Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Martin

@mshelton@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

Security therapist. Deputy Director of Digital Security @freedomofpress@social.freedom.press. Journalism, digital security, research.

If you want to get security news and updates from our team somewhere that's not Twitter, subscribe to the newsletter: https://freedom.press/newsletters/

2364 Followers
503 Following
45 Posts
Joined April 05, 2022
Website:
https://mshelt.onl/
freedom.press:
https://freedom.press/people/martin-shelton/
Digital security newsletter:
https://freedom.press/newsletters/
Pronouns:
He/him
Open post
Martin @mshelton@mastodon.social
· 1w ago
When AI companies do felonies with their software, governments need to begin hitting them where it hurts: In their pocketbooks. https://techcrunch.com/2026/09/24/australia-to-investigate-if-openai-hack-of-government-health-website-broke-the-law/
Australia to investigate if OpenAI hack of government health website broke the law | TechCrunch
TechCrunch

Australia to investigate if OpenAI hack of government health website broke the law | TechCrunch

The incident is the first known breach to affect a government agency, and Australia's prime minister has vowed to hold OpenAI accountable.

8
0
7
0
Open post
Martin @mshelton@mastodon.social
· 2mo ago
Even the LAPD doesn't want to work with Flock because of its privacy and data storage risks. The LAPD. I'm going to say that a third time: The LAPD. https://techcrunch.com/2026/07/13/lapd-lets-contract-with-surveillance-giant-flock-expire-citing-serious-concerns-over-civil-liberties-and-privacy/
LAPD lets contract with surveillance giant Flock expire, citing 'serious concerns' over civil liberties and privacy | TechCrunch
TechCrunch

LAPD lets contract with surveillance giant Flock expire, citing 'serious concerns' over civil liberties and privacy | TechCrunch

The LAPD, one of Flock's biggest government customers, is ending its contract with the company citing civil liberties concerns.

95
12
76
0
Open post
Martin @mshelton@mastodon.social
· 4mo ago
Next time you hear lawmakers talking about limiting your right to use a VPN, because they want age verification, my colleague Caitlin Vogus and I want you to share this. https://freedom.press/issues/how-journalists-rely-on-vpns-to-protect-press-freedom/
freedom.press
103
0
102
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago
Boosted by @tchambers@indieweb.social
If you use Signal to work with sensitive contacts, it’s not a “set it and forget it” app. You do need to maintain the safety of your account. Fortunately it's pretty easy to do. Check out our guide: https://freedom.press/digisec/blog/signal-account-safety/
freedom.press
46
4
57
1
Open post
Martin @mshelton@mastodon.social
· 3w ago
"This camera is missing Android security updates for the last eight years." https://micahflee.com/flock-cameras-are-riddled-with-security-vulnerabilities-and-hard-coded-credentials/
Flock cameras are riddled with security vulnerabilities and hard-coded credentials
micahflee

Flock cameras are riddled with security vulnerabilities and hard-coded credentials

This morning, DDoSecrets published an exciting new dataset: Filesystem images of the partitions from an in-use Flock ALPR camera. 404 Media and Wired published a joint investigation into it. I downloaded the dataset and am now thoroughly nerd-sniped. Hackers from a collective called stegan0gram collected the data. “Why

3
1
2
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago
Replying to
Signal's recent disclosure of how little it could share in response to a grand jury subpoena is pretty telling. Its defaults are very strong. But if you want to go further, we have a guide on really how to really maximize its privacy settings. https://freedom.press/digisec/blog/locking-down-signal/
freedom.press
170
1
170
1
Open post
Martin @mshelton@mastodon.social
· 3mo ago
If you or me download a copyrighted work from the web, it's piracy. So don't do that. But if you pirate the entire public internet, including copyrighted works, that's actually okay. So long as you use it to train LLMs and start a company.
38
5
34
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago

Hoo boy. I am analyzing this to learn more about how it happened. I will have a writeup about how newsrooms can prevent Signal username hijacking risks. https://www.dropsitenews.com/p/intercept-signal-tip-line-breach-hack

A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers
dropsitenews.com

A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers

The news outlet changed its tip line this week, but has not informed potential sources or the public of the breach.

30
8
34
1
Open post
Martin @mshelton@mastodon.social
· 3mo ago

I don't know how any AI companies can justify being upset when someone copies content from them to train their models. https://arstechnica.com/tech-policy/2026/06/anthropic-claims-alibaba-defied-trump-to-attack-claude-and-steal-capabilities/

arstechnica.com
25
7
13
0
Open post
Martin @mshelton@mastodon.social
· 2mo ago
Replying to
Let's say you let someone take a driving test and found along the way that they have a tendency to occasionally try ramming other cars off the road to get where they're trying to go. They would probably not be allowed to have a license.
16
0
3
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago

I’ve been seeing misinformation about Signal related to the recent news about an FBI investigation into ICE protesters in Minneapolis who used Signal group chats to organize. The misinfo goes something like this: The FBI sees your Signal messages, it must be compromised. This is wrong.

