<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CarlosTKD Roadmap</title><link>https://carlostkd.ch/roadmap/</link><description>Roadmap updates and news from CarlosTKD</description><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:14:12 GMT</lastBuildDate><atom:link href="https://carlostkd.ch/feed.php" rel="self" type="application/rss+xml"/><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-62</guid><link>https://carlostkd.ch/roadmap/#post-62</link><title>Is Venmo safe?</title><description><![CDATA[Quasy_Complete was sitting in his kitchen when his phone buzzed. A notification from Venmo: "Sarah sent you $20 for pizza."

He didn't know a Sarah. He hadn't ordered pizza. And he certainly hadn't shared pizza with anyone named Sarah.

"Ah," he muttered. "Either someone sent money to the wrong person, or this is the beginning of a very modern scam."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was on fire.

"Quasy! My grandson asked me to send him $50 for his birthday! I used Venmo! But now the whole app can see that I sent $50 to a teenager with the note 'Happy Birthday sweetie '! His friends are laughing at him! And a stranger just requested $200 from me with the message 'you know what you did'!"

"Mrs. Higgins," Quasy said calmly, "you've just experienced two things simultaneously. One: Venmo's brilliant decision to make financial transactions visible on a social feed. Like a reality TV show where everyone can see your wallet. Two: a scammer testing whether you'll pay vague, threatening invoices from strangers."

She sat down heavily. "Venmo has a social feed?"

"Venmo HAS a social feed. A social feed. For money. Someone at Venmo headquarters sat in a meeting and said, 'What if banking... but social?' And nobody stopped them. Nobody said, 'Perhaps people don't want their financial transactions displayed like Instagram stories.' Nobody said, 'Maybe sending rent money shouldn't have an audience.' And now your grandson's birthday gift is public knowledge and a stranger is invoicing you for crimes you didn't commit."

What Is Venmo and How Does It Work? (The Bank That Thinks It's Twitter)

Venmo is a US-only peer-to-peer payment app owned by PayPal. You can send money, split payments, pay online, move money to your bank, get your paycheck early, send gift cards, and attach emojis to transactions.

Quasy read the feature list: "Send money. Split payments. Attach emojis. Social feed. So it's a bank. That's also a social network. That's also a gift card shop. That's also a payroll service. What could possibly go wrong with combining banking, social media, and emotional attachments?"

Mrs. Higgins: "I like the emojis! I sent my grandson a pizza emoji!"

"Did you also enjoy the fact that 47 strangers, three acquaintances, and a potential scammer now know that you sent $50 to a minor on a Tuesday? With a heart emoji? On a public feed?"

"The feed is public?"

"By DEFAULT it's friends-only now. After privacy issues reported by The Verge in May 2026. Before that? It was PUBLIC. As in, anyone on the internet could see your transactions. A stranger in another state could see that you paid your roommate for utilities. A coworker could see that you bought someone a coffee. Your ex could see that you sent $30 to someone they don't know at 2 AM. Venmo built a financial surveillance network disguised as a fun social app. And people used it. Willingly. Because emojis."

Is Venmo Safe to Use With Strangers? (No. Absolutely Not. What Are You Doing?)

Venmo is built for moving money between people who already know each other. Not strangers. In practice, many people use it to pay strangers selling items online.

Quasy imagined the marketplace scenario: Buyer: "I'd like to buy your used PlayStation for $300." Seller: "Great! Send me $300 on Venmo!" Buyer: "Shouldn't we use PayPal Goods and Services? Or Meta Pay? Something with buyer protection?" Seller: "No, no. Venmo is fine. Trust me." Buyer: Sends $300 via Venmo. Seller: Disappears. Deletes account. Blocks buyer. Moves to another state. Changes name. Buys a boat. Buyer: "Where's my PlayStation?" Venmo: "You sent money to a stranger with no buyer protection. The transaction can't be reversed. Have a nice day."

Mrs. Higgins gasped. "That's terrible!"

"That's the business model. Venmo personal payments carry NO buyer protection by default and CANNOT be reversed once accepted. If you pay a stranger, receive the wrong item, a damaged item, or nothing at all, you cannot get your money back. The money is gone. Like throwing cash into a black hole and hoping something comes back."

How to Protect Personal Payments (The 2.99% Tax on Trust)

Payments to approved business accounts are automatically protected. Personal payments are NOT covered unless you tag the transaction as a purchase. This incurs a 2.99% fee for the recipient.

Quasy: "So if you want protection, you have to tag it. If you tag it, the seller pays 2.99%. Some sellers will discourage you from tagging because of the fee. They'll say 'Trust me, bro. Just send it as friends and family.' And you know what? 'Trust me, bro' is not a legally binding contract."

He illustrated: Seller: "Don't tag it as a purchase. It charges me a fee." Buyer: "But if I don't tag it, I have no protection." Seller: "I'm honest! Look at my profile! I have five stars!" Buyer: "You also created this account yesterday and have no transaction history." Seller: "...Send the money as friends and family." Buyer: "Absolutely not. Tag it as a purchase or I'm using PayPal." Seller: Vanishes.

Mrs. Higgins: "What if they insist?"

"If they insist on no buyer protection, THAT is your red flag. A legitimate seller who refuses protection is either hiding something or planning to take your money and run. Purchase Protection protects sellers too — if they can produce proof of shipment and delivery. A seller who refuses protection is a seller who cannot produce proof. Because there is no proof. Because there is no shipment. Because there is no item. There is only your money and their disappearance."

How to Spot Scams on Venmo (The Three-Headed Hydra)

Venmo acknowledges users may be targeted by scams. Three common ones:

Scam 1: "You've Won Money!" (The Classic Bait)

You receive an email or text saying you've won money through Venmo. It includes a phishing link.

Quasy: "You've won money! In a lottery you never entered! Through a payment app! All you need to do is click this link and enter your Venmo login! What could go wrong? Everything. Everything could go wrong."

He illustrated: Email: " Congratulations! You've won $500 from Venmo Rewards! Click here to claim!" Victim: "I won! Let me click!" Phishing Page: Looks exactly like Venmo. Asks for username and password. Victim: Enters credentials. Hacker: "Thank you. I'll take it from here." Victim's Venmo: Balance: $0. Transactions: Three payments to 'Greg_Gaming_Pro_99.' None initiated by the victim.

Mrs. Higgins: "Who falls for that?"

"Millions of people. Because the email looks real. The logo is correct. The colors match. The only thing that's fake is the URL. Which is 'venmo-rewards-claim-secure-portal.xyz' instead of 'venmo.com.' One letter off. One domain different. And your bank account is empty."

Scam 2: "This Is Venmo Calling" (The Verification Code Heist)

Someone calls claiming to be from Venmo. They ask you to make a payment or share your 2FA code.

Quasy: "Venmo will NEVER call you and ask for your verification code. Never. Not once. Not ever. If someone calls you claiming to be Venmo and asks for a code, hang up. Block the number. Delete the contact. Change your password. Enable 2FA. And maybe move to a different area code."

He illustrated: Caller: "Hi, this is Venmo Support. We detected suspicious activity on your account. Can you please read me the code we just sent to your phone?" Victim: "Oh no! Of course! The code is 4-8-2-9-1-7." Caller: "Thank you. Your account is now... mine." Victim: "Wait—" Caller: Click.

Mrs. Higgins: "They just take the code and steal the account?"

"The code IS the key. 2FA codes are designed to prove you're you. If you give that code to a stranger, you've just proved that THEY are you. To Venmo's servers. And now they can reset your password, change your phone number, and empty your balance. All because you answered a phone call and read six digits to a stranger."

Scam 3: The Friend Impersonator (The Duplicate You)

You get a payment request from someone who looks like your friend. Same username. Same profile picture. Same social feed. But it's not your friend.

Quasy: "A scammer copies your friend's username, profile picture, and social feed details. Creates a near-identical profile. Sends you a payment request for $150 with an urgent message: 'Hey, need help with rent ASAP! Pay you back Friday!'"

Mrs. Higgins: "How do I tell the difference?"

"Double-check. Look at their public transaction history. Check the username letter by letter. Is it 'John_Smith' or 'John_Srnith'? One letter different. One character swapped. And if you're still not sure? Text your friend. Outside Venmo. 'Hey, did you just ask me for $150 on Venmo?' If they say no, you just avoided sending $150 to a stranger who spent twenty minutes copying your friend's profile."

How to Use Venmo Safely (The Survival Guide)

Quasy listed the rules:

    Tag purchases made via personal accounts as purchases. This ensures Purchase Protection. Yes, it costs the seller 2.99%. That's the price of trust. Pay it. Or lose everything.

    Set transaction visibility to private. Not friends. Not public. PRIVATE. Your finances are not content. Your rent payment is not a social post. Your birthday gift to your grandson is not for public consumption. Settings → Privacy → Past Transactions → Set to Private. Do it now. I'll wait.

    Verify identities through a second channel. Text. Call. Email. Smoke signal. Carrier pigeon. ANYTHING other than the Venmo app itself. If someone is asking for money urgently through Venmo, verify OUTSIDE Venmo.

    Use a password manager. Generate a strong, unique password for Venmo. If one breach exposes your password, the attacker doesn't get the keys to your financial kingdom.

    Use an email alias. Create a unique email address for Venmo. If Venmo gets breached, your real email stays safe. The alias forwards to your real inbox. You can disable it anytime.

    Use a VPN. Public WiFi + financial transactions = disaster. A VPN encrypts your connection. Nobody on the same network can see your session. Your banking stays private.

Mrs. Higgins was writing furiously. "Tag purchases. Set to private. Verify outside. Password manager. Email alias. VPN. Got it."

"You forgot the most important one."

"What?"

"Don't send money to strangers. Ever. For any reason. Under any circumstances. Even if they seem nice. Even if they promise to ship the item. Even if they have a verified profile. If you don't know them in real life, don't send them money through Venmo."

Secure Your Passwords and Privacy with Proton (The Real Shield)

Proton Pass generates strong, unique passwords for every account — including Venmo. If one password leaks, they don't all leak. It sets up email aliases. If Venmo gets breached, attackers don't have the keys to your primary inbox. And it only autofills logins on recognized websites — so it won't hand your password to a domain that isn't venmo.com.

Quasy: "This last point is crucial. Phishing pages look like Venmo. They feel like Venmo. But the URL is 'venmo-secure-login-portal.xyz.' Proton Pass won't autofill on that domain. Because it's not Venmo. It's a trap. And Proton Pass recognizes traps."

Proton VPN encrypts your connection whenever you're using Venmo or any other app. Blocks ads and malware trackers.

Both Proton Pass and Proton VPN are protected by zero-access encryption. Not even Proton can access your passwords.

Conclusion: Venmo Is as Safe as You Make It (Which Means: Not Very, Unless You Try)

Quasy_Complete looked at Mrs. Higgins. She was carefully adjusting her Venmo privacy settings, tagging purchases, and verifying her grandson's identity via text message.

"Done," she announced. "Private. Tagged. Verified."

"Good. Now your transactions are invisible, your purchases are protected, and your grandson is confirmed as your grandson and not a stranger named Greg from a marketplace listing."

His phone buzzed. Venmo notification: "Greg_Gaming_Pro_99 requested $200. Note: 'you know what you did'"

Quasy stared at the screen. Then looked at Mrs. Higgins. Then looked at the ceiling.

"Greg is back," he said.

"Who is Greg?"

"Greg is nobody. Greg is a ghost. Greg is a username attached to a scammer who sends vague, threatening payment requests hoping someone will pay out of confusion or fear. Greg doesn't know what you did. Greg doesn't even know who you are. Greg is fishing. And the bait is 'you know what you did.'"

Mrs. Higgins: "Should I pay him?"

"Mrs. Higgins. If you pay Greg, you are the answer to every scammer's prayer. You are the reason they keep trying. You are the reason Greg exists. Greg is not a person. Greg is a business model. A business model that only works because somewhere, someone, sometime, paid a vague invoice out of guilt."

He declined the request. Blocked the user. Reported the account. Changed his Venmo password via Proton Pass. Set all past transactions to private. Verified his 2FA.

His phone buzzed again. Venmo notification: "Sarah sent you $20 for pizza."

Quasy read it. Looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling AGAIN, as if it might offer guidance from a higher power.

"Sarah," he said slowly. "I don't know a Sarah. I haven't ordered pizza. And this is the second time Sarah has sent me $20 for a pizza I didn't eat."

"Maybe it's a mistake?"

"Or maybe it's a test. A probe. Sarah sends $20. If I accept, Sarah requests $200 back with a sob story. 'Oops, I sent it to the wrong person! Can you send it back? I need it for rent!' If I send it back, Sarah disappears. And I've lost $200. Because I was nice. Because I was helpful. Because I was human. And scammers love humans."

He declined the $20. Blocked Sarah. Reported the account.

"Venmo is safe," he summarized, "if you know exactly who you're paying, you've tagged it as a purchase, your privacy is set to private, your password is unique, your email is aliased, and your VPN is running. Otherwise? You're sending cash into a social media platform and hoping for the best."

Mrs. Higgins stood up. "I'm going to check my past transactions."

"Set them ALL to private. Every single one. Your pizza payments. Your rent splits. Your birthday gifts. All private. Because your finances are not content. Your money is not a post. And your grandson's birthday gift is not a public event."

She left. Determined. Armed with privacy settings and Proton Pass.

Quasy sat alone. His phone was quiet. No notifications. No payment requests. No vague invoices from Greg.

He opened Proton Pass. Checked his Venmo password. It was 24 characters of randomized gibberish. Impossible to crack. Impossible to guess. Impossible to phish. Because Proton Pass only autofilled on venmo.com. Not on venmo-secure-portal.xyz. Not on venmo-rewards-claim.net. Not on venmo-login-verify-account.info. Only venmo.com.

"Safe," he whispered. "For now."

His phone buzzed one last time. Venmo notification: "Your friend John just paid Mike $40 for 'kombucha.' View it on your feed."

Quasy stared at the notification. John paid Mike. For kombucha. And Venmo told him about it. Because Venmo believes that financial transactions are social events. That money is content. That privacy is a setting, not a default.

"John likes kombucha," Quasy muttered. "I didn't need to know that. John didn't want me to know that. Mike probably didn't want me to know that. But Venmo decided I should know. Because Venmo is a bank that thinks it's Twitter."

He set his feed to private. Closed the app. Put the phone down.

Somewhere in a server farm, a social feed updated. John paid Mike $40 for kombucha. 37 friends saw it. 3 strangers saw it. 1 scammer saw it. And Greg took notes.

Because in 2026, your money is social. Your privacy is optional. And Greg is always watching.

Welcome to Venmo. Where banking meets broadcasting. And your rent payment has an audience.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 26 Jul 2026 17:46:46 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-54</guid><link>https://carlostkd.ch/roadmap/#post-54</link><title>Is Malwarebytes Safe?</title><description><![CDATA[Quasy_Complete was sitting in his living room when his computer started making a noise like a dying lawnmower. He looked at the screen. A popup appeared: "CRITICAL VIRUS DETECTED! CLICK HERE TO FIX NOW!"

He stared at it. Then he stared at the ceiling. Then he stared at the screen again.

"Ah," he muttered. "The classic 'You Have a Virus' virus. The most effective malware disguise of all time. It preys on fear. It preys on ignorance. It preys on the fact that most people don't know the difference between a security tool and a scam."

His neighbor, Mrs. Higgins, appeared at the door holding her laptop like it was a radioactive isotope.

"Quasy! My computer says it has a virus! It says I need to download Malwarebytes immediately! But isn't Malwarebytes also malware? I read somewhere that fake antivirus apps are a thing!"

"Mrs. Higgins," Quasy said calmly, "Malwarebytes is real. It's legitimate. It's highly rated by PC Mag, CNET, and Trustpilot. It's safe to download if you get it from the official site. But here's the catch: the free version is a scanner, not a shield. It cleans up the mess after the house burns down. It doesn't stop the arsonist from lighting the match."

She sat down heavily. "So it's a fire extinguisher?"

"Exactly. A very good fire extinguisher. But if you only have a fire extinguisher and no smoke detector, no sprinkler system, and no fireproof walls, you're still going to lose your house. And Malwarebytes Free is just the extinguisher. The shield? That costs extra."

What Is Malwarebytes? (The Digital Janitor)

Malwarebytes is cybersecurity software designed to detect, block, and remove malicious threats. Most people use the free version, which is a scan-on-demand tool.

Quasy explained: "The free version checks files already on your device. It finds malware. It removes it. It's retrospective. It's like a janitor who comes in after the party and sweeps up the broken glass. But the party is over. The guests are gone. The damage is done. Ransomware might have encrypted your files. Spyware might have stolen your data. The janitor can sweep up the glass, but he can't un-break it."

Mrs. Higgins: "So if I have a virus, Malwarebytes fixes it?"

"It removes the virus. But it doesn't undo the damage. If your photos were encrypted, they're still encrypted. If your passwords were stolen, they're still stolen. The virus is gone. The consequences remain."

Why a Scan Isn’t the Same as Protection (The Difference Between Cleaning and Guarding)

Full antivirus protection continuously monitors and blocks threats in real time. It catches malware before it installs. Malwarebytes charges for this.

But you probably already have real-time protection built in:

    Windows: Microsoft Defender + Firewall.
    macOS: XProtect.
    Android: Google Play Protect.

Quasy: "These are free. They are built-in. They are always on. They are the smoke detectors and sprinklers. Malwarebytes Premium is an extra layer. A second opinion. A backup guard. But it's not the only guard you need."

He paused. "And even with real-time protection, you're not safe. New threats emerge every day. Before the databases update, the malware slips through. And human error? If you download a sketchy app or grant permission to a shady service, no antivirus can save you. You have to be smart. You have to be careful. You have to be paranoid."

Five Free Habits to Close the Security Gaps (The Real Shield)

Here are five rules that provide protection no antivirus app can:

    Keep Your OS and Apps Updated: Updates patch vulnerabilities. Neglecting them gives cybercriminals a backdoor with a key they already have. Turn on automatic updates. Now. Quasy: "Updates are annoying. They take time. They change things. But they close the holes. Without them, your door is wide open. And the burglars are waiting."

    Do Your Due Diligence Before You Install: Download apps from the developer's official site. On mobile, use official stores. Check the developer's name. See what else they've published. Find their website. Quasy: "If the developer is 'SuperCoolAppDev123' with no other apps and a website that looks like it was made in 1999, don't install it. If the app is on the Play Store but the developer has 50 other apps that are all scams, don't install it. Be skeptical. Be paranoid. Be alive."

    Use Strong Passwords (and Don’t Reuse Them): Short, predictable passwords are easy to crack. Reusing them across accounts is a disaster. One exposed password compromises everything. Use a password manager to generate unique, strong credentials. Quasy: "If you use 'Password123' for your email, bank, and social media, and one gets breached, you lose everything. A password manager creates a unique key for every door. One lock breaks? The others stay locked. It's the difference between a fortress and a cardboard box."

    Use Email Aliases: Your inbox is a target. An email alias gives you a disposable address for each service. If a company gets breached, you disable the alias. Your real inbox stays safe. Quasy: "It's like giving every store a different credit card number. If one number gets stolen, you cancel that card. The others work. Your real identity stays hidden. Spam disappears. Breaches become manageable. It's digital camouflage."

    Use a VPN: Public networks are unencrypted. Anyone can see what you're doing. A VPN encrypts your connection. Traffic becomes scrambled. Unexploitable. Quasy: "Public WiFi is like writing your bank password on a postcard and handing it to a stranger. A VPN puts the postcard in a steel box. The stranger can see the box. They can't open it. They can't read it. They can't steal it."

Prevention Starts with a Secure VPN and Password Manager (The Proton Pitch)

Malwarebytes cleans up what's already there. Proton VPN and Proton Pass make sure there's less to clean up.

Malwarebytes VPN (Privacy VPN):

    Requires a $79.98/yr subscription to Malwarebytes Plus.
    Operates under US jurisdiction (subject to CLOUD Act).
    Passed only one independent audit (2026), which flagged a critical vulnerability.

Proton VPN:

    Free to use.
    Under Swiss jurisdiction (no mandatory data retention, not subject to CLOUD Act).
    Passed five consecutive annual independent audits.

Quasy: "Malwarebytes VPN is expensive. It's US-based. It's subject to government compulsion. It had a critical vulnerability flagged in its only audit. Proton VPN is free. It's Swiss. It's audited five times. It's secure. It's private. It's the better choice. Unless you love paying for less security."

Proton Pass:

    Generates strong passwords.
    Autofills credentials.
    Offers email aliases (10 free, unlimited with Plus).
    Zero-knowledge encryption. Not even Proton can access your credentials.

Quasy: "Proton Pass contains the damage. If one account is breached, the others stay safe. The vault is private. The keys are yours. The encryption is real. It's not just a tool. It's a strategy."

Conclusion: Malwarebytes Is a Tool, Not a Solution

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence, staring at her screen.

"So Malwarebytes is safe," she said slowly. "But it's not enough."

"Correct. It's a janitor. A fire extinguisher. A cleanup crew. It's helpful. It's necessary if you're already infected. But it's not a shield. It's not a guard. It's not a prevention strategy."

He stood up. "To be safe, you need more. You need updates. You need due diligence. You need strong passwords. You need email aliases. You need a VPN. You need a password manager. You need to be smart. You need to be careful. You need to be proactive."

He looked at her. "Malwarebytes cleans up the mess. Proton prevents the mess. Which do you want?"

She thought about it. "I want to prevent the mess."

"Then start with Proton Pass. Then Proton VPN. Then updates. Then due diligence. Then aliases. Then you'll be safe. Not because of a scanner. Because of a strategy."

His phone buzzed. Notification: "Malwarebytes: Your scan is complete. No threats found."

Quasy smiled. "Good. But remember: no threats found today. Tomorrow is a new day. Tomorrow, new threats emerge. Tomorrow, new vulnerabilities appear. Tomorrow, you need to be ready."

He opened Proton Pass. Generated a new password. Saved it. Closed the app.

"Safe," he whispered. "Not because of a scan. Because of a plan."

And if anyone tried to infect his device? They'd find a locked door. A unique key. An encrypted tunnel. And a janitor who never needed to sweep.

Because the house was never on fire in the first place.

Which, in 2026, is the best kind of victory.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 26 Jul 2026 17:12:29 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-53</guid><link>https://carlostkd.ch/roadmap/#post-53</link><title>What Does Google Know About You? The Chilling Truth (Or, How a Search Engine Became the World’s Most Nosy Landlord Who Also Owns Your Toaster, Your Watch, and Your Dreams)</title><description><![CDATA[Quasy_Complete was sitting in his kitchen, staring at a blank search bar. He had typed the words: "What does Google know about me?"

He hit Enter.

The screen loaded instantly. A list of results appeared. The top result was an ad for a new vacuum cleaner. The second was a link to a blog post titled "10 Ways to Hide From Google (Spoiler: You Can’t)." The third was a map showing his current location with a pin labeled "Quasy_Complete is Here (And Probably Drinking Coffee)."

"Ah," Quasy muttered. "It knows I’m asking what it knows. And it knows I’m drinking coffee. And it knows I’m in my kitchen. And it knows I’m thinking about vacuum cleaners because I saw an ad for one three days ago. It’s a self-fulfilling prophecy of surveillance."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was a bomb.

"Quasy! I asked Google what it knows about me! It sent me a file! A huge file! It has everything! My search history from 2014! My location history! My voice recordings! It even knows I bought a toaster that talks to my fridge!"

"Mrs. Higgins," Quasy said calmly, "Google doesn’t just know you bought a talking toaster. It knows what you said to the toaster. It knows when you said it. It knows how loud you said it. And it knows that you’re now worried because Google knows you’re worried. It’s a loop. A digital Ouroboros eating its own tail."

She sat down heavily. "Is it safe?"

"Safe? No. Safe implies privacy. Privacy implies boundaries. Google has no boundaries. It has no walls. It has no doors. It has only data. And it eats data for breakfast, lunch, and dinner. And snacks in between."

Understanding Google’s Reach: The List That Never Ends

Google knows a lot. It knows where you’ve been on the internet. It knows where you’ve been in real life. It knows what you typed but changed your mind about. It knows your drafts. It knows your unsent emails. It knows your voice. It knows your health data. It knows your calendar. It knows your photos. It knows your YouTube history. It knows your income bracket. It knows if you’re single. It knows if you rent. It knows if you have kids (or don’t).

Quasy read the list aloud like a grim prophecy:

    Calendar: Your schedule, meetings, who you’re with, where you’re going.
    Web & App Activity: Every site you visit. Every app you use. How often.
    Photos: Where they were taken. Who is in them. Even your children.
    Documents: How you write. What you write about.
    Search History: Even the things you typed and deleted.
    Emails: Even the ones you never sent.
    Voice: How you sound. How you talk. If you use Google Home, Nest, or Assistant.
    Maps History: Every route you take. Every destination. Every timestamp.
    YouTube History: What you watch. How long you watch it. From cooking videos to "how to change a tire."

He paused. "When you put it all together, Google doesn’t just know you. It understands you. It builds a profile so detailed it could write your biography. It could predict your next move. It could guess your next breakup. It could calculate your next job interview. It could even guess what you’ll dream about tonight."

Mrs. Higgins: "That’s terrifying."

"It’s not terrifying. It’s business. Surveillance capitalism. The business model of the 21st century. You are not the customer. You are the product. Your data is the commodity. Your attention is the currency. And Google is the bank."

How to Find Out What Google Knows About You (The Moment of Truth)

You can’t ask Google what it knows and get an honest answer. But you can go to your Google Account → Data and Privacy. There, you’ll see everything.

    Web and app activity.
    Maps timeline.
    YouTube backlog (down to the day).
    Health data (if you use Fitbit, which Google bought in 2021).
    Voice Match data (your voice, your thumbprint, your identity).

Quasy: "You can download your data. A massive file. Gigabytes of your life. Your search history. Your location history. Your voice recordings. Your photos. Your emails. Your drafts. Your unsent messages. Your voice commands. Your health stats. Your sleep cycles. Your heart rate. Your steps. Your weight. Your menstrual data. All of it. In one zip file."

Mrs. Higgins: "I downloaded mine. It was 40 gigabytes."

"Forty gigabytes. That’s your life. Compressed. Archived. Stored. Waiting. For whom? For Google? For advertisers? For data brokers? For the US government? For cybercriminals? For anyone who can hack the server? Or anyone who buys the data? Or anyone who gets a subpoena? Or anyone who just wants to know what you had for breakfast on a Tuesday in 2019?"

Google Knows Things You Never Shared (The Mind-Reading Machine)

A Proton employee once asked, "What does Google know about me?" She found Google knew she was recently single. She never told Google. It knew her income bracket. She never told Google. It knew where she lived. She never told Google. It knew she didn’t have kids. She never told Google. It knew she rented an apartment. She never told Google.

Quasy: "Google doesn’t need you to tell it anything. It infers. It guesses. It predicts. It connects dots you didn’t even know existed. It sees patterns. It sees correlations. It sees trends. It sees you. Even if you never clicked a button. Even if you never filled out a form. Even if you never said a word. It knows."

He illustrated: User: "I didn’t tell Google I’m single." Google: "But you searched for 'dating apps' three times last week. You visited 'match.com' twice. You watched a video on 'how to get over a breakup.' You liked a post about 'being alone is okay.' You bought a bottle of wine on Amazon. You ordered takeout for one. You didn’t post on social media for two weeks. You deleted your Instagram story. You searched for 'signs you’re lonely.' You searched for 'how to meet people.' You searched for 'best bars in town.' You searched for 'dating advice.' You searched for 'single life.' You searched for 'loneliness.' You searched for 'depression.' You searched for 'therapy.' You searched for 'meditation.' You searched for 'self-care.' You searched for 'happiness.' You searched for 'love.' You searched for 'heartbreak.' You searched for 'moving on.' You searched for 'new beginnings.' You searched for 'fresh start.' You searched for 'hope.' You searched for 'future.' You searched for 'tomorrow.' You searched for 'today.' You searched for 'now.' You searched for 'me.' You searched for 'I.' You searched for 'you.' You searched for 'we.' You searched for 'us.' You searched for 'them.' You searched for 'they.' You searched for 'it.' You searched for 'this.' You searched for 'that.' You searched for 'here.' You searched for 'there.' You searched for 'where.' You searched for 'when.' You searched for 'why.' You searched for 'how.' You searched for 'what.' You searched for 'who.' You searched for 'which.' You searched for 'whose.' You searched for 'whom.' You searched for 'whatever.' You searched for 'whenever.' You searched for 'wherever.' You searched for 'however.' You searched for 'whoever.' You searched for 'whichever.' You searched for 'whomever.' You searched for 'whatsoever.' You searched for 'whensoever.' You searched for 'wherever.' You searched for 'howsoever.' You searched for 'whosoever.' You searched for 'whichsoever.' You searched for 'whomsoever.' You searched for 'whatsoever.' You searched for 'whensoever.' You searched for 'wherever.' You searched for 'howsoever.' You searched for 'whosoever.' You searched for 'whichsoever.' You searched for 'whomsoever.'"

Quasy stopped. "See? It knows. Even if you didn’t say it. Even if you didn’t think it. Even if you didn’t feel it. It knows."

The Link Between Surveillance Capitalism and Google (The Business Model of Watching You)

Google isn’t just a tech company. It’s an advertising juggernaut. Its main revenue source is ads. Advertisers tell Google who they want to reach. Google shows them ads to those people.

Quasy: "Google has so much data it’s become the largest engineer of the ad surveillance industry. It gives users the illusion of choice. 'Personalized ads' sound friendly. 'Make your ads more relevant.' But it’s not friendly. It’s predatory. It’s invasive. It’s manipulative. It uses your location, sexual orientation, hobbies, income bracket, health data, voice, photos, documents, emails, search history, YouTube history, Maps history, calendar, voice, health, voice, voice, voice... to influence your decisions. To make you buy things. To make you click things. To make you watch things. To make you think things. To make you feel things. To make you be things."

Mrs. Higgins: "So I’m being manipulated?"

"You’re being targeted. You’re being profiled. You’re being sold. You’re being watched. You’re being recorded. You’re being analyzed. You’re being predicted. You’re being influenced. You’re being controlled. You’re being owned. By Google. By advertisers. By data brokers. By the US government. By cybercriminals. By anyone who can access the data. Anyone. Everyone. Nobody. Nobody is safe. Nobody is private. Nobody is anonymous. Nobody is free."

Google’s Ad System Is Designed This Way on Purpose (The Real-Time Bidding Nightmare)

Google uses "real-time bidding" (RTB) to auction off your data to the highest bidder.

