
EP 247.5 Deep Dive Broken Windows. The IT Privacy and Security Weekly Update for the Week Ending June 17th., 2025
About this episode
Windows Hello's Facial Authentication Update
Microsoft updated Windows Hello to require both infrared and color cameras for facial authentication, addressing a spoofing vulnerability. This enhances security but disables functionality in low-light settings, potentially inconveniencing users and pushing some toward alternatives like Linux for flexible authentication.
EchoLeak and AI Security
'EchoLeak' is a zero-click vulnerability in Microsoft 365 Copilot, discovered by Aim Labs, allowing data exfiltration via malicious emails exploiting an "LLM Scope Violation." It reveals risks in AI systems combining external inputs with internal data, emphasizing the need for robust guardrails.
Denmark’s Shift to LibreOffice and Linux
Denmark is adopting LibreOffice and Linux to boost digital sovereignty, reduce reliance on foreign tech like Microsoft, and mitigate geopolitical and cost-related risks. This follows a 72% rise in Microsoft software costs over five years.
Chinese AI Firms Bypassing U.S. Chip Controls
Chinese AI companies evade U.S. chip export restrictions by processing data in third countries like Malaysia, using tactics like physically transporting data and setting up shell entities to access high-end chips and return trained AI models.
Mattel and OpenAI Partnership
Mattel’s collaboration with OpenAI to create AI-enhanced toys introduces engaging, safe experiences for kids but raises privacy and security concerns, highlighting the need for "Zero trust" models in handling children’s data.
Apple’s Passkey Import/Export Feature
Apple’s new FIDO-based passkey import/export feature allows secure credential transfers across platforms, enhancing security and convenience. It uses biometric or PIN authentication, replacing less secure methods and improving interoperability.
Airlines Selling Passenger Data to DHS
The Airlines Reporting Corporation, owned by U.S. airlines, sold domestic flight data to DHS’s CBP, including names and itineraries, with a clause hiding the source. This raises privacy concerns about government tracking without transparency.
WhatsApp’s New Ad Policy
WhatsApp’s introduction of ads in its "Updates" section deviates from its original "no ads" philosophy. While limited and preserving chat encryption, this shift alters the ad-free experience that attracted its two billion users.
https://rprescottstearns.blogspot.com/2025/06/broken-windows-it-privacy-and-security.html
Get every episode summarized
Each time The IT Privacy and Security Weekly Update. publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The IT Privacy and Security Weekly Update.

Episode 286. The Deep Dive. Subliminal Learning with the AI, Security, and Priva...
The IT Privacy and Security Weekly Update.

Subliminal Learning with the AI, Security, and Privacy Weekly Update for the Wee...
The IT Privacy and Security Weekly Update.

Episode 285.5 Deep Dive. Patience and the AI, Privacy, and Security Weekly Updat...
The IT Privacy and Security Weekly Update.

Patience and the AI, Privacy, and Security Weekly Update for the Week Ending Mar...
The IT Privacy and Security Weekly Update.