메뉴
BL
Wired AI 11일 전

생리 주기 앱, 당신의 개인정보를 감시하고 있다

IMP
7/10
핵심 요약

Mozilla 재단의 감사 결과, 대부분의 인기 생리 주기 추적 앱이 사용자의 민감한 건강 데이터를 제3자와 무단으로 공유하는 것으로 나타났습니다. 이와 함께 샌프란시스코 경찰국의 드론 감시 문제, 여성을 표적으로 한 딥페이크 합성 앱 규제, 거대 기업들의 AI 법제화 촉구 등 보안과 프라이버시를 위협하는 주요 이슈들이 한자리에서 다뤄졌습니다.

번역된 본문

샌프란시스코 경찰국의 드론 동영상 영상이 공개된 웹에 노출된 사건은, 매우 세밀하고 결과가 치명적인 도시 감시의 새로운 시대를 보여줍니다. 이와 동시에 샌프란시스코 시 법무관 사무소는 이번 주 애플과 구글에게 기술 거대 기업들이 자사 앱 스토어에서 여성과 소녀들을 표적으로 삼는 데 거의 독점적으로 사용되는 13개의 AI 나체화 '안면 인식 합성(face-swap)' 앱을 삭제하라고 요구하는 내용의 정지 및 경고 서한을 보냈습니다. 와이어드(WIRED)가 6월에 메타(Meta)의 NameTag 안면 인식 시스템을 처음 보도한 이후, 회사 경영진은 이 기능이 실제로 존재하는지에 대해 불투명하고 모순된 발언을 해왔습니다. 우리는 한 발짝 물러서서 이 매우 현실적인 시스템에 대한 주장과 사실을 정리해 보았습니다. 목요일 연설에서 도널드 트럼프 대통령은 2020년 미국 대선 개입에 대한 근거 없고 완전히 반박된 주장을 계속해서 펼쳤습니다. 그는 백악관 웹사이트에 게시된 대량의 문서에서 엄청난 폭로를 약속하기까지 했지만, 해당 파일들은 그의 주장을 증명하지 못했으며 오히려 트럼프의 주장과 모순되는 경우도 있었습니다.

AI 도입이 빠르게 확대되고 그 기능이 향상됨에 따라, 기술 거대 기업인 앤스로픽(Anthropic)은 미국 각주가 AI를 규제하도록 촉구하는 움직임을 계속 이어가고 있습니다. 앤스로픽의 미국 주 및 지방 정부 관계 책임자인 세자르 페르난데스(Cesar Fernandez)는 이번 주 와이어드와의 인터뷰에서 작년 캘리포니아와 뉴욕의 AI 투명성 요구 사항에 대해 언급하며 이렇게 말했습니다. "2025년의 투명성 중심의 안전 법안은 매우 중요한 시작이었지만, AI 시스템의 기능이 계속해서 빠르게 발전함에 따라 정책적 대응도 이에 발맞춰야 합니다." 또 다른 소식들도 있습니다. 매주 우리는 심층적으로 다루지 못한 보안 및 개인정보 보호 뉴스를 모아서 전해 드립니다. 전체 기사를 읽으려면 헤드라인을 클릭하세요. 그리고 밖에서 안전하게 지내시길 바랍니다.

