
      <title>Researchers Found Your Password Leaking Before You Even Hit Submit</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sun, 06 Sep 2026 11:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/researchers-found-your-password-leaking-before-you-even-hit-submit-dil</link>
      <guid>https://dev.to/shortlivedage/researchers-found-your-password-leaking-before-you-even-hit-submit-dil</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2022 study crawled the top 100,000 websites, filling in email and password fields on forms and then monitoring network traffic without ever clicking submit. On 1,844 sites tested from the EU and 2,950 from the US, the typed email address was sent to a tracking, marketing, or analytics domain before the form was submitted and without any consent given. The researchers also found 41 tracking domains doing this that weren’t listed on any of the popular ad-blocker filter lists people count on for protection. Rejecting a cookie consent banner made almost no difference to whether the leak happened.&lt;/p&gt;

&lt;p&gt;The bigger finding involved passwords. On 52 websites, typed passwords were captured by third-party session replay scripts, tools built to record a visitor’s on-page behavior for customer-experience analysis. Most of these leaks traced back to a single vendor’s script that was supposed to filter password fields out of what it recorded, and didn’t. Seven of the affected sites ranked among the top 20,000 most visited websites in the world, including a major bank’s site.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why closing the tab doesn’t undo it
&lt;/h2&gt;

&lt;p&gt;Most people’s mental model of a web form is that nothing happens until you click submit, so backing out or closing the tab feels like a clean exit. Session replay and form-tracking scripts don’t work on that logic. They can read what’s typed into a field as it’s typed, apart from whether the form is ever completed. A password manager’s autofill, a half-finished signup you abandoned, a login you started and reconsidered: any of these can already be captured before you decide not to go through with it.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Treat information typed into a web form as visible the moment you type it, not only after you submit, on sites you don’t fully trust in particular. A password manager that fills fields for you rather than requiring you to type them by hand cuts down this specific exposure to some degree, since less of what’s captured is raw keystrokes. If you started filling out a form and decided against continuing, that decision doesn’t undo what you already typed, so hold off on entering real information into a field until you’re ready to submit it.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/aQu2oaNxuqU" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;The vendor most responsible for the password-leak findings fixed the issue after the researchers reported it, and browser vendors and privacy tools have added detections for some of this behavior since the study was published. The specific sites named in this research may no longer be affected. The underlying technique, and the fact that consent banners don’t stop it in any reliable way, remains a current risk across the web.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Reference
&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;Senol, A., Acar, G., Humbert, M., Zuiderveen Borgesius, F. “Leaky Forms: A Study of Email and Password Exfiltration Before Form Submission.” Proceedings of the 31st USENIX Security Symposium, 2022. &lt;a href="https://www.usenix.org/system/files/sec22fall_senol.pdf" rel="noopener noreferrer"&gt;https://www.usenix.org/system/files/sec22fall_senol.pdf&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>privacy</category>
      <category>webtracking</category>
      <category>resources</category>
    </item>
    <item>
      <title>Older Adults Told Researchers What Matters Most After They Die, and It Wasn't Instagram</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sat, 05 Sep 2026 11:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/older-adults-told-researchers-what-matters-most-after-they-die-and-it-wasnt-instagram-40p</link>
      <guid>https://dev.to/shortlivedage/older-adults-told-researchers-what-matters-most-after-they-die-and-it-wasnt-instagram-40p</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A study from Carnegie Mellon University’s CyLab, presented at the 2026 ACM CHI Conference, interviewed people over 60 about how they think about their online accounts after death. The clearest finding: participants prioritized financial account access for their heirs over concerns about their social media presence or online identity, by a wide margin. Bank accounts, investment portals, bill-pay services: these were treated as urgent. Photos and social content were often seen as already handled, since many participants had shared or backed up what mattered to family already.&lt;/p&gt;

&lt;p&gt;The researchers also found something less expected. Many participants showed little concern about their own postmortem privacy, a contrast with how much digital legacy research and design tends to assume people want privacy protected after death. And despite general awareness that planning matters, the actual tools built for this (Google’s Inactive Account Manager, Apple’s Legacy Contact, similar features from other platforms) were unfamiliar to most participants, who leaned on informal methods instead, most often a handwritten list of passwords kept somewhere in the house.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why the built-in tools aren’t the default solution people assume
&lt;/h2&gt;

