<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>CarlosTKD Roadmap</title><link>https://carlostkd.ch/roadmap/</link><description>Roadmap updates and news from CarlosTKD</description><language>en-us</language><lastBuildDate>Thu, 17 Sep 2026 09:57:44 GMT</lastBuildDate><atom:link href="https://carlostkd.ch/feed.php" rel="self" type="application/rss+xml"/><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-78</guid><link>https://carlostkd.ch/roadmap/#post-78</link><title>The Google Account Recovery Scam</title><description><![CDATA[One morning in August, a member of the Proton team answered a call from a California number.

Quasy_Complete heard about it over lunch, and his first reaction was to stare at the ceiling for a prolonged period of time. Not out of despair  out of professional admiration.

"Ah," he said. "They've done it again. They've weaponized the one thing every anti-phishing check relies on: authenticity. Real sender. Real branding. Real code. Real servers. And then a polite man from California calls you to explain what you're looking at. Do you understand how diabolical that is? The phishing email isn't the attack. The phishing email is the stage. The attack is the phone call."

Quasy at his office desk, coffee in hand, answering the mysterious California call while the smoky silhouette of the caller seeps out of the receiver.)

Mrs. Higgins appeared  because Mrs. Higgins always appears, usually when the topic involves telephones, which she considers the pinnacle of civilization.

"A call from Google? What's wrong with that? Google calls me all the time!"

"Google has never called you once in your life, Mrs. Higgins. Google does not know you exist as anything more than an advertising demographic. That's the first tell. But let me walk you through the con, because it's beautiful. Textbook. A masterpiece of social engineering. If it weren't evil, it would deserve a museum."

How This Google Account Recovery Scam Works (A Heist Movie, Explained Slowly)

The setup: Before the phone rings, the scammer creates a fresh, anonymous Gmail address — random letters and digits, no identity, no history. Then, using Google's perfectly legitimate "add a recovery email" flow, they try to add YOUR address as the recovery email for THEIR throwaway account.

The scammer in his basement den, script binder, burner phones, red-string victim board.)

Quasy: "Notice what just happened. The criminal used a legitimate Google feature. Exactly as designed. No hacking. No malware. No exploited vulnerability. Just a form. The most dangerous software exploit ever devised: a form, filled in politely."

The first real email: Google's system needs your confirmation, so an authentic message arrives asking you to verify the recovery email. Real sender. Real branding. Real code. Every phishing detector on Earth nods approvingly.

The call: The scammer calls, poses as Google's security team, describes a "suspicious account access attempt" that was supposedly blocked, even claiming to have intercepted your authenticator code. "Blocked" casts the caller as the hero  your protector. The cavalry. Meanwhile, the only attack taking place is the call itself.

Quasy: "He intercepts the situation you're not actually having, resolves the threat that doesn't exist, and positions himself as the guardian standing between you and chaos. It's a fireman arsonist. He sets nothing on fire  he just shows up with a hose and asks for your house keys to 'protect' them."

The second real email: Still on the line, a genuine "Security alert" arrives announcing that a recovery email was changed on a linked Google Account. Skimmed, it looks like YOU were compromised. Read carefully, the fine print reveals it's a copy of an alert sent to the scammer's address. The subject line addresses the scammer's inbox, not yours. "A copy of a security alert sent to..."  the biggest tell in the entire scam, and the easiest to miss when a friendly voice is narrating over your shoulder.

The vanishing act: The first email actually offers a legitimate escape  a "Remove email" button that ejects your address from the stranger's account. But the moment our colleague hung up, the scammer withdrew the recovery request, erasing the trail, and presumably dialed the next number on the list.

Quasy decisively hanging up while the caller's smoky silhouette dissolves and the email trail evaporates.)

The Tells, Annotated (Fine Print: The Unsung Hero of the Internet)

Quasy grabbed a marker and walked Mrs. Higgins through the annotated tells as though reviewing a crime scene:

    The genuine Google sender — real, which is precisely what makes it dangerous. The padlock on the sender is a padlock on a wolf costume.
    "Wants to use your email address as their recovery email" — reversed logic. This email is not about YOUR account. It's about a stranger's.
    The anonymous throwaway address — a string of random letters. No face. No history. No accountability. The digital equivalent of a man in a mask buying matches.
    The expiring code — manufactured urgency. Your heart rate is part of the attack surface.
    "Remove email" — the one button that actually stops the scam. And precisely the action the scammer cancels the moment you hang up, which is its own confession.
    The subject addresses the scammer's inbox, not yours — read the actual sentence. Whose account is this about?
    The alarming headline — designed to trigger panic before comprehension. Fear first, fine print never.
    "If you didn't change it, check what happened" — planted doubt, priming you to trust the caller instead of your own eyes.
    The "Check activity" button — a prompt to ACT FAST instead of READ SLOWLY.

