Elektrine
Log in Register
Paige Chat Timeline Gallery Friends Email Drive DNS Private DNS Domains VPN Kairo Nerve
Remote

Wolfie Christl

@wchr@mastodon.social
mastodon 4.8.0-nightly.2026-10-06
  • Open on mastodon.social

Public-interest researcher https://crackedlabs.org | Tech and society. Tracking, surveillance, consumer data, platform power, algorithmic decisions, datafication of work.

https://wolfie.crackedlabs.org/en

5098 Followers
262 Following
45 Posts
Joined November 01, 2016
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
This screen, from a leaked 2021 document, shows how Webloc tracked a person travelling from Germany via Austria to Hungary. The system obtains the data from everyday consumer apps installed on phones. The data is tied to mobile device IDs typically used for ad targeting, which identify a phone and its owner. The systematic misuse of this data for tracking and profiling in digital marketing is already highly problematic. Misusing it for government surveillance is another level of disastrous.
145
14
143
2
Open post
Wolfie Christl @wchr@mastodon.social
· 3mo ago
Public records confirm that the Austrian Ministry of the Interior bought Webloc, a geolocation mass surveillance system based on data from mobile apps and digital advertising = almost certainly illegal under the GDPR. Austria is now - after Hungary - the second EU state known to use such a system. https://mastodon.social/@wchr/116817729453918994
Open quoted post
Quoting
Wolfie Christl
@wchr@mastodon.social
Ein EU-Vergabedokument bestätigt: das österreichische Innenministerium kauft große Mengen hochsensibler Daten von Smartphone-Apps über die Standorte, Bewegungen und andere Verhaltensweisen der halben Bevölkerung für: Überwachungszwecke. Vermutlich schon seit 2024, illegal nach der DSGVO, verfassungsrechtlich fragwürdig. https://www.derstandard.at/story/3000000329055/was-macht-das-innenministerium-mit-einer-ueberwachungssoftware-die-auch-die-us-behoerde-ice-einsetzt
Open quoted post
mastodon.social
27
0
56
1
Open post
Wolfie Christl @wchr@mastodon.social
· 4mo ago

At least one German state-level criminal police department (LKA) purchased location data from digital advertising for surveillance, despite lacking a lawful basis, prompting an investigation by the state's data protection authority.

Highly problematic on many levels:
https://netzpolitik.org/2026/daten-schwarzmarkt-deutsche-polizei-nutzt-offenbar-rechtswidrig-databroker/

netzpolitik.org
32
1
44
1
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
Alongside our report, Hungarian journalist Szabolcs Panyi publishes a VSquare investigation which reveals that Hungarian domestic intelligence has used Webloc since at least 2022, and still does today. This is the first confirmation of the use of ad-based surveillance technology in Europe: https://vsquare.org/orban-spying-toolkit-cobwebs-webloc-hungary-spyware-citizen-lab
vsquare.org
47
4
68
1
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago

Last week, we at The Citizen Lab and VSquare exposed Hungarian intelligence’s use of Webloc, an ad-based surveillance system based on mobile app data.

Update: The Hungarian GDPR regulator told us it's launched an investigation into the matter. A great first step.

I hope Hungary's new govt secures the mandate and independence of its regulator.

Other European data protection authorities must follow and investigate ad-based surveillance firms and their data supply chains:
@wchr@mastodon.social

