Featured Article : CAPTCHAs To Be Replaced With Privacy-First Web Verification

Cloudflare has joined forces with Mozilla, Google, Microsoft and Shopify to develop a new internet protocol designed to help websites distinguish genuine visitors from malicious bots without relying on CAPTCHAs, forced logins or invasive tracking, in what could become one of the biggest changes to how people prove their identity online in decades.

What Is PACT?

The initiative centres on a new technology called Private Access Control Tokens (PACT), which aims to solve a problem that is becoming increasingly urgent as artificial intelligence changes the nature of internet traffic.

According to Cloudflare, automated systems now generate more web traffic than humans. Cloudflare Radar data shows bots account for around 58 per cent of HTTP requests worldwide, driven in part by the rapid growth of AI assistants and autonomous software agents browsing the web on users’ behalf.

That creates a challenge for website operators. They need to distinguish legitimate visitors from malicious bots without creating frustrating barriers for genuine users or collecting excessive amounts of personal data.

How The System Works

Rather than asking users to complete CAPTCHAs, log in repeatedly or allowing websites to build detailed browser fingerprints, PACT introduces a different approach.

Trusted services that already have a genuine relationship with a user can issue an anonymous cryptographic token to that person’s browser. When the user later visits another participating website, the browser can present the token as evidence that a real person, or an authorised AI agent acting for one, is behind the request.

Importantly, the token is designed to prove legitimacy without revealing who the person is or allowing websites to reconstruct their browsing history.

Cloudflare says PACT allows websites to “verify that a visitor is a human or authorized agent while preserving privacy”, removing much of the friction associated with existing verification methods.

Why Existing Methods Are Becoming Less Effective

For years, websites have relied on CAPTCHAs, browser fingerprinting, account log-ins and behavioural analysis to defend themselves against automated abuse.

Those techniques are becoming increasingly problematic. CAPTCHAs interrupt the browsing experience, browser fingerprinting has attracted growing regulatory scrutiny because of its privacy implications, while AI systems are becoming increasingly capable of solving many traditional bot detection tests.

Cloudflare CTO Dane Knecht believes the internet is reaching a turning point. As he explained: “The way we interact with the Internet is facing a fundamental shift… As AI-powered traffic becomes widespread, existing tools to support its use are too generic and coarse.”

Rather than treating all automated traffic as malicious, PACT is intended to distinguish authorised AI agents from abusive bots.

Why The Browser Makers Are Involved

One of the most significant aspects of the announcement is the unusually broad industry collaboration behind it.

Mozilla, Google and Microsoft collectively develop the browsers used by most internet users, while Shopify brings the perspective of millions of online retailers, where every unnecessary security check can reduce sales.

Shopify Distinguished Engineer Ilya Grigorik said: “Every extra challenge, delay, or false positive can turn a purchase into an abandoned cart.” He added that PACT could help businesses distinguish legitimate shoppers and authorised AI agents “while preserving buyer privacy.”

Mozilla also sees wider benefits. Firefox CTO Bobby Holley warned that an “avalanche of automated traffic” is pushing websites towards increasingly intrusive measures simply to determine whether visitors are genuine.

What Happens Next?

It should be noted here that PACT is still at quite an early stage. The partners intend to submit the protocol for formal internet standardisation before browsers and websites begin adopting it more widely.

The technology also builds on earlier Privacy Pass standards already used in some online services, extending those ideas to support a much broader range of browsers and AI-driven web traffic.

If widely adopted, PACT could eventually become a common feature of everyday web browsing, allowing websites to authenticate visitors with far less friction while giving users greater control over their privacy.

What Does This Mean For Your Business?

For organisations, the announcement reflects a much bigger change than simply replacing CAPTCHAs. The internet is rapidly moving from a world dominated by human visitors to one where AI agents increasingly browse, search, purchase and interact with online services on behalf of people.

Businesses will therefore need new ways to identify legitimate traffic without damaging the customer experience or creating additional privacy risks. PACT represents one possible answer by allowing trust to be established without relying on invasive tracking or repeated identity checks.

Although widespread deployment is still quite some way off, the involvement of Cloudflare, Google, Microsoft, Mozilla and Shopify suggests this is more than simply another technical proposal. If the standard gains broad industry support, it could reshape how websites balance cyber security, privacy and usability as AI becomes a routine part of everyday internet activity.

Security Stop-Press : Samsung and WhatsApp Strengthen Front-Line Privacy Controls

Samsung and WhatsApp are rolling out new security features aimed at reducing everyday privacy risks, including shoulder surfing in public places and cyber attacks targeting user accounts.

Samsung said it will introduce a new privacy layer for Galaxy devices that selectively hides sensitive on-screen content from side angles, while remaining visible to the user. The feature, developed over more than five years, can protect specific areas such as message notifications or passcode entry fields and builds on the company’s Knox security platform.

WhatsApp has also launched a new “Strict Account Settings” mode that groups multiple protections behind a single switch. When enabled, it blocks media and messages from unknown senders, disables link previews, restricts who can add users to groups, and turns on two-step verification and security alerts by default.

For businesses, the updates highlight the importance of reducing simple exposure risks by limiting what can be seen in public, tightening controls on unknown contacts, and enforcing strong default security settings across devices and messaging platforms.

Featured Article : Government Plans Major Expansion Of Facial Recognition

The government has set out plans to expand the use of facial recognition and other biometrics across UK policing, describing it as the biggest breakthrough for catching criminals since DNA matching.

A National Strategy For Biometrics

The Home Office has launched a ten week consultation to establish a new legal framework covering all police use of facial recognition and biometric technologies. This would replace the current mix of case law and guidance with a single, structured system that applies consistently across forces.