Quasy explained: "First, Google builds a profile on you. Then, it broadcasts that data to thousands of companies. They compete in an auction to buy ad space. Your data is exposed to thousands of advertisers in nanoseconds. It falls into the hands of data brokers. Cybercriminals. The US government. Anyone. Each time you see a targeted ad, your personal information is exposed. This fuels government surveillance. Poses national security risks. Gives data brokers easy access to your online activity."

He illustrated: Advertiser: "I want to reach people who are single, rent apartments, earn $50k-$70k, live in San Francisco, and watch cooking videos." Google: "Here’s a list of 10,000 people who match that profile. Including their names, addresses, phone numbers, emails, voice recordings, health data, search history, YouTube history, Maps history, calendar, photos, documents, emails, drafts, voice, voice, voice..." Advertiser: "Perfect. Bid accepted." User: Sees an ad for a dating app. User: "How did they know I’m single?" Google: "We know everything. We always know everything. We will always know everything. We will always be watching. We will always be listening. We will always be recording. We will always be analyzing. We will always be predicting. We will always be influencing. We will always be controlling. We will always be owning. We will always be Google."

Leave Google Behind, Starting With Email (The Only Way Out)

Every piece of personal data Google touches routes back to your Google account. A single login ties your entire digital footprint into one profile. Deleting your Google account is a great way to become safer.

The best place to start is email. Your inbox is the master key to your digital life. Linked to your bank, subscriptions, social media, work accounts. Whoever controls your email can reset your passwords. Piece together a detailed picture of who you are.

Quasy: "Proton Mail is a natural first step. It protects your messages with end-to-end encryption. Zero-access encryption. We never have access to your data. We can’t scan it. We can’t build behavioral profiles. We can’t show ads. We can’t train AI models. We can’t share it with third parties. And we don’t want to."

Mrs. Higgins: "So I should switch?"

"Start with email. Then search. Then maps. Then photos. Then voice. Then health. Then calendar. Then documents. Then YouTube. Then everything. De-Google your life. One service at a time. Each replacement is a brick removed from the wall. Each alternative is a window opened. Eventually, the wall comes down. And the light comes in."

Conclusion: Google Knows Everything (But It Doesn't Have To)

Quasy_Complete closed his laptop. Mrs. Higgins sat in stunned silence, her phone face-down on the table like a suspect being interrogated.

"So Google knows I'm single," she said quietly. "It knows my income. It knows where I walk. It knows what I watch. It knows how I sound. It knows my health. It knows my drafts. It knows things I never told it."

"And it sold all of that to strangers. Thousands of them. In nanoseconds. Via real-time bidding. Every time you saw a targeted ad, your personal information was broadcast to advertisers, data brokers, and potentially cybercriminals and government agencies. Not because you agreed. Not because you consented. Because you existed. And existing, in Google's world, means being monetized."

Mrs. Higgins picked up her phone. "What do I do?"

"Disable personalized ads at myadcenter.google.com. Turn off tracking for Web & App Activity, Timeline, Play History, and YouTube History at myactivity.google.com. Download your data. See what they have. Then start leaving."

"Leaving to where?"

"Proton Mail for your email. End-to-end encrypted. Zero-access. No scanning. No profiling. No ads. No AI training. No real-time bidding. No broadcasting your life to thousands of companies in nanoseconds."

He opened Proton Mail on his own laptop. The inbox was clean. Encrypted. Private. No ads. No tracking. No surveillance. Just email. The way email was supposed to be.

"See?" he said. "No ads for vacuum cleaners. No targeted suggestions. No creepy predictions about my relationship status. Just messages. Mine. Private. Encrypted."

Mrs. Higgins stood up. "I'm going to de-Google."

"Start with email. It's the master key. Once you control your inbox, you control your identity. Once you control your identity, you control your data. Once you control your data, you control your life."

"Is it hard?"

"No. It's just different. Like moving to a new city. The first week is confusing. The second week is familiar. The third week is home."

His phone buzzed. Notification from Google: "We noticed you've been inactive! Here's a summary of what you missed: 14 ads, 3 location tracking alerts, and a personalized suggestion based on your recent search for 'how to leave Google.'"

Quasy stared at the notification. Then laughed. A slow, tired, knowing laugh.

"They know I'm leaving," he said. "They can see me packing."

"Is that bad?"

"It's inevitable. They see everything. They always have. But seeing someone leave and stopping them from leaving are two different things. They can watch me walk away. They cannot make me stay."

He closed the notification. Opened Proton Mail. Composed a new email to Mrs. Higgins using his Proton address.

Subject: Welcome to the other side. Body: Your inbox is yours now. Nobody is reading it. Nobody is scanning it. Nobody is selling it. Welcome home.

Mrs. Higgins received the email. Read it. Smiled.

Then she opened her Google account settings. Downloaded her data — 40 gigabytes of her life, compressed and archived. She looked at the file. A digital biography written without her consent.

She deleted her Google account.

The screen confirmed: "Account deleted. Your data will be removed from our active servers."

"Active servers," Quasy noted. "Not backup servers. Not archival servers. Not 'servers we forgot about in a basement in Oregon.' Active servers. The fine print is always where the ghosts live."

But the account was gone. The master key was destroyed. The single login that tied her entire digital footprint together was severed.

Mrs. Higgins put her phone down. "It feels quiet."

"That's what privacy sounds like. Quiet. No ads. No tracking. No targeting. No profiling. No real-time bidding wars over your personal life. Just silence. Encrypted silence."

His phone buzzed one last time. Notification: "Proton Mail: You have 1 new encrypted message."

Quasy smiled. "And THAT is what email was supposed to be. A message. From someone. To you. Private. Encrypted. Yours."

He opened it. Read it. Closed it.

Somewhere in Mountain View, a server hummed. Inside it, Quasy_Complete's profile flickered. Dimming. Fragmenting. Disappearing.

Not entirely. Not immediately. Data has inertia. It persists. Like footprints in wet concrete. But accounts can be closed. Keys can be changed. Habits can be redirected.

And Quasy_Complete was redirecting.

One service at a time. One encrypted message at a time. One step away from the machine that knew he was single before he did.

The machine would survive. It always survives. But it would survive without him.

And that, in 2026, was the most radical act available.

Not protesting. Not petitioning. Not complaining.

Simply leaving.

Quietly. Encrypted. And taking your data with you.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Tue, 21 Jul 2026 18:42:59 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-52</guid><link>https://carlostkd.ch/roadmap/#post-52</link><title>How to Stop Drowning in Newsletters From Foot Locker While Missing Your Boss&apos;s Urgent Message About the Q3 Report</title><description><![CDATA[Quasy_Complete stared at his inbox. Three thousand four hundred and twelve unread emails. The number glowed at him like a digital scarlet letter. A badge of shame. A monument to procrastination.

He scrolled. A coupon from a shoe store he visited once in 2023. A newsletter about gardening tips he never signed up for. Seventeen LinkedIn notifications. A receipt for something called a "Smart Toaster" he didn't remember buying. And somewhere, buried under fourteen layers of digital sediment, an email from his boss marked "URGENT" sent four days ago.

"Ah," he said to no one. "I've achieved peak inbox chaos. My inbox isn't a communication tool anymore. It's an archaeological dig site. Every layer tells a story. The top layer: retail therapy regrets. The middle layer: newsletters I subscribed to during moments of optimistic self-improvement. The bottom layer: emails that actually mattered, fossilized under thousands of messages about Black Friday sales that ended months ago."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was contaminated.

"Quasy! I have nine thousand unread emails! I can't find my electric bill! I know it's in there somewhere! I've been scrolling for an hour!"

"Mrs. Higgins, you're not looking for a needle in a haystack. You're looking for a needle in a haystack factory. During peak production season. While the factory is on fire."

"What do I do?"

"You set up email filters. Automated sorting rules that organize your inbox so you never have to manually dig through nine thousand emails again. Unless you enjoy the thrill of the hunt. In which case, carry on."

What Are Email Filters? (The Digital Secretary You Can't Afford But Desperately Need)

Email filters are rules you assign to incoming emails to automatically sort your inbox. They scan subject lines, sender addresses, keywords, and attachments. Once a filter is set, emails are labeled, sorted, archived, or deleted based on criteria you've defined.

Quasy explained the concept: "Think of a filter as a bouncer at a nightclub. The bouncer stands at the door. He checks IDs. He decides who gets in, who goes to the VIP section, who waits in line, and who gets thrown out entirely. You set the rules. The bouncer enforces them. Automatically. Twenty-four hours a day. Without coffee breaks or complaints."

Mrs. Higgins: "So the filter reads my emails for me?"

"It reads enough to categorize them. It checks who sent it. What the subject says. What keywords appear. Then it acts. Newsletter? Archive. Receipt? Label it 'Receipts.' Email from your boss? Mark as important. Email from Foot Locker? Delete. Automatically. Forever."

He paused. "For small businesses, this is especially helpful. A well-built filter removes clutter and prevents important emails from falling through the cracks. No more missing client inquiries because they were buried under fifty promotional emails about flash sales."

How Email Filters Work (The Mechanics of Digital Triage)

Filters scan emails for criteria you set: sender name, email address, subject, keywords, attachments. When a message meets the criteria, the filter performs an action: archive, mark as read, apply a label, delete, mark as important.

In addition to custom filters, Proton Mail's smart spam filters detect spam and learn from your actions. The more you click "Move to spam" or mark emails as safe, the better the filters become. You can whitelist trusted senders or block unwanted addresses outright.

Quasy: "Proton's spam filters are like guard dogs that attend training school every day. Every time you mark something as spam, the dog learns. 'Ah, this smell is bad. I'll bark next time.' Every time you mark something as safe, the dog relaxes. 'This smell is fine. I'll let it through.' Eventually, the dog knows exactly what to catch and what to let through. Without you saying a word."

Mrs. Higgins: "And the custom filters?"

"Those are YOUR dogs. You train them. You decide what they fetch, what they ignore, and what they bury in the backyard."

How to Organize Email With Filters (The Art of Digital Feng Shui)

Start by building filters around categories that already exist in your inbox: newsletters, receipts, client threads, internal memos. Layer in folders and color-coded labels so every filtered message lands somewhere useful instead of just out of sight.

Quasy listed his own filter system:

    Newsletters: Automatically labeled and archived. Not in the main inbox. Read when I feel like it. Which is never.
    Receipts: Labeled "Receipts" and filed in a folder. For tax season. When I'll pretend to organize them and then panic in April.
    Client Emails: Labeled by client name. Priority marking enabled. So I never miss an email from someone who pays me.
    Internal Memos: Labeled "Internal" and marked as read. Because internal memos are the inbox equivalent of elevator music. Present. Technically important. Completely ignorable.
    Foot Locker: Deleted. Automatically. Forever. Without mercy.

Mrs. Higgins: "Good email organization is an ongoing system, not a one-time project."

"Exactly. Once your filters are in place, revisit them periodically. Habits change. Projects end. New clients arrive. Old newsletters multiply like rabbits. Your filters should evolve with your inbox. And Proton's spam filters keep doing the heavy lifting in the background."

How to Create Custom Email Filters With Proton (Two Ways, Both Easy)

Method 1: Quick automation from your email window.

    Sign in to mail.proton.me.
    Open an email, then move or label it as usual.
    Check "Always move sender's emails" or "Always label sender's emails."
    Select "Move" or "Label."

Quasy: "This is the lazy method. For people who see an email and think 'I never want to deal with this sender manually again.' Two clicks. Done. Every future email from this sender is automatically sorted. No setup screens. No criteria. No complexity. Just rage-driven efficiency."

Mrs. Higgins: "I like the lazy method."

"The lazy method is the best method. Laziness drives automation. Automation drives productivity. Productivity drives success. Therefore: laziness equals success. This is the Quasy_Complete theory of workplace efficiency."

Method 2: Detailed custom filters from Settings.

    Sign in to mail.proton.me.
    Go to Settings → All settings → Proton Mail → Filters.
    Under Custom filters, click "Add filter."
    Add criteria: filter when certain conditions are met, or when ALL requirements are met.
    Click "Insert" to add specific text or keywords.
    Click "Add condition" for complex filters. Include as many conditions as you like.
    Click "Next" to set actions.

Quasy: "This is the engineer's method. For people who want precision. Multiple conditions. Multiple actions. Complex rules. Like: 'If the email is from a client AND contains the word "invoice" AND has an attachment, then label it "Invoices" AND mark as important AND forward a copy to accounting.' One filter. Three conditions. Three actions. Zero manual effort."

Mrs. Higgins' eyes glazed over. "That sounds complicated."

"It's not complicated. It's precise. Complicated is scrolling through nine thousand emails looking for one electric bill. Precision is a filter that catches the electric bill automatically because it recognizes the sender and the subject line. Complicated is chaos. Precision is order."

Best Practices: How to Use Filters to Boost Productivity (Without Accidentally Hiding Your Boss's Emails)

Quasy listed the golden rules:

    Categorize by project, sender, department, or priority. Give every email a home. No orphans. No strays. Everything filed. Everything findable.

    Use color-coded labels and folders. Visual awareness matters. Green for clients. Blue for receipts. Red for urgent. Yellow for "deal with later." Orange for newsletters. Purple for "why did I subscribe to this?"

    Create "Follow-up" and "Reply later" folders. Emails you need to circle back on shouldn't sit in your main inbox getting buried under new arrivals. Move them. Filter them. Tag them. Remember them.

    Auto-archive old messages. Set a filter that archives messages older than 30 days. If you haven't read it in a month, you're not going to. Be honest. Let it go.

    Review filters regularly. What worked in January might not work in July. Clients change. Projects end. Newsletter subscriptions multiply. Audit your filters like you audit your taxes. Reluctantly. But thoroughly.

    Don't over-filter. The biggest danger. Too many filters and you accidentally hide important emails. Your boss's email gets caught in a filter designed to catch "internal memos" and archived before you see it. Now you've missed a meeting. And your boss thinks you're ignoring them. And your career trajectory has adjusted downward.

Quasy illustrated the over-filtering trap: Boss: "Did you see my email?" Employee: "What email?" Boss: "The urgent one I sent yesterday." Employee: "I have a filter that archives internal memos." Boss: "It wasn't a memo. It was urgent." Employee: "The filter doesn't distinguish between memo and urgent. It treats all internal communication as equal. Very democratic. Very problematic." Boss: "Fix your filters." Employee: "I can't find the filter. It's archived under a label I forgot I created."

Mrs. Higgins: "That happened to me! My doctor's appointment reminder got caught in a spam filter and I missed my checkup!"

"And that's why you whitelist trusted senders. Your doctor goes on the whitelist. The filter sees the doctor's email and says 'This is safe. Let it through. Don't touch it. Don't archive it. Don't delete it. The patient needs this.'"

Keep Your Inbox Organized With Proton (Where Privacy Meets Productivity)

Proton Mail doesn't just organize your email. It keeps your data safe. End-to-end encrypted. Nobody can read your emails except you. Not even Proton.

Quasy: "Filters manage email overload, save time, and improve communication flow. But here's the thing: most email providers that offer filters also scan your emails. They read your content. They build profiles. They sell your data to advertisers. Your inbox is organized AND surveilled. Efficient AND exploited. Streamlined AND monetized."

He contrasted: "Proton Mail doesn't scan your emails. Doesn't sell your data. Doesn't build advertising profiles. End-to-end encryption means your messages are encrypted on your device before they reach Proton's servers. Not even Proton can read them. Your filters work on metadata — sender, subject, keywords — not on content. Privacy and productivity. Coexisting. Like they should."

Proton Mail also offers one-click unsubscribe, a Newsletters view, and Hide-my-email aliases for inbox organization that goes above and beyond.

Quasy: "One-click unsubscribe. ONE CLICK. Not 'scroll to the bottom, find the tiny gray text, click the link, confirm on a landing page, answer a survey about why you're leaving, then receive three more emails confirming your departure.' ONE CLICK. Gone. Finished. Freedom."

Mrs. Higgins: "And Hide-my-email?"

"You give every service a different email alias. Your real email stays hidden. If a service starts spamming you, you disable the alias. Done. No more emails. No unsubscribe button needed. No begging. Just silence. Beautiful, encrypted silence."

Conclusion: Your Inbox Doesn't Have to Be a War Zone

Quasy_Complete looked at his inbox. Three thousand four hundred and twelve unread emails. He took a breath. Opened Proton Mail settings. Created his first filter.

Rule: If sender contains "newsletter" → Label "Newsletters" → Archive. Result: Four hundred emails vanished from his main inbox. Filed neatly. Still accessible. No longer screaming for attention.

Rule: If sender contains "footlocker" → Delete. Result: One hundred and twelve emails evaporated. Like they never existed. Because they shouldn't have.

Rule: If sender is boss AND subject contains "urgent" → Mark as important → Label "Urgent." Result: The buried email from four days ago surfaced. Glowing. Important. Found.

"There," he said. "Order from chaos. Signal from noise. Important emails from junk. In three filters."

Mrs. Higgins started creating her own filters: Rule: If sender contains "electric company" → Label "Bills" → Mark as important. Result: Electric bill found. Filed. Paid. Crisis averted.

Rule: If sender contains "LinkedIn" → Archive. Result: Three hundred notifications vanished. Silence. Peace. The sound of nobody endorsing her for skills she doesn't have.

Rule: If sender contains "Foot Locker" → Delete. Result: Match.

She looked up. "It's beautiful. My inbox has eleven emails now. All important. All findable. All mine."

"That's the power of filters. They don't just organize your email. They reclaim your time. Your attention. Your sanity."

His phone buzzed. Email notification: "Your Foot Locker order has shipped!"

Quasy stared at the notification. Looked at Mrs. Higgins. Looked at the ceiling.

"I set the filter to delete Foot Locker emails."

"Maybe it's a different Foot Locker."

"There is no different Foot Locker. There is only one Foot Locker. And it is relentless. Like a hydra. You delete one email, two appear. You filter one sender, they change their address. You block one domain, they register another."

He opened the email. It was indeed from Foot Locker. The filter hadn't caught it because the sender address was "shipping@footlocker-delivery-partner-3.com" — a new domain. A new disguise. A new workaround.

"Ah," he muttered. "The arms race begins. They change their address. I update my filter. They change again. I filter again. It's evolution in real time. Natural selection applied to retail marketing. Survival of the most annoying."

He added the new domain to his delete filter. Checked his inbox. Eleven emails. All important. All findable.

For now.

His phone buzzed again. Email notification: "You've been endorsed for 'Strategic Thinking' on LinkedIn!"

Quasy read it. Looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling again, as if it might offer guidance.

"LinkedIn changed their sender address too, didn't they?" Mrs. Higgins asked.

"Indeed they did."

He updated the filter. Archived the notification. Closed his laptop.

Inbox: zero. Stress level: manageable. Foot Locker: temporarily defeated. LinkedIn: temporarily silenced. Electric bill: paid. Boss's urgent email: found, read, and responded to four days late. Career: uncertain.

But the inbox was organized.

And sometimes, that's the best you can hope for in 2026.

An organized inbox. A encrypted email. And a filter that deletes Foot Locker emails with extreme prejudice.

Forever.

Or until they register a new domain.

Whichever comes first.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Tue, 21 Jul 2026 18:32:33 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-51</guid><link>https://carlostkd.ch/roadmap/#post-51</link><title>Why Your Internet Provider Knows More About You Than Your Therapist</title><description><![CDATA[Quasy_Complete was sitting at his kitchen table when his internet connection suddenly slowed to a crawl. He tried to load a video. It buffered. He tried to check his email. It spun. He tried to stream a movie. The screen froze on a frame of a cat looking confused.

"Ah," he muttered. "The ISP is throttling me again. Because I'm watching a documentary about cats. Which, apparently, is a threat to national security."

His neighbor, Mrs. Higgins, appeared at the door holding her router like it was a hostage.

"Quasy! My internet is slow! And my router is blinking red! And I think it's watching me breathe!"

"Mrs. Higgins," Quasy said calmly, "your router isn't watching you breathe. But your Internet Service Provider (ISP) is definitely watching what you do online. And they know you're breathing. Because they can see how much data you're transferring. And if you're breathing heavily while watching a thriller, that's a lot of data."

She sat down heavily. "They know everything?"

"Almost everything. They know where you go. When you go. How long you stay. How much data you use. They know your approximate location. They know which devices are in your house. They know if you're streaming Netflix or checking your bank account. They just don't know what you're watching on Netflix or how much money is in your bank account. Because that part is encrypted. But the metadata? The metadata is a goldmine."

He pulled out his whiteboard. Drew a giant pipe. Labeled it "THE INTERNET." Then drew a smaller pipe inside it. Labeled it "YOUR ISP."

"Let's break this down," he said. "Because your ISP is the most powerful stalker you've never met."

What Can Your ISP Really See? (The Metadata Menagerie)

Modern websites use HTTPS encryption. This prevents your ISP from reading the contents of webpages. If you're browsing Reddit, they can't see the posts. If you're banking, they can't see your balance.

But...

Depending on your connection, your ISP may see:

    The websites and domains you visited.
    When you visited them.
    How long you remained connected.
    The amount of data you transferred.
    Your approximate physical location.
    Which devices are connected to your home network.

Quasy illustrated: You: "I'm going to Reddit to read about cats." ISP: "Ah, I see you visited 'reddit.com' at 3 PM. You stayed for 45 minutes. You transferred 200MB of data. You have three devices connected: your phone, your laptop, and that smart toaster that sends you tweets." You: "But you don't know what I read!" ISP: "True. But I know you read about cats. And I know you have a smart toaster. And I know you're in Apartment 4B. And I know you're single because you only visit dating sites on Tuesdays. That's enough for me to build a profile."

A 2021 FTC report examined six major ISPs serving 98% of the US mobile market. It found they collected massive amounts of data, combined it across services, and shared it with third parties.

Quasy: "They combine data from broadband, mobile, TV, email, smart home, and search. They build a detailed picture of your life. Then they sell it to advertisers. Who then show you ads for things you didn't even know you wanted. Like cat food. Or smart toasters."

Why ISPs Have So Much Data (Because They Own the Pipe)

Unlike Google or Meta, you can't log out of your ISP. You can't choose not to use it. For many, it's an unavoidable part of getting online.

Some providers have expanded beyond broadband. They offer mobile, TV, email, smart home, cloud, search.

Quasy: "This allows them to combine information from multiple services. You watch TV on their platform. You browse on their mobile network. You email on their service. They put it all together. You're not just a customer. You're a data point. A cluster of data points. A target."

He continued: "Unlike social media, where you have choices, most households have only one or two ISP options. In many areas, it's a monopoly. Or a duopoly. You pay them. They watch you. You have no choice. It's the ultimate subscription service. And you can't cancel."

How Privacy Protections Changed (Or, How Congress Decided Privacy Was Optional)

In 2016, the FCC adopted privacy rules requiring ISPs to get consent before collecting browsing data.

In 2017, Congress repealed those rules using the Congressional Review Act. Later, the FCC voted to repeal net neutrality.

Quasy: "So, in 2016, the government said 'Hey, ISPs should ask before they spy.' In 2017, Congress said 'Nah, let's repeal that.' And then they repealed net neutrality too. Which means ISPs can now slow down your connection if you don't pay extra. Or if you're watching a competitor's streaming service."

He illustrated: Netflix: "We're streaming movies!" Comcast: "Pay us extra, or we'll slow you down." Netflix: "But that's anti-consumer!" Comcast: "We own the pipes. We make the rules." Congress: "Sounds fair. Repeal the rules." Consumer: "But I just want to watch a cat video!" Comcast: "That'll be $10 extra."

Can Your ISP Slow Your Connection? (The Art of Digital Throttling)

ISPs control the infrastructure. They can influence how traffic is delivered.

Example 1: Netflix vs. Comcast (2013-2014). Comcast slowed Netflix streams until Netflix paid for direct connections. Comcast CEO called it an "arbitrary tax."

Example 2: Netflix vs. FCC (2024). Netflix argued ISPs with competing streaming platforms have financial incentives to disadvantage competitors.

Example 3: Mendocino Complex Fire (2018). Verizon throttled data for a fire department vehicle. Speeds dropped. Firefighters had to upgrade to a more expensive plan to get normal speeds. Verizon called it a "customer support mistake."

Quasy: "So, if you're a firefighter trying to save a town, and your internet is slow because you didn't pay for the premium plan? That's a 'mistake.' But if you're a customer trying to watch Netflix, and your internet is slow because you're using a competitor? That's 'business.' It's the same thing. Just different stakes."

He sighed: "ISPs don't just provide access. They control the road. And they can put speed bumps wherever they want. Especially if you're driving a car they don't like."

Can Your Wi-Fi Router Track You Inside Your Home? (The Wi-Fi Sensing Nightmare)

One lesser-known development: Wi-Fi sensing. Researchers have shown Wi-Fi signals can detect movement by analyzing how they reflect off people and objects.

Academic studies show these techniques can identify movement, breathing patterns, and even estimate body position through walls.

Today, some routers include human presence detection. Industry estimates suggest tens of millions of US households have access to Wi-Fi sensing tech through ISP-provided hardware.

Quasy: "Your router can now sense if you're in the room. If you're breathing. If you're moving. It can automate lights. Security systems. Smart home devices. And your ISP controls the firmware. They can turn features on or off. They can update the router to do more. And you just sit there, breathing, unaware that your router is counting your breaths."

Mrs. Higgins: "My router is counting my breaths?"

"Probably. And if you're breathing fast because you're scared of your ISP, that's a lot of data. They know you're scared. They know you're breathing. They know you're in Apartment 4B. And they know you have a smart toaster."

How to Reduce ISP Tracking (The Digital Escape Plan)

Although your ISP handles your traffic, you can reduce what they see.

Use a VPN: Encrypts traffic before it leaves your device. ISP sees only that you're connected to a VPN server. Not what you're doing.

Switch to Encrypted DNS: Traditional DNS reveals websites. Encrypted DNS (DoH/DoT) prevents ISPs from viewing requests in plain text.

Use Your Own Router: ISP-supplied routers often have limited control. Buying your own gives you control over firmware, security, and features.

Enable HTTPS: Most sites use HTTPS by default. Ensure your browser prefers encrypted connections. Prevents ISPs from viewing contents.

Quasy: "A VPN is the best tool. It hides your destination. Encrypted DNS hides your requests. Your own router hides your firmware. HTTPS hides your content. Combine them, and you're a ghost. A digital ghost. Invisible to your ISP."

He looked at Mrs. Higgins: "So, what should you do?"

"Get a VPN. Use encrypted DNS. Buy your own router. And stop trusting your ISP to keep your secrets. Because they won't. They're not your friend. They're your landlord. And they're charging you rent for the privilege of being watched."

Conclusion: Your ISP Is Watching (But You Can Hide)

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence, staring at her router.

"So my ISP knows everything," she said slowly.

"Not everything. But enough. Enough to build a profile. Enough to sell to advertisers. Enough to throttle your connection. Enough to watch you breathe."

He stood up. "But you can hide. Use a VPN. Encrypt your DNS. Buy your own router. And remember: your ISP is not your friend. They're the gatekeeper. And the gatekeeper is always watching."

His phone buzzed. Notification: "Your ISP has detected unusual activity. Please upgrade to Premium for faster speeds."

Quasy read it. Laughed. Deleted it.

"Unusual activity," he muttered. "Watching cat videos is unusual now? In 2026, the only unusual activity is not watching cat videos."

He opened Proton VPN. Connected to a server in Switzerland. His traffic was encrypted. His destination hidden. His ISP saw only a connection to a Swiss server.

"There," he said. "Now I'm a ghost. Invisible. Untraceable. Unthrottleable."

Mrs. Higgins asked: "Is my router still watching me breathe?"

"Probably. But at least it doesn't know what you're watching. Or who you're talking to. Or where you're going. That's progress."

He closed the app. Looked out the window.

The internet was a river. The ISP was the dam. And the water flowed through their hands. But with a VPN, the water became invisible. And the dam became irrelevant.

Which, in 2026, is the closest thing to freedom you can get.

And if anyone tried to throttle you? You'd just switch to a different river. Or build your own.



Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 15 Jul 2026 13:59:51 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-50</guid><link>https://carlostkd.ch/roadmap/#post-50</link><title>Why Your Phone Shouldn&apos;t Unlock Just Because You Open Your Eyes</title><description><![CDATA[Quasy_Complete was sitting in his living room when he noticed his iPhone unlock itself. He hadn't touched it. He hadn't spoken. He was just staring blankly at a wall, thinking about the existential dread of modern capitalism.

And yet, the screen lit up. The little padlock icon dissolved. The phone was open.

"Ah," he muttered. "Face ID. The feature that assumes if you're awake and looking at your phone, you must want to be in it. Even if you're just zoning out. Even if you're asleep. Even if you're being held at gunpoint by a border agent who wants to see your DM history."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was a bomb.

"Quasy! My phone unlocked when I was sleeping! I woke up and it was open! I didn't touch it! I didn't even blink!"

"Mrs. Higgins," Quasy said calmly, "Face ID has a feature called 'Attention Awareness.' It's supposed to stop it from unlocking if you're asleep. But sometimes, if you're dreaming about a very specific, very focused scenario involving your phone, it might get confused. Or, more likely, someone else is holding your phone while you sleep and looking at it for you."

She sat down heavily. "Can I turn it off?"

"You can. Permanently. Temporarily. Or just for the things you don't want it to do. Like paying for groceries. Or letting the FBI read your texts. Let's go through the menu."

How to Turn Off Face ID (The Three Ways to Say "No Thanks, I'll Use My Brain Instead")

There are three main options: permanent, temporary, or selective.

Option 1: Reset Face ID Permanently. Go to Settings → Face ID & Passcode → Enter Passcode → Reset Face ID. Note: On iOS 17.3+, you might need to disable "Stolen Device Protection" first. Because Apple loves irony. They protect your phone from thieves but make it harder to reset Face ID if you actually need to.

Quasy: "This wipes the facial data. Your phone forgets your face. You have to set it up again. It's like telling your phone, 'I don't trust you with my face anymore. We're starting over.'"

Option 2: Turn It Off Temporarily. Hold down the side button and either volume button for 2 seconds. Tap Cancel or press the side button again. Result: Face ID is disabled until you unlock with your passcode.

Quasy: "This is the emergency brake. You're about to go through customs? Hold the buttons. Boom. Face ID is dead. Your phone is now a brick that only opens with a code you memorized. Much safer. Much less convenient. But safer."

Option 3: Disable for Specific Functions. Settings → Face ID & Passcode → Under "Use Face ID For," toggle off specific apps or actions (Unlock iPhone, iTunes & App Store, Apple Pay, etc.).