If you have a public group, anyone can join. If someone’s phone is compromised or seized, yes, they can read your messages just like you can. No app can protect against that. https://www.nbcnews.com/tech/internet/fbi-investigating-minnesota-signal-minneapolis-group-ice-patel-kash-rcna256041

nbcnews.com
25
2
29
0
Open post
Martin @mshelton@mastodon.social
· 2mo ago
New research points to another easy way to conduct prompt injection attacks: LARPing. Talk like an LLM in a prompt. The LLM may interpret this part of the prompt as its own "thinking." Imagine an agent running on your browser or computer being exploited in this way. I wrote about how newsrooms should approach this and overlapping issues in our newsletter. https://freedom.press/digisec/blog/the-s-in-llm-stands-for-security/
freedom.press
13
0
12
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago

On top of boiling the ocean, the price of the Steam Machine means I will forever curse AI companies.

18
0
8
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago

This is basically how I feel about these chatbots. They can be fun. But ultimately they are software operating on behalf of a company. They’re not doing this for free. https://techcrunch.com/2026/06/20/signals-meredith-whittaker-wants-you-to-remember-that-ai-chatbots-are-not-your-friends/

techcrunch.com
17
2
12
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago

I am really excited to see what developers do with this. We could see a lot more end-to-end encrypted communication and collaboration tools. https://www.wired.com/story/signal-alums-release-encrypted-spaces-a-new-system-for-building-private-collaboration-apps/

wired.com
17
0
11
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago
Fun reminder that you don't need to give any of these companies your ID, or your data. If you must use a model, you can always run it locally on your own device — no state-mandated ID required. https://techcrunch.com/2026/06/22/anthropic-says-claude-may-want-to-see-your-id/
Anthropic says Claude may want to see your ID | TechCrunch
TechCrunch

Anthropic says Claude may want to see your ID | TechCrunch

Claude's chatbot may ask to verify your age and identity "in certain circumstances," such as with a passport or driver's license, according to a privacy policy change.

14
6
9
0
Open post
Martin @mshelton@mastodon.social
· 8mo ago

We're getting a lot of questions about Signal group chats, and how to use them as safely as possible. Share widely! https://freedom.press/digisec/blog/signal-group-safety/

freedom.press
61
0
92
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago

We wrote a couple of things here:
https://freedom.press/digisec/blog/signal-account-safety/
https://freedom.press/digisec/blog/lessons-from-the-intercepts-signal-tipline-username-breach/

freedom.press
10
0
7
0
Open post
Martin @mshelton@mastodon.social
· 2mo ago
Replying to
This isn’t really a ‘whoopsie.’ We’re developing norms for how companies are (and are not) held accountable when their employees make decisions about guardrails.
5
0
1
0
Open post
Martin @mshelton@mastodon.social
· 6mo ago

I found this discussion with the @eff@mastodon.social's executive director, Cindy Cohn, really inspiring. Whether fighting for free speech or against surveillance, underneath is a fight about optimism. What kind of Internet do WE want? https://www.youtube.com/watch?v=QkC1aK7jfLo

Cindy Cohn - Fighting for Digital Human Rights in “Privacy’s Defender” | The Daily Show

21
0
11
0
Open post
Martin @mshelton@mastodon.social
· 3mo ago

Microsoft constantly demonstrates that the killer app is maintenance and stability. They aren't good at those things. https://www.windowslatest.com/2026/06/25/windows-10-support-quietly-extended-until-oct-2027-as-users-reject-windows-11/

windowslatest.com
7
2
5
0
Open post
Martin @mshelton@mastodon.social
· 6mo ago

It takes engineering hours to remove a feature. Even if few people use it, why go out of your way to remove it? Meta’s hurting its users. And for what? https://www.theverge.com/tech/894752/instagram-end-to-end-encryption

theverge.com
22
10
27
0
Open post
Martin @mshelton@mastodon.social
· 6mo ago

"It depends."