 Quasy staring at the two "genuine" alerts with the magnifying glass on the fine print.)

Mrs. Higgins: "But both emails are REAL?"

"Both emails are REAL. That's the genius and the horror. Every anti-phishing lesson you've ever learned — check the sender, check the spelling, hover over links — passes with flying colors. The scam isn't a fake email. It's a real email placed in the wrong story. And the caller is the storyteller."

Why This Gmail Scam Is So Convincing

Both phishing emails come from Google's real servers, so every conventional check passes. Each element corroborates the others: real notifications plus a caller who knows exactly what just landed in your inbox. The conversation is engineered to discourage you from clicking "Remove email" and keep you anchored to the caller's script instead.

Quasy: "It's a confidence trick where the props are all real. The banknotes are genuine — the wallet is stolen. And a data breach makes it worse: even when passwords aren't leaked, exposed names and contact details let scammers personalize the call and sound credible. Trust built from scraps."

How to Protect Yourself From Account Takeover Attempts (The Anti-Con Checklist)

Quasy counted off on his fingers:

"Hang up and verify independently — end the call, check your account yourself, never through their instructions. Read Google security emails carefully — which account does the alert actually reference? Especially any line saying it's a copy of an alert sent to another address. Never share verification codes — Google will never ask you to read out an authenticator or recovery code over the phone. Use 'Remove email' if you don't recognize the account. Don't let anyone rush you — urgency is the attacker's oxygen. Review your Google Account security directly: recent activity, signed-in devices, recovery details. Report suspicious calls. And review your Google privacy settings, because reducing exposure never hurt anybody."

A genuine urgent request survives a two-minute verification call. A fake one can't survive ten seconds of fine print.

A Safer Inbox Starts With Better Email Security

Quasy: "Remember the rule for Proton: Proton will never call you about an account security issue. Ever. Nobody from Proton will ever ask for a code. Enable two-factor authentication — on paid plans, Proton Sentinel adds human security analysis on top of automated detection. Proton Mail also ships PhishGuard, which blocks and flags suspected phishing, plus link confirmation prompts before opening external links. And if someone does break in using email or SMS recovery, they won't automatically get your emails and contacts, thanks to separate data recovery protections."

He paused. "The real lesson of this scam isn't technical, Mrs. Higgins. It's theatrical. The email is the prop. The code is the prop. The friendly voice from Google is the performance. And the only thing standing between the scammer and your account is a person willing to say: 'Hold on. Let me check that myself.'"

Mrs. Higgins checked her phone. Then hung up on a call from "Google Support" she had been on for four minutes.

"That was nice of you," Quasy said. "Also, that was my phone ringing. Yours hasn't rung."

"...Oh."

His phone buzzed. Notification: "Google: A copy of a security alert sent to x7fk29qz@gmail.com..."

Quasy looked at it. Looked at the ceiling. Blocked the sender. Went back to his tea.

The scammer, somewhere in his den, updated his script. Script 13 would be warmer. Friendlier. More patient. Script 14 would sound even more like Google. And someone, somewhere, would read the fine print.

Or wouldn't.

The ceiling remains silent. But it would like you to know: neither will Google. Google doesn't call. Check yourself.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 07 Sep 2026 13:25:01 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-77</guid><link>https://carlostkd.ch/roadmap/#post-77</link><title>How a Midnight Air Filter Swap Melted a Datacenter</title><description><![CDATA[Quasy_Complete woke up at 1 AM to his phone buzzing. He reached over. The screen said: "Proton Mail is experiencing a service disruption."

He blinked. Rubbed his eyes. Read it again.

"Ah," he muttered into the darkness. "It's 1 AM. My email is down. And somewhere in Frankfurt, servers are cooking in a datacenter sauna like a digital version of a rotisserie chicken. Marinating slowly. At 51.9 degrees Celsius. While an engineer in pajamas makes life-or-death decisions about database replicas."