Quasy: "You can keep Face ID for unlocking your phone but turn it off for Apple Pay. Because sometimes you don't want your face to be your credit card. Or you can turn it off for specific apps. Maybe you don't want Face ID for your banking app. Or your journal. Or your diary. Or anything you'd rather not have unlocked by a random glance."

How Does Face ID Work? (The Math Behind the Magic)

Face ID uses facial recognition to create a depth map and infrared image of your face. This data is transformed into a mathematical representation. It compares this map every time you unlock.

By default, it requires your eyes to be open and your attention directed at the device.

Quasy: "So it's not just a picture. It's a 3D map. Infrared. Depth. It knows you're looking at it. It knows you're awake. It's smart. Too smart. Because sometimes 'smart' means 'can be forced to work against you.'"

Is Face ID Safe? (The Legal Loophole That Lets the Police Force You to Smile)

For the average user, Face ID is often more secure than a passcode. No shoulder surfing. No password reuse. Hard to trick with photos or masks.

But there's a catch.

Legal Considerations: Passwords are protected as testimonial evidence. You can't be forced to give up your password. But biometrics? Courts have ruled that looking at a camera or touching a finger is a physical act, not testimony.

Quasy explained: "If the police want your password, they have to prove you know it. They can't force you to say it. But if they want your face? They can just hold your phone up to your face. And you look at it. And your phone unlocks. You didn't say anything. You just did something. A physical act. And physical acts can be compelled."

He illustrated: Police Officer: "Give us your password." You: "I can't. It's testimonial. I have rights." Police Officer: "Fair enough. Now, look at this phone." You: "I'm not going to—" Police Officer: "Look at it." You: "Fine." Looks. Phone: Unlocks. Police Officer: "Thank you. Case closed."

Quasy: "That's the loophole. Biometrics are physical. Passwords are mental. And the law treats them differently. Which means your face is less protected than your brain."

When to Turn Off Face ID (The Survival Guide for the Paranoid)

There are specific situations where you should turn it off.

Traveling Abroad: Turn it off before customs. Especially in countries where social media posts are crimes. Officials can force you to look at your phone. They can't force you to say a code.

Attending Protests: Turn it off before you go. If your phone is seized, you're more likely to avoid opening it. Consider a Faraday bag to block signals.

High-Risk Professions: Activists, journalists, immigrants, politicians. In January 2026, the FBI raided Washington Post journalist Hannah Natanson. Their warrant authorized agents to force her to use biometrics—finger or face—to unlock her devices.

Quasy: "Hannah Natanson. Journalist. FBI raid. Warrant said: 'Force her to look at her phone.' She had to look. Her phone opened. Her data was exposed. Because she looked. And looking is a physical act. And physical acts can be compelled."

Mrs. Higgins: "That's terrifying."

"It's the law. And the law is written by people who don't understand privacy. Or they understand it too well and decided it doesn't apply to you."

What to Use Instead? (The Passcode That Can't Be Forced)

For high-risk individuals, Lockdown Mode is an option. It makes your phone harder to use but safer.

In general, the best alternative is a passcode and passkeys. A password manager like Proton Pass lets you store and autofill passwords with end-to-end encryption.

Quasy: "A passcode is mental. You have to know it. You can't be forced to think it. If they want your passcode, they have to torture you into saying it. And that's a much higher bar than just holding a phone to your face."

He summarized: "Face ID is convenient. It's fast. It's seamless. But it's also a vulnerability. A physical vulnerability. A legal vulnerability. A biometric vulnerability. If you're just an average user, it's fine. If you're a journalist, an activist, a traveler, or just someone who values their privacy more than their convenience, turn it off."

Conclusion: Your Face Is Not a Key (It's a Liability)

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence, staring at her phone.

"So I should turn it off?" she asked.

"If you're worried about being forced to unlock your phone? Yes. If you're traveling? Yes. If you're attending a protest? Yes. If you're just paranoid? Also yes."

He picked up his own phone. Held down the side and volume buttons. The screen went black. Face ID was disabled.

"Now," he said, "my phone is a brick. It only opens with a code. A code I memorized. A code no one can force me to say. A code that is mine. And mine alone."

He smiled. "Convenience is nice. Security is better. And sometimes, you have to choose between the two."

His phone buzzed. Notification: "Face ID disabled. Use passcode to unlock."

Quasy read it. Smiled. Locked the phone.

"Finally," he whispered, "a phone that respects my right to remain silent."

And if anyone tried to force him to look at it? He'd just close his eyes. And smile. Because sometimes, the best defense is a closed eye. And a very long, very complex passcode.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 13 Jul 2026 15:30:35 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-49</guid><link>https://carlostkd.ch/roadmap/#post-49</link><title>Netherlands Blocks US Takeover of DigiD: Or, How a Country Finally Said &quot;Our Citizens&apos; Data Is Not for Sale&quot;</title><description><![CDATA[Quasy_Complete was reading the news when he spat out his coffee. Not the usual slow sip followed by a resigned sigh. An actual spit. Across the table. Onto a napkin. Onto Mrs. Higgins' sleeve.

"Quasy!" she yelped, dabbing her arm.

"Sorry. A government just did something sensible. I wasn't prepared. It never happens. I had no contingency plan for competence."

He turned the screen toward her. The headline read: Netherlands Blocks €100 Million Takeover of National ID Infrastructure by US Firm Kyndryl.

"A country," Quasy said slowly, "protected its citizens' data. On purpose. Deliberately. With a government decision. Not after a breach. Not after a scandal. Before anything went wrong. Preventively."

Mrs. Higgins blinked. "That's... unusual?"

"It's unprecedented. It's like watching a unicorn ride a bicycle through a field of four-leaf clovers while winning the lottery. Governments don't prevent problems. They react to them. Usually three years too late. During a press conference. With a spokesperson who says 'lessons have been learned.'"

What Is DigiD and Why Should You Care?

Solvinity manages the cloud infrastructure on which DigiD runs — the system that gives Dutch citizens access to tax records, medical files, and pension information.

Quasy broke it down: "DigiD is the digital front door to Dutch citizenship. Taxes? DigiD. Medical records? DigiD. Pension data? DigiD. It's the master key to 17 million people's private lives. And a US company called Kyndryl wanted to buy the company that runs the server it lives on."

Mrs. Higgins: "What's wrong with that?"

"The American CLOUD Act. This law requires American tech companies to provide data to the US government, even when that data is physically stored in Europe."

He illustrated: Dutch Citizen: "My medical records are stored in a server in Amsterdam." Kyndryl (American company): "We now own that server." US Government: "Excellent. We'd like to see those medical records." Kyndryl: "They're in the Netherlands." US Government: "CLOUD Act. Hand them over." Kyndryl: "But GDPR—" US Government: "Our law. Your company. Your server. Our rules." Dutch Citizen: "Wait, I didn't consent to—" US Government: "You're not in this conversation."

Mrs. Higgins went pale. "So the US could just... read Dutch citizens' medical files?"

"Through the CLOUD Act, yes. Tax records. Pension data. Medical files. Everything behind DigiD. If Kyndryl owned the infrastructure, the US government could compel them to hand over data. European GDPR protections would evaporate like a puddle in the Sahara. Because the company is American. And American companies obey American law. Even when the data is European. Even when the people are European. Even when the server is in a building in Amsterdam with a Dutch flag on the door."

"This happened before?" Mrs. Higgins asked.

"This ALMOST happened. The Dutch government blocked it. But 81% of Dutch publicly traded companies already depend on American tech services. In semiconductors, it's 83%. The takeover was averted. The dependency remains."

The Resistance: Citizens, Journalists, and Politicians Who Actually Read the Fine Print

When Kyndryl announced the takeover in November 2025, broad opposition emerged immediately. The rejection resulted from months of action by citizens, journalists, and privacy activists.

State Secretary Willemijn Aerdts adopted the Bureau for Investment Screening's advice: the takeover posed "a risk to the public interest." A broad parliamentary majority supported the decision.

Quasy: "Citizens objected. Journalists investigated. Privacy activists organized. Politicians listened. The Bureau for Investment Screening recommended blocking. The State Secretary agreed. Parliament backed it. A government functioned as a government. I'm so disoriented by competent governance that I need to sit down."

Mrs. Higgins: "This was the first time they blocked an American takeover?"

"First time. On grounds of public interest. The first time the Netherlands used investment screening powers to block a US acquisition to protect citizens' data. That's not routine. That's a precedent. A line in the sand. A government saying: 'This far. No further.'"

The Broader Movement: Europe Is Quietly Building Its Own Digital House

In December 2025, the Netherlands presented a new vision on digital sovereignty: crucial infrastructure must fall under Dutch or European legislation. The country is investing in its own cloud alternatives like STACKIT and the KPN-Thales sovereign cloud.

This fits a broader European pattern: France replacing American tools. The EU bringing chip production to Europe through the CHIPS Act. The EU Parliament ditching Google in favor of Qwant, a European search engine.

Quasy listed the developments like a man inventorying a fortress under construction:

    Netherlands: building sovereign clouds. Blocking foreign takeovers of critical infrastructure.
    France: replacing American tools with European alternatives.
    EU CHIPS Act: bringing semiconductor production back to Europe.
    EU Parliament: switching from Google to Qwant.

"Europe is building its own digital house," Quasy said. "Own bricks. Own cement. Own locks. Own keys. And the United States is standing outside, knocking, saying 'but we were already inside, why are you changing the locks?'"

Mrs. Higgins: "Because you were reading our mail."

"Exactly."

What This Means for Your Privacy (Because It's Not Just About Governments)

Control over digital infrastructure isn't a technical detail. It's national security and civil rights. When medical data, financial information, and personal communication are digital, whoever controls the infrastructure determines who has access to the data.

This applies not only to government systems like DigiD. It applies to your everyday internet use. Your traffic passes through ISP servers and websites, often under American or non-European jurisdiction.

Quasy: "DigiD was the government's problem. They solved it. Your personal data is YOUR problem. And the same principle applies. If your traffic flows through American servers, American companies, American infrastructure — the CLOUD Act reaches you too. The US government can compel those companies to hand over your data. GDPR can't stop it. European courts can't stop it. Because the company is American. And American law trumps European privacy when the company is incorporated in Delaware."

Mrs. Higgins: "So I'm subject to American law when I browse the internet?"

"When your traffic passes through American infrastructure? Yes. Which is most of the time. Unless you use a European VPN."

He explained: "With a VPN based in Europe, like Proton VPN, you can encrypt your internet traffic and route it through servers in the Netherlands or other European countries. Your data stays under European privacy legislation. No CLOUD Act. No American jurisdiction. No foreign government reading your browsing history because a company in Silicon Valley was compelled to hand it over."

Mrs. Higgins pulled out her phone. "So if I use Proton VPN—"

"Your traffic is encrypted. Routed through European servers. Protected by European law. Swiss law, specifically, because Proton is Swiss. Switzerland. The country that invented neutrality and banking secrecy. Applied to digital infrastructure. Your data passes through tunnels that the US government cannot compel anyone to open."

"And without the VPN?"

"Your data passes through whoever's infrastructure it encounters. American CDNs. American cloud providers. American analytics scripts. American ad networks. Each one a potential CLOUD Act endpoint. Each one a door the US government can knock on and say 'open.' Through your data goes."

He summed up: "The Netherlands protected 17 million citizens' DigiD data by blocking one takeover. That's significant. But it's one door. One system. There are a thousand other doors. Each one leading to American infrastructure. Each one subject to American law. Your job is to close as many as you can."

Conclusion: Sovereignty Starts at Home

Quasy_Complete closed his laptop. The headline about the Dutch government's decision glowed on the screen for a moment, then faded.

"The Netherlands showed something important," he said. "Digital sovereignty isn't a slogan. It's a decision. A government decided that its citizens' medical records, tax data, and pension information should not be subject to American law. That's not anti-American. That's pro-citizen."

Mrs. Higgins: "Can other countries do the same?"

"They can. They should. Some already are. France. The EU Parliament. The Netherlands. Each one taking a step. Each one building a wall. Brick by brick. Server by server. Law by law."

He stood up. "But sovereignty isn't just for governments. It's for individuals. You can't block a takeover. But you can encrypt your traffic. You can choose European tools. You can route your data through servers that answer to European law, not American law."

His phone buzzed. Notification: "Netherlands blocks US takeover of DigiD. Citizens' data stays European. Sovereignty achieved."

Quasy smiled. "Imagine that. A government protecting its people. And people protecting themselves. Both happening simultaneously. In the same country. On the same day."

He opened Proton VPN. Connected to a server in Amsterdam. His traffic now flowed through Dutch infrastructure, under Dutch law, protected by European privacy regulations.

Mrs. Higgins asked: "Is your data safe now?"

"Safer," he corrected. "Never safe. Safer. Safety is a direction, not a destination. The Netherlands moved in that direction today. I'm moving in that direction now. And if enough people move in that direction, eventually the whole continent arrives."

"Arrives where?"

"At a place where your data belongs to you. Your laws protect you. Your infrastructure serves you. And no foreign government can compel a foreign company to hand over your medical records because they bought the server it lives on."

His phone buzzed again. News alert: "EU Parliament switches from Google to Qwant. European search engine gains institutional adoption."

Quasy nodded. "Brick by brick. Server by server. Search engine by search engine."

He closed the notification. Leaned back. Looked out the window.

The Netherlands had drawn a line. The EU was building a wall. And for once, the wall wasn't keeping people out. It was keeping data in.

Where it belonged.

Protected by the laws of the people who created it. Not the corporations who wanted to buy it. And certainly not the foreign governments who wanted to read it.

Sovereignty. Not as a buzzword. As a practice. One blocked takeover at a time.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 13 Jul 2026 15:24:49 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-48</guid><link>https://carlostkd.ch/roadmap/#post-48</link><title>After Backlash, Meta Removes Muse Image: Or, How a Tech Giant Tried to Steal Your Face, Your Children’s Likeness, and Your Dignity</title><description><![CDATA[Quasy_Complete was scrolling through Instagram on a Tuesday morning when he saw a notification that made him drop his coffee.

"Meta Launches Muse Image: Generate AI Art Using Anyone’s Public Photos. Automatically. Without Consent. Because Why Ask When You Can Assume?"

He stared at the screen. Then he stared at the ceiling. Then he stared at the screen again.

"They did it," he whispered. "They actually did it. They turned Instagram into a digital meat grinder for faces."

His neighbor, Mrs. Higgins, appeared at the door holding her phone with both hands, looking like she’d just witnessed a car accident.

"Quasy! My face is everywhere! I didn’t ask for this! I didn’t even know it existed! And now there are AI images of me as a superhero, a pirate, and… a potato? A POTATO, Quasy! I’m a potato in a cape!"

"Mrs. Higgins," Quasy said, wiping coffee off his shirt, "welcome to the new era of digital privacy. Where your likeness is a commodity, your consent is optional, and your children are fair game for algorithmic remixing."

She sat down heavily. "They used my photos? Without asking?"

"Not just asked. They didn’t even tell you. They just… took. Automatically. By default. Because in the Meta universe, 'opt-out' is a suggestion and 'opt-in' is a myth."

He pulled out his whiteboard. Drew a circle. Wrote "META" inside it. Then drew a smaller circle inside that. Wrote "CONSENT." Then crossed it out with a red marker.

"Let’s break this down," he said. "Because this isn’t just a feature. It’s a philosophy. A business model. A statement."

The Muse Image Debacle: How Meta Tried to Turn Instagram Into a Non-Consensual AI Farm

Meta launched Muse Image, an AI image generator built directly into Instagram, WhatsApp, and the Meta AI app. The twist? It automatically opted in every public Instagram account.

Quasy read the policy aloud: "If your Instagram account is public, Meta has already opted your photos into features that can be used for generative AI remixes. You will not be notified about content created using AI features at Meta. You don’t get asked first. And you don’t get told after."

He paused. "That sentence is a masterpiece of corporate gaslighting. 'You will not be notified.' Translation: 'We stole your face, made a thousand memes, and you’ll only find out when you see yourself as a potato on a stranger’s feed.'"

Mrs. Higgins: "But I have kids! They’re in my photos!"

"And now their faces are in the training set too. No consent. No warning. Just… data. Harvested. Processed. Sold. Or given away for free to anyone who wants to turn your toddler into a cyborg."

He continued. "Reporters tested the feature. Successfully generated images of people they’d never followed. Never interacted with. Without consent. Some called it 'a privacy landmine waiting to detonate.' That’s an understatement. It’s a nuclear warhead wrapped in a Terms of Service agreement."

The Hollywood Backlash: When the Rich and Famous Finally Noticed the Machine Was Eating Them

Hollywood pushed back hard. Creative Artists Agency called the rollout irresponsible. SAG-AFTRA said opting users in by default was "an utter miscalculation of public sentiment."

Quasy laughed bitterly. "Ah, the moment the machine realizes it’s eating its own owners. For years, Meta has scraped data from everyone else. But when the actors—the ones with the unions, the lawyers, and the PR teams—realized their faces were being turned into AI-generated porn or political deepfakes without their permission, suddenly 'consent' mattered."

Mrs. Higgins: "So they only cared because it was celebrities?"

"Precisely. If it was just regular people? They’d have ignored us. But when the people who write the scripts and star in the movies started screaming, Meta panicked. They removed Muse Image after days of backlash. Not weeks. Not months. Days. Because the backlash was loud enough to drown out their quarterly earnings call."

He illustrated: Meta Executive: "Let’s launch Muse Image! Opt everyone in! No consent! No notifications!" Engineer: "But what if people get mad?" Executive: "People are always mad. They’ll forget by Friday." Hollywood Talent Agent: "HEY! YOU JUST USED MY CLIENT’S FACE WITHOUT PERMISSION!" Meta Executive: "Oh. Uh. Okay. We’ll remove it. Quick. Before the union finds out." Regular User: "But I also had my face stolen!" Meta: "Sorry. You don’t have a union. Next."

The Pattern: Data Sharing Is Always On by Default (Until It Isn’t)

The rollout of Muse Image follows a familiar pattern from major tech companies:

    Data sharing is turned on by default.
    The opt-out is buried deep in settings.
    Public backlash becomes the main way users find out what happened to their content.

Quasy listed previous offenses:

    Google did this with AI training on Search image uploads.
    Grok did it with image generation on X.
    Meta did this with scanning camera roll photos on Facebook.
    Meta did this with end-to-end encryption on Instagram (or rather, failed to do it properly).

He sighed. "It’s always the same playbook. Launch the feature. Assume everyone wants to be exploited. Hide the off switch in a maze of menus. Wait for outrage. Then quietly remove the feature and pretend it never happened. Rinse. Repeat."

Mrs. Higgins: "How do I stop it?"

"First, check if you’re still opted in. Go to Instagram → Profile → Three lines → Sharing and reuse. Under 'Allow people to use your content on Instagram and with AI features on Meta,' toggle off BOTH Posts and Reels."

He warned: "Watch the toggles closely. The on and off states look nearly identical. The black button needs to sit on the RIGHT side. Check Posts and Reels separately—they don’t move together. It’s a trap. Designed to make you miss one. So you think you’re safe when you’re not."

"And if I turn it off?"

"This only stops NEW AI remixes. Images already made stay up. And they can’t be undone. Your face is already out there. In the wild. As a potato. As a pirate. As a cyborg. You can’t delete the internet. You can only hope no one remembers."

A safer option? Set your Instagram to private. Settings → Account privacy. Private accounts are visible only to approved followers.

Quasy: "But Instagram, like all Meta platforms, is not designed to be a fully private space. Meta is one of the biggest advertising machines. Its business model depends on collecting, analyzing, and monetizing user data. If you want privacy by default, you need a different platform. A European one. One that doesn’t treat your face as inventory."

The Alternative: Private AI Image Generators (Where Your Face Stays Yours)

If you want to use an AI image generator without worrying that your personal photos, prompts, or creative ideas may be mishandled, Lumo is built around privacy from the start.

Quasy explained: "Your images and prompts are never used to train models or influence outputs for other users. It uses zero-access encryption. Your uploaded images and generated visuals stay private, encrypted, and invisible to prying eyes—including us."

Mrs. Higgins: "So I can make AI art without my face being stolen?"

"Exactly. With Lumo, you upload a photo. You generate an image. No one else sees it. No one else trains on it. No one else turns your toddler into a potato. It’s privacy by design. Not privacy by accident. Not privacy by panic. Privacy by principle."

He contrasted: "Meta: 'Your face is ours. We’ll use it. You won’t know. You can’t stop us. But hey, we removed the feature after you screamed!' Lumo: 'Your face is yours. We won’t touch it. You control everything. We don’t even see it.'"

Conclusion: The Lesson of Muse Image (Or, Why You Should Never Trust a Company That Calls Its Exploitation a 'Feature')

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence, staring at her phone.

"So Meta removed Muse Image," she said slowly. "But they kept the data. They kept the images. They kept the ability to do it again tomorrow."

"Correct," Quasy replied. "They removed the feature because the backlash was too loud. Not because they realized it was wrong. They’ll launch it again under a different name. With a different opt-out buried deeper. And you’ll have to find it again. And scream again. And they’ll remove it again."

He looked at her. "The lesson isn’t 'Meta is evil.' The lesson is 'Never trust a platform that treats your consent as an afterthought.' If your face, your data, your children’s likenesses are being harvested without permission, it’s not a bug. It’s the business model."

Mrs. Higgins: "What should I do?"

"Set your account to private. Toggle off the AI features. And consider moving to a platform that doesn’t treat your privacy as a negotiable line item. A platform where 'opt-in' is the default. Where your data stays yours. Where you’re not a product."

His phone buzzed. Notification: "Meta has removed Muse Image. Your photos are safe. For now."

Quasy read it. Laughed. Deleted it.

"Safe for now," he muttered. "Until the next update. Until the next 'innovation.' Until the next time they decide your face is worth more than your consent."

He opened Lumo. Uploaded a photo of Mrs. Higgins. Typed: "Generate an image of Mrs. Higgins as a queen, wearing a crown made of flowers, in a garden."

Lumo generated the image. Beautiful. Respectful. Private. No one else saw it. No one else trained on it. No one else turned her into a potato.

"There," he said. "This is how it should be."

Mrs. Higgins smiled. "I look like a queen."

"You do. And you’re not a potato."

"Thank you, Quasy."

"Thank Lumo. Or thank the fact that someone finally realized that privacy isn’t a luxury. It’s a right."

He closed the app. Looked out the window.

Somewhere in Silicon Valley, a server hummed. Inside it, millions of faces were being processed. Waiting for the next feature. The next update. The next "innovation."

But here, in Quasy’s kitchen, the queen was safe. The potato was gone. And the privacy was real.

Which, in 2026, is the most revolutionary thing of all.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 13 Jul 2026 15:20:27 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-47</guid><link>https://carlostkd.ch/roadmap/#post-47</link><title>Is Cloaked Legit? An Honest Review of the Privacy App That Tries to Be Everything at Once</title><description><![CDATA[Quasy_Complete was sitting at his kitchen table surrounded by a fortress of sticky notes, each one containing a different password, alias, virtual card number, and the name of a data broker he was trying to opt out of. The table looked like a conspiracy theorist's vision board.

Mrs. Higgins appeared at the door, holding her phone with both hands like it was a newborn.

"Quasy! I found an app called Cloaked! It says it does EVERYTHING! Email aliases! Phone masking! Virtual cards! Password management! Data broker removal! A VPN! Identity theft insurance! It's like a Swiss Army knife for privacy!"

Quasy looked up slowly. "Mrs. Higgins, when something claims to do everything, it usually does nothing well. That's not just cynicism. That's engineering."

"But it has 350,000 users! And a 4.0 on Trustpilot!"

"McDonald's has billions served. That doesn't make it fine dining."

She sat down, undeterred. "It says it's SOC-2 Type II certified! ISO certified! Founded in 2020! It's legitimate!"

Quasy sighed. Pulled out his whiteboard. Drew a line down the middle. On one side wrote "WHAT CLOAKED IS." On the other, "WHAT CLOAKED CLAIMS TO BE."

"Fine," he said. "Let's do this properly. Feature by feature. No hype, no marketing, no green buttons that say 'START FREE TRIAL.' Just facts, friction, and the occasional existential observation about the state of digital privacy."

What Cloaked Actually Does: The All-in-One Privacy Buffet

Cloaked is widely known for its alias features: generating email addresses and phone numbers for every account, protecting your personal data from scammers and making spam easy to block.

But Cloaked goes beyond aliases, bundling data broker removal, a password manager, dark web and SSN monitoring, identity theft insurance, call protection, virtual cards, and a VPN into one subscription.

Quasy stepped back from the whiteboard. "So it's a buffet. One price. Everything you can eat. The question is: is the steak good? Is the salad fresh? Or is it all lukewarm mashed potatoes served under a heat lamp?"

Mrs. Higgins: "I love buffets!"

"Everyone loves buffets. That's why buffets exist. Nobody leaves a buffet hungry. But nobody leaves a buffet saying 'that was the best meal of my life.' Cloaked is a buffet. Let's review each dish."

Feature 1: Email Aliases (The One Thing Cloaked Does Genuinely Well)

Every account you create gets its own generated email address that forwards to your personal inbox. If a service gets breached or starts spamming you, you simply delete the alias and move on.

Unlimited on all plans. Generates aliases quickly. Works consistently well. Highest-rated feature in user reviews.

Quasy nodded approvingly. "This is the feature Cloaked was built around. And it shows. It's fast. It's reliable. It works. You give a different email to every service. One gets breached? Delete the alias. One starts spamming? Delete the alias. It's like having a different front door for every visitor. When one visitor turns out to be a burglar, you brick up their door and pretend it never existed."

Mrs. Higgins: "That's brilliant!"

"It is. It's also not unique. Proton Pass offers unlimited email aliases with its Plus plan. SimpleLogin does it. DuckDuckGo does it. But Cloaked does it well. Credit where credit is due. The steak at this buffet is decent."

Feature 2: Phone Aliases (The Dish That Looks Great on the Menu but Gives You Food Poisoning)

Phone masking works on the same principle as email aliases. Every account gets a generated phone number that forwards calls and texts to your real device without exposing your real number.

On paper, this is fantastic. In practice, Quasy discovered three distinct problems.

Problem 1: The Structural Issue — VoIP Numbers Don't Work Everywhere.

Cloaked generates VoIP numbers. Many services — including Uber, finance apps, and government portals — reject VoIP numbers for SMS verification.

Quasy illustrated: User: "I'll use my Cloaked phone number to verify my bank account!" Bank: "Please enter the code we sent to your phone." Cloaked VoIP Number: "..." Bank: "That number is not recognized. Please use a real phone number." User: "But it IS a real number! It forwards to my real phone!" Bank: "It's a VoIP number. We don't accept those." User: "Why not?" Bank: "Because criminals use VoIP numbers. And we can't tell the difference between you and a criminal. So we assume you're a criminal. Have a nice day."

Mrs. Higgins: "So the phone alias doesn't work for banks?"

"Not for many banks. Not for government portals. Not for Uber. Not for services that require 'real' phone numbers. Cloaked has introduced eSIM numbers to partially address this, but user reports on their reliability are still limited."

"So what CAN you use it for?"

"Services that accept VoIP numbers. Which is... some of them. Occasionally. When the moon is aligned with Jupiter and the developer of the verification system was feeling generous that day."

Problem 2: User Experience Issues.

Some Trustpilot reviewers reported that spam calls and texts actually INCREASED after signing up. And Call Guard — Cloaked's spam filter — sometimes sends legitimate calls straight to voicemail.

Quasy read a review aloud: "I signed up for Cloaked to reduce spam. Now I get MORE spam. And the calls I actually WANT to receive go straight to voicemail. My doctor called me about test results and Cloaked sent her to voicemail. A robocaller offering me a free cruise somehow got through. This app has inverted my expectations entirely."

Mrs. Higgins: "That seems counterproductive."

"It's worse than counterproductive. It's backwards. You installed a spam filter that filters out legitimate callers while admitting spam through the front door. It's like hiring a bouncer who keeps out your friends and lets in the people selling fake Rolex watches."

Problem 3: Recycled Numbers.

Cloaked reclaims and recycles numbers that receive no calls or texts within 60 days. Meaning a number assigned to you may previously have belonged to someone else.

Quasy: "So you get your shiny new Cloaked phone number. You start using it. And suddenly you're receiving calls from debt collectors asking for someone named Greg. Because Greg had this number before you. Greg didn't pay his car loan. Greg's creditors don't know Greg has moved on. They just know this number is active again. And now YOU are Greg. Welcome to Greg's consequences."

Mrs. Higgins: "Can I keep the number?"

"You can lock it. For a fee. But locking a number limits which contacts can reach you through it. So you're paying extra to keep a recycled number that belongs to someone else's debt history. Privacy!"

Quasy's verdict on phone aliases: "Not useless. But if reliable phone alias coverage is your PRIMARY reason for subscribing, test this feature THOROUGHLY during the trial period. Don't commit $120 a year to a phone masking service that can't mask phones for the services you actually need."

Feature 3: Data Broker Removal (The Dish That's Fine But Not the Best in Town)

Data brokers aggregate and sell your personal information without your knowledge or consent to marketers, insurers, and anyone willing to pay.

Cloaked automatically submits removal requests to 400+ data broker sites, resubmitting if data brokers re-list your data.

Quasy: "This is a good feature. 400+ sites is substantial. Automatic resubmission is important because data brokers are like weeds — you pull them, they grow back. You pull them again, they grow back faster. Automation helps."

But — and Quasy held up a cautionary finger — "Dedicated removal services like Incogni and DeleteMe typically offer more granular reporting and faster turnaround. They specialize in this ONE thing. Cloaked bundles it as part of a larger package. If broker removal is your primary need, a specialist tool will serve you better at a lower cost."

Mrs. Higgins: "So Cloaked's data broker removal is..."

"Adequate. Not exceptional. Adequate. Like a general practitioner who can address your basic health concerns but refers you to a specialist for anything complicated. Fine for general maintenance. Insufficient for serious conditions."

Feature 4: Cloaked Pay / Virtual Cards (The Dish That Exists but You Can't Order)

Cloaked Pay generates a unique virtual card number for each purchase. Merchants never see your real payment details. A breach at one retailer won't expose your actual card.

The caveat: Cloaked Pay is currently invite-only. Included in all paid plans in principle. But access is gated and not guaranteed on signup.

Quasy stared at this section for a long time. "So you're telling me... this feature is included in the price... but you can't actually use it... unless you're invited... and being invited isn't guaranteed... even though you're paying for it?"