&lt;p&gt;The gap here is a mismatch between what people worry about and what the available tools were built to solve, not a lack of concern. Legacy contact features are built around photos, messages, and social profiles, the exact category participants treated as lower priority. Financial account access, the thing people cared about most, isn’t something these built-in features are designed to hand over in a clean way. Even Apple’s own Legacy Contact system leaves out access to Keychain, meaning stored passwords and payment information stay out of reach even for a designated contact, and access through the feature runs out after three years, when the account gets deleted for good.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;If you’re the one setting this up, treat financial account access as the priority, not an afterthought handled by whatever a social platform’s tool happens to cover. A password manager with an emergency access feature, or a documented, secured list reviewed with a trusted person while you’re alive, does more real work here than any single platform’s legacy tool. If you do use built-in options like Apple’s Legacy Contact or Google’s Inactive Account Manager, set them up with a clear sense of their real limits: they’re useful for photos and messages, not a full financial safety net.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/Ep4oVxvgo10" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Platform-specific tools and their limits change over time as companies update their policies. Whatever rule applies to a given platform’s legacy feature today is worth checking against the source rather than assuming it still matches older information.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Tang, J., Wu, X., Bauer, L., Christin, N., Cranor, L. F. “Passing Down Passwords: How Older Adults Approach Postmortem Account Access and Digital Estate Planning.” Proceedings of the 2026 CHI Conference on Human Factors in Computing Systems, summarized by Carnegie Mellon University CyLab. &lt;a href="https://www.cylab.cmu.edu/news/2026/04/15-digital-estate-planning.html" rel="noopener noreferrer"&gt;https://www.cylab.cmu.edu/news/2026/04/15-digital-estate-planning.html&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Apple. “Request access to an Apple Account as a Legacy Contact.” &lt;a href="https://support.apple.com/en-lamr/102678" rel="noopener noreferrer"&gt;https://support.apple.com/en-lamr/102678&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>digitalestateplanning</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>Researchers Tested 40 Routers. They Found 30 Ways In, All Left On by Default.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Thu, 03 Sep 2026 12:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/researchers-tested-40-routers-they-found-30-ways-in-all-left-on-by-default-2dcf</link>
      <guid>https://dev.to/shortlivedage/researchers-tested-40-routers-they-found-30-ways-in-all-left-on-by-default-2dcf</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2024 study built a detailed threat model and tested 40 commercial home routers across 14 brands, examining 81 default settings and behaviors on each one. The researchers reported 30 exploitable vulnerabilities to the vendors. Among the specific issues found: IPv6 devices left exposed due to missing firewall protection, weak Wi-Fi security protocols still active by default, some routers shipping with open Wi-Fi networks or trivial admin passwords built for “plug and play” setup, and firmware update traffic sent without encryption. The researchers also found WPS PIN support enabled on some routers by default, in certain cases paired with a PIN simple enough to guess.&lt;/p&gt;

&lt;p&gt;A separate 2025 survey of 392 router owners across multiple countries found the human side of this problem runs equally deep. An estimated 91% of participants’ routers were still running default settings, and while most people did change their default password at setup, a real share admitted to coping strategies, like writing the password down somewhere accessible, rather than managing it well.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why “default” doesn’t mean “safe”
&lt;/h2&gt;