모질라(Mozilla), 생리 주기 추적 앱의 프라이버시 등급 평가... 단 한 곳만 통과 BBC가 하버드 버크만 클라인 센터와의 협력으로 인기 생리 주기 추적 앱 6종에 대한 모질라 재단의 감사 결과를 가장 먼저 보도한 바에 따르면, 별자리 테마의 생리 추적 앱인 '스타더스트(Stardust)'는 피임약 종류, 임신 상태, 기분, 유방 압통 및 위 경련과 같은 구체적인 증상에 이르기까지 사용자의 생식 건강 세부 정보를 자체 개인정보 처리방침에 명시되지 않은 데이터 회사로 전송합니다. 스타더스트는 10점 만점에 2점을 받아 그룹에서 가장 최악의 점수를 기록했습니다. 모질라 연구원 쇼샤나 보딘스키(Shoshana Wodinsky)는 사용자가 어떤 정보도 입력하기 전인 앱이 열리는 순간부터 제3자 추적기와 통신한다는 것을 발견했습니다. 그녀가 증상을 기록하는 즉시 해당 세부 정보는 공유를 끌 수 있는 앱 내 기능 없이 영구적인 사용자 ID와 함께 분석 회사인 러더스택(RudderStack)으로 전송되었습니다. 러더스택은 모질라가 관찰할 수 없는 목적지로 데이터를 전달하도록 설계되었습니다. 또한 스타더스트는 앱 내 행동을 페이스북의 기존 프로필과 연결하는 광고 식별자를 페이스북에 제공합니다. 이 회사는 테크크런치(TechCrunch)에 사용자 데이터에 대한 법적 요구를 받은 적이 없다고 밝혔습니다. 반면 비영리 단체가 운영하는 추적 앱인 '에우키(Euki)'는 완벽한 10점을 받았습니다. 이 앱은 계정이 필요 없고 건강 데이터가 휴대폰 외부로 절대 나가지 않으며, 사용자는 PIN을 설정하거나 자동 삭제를 예약하거나 누군가가 휴대폰을 강제로 열 때를 대비해 가짜 화면을 띄울 수 있습니다. 유일한 약점은 교육 페이지용 앱 내 브라우저가 일반적인 웹 추적기를 로드하지만, 방문 사이마다 식별자를 재설정한다는 점입니다.

러시아 연방보안국(FSB), 폴란드 인프라 사이버 공격으로 제재 러시아 연방보안국(FSB)은 오랫동안 고도로 정교한 사이버 간첩 활동으로 악명이 높았으며, 파괴적인 사이버 공격은该国의 군사 정보 기관인 그루(GRU)의 해커들에게 맡겨왔습니다. 하지만 이번 주 EU와 영국의 제재와 함께 미국 사이버보안/인프라보안국(CISA), FBI, NSA의 권고에 따르면 폴란드 전력망에 대한 사이버 공격이 FSB의 '센터 16(Center 16)'에 의한 것으로 지목되었습니다. 이는 크렘린의 기관이 해당 국가의 전기 및 수도 유틸리티 정전을 거의 일으킬 뻔한 사이버 공격을 실행한 희귀한 사례입니다. 폴란드 정부가 대규모 정전을 일으키기 직전이었다고 밝힌 이번 공격은 (후략)