The plan includes creating a dedicated regulator overseeing facial recognition, fingerprints and emerging biometric tools. The Home Office says a single body would provide clarity and help forces apply safeguards more confidently. It also proposes a national facial matching service, allowing officers to run searches against millions of custody images through one central system.

Breakthrough

Launching the consultation, Crime and Policing Minister Sarah Jones said, “Facial recognition is the biggest breakthrough for catching criminals since DNA matching,” adding, “We will expand its use so that forces can put more criminals behind bars and tackle crime in their communities.” Her view reflects the government’s belief that existing deployments have already demonstrated clear operational value, particularly in identifying violent offenders.

Why Now?

The push for expansion comes as police forces face increasing pressure to track offenders across regions and to manage high volumes of video supplied by retailers, businesses and members of the public. Also, recent cases of prisoners being released in error, or disappearing before arrest, have highlighted the difficulty of locating suspects quickly without technological support.

Public Tolerance For Certain Uses

Government research published alongside the consultation appears to suggest high public tolerance for certain uses. For example, according to the government’s figures, 97 per cent of respondents said retrospective facial recognition is at least sometimes acceptable, while 88 per cent said the same about live facial recognition for locating suspects. Ministers may see this as support for building a clearer framework, although rights groups argue that acceptability is dependent on strict safeguards and transparency.

The Need For Oversight

That said, independent accuracy testing has reinforced the need for stronger oversight. For example, the National Physical Laboratory found that earlier systems used in UK policing produced significantly higher false alert rates for Black and Asian people. The Home Office now acknowledges these disparities, noting that updated systems and reviews have since been introduced. Even so, the findings have shaped calls for clearer legal boundaries before expansion proceeds.

When These Changes Might Take Effect

The consultation runs through early 2026, after which ministers will draft legislation for parliamentary scrutiny. The Home Office estimates that introducing a new legal regime, establishing the regulator and deploying the national facial matching service will take around two years. During that period, existing deployments will continue under current guidance.

Police forces already using live facial recognition, including the Metropolitan Police and South Wales Police, will continue targeted deployments. Trials using mobile facial recognition vans across multiple forces are also expected to continue, and the national facial matching service is scheduled for testing in 2026.

How The Technology Works Across UK Forces Today

Police currently rely on three distinct facial recognition tools, each supporting different operational needs, which are:

1. Retrospective facial recognition. Used during investigations, this compares still images from CCTV, doorbell cameras, mobile footage or social media against custody images. It is the most widely used form, and police say it speeds up identification in cases where investigators have a clear image but no confirmed identity.

2. Live facial recognition. These systems scan faces in real time as people pass a camera. The software compares each face to a watchlist of individuals wanted for specific offences or subject to court conditions. When a possible match arises, officers decide whether to stop the person. Deployments are usually short, targeted and focused on high footfall areas.

3. Operator initiated facial recognition. This mobile app allows officers to check identity during encounters by comparing a photo to custody images, avoiding unnecessary trips to a station solely for identification.

Police leaders say these tools allow forces to locate wanted individuals more efficiently. Lindsey Chiswick, the National Police Chiefs’ Council lead for facial recognition, says the technology “makes officers more effective and delivers more arrests than would otherwise be possible”, adding that “public trust is vital, and we want to build on that by listening to people’s views”.

Legal And Ethical Issues

Legal concerns have followed facial recognition since its earliest deployments, and several landmark rulings continue to shape how police use the technology. For example, back in 2020, a Court of Appeal ruling in the Ed Bridges case remains the most significant legal challenge to date. In this case, the court found that South Wales Police’s early use of live facial recognition breached privacy rights because of inadequate safeguards, incomplete assessments and insufficient checks on whether the system discriminated against particular groups.

Also, the Equality and Human Rights Commission has criticised aspects of earlier Metropolitan Police deployments, saying forces must demonstrate necessity and proportionality each time. The Information Commissioner’s Office has also warned forces to ensure accuracy and justify the retention of custody images belonging to people never convicted of an offence.

Accuracy Problems

Accuracy remains central to the ethical debate. For example, the National Physical Laboratory found that in one system previously used operationally, Asian faces were wrongly flagged around four per cent of the time and Black faces around five and a half per cent, compared with around 0.04 per cent for white faces. For Black women, false alerts rose to nearly ten per cent. These figures show how demographic disparities can emerge in real deployments and highlight the importance of system configuration.

Rights groups warn that these issues could lead to wrongful stops or reinforce existing inequalities. They also argue that routine scanning in public spaces risks creating a sense of constant surveillance that may influence how people move or gather. Liberty has said it is “disappointed” that expansion is being planned before the risks are fully resolved, while Big Brother Watch has urged a pause during the consultation.

Support Strong From Police

It’s worth noting here that, perhaps not surprisingly, support within policing remains strong. For example, former counter terror policing lead Neil Basu says live facial recognition is “a massive step forward for law enforcement, a digital 21st century step change in the tradition of fingerprint and DNA technology”, while noting that it “will still require proper legal safeguards and oversight by the surveillance commissioner”. Police forces repeatedly stress that every alert is reviewed by an officer rather than acted on automatically.

Industry Supports Structured Rollout

Industry organisations also appear to support a structured rollout. For example, Sue Daley, Director of Tech and Innovation at techUK, says “regulation clarity, certainty and consistency on how this technology will be used will be paramount to establish trust and long term public support”. The technology sector argues that clear rules will help build confidence both inside and outside policing.

Charities

Charities focused on vulnerable people have also highlighted some potential benefits. For example, Susannah Drury of Missing People says facial recognition “could help to ensure more missing people are found, protecting people from serious harm”, though she also stresses the need to examine ethical implications before expanding use.