mastodon.social
22
1
20
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
i and my colleagues at the University of Toronto's Citizen Lab spent months investigating Webloc, its capabilities and customers, based on public records, leaked docs, freedom of information requests and technical analysis. Webloc is an add-on to the social media and web intelligence system Tangles, both developed by Israeli Cobwebs Technologies and since 2023 sold by US-based vendor Penlink.
23
1
19
0
Open post
Wolfie Christl @wchr@mastodon.social
· 7mo ago
Das österreichische Innenministerium hat die Socialmedia-Überwachungssoftware 'Tangles' des umstrittenen Anbieters Cobwebs/Penlink gekauft und macht daraus ein Staatsgeheimnis. Das Ministerium weigert sich, zu beantworten, ob auch das Tangles-Zusatzmodul 'Webloc' gekauft wurde, das eine Art von Massenüberwachung auf Basis von Werbe- und Smartphone-Daten über die halbe Bevölkerung ermöglicht. Ausführlicher Artikel von @suka_hiroaki@chaos.social im Standard: https://www.derstandard.at/story/3000000309258/innenministerium-nutzt-ueberwachungssoftware-von-zwielichtiger-firma-will-nicht-darueber-reden
derstandard.at
34
0
63
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
Trapdoor has rarely been reported or mentioned anywhere. We discovered a Vietnamese requirements doc and servers located in Kenya and Indonesia that display Trapdoor login pages, which contain publicly available Javascript code for its admin interface. The source code and the doc suggest that Trapdoor can help send phishing links that lead to fake web pages, which can open hidden tabs in the browser, extract passwords, access camera and microphone, and even deliver "files or payloads".
19
1
18
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
Our research shows that Webloc was used by El Salvador National Civil Police. In the US, it is or was used by ICE, the US military, Texas Department of Public Safety, DHS West Virginia and several police departments in Los Angeles, Dallas, Baltimore, Tucson, Durham down to smaller cities/counties like City of Elk Grove and Pinal County. Public records indicate that an even larger number of US federal, state and local agencies bought Tangles. Some of them might also use the Webloc add-on.
19
5
14
0
Open post
Wolfie Christl @wchr@mastodon.social
· 7mo ago

"Burger King is launching an AI chatbot that will live in the headsets used by employees [and will] evaluate their interactions with customers for 'friendliness,' ... recogniz[ing] certain words and phrases, such as 'welcome to Burger King,' 'please,' and 'thank you.' ... the company is 'iterating' on capturing the tone of conversations as well"

Horrible. At least the latter is probably illegal under the EU's AI act.
https://www.theverge.com/ai-artificial-intelligence/884911/burger-king-ai-assistant-patty

theverge.com
25
8
27
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
Another screen from the same 2021 doc shows how Webloc tracked a male person in Abu Dhabi, who has 141 apps installed on his phone, some of which sent 81 GPS location records to the system over the past 5 days. He was also located based on Wi-Fi access points nearby his phone 110 times. The activity graph on the right bottom indicates that the system tracked his location up to 12 times a day. The code shown at the right top is the so-called 'Advertising ID' that identifies his mobile device.
18
1
17
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
Penlink claims that Webloc doesn't process age, gender & ad targeting categories anymore today but 'merely' location records tied to device identifiers. Location data can reveal a person's home, workplace, family, friends, habits, interests and more. Misusing it for government surveillance is highly problematic. Another 2021 screen shows how Webloc displays location records in Street View, all of them possibly associated with a person who was frequently located in front of a certain house.
17
7
12
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
We also investigate corporate networks. Cobwebs Technologies, founded in 2015 by former members of IDF special forces and intel units, merged with Penlink in 2023/24. Cobwebs' founder and long-term president, who now oversees Penlink's global operations, holds an indirect interest in the spyware vendor Quadream. A former Cobwebs exec and investor is a key investor in Quadream, whose spyware was used to target civil society, journalists and political opposition figures: https://citizenlab.ca/research/spyware-vendor-quadream-exploits-victims-customers/
citizenlab.ca
16
0
22
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
Here's how Webloc displayed a targeted person's profile information in 2021, in this example a Hungarian who used a Samsung S8 phone with the language set to English. The profile also lists “user segments” typically used in digital advertising, which can be much more sensitive than the ones shown here.
14
8
12
0
Open post
Wolfie Christl @wchr@mastodon.social
· 7mo ago

The Austrian Ministry of the Interior bought social media surveillance software Tangles from Cobwebs/Penlink and refuses to tell the public whether they also bought the intrusive geolocation tracking add-on Webloc, which relies on the mass collection of personal data from digital advertising and mobile apps.

Public record on the €900k Tangles contract:
https://ted.europa.eu/en/notice/-/detail/17316-2025

German-lang article by @suka_hiroaki@chaos.social:
https://www.derstandard.at/story/3000000309258/innenministerium-nutzt-ueberwachungssoftware-von-zwielichtiger-firma-will-nicht-darueber-reden

Summary on the Citizen Lab site:
https://citizenlab.ca/austrian-interior-ministry-using-cobwebs-surveillance-software/

ted.europa.eu
18
0
20
0
Open post
Wolfie Christl @wchr@mastodon.social
· 8mo ago

"Companies are offering law enforcement agencies the ability to track smartphone users through advertising data gathered on their devices. Le Monde attended confidential presentations of these new surveillance tools ... According to Le Monde's analysis, around 15 companies, at least, now propose such services"