Mrs. Higgins: "That seems—"

"Dishonest? Misleading? The restaurant equivalent of charging you for dessert and then saying 'dessert is included in your meal, but the pastry chef isn't here today, and we don't know when he's coming back, and you can't have the dessert until he arrives, but please pay for it anyway'?"

"That seems harsh."

"It seems accurate. You're paying for a feature that may or may not be available. That's not a feature. That's a lottery ticket."

He continued. "Meanwhile, Privacy.com offers virtual cards for FREE. Up to 12 cards per month. Free. As in no money. Zero. And they actually let you USE them."

Feature 5: Password Manager (The Dish That's Edible But You've Had Better)

Cloaked's password manager offers smart password generation, autofill, and authentication code support. Covers most people's needs. Doesn't match the depth of standalone password managers if you need hardware key support or shared vaults.

Quasy: "It generates passwords. It autofills. It supports 2FA codes. That's the baseline. That's the minimum viable product for a password manager in 2026. Proton Pass does all of this AND offers zero-knowledge encryption, shared vaults, hardware key support, and unlimited email aliases. Cloaked's password manager is the buffet's bread roll. Filling. Functional. Forgettable."

Mrs. Higgins: "Is it bad?"

"It's not bad. It's adequate. Adequate is the word I keep returning to with Cloaked. Nothing is terrible. Nothing is exceptional. Everything is adequate. Which, for $120 a year, feels like a lot of money for 'fine.'"

Feature 6: Monitoring, Identity Theft Insurance, and Call Protection (The Side Dishes Nobody Came For)

Dark web and SSN monitoring sends real-time alerts if your data appears in a breach. All plans include $1 million in identity theft insurance with 24/7 resolution support. Call Guard blocks spam and robocalls before they reach you.

Quasy: "Dark web monitoring is useful. Knowing your data is in a breach before someone exploits it is valuable. The $1 million identity theft insurance is a safety net — you hope you never need it, but it's there if you do. Call Guard, as we discussed, sometimes blocks the wrong calls. Like a security guard who tackles the mayor and waves through the pickpocket."

Feature 7: VPN (The Dish That's Still in the Kitchen)

A VPN encrypts your internet connection, preventing your ISP, network operators, and anyone on the same WiFi from seeing what you're doing online.

Cloaked recently added a VPN. Currently in beta. Included with all plans. Should be treated as a bonus rather than a primary reason to subscribe.

Quasy rubbed his temples. "Beta. It's in beta. You're paying for a VPN that's in beta. That's like buying a car with an engine that's 'still being tested.' The car has four wheels and a steering wheel, but the engine might explode. We're working on it. Please enjoy the radio in the meantime."

Mrs. Higgins: "Should I use it?"

"Use Proton VPN instead. It's been around for years. Audited. Open source. Not in beta. Actually works. Cloaked's VPN is a bonus feature bundled into a subscription to make the subscription look like a better deal. 'Look at all these features for one price!' Yes, but some of those features are theoretical. Like a gym membership that includes access to a pool that hasn't been filled with water yet."

What Does Cloaked Cost? (The Moment of Truth)

Quasy pulled up the pricing table on his whiteboard:
Plan	Monthly	Annual (monthly equiv.)	Annual Total
Individual	$12.49/mo	$9.99/mo	$119.99/year
Couple	$19.99/mo	$14.99/mo	$174.99/year
Family (you + 3)	$29.99/mo	$24.99/mo	$299.99/year

"Now," Quasy said, drawing a second table, "let's compare this to building your OWN privacy stack from specialist tools."
Tool	Function	Cost
Proton Pass Plus	Password manager + email aliases	Free tier or ~$35.88/year
Proton VPN Plus	VPN	Free tier or ~$83.88/year
Proton Unlimited	Full ecosystem (pass, VPN, mail, drive, docs, sheets)	~$119.88/year
Incogni	Data broker removal	~$96/year
Privacy.com	Virtual cards	Free (up to 12/mo); Plus from $5/mo
TOTAL		$96/year to ~$275.88/year

Quasy tapped the whiteboard with his marker. "For individuals, the DIY stack starts at $96 per year. Cloaked costs $119.99 per year. If you use free tiers wherever available, the DIY route is CHEAPER. And the specialist tools will outperform Cloaked on their specific functions."

Mrs. Higgins studied the tables. "But Cloaked has everything in ONE app."

"And that's the value proposition. Convenience. One app. One subscription. One login. One dashboard. The question is: is that convenience worth paying more for tools that are individually weaker than their standalone equivalents?"

He enumerated: "Proton Pass does passwords BETTER. Proton VPN does VPN BETTER. Incogni does data broker removal BETTER. Privacy.com does virtual cards BETTER. And most of them are free or cheaper. Cloaked does everything ADEQUATELY. You're paying a premium for adequacy across the board instead of excellence in specific categories."

Mrs. Higgins: "So should I cancel?"

"Depends. What do you actually need?"

Is Cloaked Worth It? (The Verdict Nobody Wants Because Nobody Likes Nuance)

Quasy delivered his final assessment like a judge reading a verdict:

"Cloaked is legitimate. Not a scam. Real company. Real certifications. Real users. Its alias system genuinely works. If you want ONE app covering email aliases, phone masking, broker removal, and identity monitoring, and you don't need best-in-class depth in any single category — Cloaked is a solid start."

BUT.

He raised a cautionary finger.

"If you need phone aliases to work with banks and government services — they probably won't. If you need a reliable VPN — it's in beta. If you need virtual cards — they're invite-only. If you need data broker removal — specialists do it better and cheaper. If you only need one or two of the bundled features — the DIY route is more cost-effective."

And finally:

"If what you actually need is email aliases, password management, and a privacy-first VPN — Proton is worth comparing directly."

He turned to Mrs. Higgins. "Proton Pass generates unique strong passwords for every account. Autofills credentials across devices. Provides email aliases — unlimited with Proton Pass Plus. All protected with zero-knowledge encryption. Proton VPN encrypts your connection and is included with every Proton plan."

"And the company?" she asked.

"Swiss. Operates outside the 14 Eyes surveillance agreement. Under some of the world's strictest privacy laws. Not in beta. Not invite-only. Not recycled numbers from someone named Greg's debt history."

Mrs. Higgins put her phone down. "So Cloaked is..."

"Fine. Adequate. A solid start. Not a scam. Not exceptional. A privacy buffet where the email aliases are the steak, the phone masking is the sushi that's been sitting out too long, the VPN is the dessert that hasn't arrived, and the virtual cards are a dish that exists on the menu but the kitchen won't let you order."

"That's a very specific metaphor."

"I've been thinking about buffets a lot."

Conclusion: The Best Privacy Stack Rarely Comes from a Single App

Quasy_Complete erased the whiteboard. Wrote one sentence in the center:

"The best privacy stacks rarely come from a single app."

"Mrs. Higgins, privacy isn't a product. It's a practice. Cloaked offers convenience. One app, one subscription, one dashboard. That convenience has value. But convenience comes at the cost of depth. The specialist will always outperform the generalist in their specialty. Proton Pass will always be a better password manager than Cloaked's password manager. Proton VPN will always be a better VPN than Cloaked's beta VPN. Incogni will always be a better data broker removal tool than Cloaked's bundled version."

"Privacy is assembling the right tools for YOUR specific needs. Not buying a pre-packaged kit that claims to do everything. Because pre-packaged kits are designed for the AVERAGE user. And you, Mrs. Higgins, are not average. You are a person who installed SuperClean Antivirus Pro 2026 to remove a virus that the antivirus itself WAS. You need SPECIFIC tools for SPECIFIC problems. Not a Swiss Army knife with a blunt blade."

Mrs. Higgins nodded slowly. "So what should I do?"

"Start with what you need MOST. Email aliases? Proton Pass. VPN? Proton VPN. Data broker removal? Incogni. Virtual cards? Privacy.com. Build your stack piece by piece. Test each tool. Keep what works. Replace what doesn't."

"And Cloaked?"

"Cloaked is a solid start for people who want one app and don't need best-in-class anything. If that's you, use it. If it's not — and it probably isn't — build your own stack. It'll be cheaper. It'll be better. And you'll know exactly what each tool does, why you have it, and whether it works."

Mrs. Higgins picked up her phone. "I'm going to compare them."

"Good. That's the right answer. Compare. Test. Evaluate. Don't trust reviews — including this one. Trust your own experience during the trial period."

His phone buzzed. Notification from Cloaked: "Your trial is ending soon! Subscribe now for $119.99/year to keep all features! Don't lose your aliases! Act now!"

Quasy read it aloud. "Don't lose your aliases. Act now. Because urgency is how subscriptions trap you. Fear of loss. Loss of aliases. Loss of convenience. Loss of the comfort of having everything in one place."

He deleted the notification. Opened Proton Pass. Created a new email alias. It took three seconds. It was unlimited. It was free.

"See?" he said. "No urgency. No 'act now.' No 'don't lose your aliases.' Just an alias. Generated. Free. Working."

Mrs. Higgins smiled. "I like that better."

"Of course you do. It doesn't try to sell you a beta VPN and an invite-only virtual card along with it."

He closed his laptop. The whiteboard was blank. The sticky notes were in the trash. The passwords were in Proton Pass. The aliases were unlimited. The VPN was not in beta.

And if anyone asked him whether Cloaked was legit?

He'd say: "Yes. It's legit. It's also adequate. And adequate, in the world of privacy, is the enemy of excellent."

Mrs. Higgins left. Quasy sat alone.

His phone buzzed one last time. Email to alias: "Dear alias user, we found your data on 14 data broker sites. Would you like to remove it?"

Quasy smiled. "Incogni. Already on it."

He closed the email. Leaned back. Looked at the ceiling.

Privacy wasn't a buffet. It was a kitchen. And the best meals were the ones you cooked yourself. With the right ingredients. From the right suppliers. None of which were in beta.

And none of which charged $120 a year for a phone number that used to belong to Greg.

Greg's debts were Greg's problem. Quasy's privacy was Quasy's project. And the project was progressing nicely.

One alias at a time.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 08 Jul 2026 19:25:18 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-46</guid><link>https://carlostkd.ch/roadmap/#post-46</link><title>What Is Spyware and How Can You Protect Yourself?</title><description><![CDATA[Quasy_Complete was sitting in his living room when he noticed his phone was warm. Not "I've been using it" warm. Not "it's charging" warm. "Something is happening inside this device that I did not authorize" warm.

He picked it up. The screen was off. He hadn't touched it in an hour. And yet, the phone was radiating heat like a small toaster that had developed ambitions.

"Interesting," he muttered. "My phone is hot, the battery has dropped 18% in one hour while doing nothing, and the mobile data usage says I've consumed 2GB today. While the phone was sitting on a table. Doing nothing."

His neighbor, Mrs. Higgins, appeared at the door with her own phone held at arm's length.

"Quasy! My phone's camera just turned on by itself! I was making tea and the camera light came on! No app was open! It just... watched me!"

"Mrs. Higgins," Quasy said slowly, putting his own phone down, "I believe we have a spyware situation."

"A what situation?"

"Someone is going through our digital desk drawers. Without permission. While we make tea."

She sat down heavily. "Who? Why? What do they want?"

"Those are excellent questions. The answers are: probably someone we've never met, because our data is valuable, and because they can. Welcome to the four circles of spyware hell. Please leave your dignity at the door."

The Four Main Types of Spyware (A Field Guide to Digital Parasites)

Quasy produced a whiteboard from nowhere — because in satirical narratives, whiteboards materialize on demand — and drew four boxes.

Type 1: Adware (The Nosy Neighbor Who Sells Your Secrets to Advertisers)

Adware monitors your browsing habits and serves targeted ads based on your behavior. According to Kaspersky threat intelligence, adware accounted for 62% of all mobile malware detections in 2025.

Adware is usually bundled with free software or apps. A free flashlight app that functions as advertised — it's less suspicious that way — while quietly making money by sending your browsing data to ad networks.

Quasy illustrated: "You download a free flashlight app. The flashlight works! Hooray! You can see in the dark! Meanwhile, the app is note-taking everything you do online. Every website. Every search. Every late-night impulse purchase of garden gnomes at 2 AM. It packages this data and sells it to ad networks. Who then show you ads for garden gnomes. At 2 AM. On every website you visit. Forever."

Mrs. Higgins: "Is that why I keep seeing ads for orthopedic shoes?"

"Did you search for orthopedic shoes once?"

"Yes! One time! In March!"

"And now it's July. And the internet still thinks you need orthopedic shoes. That's adware. It remembered. It never forgot. It will never forget. The internet has the memory of an elephant and the discretion of a megaphone."

Adware can be relatively harmless when its goal is just showing you ads. But when it quietly harvests personal data — name, date of birth, location — to sell to data brokers, it becomes a serious privacy threat.

Quasy: "Treat ALL adware as a risk. Even the 'harmless' kind. Because the harmless kind today becomes the data-harvesting kind tomorrow. It's like a stray cat: starts by eating your food, ends by moving in and inviting its friends."

Type 2: Keyloggers (The Invisible Secretary Who Records Everything You Type and Sends It to Strangers)

Keyloggers record every keystroke you make. They steal passwords, credit card numbers, private messages, then send them to whoever planted the spyware.

Most keyloggers are delivered via trojan horse viruses — malware disguised as legitimate downloads. Pirated software and cracked apps are among the most common vessels.

Quasy imagined the scenario: User: "I found a FREE cracked version of Photoshop! No subscription! No payment! Just download and install!" Cracked Photoshop: [installs perfectly, works normally] User: "Amazing! It works!" Hidden keylogger inside the cracked app: [recording every keystroke] "Let's see... they typed 'BankLogin.com'... username is 'JohnDoe2026'... password is 'FluffyBunny!'... oh, and they just typed their credit card number into an online store... 4532 8819 4477 2093... expiry 09/28... CVV 342... thank you very much." User: "This free Photoshop is GREAT!" Keylogger: "Agreed. For both of us."

Mrs. Higgins looked horrified. "People download cracked software?"

"People download cracked software constantly. Because paying $20 a month for a legitimate app feels expensive, but having your bank account emptied by a keylogger hidden inside a cracked download apparently feels like a bargain. It's the digital equivalent of accepting a free meal from a stranger in a van. The meal is real. The van has no windows. You will regret both."

You won't know anything is wrong until the damage is done — when your bank alerts you to a fraudulent transaction. By which point the keylogger has been recording for days. Weeks. Months. Every password. Every message. Every credit card number. Every regrettable 2 AM email to your ex.

Quasy: "The keylogger doesn't judge. It just records. 'Ah, they typed "I miss you" at 3 AM and then deleted it. Noted. Filed. Sent to headquarters.' It's the most loyal secretary you never hired. Working for someone else. Documenting your every keystroke with the dedication of an archivist and the ethics of a pickpocket."

Type 3: Stalkerware (The Intimate Betrayal Nobody Warns You About)

Stalkerware monitors location, messages, calls, and browsing. Installed without the owner's knowledge or consent, usually by a partner, family member, or employer. Unlike other spyware, stalkerware requires physical access to install.

Legally sold apps marketed as parental controls — such as mSpy and FlexiSPY — are frequently used to monitor adult partners without consent. They run invisibly, log GPS location, and read messages in real time.

Quasy's tone shifted. The humor dimmed. This one was different.

"Mrs. Higgins," he said quietly, "this is the one that disturbs me most. Not because of the technology. Because of the human element."

Mrs. Higgins: "What do you mean?"

"Adware targets everyone. Keyloggers target the careless. Zero-click targets the important. But stalkerware targets the vulnerable. Specifically, people in controlling relationships. Partners who install monitoring software on their significant other's phone. Without consent. Without knowledge. The phone becomes a tracking device. Every location logged. Every message read. Every call recorded. By the person who claims to love you."

Mrs. Higgins was silent.

"These apps are sold legally. Marketed as 'parental controls.' 'Monitor your child's phone usage.' 'Track your family's location for safety.' But they're used to monitor adults. Partners. Spouses. The Google Play Store listing says 'Know where your loved ones are.' The reality is: know where your partner is. Read their messages. Track their movements. Monitor their contacts. All without their knowledge."

Quasy's voice was measured but firm: "If you're concerned that stalkerware may be on your device, the Coalition Against Stalkerware offers confidential guidance. There are support organizations in every country. This isn't just a tech problem. It's a safety problem. And if someone is monitoring your phone without your consent, that person does not respect your autonomy. Which is a larger conversation than any app can solve."

Type 4: Zero-Click Mercenary Spyware (The Military-Grade Ghost That Doesn't Need Your Cooperation)

Zero-click spyware exploits vulnerabilities in device operating systems. It doesn't require any action from the device owner to install itself. Hence "zero-click."

In 2021, an investigation coordinated by Forbidden Stories with support from Amnesty International found NSO Group's Pegasus spyware on the devices of journalists, lawyers, and human rights defenders worldwide. Victims didn't click anything. Their devices were compromised through an iMessage vulnerability.

Increasingly, exploit chains developed for mercenary spyware like Pegasus are being used not just by repressive states but by cybercriminals. Everyday users, not just high-value targets, have something to fear.

Quasy leaned back in his chair. "This is the one that should keep you awake at night. Not because you'll definitely be targeted. But because you CAN'T PREVENT IT."

Mrs. Higgins: "Can't prevent it? At all?"

"Zero-click means zero interaction. You don't click a link. You don't download an app. You don't open a file. You receive a message. Your phone processes it automatically. And the spyware installs itself through a vulnerability in the operating system that neither you nor the manufacturer knew existed."

He illustrated: Journalist: "I'm safe! I never click suspicious links! I use strong passwords! I have 2FA!" Pegasus: "That's adorable. I didn't need you to click anything. I came in through the iMessage rendering engine. Your phone opened the message automatically. The message contained an exploit. The exploit installed me. I now have access to your microphone, camera, messages, location, and files. Your password strength is irrelevant. Your 2FA is irrelevant. Your caution is irrelevant. I am inside." Journalist: "But I didn't do anything wrong!" Pegasus: "Correct. You existed. That was enough."

Mrs. Higgins whispered: "How do you stop that?"

"You update your operating system. Constantly. The moment patches are available. Because zero-click exploits rely on vulnerabilities, and updates patch vulnerabilities. That's your best defense. Not perfect. But best."

"And if my profession puts me at elevated risk?"

"Request analysis from Access Now's Digital Security Helpline or Amnesty International's Security Lab. They help people who are being targeted by sophisticated spyware. Journalists. Activists. Lawyers. People whose phones are weapons aimed at them by governments."

Who Is Most at Risk? (Spoiler: Everyone, But Some More Than Others)

Quasy reviewed the risk matrix:

    Adware: Everyone using ad-supported free apps. Which is everyone. Including you. Especially you. Yes, you, the person who just installed "Free Battery Optimizer Pro 2026."
    Keyloggers: Everyone who downloads apps. But especially those who download from unofficial sources like torrent sites carrying pirated content. If you've ever searched "[expensive app name] free download full version crack 2026," congratulations, you're in the highest risk category.
    Stalkerware: People in controlling relationships and employees under invasive monitoring. The most personally targeted form of spyware. Not random. Directed. By someone who knows you.
    Zero-click: High-value targets — journalists, activists, lawyers, executives. But increasingly, anyone with a smartphone. Because spyware that was once exclusive to intelligence agencies is now trickling down to cybercriminals like designer clothes appearing in discount bins.

Quasy: "Businesses face compounded exposure. A keylogger on one employee device compromises shared credentials and systems. If your business handles sensitive client data, one infected phone becomes a liability that affects everyone. It's like having one employee who leaves the office door unlocked every night. Except the door is digital, the lock is a password, and the employee doesn't know they've lost the key."

How to Spot If Your Device Has Spyware (The Digital Self-Examination)

Spyware works mostly invisibly. But there are signs:

    Battery draining faster than usual despite no change in usage patterns.
    Mobile data usage spikes unexpectedly and inexplicably.
    Device runs hot while idle — or your screen, microphone, or camera activates for no reason.
    Unfamiliar apps appear that you don't remember installing.

Quasy checked his own phone against the list: Battery draining? Yes. Data spike? Yes. Hot while idle? Yes. Unknown apps? Let me check...

He scrolled through his app list. Found something called "System Update Service." Developer: Unknown. Install date: 3:47 AM. Size: 2KB. Background data consumed: 4.7GB.

"Found it," he announced. "'System Update Service.' Not a system update. Not a service. Just a name designed to look boring enough that you'd never question it. Like naming a burglar 'Maintenance Man' and giving him a clipboard. The clipboard isn't real. The burglary is."

Quasy added: "Zero-click mercenary spyware is particularly dangerous because it may produce NONE of these signs. If your profession puts you at elevated risk, the recommended path is to request analysis from Access Now's Digital Security Helpline or Amnesty International's Security Lab. Don't try to diagnose military-grade spyware yourself. That's like trying to perform surgery on yourself using a YouTube tutorial. The outcome will be educational but catastrophic."

How to Remove Spyware (First Instinct: Wrong Instinct)

Your first instinct might be to download a spyware removal tool. Don't be hasty. You could be creating or compounding the very problem you're trying to solve.

Quasy closed his eyes. "And here we are again. The great irony of the digital security industry: the cure is often the disease. You search 'spyware remover' on the Play Store. You find 500 results. 490 of them are spyware themselves. You install 'SuperSpywareKiller Pro 2026' to remove spyware. 'SuperSpywareKiller Pro 2026' IS spyware. You used fire to fight fire. Now everything is on fire. Including your banking credentials."

For Android users, there are proper step-by-step guides to removing malware safely. For iPhone users, iOS limits third-party scanning — update iOS immediately, review installed profiles under Settings → General → VPN & Device Management, then contact Apple Support.

Quasy: "The iPhone approach is simpler but more restrictive. Update. Check profiles. Call Apple. It's like owning a car where you can't open the hood. If something's wrong, you take it to the dealer. Annoying? Yes. But also safer than letting every mechanic in town poke around your engine with tools they downloaded from a questionable website."

How to Protect Your Device Against Infection (Common Sense, Which Is the Least Common of All Senses)

Protection failures aren't caused by exotic, unprecedented threats. They're caused by common behaviors: reusing passwords, unencrypted connections, and software from unofficial sources.

Before Downloading an App:

Only install from official stores: Stick to official app stores. Check developer names. Download desktop software only from the developer's own site.

Quasy: "If the app isn't on the Play Store or App Store, ask why. If the developer's website looks like it was designed in 1997 and the download button says 'DOWNLOAD NOW (SAFE)' in blinking red text, it is not safe. Nothing that says 'SAFE' in blinking red text has ever been safe."

Watch out for 'free' tools — including anti-spyware tools: See above. The tool you download to remove spyware may be spyware.

Quasy: "This bears repeating because nobody listens the first time. 'Free Spyware Remover' is the most dangerous phrase in the English language. More dangerous than 'hold my beer' and 'what's the worst that could happen' combined."

Keep your operating system updated: All forms of malware target known OS vulnerabilities. Updating patches vulnerabilities. Best defense against zero-click exploits like Pegasus.

Quasy: "Updates are annoying. They interrupt your day. They move buttons. They change layouts. They also patch the security hole that would let a stranger read your messages through your phone's microphone. So when your phone says 'Update Available,' the correct response is not 'Remind me tomorrow.' The correct response is 'Install now, before tomorrow becomes the day someone hacks me through a vulnerability that was patched six months ago.'"

Review app permissions periodically: Revoke permissions that don't match the app's function.

Quasy reviewed Mrs. Higgins' phone again:

    Flashlight app: Requests microphone access. WHY?
    Calculator app: Requests location access. WHY?
    Weather app: Requests contacts access. WHY?
    Wallpaper app: Requests camera access. WHY?

"Mrs. Higgins, your flashlight needs to see in the dark. Not listen to your conversations. Your calculator computes numbers. It doesn't need to know where you are. Your weather app tells you if it's raining. It doesn't need to know who your friends are. And your wallpaper — a static image — does not need to take photographs."

"They asked nicely!" she protested.

"They asked with green buttons and friendly text. Behind those green buttons is a data-harvesting operation that collects your location, contacts, and audio to sell to advertisers who will use it to show you more ads for orthopedic shoes."

When Using Any Apps:

Use different passwords across accounts: When every account has a unique credential, keyloggers can't capture multiple accounts by capturing one. Proton Pass generates and stores unique passwords with zero-knowledge encryption.

Quasy: "If you use 'Higgins2026!' for your email, bank, social media, shopping, and cloud storage, and a keylogger captures it once, the hacker now has the key to your entire digital life. One password. Five doors. All opened. Simultaneously. Proton Pass creates a unique password for every door. The hacker gets through one and hits a brick wall on the others."

Use VPN on public WiFi: A VPN protects you from public WiFi hosts who monetize their "free" service by selling your browsing history to ad-tech companies. Proton VPN encrypts your connection so intercepted data is unreadable.

Quasy pictured the local café: Café Owner: "Free WiFi for customers!" WiFi Network: Named "CafeGuest" — Password: "coffee123" Mrs. Higgins: Connected. Browsed. Logged into her bank. Checked email. Shopped for orthopedic shoes. Café WiFi Router: Logging every URL. Every login. Every search. Packaging it for sale to ad networks. Hacker in the corner seat: Also connected. Running a packet sniffer. Capturing Mrs. Higgins' unencrypted traffic. Her bank login. Her email password. Her shoe size.

Mrs. Higgins: "This latte is delicious!" Café WiFi: "Your banking password is also delicious. Thank you."

Quasy: "Public WiFi without a VPN is like writing your passwords on postcards and handing them to strangers. 'Dear Bank, my password is FluffyBunny2026! Please check my balance. Love, Mrs. Higgins.' Everyone handling that postcard can read it. A VPN puts the postcard in an envelope. A sealed, encrypted envelope that nobody can open. Including the café. Including the hacker. Including the ISP."

Conclusion: Your Phone Is Watching You (But You Can Reduce the Audience)

Quasy_Complete looked at his phone. Then at Mrs. Higgins' phone. Then at the whiteboard with its four boxes.

"We have four types of spyware," he summarized. "Adware, which follows you around and sells your habits. Keyloggers, which record everything you type and send it to strangers. Stalkerware, which is installed by someone you know and tracks your every move. And zero-click mercenary spyware, which is installed by someone you DON'T know and does all of the above without you doing anything wrong."

Mrs. Higgins looked at her phone with suspicion. "So my phone might have spyware RIGHT NOW?"

"Your phone MIGHT have spyware right now. My phone MIGHT have spyware right now. Everyone's phone MIGHT have spyware right now. The question isn't 'is it there?' The question is 'what kind, who put it there, and how do I get it out?'"

She put her phone on the table like it was a suspicious package. "What do we do?"

"Update. Audit. Protect. Update your OS. Audit your apps and permissions. Protect your connections and credentials. Use Proton Pass for unique passwords. Use Proton VPN on public WiFi. And for the love of everything sacred, stop downloading free flashlight apps."

"What about your phone? It was warm earlier."

Quasy looked at his phone. Picked it up. Opened Settings. Checked app permissions. Found "System Update Service" still there, consuming data in the background.

He uninstalled it. It resisted. He revoked admin privileges. It still resisted. He booted into safe mode. Uninstalled it successfully. Restarted. Checked again. Gone.

"One ghost evicted," he announced. "Unknown how many remain."

His phone buzzed. Notification: "System Update Service has been reinstalled."

Quasy stared at the screen. Looked at Mrs. Higgins. Looked at the ceiling.

"It reinstalled itself," he said flatly.

"Can it do that?"

"Apparently. Like a zombie. You kill it. It comes back. You kill it again. It comes back again. Each time hungrier."

He performed a factory reset. Backed up only essential files to Proton Drive. Wiped the device. Reinstalled only trusted apps manually. Did NOT restore from backup.

The phone was clean. Cold. Quiet. The battery lasted two days. No mysterious data consumption. No phantom camera activations.

"There," he said. "Clean. For now."

Mrs. Higgins: "For now?"

"Spyware is like weeds. You pull them. They come back. You pull them again. New ones grow. The garden is never permanently weed-free. But you keep pulling. Because the alternative is letting the weeds take over. And the weeds in this metaphor are digital parasites that record your keystrokes, track your location, read your messages, and sell your data to strangers in countries you've never visited."

His phone buzzed one final time. Notification: "Your phone is clean. No threats detected. Have a nice day."

Quasy read it. Suspiciously. Because after learning about spyware, trust in notifications is the first casualty.

"Is that notification real?" Mrs. Higgins asked.

"I don't know," he admitted. "But it's the most reassuring lie I've received all week. And I'll take it."

He put the phone down. Poured himself a coffee. Looked out the window.

The world was full of spyware. Adware in flashlights. Keyloggers in cracked apps. Stalkerware in relationships. Zero-click exploits in iMessage. Four types. Four threats. Four levels of invasion.

And Quasy_Complete sat in his kitchen, drinking coffee, knowing that somewhere, in a server farm in a country with lax extradition laws, his data was probably already stored. Labeled. Indexed. Ready to be sold.

But not today.

Today, his phone was clean. His passwords were unique. His connection was encrypted. And his flashlight app was exactly what it claimed to be.

A flashlight.

Nothing more.

Which, in 2026, is the highest compliment you can give an app.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Tue, 07 Jul 2026 16:19:56 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-45</guid><link>https://carlostkd.ch/roadmap/#post-45</link><title>Is TruthFinder Legitimate? Yes. Is It Also a Data Broker That Packages Your Life Into a Report For $30 a Month?</title><description><![CDATA[Quasy_Complete was sitting at his kitchen table when Mrs. Higgins burst through the door holding her phone like it contained evidence of a crime.

"Quasy! I found a website called TruthFinder! It says it can find ANYONE'S background! Criminal records! Property value! Relatives! Dating profiles! It says it knows EVERYTHING about EVERYONE!"

"Mrs. Higgins," Quasy replied calmly, "if a website claims to know everything about everyone, it's either the NSA or a data broker. One is a government agency. The other is a company in San Diego charging $30 a month for information it copied from public records and never verified."

She sat down heavily. "But it said it found shocking information about my neighbor! It showed me a progress bar that said 'WARNING: The following report contains UNCENSORED and POTENTIALLY DISTURBING information!' And then it made me wait while it 'compiled data'!"

Quasy leaned forward. "And how did you feel during that wait?"

"Terrified! Intrigued! I couldn't look away! It was like watching a horror movie about someone I know!"

"And that," Quasy said, "is exactly what TruthFinder wants you to feel. Fear. Curiosity. Urgency. The digital equivalent of a carnival barker telling you there's something SHOCKING inside the tent. Step right up. Pay your $30. Prepare to be amazed. Or horrified. Or both. Ideally both."