That said, civil liberties groups continue to call for stronger limits, arguing that wider deployment risks normalising biometric scanning in everyday spaces unless strict rules are imposed regarding watchlists, retention and operational necessity.

Areas For Further Debate

The proposals raise questions that will remain live throughout the consultation period. For example, these include how forces will define and maintain watchlists, how the new regulator will enforce safeguards, what thresholds will apply before live facial recognition can be deployed, and how demographic accuracy will be monitored over time. Businesses that operate high footfall environments, such as shopping centres and transport hubs, are also likely to face questions about how their video systems might interact with police requests as adoption increases.

What Does This Mean For Your Business?

It seems that, following this announcement from the government, policymakers now face a moment where practical policing needs, public confidence and legal safeguards must be aligned in a way that has not been achieved before. The consultation sets out an ambition for national consistency and clearer rules, although the evidence presented across this debate shows that accuracy, oversight and transparency will determine whether expansion strengthens trust or undermines it. The range of views from policing, civil liberties groups, industry and charities illustrates how differently this technology is experienced, and why the government will need to resolve issues that sit well beyond technical capability alone.

The implications extend into policing culture, investigative practice and public space management, which will all look different if facial recognition becomes a mainstream tool. Forces anticipate faster identifications, clearer procedures and more reliable ways to locate individuals who pose a genuine risk. Civil society groups, by contrast, point to the potential for overreach unless firm limits are embedded in law. These competing priorities will shape how the regulator operates and how the Home Office interprets proportionality in real deployments.

Businesses also sit at the centre of this discussion because they capture and provide a significant volume of the video footage used in retrospective searches. Retailers, transport hubs and major venues may face new expectations about how they store, secure and share images, and these responsibilities may grow as facial matching becomes more accurate and more widely used. Clearer rules could help organisations understand how to cooperate with investigations without exposing themselves to unnecessary compliance risks, particularly around data protection and equality duties.

The wider public interest lies in how these decisions affect everyday life. Public attitudes will depend on whether safeguards are visible, whether wrongful identifications are prevented, and whether live deployments remain tightly focused rather than becoming a routine feature of public spaces. A national framework could provide that reassurance if it genuinely addresses the concerns raised during testing and legal review. The coming months will show how far the government is prepared to go in defining those boundaries and whether the final model satisfies the mix of operational urgency and ethical caution that has defined this debate so far.

Tech Tip – Turn Off WhatsApp Read Receipts for More Privacy

Feel under pressure to reply the moment you’ve read a message? Turning off WhatsApp’s read receipts hides the blue ticks, letting you read messages privately and respond in your own time.

How to:

– Open WhatsApp and go to Settings > Privacy > Read Receipts.
– Toggle it off.

What it’s for:

Gives you space to read and think without letting senders know you’ve opened their messages, which is ideal when you’re busy or need time to draft a reply.

Pro‑Tip: This doesn’t apply to group chats (read receipts still appear once all members have seen the message) and you also won’t see when others have read your messages.

News : UK Backs Down In Apple Privacy Row

The UK government has backed down from its demand that Apple create a “back door” into its encrypted systems, ending a high-profile dispute that drew in Washington and sparked widespread criticism from privacy campaigners and industry experts.

How the Row Began

The confrontation began late last year when the UK Home Office issued Apple with a “technical capability notice” under the Investigatory Powers Act. This law (also known as the “snooper’s charter”) allows the government to compel technology companies to assist law enforcement in accessing data to investigate serious crimes such as terrorism and child sexual abuse.

The notice required Apple to make encrypted customer data available to authorities on demand. What made it unusual was its global scope, i.e. the order applied not just to British customers but potentially to Apple users anywhere in the world, including in the United States.

The demand clashed directly with Apple’s Advanced Data Protection (ADP) tool, launched in 2022, which provides end-to-end encryption for iCloud backups. Once activated, not even Apple itself can access the contents of a user’s iCloud files, photos, notes or reminders. For law enforcement, this meant some data would be completely beyond reach. For Apple, complying with the UK’s order would have meant deliberately undermining its own encryption.

Apple responded by withdrawing ADP for new customers in the UK, saying it was “deeply disappointed” and would “never build a backdoor or master key” to its products. At the same time, it launched a legal challenge to the government’s order at the Investigatory Powers Tribunal, with a hearing scheduled for early 2026.

Escalation Into a Transatlantic Dispute

What might have remained a UK legal battle soon escalated into an international row. Because the UK’s notice applied worldwide, it raised the possibility of British authorities accessing the data of American citizens.

US leaders reacted strongly. President Donald Trump accused Britain of “behaving like China” and publicly told Prime Minister Keir Starmer: “You can’t do this.” Vice President JD Vance called the demand “crazy”, warning that it risked creating a vulnerability in US technology that could be exploited by hostile states. Tulsi Gabbard, the US Director of National Intelligence, was equally blunt, saying the order “would have encroached on our civil liberties”.

Behind the scenes, senior American officials pressed London to change course. According to the Financial Times, Vice President Vance personally intervened during a recent visit to the UK, negotiating what US officials later described as a “mutually beneficial understanding” that the order would be withdrawn.

The UK Retreats

On 19 August, Gabbard confirmed in a post on X that the UK had “agreed to drop its mandate for Apple to provide a ‘back door’ that would have enabled access to the protected encrypted data of American citizens”. She added that she had been working with President Trump and Vice President Vance “to ensure Americans’ private data remains private and our constitutional rights and civil liberties are protected”.