&lt;p&gt;A router shipped for easy setup is built for one thing: getting a new user online in a few minutes without a support call. Security and quick setup pull in opposite directions almost by design, since most of the meaningful security choices (a unique admin password, disabling unused remote features, updating firmware) need a step beyond plugging the device in and following the on-screen prompts. Manufacturers know this, which is part of why the survey researchers argue the responsibility belongs with safer factory defaults, not with user behavior alone. But until that shift happens across the industry, the gap between what ships and what’s safe sits with whoever sets the router up.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Change the router’s admin password from its factory default, not the Wi-Fi password alone, since the two are often confused and the admin panel controls far more. Check whether WPS is enabled in your settings and turn it off if you don’t use it, since it’s a known weak point. Update your router’s firmware through its admin interface rather than assuming it updates on its own, since many models don’t. If your router is several years old and no longer receives firmware updates from the manufacturer, that’s a concrete reason to replace it, not a vague upgrade urge.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/5J7-630eglc" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;This research tested specific router models available at the time of the study. Individual vendors patch specific flaws once notified, so a router named in this research may have since received a fix. The broader pattern (that factory defaults across the industry lean toward convenience over security) holds regardless of any single model’s current patch status.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Ye, J., de Carné de Carnavalet, X., Zhao, L., Zhang, M., Wu, L., Zhang, W. “Exposed by Default: A Security Analysis of Home Router Default Settings.” Proceedings of the 19th ACM Asia Conference on Computer and Communications Security, 2024. &lt;a href="https://dl.acm.org/doi/pdf/10.1145/3634737.3637671" rel="noopener noreferrer"&gt;https://dl.acm.org/doi/pdf/10.1145/3634737.3637671&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Ye, J., et al. “Understanding Home Router Configuration Habits &amp;amp; Attitudes.” Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems. &lt;a href="https://doi.org/10.1145/3706598.3714231" rel="noopener noreferrer"&gt;https://doi.org/10.1145/3706598.3714231&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>homenetwork</category>
      <category>practicaltech</category>
      <category>routersecurity</category>
    </item>
    <item>
      <title>A Tiny Invisible Image Is Leaking Health Data From Hospital Websites</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Wed, 02 Sep 2026 12:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/a-tiny-invisible-image-is-leaking-health-data-from-hospital-websites-mh3</link>
      <guid>https://dev.to/shortlivedage/a-tiny-invisible-image-is-leaking-health-data-from-hospital-websites-mh3</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2025 study in &lt;em&gt;PNAS Nexus&lt;/em&gt; analyzed 12 years of archived website data from 1,201 large US hospitals, tracking the use of tracking pixels (invisible embedded snippets that send visitor data to outside companies) and comparing pixel use against reported data breaches at each hospital. Third-party pixel use showed up on 66% of hospital websites sampled. Hospitals using third-party pixels had a data breach probability 1.4 percentage points higher than hospitals that didn’t, a 46% relative increase over the 3% baseline breach rate in the sample. First-party pixels, which keep data inside the hospital’s own systems rather than sending it to an outside vendor, showed no connection to breach risk. The difference sat in data leaving the building.&lt;/p&gt;

&lt;p&gt;The paper points to two real cases behind these numbers. Community Health Network disclosed a breach affecting about 1.5 million patients in 2023, traced to tracking pixels sending data to third parties. Advocate Aurora Health reported a breach covering 3 million patients in 2022, tied to the same mechanism: pixels sending information to Meta.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why the same small piece of code shows up everywhere
&lt;/h2&gt;

&lt;p&gt;A tracking pixel works the same way whether it’s embedded in a marketing email you opened this morning or sitting on a hospital appointment page: a tiny, invisible image that loads from a server the moment you view the content, confirming you opened it and often what page you were on when you did. In an email, that mostly confirms you’re a reachable inbox. On a hospital website, the same mechanism can transmit far more sensitive signals: an IP address tied to a specific appointment request, browsing patterns tied to medical conditions people were researching. The technology doesn’t distinguish. The stakes attached to what it’s tracking do.&lt;/p&gt;

&lt;p&gt;Regulators have taken notice in healthcare. US Health and Human Services issued guidance in December 2022 stating that IP addresses linked to hospital webpages could count as protected health information, and HHS and the FTC sent warning letters to 130 healthcare providers in 2023 about tracking pixel risk.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;You can’t audit which hospital or health system uses third-party pixels on your own, but you can limit what you expose regardless of the site. Browser extensions that block third-party trackers cut off a meaningful share of this exposure without any effort on your part after setup. For anything sensitive (a specific diagnosis, a mental health inquiry), avoid researching it through a search bar or a portal you’re logged into on a device or browser where you’d rather that activity not be linked back to your identity.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/CbLKe-oKwQ4" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;This research establishes a strong statistical association between third-party pixel use and breach risk, with the authors running several checks to rule out reverse causation. It doesn’t prove each pixel-related exposure results in a reportable breach, and hospitals vary in which vendors they use and how those vendors handle the data they receive.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Reference
&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;Atasoy, H., McDonough, R., Zhang, G. M. “Beyond the click: Pixel tracking technologies and patient data security in hospitals.” PNAS Nexus, 2025. &lt;a href="https://doi.org/10.1093/pnasnexus/pgaf360" rel="noopener noreferrer"&gt;https://doi.org/10.1093/pnasnexus/pgaf360&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>privacy</category>
      <category>trackingpixels</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>One Phone Gets Hacked. Everyone in the Family Circle Is Exposed.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Mon, 31 Aug 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/one-phone-gets-hacked-everyone-in-the-family-circle-is-exposed-3p0a</link>
      <guid>https://dev.to/shortlivedage/one-phone-gets-hacked-everyone-in-the-family-circle-is-exposed-3p0a</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A forensic analysis of Life360, one of the most used family location tracking apps, found that compromising a single device gives access to the personal data of each member in that person’s Circle, not just the one phone. Researchers recovered detailed location histories, driving data, and other sensitive artifacts through standard forensic tools applied to only one device, exposing information about people who never had their own phone touched. The same analysis found the app doesn’t require entering a child’s age during account setup, a gap that sidesteps the added protections apps are supposed to apply to younger users.&lt;/p&gt;