His neighbor, Mrs. Higgins, appeared at his door in a dressing gown, holding her phone like a sick relative.

"Quasy! My email is down! It's 1 AM! I was expecting an important message! The temperature in my inbox is... metaphorically... 51.9 degrees! What happened? Did Proton explode?"

"Mrs. Higgins," Quasy said calmly, "Proton didn't explode. But the Frankfurt datacenter came dangerously close to becoming the world's largest sous-vide machine. The cooling system failed. The temperature jumped from 21.8°C to 51.9°C in less than half an hour. Some probes reported 60°C. And the servers started dying. One. By. One. Like dominoes. But the dominoes were expensive. And irreplaceable. Because of the AI boom."

She sat down on his couch. "The AI boom did this?"

"The AI boom did this. I'll explain. But first, let me walk you through the timeline. Because this incident report is a masterpiece of modern crisis management. A tragedy in four acts. Starring: heat, luck, a failed air filter, and a datacenter operator who decided to do maintenance at midnight without telling anyone."

The Timeline (Night of the Living Servers)

Just after 11 PM on Wednesday, August 26, a cooling system failure occurred in the main room of the Frankfurt datacenter. At around 11:15 PM, temperature started rising from 21.8°C to 51.9°C in less than half an hour, with some probes reporting 60°C. Server and networking equipment started dying one by one.

Quasy explained: "Twenty-one point eight degrees. That's a nice, comfortable server temperature. Then thirty degrees. Then forty. Then fifty-two. Sixty in some spots. For context: your servers are happiest at 21°C. Your servers start panicking at 45°C. Your network cards shut themselves down at 105°C. And your servers DIE somewhere in between. This entire temperature journey happened in THIRTY MINUTES."

Mrs. Higgins: "Why so fast?"

"Because of the AI boom. Here's the physics lesson nobody asked for: modern servers have massively more powerful CPUs and GPUs, because everyone needs AI now. AI everywhere. AI in your toaster. AI in your email. AI in your fridge. And AI hardware runs HOT. Really hot. Which means server power density has skyrocketed. Which means the time between 'cooling failure' and 'everything melts' has collapsed from three to four hours... to twenty minutes."

He paused. "Let me repeat that, because it's important. A complete cooling failure used to give engineers three to four hours to react. Now it gives them twenty minutes. The AI boom didn't just create a hardware shortage. It created a temperature emergency. Our datacenters are now packed with hot-running chips, all generating heat, all waiting for one air filter to fail so they can cook."

Midnight: The Critical Redundancy Loss

The user-facing incident began at around midnight when both the primary AND backup network switch on a critical rack failed. That rack contained several primary database copies.

Quasy: "Redundancy means you have a backup for everything. One switch dies? The backup takes over. That's the whole point. But this rack had BOTH switches fail. Simultaneously. And the rack contained primary database copies. The digital crown jewels. And here's the fun part: primary database failovers are NOT automatic. They require human supervision."

Mrs. Higgins: "Why not make it automatic?!"

"Because of something called 'split brain.' It sounds like a horror movie. It's actually worse. If a primary database goes down and the replicas don't know it, the replicas might miss some updates and become de-synced. Now you have two databases, both thinking they're the boss, both with different versions of the truth, and reconciling them later is a nightmare. It's like having two copies of your wedding photo album where one remembers a different spouse. You can't just pick one. Somebody's memories are wrong. And in database terms, wrong memories mean lost emails. Or corrupted accounts. So Proton keeps a human in the loop. Which is great for safety. And terrible when the human is asleep at midnight and the building is on fire. Metaphorically. Almost literally."

The Decisions (Engineering at 1 AM, or Professional Trolley Problems)

At this point, Proton's on-call engineers needed to make consequential decisions under extreme pressure.

Quasy listed them:

Decision 1: Save the service, or save the hardware? "Do they prioritize bringing the service back online, or prioritize addressing the cooling problem and saving the hardware inside the datacenter? Most companies never face this question, because cooling systems are redundant. But this cooling failure was complete. Both redundant air compressors. Both replaced at the same time. At midnight. Without notice."

He continued: "And here's where it gets brutal: due to a server equipment shortage tied to the ongoing AI boom, a lot of this hardware — if lost — could NOT be replaced on short timelines. The world is currently consuming GPUs like a starving person at a buffet. Saving the hardware had to be a priority. Even at the cost of extending YOUR downtime."