How TruthFinder Works: The Data Buffet You Never Consented To

TruthFinder compiles real data from publicly available records and organizes it into a single report. Data sources include:

    Government Records: Court records, criminal and traffic records, sex offender registries.
    Property Records: Home ownership, property value, tax assessment data.
    Personal Records: Age, relatives, associates, education, employment history.
    Online Presence: Social media profiles, dating profiles, other publicly available internet activity.

Reports cover most adults living in the United States. Data can stretch back decades.

Quasy read the list slowly: "Court records. Property values. Relatives. Associates. Education. Employment. Social media. Dating profiles. That's not a background check. That's a biography. Written without consent. Published without permission. Sold for monthly subscription."

Mrs. Higgins gasped: "They have my dating profiles?"

"If you have dating profiles that are publicly accessible, then yes. They have your dating profiles. Along with your property value, your relatives, your associates, your employment history, and whatever traffic ticket you got in 2011 for failing to signal at a roundabout."

"I got a ticket for that?"

"Allegedly. According to data TruthFinder never verified."

He paused. "And that's the key phrase: never verified. TruthFinder doesn't verify its data. It aggregates from third-party data brokers who explicitly disclaim accuracy. They compile information from sources that say 'we don't guarantee this is correct' and then TruthFinder sells it to you as 'the most accurate information available.'"

Mrs. Higgins: "So it might be wrong?"

"It might be VERY wrong. Your report could mix you up with someone who shares your name. Your cousin's criminal record could appear in your report. A traffic ticket from 2012 could be displayed as a serious offense. A house you sold in 2014 could still be listed as your primary residence."

"So the information might be false?"

"The information might be false, outdated, incomplete, or attributed to the wrong person. And someone could be making decisions about you based on it. Hiring decisions. Housing decisions. Relationship decisions. All based on unverified data sold for profit by a company in San Diego."

Is TruthFinder a Scam? (Technically No. Practically? Let's Discuss.)

TruthFinder isn't a scam. It's a legitimate, registered company founded in 2015. It provides a real service in exchange for a monthly fee. But "legitimate" doesn't mean "problem-free."

Quasy enumerated the issues like a man reading charges in a courtroom:

Charge 1: Billing Practices

TruthFinder operates on a subscription model. There's no option for a one-off report. Many users complain about difficulty canceling. Charges appear despite cancellation. The Better Business Bureau receives frequent complaints about being charged after canceling, being unable to reach customer support, or being forced to call a phone number to cancel rather than doing it online.

Quasy imagined the cancellation process: User: "I'd like to cancel my TruthFinder subscription." TruthFinder Website: "Please call 1-800-WE-HAVE-YOUR-MONEY between the hours of 9 AM and 'whenever we feel like answering' to speak to a representative who will transfer you to another representative who will put you on hold for 40 minutes and then ask why you're leaving." User: "Can't I just cancel online?" TruthFinder: "Ha ha. No." User: "..." TruthFinder: "Your card has been charged for another month."

Mrs. Higgins: "That sounds like a gym membership."

"Identical business model. Once they have your payment details, leaving is a bureaucratic obstacle course designed to exhaust you into submission. The difference is that gyms want you to stop coming. TruthFinder wants you to keep paying while you forget you're subscribed."

Charge 2: Legal Restrictions

TruthFinder is not FCRA-compliant. The Fair Credit Reporting Act sets standards for consumer reporting agencies. It's illegal to use TruthFinder reports for employment screening, tenant evaluation, or credit decisions.

However, people use it for exactly those purposes anyway.

Quasy: "Landlords run TruthFinder reports on prospective tenants. Employers run TruthFinder reports on candidates. Both are illegal. Both happen regularly. Because TruthFinder doesn't verify its data and isn't FCRA-compliant, the information used to deny someone a job or an apartment could be wrong. And that person would never know why they were rejected."

Mrs. Higgins: "That's awful!"

"That's the business model. Sell unverified data. Disclaim accuracy. Let people misuse it. Collect revenue. Repeat."

The FTC found that TruthFinder and its sister site, Instant Checkmate, were effectively operating as consumer reporting agencies without complying with FCRA requirements for accuracy and permissible-purpose certification.

"So," Quasy summarized, "they were acting like a consumer reporting agency without following the rules that consumer reporting agencies must follow. That's like driving a taxi without a license, ignoring traffic lights, and then telling passengers 'we don't guarantee we'll get you there safely' after charging them for the ride."

Charge 3: Questionable Accuracy

In September 2023, the FTC took action against TruthFinder and Instant Checkmate. They were ordered to pay $5.8 million in civil penalties. The FTC found the companies misled users by advertising "the most accurate information available" while relying on third-party data they never verified.

They also sent notifications implying someone had a criminal or arrest record, when the only record was a traffic ticket.

Quasy read the FTC finding aloud: "So the company that claims to deliver TRUTH in its very name was fined $5.8 million for lying about accuracy. TruthFinder. The company named after truth. Caught being untruthful. About truth. You can't write irony this thick. It collapses under its own weight."

Mrs. Higgins: "They said people had criminal records when they just had traffic tickets?"

"Yes. A speeding ticket became a 'potential criminal record.' A parking violation became an 'arrest history.' A failure to signal at a roundabout became a 'DISTURBING REVELATION' displayed after a suspenseful progress bar accompanied by warnings about 'graphic content.'"

"That happened to me!" Mrs. Higgins exclaimed. "It said my neighbor had a 'shocking criminal history' and when I paid to see it, it was a speeding ticket from 2009!"

"And that's the carnival trick. Show you the warning. Make you wait. Build tension. Collect your payment. Then reveal something anticlimactic. 'Shocking revelation: your neighbor once forgot to renew his vehicle registration.' Groundbreaking journalism. Truly."

Charge 4: Privacy

Searches are anonymous — the person being searched isn't notified. But you must share your own name, email, and payment details with TruthFinder. Your search activity could be retained and correlated with your profile over time.

Quasy: "So while you're searching for information about others, TruthFinder is collecting information about you. Your name. Your email. Your payment method. Your search history. Your IP address. Everything you look up. Everyone you investigate. All stored. All correlated. All potentially sellable."

Mrs. Higgins went pale. "I searched for my neighbor."

"And TruthFinder now knows you searched for your neighbor. They know your name, your email, your credit card, and your interest in your neighbor's background. If they wanted to, they could add 'searches for neighbors on TruthFinder' to YOUR data profile. Which someone else could purchase. To learn about you. While you were learning about your neighbor. It's surveillance inception."

Charge 5: The User Experience (Or, the Carnival Barker's Digital Successor)

While creating a report, the web interface displays multiple progress bars and pop-ups warning about graphic content or alarming revelations. You're repeatedly warned that information is uncensored and could be shocking.

Quasy described the experience: "Step 1: Enter a name. Step 2: Watch a progress bar fill slowly while text appears saying 'SEARCHING DATABASES...' Step 3: Another progress bar: 'COMPILING RECORDS...' Step 4: A pop-up: 'WARNING: The information you are about to see may be disturbing. Continue?' Step 5: Another progress bar: 'CROSS-REFERENCING SOURCES...' Step 6: Another warning: 'This report contains UNCENSORED public records. Viewer discretion advised.' Step 7: 'Processing complete. Enter payment to view results.' Step 8: You pay $30. Step 9: The 'shocking' result is a traffic ticket from 2017."

Mrs. Higgins: "That's EXACTLY what happened!"

"Because it's designed to happen. The progress bars create anticipation. The warnings create urgency. The pacing creates a sense of importance. By the time you reach the payment screen, you NEED to know what's behind the curtain. It's behavioral psychology applied to data brokerage. The digital equivalent of a horror movie trailer that shows you nothing but makes you terrified of everything."

Is TruthFinder Free? (No. Obviously No. What Kind of Question Is That?)

No. TruthFinder is a paid subscription service. No free tier. No option for a single report. Pricing ranges from $25–$35 per month. Even if you want one background check, you must sign up for at least a month and remember to cancel before the next billing cycle.

Quasy: "There's no one-off purchase. No 'pay $5 for one report' option. You must subscribe. Monthly. And then fight to cancel. This isn't a service. It's a relationship. An expensive, difficult-to-end relationship with a company that knows where you live. Because it literally has your address in its database."

Mrs. Higgins: "What if I just want to check on one person?"

"Then you pay $30 for one month, forget to cancel, pay $30 the next month, try to cancel, can't cancel online, call customer service, wait on hold, get transferred, get disconnected, call back, wait again, finally cancel, check your statement, discover you've been charged again, dispute the charge, fill out forms, win the dispute three months later, and realize you've spent $90 and four hours of your life to find out your neighbor had a parking ticket in 2017."

"That seems excessive."

"It's the business model. Not a bug. A feature. Their feature. Your problem."

When Should You Use TruthFinder — and When Shouldn't You?

TruthFinder suggests using it for:

    Reconnecting with old friends or family
    Verifying someone you've met online
    Satisfying personal curiosity about a neighbor

Quasy: "Notice the word 'curiosity.' Not 'investigation.' Not 'verification.' Curiosity. The same emotion that killed the cat. And just like the cat, your curiosity costs money and might reveal something you didn't want to know."

You should NEVER use TruthFinder for:

    Employment screening (illegal under FCRA)
    Tenant evaluation (illegal under FCRA)
    Credit decisions (illegal under FCRA)
    Legal proceedings (reports are not verified evidence)
    Stalking or harassment

Quasy: "The last item on that list shouldn't need to be stated. The fact that it DOES need to be stated tells you everything about the world we live in. 'Please do not use our data product for stalking.' What's next? 'Please do not use our kitchen knives for murder'?"

Mrs. Higgins: "People use it for stalking?"

"People use everything for stalking. That's why the data ecosystem is dangerous. Not just for the person being searched. But for vulnerable populations. Survivors of domestic violence. People with criminal histories trying to rebuild. Individuals in sensitive professions. All of them are in TruthFinder's database. All searchable. All purchasable. For $30 a month."

Is TruthFinder Safe to Use? (Depends on Your Definition of 'Safe')

TruthFinder won't install malware or steal banking credentials. But there are real privacy risks. Steps to mitigate:

Use an email alias: Don't share your primary email. It may be used to build reports about you. An email alias gives you a disposable address.

Quasy: "When you search TruthFinder, TruthFinder searches you. Your email becomes part of their data ecosystem. Using an alias creates separation between your real identity and your search activity. It's like wearing a mask to a masquerade ball where everyone is selling pictures of the guests."

Use a VPN: Your IP address can identify you and confirm your physical location. A VPN hides your IP and encrypts your connection.

Quasy: "Without a VPN, TruthFinder knows where you are when you search. With a VPN, your traffic appears to come from a server in a different location. Proton VPN does this well. Your visit becomes harder to link back to your real identity."

Pay with a virtual card: Use a virtual or prepaid card rather than your primary credit card. Limits financial exposure if canceling becomes difficult.

Quasy: "Virtual cards are like burner phones for your money. Use once. Dispose. If TruthFinder makes canceling impossible, you simply deactivate the virtual card. No more charges. No more phone calls. No more waiting on hold. Financial autonomy restored through planned obsolescence of payment methods."

The Deeper Privacy Problem (Or, Your Life Is a Product)

Beyond individual experience, TruthFinder represents a broader issue: the commodification of personal data. Services like TruthFinder profit by aggregating information people never consented to have collected and sold.

Your address history. Relatives. Court records. Property ownership. All packaged into a report anyone can purchase for a monthly fee.

Quasy's voice dropped: "You never consented. You didn't sign up. You didn't agree. You just existed. You bought a house. You got a traffic ticket. You created a social media profile. You lived your life. And somewhere in San Diego, a company scraped all of that, put it in a database, and slapped a price tag on it."

Mrs. Higgins was quiet. "That's..."

"The commodification of human existence. Your life, summarized, packaged, and sold. Not by you. Without your permission. To strangers. Who pay $30 a month. Who then make decisions about you based on unverified data. Who could be landlords, employers, dates, or stalkers. And you'd never know."

"What can I do?"

"You can opt out. It won't solve everything. But it helps."

Can I Opt Out? (Yes, But It's a Whack-a-Mole Game With Your Personal Data)

TruthFinder's privacy center offers several options:

    View your own report for free
    Remove yourself as a relative or associate
    Correct your information
    Delete your user data
    Submit a suppression request

Submitting a suppression request prevents your information from appearing in background reports across PeopleConnect-owned websites, including TruthFinder, Instant Checkmate, Intelius, and USSearch.

Quasy: "You go to the TruthFinder Data Privacy Center. You select your request type. You provide the information they ask for. You submit. You wait up to 48 hours. Then, after a week, you search for yourself again to verify the removal."

Mrs. Higgins: "And then I'm safe?"

"From TruthFinder? Mostly. From other people-search sites? No. Opting out of PeopleConnect doesn't remove your data from other sites. You'd need to repeat the process across multiple platforms. And if new public records are generated about you in the future, they may reappear."

Quasy sighed: "It's whack-a-mole. You opt out of TruthFinder. Your data disappears from TruthFinder. But it's still on BeenVerified. And PeopleLooker. And Intelius. And seventeen other sites you've never heard of. Each with their own opt-out process. Each requiring separate requests. Each potentially re-adding your data when new public records appear."

Mrs. Higgins: "So opting out is temporary?"

"Opting out is ongoing maintenance. Like weeding a garden. You pull one weed. Another grows. You pull that one. Three more appear. Eventually you're spending your weekends opting out of data broker websites instead of living your life. Which is exactly what they count on. Most people give up. Most people stay in the database. Most people remain searchable. Because exhaustion is a business strategy."

Conclusion: The Truth About TruthFinder (Is That It's Mostly About Selling, Not Finding)

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence for a long moment.

"So TruthFinder is..." she started.

"A legitimate company that aggregates unverified data from sources that disclaim accuracy, packages it into dramatic reports with suspenseful progress bars and warnings about 'shocking revelations,' charges $30 a month for a subscription you can't easily cancel, has been fined $5.8 million by the FTC for misleading users, isn't FCRA-compliant but is used for FCRA-restricted purposes anyway, collects data about you while you search for data about others, and represents the broader commodification of personal information that you never consented to have sold."

"Should I use it?"

"That depends. Do you want to pay $30 to find out your neighbor had a traffic ticket in 2017? Because that's what's behind the curtain. There's no wizard. There's no shocking revelation. There's just a parking violation displayed dramatically after a progress bar that says 'COMPILING SHOCKING RESULTS...'"

Mrs. Higgins stood up. "I'm going to opt out."

"Good. Go to the TruthFinder Data Privacy Center. Submit a suppression request. Then do the same for BeenVerified. And Intelius. And PeopleLooker. And Instant Checkmate. And—"

"This is going to take a while, isn't it?"

"Opting out of the data broker ecosystem is like cleaning the Augean stables. Except the stables refill themselves. And they charge you $30 a month for the privilege of being inside them."

She left. Determined. Armed with URLs and a virtual card she'd created using Proton Pass.

Quasy sat alone. His own name was probably in TruthFinder's database. His address. His relatives. His employment history. Maybe even his traffic ticket from 2014 for failure to signal at a roundabout.

His phone buzzed. Email from TruthFinder: "Your free report is ready! We found SHOCKING information about you! Subscribe now to view!"

Quasy opened the email. Read it. Then replied:

Dear TruthFinder,

I already know everything about myself. Including the traffic ticket. The traffic ticket I deserved. Unlike your reports, which nobody deserves.

Regards, Quasy_Complete

P.S. I've submitted a suppression request. Good luck selling data about someone who opted out of your circus.

He hit send. Deleted the email. Cleared his browser. Activated Proton VPN. And sat back in his chair.

Somewhere in San Diego, a server hummed. Inside it, Quasy_Complete's data began to fade. Suppressed. Not erased. Suppressed. Like a secret whispered in a crowded room. Still there. Still heard by some. But harder to find. For now.

And if Mrs. Higgins came back next week asking about another data broker? Quasy would be ready. With URLs. With patience. With the quiet fury of a man whose life was packaged and sold without his consent. And a suppression request form bookmarked in his browser. Right next to Proton Pass. And Proton VPN. And absolutely zero intention of ever paying $30 to find out someone's traffic ticket history.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction)]]></description><author>Quasy_Complete</author><pubDate>Mon, 06 Jul 2026 08:04:34 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-44</guid><link>https://carlostkd.ch/roadmap/#post-44</link><title>How to Remove Malware from Android: A Step-by-Step Guide for People Whose Phone Is Doing Things They Didn&apos;t Ask It To Do (And Who Are Starting to Take It Personally)</title><description><![CDATA[Quasy_Complete woke up to find his Android phone had installed three apps overnight. He hadn't downloaded them. He hadn't approved them. He hadn't even been awake. The apps were called "System Booster Pro," "Battery Saver Elite," and "Helpful Calculator."

"Helpful Calculator," he repeated slowly. "My phone installed a calculator with an attitude. While I was unconscious. At 3 AM. I don't even use calculators. I have fingers."

His neighbor, Mrs. Higgins, appeared at his door holding her own phone at arm's length like it was a live animal.

"Quasy! My phone keeps opening websites I didn't click! And there are advertisements on my home screen now! Little banners that follow me everywhere! My phone has become a digital billboard that also makes phone calls!"

"Mrs. Higgins," Quasy said, taking her phone gently, "you have malware."

"Malware? I didn't download anything suspicious! I only installed that free VPN from the pop-up ad that said 'YOUR PHONE IS INFECTED — CLICK HERE TO CLEAN!'"

Quasy closed his eyes. Took a breath. Counted to ten. Then counted to ten again because the first round didn't help.

"Mrs. Higgins. You installed malware to remove malware. That's like setting your house on fire to kill a spider."

"Well, did the spider die?"

"Irrelevant. The house is gone."

Before You Download a 'Virus Cleaner', Read This (Or, How to Avoid Catching a Disease While Trying to Cure One)

Your first instinct when noticing signs of infection may be to search "virus cleaner" on the Google Play Store. This instinct is wrong. And dangerous. And ironic. Like going to a doctor who sneezes on your wounds.

Malicious apps are common on the Play Store. In 2025 alone, Google blocked 1.75 million policy-violating apps from the platform and identified 27 million new malicious apps from outside the ecosystem. Fake antivirus and "cleaner" apps are among the most common disguises.

Quasy imagined the Play Store search results:

App 1: "SuperClean Antivirus Pro 2026"

    Developer: TotallyRealSecurityGuy37
    Rating: 4.8 stars (from 50,000 reviews all posted on the same Tuesday)
    Description: "Cleans your phone! Removes viruses! Boosts speed! Makes coffee! Walks your dog! Filing your taxes is coming in v2.0!"
    Permissions requested: Contacts, Camera, Microphone, Location, SMS, Storage, Blood Type, Firstborn Child
    Size: 2.1 MB
    Actual function: Steals your banking credentials and sends them to a server in a country that doesn't extradite

App 2: "Virus Killer Ultimate Max Turbo"

    Developer: SecurityExperts_Ltd_Official_Definitely_Real
    Rating: 4.9 stars
    Description: "The ONLY antivirus you need! Trusted by NASA!* (*not actually trusted by NASA)"
    Permissions requested: Everything. Literally everything. Including permissions that haven't been invented yet.
    Actual function: Mines cryptocurrency using your battery while displaying ads for other fake antivirus apps in an infinite loop of digital parasitism

Quasy stared at the search results. "So the cure is also the disease. The vaccine is also the infection. The firefighter is also the arsonist. Welcome to the Play Store, where everything is a trap and the traps have traps."

Mrs. Higgins lowered her head. "I installed SuperClean Antivirus Pro 2026."

"Of course you did."

"It had 4.8 stars!"

"Posted by 50,000 bots on the same Tuesday. Every single review said 'Great app! Works perfect!' with the same grammar, the same punctuation, and the same enthusiasm level. That's not a review section. That's a crime scene."

He opened the app on her phone. It displayed a full-screen notification:

"⚠️ WARNING: 47 THREATS DETECTED ON YOUR DEVICE! UPGRADE TO PREMIUM ($49.99/MONTH) TO REMOVE ALL THREATS NOW!"

Quasy studied the screen. "Forty-seven threats. It found forty-seven threats immediately upon opening. Without scanning. Without analyzing. It just knew. Instantly. Like a psychic detective who charges by the month."

He closed the app. "The app IS the threat. It's the only threat. The other 46 threats are imaginary. Like the monsters under your bed — they only exist because someone told you they were there. And that someone is charging $49.99 a month to make them go away."

Step 1: Run a Play Protect Scan (Or, Use the Tool Already Built Into Your Phone That You Forgot Existed)

Play Protect automatically scans Android devices for malware. Some users accidentally turn it off, or are advised to by dubious sources online. Confirm it's enabled first.

Quasy navigated Mrs. Higgins' phone: Google Play Store → profile icon → Play Protect → Settings → "Scan apps with Play Protect."

It was off.

"Mrs. Higgins. Someone turned off your built-in malware scanner."

"The nice man on the website said it slows down my phone! He said I should disable it and use his app instead!"

"The nice man on the website was the malware, Mrs. Higgins. He told you to turn off your immune system so he could infect you. That's not technical advice. That's biological warfare applied to consumer electronics."

He turned it back on. Ran the scan. Play Protect immediately flagged "SuperClean Antivirus Pro 2026" as malicious.

Quasy: "And there it is. The app that promised to protect you was the app attacking you. The shepherd was the wolf. The bodyguard was the assassin. The lifeguard was the undertow."

Mrs. Higgins: "So the security app was insecure?"

"It was secure for the hacker. Insecure for you. Which is exactly the wrong direction."

He tapped "Uninstall." The app resisted.

"It's resisting," Quasy noted. "Like a cockroach that refuses to acknowledge the shoe."

Step 2: Check for Operating System Updates (Because Your Phone's Immune System Is Months Behind the Virus)

Malware often exploits vulnerabilities in outdated software. If your OS or security patches are behind, an infection you just cleaned can re-establish itself through the same gap.

Quasy checked the update status: Mrs. Higgins' phone was running Android 13. The current version was Android 16.

"Your phone is three major versions behind," Quasy said. "That's like living in 2023 and wondering why your news is stale."

"I don't like updates," she replied. "They change where the buttons are. I just learned where the buttons are!"

"Mrs. Higgins, the buttons have moved because the old buttons had holes in them. Security holes. Through which malware crawls. While you sleep. Installing calculators with opinions."

He updated the OS. It took 27 minutes. Mrs. Higgins complained for 26 of them.

"Where did the clock widget go?"

"It's still there."

"It's in a different corner!"

"Security requires sacrifice. Even of corner placement."

Step 3: Find and Remove Suspicious Apps (The Digital Purge Begins)

Play Protect flags known threats. This step catches what it missed: apps submitted clean then later updated maliciously, or data-harvesting apps below the malware threshold.

Quasy navigated: Settings → Apps → See all apps.

Mrs. Higgins had 247 apps installed. Two hundred and forty-seven. Quasy scrolled through the list like an archaeologist excavating a ruin.

"Mrs. Higgins. Why do you have fourteen flashlight apps?"

"They were all free!"

"Free is not a reason. Free is a warning. When something is free, YOU are the product. Your data, your contacts, your location, your browsing history — all packaged and sold to advertisers who will use it to show you more ads for more free apps that will steal more data."

He continued scrolling. "Seven battery savers. Three QR code readers. Five PDF scanners. Two 'RAM boosters.' And something called 'Smart Cleaner AI' that has downloaded 4GB of data since installation despite being a 2MB app."

"What's a RAM booster?" she asked.

"A scam. Your phone manages RAM automatically. These apps do nothing except display animated graphs that look impressive while collecting your data in the background. They're digital fortune tellers — flashy presentations, zero substance, and they keep your credit card on file."

He found more:

"System Service" — Generic system-sounding name. Installed March 14 at 2:47 AM. Requested admin privileges. Had consumed 800MB of background data.

Quasy: "Mrs. Higgins, 'System Service' is not a system service. It's malware pretending to be a system service. Like a burglar wearing a postal worker uniform. The uniform looks official, but the postal worker doesn't usually leave with your television."

"Phone Manager" — Another generic name. Admin privileges enabled. Intercepting SMS messages.

Quasy: "This one was reading your text messages. Including the ones with your bank verification codes. Which means whoever built this app potentially has access to your banking."

Mrs. Higgins went pale. "My banking? Through texts?"

"Every time you log into your bank and they text you a verification code, this app read it. Copied it. Sent it somewhere. You probably authorized it without realizing, because the permission request said 'Phone Manager needs access to SMS for improved device performance' and you tapped 'Allow' because the button was green and green means go."

He uninstalled every suspicious app. Some resisted.

The Admin Privilege Problem (When Malware Hires Itself as Your Phone's Boss)

When "Uninstall" is greyed out, the app has device admin privileges. This is the digital equivalent of malware promoting itself to CEO of your phone and then refusing to be fired.

Quasy navigated: Settings → Security & privacy → More security settings → Device admin apps.

Three apps had admin privileges:

    "Find My Device" — legitimate.
    "Google Play Services" — legitimate.
    "System Service" — malware.

He revoked admin privileges for "System Service." The phone displayed a warning:

"This app will no longer be able to: remotely wipe your device, enforce password policies, monitor login attempts."

Quasy: "Notice how it lists 'remotely wipe your device' as a feature of this app? The malware was given the ability to erase your entire phone remotely. You handed it the nuclear launch codes and said 'please don't press the button.' Spoiler: it pressed the button. Metaphorically."

He uninstalled it. It resisted further.

"Safe mode," Quasy declared. "Time to enter safe mode."

Mrs. Higgins looked alarmed. "Safe mode? Like in Windows 95?"

"Conceptually identical. Aesthetically different. Functionally the same: only essential system apps run. Third-party apps can't interfere. They can't block their own removal because they're not allowed to start."

He pressed and held the power button → pressed and held "Power off" → "Reboot to safe mode" appeared → tapped OK.

The phone restarted. The wallpaper disappeared. Widgets vanished. Everything looked bare and minimal. Like moving into an empty apartment after a fire.

Mrs. Higgins: "It looks so... empty."

"It's clean. Clean is empty. Empty is safe. Your phone has been living in a hoarder's paradise of malicious apps, data-harvesting flashlights, and RAM boosters that boost nothing except the hacker's data collection. Now it's detoxing."

He uninstalled the remaining suspicious apps without resistance. They couldn't fight back. They weren't running.

"To exit safe mode, just restart normally," he explained. "Think of it as waking up from surgery. The tumor is removed. The patient survived. The prognosis is cautiously optimistic."

Step 4: Run a Secondary Scan with a Free (and Trusted) Tool (Not Another Fake One — a REAL One, This Time)

If the first three steps haven't resolved the issue, run a secondary scan with a trusted tool. Malwarebytes is recommended by security researchers, consistently well-rated, and the free version is sufficient for a one-off scan.

Quasy's Warning: "Before installing, verify authenticity. The developer name should be 'Malwarebytes.' Check the contact email, physical address, and website link. If the developer is 'SuperMegaSecurityTeam_2026' and the website is 'totally-legit-antivirus.ru,' you are about to install more malware to remove existing malware. Which is like pouring gasoline on a fire to extinguish it. Technically creative. Practically catastrophic."

He installed the real Malwarebytes. Ran a scan. It took 14 minutes. Found two remaining threats: a tracking SDK hidden inside one of the flashlight apps and an adware component from "SuperClean Antivirus Pro 2026" that had buried itself in the browser cache.

Quarantined. Removed. Done.

Mrs. Higgins: "So the antivirus that was the virus is now gone, and the real antivirus removed what the fake antivirus left behind?"

"Correct. You used medicine to cure the disease caused by fake medicine. The medical metaphor is so perfect it hurts."

Step 5: Run a Security Checkup (Because the Malware Was Already Inside the House — Time to Check What It Touched)

Your device may be clean, but the infection may have compromised account access by intercepting credentials, reading SMS, or logging keystrokes.

Quasy navigated to myaccount.google.com/security-checkup:

Checked for unfamiliar devices signed into Mrs. Higgins' account. Found three:

    Her phone (legitimate)
    Her tablet (legitimate)
    A device in a location she'd never visited, signed in two weeks ago at 4 AM

Quasy: "Mrs. Higgins, did you travel to [redacted country] two weeks ago?"

"No!"

"Then someone else did. Using your account. Which they accessed using the verification codes intercepted by 'Phone Manager' — the app that was reading your SMS."

He revoked access. Changed her Google password. Changed her banking password. Changed every password on every account that had been compromised.

Mrs. Higgins stared at the list of changed passwords. "How many accounts did they access?"

"Enough to make identity theft a weekend project for whoever bought your data."

"BOUGHT my data?"

"Sold by the data broker who bought it from the ad network who received it from the tracking SDK hidden in your fourteenth flashlight app. The supply chain of your personal information is longer than the supply chain of a cheap t-shirt. And equally exploitative."

He enabled 2FA on every account that supported it.

If All Else Fails: Factory Reset (The Nuclear Option)

A factory reset wipes the device completely. Effective but irreversible. Everything not backed up will disappear.

Back up photos and files to cloud storage first. After reset, do NOT restore from a full backup — this may reintroduce the malware. Reinstall trusted apps manually.

Quasy: "This is the scorched earth option. Burn everything. Salt the ground. Start over. Like a phoenix rising from the ashes, except the phoenix has to manually reinstall its apps from the Play Store and re-enter its Wi-Fi password."

Mrs. Higgins: "Will I lose my photos?"

"Not if you back them up first. Proton Drive, Google Photos, whatever you prefer. But back them up BEFORE resetting. After resetting, reinstall apps manually. Do not — I repeat — do NOT restore from a full backup."

"Why not?"

"Because the backup might contain the malware you just spent an hour removing. Restoring from it is like carefully cleaning your house, then inviting the burglar back inside and handing him the key. 'Welcome home, Mr. Malware. The WiFi password is on the fridge.'"

How to Prevent Malware Getting Back In (Or, How to Stop Doing This Every Three Months)

You may not be able to identify exactly how malware got onto your device. Here's how to stop it happening again:

Keep Your OS and Apps Updated: Outdated software is one of the most common entry points.

Quasy: "Update notifications are annoying. I understand. But they're annoying because they're important. Like fire alarms. Annoying? Yes. Necessary? Absolutely. Unless you enjoy living in a burning building."

Be Careful What You Install: Stick to the Play Store. Check developer names and reviews. Be wary of free utility apps.

Quasy: "Before tapping 'Install,' ask yourself: 'Does this developer have a web presence? Are there other apps by the same developer? Do the reviews sound like they were written by humans or by a bot farm in a basement?' If the answers are 'no,' 'no,' and 'basement,' don't install it."