&lt;p&gt;A separate, far larger study, the largest of its kind on this topic, surveyed 3,000 people and found half of them use continuous location-sharing apps. Among 896 who completed detailed surveys about their experience, a share described real discomfort with how the apps were used. Follow-up interviews with those who reported the most negative experiences found a pattern that builds over time. It starts with a boundary being crossed, continues as ongoing unease, and can end with someone changing their behavior and choices because they know they’re being watched.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why a “trusted circle” doesn’t function like private data
&lt;/h2&gt;

&lt;p&gt;The appeal of these apps rests on the idea that visibility stays contained within a small, trusted group: family, close friends, people you’d already tell your location to anyway. The forensic findings complicate that framing in two ways. On the technical side, trust in the people you’ve added doesn’t protect you from a security failure on any single device in that group, since compromising one phone was enough to expose the whole Circle’s data in the research. On the social side, “trusted” doesn’t mean “comfortable,” and the discomfort study found that even within family relationships, continuous visibility can shift a dynamic in ways neither party expected going in.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;If your family uses a location-sharing app, check each phone’s security on its own, since the weakest device in the group becomes the weak link for everyone in it. Use a strong passcode and enable any available two-factor authentication on the account itself, not just the device. And treat the emotional side with the same weight as the technical side: the discomfort research suggests it’s worth having a direct conversation about what the sharing is for and revisiting it now and then, rather than setting it up once during a moment of worry and leaving it running for years without either side reconsidering it.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/I1M5CzAwKN8" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;This research focused on Life360, the most used app in this category. Other family tracking apps may handle security and data in a different way, so the specific technical findings shouldn’t be assumed to apply the same way across each app in this space, even though the underlying single-point-of-failure risk is a structural concern worth checking regardless of which app you use.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Aagaard, P., Dinyarian, B., Abduljabbar, O., Choo, K.-K. R. “Family locating sharing app forensics: Life360 as a case study.” Forensic Science International: Digital Investigation, 2023. &lt;a href="https://cspecc.utsa.edu/publications/files/Refereed_Papers/2022-Choo-Family%20locating%20sharing%20app%20forensics-Life360%20as%20a%20case%20study.pdf" rel="noopener noreferrer"&gt;https://cspecc.utsa.edu/publications/files/Refereed_Papers/2022-Choo-Family%20locating%20sharing%20app%20forensics-Life360%20as%20a%20case%20study.pdf&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Childs, K., Gibson, C., Crowder, A., Warren, K., Stillman, C., Redmiles, E. M., Jain, E., Traynor, P., Butler, K. R. B. “I Had Sort of a Sense that I Was Always Being Watched...Since I Was: Examining Interpersonal Discomfort From Continuous Location-Sharing Applications.” Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security. &lt;a href="https://par.nsf.gov/servlets/purl/10561479" rel="noopener noreferrer"&gt;https://par.nsf.gov/servlets/purl/10561479&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>privacy</category>
      <category>familysafety</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>Researchers Tested 125 Car Apps. 70% Had a Way In.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sun, 30 Aug 2026 13:30:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/researchers-tested-125-car-apps-70-had-a-way-in-518i</link>
      <guid>https://dev.to/shortlivedage/researchers-tested-125-car-apps-70-had-a-way-in-518i</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;Researchers at the University of Kansas ran a full security analysis on 125 Android automotive companion apps pulled from the Google Play Store, the kind of app that connects to your car through an OBD-II diagnostic dongle to show fuel level, engine data, or remote diagnostics. Combining static code analysis, live runtime testing, and network traffic monitoring, they found 70% of the apps carried vulnerabilities that could lead to private information leakage, property theft, or direct risk while driving.&lt;/p&gt;