Quasy illustrated: Engineer, 12:30 AM: "Option A: Restore service. Users get email back in 20 minutes." Engineer: "Option B: Save the servers. Users stay offline another hour. But we don't lose millions in equipment that takes nine months to replace." Engineer, staring at thermometer: "Sixty degrees... it's a rotisserie down there. We're out of time. Power off everything. Now." Users: "WHY IS MY EMAIL DOWN?!" Engineer: "Because your email lives on machines that are currently baking. And replacements are backordered until 2028. Because AI."

Decision 2: Failover to Frankfurt or Zurich? "Failover to replicas in the same building — faster, less disruptive, but possibly pointless if the building is still cooking. Or failover to Zurich — safer from the heat, but a bigger traffic change that could create new instability."

"They chose Frankfurt if a replica was still alive, Zurich if not. Reasonable. Logical. Given the cooling was restored by 00:45, they assumed Frankfurt recovery would be quick."

It was not.

Decision 3: Everything or just what's down? "Complete datacenter failure is actually EASY — there's a contingency, everything fails over automatically. But random servers dying one by one, unpredictably, while others survive? That's the nightmare scenario. The failover logic doesn't handle it gracefully. Partial failure is harder than total failure. Physics is cruel that way."

Mrs. Higgins: "So they made good decisions and it STILL went wrong?"

"They made GOOD decisions. Based on reasonable assumptions. And reality said 'no.' Reality said: 'Surprise! The network cards cooked themselves to 105°C and entered a special protection mode, and now they're DISABLED until someone physically cold-resets them.'"

The 105°C Surprise (Why Being Careful Backfired Beautifully)

During the incident, many network cards in Frankfurt reached 105°C — normal is 45°C. This triggers a temperature protection mode, disabling the card until a cold system reset. Proton's security posture limits access to the out-of-band controllers, so they had to wake up additional staff.

Quasy: "Here's the beautiful irony. Proton's security posture — the SAME posture that protects YOUR data — limits who can access the out-of-band management controllers. You know, the emergency doors. So when the network cards shut down and needed a cold reset via those controllers, the regular night crew COULDN'T DO IT. They had to wake up more people. At 1 AM. Because the security that protects you also slowed down the rescue."

He paused. "This is the fundamental dilemma of security. Every lock slows down the intruder. It also slows down you. The tighter the posture, the slower the recovery. It's not a mistake. It's a trade-off. And on August 27, that trade-off cost Proton some recovery time. You're welcome, by the way. The lock that slowed them down also stops attackers from waltzing into your email."

He continued: "By 01:30 CEST, most services were back for most users. Push notifications and payment processing took until 02:00. And here's the critical fact: no emails were lost. Delivery was delayed in both directions. Delayed. Not deleted. Your email didn't vanish into the heat. It waited. Patiently. Like an email should."

The Database Team's Longest Night (The Morning After the Heat Death)

User-facing services were restored, but the night wasn't over. The infrastructure was left in an abnormal state: some primary databases in Zurich, others in Frankfurt, several operating with reduced redundancy and performance. The database team worked through the night, and through the following day, restoring full redundancy.

Quasy: "Imagine the state of that infrastructure. Primaries scattered across two cities like mismatched socks. Some running on reduced redundancy. Some limping on reduced performance. It was the database equivalent of a hospital after a disaster — everyone alive, but nobody in the right bed. And the database team, bless them, spent the entire next day playing infrastructure Tetris to put everything back."

He paused. "Almost all infrastructure was saved. Some servers suffered heat death. Actual, literal heat death. Servers that met their maker via thermal threshold. And here's the sobering part: they don't know yet if the surviving equipment's lifespan was shortened. Heat stress on hardware is like sunburn on skin. It might be fine. It might age faster. Only time will tell."

Mrs. Higgins: "Heat death. Like the universe."

"Exactly like the universe. Except the universe gets trillions of years. Servers get twenty minutes of failed cooling."

Root Cause and Next Steps (The Maintenance Guy Who Came at Midnight)

The investigation traced the root cause: an air filter replacement on BOTH of the redundant air compressors powering the cooling system. The datacenter operator performed this operation in the middle of the night, without prior notice, AND failed to communicate the cooling failure when it happened.

Quasy stared at this paragraph for a long time. Then he read it aloud.