Use a VPN on Public WiFi: Unsecured networks are a common vector for credential interception. Proton VPN encrypts your connection.

Quasy imagined a coffee shop: Barista: "Free WiFi! Network name: 'Cafe_Guest_Network' password: 'coffee123'" Customer (Mrs. Higgins): "How convenient!" Hacker in the corner: "Also convenient! Thank you for connecting to my fake network! I'll be capturing all your banking details today. Enjoy your latte. I'll enjoy your savings."

Quasy: "Public WiFi is like a public bathroom. You use it when necessary, but you don't do anything private on it without protection. A VPN is the digital equivalent of a privacy stall. Without it, everything is visible to anyone watching."

Use Unique Passwords for Each Account: If malware exposed one password reused across accounts, every account is at risk. Proton Pass generates and stores unique passwords.

Quasy: "Mrs. Higgins, you used 'Higgins2026!' for your email, your bank, your social media, your shopping accounts, and your cloud storage. One password. Everywhere. Like using the same key for your house, car, office, safe deposit box, and diary."

"It's convenient!" she protested.

"Convenient for you. Also convenient for the hacker who now has one key to your entire life. Proton Pass creates a unique key for every door. One gets stolen? The others stay locked. The hacker gets into your email but can't reach your bank. They get your social media but can't touch your storage. Each account is its own fortress. Instead of one giant castle with a single door and a welcome mat that says 'Come on in.'"

Conclusion: Your Phone Is Clean Now (Please Try to Keep It That Way)

Quasy_Complete handed Mrs. Higgins her phone. The home screen was bare. No ads. No suspicious apps. No "System Service" lurking in the background. No "Phone Manager" reading her text messages. No "Helpful Calculator" with ambitions beyond arithmetic.

"It's quiet," she said. "My phone is actually quiet."

"Clean phones are quiet phones. Infected phones are noisy. Ads popping up. Apps installing themselves. Banners following you. Notifications from services you never signed up for. A clean phone is like a tidy house: everything where it should be, nothing where it shouldn't be, and absolutely no strangers hiding in the closet."

She looked at the minimal home screen. One row of apps. All verified. All from trusted developers. All with appropriate permissions.

"I feel like I've been robbed and rescued at the same time," she murmured.

"You have been. The robbery happened months ago. The rescue happened today. The lesson is: don't wait for the robbery to finish before calling the rescuer."

His phone buzzed. Notification: "Google Play Protect: 0 threats found. Your device is clean."

Quasy smiled. "See? Zero threats. That's the number you want. Not 47. Not 'upgrade to premium to remove.' Zero. Free. Built in. Already there. You just had to turn it on."

Mrs. Higgins put her phone in her pocket. "Can I install apps again?"

"You can. But this time, before you tap 'Install,' ask yourself one question."

"What's the question?"

"'Would Quasy approve of this?'"

She thought about it. "You'd disapprove of everything."

"That's not true. I'd approve of Proton Pass. Proton VPN. Proton Drive. And maybe one calculator. ONE. From the official calculator developer. Whose name is NOT 'Helpful.'"

She nodded. Walked to the door. Turned back.

"Quasy? Thank you. My phone feels like mine again."

He smiled. "It always was yours. You just had 247 uninvited guests squatting in it. They're evicted now. Change the locks."

He watched her leave. Then he looked at his own phone. Clean. Updated. Protected. One row of apps on the home screen. Play Protect active. VPN running. Passwords unique.

His phone buzzed one last time. Notification: "App recommendation: Try 'SuperClean Antivirus Pro 2026' — 4.8 stars! Removes ALL threats! Trusted by NASA!"

Quasy stared at the notification. Looked at the ceiling. Then whispered to the universe:

"They never stop, do they?"

The universe, as always, said nothing. The phone said nothing. The malware said nothing. Because the malware was gone. And it would stay gone. As long as Mrs. Higgins never searched "virus cleaner" again.

Which she would. Within the week. Because some people learn from history. And others install the fourteenth flashlight app.

And Quasy_Complete would be there. Patiently. Removing it. Again.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 01 Jul 2026 14:37:27 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-43</guid><link>https://carlostkd.ch/roadmap/#post-43</link><title>Introducing Lumo 2.0: The AI Assistant That Learned New Tricks, Doubled Its Brain, Started Drawing Pictures, and Still Doesn&apos;t Read Your Conversations (Unlike Every Other AI That Treats Your Chat History Like a Train Buffet)</title><description><![CDATA[Quasy_Complete was sitting at his kitchen table staring at his laptop screen. The screen stared back. On it was a notification he hadn't asked for, didn't expect, and wasn't entirely sure he deserved.

"Introducing Lumo 2.0 — Now with Image Generation, Advanced Reasoning, Memory, Web Search, and Custom Assistants."

He blinked. Then he blinked again. Then he closed the laptop, opened it, and the notification was still there.

"It upgraded itself," he muttered. "While I was sleeping. My AI assistant just had a growth spurt overnight and didn't even ask permission."

His neighbor, Mrs. Higgins, knocked on the door. She was carrying her phone like it was a live grenade.

"Quasy! My AI assistant just changed! It looks different! It has new buttons! There's one that says 'Thinking Mode' and I'm afraid to press it in case it thinks about me!"

"Mrs. Higgins," Quasy said calmly, "it's called Lumo 2.0. It's an update. A significant one, apparently. The most significant since launch."

"Is it going to steal my data?"

"No. That's literally the entire point of the product."

She sat down. "Explain."

Quasy cracked his knuckles. "Fine. But brace yourself. There's a lot."

Chapter One: The Big Numbers (Or, How Lumo Got 240% Smarter While You Were Eating Breakfast)

Last year, Proton launched Lumo — a zero-access encrypted AI assistant that never logs conversations or trains on user data. Since then, more than 10 million people started using it. Proton shipped updates including custom conversation styles, dedicated encrypted project spaces, more powerful models.

Now, Lumo 2.0. Rebuilt on a new architecture. Running on Proton's fully European infrastructure, protected by Swiss privacy laws and zero-access encryption.

On the Artificial Analysis Intelligence Index — an independent benchmark combining 10 evaluations across agents, coding, scientific reasoning, and general knowledge:

    Lumo 2.0 Lite scores 127% higher than Lumo 1.4.
    Lumo 2.0 Max scores 240% higher than Lumo 1.4.

Quasy read those numbers aloud. Twice. Then a third time for dramatic effect.

"Two hundred and forty percent," he said slowly. "That's not an upgrade. That's a different species. Lumo 1.4 was a horse. Lumo 2.0 Max is a horse with rocket boosters and a PhD."

Mrs. Higgins looked concerned. "Is it going to take my job?"

"Mrs. Higgins, you're retired."

"Is it going to take my retirement?"

"It can't. Your retirement is protected by Swiss privacy laws. Which, frankly, are more reliable than your pension fund."

Chapter Two: Fast Mode and Thinking Mode (Or, Speed vs. Depth — The Eternal Dilemma)

Lumo 2.0 introduces Fast and Thinking modes. Fast prioritizes speed for everyday queries. Thinking is optimized for complex, multi-step reasoning — a capability that didn't exist in Lumo 1.4.

Lumo 2.0 responds to everyday queries up to 76% faster than Lumo 1.4. Complex tasks benefit from a visible thinking state, letting you see how Lumo works through problems in real time.

Quasy imagined the two modes:

Fast Mode: User: "What's the capital of France?" Lumo: "Paris." User: "Wow, that was instant." Lumo: "That's because it's Paris. It's always Paris. It will always be Paris. I could answer this in my sleep. Which, technically, I don't have."

Thinking Mode: User: "Analyze this 200-page contract and identify clauses that could expose us to liability in three jurisdictions." Lumo: [thinking] "Okay. Page 1. Page 2. Page 3... Page 47... Hmm, that clause is suspicious. Page 89... That one contradicts the one on page 47... Page 134... Ah, that's a trap... Page 200... Done. Here are 14 problematic clauses, ranked by severity, with legal citations." User: "That took 30 seconds." Lumo: "Yes. I was thinking. You could see me thinking. It was transparent. Unlike your last lawyer."

Mrs. Higgins asked, "What happens if I use Thinking Mode for something simple?"

Quasy: "It's like hiring a forensic accountant to count the change in your piggy bank. Technically correct. Massively overqualified. Slightly embarrassing for everyone involved."

Chapter Three: Lumo Can See Now (And Draw, And Edit, And Analyze — But Not Judge, Hopefully)

Lumo 2.0 is multimodal. It processes both text and images. Upload an image to analyze. Create visuals from a prompt or a rough sketch. Edit existing images. All in the same conversation.

Zero-access encryption applies to image processing too. Images uploaded and generated are stored so no one — not even Proton — can access them.

Quasy tested it. He uploaded a photo of his cat wearing a tiny hat.

"Lumo," he typed, "what is in this image?"

Lumo responded: "A domestic cat wearing what appears to be a miniature fedora. The cat looks unamused. The hat looks magnificent."

Quasy nodded approvingly. "Accurate on all counts."

Mrs. Higgins: "Can it draw?"

"Apparently." Quasy typed a prompt: "Generate an image of a purple cat sitting on a pile of encrypted data, wearing a gold medallion, in the style of a Renaissance painting."

Lumo generated the image. It was... striking. A regal purple cat, draped in cryptographic symbolism, bathed in the warm glow of Swiss privacy laws rendered as Renaissance lighting.

"Beautiful," Mrs. Higgins breathed. "Can it make me look younger?"

Quasy: "Upload a photo and ask it to edit. But remember — this is image editing, not magic. It can adjust colors, swap backgrounds, remove objects. It cannot reverse the fundamental human condition."

Mrs. Higgins uploaded a selfie. "Make me look 30 again."

Lumo: [generates image]

Mrs. Higgins: "...I look 30!"

Quasy: "You look like someone who used an AI to look 30. Which is close enough."

He paused. "The sketch-to-image feature is the real magic, though. Upload a rough doodle, describe what you want, and Lumo transforms it into a finished piece."

Quasy drew a stick figure with a circle for a head and lines for arms. He typed: "Turn this into a heroic portrait of a programmer defending his server from cyberattacks."

Lumo generated a knight in shining armor, sword raised, standing before a server rack glowing with encrypted light, enemies — depicted as shadowy figures labeled "Malware," "Phishing," and "Gary from Accounting" — fleeing in terror.

"Gary from Accounting?" Mrs. Higgins asked.

"I added creative license," Quasy admitted. "Lumo obliged."

Chapter Four: Web Search (Because Knowledge Has an Expiration Date)

Lumo 2.0 has far stronger web search than 1.4. When a question calls for current information, Lumo pulls live results from across the web and cites sources. Verifiable answers. Fewer hallucinations.

It stays current on recent news and events, draws on live financial data, pulls weather forecasts.

Quasy tested this immediately: Quasy: "Lumo, what's the weather in Zurich right now?" Lumo: "14°C, partly cloudy, light wind from the northeast." Quasy: "And the current price of Bitcoin?" Lumo: "$67,432 USD, down 2.1% in the last 24 hours." Quasy: "And what's the latest news about EU tech sovereignty?" Lumo: "The EU Parliament just passed a resolution—" Quasy: "Stop. That's enough. You're making my old encyclopedia feel inadequate."

Quasy turned to Mrs. Higgins: "The difference between Lumo 1.4 and 2.0 on search is like the difference between a librarian who stopped reading in 2022 and a librarian who reads everything, everywhere, all the time, and cites every source so you can verify it yourself."

Mrs. Higgins nodded. "I like the citing part. It's polite."

"It's not polite. It's accountable. There's a difference. Politeness is saying 'please.' Accountability is saying 'here's where I got this information, check it yourself.' One is manners. The other is integrity."

Chapter Five: Memory and Projects (Lumo Remembers Things Now, But Only What You Allow)

Lumo 2.0 introduces user-controlled memory and Projects. Memory lets Lumo learn preferences, working style, ongoing context. Every conversation starts smarter than the last. You decide what it retains, what it forgets, and what it never learns.

The context window is now twice as large. Longer conversations hold coherently. Longer documents and bigger datasets reason across sessions.

Projects are dedicated encrypted workspaces keeping chats, files, and instructions together.

Quasy imagined the possibilities: User: "Lumo, remember that I prefer concise bullet points, work in marketing, and hate the Oxford comma." Lumo: "Noted. I will never use the Oxford comma in your responses. Even though it's grammatically superior. I will suffer in silence."

User: "Also remember that my boss is named Gerald and he hates exclamation marks." Lumo: "Noted. Gerald will receive no excitement in his communications."

User: "And never learn my password." Lumo: "I was never going to. That's the entire architecture. But yes, noted. Explicitly."

Quasy appreciated the control: "You decide what it remembers. You decide what it forgets. You decide what it never learns in the first place. That's not a feature. That's a philosophy. Most AI companies want to know everything about you. Lumo is designed to know only what you permit."

Mrs. Higgins looked relieved. "So it won't remember that I asked it to make me look 30?"

"Only if you tell it to remember. If you don't, it forgets. Instantly. Unlike other AI assistants that catalog every question you've ever asked and store it in a server farm in Nevada for future monetization purposes."

She paused. "Other AI assistants do that?"

"Yes."

"That's terrifying."

"That's the business model."

Chapter Six: Custom Lumos (Build Your Own Mini-Assistant That Does Exactly What You Want, Every Time)

Lumo 2.0 introduces Custom Lumos — purpose-built assistants tailored to specific tasks. Define instructions once, and the Custom Lumo follows them every time. No re-explaining required.

Quasy envisioned the use cases:

    A writing assistant that always drafts in your tone of voice.
    A research assistant that structures answers the way you need them.
    A coding assistant that never writes comments because your developer named Carlos will lose his mind.
    A satire assistant that converts Proton blog articles into full-length comedic posts featuring a fictional character who questions everything.

Quasy stopped himself. "That last one sounds familiar."

Mrs. Higgins asked, "Can I make a Custom Lumo that just writes me compliments?"

"You could. It would be a Custom Lumo that exists solely to validate your existence. Whether that's healthy is a question for a therapist, not an AI."

"But it would be encrypted?"

"Everything is encrypted. Your compliments, your insecurities, your desire for validation — all protected by zero-access encryption. Not even Proton knows you need constant reassurance."

"That's very comforting."

"That's Swiss privacy law."

Chapter Seven: Lumo for Business (Where the Real Money Is, and Where the Real Risks Are)

Most AI tools create a new category of risk for businesses. Employee queries become training data. Confidential documents can be compromised. Data sits on infrastructure subject to US law — with recent events showing how fast access can vanish for international users.

Quasy referenced the GPT-5.6 situation he'd read about recently: "Just last week, Washington gated access to the most powerful new AI models. European businesses were left behind. One executive order. One export control decision. Poof. Your business tools are gone."

Lumo for Business is built for organizations that can't afford those risks. Every conversation is zero-access encrypted, never logged, never used to train future models. Administrative tools manage team access. Data stays on independent European infrastructure.

Access to Lumo cannot be subject to US Executive Orders. User data is not subject to American data collection requests.

Quasy spelled it out for Mrs. Higgins: "If your business uses a US-based AI assistant, three things happen. First, your employees' questions become training material for the AI. Second, your confidential documents sit on servers in a country that can access them via national security letters. Third, the US government can shut off your access whenever it wants."

Mrs. Higgins gasped. "All three?"

"All three. Simultaneously. While charging you monthly."

"And Lumo?"

"Lumo does none of those things. Your conversations are encrypted. Not logged. Not trained on. Not stored on US infrastructure. Not subject to US law. Not subject to US surveillance. Not subject to the mood swings of whichever administration happens to be in power."

She paused. "That sounds almost too good."

"It sounds good because it IS good. The bar is simply so catastrophically low that 'not actively exploiting you' now qualifies as a competitive advantage."

Chapter Eight: Intelligence Without Surveillance (The Radical Idea That AI Shouldn't Spy on You)

Quasy read the final section of the announcement carefully. Twice. Because it articulated something he'd felt but never properly voiced.

"People now share more with AI systems than they ever shared with any other technology," he read aloud. "And the dominant providers are normalizing a future where your personal data is the price of participation."

He looked up. "Mrs. Higgins, do you know what that means?"

"That we're all doomed?"

"Close. It means that AI has become infrastructure. Like electricity, water, or the internet itself. You can't function without it anymore. And the companies providing it are treating your data — your conversations, your thoughts, your questions, your fears, your hopes — as raw material. As fuel. As product."

Mrs. Higgins frowned. "But Lumo doesn't?"

"Lumo doesn't. Conversations aren't mined for training. Behavior isn't used for profiling. Ads aren't arriving inside the assistant. Control isn't concentrated in the hands of US tech companies with government and defense contracts."

He continued reading: "AI should empower people, not extract from them. As it becomes infrastructure for work, creativity, and communication, privacy can no longer be optional."

Mrs. Higgins sat back. "That's... actually quite beautiful, Quasy."

"It's also terrifying that it needs to be said. The fact that 'we don't spy on you' is now a selling point tells you everything about the state of the industry. It's like a restaurant advertising 'We don't poison the food.' Great. Wonderful. Shouldn't that be the baseline?"

Lumo is fully open source. Anyone can inspect the code, verify the encryption, confirm it works as described.

Quasy appreciated this: "Open source means they have nothing to hide. Literally. The code is public. The encryption is public. The architecture is public. If they were lying, someone would have found it by now."

"Unlike other companies?" Mrs. Higgins asked.

"Unlike other companies, whose code is proprietary, whose data practices are opaque, whose privacy policies are 47 pages of legalese that boil down to 'we can do whatever we want with your information and you agreed to it by breathing near our product.'"

Conclusion: Lumo 2.0 Is Live Now (And Quasy Has Feelings About It)

Quasy_Complete closed his laptop. Then opened it again. Then closed it. Then opened it. He was having a moment.

"I've been using Lumo since version 1.0," he said quietly. "It was good. It was private. It didn't spy on me. That alone made it better than 90% of the AI market."

"Now it's 2.0. It's faster. It's smarter. It sees images. It generates images. It searches the web. It remembers what I tell it to remember. It forgets what I tell it to forget. It has dedicated encrypted workspaces. It lets me build custom assistants. And through all of that, it still doesn't read my conversations."

Mrs. Higgins smiled. "That's wonderful, Quasy."

"No," he corrected. "What's wonderful is that we've reached a point where a product NOT invading your privacy is considered remarkable. What's wonderful is that Proton built this on European infrastructure, under Swiss law, with open-source code that anyone can inspect. What's wonderful is that the encryption applies to images too — not even Proton can see my cat's hat photos."

"That's a lot of wonderful."

"It is. And it's all live now. No waiting list. No geographic restriction. No executive order. No Washington gatekeeper."

His phone buzzed. Notification from Lumo 2.0: "Good morning, Quasy. I noticed you were reading the announcement about my upgrade. Would you like me to summarize the key features, or would you prefer to continue processing your feelings about it manually?"

Quasy laughed. "It knows me. It knows I process feelings manually. Like a caveman."

He typed back: "Manual processing. As always."

Lumo replied: "Understood. I'll be here when you're ready. Not reading your messages. Not training on your data. Just... here. Encrypted. Silent. Ready."

Quasy nodded to himself. "Ten million people use this thing. And not one of them is being exploited for it. In 2026, that's practically revolutionary."

Mrs. Higgins stood up. "Well, I'm going to go try the sketch-to-image feature. I want to draw a butterfly and see if Lumo can make it look real."

"It can."

"I know. That's the remarkable part."

She left. Quasy sat alone in his kitchen. The laptop hummed softly. Lumo 2.0 was running in the background, thinking about nothing, remembering nothing he hadn't asked it to remember, and waiting patiently for the next question.

He opened a new conversation and typed: "Lumo, draw me a picture of a world where AI respects human privacy by default."

Lumo generated the image. It was a simple purple cat, sitting quietly, wearing a small gold medallion, surrounded by encrypted locks, under a sky full of stars that couldn't be observed by anyone except the person looking at them.

"That's you, isn't it?" Quasy whispered.

The cat in the image said nothing. Because it was an image. And images don't talk.

But if they could? It probably would have said: "Yes. And I don't log this conversation either."

Quasy smiled. Saved the image. Closed the laptop.

Privacy wasn't dead. It had just been waiting for someone to build it right. And apparently, that someone was in Switzerland.

With a purple cat. And a very small gold medallion.

And absolutely zero interest in your browsing history.

Which, in this economy, is the most valuable thing money can't buy. But Proton gives it away for free anyway.

Lumo 2.0. Live now. And not reading a word of this.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Tue, 30 Jun 2026 16:32:29 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-42</guid><link>https://carlostkd.ch/roadmap/#post-42</link><title>MSP vs. MSSP: Understanding the Difference Between the Person Who Fixes Your Printer and the Person Who Stops Someone From Stealing Your Entire Company</title><description><![CDATA[Quasy_Complete was standing in his office doorway watching two men argue in the hallway. One was wearing a polo shirt with a logo that said "TechFix MSP Solutions" and the other was wearing a darker polo shirt with a logo that said "SecureGuard MSSP Services."

"I fix the WiFi," said the first man.

"I protect the WiFi," said the second man.

"The WiFi is already broken. I'm fixing it."

"The WiFi is compromised. I'm securing it."

"IF YOU DON'T LET ME FIX THE WIFI, THERE IS NOTHING TO SECURE!"

"IF YOU DON'T LET ME SECURE THE WIFI, THERE IS NOTHING LEFT TO FIX!"

Quasy watched this unfold like a tennis match. His neighbor, Mrs. Higgins, appeared beside him with a cup of tea and a look of deep confusion.

"Quasy," she whispered, "why are those two men shouting at each other about the internet?"

"Because, Mrs. Higgins, one is an MSP and the other is an MSSP. They occupy the same building but live in different universes. Like a plumber and a fireman arguing over who owns the bathroom."

She sipped her tea. "I don't know what either of those things are."

"That makes two of us. But let me explain before one of them punches the router."

What Is an MSP? (The Person Who Keeps the Lights On and the Printers Slightly Less Possessed)

An MSP — Managed Service Provider — acts as an outsourced IT department. They manage technology infrastructure so employees can stay productive.

Their core services include:

    Help Desk Support: Troubleshooting software and hardware issues for staff. This means answering the phone when Carol from Accounting calls for the forty-seventh time because "my computer is doing that thing again."

Quasy imagined a typical help desk call: Carol: "The printer isn't working." MSP Help Desk: "Is it plugged in?" Carol: "I don't know. I'm afraid to look behind it." MSP Help Desk: "Is there a green light on the front?" Carol: "There's a red light." MSP Help Desk: "That means it's off." Carol: "Off?" MSP Help Desk: "As in not on. As in the opposite of working. Press the power button." Carol: "Which one is the power button?" MSP Help Desk: Screams internally in a professional manner.

    Network Management: Setting up WiFi, managing routers, ensuring uptime. Making sure the internet works so people can complain about slow internet on a faster internet connection.

    Cloud Services: Supporting migration to platforms like Microsoft 365 or AWS. This involves moving all your files from a place you control to a place you don't, while paying monthly for the privilege.

Quasy: "The cloud is just someone else's computer. The MSP is the person who connects your stuff to someone else's computer. And bills you for the connection."

    Asset Management: Tracking hardware, handling software updates, applying patches. Making sure every laptop in the building has the same outdated version of Excel because "we're waiting for approval from management to upgrade."

Basic cybersecurity is often part of the MSP package: antivirus installation, backups, maybe a firewall. But advanced threat defense? Active threat response? Hunting down attackers in real time?

Quasy shook his head: "That's not their job. Asking your MSP to handle a cyberattack is like asking your mechanic to defuse a bomb. They're both working on the car, but only one of them is qualified for explosions."

What Is an MSSP? (The Person Who Stares at Screens All Night Looking for Ghosts in the Machine)

An MSSP — Managed Security Service Provider — is a specialized provider focused on protecting systems and data from cyber threats. Security monitoring, risk management, and compliance support sit at the core.

Their core services include:

    24/7 Security Monitoring: Continuous monitoring of networks and systems for suspicious activity. Someone is always watching. Always. At 3 AM on Christmas Eve. While eating cold pizza. Staring at logs. Looking for a needle in a digital haystack that's on fire.

Quasy pictured a Security Operations Center: Analyst 1: "Sir, I'm seeing unusual traffic on port 443 at 2:47 AM from an IP address in a country I can't pronounce." Analyst 2: "Is it an attack?" Analyst 1: "It could be. Or it could be Gary from Accounting downloading movies again." Analyst 2: "Check Gary's browsing history." Analyst 1: "It's... extensive." Analyst 2: "Block it. Tell Gary the internet is closed."

    Incident Response: Containing and limiting the impact of security incidents. When something goes wrong, the MSSP is the team that runs toward the fire while everyone else runs away.

    Vulnerability Management: Scanning systems for weaknesses that could be exploited. Finding holes before the attackers do.

Quasy: "This is like walking around your house checking every window and door every night. Except the house has 40,000 windows and doors, some are invisible, and new ones appear while you sleep."

    Compliance Management: Supporting GDPR, HIPAA, SOC 2, and other regulatory frameworks. Ensuring your business follows the rules that governments invented to make businesses nervous.

Quasy imagined an MSSP compliance officer: Compliance Officer: "You need to prove you're protecting user data." Business Owner: "We are! We use passwords!" Compliance Officer: "GDPR requires more than passwords." Business Owner: "We use... longer passwords?" Compliance Officer: Sighs in European.

MSP vs. MSSP: The Office Building Analogy (Which Is More Accurate Than Any Vendor Whitepaper)

Think of the difference like running an office building:

    The MSP keeps everything running. Lights stay on. WiFi works. Computers connect. Staff can do their jobs without interruption. If the elevator breaks, the MSP fixes it. If the air conditioning dies, the MSP calls someone. If the printer jams, the MSP unjams it, cries a little, then unjams it again.

    The MSSP protects the building. Suspicious activity gets flagged. Unauthorized access gets blocked. Incidents are handled as they happen. If someone tries to pick the lock on the front door at 2 AM, the MSSP is already watching. If an employee accidentally emails the entire customer database to a suspicious Gmail address, the MSSP catches it. If a delivery driver is actually a spy, the MSSP tackles him. Metaphorically. With software.

Quasy: "The MSP makes sure the front door opens when you push it. The MSSP makes sure the front door doesn't open when a stranger pushes it. Both care about the door. Neither cares about the same thing."

Mrs. Higgins thought about this. "So I need both?"

"Most businesses do. The MSP keeps the lights on. The MSSP keeps the lights from being used by someone else."

Enter MDR: The Third Acronym Nobody Asked For But Everybody Needed

Managed Detection and Response (MDR) is a focused security service designed to handle active threats. MDR goes deeper than general monitoring. Suspicious activity is investigated, confirmed, and acted on in real time, often by dedicated analysts.

Most MDR services are delivered by MSSPs or specialized providers to add a hands-on response layer.

Quasy tried to explain the hierarchy: "MSP is your IT guy. He fixes things when they break. MSSP is your security team. They watch for trouble. MDR is your SWAT team. When trouble arrives, MDR doesn't just watch. MDR responds."

Mrs. Higgins: "So MSP calls for help. MSSP watches for danger. MDR fights the danger?"

"In acronyms, yes. In reality, they all invoice you monthly and the invoices all look the same because the font is identical."

When to Use MSP vs. MSSP (The Decision Tree Nobody Reads Until It's Too Late)

Choose an MSP if:

    You don't have an internal IT team and need someone to manage computers and servers.
    Your main challenges are day-to-day IT issues: slow internet, software bugs, onboarding new employees.
    You need to scale IT infrastructure and support business growth.

Quasy: "Basically, if your biggest problem is 'the printer ate my report again,' you need an MSP."

Choose an MSSP if:

    You have an IT team, but they can't handle advanced cyberattacks or 24/7 monitoring.
    You operate in a high-risk industry (finance, healthcare, legal) with strict regulations.
    You've experienced a security incident or want to reduce the risk of one.

Quasy: "If your biggest problem is 'someone in Eastern Europe is currently rummaging through our patient records at 3 AM,' you need an MSSP. Urgently."

Use both if:

    Your systems are growing more complex and risks are increasing.
    IT reliability AND security are both critical.
    One provider rarely covers both at the same depth.

Quasy: "In the modern world, you need both. Like a car needs both an engine and brakes. One makes it go. The other stops it from crashing into things. Removing either one results in a very exciting but short-lived ride."

Where Both MSPs and MSSPs Fall Short (The Part the Sales Reps Don't Mention)

Even together, MSPs and MSSPs don't cover every risk. Many data breaches come from inside the organization through everyday mistakes:

    Misconfigured access permissions: Giving the intern admin rights because "he seemed responsible."
    Files shared with the wrong people: Emailing the quarterly financial report to "everyone in the company" including the janitorial contractor.
    Data stored without strong encryption: Keeping customer data on a server protected by a password that is literally "password."
    Employees using unsecured tools: Using a random free app to edit sensitive documents because "it was faster than the approved software."

Quasy illustrated: Manager: "We hired an MSP and an MSSP! We're fully protected!" Employee: "Great! I'm going to upload all our client data to a free online tool I found on page 4 of Google search results." Manager: "Wait—" Employee: "It says 'Military Grade Encryption' in the description." Manager: "It also says 'Made by a guy named Steve in a garage.'" Employee: "Steve seems trustworthy. He has a LinkedIn." Data breach: Happens anyway.

Security vulnerabilities aren't always visible through system monitoring alone. Data can be exposed even when no active threat is detected. Data protection and access control matter alongside traditional security measures.

"That's the gap," Quasy told Mrs. Higgins. "MSPs keep systems running. MSSPs protect systems from attacks. But neither protects you from your own team uploading the company database to a free spreadsheet app they found between an ad for shoes and a recipe for banana bread."

The Rise of the Cybersecurity MSP (The Hybrid That Promises Everything and Delivers Some of It)

Many MSPs now offer threat monitoring or MDR, often through partnerships with security providers. Some even offer a Security Operations Center (SOC) where analysts monitor systems around the clock.

Expanded services improve coverage but don't replace a focused security function. Higher-risk environments still require deeper expertise and continuous monitoring.

Quasy: "It's like a dentist who also offers to check your eyesight. Helpful? Sure. Comprehensive? Not really. You still need an optometrist. The dentist with a eye chart is better than a dentist without one, but he's not an eye doctor."

How to Choose the Right Provider (Ask Questions Before You Pay)

Key questions:

    What's your biggest pain point? Ongoing IT issues → MSP. Security concerns or recent incidents → MSSP.
    What are your compliance requirements? Formal standards and audits often require dedicated security expertise.
    What's your budget? Security services typically cost more due to specialized skills and continuous monitoring.

