Philippe Buschini

Home /Watch/Cybersecurity & Privacy

Cybersecurity & Privacy

I spend a good deal of time following what gets published across several topics. This page brings together the reads I wanted to share rather than leave to gather dust in my bookmarks.

  1. ChatGPT: Humans Can Read Your Conversations Despite Anonymization

    Some conversations with ChatGPT may be read by contractors tasked with assessing the quality of the artificial intelligence’s responses. Revealed by 404Media, the initiative, known as Project Lily, is designed in particular to fine-tune ChatGPT’s personality and correct responses that stray too far from their intended boundaries. However, users are not notified when their conversations are selected. OpenAI says that requests are anonymized before being reviewed. Yet the company acknowledges that this protection has its limits: the algorithm may fail to detect unusual identifying information, or may conceal too much or too little data when it lacks sufficient context. In some cases, contractors may also gain access to memories the AI has retained about the user. This raises particular concerns when conversations contain personal information or messages explicitly asking that an exchange remain private. A setting can nevertheless reduce the risk for future conversations. In the ChatGPT account settings, users need to open the “Data Controls” section and disable the “Improve the model for everyone” option. Enabled by default for Free, Plus and Pro users, this feature allows conversations to be used to improve the models. Disabling it does not apply retroactively to conversations that have already been stored. The same section also allows users to turn off other settings that may provide the AI with personal information, including location data or shared audio recordings. This step therefore limits the future use of conversations, without guaranteeing the deletion or retroactive protection of data already entrusted to the service. Above all, it encourages users to review their privacy settings before sharing sensitive information, while bearing in mind that the stated anonymization process does not eliminate the risk of identification entirely.

    ChatGPTprivacypersonal data Siècle Digital

  2. Pokémon Go, how player scans helped build a military navigation system

    Since 2021, Pokémon Go has encouraged players to scan PokéStops with their phone cameras in exchange for a few virtual rewards. Behind this seemingly harmless feature, Niantic amassed a database of nearly 30 billion images of real-world locations. Processed by artificial intelligence, these images were used to build a vast three-dimensional representation of the world and develop a visual positioning system capable of locating a device with great accuracy, without relying solely on GPS. The technology is now attracting direct interest from the defense industry, particularly as a means of guiding drones or vehicles when satellite signals are jammed or unavailable. After Pokémon Go and Niantic’s other games were sold to Scopely, the mapping data remained in the hands of Niantic Spatial. In late 2025, the company entered into a partnership with Vantor, formerly Maxar Intelligence, a provider of geospatial intelligence to the US government. The two companies are working to combine Vantor’s Raptor software with Niantic’s positioning system. Vantor says it does not directly use data from the game, but has declined to clarify whether the model it plans to deploy was trained on it. Yet a spokesperson had previously acknowledged that player scans had been used to train an early version of the model. The case exposes a profound gap between legal consent and users’ actual understanding. Niantic’s terms of service did grant the company a transferable license to the images, but players could hardly have anticipated that their virtual outings would one day contribute to military applications. Once absorbed into an AI model, moreover, such data becomes virtually impossible to identify, remove, or even prove it was ever used.

    Pokémon Gopersonal datadefense Mac4Ever

  3. Tax Data of Nearly 700,000 Taxpayers Allegedly Stolen

    Following the data breach affecting Bloctel, the French government is facing another IT incident, this time on an entirely different scale. The Directorate General of Public Finances has confirmed that its information system was accessed illegally in late June 2026. The intrusion reportedly enabled tax data to be viewed and extracted, although the precise number of people affected is currently based on claims made by a hacker operating under the name ZeroBytes. The hacker claims to have retrieved 678,437 records relating to 392,867 individuals and 285,570 businesses. Among the individuals listed, 26,805 reportedly had a reference taxable income exceeding €100,000. According to the hacker’s account, the attack did not involve directly compromising the servers hosting taxpayers’ records. Internal servers were allegedly infiltrated first, subsequently providing access to the tax authority’s VPN, its business applications and taxpayers’ information. The potentially exposed data is particularly sensitive: full identity details, date and place of birth, addresses, telephone number, email address, internal tax identifier, family circumstances, dependants, number of tax units, reference taxable income, withholding tax rate and history of interactions with the tax authority. For businesses, the information obtained reportedly also included the SIREN registration number. The intrusion appears to have been detected quickly, but the extraction was not publicly confirmed until 13 August, after data allegedly originating from the Ministry for the Economy and Finance had been published. The incident comes six months after a breach involving Ficoba, which exposed 1.2 million bank accounts. This succession of incidents once again raises the question of whether the government can protect its systems over the long term and prevent such readily exploitable information from being scattered across the internet again.

    cybersecuritytax dataDGFiP MacGeneration

  4. Utiq: how telecom operators turn your Internet connection into an advertising identifier

    Utiq embeds advertising tracking directly into the Internet connection itself. Developed by several major European telecom operators, including Orange, Deutsche Telekom, Vodafone and Telefónica, the system assigns an identifier to a fixed or mobile line. Unlike conventional cookies, it does not rely solely on the browser. Clearing the cache, using private browsing, switching browsers or moving from one device to another may therefore not be enough to stop tracking when the connection remains the same. The system also relies on dedicated subdomains belonging to partner websites, using a technique known as CNAME cloaking that can make tracking harder for some blockers to detect. Its activation nevertheless requires the user’s consent, while operators remain subject to European rules governing connection data. One area remains opaque: the “Network Signal”, the initial identifier supplied by the operator, whose exact content is reportedly unclear, even to the CNIL, France’s data protection authority. This lack of transparency raises questions about whether consent can genuinely be considered informed. Utiq has already reached significant scale, with 36 partner operators, more than 330 publishers and 75 million identifiers created, including 40 million in France. Presented as a more ethical European alternative to the advertising tools of major US platforms, the system primarily shifts the source of tracking to the telecom operator. Users can opt out through the consenthub.utiq.com portal, which allows them to check their status and block Utiq for one year. On websites that use it, they should also refuse the service through the consent settings. Finally, using a VPN can make connections harder to correlate by changing the IP address on which the system relies.

    Utiqprivacytargeted advertising Next