&lt;p&gt;Eighteen of the apps could connect to an open OBD dongle with no authentication required at all, then accept arbitrary commands sent to the vehicle’s internal network without checking them first. The researchers demonstrated this against real vehicles, not just in simulation.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why the OBD port makes this different from a typical app risk
&lt;/h2&gt;

&lt;p&gt;The OBD-II port is a direct line into the vehicle’s internal control network, the same system responsible for things like engine timing and diagnostic reporting, not a side channel these apps happen to use. An app that verifies its connection badly at that point risks more than your data: it risks a pathway into systems that affect how the car runs. Most people plugging in a diagnostic dongle are thinking about fuel economy or a check-engine light, not whether the app managing that connection checks commands before passing them through.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;If you use an OBD dongle and companion app, stick to ones from the vehicle manufacturer or a small number of well-established, maintained brands rather than a low-cost or unfamiliar option from the app store, since maintained apps are far more likely to have had security issues identified and patched. Unplug the OBD dongle when you’re not using its features instead of leaving it connected all the time, since an idle, always-connected dongle is the exact setup this research tested. And check what permissions the companion app requests during setup: an app asking for far more access than fuel level or diagnostics requires is worth a second look before you grant it.&lt;/p&gt;


&lt;div&gt;
    &lt;iframe src="https://www.youtube.com/embed/q4ZpjwtfoSM" width="315" height="560"&gt;
    &lt;/iframe&gt;
  &lt;/div&gt;


&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;This research tested apps available through the Google Play Store at the time of the study. App security postures change as developers patch known issues, so a specific app flagged in this research may have since been fixed. The broader pattern (that this app category carries demonstrated risk as a whole) holds regardless of any one app’s current state.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  Reference
&lt;/h2&gt;

&lt;p&gt;&lt;em&gt;Mallojula, P., Li, F., Du, X., Luo, B. “Companion Apps or Backdoors? On the Security of Automotive Companion Apps.” University of Kansas, ITTC. &lt;a href="https://www.ittc.ku.edu/%7Ebluo/pubs/mallojula2024esorics.pdf" rel="noopener noreferrer"&gt;https://www.ittc.ku.edu/~bluo/pubs/mallojula2024esorics.pdf&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>carprivacy</category>
      <category>security</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>Your Password Manager Might Be Filling In Fields You Can't Even See</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Sat, 29 Aug 2026 13:10:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/your-password-manager-might-be-filling-in-fields-you-cant-even-see-4o2p</link>
      <guid>https://dev.to/shortlivedage/your-password-manager-might-be-filling-in-fields-you-cant-even-see-4o2p</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2024 study tested 30 popular password managers against web forms containing hidden fields (invisible to a normal user through techniques like CSS positioning or zero-height containers), the same techniques legitimate sites sometimes use for layout, but which can also be used to harvest data without anyone noticing. Every password manager tested filled data into at least one hidden field across the scenarios tried, with an overall fill rate of 58.7% across more than 1,000 test cases. Login forms were the most exposed, with hidden fields getting filled 65.7% of the time. Password managers built into a browser turned out to be about four times more likely to fill hidden fields than separately installed ones, and several browser-built-in managers filled passwords into hidden fields no matter which concealment technique was used.&lt;/p&gt;

&lt;p&gt;A separate 2023 study found something related from a different angle: passwords sitting in plain, unencrypted text within a webpage’s own source code, readable by anything with basic page access, on a meaningful share of sites tested, including high-traffic ones.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why convenience and safety pull against each other here
&lt;/h2&gt;