원문 보기
원문 보기 (영어)
Comment Loader Save Story Save this story Comment Loader Save Story Save this story Hours of San Francisco Police Department drone video footage exposed on the open web illustrates a new era of incredibly granular—and consequential—urban surveillance. Meanwhile, the San Francisco City Attorney’s Office sent cease-and-desist letters to Apple and Google this week demanding that the tech giants delete 13 AI nudifying “face-swap” apps from their app stores that are almost exclusively used to target women and girls. Since WIRED first reported in June about Meta’s NameTag face-recognition system, company executives have made opaque and conflicting comments about whether the feature even exists. We took a step back to lay out both the claims and the facts about the very real system. In a speech on Thursday, President Donald Trump continued to push unsubstantiated and thoroughly debunked claims about interference in the 2020 US election. He even promised massive revelations in a trove of documents posted to the White House website, but the files did not prove his assertions—and in some cases actually contradicted Trump’s claims. As adoption of AI tools rapidly expands and their capabilities increase, the tech giant Anthropic continued a push to get US states to regulate AI . Speaking about AI transparency requirements in California and New York from last year, Anthropic’s head of US state and local government relations, Cesar Fernandez, told WIRED this week, “The transparency-focused safety bills of 2025 were a really important start, but as the capabilities of AI systems continue to advance quickly—the policy responses need to match.” And there’s more. Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there. Mozilla Graded Period Trackers on Privacy. Only One Aced It The astrology-themed period tracker Stardust sends users’ reproductive health details—birth control type, pregnancy status, moods, and symptoms as specific as tender breasts and stomach cramps—to a data firm not named in its privacy policy, according to the BBC , which first reported a Mozilla Foundation audit of six popular trackers produced in partnership with Harvard's Berkman Klein Center. Stardust scored 2 out of 10 , the worst of the group. Mozilla researcher Shoshana Wodinsky found the app pings third-party trackers from the moment it opens, before a user enters anything; the instant she logged a symptom, the details went to analytics firm RudderStack alongside a persistent user ID, with no in-app way to shut the sharing off. RudderStack is built to route data onward to destinations Mozilla couldn't observe. Stardust also hands Facebook an ad identifier that ties in-app behavior to the platform's existing profiles. The company told TechCrunch it has never received a legal demand for user data. Euki, a nonprofit-run tracker, earned a perfect 10 : no account required, health data never leaves the phone, and users can set a PIN, schedule automatic deletion, or pull up a decoy screen if someone forces the phone open. Its one soft spot is an in-app browser for educational pages that loads the usual web trackers, but it also resets identifiers between visits. Russia’s FSB Sanctioned for Cyberattack on Polish Infrastructure Russia’s FSB has long had a reputation for highly sophisticated cyberespionage, leaving disruptive cyberattacks to its fellow hackers in the country’s GRU military intelligence agency. But sanctions from the EU and UK this week, along with an advisory from the US Cybersecurity and Infrastructure Security Agency, the FBI, and the NSA, pinned a cyberattack against the Polish electric grid on Center 16 of the FSB, a rare example of the Kremlin agency carrying out a cyberattack that nearly caused outages in the country’s electric and water utilities. The attack, which the Polish government has said came “very close” to causing a blackout, was initially attributed by cybersecurity firms Dragos and ESET to Sandworm , also known as Unit 74455 of the GRU, a more usual suspect in infrastructure hacking given its active role in Russia’s long-running cyberwar against Ukraine. But the Polish computer emergency response team at the time disputed that finding and tied the attack to the FSB, a conclusion now supported by a wide consensus of Western governments. The incident suggests that the FSB may be taking on some of the reckless, highly aggressive tendencies—and targeting—of its GRU coworkers. An Alleged Russian State-Sponsored Hacker Worked for Kaspersky For years, the Russian cybersecurity firm Kaspersky has been alleged to have ties to the Russian government, including by US officials who banned use of the company’s products within the US government and eventually by all American customers. Yet overt evidence of those connections has been scarce. Now Reuters reports that Denis Obrezko, a Russian man facing hacking charges in Boston and an alleged member of a hacker group known as Void Blizzard or Laundry Bear, spent two years working at Kaspersky. His stint at the company took place just before he joined another cybersecurity company, Yutek-NN, where he allegedly took part in the group’s hacking campaign that stole data and communications from numerous NATO governments and at least 11 US companies, according to US prosecutors. Prior to Kaspersky, Obrevko also allegedly worked at the FSB, neatly bookending his time at the company with apparent work for Russia’s intelligence services. Obrevko has pleaded not guilty to the hacking charges. Kaspersky responded in a statement to Reuters that “the offenses charged cannot be related to the individual’s role or responsibilities during the employment at Kaspersky.” A Real DHS Breach Was Twice Ruled a False Positive In an incident that will induce anxiety in anyone responsible for assessing suspicious network activity, DHS officials ruled—twice—that signs of a hacker breach in its data-sharing Homeland Security Information Network platform were false positives when they were, in fact, signs of a very real intrusion. HSIN, used for sharing unclassified data between state, local, and federal agencies, as well as foreign partners, was breached by hackers two months ago, according to reporting from Nextgov/FCW. Analysts at the Federal Emergency Management Agency spotted signs of hacker activity in mid-May—altering files and code, hijacking a legitimate web server, and deleting logs of their behavior—but the findings were dismissed as a false positive. In the weeks that followed, the hackers returned, were again detected, and were again dismissed as a mirage. It’s not clear why the signs of the breach were misjudged, but the incidents may represent federal analysts’ increasing challenges in detecting “living off the land” hacking techniques that use legitimate features of networks to access target assets on a network rather than planting more easily spotted malware. While the HSIN houses only unclassified data, the information is “highly sensitive,” Senate Intelligence Committee vice chair Mark Warner said in a statement following the report of the breach, and “its exposure risks national security.” Hack Exposes an AI Music Generator’s Scraping Secrets The AI music startup Suno scraped millions of songs, lyrics, and podcasts from YouTube Music, Deezer, Genius, and a string of stock-audio libraries to train its models, according to 404 Media, which reviewed internal data provided by a hacker who breached the company. The intrusion also exposed account information for hundreds of thousands of customers, including emails, phone numbers, and Stripe payment records. Dataset notes in source code apparently from 2023 and 2024 tally 113,879 hours of YouTube Music audio alone, plus tens of thousands more from Pond5, Deezer, and other libraries—decades of music in total. Other files show Suno routing its YouTube scraping through Bright Dat