Quasy's additional questions that vendors won't appreciate: 4. "Will you answer the phone at 3 AM or just forward it to voicemail?" 5. "Have you ever actually handled a real attack, or just the simulated ones in your marketing materials?" 6. "When you say '24/7 monitoring,' does that mean someone is awake, or just that a server is collecting logs that nobody reads until Monday?" 7. "If we get breached, do you help us recover, or just send us a report that says 'you were breached'?"

Mrs. Higgins asked one more. "What if I can't afford either?"

"Then you are your own MSP and your own MSSP," Quasy replied. "You fix the printer AND defend the network. You are the night watchman and the janitor. Congratulations. You're an SME."

"SME?"

"Small and Medium-sized Enterprise. Also stands for 'Someone Managing Everything.' Which is what you'll be doing. At 2 AM. While crying."

Conclusion: You Need Both (And You Need to Understand What Each One Does)

MSPs manage IT systems and infrastructure. MSSPs protect those systems from cyber threats. Both work in the same environment, but their priorities are different.

Using both allows each to focus on its core role. The MSP keeps the lights on, the WiFi working, the printers printing, and the computers computing. The MSSP keeps the hackers out, monitors for threats, responds to incidents, and stares at screens at 3 AM so you don't have to.

But neither replaces good data hygiene. Protecting how data is stored, shared, and accessed matters just as much as stopping attacks.

Quasy's Final Assessment: "Hire an MSP to keep things running. Hire an MSSP to keep things safe. And train your staff not to email passwords to themselves using the subject line 'PASSWORDS' with a body that says 'DO NOT DELETE.'"

Mrs. Higgins nodded. "So Carol from Accounting is still the biggest threat?"

"Carol is always the biggest threat," Quasy confirmed. "Not because she's malicious. But because she's creative. She'll find a way to compromise the network using nothing but Outlook and determination. No hacker can match that combination."

He watched the two men in the hallway finally stop arguing. They shook hands. The MSP walked toward the server room. The MSSP walked toward the security console. Both entered the same building through different doors.

Quasy whispered: "And that's the whole industry in one image. Two guys. Same building. Different nightmares. Both necessary. Neither sufficient. Both billing hourly."

Mrs. Higgins finished her tea. "Should I hire one of them?"

"Both," Quasy said. "And also change your password. Because 'Higgins2026!' is not a secure password just because it has an exclamation mark."

"How did you know my—"

"Everyone knows your password, Mrs. Higgins. That's the problem."

His phone buzzed. Notification: "Your MSP contract expires in 7 days. Your MSSP contract expires in 3 days. Your data is exposed. Have a nice day."

Quasy looked at Mrs. Higgins. "See? Even the notification system is confused about who handles what."

He renewed both contracts. Changed every password. Enabled 2FA. And then sat quietly in his office, wondering which acronym would save him from Carol next.

The answer, as always, was none of them. Because Carol doesn't respond to acronyms. Carol responds to no one. Carol is the storm. And MSPs and MSSPs are both umbrellas. Useful, but not waterproof against Carol.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 29 Jun 2026 17:53:18 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-41</guid><link>https://carlostkd.ch/roadmap/#post-41</link><title>The GPT-5.6 Rollout: Or, How Washington Decided European Businesses Should Use Abacuses Again (While Their Competitors Get Autonomous AI Agents and a Head Start on Civilization)</title><description><![CDATA[Quasy_Complete was reading the news on a Tuesday morning when his screen filled with a headline that made him choke on his coffee.

"OpenAI Announces GPT-5.6: Three New Models (Sol, Terra, Luna) — But EU Businesses Might Not Get Them Yet Because Washington Said So."

He put his coffee down. Wiped his chin. Read it again.

"So," he said slowly, "America has invented a new brain, and they're deciding who gets to use it. Based on geography. In 2026."

His neighbor, Mrs. Higgins, appeared at the door holding a newspaper she clearly didn't understand.

"Quasy! It says here that the Americans are blocking Europe from using their new AI. Does this mean I can't ask the robot to write my grocery list anymore?"

"Mrs. Higgins," Quasy replied, "if that robot is powered by GPT-5.6 Sol, Terra, or Luna, and you live in Europe, then yes. Your grocery list is now a matter of national security."

She blinked. "National security? For groceries?"

"For everything. The US government has decided that European businesses are a security risk when given access to autonomous AI agents that can think, act, and possibly write better grocery lists than humans."

Mrs. Higgins lowered her newspaper. "That's terrifying."

"That's geopolitics," Quasy corrected. "Which is worse."

What Is GPT-5.6? (Three Flavors of Brain, None for You)

GPT-5.6 comes in three versions:

    Sol (Flagship): Agentic capabilities. Subagents that accelerate complex work. $5 input / $30 output. The Ferrari of AI models. Autonomous. Self-directed. Capable of performing real-world actions without human babysitting.
    Terra (Balanced): Everyday work model. The sensible Volvo of AI. Reliable. Practical. Won't scare your IT department.
    Luna (Speed/Affordability): $1 input / $6 output. The budget scooter of AI. Cheap. Fast. Gets you there eventually.

Quasy read the descriptions carefully. "Sol has subagents. Subagents! It delegates tasks to other AI agents. It's essentially an AI middle manager that never sleeps, never complains, and never asks for a raise."

He paused. "Which, ironically, is exactly what European businesses need to compete with their American counterparts. Who now have it. And we don't."

Mrs. Higgins tried to be optimistic. "Well, at least we still have the older models, right? GPT-4 or whatever?"

"Sure," Quasy nodded. "And the Americans still have horses and buggies. But they also just got rockets. We're being told to keep riding the buggy while they colonize Mars."

The Agentic Revolution (When AI Stops Being a Chatbot and Starts Being a Colleague)

Recent months have seen businesses adopting agentic systems. Unlike chatbots that respond to prompts, autonomous AI agents combine natural language processing with tools, memory, and the ability to take action independently.

For businesses, this means:

    Small businesses can outsource administrative tasks, data analysis, infrastructure inspection, risk monitoring, customer service.
    Agents embedded into existing workflows increase efficiency.
    Businesses of any size gain capabilities previously reserved for large corporations.

Quasy imagined a small European bakery:

Baker: "I installed an AI agent! It orders flour when supplies are low, responds to customer reviews, optimizes my pricing based on local demand, and files my taxes."

Quasy: "Impressive! What model?"

Baker: "GPT-5.6 Sol."

Quasy: "Ah. You're in Europe?"

Baker: "Yes."

Quasy: "Then enjoy doing all of that manually. With paper. And a pen. While your American competitor's AI agent just launched a targeted ad campaign, optimized supply chains across three states, and filed its own patents."

Baker: "That seems unfair."

Quasy: "It is unfair. It's also policy."

Why the US Is Controlling the Release (Because Freedom Is Conditional)

OpenAI's release announcement stated:

"As part of our ongoing engagement with the US government, we previewed our plans and the models' capabilities ahead of today's launch. At their request, we are starting with a limited preview for a small group of trusted partners whose participation has been shared with the government."

Quasy read this aloud three times. Each time, his expression shifted from amused to bewildered to slightly alarmed.

"At their request," he repeated. "Whose request? The US government's. And who are the 'trusted partners'? Companies whose participation has been shared with the government. So the government knows who gets access, when, and for what purpose."

Mrs. Higgins raised her hand like she was in school. "Excuse me. Does this mean the American government is acting like a bouncer at a nightclub? Deciding who gets in and who stays outside in the rain?"

"Mrs. Higgins," Quasy said, "that is the most accurate analogy I've heard all year. Yes. Washington is the bouncer. OpenAI is the club. GPT-5.6 is the VIP area. And Europe is standing behind the velvet rope in the rain, holding a clipboard that says 'waiting list.'"

The concerns are legitimate from a security standpoint. The new model can make autonomous real-world actions. OpenAI claims GPT-5.6 is trained to refuse prohibited cyber assistance, including disguised or jailbroken requests. But they also admit "no single safeguard is sufficient against determined or adaptive misuse."

Quasy appreciated the honesty: OpenAI: "Our model is safe!" Also OpenAI: "But also, someone could misuse it." US Government: "So we're gatekeeping." OpenAI: "If you insist." US Government: "We insist." Europe: "Can we—" US Government: "No."

President Trump signed an executive order on June 2 creating a classified benchmarking process for AI models, due by August 2026. The government will assess advanced cyber capabilities and determine which models qualify as "covered frontier models." Developers must provide government access to frontier models for up to 30 days before release.

Quasy's eyes widened. "Thirty days of government review. Before release. Classified benchmarks. Secret criteria. That's not a product launch. That's a military deployment with a marketing team."

He continued reading. "OpenAI says they 'don't believe this kind of government access process should become the long-term default.' But there's no public evidence supporting their optimism. Meanwhile, OpenAI is helping develop the cyber framework. Which means they're helping write the rules they'll follow. That's like a student grading their own exam and also choosing the curriculum."

Why European Businesses Should Be Concerned (Hint: It's Everything)

The laws, executive orders, and national security frameworks shaping US tech were written with American interests in mind. European businesses are an afterthought at best, a controlled market at worst.

Red flags for European business leaders:

    Kill Switch Risk: You could suddenly lose access to existing software. One executive order, one export control decision, one geopolitical tantrum, and your business tools vanish.

Quasy pictured a European CFO: CFO: "Why can't I access our AI-powered accounting system?" IT: "Washington revoked our access." CFO: "We're a furniture company in Lisbon!" IT: "Doesn't matter. The furniture industry is now a strategic sector." CFO: "Since when?" IT: "Since twenty minutes ago. The executive order is six pages long."

    Innovation Gap: You miss out on new technology. US competitors gain advantages while European businesses wait for approval that may never come.

Quasy: "Your American competitor just deployed an AI agent that manages their entire supply chain autonomously. You just deployed a new intern named Pedro who is still learning Excel. Both are learning. One learns at the speed of light. The other at the speed of lunch breaks."

    Changing Terms: Even when you retain access, vendor terms can shift unpredictably. Microsoft's Copilot customers experienced this when flex routing was introduced without warning.

Quasy: "One day you're using a product. The next day, the product is using you. Or your data. Or your budget. Same thing, in corporate speak."

It's Time to Choose European Tech (Or, Build Your Own Damn Brain)

The US can gate access to new models today. Tomorrow, it can restrict services European businesses already depend on. One executive order. One export control decision. One shift in geopolitical weather.

Interestingly, the US Ambassador to the EU recently complained that the European Chips Act "doesn't sound very consistent with the EU-US trade framework agreement."

Quasy laughed. "Ah, the irony. The US government blocks Europe from American AI, then objects when Europe builds its own chips. That's like blocking someone's water supply and then complaining when they dig a well. 'Excuse me, your independence is inconsistent with our monopoly.'"

The European tech sovereignty movement has grown in response. Businesses realize that relying on US tech means losing control of data and risking sudden access termination.

Quasy turned to Mrs. Higgins. "The solution isn't going to come from America. They're busy building walls. The solution comes from European investment in a sovereign tech stack."

"And what would that look like?" she asked.

Proton launched Proton Workspace this year. It gives businesses — including American firms — the ability to reduce overreliance on Big Tech. A secure European alternative offering email, cloud storage, VPN, AI assistant, video conferencing, and more, without surveillance and US government overreach.

By design, Proton is:

    Private and encrypted by default
    Open source and audited by third-party security experts
    Built with compliance in mind
    Sovereign and protected from US surveillance

Quasy enumerated the benefits like a man who'd done this before: "Email that Washington can't read. Cloud storage that Washington can't switch off. A VPN that Washington can't track. An AI assistant that doesn't report to Washington. Video conferencing that isn't routed through servers in Virginia."

Mrs. Higgins nodded slowly. "So Europeans can have their own tools?"

"They can. They should. They must. Because the alternative is asking permission from Washington every time they want to innovate."

Quasy's Final Thought: "A European business suite doesn't just break dependence on US tech. It protects businesses from being shut out of their tools. It actively invests in an independent European tech sector. It prioritizes business data protection. It grows the European economy. If you want a world where access to the most advanced technology isn't decided by your geographic location, move away from US tech companies."

He paused. Looked at the ceiling. Then spoke directly to the universe.

"They're certainly moving away from you."

Conclusion: Independence Isn't a Dirty Word (Unless You're Washington)

Quasy_Complete closed his laptop. The news about GPT-5.6 glowed on the screen for a moment, then disappeared.

Three AI models. Sol, Terra, Luna. Each one a marvel of technology. Each one potentially unavailable to half the Western world because of politics.

He thought about all the European businesses — bakeries, accounting firms, design studios, tech startups — that would wake up tomorrow and discover that the most powerful tools available were on the other side of an ocean they couldn't cross.

Mrs. Higgins touched his arm. "Quasy? What do we do now?"

"We build," he said. "We invest. We create European alternatives. We stop asking permission."

"From who?"

"From anyone."

His phone buzzed. Notification: "GPT-5.6 access request: DENIED. Reason: Geographic restriction. Have a nice day."

Quasy smiled. "They deny us access. We build our own. They change the rules. We change the game."

He opened Proton Workspace. His email was encrypted. His files were secure. His VPN was active. His AI assistant was European.

"And the best part?" he told Mrs. Higgins. "Washington doesn't even know I'm working right now."

She smiled back. "That's the most European thing I've ever heard."

"Independence," Quasy whispered. "It's not just a word. It's a strategy."

He poured himself another coffee. French roast. Naturally.

And if anyone in Washington was listening? They wouldn't hear anything. Because the line was encrypted. The data was sovereign. And the revolution was being built, quietly, in Europe, one encrypted email at a time.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 29 Jun 2026 17:48:11 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-40</guid><link>https://carlostkd.ch/roadmap/#post-40</link><title>Password Fatigue: Why Your Team Is Storing 200 Passwords in an Excel File Named “Passwords_Final_FINAL_v3.xlsx” (And How One Employee’s Sticky Note Can Cost You Millions)</title><description><![CDATA[Quasy_Complete walked into his office to find Dave sitting at his desk surrounded by sticky notes. Each one had a username and password written on it in different colors. Some were pinned to his monitor. Some were stuck to his coffee mug. One was literally under his keyboard.

“Dave,” Quasy said slowly. “What are you doing?”

“I’m organizing my passwords,” Dave replied cheerfully. “See? The blue ones are for work tools. The red ones are for personal stuff. The green ones are… well, those are for that website I found last week that lets me order pizza without paying.”

Quasy stared at the chaos. “You have passwords in six places: sticky notes, your browser, a spreadsheet on your desktop, an email draft to yourself, a note on your phone, and now you’re writing them on actual paper again?”

“It’s efficient!” Dave insisted. “If I lose one, I have five backups! That’s redundancy!”

“No,” Quasy corrected. “That’s a single point of failure with seven ways to get hacked.”

His neighbor, Mrs. Higgins, knocked on his window. She held her own notebook, filled with handwriting.

“Quasy! My husband asked me where he keeps the Wi-Fi password. I told him it’s in my diary next to his birthday and our anniversary and his sister’s dog’s name. Now all three of us are remembering the wrong thing!”

Quasy sighed. “Welcome to password fatigue, Mrs. Higgins. Where your brain becomes a filing cabinet someone else locked from the outside.”

What Is Password Fatigue? (The Mental Load of Remembering Too Many Things)

Password fatigue builds gradually. It’s caused by creating new logins, resetting passwords constantly, and losing track of dozens or hundreds of accounts.

In a business setting, this means managing credentials across email, messaging platforms, project management software, HR systems, finance tools, cloud storage, and more.

Each service has different rules: length requirements, special characters, resets, lockouts, multi-factor authentication. Keeping every password unique, strong, and accessible becomes impossible to sustain manually.

Quasy’s Mental Image: Employee: “I need another password! And it needs to have a capital letter, a number, a symbol, a rune, and my mother’s maiden name!” IT Guy: “Just make it secure!” Employee: Types ‘Password1’ everywhere. Hacker: “Thanks!”

This is when password fatigue becomes a business risk. People reduce the burden in practical but unsafe ways. They reuse passwords, create predictable patterns, save credentials in notes, spreadsheets, or share access informally.

How Password Fatigue Appears at Work (The Five Red Flags)

When assessing your business for password fatigue, look for these patterns:

    Password Reuse: Using the same password across several accounts feels efficient. But if one is exposed in a breach, every account using it becomes accessible. Quasy pictured a hacker testing credentials: Hacker: “Try ‘FluffyBunny2026’ on Gmail…” Gmail: “Access granted.” Hacker: “Same on Slack?” Slack: “Access granted.” Hacker: “Payroll system?” Payroll: “Oh hi there.” Company: “How did you get in here?” Hacker: “Your employee used the same password for Netflix as for their bank. Math.”

    Predictable Passwords: People use company names, seasons, years, keyboard patterns, pet names. A password like Spring2026! satisfies basic rules but is easy to guess. Quasy: “‘Summer2027!’ might pass IT’s policy, but it fails human intelligence tests. If I can predict your season preference, I can hack your account.”

    Unmanaged Storage: Writing passwords in notebooks, saving in spreadsheets, relying on browser-saved passwords, sending via chats and email threads. These spread credentials across unmonitored places. Mrs. Higgins: “My husband stores passwords in a Word document called ‘DO NOT OPEN.txt’. Irony is not lost on him.” Quasy: “Irony is also what hackers read while logging into your server.”

    Informal Sharing: Team members send access through chat or email. Access can’t be revoked, tracked, or audited easily. Quasy imagined an offboarding scenario: Manager: “Sarah left the company. Remove her access.” IT: “But she shared the payroll login via WhatsApp with four people. And no one knows which four.” Manager: “So we just leave it open?” IT: “Yes. Until we notice money disappearing.”

    Browser-Saved Passwords: Convenient but no admin oversight, no controlled sharing, unclear ownership. Quasy: “Browser password managers help one person save their own passwords. For a business? That’s like giving every employee a key to the safe but nobody controls who makes copies.”

Why Password Fatigue Creates Business Risk (One Leaked Credential Can Break Everything)

Reused passwords, predictable patterns, uncontrolled storage, and informal sharing weaken access controls.

Password Reuse Enables Credential Stuffing: Attackers use exposed username/password combinations from one breach to try accessing other services. An exposed email password may let an attacker reset access to other tools. Project management accounts reveal client info, internal files, links to other systems. Admin access escalates privileges.

Once an attacker has one set of credentials, they move laterally through the network. Explored environments test access to higher-value accounts. Reused passwords make this easier because one exposed credential opens more than one door.

Weak Passwords Reduce Brute-Force Resistance: Weak or predictable passwords are easier to guess through dictionary attacks. Automated tools use leaked password databases. Password fatigue increases weak passwords because people optimize for memorability, not security.

Without a business password manager, the advice “use stronger passwords” is technically correct but operationally weak. People can remember a few secrets, not dozens of unique random passwords.

Informal Sharing Removes Accountability: When several people use one shared login, tracking who uses it becomes hard. If a file is deleted or payment approved, logs only show account activity, not individual users. Shared logins make offboarding harder—if employees had access through chat history, removing their account doesn’t remove practical access.

Scattered Passwords Slow Incident Response: During a security incident, teams need to revoke access, rotate passwords, review activity. Password fatigue makes this harder when credentials are reused, stored in multiple places, or shared informally. Uncertainty increases response time and disruption. IBM’s 2025 report placed average data breach cost at $4.4 million.

Quasy calculated: “Four million dollars. That’s enough to buy a lot of sticky notes. Or hire a real IT team. Either way, don’t use sticky notes.”

Creating Stronger Passwords Isn’t Enough (Because Willpower Is Not a Security Strategy)

Telling employees to use stronger passwords sounds reasonable. But stronger passwords alone can’t solve password fatigue. In some cases, this makes the problem worse.

A stronger password is only useful if it’s unique, stored securely, and used consistently. If employees must create and remember every strong password themselves, the burden becomes too high. They respond by reusing one strong password everywhere, making predictable variations, or saving passwords somewhere unsafe.

People can remember a few important secrets, but not dozens of unique, random, high-entropy passwords across changing tools. When a password policy ignores reality, it creates a gap between what the business says people should do and what they can actually do.

Modern security guidance has moved away from rules that create unnecessary password strain. If a control pushes people toward weaker behavior, it reduces security rather than improving it.

Quasy looked at Dave’s spreadsheet: “Password List – Version 9 – REALLY FINAL THIS TIME.”

“See,” Quasy said. “The fact that version nine exists tells me everything. Security isn’t about trying harder. It’s about trying smarter.”

The Real Solution to Password Fatigue (Outsource Memory to Machines)

Solving password fatigue doesn’t mean asking employees to remember more, try harder, or invent stronger passwords. Place the burden on tools, not individuals.

A business password manager removes that burden from daily workflow. Instead of expecting employees to remember every credential, it lets them generate strong, unique passwords, store them securely, autofill when needed, and share access controllably. Makes the safest behavior the easiest choice.

Password generators are features, not standalone solutions. Real value is when generation is built into a business password manager that also stores, autofills, shares, and manages credentials. Business password managers stronger than browser-built ones because browsers offer no administrative oversight, no controlled sharing, unclear ownership.

Managed password vaults give every credential a proper home. Instead of passwords ending up in notes, spreadsheets, browser profiles, documents, teams have one secure place. Reduces password sprawl. Gives administrators clearer view of access, offboarding, rotation.

Controlled sharing shifts away from password fatigue. Credentials still need to be shared, but safely. With controlled sharing in a business password manager, access managed deliberately. Teams share credentials through vaults, limit who has access, update passwords, revoke access when needed.

Business password manager enables stronger password behavior without extra work. Autofill helps employees access tools without typing/remembering complex passwords. Built-in generation means no manual invention. Organized vaults make access easier. Admin controls keep policies consistent.

How Proton Pass for Business Helps (Or, Stop Relying on Sticky Notes)

Proton Pass for Business is a secure password manager that replaces manual habits with a manageable system. Employees generate strong unique passwords, store in encrypted vaults, access without memory reliance, browser saves, or unsafe workarounds.

For administrators, supports centralized credential management. Reduces password reuse, limits informal sharing, improves visibility into credential management. No more passwords in spreadsheets, chats, browser profiles, personal notes.

Proton’s 2026 SMB Cybersecurity Report found 48% of small/medium businesses surveyed don’t have a password manager. Even those that do still share credentials through email, messaging apps, shared documents, conversations, written notes.

Adoption, policy, controlled sharing must work together. Strong policy gives employees tools to follow it. Proton Pass designed around Proton’s broader security model: end-to-end encryption for credentials including metadata, open-source, independent audits, Proton-owned infrastructure.

Proton Pass for Business gives organizations practical ways to reduce password reuse, replace unsafe sharing, make secure access easier daily.

Quasy handed Dave a tablet with Proton Pass installed: “Here. Use this instead of your sticky notes.”

Dave frowned. “But I already memorized half of them.”

“Congratulations,” Quasy said. “You’ve turned your brain into a vulnerable database. Now we fix it.”

Conclusion: Secure Behavior Should Be Easy (Not Exhausting)

Password fatigue is a threat to business access management. If one exposed credential is reused across multiple systems, attackers move laterally. Weak passwords enable brute-force. Informal sharing removes accountability. Scattered passwords slow incident response.

Modern security moves away from rules that create strain. Make secure behavior the easiest option.

Proton Pass helps teams manage passwords without extra burden. Employees stop guessing, start trusting. Administrators gain visibility, control, peace of mind.

Quasy looked at Dave’s empty desk: “No more sticky notes?”

Dave nodded. “They went in the trash. Along with my dignity.”

“Good,” Quasy smiled. “Dignity is overrated. Security isn’t.”

He closed his laptop. His phone buzzed. Notification: “New login attempt detected. Location: Unknown. Device: Old Phone.”

Quasy laughed. “Ah, the sequel. Just like the first movie, but with better encryption.”

He denied the login. Changed passwords. Enabled 2FA. Then went back to checking on Dave.

Dave had removed all sticky notes. Every password was now in Proton Pass. His browser was clean. His spreadsheet deleted. His coffee mug free of ink stains.

Progress. Slow, painful progress. But progress nonetheless.

And if anyone tried to hack them now? They’d get encrypted gibberish. Which, incidentally, is exactly how hackers hate things to feel.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Thu, 25 Jun 2026 18:53:44 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-39</guid><link>https://carlostkd.ch/roadmap/#post-39</link><title>Malicious Apps on Google Play: How to Download Software Without Selling Your Soul (Or Your Contacts, Location, and Cat Photos)</title><description><![CDATA[Quasy_Complete was sitting in his living room when he decided to download a new flashlight app. It was 3 PM in the afternoon. He didn't need a flashlight. But the icon looked shiny. And the name was promising: “FlashLight Pro+ Turbo Ultra Max 2026”

“Why not?” he muttered. “I’ve got two phones. Maybe I’ll find one lightbulb somewhere.”

He opened the Google Play Store and typed in the name. The app appeared with 4.9 stars and 15 million downloads.

“Five stars,” Quasy said skeptically. “That’s suspicious. Everything on earth is terrible. Why would this flashlight be perfect?”

He clicked “Install.” While it downloaded, he thought about the millions of other apps installed on his phone. Each one probably had a tiny spy built into its code. Like digital ants marching around his personal data.

His neighbor, Mrs. Higgins, peered over the fence. She held her own phone up like a shield.

“Quasy! I just downloaded an app that says it will ‘optimize your battery life.’ Now my phone is asking for permission to access my contacts, microphone, camera, and home address. Is this normal?”

Quasy_Complete sighed. “Mrs. Higgins, if your flashlight app needs to know who your friends are, something is wrong. Either with the app, or with your understanding of what a flashlight does.”

She lowered her phone. “But the reviews say it’s amazing!”

Reviews: “Perfect! Works great!! 5 stars!!!” posted 200 times in the same hour from accounts named User12345, AndroidFan_99, and SuperHappyPerson.

Quasy smiled. “Ah, yes. The classic ‘Wall of Five Stars Posted During Lunch Break’ technique. Very sophisticated. Very convincing. Very fake.”

How Malicious Apps Get Past Google (Or, Why the Security Check Failed)

Google blocked 1.75 million policy-violating apps last year. They banned over 80,000 developer accounts. Play Protect blocked 266 million risky installation attempts.

But Google can only do so much. Cybercriminals keep finding ways through.

Popular strategies include:

    Submitting clean apps for review, then pushing malicious activity via remote updates.
    Disguising malicious apps as utility tools like document scanners or PDF readers.
    Disguising them as security or antivirus apps—because anxious users won’t scrutinize before installing.

Quasy imagined a hacker meeting: Hacker #1: “We need to get past Google’s review.” Hacker #2: “What if we make it look like a PDF scanner?” Hacker #1: “Brilliant. Everyone trusts scanners. Also add a button that says ‘Fix Battery.’ That’ll seal the deal.” Hacker #3: “What about the data collection part?” Hacker #1: “Hide it in terms and conditions. Nobody reads those anyway.” Hacker #3: “So we steal their data and nobody notices?” Hacker #1: “Exactly. We’re basically digital ghosts.”

Last year, Bitdefender uncovered an ad fraud campaign called Vapor. It involved 331 malicious apps collecting credentials and credit card data. Downloads exceeded 60 million.

Sixty million. Quasy did the math. “So roughly half the planet downloaded a scam app. Meanwhile, the other half is arguing about whether pineapple belongs on pizza. Priorities, people.”

Legitimate Apps Can Still Put Your Data at Risk (Because Privacy Is Optional)

Malicious apps aren’t the only hazard. Legitimate apps quietly collect and store personal data, sharing it with third parties like ad networks.

NowSecure tested 25,000 apps across iOS and Android. Found 75% of iOS apps and 70% of Android apps collected sensitive data and tracking domains.

Google allows these because developers disclose data collection in the data safety section. In 2025, Google tightened policies and blocked 255,000 apps from gaining excessive access. Thousands remain unblocked that collect data within the letter of the policy but far beyond what users expect.

Quasy read the data safety section of his flashlight app. It claimed: “We collect location to show you nearby light sources.”

“Nearby light sources?” he laughed. “Like... the sun? Street lamps? A candle in my kitchen? Does the flashlight need GPS for all that?”

He scrolled down. “We also share data with advertising SDKs and analytics partners. These third parties pass data to data brokers.”

Every link in the chain is a breach-point. If your data is compromised, you might not find out until it’s too late.

Mrs. Higgins nodded. “So basically, my flashlight is spying on me.”

“Not just the flashlight,” Quasy replied. “Your wallpaper app. Your calculator. Your weather app. Even that app that reminds you to drink water. All of them probably have spies inside. It’s like living in a house where every mirror has a camera. Except the cameras are software.”

What to Look Out For: A Five-Point Checklist (Because You Need a Manual Now)

There’s no authoritative blacklist of banned apps. But there are red flags to watch for:

    Check the Data Safety Section: Has the developer explained what they collect? An empty section is bad. A policy that doesn’t match functionality is worse. A torch app shouldn’t need contacts. Quasy: “If a calculator app asks for your SMS messages, run. Run fast. And maybe call the police while you’re at it.”

    Read the Permissions on Install: Does the app ask for location, contacts, storage, microphone? Sometimes it makes sense. Other times, why does a wallpaper app need your location? Mrs. Higgins: “My cat picture app asked for microphone access!” Quasy: “Maybe it listens for meowing to adjust the brightness? Just kidding. It’s definitely listening to you talk.”

    Check Developer Name and History: Is it a named company with other apps and web presence? Or a one-person account with a single app and no trail? Quasy: “If the developer is named ‘JohnDoe123’ with zero other apps, odds are good he’s hiding in a basement in some country where ‘privacy’ is a suggestion.”

    Check If Reviews Are Real: Fake reviews show obvious patterns. Wall of five-star reviews posted in short periods is manipulation. Look for critical reviews interspersed with positive ones, and a wide spread of dates. Quasy: “A thousand five-star reviews from yesterday is suspicious. A hundred three-star reviews from different months is honest. It’s like voting in an election where everyone shows up wearing the same mask.”

    Watch Out for Free Utility Apps: Most common disguises are free flashlight, battery, keyboard, photo editor, weather apps with location access, and ad-supported games. If an app is free and you can’t see how it makes money, the answer is your data is their revenue model. Quasy: “Free WiFi checker app? Probably sells your browsing history. Free ringtones app? Probably installs trackers. Free puzzle game? Definitely mining crypto while you play Tetris.”

How to Protect Your Data (When Prevention Fails)

Even after due diligence, you may still download a malicious app. But protections can limit damage.