&lt;p&gt;Autofill exists to reduce friction: one click and a form is done. That same design goal is what creates the exposure. A password manager has to guess which fields deserve which saved data, and a hidden field designed to capture information exploits exactly that guesswork. In more than a third of the scenarios tested, the fill happened with what researchers judged too little user interaction, meaning a person had reasonable grounds to be unaware it happened at all.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Turn off automatic, one-click autofill where your password manager allows it, and switch to a mode that requires you to select which field gets filled rather than filling every recognized field on a page on its own. This adds a small amount of friction back in exchange for a meaningful reduction in this specific exposure. It’s also worth being more cautious on unfamiliar or unofficial-looking sites, since a hidden field built to harvest data is far more likely to show up on a page built to exploit autofill than on a site you already trust and use often.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;This research tested password managers under controlled conditions built to surface the vulnerability, not real-world attack rates. It shows the capability exists across most major password managers, not that any specific site is exploiting it against you right now.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Fu, Y., Wang, D. “Leaky Autofill: An Empirical Study on the Privacy Threat of Password Managers’ Autofill Functionality.” Proceedings of the 40th Annual Computer Security Applications Conference, 2024. &lt;a href="https://www.researchgate.net/publication/385420522" rel="noopener noreferrer"&gt;https://www.researchgate.net/publication/385420522&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Nayak, A., et al. “Exposing and Addressing Security Vulnerabilities in Browser Text Input Fields.” ArXiv, 2023. &lt;a href="https://arxiv.org/abs/2308.16321v1" rel="noopener noreferrer"&gt;https://arxiv.org/abs/2308.16321v1&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>privacy</category>
      <category>passwordmanagers</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>Half of Smart Speaker Owners Don't Know Their Recordings Are Saved Forever</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Fri, 28 Aug 2026 13:10:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/half-of-smart-speaker-owners-dont-know-their-recordings-are-saved-forever-11bp</link>
      <guid>https://dev.to/shortlivedage/half-of-smart-speaker-owners-dont-know-their-recordings-are-saved-forever-11bp</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A study from UC Berkeley and ICSI surveyed 116 owners of Amazon and Google smart speakers, grounding the questions in each participant’s own saved recordings rather than asking about the topic in the abstract. Around 56 percent didn’t know their recordings were stored for good and could be reviewed later. A quarter had ever gone back to review their own interaction history, and few had ever deleted anything. The finding was notable enough to win a best paper award at a major privacy research conference.&lt;/p&gt;

&lt;p&gt;People weren’t equally relaxed about every kind of recording. Participants didn’t see their own voice recordings as especially sensitive as a rule, but they were far more protective of recordings involving other people, children and guests in particular, and opposed to any of that data being used by third parties or for advertising. More than 72 percent found it acceptable for a computer to review recordings, while human review of the same recordings felt far less acceptable to most participants.&lt;/p&gt;

&lt;p&gt;A separate 2025 survey of 1,103 German smart speaker owners found the underlying problem hasn’t gone away. Existing privacy settings still don’t cover what users want, and the study found a consistent, cross-brand desire for more transparency and more control over what gets collected in the first place.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why “always listening” isn’t quite the right way to think about the risk
&lt;/h2&gt;

&lt;p&gt;The real privacy gap here is default retention paired with low visibility, not secret eavesdropping. These devices are built to keep what they record unless you go find it and delete it, and most owners never do, because reviewing recordings takes effort most people never think to make, not out of indifference. Following the original 2019 study, both Google and Amazon added auto-deletion options: Google’s set to clear recordings after 3 or 18 months, Amazon’s after a rolling window, evidence that the research pushed real product changes.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Check your smart speaker’s privacy settings rather than assuming a sensible default is in place. Both major platforms let you set recordings to delete on a schedule, and it takes a couple of minutes to turn on. Given how much more protective people are of recordings involving guests and children, it’s worth being deliberate about where these devices sit in your home: kitchens and living rooms carry more incidental exposure than a bedroom or office.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Manufacturer defaults and policies shift over time, and what’s true about retention settings today may change. Checking your specific device’s current settings is more reliable than any general description of how these systems work.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Malkin, N., Deatrick, J., Tong, A., Wijesekera, P., Egelman, S., Wagner, D. “Privacy Attitudes of Smart Speaker Users.” Proceedings on Privacy Enhancing Technologies, 2019. &lt;a href="https://petsymposium.org/popets/2019/popets-2019-0068.php" rel="noopener noreferrer"&gt;https://petsymposium.org/popets/2019/popets-2019-0068.php&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Hernández Acosta, L., Reinhardt, D. “Alexa, how do you protect my privacy? A quantitative study of user preferences and requirements about smart speaker privacy settings.” Computers &amp;amp; Security, 2025. &lt;a href="https://www.sciencedirect.com/science/article/pii/S0167404824006084" rel="noopener noreferrer"&gt;https://www.sciencedirect.com/science/article/pii/S0167404824006084&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>smarthome</category>
      <category>techtalks</category>
      <category>practicaltech</category>
    </item>
    <item>
      <title>The FBI Warned About This Threat for a Decade. It's Never Happened.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Thu, 27 Aug 2026 13:05:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/the-fbi-warned-about-this-threat-for-a-decade-its-never-happened-5ban</link>
      <guid>https://dev.to/shortlivedage/the-fbi-warned-about-this-threat-for-a-decade-its-never-happened-5ban</guid>
      <description>&lt;h2&gt;
  