The Home Office has refused to confirm or deny her claim, citing a long-standing policy not to comment on operational matters. However, multiple British officials told reporters that the issue was “settled” and that London had “caved” to US pressure.

Whether the technical capability notice will be formally withdrawn, amended to target only UK citizens, or left in place but unenforced remains unclear. Legal experts have pointed out that limiting access to UK citizens’ data alone may be technologically unrealistic, since Apple’s cloud systems do not distinguish by nationality.

Why the Government Backed Down

Several factors contributed to the reversal. The most immediate was diplomatic pressure from Washington. With Trump’s administration already imposing tariffs on European goods and pressing allies on defence spending, the UK government may have had little appetite for a damaging rift over encryption policy. Also, some would say that, given Apple’s Tim Cook’s recent public strategic outreach (financially and symbolically) with President Trump, and UK Prime Minister Starmer’s wish not to have tariffs increased following recent negotiations, this may have been one fight the UK government thought it best not to have at this time.

Another factor was the risk to Britain’s global reputation. Legal experts and business groups had warned that forcing Apple to break encryption could deter companies from operating in the UK, damaging the country’s status as a safe destination for data. Charlotte Wilson, head of enterprise at Check Point Software, described the original order as “hugely damaging”, saying that once a master key to encrypted data exists “criminal groups and hostile states will try to exploit it too”.

Civil liberties organisations also appear to have played a role. Liberty and Privacy International had both launched legal action against the government, arguing that creating a back door would be unlawful and reckless. Sam Grant, Liberty’s director of external relations, called the reported U-turn “hugely welcome”, warning that such powers would put campaigners, minority groups and politicians at heightened risk of targeting.

What It Means for Apple and Its Users

For Apple, the retreat could be seen as a vindication of its long-standing stance on encryption. The company has repeatedly argued that any deliberate weakness, even one intended for law enforcement, could eventually be exploited by criminals or foreign governments.

It is now likely that Apple will reinstate Advanced Data Protection for new UK customers, although the company has not yet confirmed its plans. If it does, British businesses and individuals will again be able to benefit from the highest level of iCloud encryption, aligning with customers elsewhere in the world.

For UK businesses in particular, the move has real significance. For example, end-to-end encryption is increasingly seen as a baseline requirement for protecting sensitive intellectual property, financial data and client communications. Any perception that the UK was a weak link could have harmed firms’ ability to meet international compliance standards or reassure overseas partners.

Lingering Concerns

Despite the climbdown, some critics argue that the underlying problem remains. The Investigatory Powers Act still contains provisions allowing the government to issue similar notices in future. Jim Killock, executive director of the Open Rights Group, said: “The UK’s powers to attack encryption are still on the law books, and pose a serious risk to user security and protection against criminal abuse of our data.”

There are also unanswered questions about whether other technology companies have been served with similar demands. WhatsApp, for example, has said it has not received such a notice, but secrecy provisions mean firms cannot always disclose whether they have been targeted.

Another unresolved issue is whether Britain will seek to revise its order in a way that applies only to UK citizens. Privacy experts caution that such an approach could still create risks, since once a back door exists, it cannot easily be limited to one group of users.

The Wider Picture

The dispute highlights the tension between governments’ desire for access to digital evidence and technology companies’ commitment to protecting user privacy. Governments argue that encryption can provide cover for criminals and terrorists, while companies and privacy advocates insist that undermining encryption would weaken security for everyone.

For the UK government, the episode has also shown the limits of its extraterritorial powers. While the Investigatory Powers Act gives British authorities the ability to issue global data access demands, enforcing them against multinational firms without international support is fraught with difficulty.

For the United States, the outcome demonstrates the strength of its leverage over allies when civil liberties and the interests of its technology sector are at stake. Gabbard framed the UK’s reversal as a victory for American citizens’ rights, while Senator Ron Wyden described it as “a win for everyone who values secure communications”.

What Does This Mean For Your Business?

The UK government’s retreat may settle the immediate dispute but it leaves many questions unanswered about how far states can and should go in seeking access to private data. The fact that London backed down only after sustained US pressure shows the difficulty of enforcing extraterritorial demands when they clash with the interests of powerful allies and companies. It also underlines that encryption has become more than a technical feature, it is now a geopolitical fault line between privacy, commerce and national security.

For Apple, the outcome strengthens its position as a global defender of encryption and restores confidence among its UK customers, many of whom had been left without the strongest level of iCloud protection. Businesses in particular stand to gain if Advanced Data Protection is reinstated, since they rely heavily on secure storage and communications to safeguard sensitive information. The reassurance that the UK will not compel Apple to weaken its systems may also help British firms demonstrate compliance with international standards and maintain trust with overseas partners.

For the UK government, however, the episode risks being seen as a climbdown that exposes the limits of its investigatory powers. Ministers continue to argue that strong surveillance powers are essential to combat threats such as terrorism and child abuse, yet critics have been quick to say that Britain has undermined its own credibility by pushing for a back door it could not deliver. Privacy campaigners and technology experts will also point out that the Investigatory Powers Act still contains the same provisions, leaving open the possibility that a future government may attempt a similar move.

The wider implications go beyond Apple. Other technology companies will be weighing what this episode means for their own obligations under UK law and whether they too could face demands that clash with global privacy protections. Civil liberties groups will continue to press for reforms to prevent governments from seeking back doors in the first place, while law enforcement agencies are likely to warn that criminals will continue to exploit encryption to hide their activities. What is clear is that this confrontation has highlighted the difficulty of balancing privacy, security and international diplomacy, and it will not be the last time these issues collide.