...feat Penlink, RCS, Wave Guard, Rayzone, Cognyte:
https://www.lemonde.fr/en/pixels/article/2026/01/22/how-surveillance-companies-track-smartphone-users-through-advertising-data_6749674_13.html

lemonde.fr
22
1
54
0
Open post
Wolfie Christl @wchr@mastodon.social
· 3mo ago
Replying to
Sowohl meine Anfrage nach dem Informationsfreiheitsgesetz als auch eine parlamentarische Anfrage wurden pauschal mit dem Argument abgeschmettert, eine Auskunft gefährde die öffentliche Sicherheit. Nun steht's schwarz auf weiß in einem öffentlichen Vergabedokument, warum auch immer das diesmal nicht redigiert wurde. Bekannt gegeben wurde eine 2jährige Vertragsverlängerung für Tangles und Webloc ab Mai 2026. Verlängerung bedeutet: Webloc war auch schon zuvor im Einsatz, vermutlich ab Ende 2024.
4
1
3
0
Open post
Wolfie Christl @wchr@mastodon.social
· 3mo ago
Replying to
Webloc bietet laut unseren Recherchen Zugriff auf Daten über bis zu 500 Mio Menschen weltweit, bis zu 3 Jahre in die Vergangenheit. Das System dient u.A. der Ortung von Personen und erstellt Bewegungsprofile. Das ermöglicht Rückschlüsse über Wohnort, Arbeitsplatz, Familie, Freunde und viele andere sensible Verhaltensweisen und Lebensbereiche. Der Screenshot stammt aus einem geleakten Dokument und zeigt, wie das System eine Person tracked, die von Deutschland über Österreich nach Ungarn reist.
4
5
5
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
We also did some technical research. After receiving a tip from Amnesty Security Lab's @DonnchaC, we identified 219 active servers located in at least 21 countries that we consider to be associated with deployments of Tangles, Webloc or other products developed by Cobwebs Technologies. Those servers are located in the US, UK, NL, DE, FR, SE, NO, IE, CY, AU, SP, MX, CO, SG, HK, ID, IN, IL, AE, IQ, KE, many of them hosted via MS Azure. 115 of them displayed a Tangles login page in the browser.
11
3
9
1
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to
There might be other Webloc customers. In Europe and the UK, we sent 96 freedom of information requests to law enforcement agencies in 14 countries and to 6 EU bodies. Many were rejected or received no response. Some responses are interesting, including those from Europol, the UK Home Office and the Swedish Police Authority. We believe that further research would also be fruitful with respect to potential Webloc purchases in Italy, Netherlands, Austria, Israel, Mexico, Vietnam and Singapore.
11
1
9
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago

Last week, we published a Citizen Lab report on the ad-based location surveillance system Webloc, its capabilities and its customers (https://citizenlab.ca/research/analysis-of-penlinks-ad-based-geolocation-surveillance-tech/).

Webloc obtains data from consumer apps installed on phones. How? We don't know.

But the ad targeting segments shown in this 2021 Webloc screenshot caught my eye:

Uncovering Webloc: An Analysis of Penlink’s Ad-Based Geolocation Surveillance Tech
The Citizen Lab

Uncovering Webloc: An Analysis of Penlink’s Ad-Based Geolocation Surveillance Tech

Location data collected from mobile apps and digital advertising can reveal habits, interests and almost any other aspect of someone's life. In this report, we uncover how a geolocation surveillance system called Webloc uses ad-based data to monitor hundreds of millions of people across the globe.

9
3
15
0
Open post
Wolfie Christl @wchr@mastodon.social
· 6mo ago
Replying to

We briefly investigated two other Cobwebs products:

  • Lynx, which helps facilitate undercover ops on the web and manage fake accounts

  • Trapdoor, which appears to help trick people into revealing information. Our analysis leads us to believe that it can help facilitate the deployment of malware on devices

We do not know whether Trapdoor and Lynx are still being sold by Penlink.

9
2
10
0
Open post
Wolfie Christl @wchr@mastodon.social
· 41mo ago

"Microsoft Edge sends a request to bingapis .com with the full URL of nearly every page you navigate to"

Microsoft secretly tracks people across myriads of websites/apps via pixel. Now it was caught tracking them directly in the browser, by default. Wild.
https://www.theverge.com/2023/4/25/23697532/microsoft-edge-browser-url-leak-bing-privacy

Microsoft Edge is leaking the sites you visit to Bing
The Verge

Microsoft Edge is leaking the sites you visit to Bing

Microsoft says it’s investigating reports of an Edge privacy issue.