  
  What the warnings say, and what the record shows
&lt;/h2&gt;

&lt;p&gt;The FBI, the FCC, and the TSA have all issued public warnings about juice jacking, a theoretical attack where a compromised public USB charging port or cable steals data or installs malware while your phone charges. The term dates back to 2011, when security researchers first demonstrated the concept at the DEF CON hacker conference. Since then, researchers have built working proof-of-concept attacks from time to time, including a 2013 Georgia Tech demonstration that installed malware on an iPhone within one minute.&lt;/p&gt;

&lt;p&gt;The record doesn’t match the warnings. An Ars Technica investigation found no documented cases of juice jacking on modern iOS or Android devices, and Apple told the outlet it was unaware of any real-world attacks. A separate review of police records, court cases, and cybersecurity incident reports turned up zero confirmed juice jacking cases outside of controlled research demonstrations. The FCC itself has said it hasn’t found any real-world attacks since it started tracking the issue in 2019.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why a real capability produced no real victims
&lt;/h2&gt;

&lt;p&gt;The gap here isn’t that juice jacking is fake. Researchers have proven the technique works in a lab. The gap is between technical possibility and practical exploitation. A malicious charging station would need to sit undetected in a public location, and if it started compromising phones at scale, security researchers would likely spot it fast, given how much attention the concept already gets. Apple and Google have also added protections over the years: modern phones now require you to confirm data access when a USB connection is made, a step that blocks the simplest version of this attack outright.&lt;/p&gt;

&lt;p&gt;That said, the arms race hasn’t stopped. A 2025 study on a technique called ChoiceJacking demonstrated a way around those confirmation prompts, restoring at least part of the original threat on unpatched devices. Researchers keep finding new angles. None of those angles have yet produced a documented victim.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;You don’t need to treat every airport charging station like a trap, but the fix costs little enough that there’s not much reason to skip it. Carry your own charging cable and a wall adapter, or a small USB data blocker that only allows power through, and plug into an outlet instead of a public USB port when you can. Keeping your phone’s operating system updated matters too, since that’s where the newer protections against techniques like ChoiceJacking get patched in.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Absence of documented cases doesn’t guarantee absence of risk going forward, given researchers keep finding new bypass techniques. But it’s a real reason to worry less than a decade of headlines might suggest, and to treat this as a low-cost precaution rather than an emergency.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Communications of the ACM, “Juice Jacking.” &lt;a href="https://cacm.acm.org/news/juice-jacking/" rel="noopener noreferrer"&gt;https://cacm.acm.org/news/juice-jacking/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Malwarebytes, “Juice jacking warnings are back, with a new twist.” &lt;a href="https://www.malwarebytes.com/blog/news/2025/06/juice-jacking-warnings-are-back-with-a-new-twist" rel="noopener noreferrer"&gt;https://www.malwarebytes.com/blog/news/2025/06/juice-jacking-warnings-are-back-with-a-new-twist&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Wikipedia, "Juice jacking." &lt;a href="https://en.wikipedia.org/wiki/Juice_jacking" rel="noopener noreferrer"&gt;https://en.wikipedia.org/wiki/Juice_jacking&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;PwnDefend, "A threat to sanity, Cyber Myth: Juice Jacking." &lt;a href="https://www.pwndefend.com/2025/10/16/a-threat-to-sanity-cyber-myth-juice-jacking/" rel="noopener noreferrer"&gt;https://www.pwndefend.com/2025/10/16/a-threat-to-sanity-cyber-myth-juice-jacking/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;ESET, "Juice Jacking: Real Threat or Cybersecurity Myth?" &lt;a href="https://www.eset.com/blog/en/home-topics/privacy-and-identity-protection/juice-jacking-real-or-myth/" rel="noopener noreferrer"&gt;https://www.eset.com/blog/en/home-topics/privacy-and-identity-protection/juice-jacking-real-or-myth/&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>techtalks</category>
      <category>cybersecurity</category>
      <category>practicaltech</category>
      <category>travelsafety</category>
    </item>
    <item>
      <title>The More You Share Online, the Safer It Starts to Feel. That's the Problem.</title>
      <dc:creator>Short Lived</dc:creator>
      <pubDate>Wed, 26 Aug 2026 13:00:00 +0000</pubDate>
      <link>https://dev.to/shortlivedage/the-more-you-share-online-the-safer-it-starts-to-feel-thats-the-problem-6bl</link>
      <guid>https://dev.to/shortlivedage/the-more-you-share-online-the-safer-it-starts-to-feel-thats-the-problem-6bl</guid>
      <description>&lt;h2&gt;
  