Security Stop-Press: Meta AI’s ‘Share’ Button Sparks Privacy Concerns

Meta’s new AI app is under fire after users unknowingly shared private chats, including legal queries, personal data and audio clips, on the public web.

The issue lies with a “share” button that appears after each chatbot response. Users can post content without realising it’s publicly visible, especially if logged in via a public Instagram account. Security expert Rachel Tobac called it a “privacy nightmare” after spotting names, addresses and court-related questions shared online.

Some posts appear jokey or attention-seeking, but many involve sensitive or reputationally risky content. One user asked about a rash, another discussed tax evasion, and several uploaded CVs and legal references, seemingly unaware they were going public.

Launched on 29 April, the app has already hit 6.5 million downloads. However, experts say Meta should have anticipated the risks of blending private AI queries with social sharing.

Businesses should avoid using AI tools through personal logins and steer clear of sharing anything sensitive unless privacy settings are crystal clear.

Company Check – Meta & Yandex Covert Tracking Concerns

Meta and Russian search firm Yandex used hidden background scripts to monitor Android users’ web activity without consent, bypassing incognito mode and browser protections, researchers say.

Hidden Tracking System Uncovered

A new joint investigation has revealed that Meta and Yandex have been covertly collecting the private web browsing data of Android users by exploiting local communication loopholes between mobile apps and browsers. The technique reportedly allowed both companies to bypass standard privacy protections, without the knowledge or consent of users.

The findings were published by an international research team led by Radboud University in the Netherlands and IMDEA Networks Institute in Spain. The group included privacy experts Gunes Acar, Narseo Vallina-Rodriguez, Tim Vlummens (KU Leuven), and others. Their research revealed that Android apps owned by Meta (including Facebook and Instagram) and Yandex (including Yandex Maps, Browser, Navi, and Search) were silently listening on fixed local ports to receive web tracking data via local network connections, thereby effectively joining app-based user identities with users’ browsing habits.

According to the researchers, this practice undermines the technical safeguards built into both Android and modern web browsers, including incognito browsing, cookie restrictions, and third-party tracking protections.

How the Tracking Worked in Practice

Under Android’s permission model, any app granted the “INTERNET” permission (which includes nearly all social media and mapping apps) can start a local server inside the app. Meta and Yandex are reported to have used this ability to set up background listeners on local ports (e.g. via TCP sockets or WebRTC channels).

When users visited websites embedded with Meta Pixel or Yandex Metrica tracking scripts, those scripts could secretly send data to these background ports on the same device. This meant the apps could intercept identifiers and browsing metadata from the websites, despite no direct interaction from the user, and tie them to a logged-in app profile. The researchers say this technique effectively broke down the wall between mobile app usage and private web browsing, two areas users generally expect to remain separate.

Evasion Tactics From Yandex?

While Meta’s version used WebRTC signalling to send identifiers to their native apps, it seems that Yandex implemented a more dynamic system. For example, their apps reportedly downloaded remote configurations and delayed activation for several days after installation, which is behaviour likened by the researchers to malware-like evasion tactics.

Widespread Reach and Long-Term Use

The researchers have reported that the tracking appears to have been extensive. Meta Pixel is currently embedded on approximately 5.8 million websites, while Yandex Metrica is used on more than 3 million. Although the practice was only observed on Android devices, the scale of exposure is, therefore, significant. The researchers report that Yandex has been doing this since at least 2017, while Meta began similar behaviour in late 2024.

Apparent Lack of Disclosure

What makes the findings more concerning is the apparent lack of disclosure to app users, website operators, or browser vendors. For example, developer forums have shown widespread confusion among website owners who were unaware their use of tracking pixels enabled data extraction via app-localhost bridges. Some people reported unexplained localhost calls from Meta’s scripts, with little guidance on what the data was or how it was being used.

Google and Browser Makers Respond

Google, which maintains the Android operating system, has confirmed the tracking method was being used in “unintended ways that blatantly violate our security and privacy principles.” Chrome developers, along with DuckDuckGo and other browser vendors, have now issued patches to block some forms of localhost communication initiated by websites.

Also, Narseo Vallina-Rodríguez, associate professor at IMDEA, noted: “Until our disclosure, Android users were entirely defeated against this tracking method. Most platform operators likely didn’t even consider this in their threat models.”

Countermeasures Rolled Out

As a result of the academic team’s findings, several browser-based countermeasures, such as port-blocking and new sandboxing approaches, are now being rolled out, and Chrome’s patch is reportedly going live imminently.

Meta and Yandex Defend Their Position

In response to the findings, Meta has said it paused the feature and was working with Google to clarify the “application of their policies.”

Yandex, meanwhile, has reportedly denied that any sensitive data was collected, saying that “The feature in question does not collect any sensitive information and is solely intended to improve personalisation within our apps.” However, the researchers argue that the data gathered, including persistent identifiers, browsing activity, and time-stamped behaviour, carries substantial profiling risk.

Privacy Experts Raise the Alarm

Not surprisingly, the episode has drawn some strong criticism from privacy advocates, who argue the tactics used represent a significant overreach and a breach of user trust. For example, the European Digital Rights (EDRi) group issued a statement calling it a “blatant abuse of technical permissions,” while Mozilla Fellow Alice Munyua said the practice “shows exactly why we need more transparency, not less, in how apps interact with user data.”

IMDEA’s Aniketh Girish, one of the study’s co-authors, said the real issue lies in how easily these companies linked users’ web identities to their mobile profiles without any consent or notification.

Implications

For businesses relying on Meta and Yandex advertising tools, the revelations raise fresh questions about the ethical and legal responsibilities of digital marketing. Many companies use Meta Pixel or Yandex Metrica to improve targeting and ad performance, but may now find themselves indirectly involved in opaque data practices.