278
51
376
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to
The Hungarian data protection agency and other European GDPR regulators must proactively investigate ad-based surveillance firms and their data supply chains, from apps to data brokers and other intermediaries. I hope the new Hungarian government secures the mandate and independence of its GDPR regulator.
6
2
2
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to
While data processing by app vendors, intermediaries and surveillance tech vendors is regulated by the GDPR, the use of the data by governments for public safety and national security purposes is subject to separate and varying national legislation in Europe and the UK. Reports suggest that its lawfulness is questionable and it lacks adequate oversight in several countries: https://www.interface-eu.org/publications/disproportionate-use-commercially-and-publicly-available-data-europes-next-frontier https://www.ftm.nl/artikelen/toezicht-veiligheidsdiensten-osint https://netzpolitik.org/2025/sicherheitsbehoerden-und-databroker-bundesregierung-macht-datenkauf-zum-staatsgeheimnis/
interface-eu.org
6
0
3
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to

More broadly:

  • The consumer data ecosystem, from mobile apps to digital advertising, is out of control, and needs to be fixed. (rather than the law, as suggested by EU deregulation advocates)

  • GDPR enforcement is broken at several levels and needs to be improved (rather than abandoned)

6
1
3
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to

Under the GDPR, the lawfulness of using this data is controversial even for targeted advertising purposes.

It's unlikely that apps, intermediaries and surveillance firms have a legal basis under the GDPR to share the data with governments for surveillance:

  • I think that mobile app vendors, intermediaries and surveillance firms cannot rely on valid consent, because no app obtains specific and informed consent for sharing the data for government surveillance purposes.
6
6
3
0
Open post
Wolfie Christl @wchr@mastodon.social
· 2mo ago
RE: https://mediapart.social/@mediapart/117015804050588276 Penlink's ad-based mass surveillance system Webloc, whose use by government agencies like ICE and Hungarian domestic intelligence is highly controversial, was offered to French businesses (!) via the security contractor Amarante, and deployed for the benefit of a subsidiary of the French luxury goods giant LVMH, according to an investigation by @yphilippin@mediapart.social and @AnttonRouget@piaille.fr:
mediapart.social
1
0
4
0
Open post
Wolfie Christl @wchr@mastodon.social
· 3mo ago
Replying to
Worum gehts? Um die werbedatenbasierte Überwachungssoftware Webloc. Ich hab kürzlich eine Studie geleitet, die ausgerechnet genau dieses System untersucht - im April veröffentlicht vom Citizen Lab an der Uni Toronto. Wir haben Ungarn als erstes EU-Land identifiziert, das Webloc einsetzt. Nun also auch Österreich.' https://citizenlab.ca/research/analysis-of-penlinks-ad-based-geolocation-surveillance-tech/
Uncovering Webloc: An Analysis of Penlink’s Ad-Based Geolocation Surveillance Tech
The Citizen Lab

Uncovering Webloc: An Analysis of Penlink’s Ad-Based Geolocation Surveillance Tech

Location data collected from mobile apps and digital advertising can reveal habits, interests and almost any other aspect of someone's life. In this report, we uncover how a geolocation surveillance system called Webloc uses ad-based data to monitor hundreds of millions of people across the globe.

2
9
2
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to
The system we examined was used in Hungary since 2022, and still is today. Leaked docs suggest that unknown parties used it to track people in Germany, Austria, Hungary, Italy and Romania already in 2021. In my personal view, the above analysis suggests a blatant violation of the rights and freedoms of many Europeans who use a phone with apps installed. The misuse of consumer data for ad targeting is already bad. Misusing it for government surveillance is another level of disastrous.
5
3
2
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to
  • In addition to purpose limitation, the data processing likely also violates proportionality, fairness and other GDPR principles.

  • Even if such a system is used to track only a few individuals, it still processes personal data on a large number of data subjects, and retains it for months or years.

  • Such a system performs extensive profiling and almost certainly processes special category data inferred from location records.