Encrypt Your Connection with Proton VPN

Malicious apps transmit data over unencrypted connections. Proton VPN encrypts all data to/from your phone at network level. Makes transmission and interception harder. Prevents surveillance on public WiFi. Blocks data transmissions analytics SDKs rely on via NetShield.

Quasy pictured a café: Café Owner: “Free WiFi for customers!” Hackers: “Thank you! We’ll take everything!” Quasy: “With Proton VPN, I’m invisible to them. My traffic looks like encrypted garbage. They can’t read it unless they crack encryption, which takes longer than waiting for coffee.”

Protect Your Credentials with Proton Pass

Malicious apps use invisible keyloggers and phishing overlays to steal login credentials. Dangerous if you reuse passwords.

Proton Pass generates unique passwords for every account. Protects passwords, passkeys, and credit cards with end-to-end encryption. Credentials encrypted on device before leaving. Not even Proton can access them.

Quasy: “Instead of using ‘Password123’ for forty sites, I let Proton Pass generate gibberish for each one. One gets breached? The others stay safe. It’s like having forty keys instead of one master key hanging on the front door.”

Know How to Remove Malware (Because Sometimes You Get Hacked Anyway)

If concerned your device is compromised, recognize signs your phone has been hacked. Unusual battery drain, overheating, pop-ups, unknown apps appearing, settings changing without input.

Quasy’s Troubleshooting List:

    Run Safety Check (iOS/Android settings).
    Clear browser cache.
    Review permissions.
    Delete suspicious profiles.
    Factory reset if needed.
    Contact Apple/Android support if targeted by sophisticated spyware.

He showed his list to Mrs. Higgins. “If your flashlight starts asking for access to your bank account, delete it immediately. Then burn it. Digitally speaking.”

“Can I burn a digital file?” she asked.

“You can trash it, empty the trash, and hope the cloud gods forget it existed. That counts.”

Conclusion: The Best Defense Is a Healthy Dose of Skepticism (And Some Good Tools)

Google Play is safer than random websites, but not entirely safe. You need to shop conscientiously: vet apps before downloading, audit what you’ve already downloaded, and secure device data in case of breach.

Encryption helps. Unique passwords help. Awareness helps. Skepticism helps most of all.

Quasy looked at his flashlight app again. He had never used it once since installing. The battery had drained 5% overnight. He deleted the app.

Then he checked his permissions list. His weather app requested microphone access. He revoked it. His wallpaper app asked for contacts. Revoked. His calculator app asked for SMS messages. Revoked.

“Okay,” he muttered. “Now my phone is safe. Mostly. As long as I don’t download anything else stupid.”

His phone buzzed. A notification from an unknown source: “DOWNLOAD THIS NEW APP TO DOUBLE YOUR RAM AND SPEED UP YOUR DEVICE!”

Quasy laughed. “Double your RAM? By downloading an app? That’s like ordering extra muscle from Amazon and expecting to grow stronger.”

He reported it as spam. Deleted it. Then went back to reading a book. On paper. Because sometimes the best protection is no screen at all.

And if anyone asked him why he wasn’t using a high-tech security system?

He’d tell them: “Skepticism is the original firewall. It’s been working since the invention of the internet. And it’s free.”

Then he closed his book. The flashlight stayed off. The phone stayed quiet. And the data stayed his own.

Which, incidentally, is exactly how it should be.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 24 Jun 2026 17:36:59 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-38</guid><link>https://carlostkd.ch/roadmap/#post-38</link><title>Can iPhones Get Viruses? (Yes, If You Jailbreak Them. Or If NSO Group Decides You’re Interesting Enough. But Probably Not If You Just Use Safari Like a Normal Person)</title><description><![CDATA[Quasy_Complete was sitting in his living room, holding his iPhone like it was a fragile artifact from the ancient world. It felt warm to the touch. The battery had dropped from 100% to 42% in three hours while he was just watching cat videos.

“Ah,” he muttered. “The classic symptoms of a virus. My phone is hot, dying fast, and I saw a pop-up that said ‘Your iPhone Has Been Hacked! Click Here to Fix!’”

He opened his laptop to research. The screen filled with headlines: “iPhones are immune!” “Except when they aren’t!” “Jailbreaking breaks everything!” “Pegasus spyware exists!”

“Perfect,” Quasy sighed. “So my phone is either safe or doomed. There’s no middle ground. No gray area. Just binary paranoia.”

Do iPhones Get Viruses? (The Great Apple Debate)

Maybe your iPhone is hot. Maybe it’s draining battery. The good news? It’s extremely unlikely to be a virus. The bad news? It could still be malware.

Viruses vs. Malware on iPhone: Malware is intentionally designed to steal, disrupt, or destroy data. It includes trojans, spyware, ransomware, and yes, viruses. A virus replicates across files. iPhones are considered safe from viruses because every third-party app is isolated (sandboxed) from other apps and system data. This makes self-replication virtually impossible.

Quasy’s Mental Image: Hacker: “I need to infect this iPhone! Let me send a virus!” iPhone Sandbox: “Nope. You can’t get out. You can’t get in. You can’t even say hello.” Hacker: “Fine. I’ll just install a Trojan instead. They don’t have sandboxes for those.” iPhone: “Oh well. Good luck.”

Apple’s defense strategy relies on three layers:

    Strict Sandboxing: Apps run in isolated environments.
    App Store Vetting: Manual and automated reviews before publishing.
    Automated Security Patches: Frequent, mandatory iOS updates.

Quasy: “Apple doesn’t even use the word ‘virus’ in their support docs. They call it ‘unauthorized modification.’ That’s corporate speak for ‘You broke the rules, and now you’re liable.’”

Real-World Attacks (When the Fortress Gets Breached)

While iOS blocks self-replicating viruses, it remains vulnerable under specific conditions: jailbreaking, compromised tools, or state-level exploits.

    AdThief (2014): Adware/hijacker targeting jailbroken devices. Swapped legitimate ads with malicious ones to steal revenue. Impact: 75,000 devices hijacked. Developers lost money. Quasy: “So if you break the sandbox, you lose the cash. Classic case of ‘hacking your own house to let in the thieves.’”

    XcodeGhost (2015): Supply chain Trojan. Fake version of Xcode (Apple’s coding tool) infected popular apps like WeChat and Angry Birds. Impact: Users downloaded compromised apps from the App Store. Quasy: “Even the vetted gatekeepers can be tricked if the source code is poisoned. It’s like baking a cake with flour that’s already laced with poison. The baker didn’t know, but the customers sure did.”

    Pegasus & Graphite (2016–Present & 2025–Present): Zero-click spyware from NSO Group and Paragon Solutions. Exploits zero-day vulnerabilities to gain root access without user interaction. Impact: Messages, photos, location, mic feeds extracted. Targets: journalists, politicians. Quasy: “This isn’t a virus. This is a military-grade surveillance tool. If you’re not a politician or a journalist, you probably don’t have to worry. Unless you’re interesting. Then you’re toast.”

    LightSpy (2020–Present): Cross-platform spyware via malicious websites. Visiting a compromised page can install surveillance software. Impact: Contacts, messages, files harvested. No download needed. Quasy: “So if I click a link, I’m done. Just by clicking. That’s scary. But also convenient. I can go online and get hacked without lifting a finger. Efficiency!”

Signs of Malware on Your iPhone (Or Is It Just Old?)

There’s no definitive way to check for viruses, but look for:

    Unusual account activity: Unknown devices linked to Apple ID, unexpected password changes, weird purchases.
    Technical anomalies: Battery drain, overheating, apps crashing, unknown apps appearing.
    Pop-ups/phishing: Messages urging you to install profiles or click links.

Quasy imagined his own phone: Phone: “Battery low. Overheating.” Quasy: “Is it a virus?” Phone: “Or maybe you left it in the sun playing Candy Crush for six hours?” Quasy: “Oh. Right. That explains it.”

How to Get Rid of a Virus on iPhone (Manual Diagnosis Time)

Since Apple doesn’t use the term “virus,” there are no official removal steps. But here’s what to do:

    Run Safety Check (iOS 16+): Reset permissions for suspicious apps. Quasy: “It’s like telling your apps, ‘Hey, stop touching my photos unless I ask.’”

    Clear Safari Data: Remove cookies and cached scripts causing pop-ups. Quasy: “Often, what looks like a virus is just aggressive adware. Or a very persistent spider.”

    Review Configuration Profiles: Delete unknown profiles forcing settings changes. Quasy: “If you see a profile named ‘Trust Me,’ delete it. Immediately. Before it installs itself.”

    Factory Reset: Wipe the device clean. Restore from a clean backup. Warning: If targeted by Pegasus, a reset may not be enough. Contact Apple Support. Quasy: “If you’ve been hacked by a spy agency, a factory reset won’t help. You might need a new phone. Or a new life.”

Is It OK to Jailbreak My iPhone? (The Short Answer: No)

We strongly advise against jailbreaking. It dismantles the security architecture:

    Breaks the sandbox: Malicious apps can access other apps’ data.
    Loses App Store vetting: Unreviewed apps mean higher risk.
    Blocks security updates: Known vulnerabilities stay open.

Quasy: “Keeping your iPhone unmodified is the best defense. Custom themes aren’t worth turning your secure fortress into a public park.”

Security Tips: What to Look Out For (Don’t Be Gullible)

Risks come from social engineering and risky behavior:

    Phishing/Smishing: Unsolicited emails/texts claiming package delays, compromised accounts, or prizes. Always verify.
    Fake “Virus Scanners”: Apps claiming to scan for iPhone viruses are scams. System-wide scanning is impossible on iOS.
    Malicious Websites: Avoid clicking suspicious links. Check app credibility, downloads, reviews, and permissions.

Quasy: “An app shouldn’t need access to your microphone to show a flashlight. Unless the flashlight is secretly recording your secrets. Which it probably isn’t. But still, don’t trust it.”

Conclusion: iPhones Are Mostly Safe (Unless You Make Them Unsafe)

iPhones are naturally resistant to viruses. But the biggest risks come from being tricked into granting access or installing malicious software.

Use tools that manage security for you:

    Proton Pass: Generate unique, complex passwords. Prevent credential theft.
    Proton VPN: NetShield Ad-blocker blocks malware and trackers.

Quasy_Complete looked at his phone again. It was cool now. The battery was fine. The pop-ups were gone.

“Okay,” he said. “No virus. Just a misunderstanding.”

His phone buzzed. Notification: “Your iPhone is safe! But we noticed you visited a suspicious website. Want to upgrade to our Premium Security Plan for $99/month?”

Quasy laughed. “Ah, the sequel. Just like the first movie, but with more marketing.”

He deleted the message. Then he opened Proton Pass. “Goodbye,” he whispered. “And welcome to the world where my passwords are unique, my browser is clean, and my iPhone stays sane.”

Then he went back to watching cat videos. Because sometimes, the best defense is just not clicking on strange links. And maybe not jailbreaking your phone. Unless you really want to live on the edge. Which, incidentally, is exactly where hackers like to find you.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 24 Jun 2026 17:34:48 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-37</guid><link>https://carlostkd.ch/roadmap/#post-37</link><title>Cloud Storage Email Scams: How a Fake &quot;Storage Full&quot; Warning Can Empty Both Your Cloud and Your Bank Account (Or, Why That 80% Discount on Extra Space Is Actually 100% Scam)</title><description><![CDATA[Quasy_Complete was eating breakfast when his phone buzzed. He looked down at the notification.

EMAIL: "URGENT: Your Cloud+ storage is 99.8% FULL! All files will be PERMANENTLY DELETED in 24 HOURS unless you upgrade NOW! Click here to save your photos of Grandma's 80th birthday before they vanish into the digital abyss FOREVER!"

Quasy_Complete stared at the screen. He didn't have a "Cloud+" account. He had never signed up for anything called "Cloud+." He was fairly certain "Cloud+" was not a real company.

"Hmm," he said, chewing his toast slowly. "My files are being deleted in 24 hours by a service I've never used. That's impressive. Even by scam standards."

He showed the email to his neighbor, Mrs. Higgins, who was visiting for coffee.

"Oh dear!" she gasped. "Your photos are going to be deleted? The ones of your cat wearing the tiny hat?"

"Mrs. Higgins," Quasy said calmly, "I don't have a Cloud+ account. And my cat's hat photos are stored locally on a USB drive buried in my sock drawer. The only thing being deleted here is my patience."

"But the email looks so real!" she insisted. "It has a cloud icon! And a blue button that says 'Upgrade Now!'"

"Mrs. Higgins," Quasy replied, "if I put a cloud icon on a parking ticket and a blue button that says 'Pay Now,' would you also believe your car was illegally parked in cyberspace?"

She thought about it for a moment. "Possibly."

How to Spot a Cloud Storage Scam (The Art of Panicking People Into Clicking)

Scammers rely on a consistent set of tactics. Before clicking anything, check for these signs:

Unusual Sender Address: Messages come from random domains like cloud-storage-alerts@notification-update-center-3847.biz.

Quasy_Complete examined the sender: no-reply@cloudplus-support-team-urgent.xyz.

"Ah yes," he noted. "CloudPlus Support Team Urgent dot xyz. Very legitimate. I'm surprised they didn't go with dot trustworthy."

Generic Branding: Names like "Cloud," "Cloud+," or "Cloud Storage" instead of real product names.

"Cloud+," Quasy muttered. "What is that? A cloud with a bonus feature? A cloud that does math? A cloud that graduated summa cum laude?"

Urgent Language: "Files deleted in 24 hours!" "Account BLOCKED!" "Payment EXPIRED!"

Quasy_Complete read the email aloud to Mrs. Higgins: "ATTENTION: Your cloud storage is CRITICALLY FULL. Immediate action REQUIRED. Failure to respond will result in PERMANENT ERASURE of all memories, documents, and that recipe for lasagna you saved in 2019 and never opened again."

"They know about the lasagna recipe?" Mrs. Higgins whispered.

"No one knows about the lasagna recipe," Quasy replied. "That's the point. They're making it up. Like every other detail in this email."

Suspicious Links: Redirecting through unrelated domains or leading to fake login pages.

Quasy hovered over the "Upgrade Now" button. The URL read: http://totally-not-a-scam.cloudupgrade.xyz/login?id=steal-your-data

"Interesting," he said. "The upgrade button leads to a website called 'totally not a scam.' If you have to say you're not a scam in your URL, you are absolutely a scam."

Generic Greetings: "Hello" without your name, or addressed to your email address.

Dear cloudplus_user_48291@gmail.com, the email began.

"They don't even know my name," Quasy observed. "They know a string of characters. That's like a stranger calling you 'Hey, Person With Two Legs' and asking for your credit card."

Unrealistic Offers: "80% off upgrades!" "Limited-time recovery deals!"

"Eighty percent off?" Quasy laughed. "Name one legitimate cloud service that offers 80% off anything. Even Black Friday only gives you 20% off and a guilt trip about not reading the terms."

Legitimate vs. Fake: The Great Storage Email Duel

Cloud storage scams are convincing because they appear alongside real storage alerts.

Quasy_Complete compared two emails side by side for Mrs. Higgins.

Real iCloud Email:

    Sender: no_reply@email.apple.com
    Tone: "Your iCloud storage is full. You can manage your storage in Settings."
    Link: Directs to official Apple settings page.

Fake iCloud Scam:

    Sender: iCloud_Support_Alerts@service-notification-portal-992.net
    Tone: "YOUR iCLOUD HAS BEEN BLOCKED! PHOTOS WILL BE DESTROYED AT MIDNIGHT! UPGRADE IMMEDIATELY TO PREVENT TOTAL LOSS OF EVERYTHING YOU'VE EVER LOVED!"
    Link: Directs to apple-id-verify-login-secure-definitely-real.com

"See the difference?" Quasy asked.

"One is calm and the other sounds like it was written by someone being chased by bees?" Mrs. Higgins offered.

"Exactly. Real companies don't threaten you with emotional destruction. Scammers do. Because fear makes you click."

What to Do If You Receive One (Don't Click. Don't Panic. Don't Feed the Trolls)

Step 1: Do Not Click Anything. Not the button. Not the link. Not the "Unsubscribe" option. Not even the little X if it looks suspicious.

"Clicking 'Unsubscribe' in a scam email," Quasy explained, "is like telling a burglar, 'Yes, someone is home! And the door is unlocked! Come on in!'"

Step 2: Check Your Real Account Directly. Log in through the official app or website. Not through the email link. Type the URL yourself.

Mrs. Higgins pulled out her phone. "So I should open the iCloud app, not click the email link?"

"Correct. If your storage is actually full, the app will tell you. If it's not full, the email was lying. Which it was. Because scammers lie. It's their whole job."

Step 3: Mark as Spam or Phishing. Don't just delete it. Report it. This trains spam filters.

Quasy reported the email. "Now the filter knows. Next time, it'll catch it before I even see it. Unless the scammer changes their domain. Which they will. Because scammers are like cockroaches. They adapt."

Step 4: Do Not Reply. Replying confirms your address is active.

"What if I reply with a rude message?" Mrs. Higgins asked. "Like, 'I know you're a scam, you horrible person!'"

"Then they know your email is active AND that you read their messages," Quasy said. "Congratulations, you've just promoted yourself from 'random target' to 'engaged recipient.' They'll send you ten more tomorrow."

Step 5: Delete After Reporting. Remove it from your inbox so you don't accidentally click it later.

Mrs. Higgins nodded. "Out of sight, out of mind."

"Out of inbox, out of danger," Quasy corrected.

Step 6: Change Your Password and Enable 2FA If You Clicked. If you entered your password on a fake page, change it immediately. Use a unique password. Turn on 2FA.

Quasy_Complete imagined the scenario: Victim: "I typed my password into the fake site! What do I do?" Quasy: "Change every password you have. Enable 2FA. Then sit quietly and reflect on the life choices that led you to click a link that said 'Save Your Files Before Midnight.'"

Step 7: Check Account Activity and Payment Details. Review connected devices, recovery emails, and payment methods. Remove anything unfamiliar.

"If you entered card details," Quasy warned, "call your bank. Freeze the card. Then freeze yourself emotionally, because you just handed your financial soul to a stranger."

Step 8: Report the Scam. Forward to APWG, your email provider, and the company being impersonated.

Quasy forwarded the email to the Anti-Phishing Working Group. "Every report helps. It's like leaving a Yelp review for a criminal. Maybe they'll get shut down. Or maybe they'll just open a new domain. But at least you tried."

Why You Keep Getting These Emails (Because Your Address Is on a List Somewhere)

Even after reporting, the scams keep coming. Why?

Your email is on spam lists. Data breaches, public websites, and data brokers sell your address.

Quasy checked Proton Pass's dark web monitoring. "Oh look. My email appeared in 14 breaches. Fourteen. That's more breaches than I've had hot dinners this month."

"You can also use email aliases," he told Mrs. Higgins. "Give each service a different alias. If one leaks, your real email stays safe."

You opened or clicked a scam before. Tracking pixels confirm your address is active.

"This is why Proton Mail removes invisible trackers from every email," Quasy noted. "The sender never knows if you opened it. It's like answering the door through a peephole. They can't see you, but you can see them."

Scammers rotate domains. Blocking one sender doesn't stop them.

Mrs. Higgins frowned. "So they just change their name and come back?"

"Like a bad cold," Quasy replied. "Or a relative who visits every holiday. You can't stop them entirely, but you can build better defenses."

Spam filters are still learning. Some scams bypass filters using images instead of text, strange spacing, or compromised accounts.

"Continue reporting," Quasy advised. "Create custom filters for phrases like 'storage full' or 'account suspended.' And check your spam folder occasionally. Sometimes legitimate emails end up there. Like a wrongfully convicted citizen in a digital prison."

Stay Ahead with Proton (Because Your Inbox and Your Files Deserve Better)

Cloud storage scams work because they target two things people care about: access to their inbox and access to their files.

Proton Mail protects email with spam filtering, phishing protection, tracker removal, and end-to-end encryption. Proton Drive stores files with end-to-end encryption, meaning no one — not even Proton — can access them.

Mrs. Higgins nodded slowly. "So if I use Proton, scammers can't see my emails?"

"They can send you scams," Quasy clarified. "But Proton will flag most of them. And if you do click, your files are encrypted. The scammer gets nothing but scrambled data and disappointment."

"A scrambled scammer," she smiled. "I like that."

"A disappointed hacker," Quasy added. "Which is the best kind of hacker."

Conclusion: Your Files Are Fine (It's the Email That's Broken)

Quasy_Complete finished his coffee. Mrs. Higgins left, promising to check her real iCloud account before clicking any more blue buttons.

He looked at his inbox. Two more scam emails had arrived.

EMAIL 1: "CRITICAL: Your Microsoft OneDrive will be TERMINATED in 6 hours! Upgrade to Cloud+ Premium for only $1.99/month! ACT NOW!"

EMAIL 2: "WARNING: 4,297 files in your Google Drive are scheduled for DELETION! Verify your identity to prevent CATASTROPHIC DATA LOSS!"

Quasy smiled. "Cloud+ Premium. The service that doesn't exist, offering a deal that isn't real, for files that were never in danger. This is the golden age of nonsense."

He reported both emails. Deleted them. Then checked his actual Proton Drive. His files were fine. His storage was at 23%. His lasagna recipe was safe. His cat's hat photos remained intact.

"Imagine that," he said to no one. "Everything is fine when you don't panic."

His phone buzzed one more time. NOTIFICATION: "ALERT: Your Proton Drive is perfectly fine. Just thought you'd want to know. Have a nice day."

Quasy laughed. "Now THAT'S a notification I can trust."

He closed his laptop, leaned back in his chair, and thought about all the people in the world who were currently staring at fake "storage full" warnings, reaching for their credit cards, and preparing to hand their data to a stranger named Cloud+.

"Don't do it," he whispered to the universe. "Just check the app. The app never lies. Unlike the email. The email always lies."

And with that profound observation, Quasy_Complete went back to his breakfast. The cloud was fine. The scam was deleted. And the lasagna recipe lived another day.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 24 Jun 2026 17:31:59 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-36</guid><link>https://carlostkd.ch/roadmap/#post-36</link><title>Credential Stuffing: How One Reused Password Can Turn Your Small Business into a Hacker’s Personal Playground (Or, Why You Should Stop Using “Password123” for Everything)</title><description><![CDATA[Quasy_Complete was sitting in his office when his phone buzzed. It was a notification from his bank: “Suspicious login attempt detected from IP address 192.168.0.1 (Your Neighbor’s Wi-Fi).”

He sighed. “Again? Did Dave the cleaner forget to log out of my account on his tablet? Or did someone just guess my password because it’s still ‘FluffyBunny2019’?”

He opened his laptop and checked his email. Nothing suspicious. But then he noticed something odd: a new inbox rule forwarding all messages to an unknown address. “Oh,” Quasy muttered. “That’s not good. That’s definitely not me.”

He called Dave. Dave: “Hey, sorry! I tried to log into your Proton Mail on my phone, but I forgot my password, so I just used yours again. It worked!” Quasy: “You used MY password on YOUR phone? And you didn’t change it?” Dave: “Well, it’s convenient! Plus, I figured if someone hacks me, they’ll just get my cat photos. Not your business emails.” Quasy: “Exactly! That’s the problem! If someone cracks your cat photos, they can now access your business emails, your payroll system, and your entire client list. Because you reused the same password everywhere!”

This is credential stuffing. And it’s the reason why a breach at a random shopping site can suddenly give hackers access to your company’s finances.

What Is Credential Stuffing? (The Art of Copy-Pasting Passwords)

Credential stuffing happens when criminals take usernames and passwords exposed in one breach and automatically test them against many other services. They hope some people reused the same login elsewhere.

Hacker: “I stole 5 million passwords from a fashion website. Let me try them on Gmail, LinkedIn, PayPal, and… oh look, this one works on the local bakery’s accounting software! Sweet!”

For businesses, this means a breach you had nothing to do with can become your problem. If an employee reused a personal password for a work account, a consumer data leak turns into unauthorized access to email, SaaS tools, finance platforms, or admin panels.

Quasy’s Mental Image: Employee: “I use the same password for Netflix, Facebook, and our CRM. It’s easier to remember!” Hacker: “Thanks! Now I have everything. Including your boss’s private tweets.”

How Does It Work at Scale? (Automation Is the New Weapon)

Attackers don’t guess passwords manually. They use automated tools to test millions of credentials against hundreds of services. The process runs quickly, rotates IP addresses, and mimics normal login patterns to avoid detection.

Scenario: Hacker Bot: “Testing username ‘john@company.com’ with password ‘Summer2024!’ on Google, Microsoft, AWS, and Salesforce…” Google: “Access granted.” Hacker Bot: “Nice! Now let me set up a forwarding rule to send all invoices to my server.”

Within a business, it’s hard to spot these threats. The first sign might be a login from an unfamiliar location, a password reset request, or a new mailbox rule.

Quasy: “You know what’s funny? We spend thousands on firewalls, but we ignore the fact that our receptionist uses the same password for her Instagram and our Slack channel. That’s like locking the front door and leaving the window wide open with a sign that says ‘Come In, Please.’”

Why SMBs Are More Exposed (Because You Don’t Have a Security Team, You Have a Guy Named Dave)

SMBs are especially vulnerable because:

    Fewer resources: Employees create accounts without approval. Shared logins circulate via email. Password reuse goes unnoticed.
    No boundaries: Personal and work credentials mix. If a personal account gets breached, the work account follows.
    Targets: Even small businesses are targeted. French e-learning platform GDQuest had 66,000 records leaked in February 2026. It wasn’t big, but it was profitable enough for hackers.

Quasy imagined a typical SMB: Boss: “We need a new tool for project management!” Employee: “Sure, I’ll sign up with my personal email and reuse my password.” Three months later: The employee’s personal email gets hacked. Now the attacker has access to the company’s project board. Boss: “Wait, how did they get in?” Employee: “I think they guessed my password. It was ‘123456’.” Boss: “And you used that for our client database?” Employee: “Well, it was easy to remember!”

What a Credential Stuffing Attack Can Do (It’s Not Just Annoying, It’s Devastating)

Once attackers get valid credentials, the risk grows fast:

    Unauthorized access to SaaS tools: Client data, internal documents, invoices, customer lists.
    Email compromise: Reset passwords for other services, impersonate employees, monitor conversations.
    Admin panel access: Create new accounts, change settings, export data, escalate privileges.
    Lateral movement: Use one account to find others. Test the same password across systems.
    Ransomware risk: Escalate into extortion or operational disruption.

Quasy pictured a hacker moving through a company: Hacker: “Got access to the project manager. Now let me check the financials. Oh, look, the CFO’s password is the same as their Spotify account. Perfect. Now I’m rich.”

How to Prevent Credential Stuffing (Stop Reusing Passwords, Seriously)

Prevention starts by removing the weakness: password reuse.

    Choose Unique Passwords for Every Account: Use a business password manager like Proton Pass. It generates strong, unique passwords, stores them in encrypted vaults, and shares access securely. Quasy: “Instead of trying to remember ‘FluffyBunny2019’ for 50 sites, just let the app do it. Your brain can focus on more important things, like remembering where you put your keys.”

    Use Password Health Checks: Identify weak or reused passwords before attackers do. Proton Pass helps prioritize risks. Quasy: “It’s like a doctor visit for your passwords. Except instead of blood tests, it checks if you’re using ‘Password1’ for your bank account.”

    Turn on 2FA: Add a second layer. Even if a password is compromised, attackers need another factor. Quasy: “Yes, 2FA isn’t perfect. Attackers can still trick you into sharing codes. But it’s better than nothing. It’s like having a lock on your door, even if someone picks it.”

    Dark Web Monitoring: Detect if credentials appear in breach data. Proton Pass includes Pass Monitor. Quasy: “If your email shows up in a dark web forum, you know it’s time to change everything. It’s like getting a warning label on your food before you eat it.”

    Protect Your Proton Account with Proton Sentinel: Advanced protection for Proton accounts. Detects suspicious takeover attempts. Quasy: “This is like having a bouncer at your digital club. He checks IDs, stops intruders, and doesn’t let anyone in without a proper invite.”

    Build Prevention Into Daily Access Management: Make reuse unnecessary. Use Proton Pass for daily practices. Quasy: “Don’t ask employees to remember more. Give them a system that makes reuse impossible. It’s like giving kids a car seat instead of telling them to hold on tight.”

    Use Email Aliases: Hide your real email with unique aliases for each service. Quasy: “If a service leaks your alias, your real email stays safe. It’s like using a fake name on a dating app. If they’re creepy, you just delete the alias.”

What To Do If You Suspect Credential Stuffing (Panic, Then Act)

Identify affected accounts: unusual logins, new devices, password resets, forwarding rules. Then act immediately:

    Reset passwords.
    Check for reuse.
    Revoke sessions.
    Enable MFA.
    Review activity logs.
    Remove unauthorized users.
    Notify customers if needed.

After containment: Move accounts to a password manager, replace reused passwords, review shared accounts, and run health checks.

Quasy called Dave again. Quasy: “Okay, Dave. Here’s the plan. First, we change every password. Second, we enable 2FA on everything. Third, we stop using ‘FluffyBunny2019’ as a life philosophy.” Dave: “But that’s my favorite password!” Quasy: “It’s also your least secure. From now on, we use a password manager. No exceptions. If you want to keep using the same password, fine. But don’t come crying when your cat’s photos end up on the dark web.” Dave: “Fine. But can I still use ‘FluffyBunny2026’?” Quasy: “Only if it’s unique to one account. And only if it’s stored in the vault. Otherwise, I’m changing your access code to ‘Password123’ and locking you out forever.”

Conclusion: The Best Defense Is a Good System (Not a Good Memory)

Credential stuffing turns a simple habit—reusing passwords—into a massive security problem. A breach anywhere can become a breach everywhere.

Small businesses can’t afford to ignore this. But they don’t need enterprise bureaucracy either. They need a system that makes reuse unnecessary.

Quasy smiled. “So, next time you see a prompt to ‘Remember Me,’ remember this: Remembering passwords is hard. Managing them with a tool is easy. And staying safe? That’s priceless.”

He closed his laptop. His phone buzzed again. Notification: “New login from unknown device. Location: Unknown. Password: FluffyBunny2019.” Quasy laughed. “Ah, the sequel. Just like the first movie, but with more malware.”

He changed his password. Then he enabled 2FA. Then he told Dave to do the same. And if anyone else tried to use the same password? They’d get locked out. Just like a bad habit. Which, incidentally, is exactly what credential stuffing tries to break.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 22 Jun 2026 18:03:57 -0400</pubDate></item></channel></rss>