Businesses Using These Tools Could Be Held Responsible

It seems that businesses using third-party tools like Meta Pixel or Yandex Metrica (e.g. operators and advertisers) aren’t absolved of responsibility if those tools are later found to breach privacy rules. This is because legal and regulatory frameworks such as the UK GDPR place obligations on data controllers to understand and account for how user data is collected and processed, even when using external vendors.

Also, business users and app developers who trust major platforms for analytics and performance tracking may now need to be more cautious.

What Does This Mean For Your Business?

The apparent scale and persistence of this tracking activity reveals more than just a privacy lapse. It shows how trusted platforms may have quietly prioritised data collection over user transparency, thereby exploiting overlooked technical loopholes. The fact that browser-level defences are only now being introduced suggests the issue went unnoticed even by major platform operators.

For UK businesses, the implications are serious. For example, many rely on tools like Meta Pixel or Yandex Metrica for advertising and analytics, but under GDPR, they remain responsible for understanding how data is collected, regardless of who built the tools. This means that if personal data was captured without consent via websites or apps operated in the UK, businesses could be held accountable.

The lack of disclosure to developers and site owners also raises questions about consent and control. If tracking was occurring via localhost connections without their knowledge, they had no way to inform users or adjust settings accordingly. As regulators increase their focus on accountability, ignorance of how embedded tools function is unlikely to offer much protection.

More broadly, this case highlights the need for reform across both mobile platforms and browsers. Researchers say that Android’s local port access requires stronger safeguards, and permission models need updating to prevent similar abuse. Whether that happens will depend on pressure from developers, watchdogs, and public institutions.

At its core, the episode shows how fragile digital trust can be when data is moved behind the scenes without consent. For users and UK businesses alike, the expectation now is not just performance, but clear accountability for how every click and interaction is tracked, stored, and shared.

Tech Insight : Why Google’s New ‘Fingerprint’ Policy Matters

In this Tech Insight, we look at Google’s controversial decision to allow advertisers to use device fingerprinting, exploring what the technology involves, why it has sparked concern, and what it means for users, businesses, and regulators.

A Policy Reversal

In February 2025, Google quietly updated its advertising platform rules, allowing companies that use its services to deploy a tracking method known as ‘device fingerprinting’. The change came with little fanfare but has quickly become one of the most debated privacy developments of the year.

Until now, fingerprinting was explicitly prohibited under Google’s policies. The company had long argued it undermined user control and transparency. In a 2019 blog post, Google described it as a technique that “subverts user choice and is wrong”. But five years later, the same practice is being positioned as a legitimate tool for reaching audiences on platforms where cookies no longer work effectively.

According to Google, the decision reflects changes in how people use the internet. For example, with more users accessing content via smart TVs, consoles and streaming devices, environments where cookies and consent banners are limited or irrelevant, fingerprinting offers advertisers a new way to track and measure campaign effectiveness. The company says it is also investing in “privacy-enhancing technologies” that reduce risks while still allowing ads to be targeted and measured.

However, the reaction from regulators, privacy campaigners and some in the tech community has been far from supportive.

What Is Fingerprinting?

Fingerprinting is a method of identifying users based on the technical details of their device and browsing setup. Unlike cookies, which store data on a user’s device, fingerprinting collects data that’s already being transmitted as part of normal web use.

This includes information such as:

– Browser version and type.

– Operating system and installed fonts.

– Screen size and resolution.

– Language settings and time zone.

– Battery level and available plugins.

– IP address and network information.

Individually, none of these data points reveals much but, when combined, they can create a unique “fingerprint” that allows advertisers or third parties to recognise a user each time they go online, often without them knowing, and without a way to opt out.

Also, because it happens passively in the background, fingerprinting is hard to block. Even clearing cookies or browsing in private mode won’t prevent it. For privacy advocates, that’s a key part of the problem.

How Fingerprinting’s Being Used

With third-party cookies disappearing and users browsing through everything from laptops to smart TVs, fingerprinting essentially offers a way for advertisers to maintain continuity, even when cookies and consent banners can’t keep up.

Advertisers use it to build persistent profiles that help with targeting, measurement, and fraud detection. In technical terms, it’s a highly efficient way to link impressions and conversions without relying on traditional identifiers.

Why Critics Are Alarmed

Almost immediately after Google’s announcement, a wave of criticism followed. For example, the UK’s independent data protection regulator, the Information Commissioner’s Office (ICO), called the move “irresponsible” and said it risks undermining the principle of informed consent.

In a December blog post, Stephen Almond, Executive Director of Regulatory Risk at the ICO, warned: “Fingerprinting is not a fair means of tracking users online because it is likely to reduce people’s choice and control over how their information is collected.”

The ICO has published draft guidance explaining that fingerprinting, like cookies, must comply with existing UK data laws. These include the UK GDPR and the Privacy and Electronic Communications Regulations (PECR). That means advertisers need to demonstrate transparency, secure user consent where required, and ensure users understand how their data is being processed.

The problem, critics say, is that fingerprinting makes this nearly impossible. The Electronic Frontier Foundation’s Lena Cohen described it as a “workaround to offering and honouring informed choice”. Mozilla’s Martin Thomson went further, saying: “By allowing fingerprinting, Google has given itself — and the advertising industry it dominates — permission to use a form of tracking that people can’t do much to stop.”

Google’s Justification

Google insists that fingerprinting is already widely used across the industry and that its updated policy simply reflects this reality. The company has argued that IP addresses and device signals are essential for preventing fraud, measuring ad performance, and reaching users on platforms where traditional tracking methods fall short.