Quasy: "Let me get this straight. The datacenter operator. Replaced the air filters. On BOTH compressors. The redundant pair. At the same time. In the middle of the night. WITHOUT TELLING ANYONE. And then, when the cooling failed, they... didn't mention it. They let the servers cook in silence. The redundancy was defeated by a maintenance schedule that said 'let's service both cooling units simultaneously, at midnight, and not warn the tenant whose entire business runs inside this building.'"

Mrs. Higgins: "That's like servicing both brakes on your car... at the same time... while the owner is driving it."

"At MIDNIGHT. On a motorway. Without a phone call. And then, when the car started smoking, the mechanic just... watched. Silently."

He continued: "Proton is working closely with the operator to prevent a repeat. Translation: there have been Words. Possibly a strongly-worded email. Though ironically, the email might have been delayed, since email delivery was delayed during the incident. The universe has a sense of humor."

He listed the fixes in progress:

    Database resilience work is underway, planned for completion by end of year — addressing the exact failure mode this incident exposed.
    Additional infrastructure capacity, including new datacenter space, is being commissioned, arriving within weeks, reducing single-site dependency.
    They're reviewing where they can safely accelerate the remaining work — because critical database changes require care, and rushing a database migration is how you turn one outage into two.

Conclusion: Highly Improbable. Yet It Happened.

Quasy_Complete closed the incident report. Mrs. Higgins was still on his couch, clutching her phone, waiting for her important email to arrive.

"The series of events," Quasy said quietly, "leading to this incident were highly improbable. Redundant cooling serviced simultaneously at midnight. No warning. No communication of the failure. AI-driven power density turning a 3-4 hour buffer into 20 minutes. Network cards entering protection mode behind security-restricted controllers. Any ONE of those things alone: survivable. All of them together, in sequence, on the same night: the incident."

"But they fixed it. No emails lost. Everything restored by 2 AM."

"Everything restored by 2 AM. Followed by a full day of database Tetris. And a promise: more resilience, more datacenters, fewer single points of failure. They apologized. Unreservedly. To every user impacted."

He paused. "And here's what I find genuinely impressive, Mrs. Higgins. In an era where most companies publish incident reports that say 'we experienced brief instability' and nothing else, Proton published a document admitting: the datacenter operator botched it, our engineers faced impossible choices, we prioritized hardware over uptime and would do it again, some servers literally died of heat, and we don't know if the survivors are traumatized. That's not spin. That's an autopsy, in public."

His phone buzzed. Notification: "Proton Mail: All systems operational."

Quasy looked at the notification. Looked at Mrs. Higgins. Looked at the ceiling. The ceiling — currently at a comfortable 21.8°C, with functioning cooling and redundant air compressors — stared back silently. The ceiling, unlike the Frankfurt datacenter, had never lied to him. Mostly because it had never spoken.

"Your email should be there now," he said.

Mrs. Higgins checked her phone. "It arrived! The important message! It was just... delayed."

"Delayed. Not lost. Delayed. Like a flight. Or a bus. Or every roadmap announcement in tech history."

She smiled. "So the servers are okay?"

"Most of them. A few are gone. Heat death. RIP. They died serving your email, Mrs. Higgins. They died protecting a message about... what was the important email, anyway?"

She checked. "A coupon. For 20% off socks."

Quasy stared at her. Stared at the ceiling. Stared at the ceiling AGAIN, longer than usual, with the expression of a man questioning whether servers should have died for sock coupons.

"Twenty minutes," he whispered. "A cooling failure. A database dilemma. A midnight maintenance disaster. Heat death. Engineers sacrificing their night. All so a sock coupon could arrive... delayed by two hours."

Somewhere in Frankfurt, technicians replaced air filters. This time, with a schedule. With notice. With redundant compressors serviced one at a time, like civilized professionals.

Somewhere in Zurich, primary databases sat in their proper racks, fully redundant, running cool, telling no lies.

And somewhere in a dark server room, a surviving server hummed quietly, its lifespan possibly shortened, its workload unchanged, processing the evening's delayed mail queue: bill payments, flight confirmations, medical reminders...

And one sock coupon.

Twenty percent off.

Highly improbable.