5
5
2
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to
The vendor we examined in our report claims to obtain location records tied to device identifiers from "providers who obtain user consent for location data sharing through SDKs", i.e. through third-party tracking software embedded in apps; we don't know whether directly or indirectly via data brokers, advertising firms or other intermediaries.
4
7
2
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to
  • Our report shows that such as system is used for identification. Location records reveal homes, workplaces, associates and more. The use of pseudonymous IDs doesn't mitigate the risks; quite the opposite, as ad IDs are widely linked to names, email etc across the industry.

  • It's unlikely that vendors can rely on any other legal basis than consent. The only other way to legitimize their processing would require govts imposing far-reaching legal obligations to share the data for surveillance.

4
4
1
0
Open post
Wolfie Christl @wchr@mastodon.social
· 7mo ago

"A security researcher has identified 287 Chrome extensions that allegedly exfiltrate browsing history data for an estimated 37.4 million installations"

Recipients include data brokers like Similarweb, roughly 1% of Chrome users affected. Just don't use browser extensions 😢

Article:
https://www.theregister.com/2026/02/11/security_researcher_287_chrome_extensions_data_leak/

Original report:
https://github.com/qcontinuum1/spying-extensions/blob/main/report.pdf

theregister.com
5
2
13
0
Open post
Wolfie Christl @wchr@mastodon.social
· 27mo ago
Replying to
Ironically, they identified, for example, the home address and travel routes of a person working in the so-called 'tin can' building on a site operated by the German federal intelligence agency BND. The NSA used this building for its mass surveillance programs according to the Snowden leaks. Now any criminal or Russian/Chinese agency can easily buy location records on people who work at military bases or intelligence sites in Germany and other countries from the marketing surveillance industry.
41
4
42
0
Open post
Wolfie Christl @wchr@mastodon.social
· 19mo ago

So, after trying to bankrupt Hondoras by suing the country for $11 billion because of their extraterritorial private city project, Thiel and other oligarchs now want the Trump/Musk regime to create tax-exempt 'freedom cities' in the US where "clinical trials, nuclear reactor startups [etc] can proceed without having to get prior approval from agencies like the Food and Drug Administration, the Nuclear Regulatory Commission, and the Environmental Protection Agency":
https://www.wired.com/story/startup-nations-donald-trump-legislation/

wired.com
22
4
32
0
Open post
Wolfie Christl @wchr@mastodon.social
· 7mo ago

Former OpenAI researcher Zoë Hitzig is of course right to worry about the fate of the stated 'principles' of ads not interfering with responses etc in the next iteration.

Even more remarkable, she quotes German worker co-determination as inspiration for a possible solution: https://www.nytimes.com/2026/02/11/opinion/openai-ads-chatgpt.html

nytimes.com
4
1
5
0
Open post
Wolfie Christl @wchr@mastodon.social
· 8mo ago

ICE "agents are tapping into a database, built by the data analytics company Palantir, that combines government and commercial data to identify real-time locations for individuals they are pursuing, the current and former officials said"
https://www.nytimes.com/2026/01/30/technology/tech-ice-facial-recognition-palantir.html

nytimes.com
4
1
10
0
Open post
Wolfie Christl @wchr@mastodon.social
· 5mo ago
Replying to
The ICE contractor, a defense firm called Edge Ops, promotes 'Project SAFE HAVEN' as an AI surveillance system to "map illegal migrants" and "identify, locate, and map both illegal migrants and the criminals who have crossed into the U.S. over the past several years" based on "years" of "non-traditional" data. https://edgeops.io/services/
edgeops.io
1
2
0
0
Open post
Wolfie Christl @wchr@mastodon.social
· 36mo ago

"Man wird das Gefühl nicht los, dass die Fokussierung auf spekulative, entfernte Zukünfte vor allem einen Zweck erfüllt: von den vielschichtigen, schwierig zu lösenden Gegenwartsproblemen abzulenken"

@ANosthoff@mastodon.social und @fmaschewski@mastodon.social über das "Doomsday-Marketing" der KI-Industrie, die Finanz- und Diskurs­macht rechter Tech-Bros und die ganz realen sozioökonomischen und gesellschaftlichen Risiken:
https://www.republik.ch/2023/10/11/apokalypse-als-businessmodell

republik.ch
12
2
9
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

I2P eepsite

j6b6cyk6gjmepjih7jjadxgxvvf3lzzujljuu2v4biemzpg3naya.b32.i2p

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)

Legal

  • Terms of Service
  • Privacy Policy
  • Transparency Report
  • Report Abuse
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 22:37:25 UTC