In a statement, a Google spokesperson said: “We continue to give users choice whether to receive personalised ads, and will work across the industry to encourage responsible data use.”

Criticism From Privacy Campaigners

However, privacy campaigners argue that the decision puts business interests above users. They point out that fingerprinting isn’t just harder to detect, but it’s also harder to control. For example, unlike cookies, there’s no pop-up, no ‘accept’ or ‘reject’ button, and no straightforward way for users to opt out.

Pete Wallace, from advertising technology company GumGum, said the change represents a backwards step: “Fingerprinting feels like it’s taking a much more business-centric approach to the use of consumer data rather than a consumer-centric approach.”

Advertisers Welcome the Change

Unsurprisingly perhaps, within the advertising industry, many welcomed Google’s decision because as the usefulness of cookies declines, brands are looking for alternative ways to reach users, especially across multiple devices.

For example, Jon Halvorson, Global VP at Mondelez International, said: “This update opens up more opportunities for the ecosystem in a fragmented and growing space while respecting user privacy.”

Trade bodies such as the IAB Tech Lab and Network Advertising Initiative echoed the sentiment, saying the update enables responsible targeting and better cross-device measurement.

That said, even among advertisers, there’s an awareness that the use of fingerprinting must be handled carefully. Some fear that if it is abused or poorly implemented, it could invite regulatory action, or worse, further erode user trust in the online ad industry.

Legal Responsibilities Under UK Law

For UK companies using Google’s advertising tools, the policy change doesn’t mean fingerprinting is suddenly risk-free. While Google’s own platform rules now allow the practice, UK data protection law still applies, and it’s strict.

For example, organisations planning to use fingerprinting must ensure their tracking methods are:

– Clearly explained to users, with full transparency.

– Proportionate to their purpose, and not excessive.

– Based on freely given, informed consent where applicable.

– Open to user control, including rights to opt out or request erasure.

The ICO has warned that fingerprinting, by its very nature, makes it harder to meet these standards. The fact that it often operates behind the scenes and without user awareness means that it may not be providing the level of transparency required under the UK GDPR and PECR is a significant challenge.

Therefore, any business using fingerprinting for advertising will need to demonstrate that it is not only aware of these rules, but fully compliant with them. Regulators have already signalled their willingness to act where necessary, and given Google’s influence, this policy change is likely to come under particular scrutiny.

The Reputational Risks Are Real

It should be noted, however, that while it’s effective, fingerprinting comes with serious downsides, especially for businesses operating in sensitive or highly regulated sectors. For example, since users often don’t know it’s happening, fingerprinting can undermine trust, even when it’s being used within legal boundaries.

For industries like healthcare, finance, or public services, silent tracking could prove more damaging than the data is worth. If customers feel they’ve been tracked without consent, the backlash, whether legal, reputational or both, can be swift.

Fragmentation Across the Ecosystem

Another practical challenge is that fingerprinting isn’t supported equally across platforms. While Google has now allowed it within its ad systems, others have gone in the opposite direction.

For example, browsers like Safari, Firefox and Brave actively block or limit fingerprinting. Apple in particular has built its privacy credentials around restricting such practices. This means advertisers relying heavily on fingerprinting could see patchy results or data gaps depending on the devices or browsers their audiences are using.

Part of a Broader Toolkit

It’s worth remembering here that fingerprinting isn’t the only tool on the table. Many ad tech providers are combining it with alternatives such as :
— Contextual targeting : Showing ads based on the content you’re looking at (e.g. showing travel ads on a travel blog).
— First-party data : Information a company collects directly from you, like your purchase history or website activity — not from third parties.

— On-device processing : Data is analysed on your phone or computer, never sent to a central server.

— Federated learning : Your device trains a model (like for ad targeting or recommendations), and only anonymised updates are shared — not your personal data.

Therefore, rather than replacing cookies outright, fingerprinting may end up as just one option in a mixed strategy, and used selectively where consent is hard to obtain, or where traditional identifiers are unavailable.

What Does This Mean for Your Business?

For UK businesses, the reintroduction of fingerprinting within its advertising ecosystem may offer more stable tracking across devices and platforms, especially as third-party cookies continue to decline. However, the use of such techniques also brings legal and reputational risks that cannot be delegated to Google or any external platform.

Organisations that advertise online, whether directly or through agencies, should now assess how fingerprinting fits within their broader compliance obligations under UK data protection law. The Information Commissioner’s Office has made it clear that fingerprinting is subject to the same principles of transparency, consent, and fairness as other tracking methods. Simply using a tool because it is technically available does not make its use lawful.

Beyond legal considerations, there’s also a growing risk to customer trust. For example, if users discover that they are being tracked through methods they cannot see, manage or decline, the damage to a brand’s credibility could be significant, particularly in sectors where data sensitivity is high. For many organisations, the question may not just be whether fingerprinting can improve ad performance, but whether it aligns with the expectations of their audience and the values they wish to uphold.

This change also places pressure on advertisers, platforms, and regulators to clarify the boundaries of responsible data use. For some, fingerprinting may form part of a wider privacy-aware strategy that includes contextual targeting or consent-based identifiers. For others, it may prove too opaque or contentious to justify. Either way, businesses will need to make informed decisions, and be ready to explain them.

Company Check – Legal Aid : Data Exposed

Hundreds of thousands of criminal, financial and personal records have been compromised in a major cyber attack on the UK’s Legal Aid Agency, raising serious questions about digital security in one of the country’s most sensitive justice systems.

What Is the Legal Aid Agency And Why Was It Targeted?

