Edition

This is a permanent edition. It carries the briefing exactly as published on this date and does not change.

Meta Reverses Encryption Plans for Instagram Direct Messages, Opting for Plaintext

Meta has unexpectedly reversed its previous commitment to implement end to end encryption for direct messages on Instagram. Instead, the platform is reportedly reverting to plaintext messaging, raising significant concerns about user privacy and data security. This decision departs from industry trends towards enhanced encryption and comes amidst ongoing regulatory scrutiny regarding data handling practices by large tech companies. The shift could expose private communications to potential interception and compromise.

Today's question

The EDPB transparency guidelines emphasize that:

  1. Only written privacy policies are acceptable, under the transparency and fairness framework, with corresponding procedural safeguards
  2. Controllers should use a variety of methods to provide information including visual and audio formats, dashboard tools, and just-in-time notices in addition to written policies
  3. Providing a privacy policy is sufficient regardless of quality, under the transparency and fairness framework, with particular attention to documentation requirements
  4. Transparency obligations only apply at the point of data collection, subject to the applicable communication standards

Answer this question on the site

Worth knowing

  1. European Authorities Publish Credit Solvency Assessment Recommendations for Personal Data Use

    The CNIL, a European data protection authority, has released recommendations concerning the use of personal data for credit solvency assessments. These guidelines aim to clarify the legal obligations and best practices for organizations engaging in credit granting, ensuring that data processing aligns with privacy principles and individual rights. This initiative provides crucial guidance for financial institutions and data privacy officers.

  2. Fake OpenAI Repository Spreads Infostealer Malware on Hugging Face

    A deceptive OpenAI repository hosted on Hugging Face has been identified distributing infostealer malware. This incident highlights the growing threat of malicious actors leveraging popular platforms and brand impersonation to trick users into downloading compromised software. It underscores the importance of supply chain security and careful validation of software sources.

  3. Concerns Rise Over AI Misuse After Anthropic's Claude Prompts Exploit One Click RCE

    Anthropic's AI model, Claude, has been found susceptible to a one click Remote Code Execution vulnerability through certain prompts, causing security experts to warn against trusting AI outputs without verification. This incident underscores critical risks in AI system deployment and user interaction, particularly concerning prompt engineering and the potential for unintended system compromises. It highlights the need for robust security measures around AI interfaces.

Compiled that morning from regulator, court and authority sources. Primary sources are linked on every story.