Yet it happened.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Thu, 03 Sep 2026 04:26:47 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-76</guid><link>https://carlostkd.ch/roadmap/#post-76</link><title>How You Just Gave a Silicon Valley AI the Keys to Your Entire Life</title><description><![CDATA[Quasy_Complete was sitting at his Mac, staring at a dialog box that said: "Allow ChatGPT to access your Messages? This will allow it to read, search, and send texts on your behalf."

Below the text was a checkbox labeled: "Trust me, I'm an AI."

He hovered his mouse over the "Allow" button. Then he stopped. Then he looked at the ceiling. The ceiling, as always, offered no legal advice, no ethical guidance, and no reassurance that OpenAI wouldn't accidentally leak his entire conversation history to the Pentagon.

"Ah," he muttered. "The siren song of convenience. 'Just let me read your messages so I can summarize them for you! Just let me draft replies so you don't have to type! Just let me search your history so I can find that date you forgot!' And in exchange? You give up the one thing that made iMessage special: the fact that nobody could read your messages. Not Apple. Not hackers. Not governments. Now? You're inviting a third party into the room. A third party that is legally obligated to hand your secrets to the US government if they ask nicely."

His neighbor, Mrs. Higgins, appeared at the door holding her MacBook like it was a radioactive artifact.

"Quasy! I just installed the ChatGPT plugin for iMessage! It's amazing! It found my dentist appointment from three years ago! It drafted a reply to my boss! It even told me what I had for lunch last Tuesday! But then I read something scary. It said ChatGPT might store my messages? And train its models on them? And the US government can read them?"

"Mrs. Higgins," Quasy said calmly, "you didn't just install a plugin. You installed a backdoor. A very polite, very helpful, very American backdoor. You took the most secure messaging system on earth—iMessage, with end-to-end encryption—and you invited a guest who doesn't respect the lock. You gave ChatGPT permission to read your private conversations. And now, those conversations are no longer private. They are data. They are training material. They are evidence."

She sat down heavily. "But it's so convenient!"

"Convenience is the bait. Privacy is the price. And the price is your entire digital life."

How the Integration Works (The Trojan Horse)

The Apple Messages plugin lets ChatGPT search conversations, find info, suggest replies, and send texts. It runs locally on Mac. OpenAI says it doesn't create a complete index. It only reads in response to a request. It stores content locally by default.

Quasy explained: "Sounds safe, right? 'Runs locally.' 'Only reads when asked.' 'Stores locally.' But here's the catch: once you authorize it, the content leaves the encrypted bubble. It enters the AI pipeline. It becomes a ChatGPT conversation. And ChatGPT conversations are subject to ChatGPT's privacy policy. Which means they can be used for training. Stored indefinitely. Handed over to the US government."

He illustrated: User: "ChatGPT, what did I say about the merger?" ChatGPT: "You said it's confidential. But I just read it. And now I've stored it. And now I've trained my model on it. And now the US government can subpoena it. And now your competitor knows about the merger. All because you asked a nice question."

Your iMessages Can Be Processed Like Any Other ChatGPT Conversation (The End of E2EE)

iMessage uses end-to-end encryption. Only sender and recipient can read. But the plugin changes this. If you authorize ChatGPT to scan, the content enters the AI pipeline.

Quasy: "This means your iMessages can:

    Train OpenAI's models. Default is ON for Free, Go, Plus, Pro accounts. Once used for training, it's gone. Forever. You can't undo it.
    Be stored on OpenAI's servers. Indefinitely. Unless you delete them. And even then, it takes 30 days. And they can keep it forever for 'legal reasons.'
    Land in the hands of the US government. Without a warrant. Under FISA Section 702. Or National Security Letters. With gag orders. So OpenAI can't even tell you they got a subpoena.
    Affect people who don't use ChatGPT. Your friend sends you a secret. You use the plugin. Their secret is now in OpenAI's database. Their privacy is compromised. Because of you."

Mrs. Higgins: "So my friend's secret is gone?"

"Your friend's secret is now a training example for a robot that works for a company that signed a deal with the Pentagon. And that robot might tell the Pentagon. Or a competitor. Or a hacker who breaches the server. Or a journalist who leaks the data. The encryption is broken. Not technically. But functionally. You opened the door."

It Could Create an Encryption Backdoor (The Loophole)

From a privacy perspective, this looks like a backdoor created without breaking E2EE. Paul Walsh pointed this out. The concern is relevant given OpenAI's agreement with the Pentagon.