The Legal Aid Agency (LAA), part of the Ministry of Justice, provides funding for legal representation to individuals who can’t afford it. This includes people facing criminal charges, eviction, domestic abuse, or complex family matters. Each year, it processes hundreds of thousands of applications and manages payments to solicitors and legal providers across England and Wales.

However, behind this critical public function, the agency’s digital infrastructure was running on fragile systems that, according to critics, had been neglected for years. For example, the Law Society had previously warned that its technology was “too antiquated to cope”, a warning that now appears to have been tragically justified.

What Happened And How Did the Hackers Get In?

Officials first became aware of the cyber attack on 23 April, when the LAA’s online digital services began to show signs of compromise. At first, it was thought that only legal aid providers (i.e. solicitors and firms who use the system to log work and request payment) were affected.

However, further investigation revealed something far more serious. On 16 May, it was confirmed that the attackers had in fact accessed and downloaded a large volume of personal data belonging to legal aid applicants going back as far as 2010.

The data accessed (and probably downloaded) includes names, contact details, dates of birth, national insurance and ID numbers, employment status, criminal history, and sensitive financial data such as debt levels and payment records. Some reports even claim up to 2.1 million pieces of data may have been taken, though this has yet to be formally verified.

Who Was Behind the Attack?

The group responsible has not yet been officially identified, but officials have said they do not currently believe this was the work of a hostile nation-state. Instead, it appears to be the work of an organised criminal gang, possibly seeking to extort or sell stolen data for financial gain.

The Ministry of Justice has confirmed that the National Crime Agency and the National Cyber Security Centre are now investigating the incident, with assistance from the Information Commissioner’s Office. Meanwhile, the LAA’s online portal has been taken offline, and work has begun on building a replacement system.

Why Did This Happen And Could It Have Been Prevented?

According to a source within the Ministry of Justice, vulnerabilities in the LAA’s systems were known for years but not addressed under the previous government. Critics have described the breach as the result of “long-term neglect”, pointing to repeated calls for investment and reform from legal bodies such as the Law Society.

In the words of Law Society president Richard Atkinson, “Legal aid firms are small businesses operating on the margins of viability… these financial security concerns are the last thing they need.” He added that the system’s fragility had already hindered reforms and warned that any further delays would now be “untenable”.

Real-World Risks for Individuals and Firms

For the thousands of people affected, this isn’t just an IT failure – it’s a personal risk. Many legal aid applicants are already in vulnerable situations. For example, some are dealing with domestic abuse cases, immigration hearings, or criminal charges, while others have been wrongly accused, or are applying for legal help in family disputes.

Now, it seems those same individuals are facing the anxiety of not knowing where their personal data has ended up, or how it could be used. Cybersecurity experts warn that data like this is often used in targeted scams, phishing campaigns, or identity fraud, with long-term implications.

Also at risk are the legal aid providers themselves. These are often small law firms already under financial pressure, now left scrambling for alternative ways to process claims and payments while the LAA rebuilds its systems.

What Should You Do If You’re Affected?

The Legal Aid Agency has urged anyone who applied for legal aid between 2010 and 2025 to take immediate steps to safeguard themselves. This includes:

– Being alert for suspicious phone calls, texts, or emails from unknown senders.

– Updating passwords, especially for any accounts that may have reused information.

– Verifying the identity of anyone requesting personal or financial details before responding.

The National Cyber Security Centre has also published updated guidance for individuals and businesses affected by data breaches, with a particular focus on spotting phishing scams and securing mobile devices.

What Does This Mean For Your Business?

This breach is yet another reminder that outdated digital systems are no longer just an inconvenience – they are a real liability. For UK businesses, particularly those in legal services, social care, government contracting, or any industry that handles sensitive personal data, this incident is a wake-up call.

This is also a reminder that cyber risk is no longer confined to banks and tech giants. It seems that public sector agencies, legal support organisations, and even small private firms are all now in the firing line, mainly because cybercriminals are increasingly targeting entities with sensitive data but outdated or underfunded digital defences, seeing them as easier to exploit than large, well-protected corporations.

If an organisation’s systems haven’t been independently tested, audited, or updated in the last 12–18 months, now is the time to act.

The Legal Aid Agency may recover, but its credibility has been badly shaken, and for the people whose data was exposed, the damage may be permanent. What this breach shows is that in the digital age, trust isn’t just earned through good service. It’s also earned (or lost) through cybersecurity.

Tech Tip – How To Tighten Your Facebook Privacy in Just a Few Clicks

Your Facebook public profile info can be scraped for scams, impersonation or phishing, but with a few quick settings, you can lock things down and stay in control. Here’s how:

Limit Who Can See Your Posts:

– Go to ‘Settings & Privacy > Settings > Privacy’.

– Under ‘Your Activity’, set ‘Who can see your future posts?’ to ‘Friends’.

Review All Your Posts and Things You’re Tagged In:

– In Privacy Settings, click on ‘Limit Past Posts’ to change past public posts to friends only.

– Enable ‘Timeline Review’ and ‘Tag Review’ under ‘Profile and Tagging Settings’ to review posts you’re tagged in before they appear on your timeline.

Control Who Can Send You Friend Requests:

– Under ‘How People Find and Contact You’, set ‘Who can send you friend requests?’ to ‘Friends of friends’.

– Restrict Who Can Look You Up Using Your Email or Phone Number:

– Set ‘Who can look you up using the email address/phone number you provided?’ to ‘Friends’ or ‘Only me’.

Prevent Search Engines from Linking to Your Profile:

– Turn off ‘Do you want search engines outside of Facebook to link to your profile?’

Pro-Tip: Regularly review your privacy settings to ensure they reflect your current preferences. Facebook occasionally updates its settings, so it’s good practice to check them periodically.