  
  What the research found
&lt;/h2&gt;

&lt;p&gt;A 2024 study combining a qualitative interview phase with a survey of 1,597 people found that the more someone engages in self-disclosure on social media, the less risky they perceive their own online activity to be. Higher engagement also came with a stronger sense of control over personal information, which itself predicted lower risk perception. The direction of that loop matters. Sharing itself appears to lower how risky the activity feels afterward, not just the other way around, creating a cycle where each post makes the next one feel a little safer than it is.&lt;/p&gt;

&lt;p&gt;A separate 2024 survey of 192 students focused on a narrower, more concrete problem: incidental data, private information that shows up in a post by accident rather than on purpose, a house number visible in a photo background, a reflection in a window, a recognizable landmark that reveals a location no one meant to share. Up to 21.88 percent of participants said they’d publish a posting containing this kind of accidental detail, and two-thirds of them recognized it as privacy-compromising even as they said they’d still post it. A related study by the same lead researcher showed how little effort it takes to exploit this: two hours of manual searching was enough to piece together private personal information a person never meant to make public.&lt;/p&gt;




&lt;h2&gt;
  
  
  Why awareness alone doesn’t fix this
&lt;/h2&gt;

&lt;p&gt;Both findings point to the same underlying gap. Knowing sharing carries risk and feeling that risk in the moment are different things, and the feeling is what drives behavior. The first study shows why the feeling keeps shrinking over time: each post that doesn’t result in visible harm reinforces the sense that sharing is safe, regardless of what’s happening with that data behind the scenes. The second study shows the risk isn’t limited to what you choose to share on purpose. A caption you write with care can still sit next to a photo that gives away far more than you intended.&lt;/p&gt;




&lt;h2&gt;
  
  
  The practical takeaway
&lt;/h2&gt;

&lt;p&gt;Before posting a photo, scan the background for things you wouldn’t say out loud: an address, a license plate, a work badge, a school uniform, a recognizable location tied to your routine. This is a different check than deciding whether to share the main content of a post. It’s a second pass looking for what’s riding along with it unnoticed. Given how fast incidental details can be pieced together by anyone motivated to look, treating background details with the same scrutiny as the caption itself is a reasonable habit, not an excessive one.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Neither study suggests people are careless by nature. The pattern described here is a normal psychological response to repeated low-harm experiences, not a personal failing. That’s part of what makes it worth naming instead of relying on people to notice it in themselves.&lt;/em&gt;&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  References
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Fejes-Vékássy, L., Ujhelyi, A., Lantos, N. A. “I don’t care, I share! The importance of self-disclosure overwrites the risks of sharing on Social Media.” Current Psychology, 2024. &lt;a href="https://doi.org/10.1007/s12144-024-06496-2" rel="noopener noreferrer"&gt;https://doi.org/10.1007/s12144-024-06496-2&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;em&gt;Kutschera, S., et al. “Incidental Data: A Survey towards Awareness on Privacy-Compromising Data Incidentally Shared on Social Media.” Journal of Cybersecurity and Privacy, 2024. &lt;a href="https://doi.org/10.3390/jcp4010006" rel="noopener noreferrer"&gt;https://doi.org/10.3390/jcp4010006&lt;/a&gt;&lt;/em&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;a href="https://ko-fi.com/shortlivedage" rel="noopener noreferrer"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F0x8a0yrz5e9avn6l2q5b.png" alt="Support Me on Ko-fi" width="800" height="162"&gt;&lt;/a&gt;&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>practicaltech</category>
      <category>socialmedia</category>
      <category>techtalks</category>
    </item>
  </channel>
</rss>