— Ancient Security Proverb

18
2
11
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

Good news for once. https://www.washingtonpost.com/national-security/2026/02/24/washington-post-reporter-search/

washingtonpost.com
22
1
11
0
Open post
Martin @mshelton@mastodon.social
· 6mo ago

I'm a bit late to the game on this one. But I work with a lot of journalists who use CapCut for video editing and their terms of service says you are giving them an "unconditional, irrevocable, non-exclusive, royalty-free, fully transferable (including sub-licensable), perpetual, worldwide license" to use your content and… I have to imagine most journalists are not aware of that. https://www.capcut.com/clause/terms-of-service

capcut.com
17
1
17
0
Open post
Martin @mshelton@mastodon.social
· 2mo ago

The weird timeline keeps getting weirder. https://www.wired.com/story/openai-models-escaped-containment-and-hacked-huggingface/

wired.com
3
0
2
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

This sounds like a killer job for someone who cares about privacy and getting the bag. Help Signal keep doing their critical work. https://jobs.lever.co/signal/68f75269-fe43-4d25-8d82-69439351f14d

jobs.lever.co
18
0
20
0
Open post
Martin @mshelton@mastodon.social
· 5mo ago

VPN users in the U.S.: Did you know that using a VPN may subject you to foreign intelligence spying?https://freedom.press/digisec/blog/vpn-surveillance-time-for-transparency-and-limits-on-spy-powers/

freedom.press
11
1
8
0
Open post
Martin @mshelton@mastodon.social
· 6mo ago

Well I got all bent out of shape about Proton Mail. There are valid use cases for these tools but users should know what the service can and can't protect. https://freedom.press/digisec/blog/proton-mail-is-not-for-anonymity/

freedom.press
11
0
7
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

I’m wondering how Windows can get more hostile to its users. Perhaps they can send over Steve Ballmer to punch me in the gut every time I turn on a Windows device. https://tech4gamers.com/windows-12-reportedly-relasing-2026-modular-ai-focused-os/

Windows 12 Reportedly Set for Release This Year as a Fully Modular, Subscription-Based, AI-Focused OS
Tech4Gamers

Windows 12 Reportedly Set for Release This Year as a Fully Modular, Subscription-Based, AI-Focused OS

Reports suggest that Microsoft may be gearing up to launch Windows 12 this year, which will be a modular and AI-focused OS.

10
0
2
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

The Justice Department seems like they are having a very difficult time keeping their facts straight with judges, part eleventy thousand. https://www.cnn.com/2026/02/20/politics/judge-rips-washington-post-fbi-reporter-warrant

cnn.com
10
1
12
0
Open post
Martin @mshelton@mastodon.social
· 6mo ago

SecureDrop inbox has a lot of new improvements that should help newsrooms move more quickly when working with tips. Check out the @securedrop@social.freedom.press team's announcement post: https://securedrop.org/news/new-features-in-securedrop-inbox/

securedrop.org
6
0
6
0
Open post
Martin @mshelton@mastodon.social
· 6mo ago
Sam Altman: ‘If I Don’t End The World, Someone Far More Dangerous Will’
The Onion

Sam Altman: ‘If I Don’t End The World, Someone Far More Dangerous Will’

5
0
2
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

Baby me: PGP, wow cool, hacker stuff
Grey hairs me: I will decrypt this and reply with my Signal. I'm so damn tired

6
0
1
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago
Replying to
About five years ago we learned that Proton shared the IP address associated with a French climate activist with Swiss police, who passed it along to French police. Again, Proton is not for anonymity. https://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities/
techcrunch.com
5
1
7
0
Open post
Martin @mshelton@mastodon.social
· 5mo ago

Journalists sometimes ask us, is my employer watching what I do on my laptop or tracking my whereabouts at work?

Sorry, I'm giving the classic "it depends" security person response. Check out our advice column on the topic. https://freedom.press/digisec/blog/ask-a-security-trainer-is-my-computer-being-monitored-at-work/

freedom.press
3
0
2
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

OpenAI is saying, here are the laws that make this decision okay. Then they go on to list a series of laws that creative lawyers are taking advantage of to enact surveillance both internationally, and domestically. I'm not sure this is the kind of defense they think it is. https://openai.com/index/our-agreement-with-the-department-of-war/

openai.com
5
1
5
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

"We made sand think."

I mean, no, we didn't. But let's say we did — what a very rude to do to those innocent computers.

4
0
1
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

I don’t use Kalshi or Polymarket but this is what I imagine they’re like

4
0
1
0
Open post
Martin @mshelton@mastodon.social
· 7mo ago

If you are a journalism instructor and want to get started teaching digital security for your students, we'd love to show you how. Sign up for our training for journalism educators. https://docs.google.com/forms/d/e/1FAIpQLSdxFwfKJkj6zNlJTvVwev-w1HvMmuaXxqnulkDeivWcpxhsmw/viewform

docs.google.com
3
2
11
0
Open post
Martin @mshelton@mastodon.social
· 26mo ago

The @tails@fosstodon.org team collaborated with our @freedomofpress@newsie.social colleague Alex Pyrgiotis on making it as easy as possible to install @micahflee@infosec.exchange's @dangerzone@fosstodon.org as additional software within Tails. Awesome news for anyone working with risky documents. https://tails.net/news/dangerzone/index.en.html

tails.net
19
1
17
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 06:58:47 UTC