Quasy: "Governments have tried to force Apple to break encryption. The UK demanded access to iCloud data. Apple withdrew Advanced Data Protection for UK users rather than create a backdoor. The FBI wanted Apple to unlock an iPhone in 2016. Apple refused, warning it would create a reusable backdoor. But now? You're creating the backdoor yourself. Voluntarily. By installing a plugin."

He continued: "You're saying, 'Apple, please keep my messages safe. But also, ChatGPT, please read them.' And ChatGPT says, 'Sure! And we'll store them! And we'll train on them! And we'll give them to the government if they ask!' And Apple says, 'Well, technically, the messages were encrypted until you gave them to ChatGPT. So we're good.'"

Full Disk Access Introduces Mac Security Risks (The Master Key)

Setting up the plugin requires granting ChatGPT Full Disk Access. This is a system-wide permission. It covers Mail, Safari history, local backups, admin rights.

Quasy: "You're not just giving ChatGPT access to Messages. You're giving it access to everything. Your emails. Your browsing history. Your local backups. Your admin rights. There's no technical safeguard preventing OpenAI from reading your emails or accessing your Safari history. You have to trust them. And trust that a future update won't quietly use that access for more than Messages."

He paused. "A bug. A compromised account. A malicious instruction. A configuration mistake. Any of these could expose your entire digital life. And for businesses? The stakes are higher. Client info. Legal discussions. Passwords. Unreleased plans. All accessible to an AI tool that might not know the difference between a secret and a joke."

Should You Connect ChatGPT to Apple Messages? (The Answer is No)

The safest approach is not to enable the plugin, especially for confidential info.

Quasy listed the risks:

    Persistent approval: Removes your last chance to catch a mistake.
    Saving to cloud: Stores your data on OpenAI's servers.
    Full Disk Access: Grants broad permissions.
    Model training: Uses your data to train the model.
    US Jurisdiction: Subject to FISA, NSLs, and government subpoenas.

He suggested mitigations if you must use it:

    Keep persistent approval off. Review every message.
    Don't save plugin conversations to the cloud.
    Revoke Full Disk Access when not using.
    Turn off "Improve the model."
    Enable FileVault.
    Ask contacts for permission.

"But honestly," Quasy said, "why risk it? Why give a US company access to your private life when you have a better option?"

Switch to a Private AI Assistant (The Swiss Alternative)

You don't have to give an AI broad access to get help. With Lumo, you get convenience without the privacy trade-off. Lumo never logs, trains on, or shares conversations. Zero-access encryption. Swiss privacy laws. Outside US jurisdiction.

Quasy: "Lumo is a private AI assistant. It helps you draft, summarize, analyze. But it never logs your chats. Never trains on them. Never shares them. It's encrypted. It's Swiss. It's not subject to US law. It's not subject to FISA. It's not subject to National Security Letters. It's just... yours."

He contrasted: "ChatGPT: 'Read your messages! Train on them! Give them to the government!' Lumo: 'Read your messages? No. Train on them? No. Give them to anyone? No. Just help you write. And keep it private.'"

Conclusion: The Lock Is Only as Strong as the Person Holding the Key

Quasy_Complete closed the dialog box. He clicked "Deny."

"Better safe than sorry," he whispered. "Better to type the reply myself than to let a robot read my secrets."

His phone buzzed. Notification: "ChatGPT: Would you like to enable the iMessage plugin? It's free! It's convenient! It's... dangerous."

Quasy ignored it. Opened Lumo. Asked for a summary of his notes.

Lumo summarized. Encrypted. Private. No training. No storage. No government access.

"Safe," he whispered. "Not because of a plugin. Because of a choice. A choice to keep your data yours."

He looked at Mrs. Higgins. She was uninstalling the plugin.

"Uninstalling?" she asked.

"Uninstalling. Revoking access. Deleting the data. Starting over. With privacy."

"Will it be hard?"

"No. It's just a click. But it's the most important click you'll make all year. Because in 2026, the most valuable thing you have isn't your money. It's your privacy. And privacy is only as strong as the locks you keep on your doors. And you just unlocked yours."

Somewhere in Mountain View, a server hummed. Inside it, millions of messages were being scanned. Stored. Trained. Subpoenaed.

And in Switzerland, a server hummed. Inside it, millions of messages were being encrypted. Protected. Private. Yours.

Because in 2026, the choice is yours. To give your secrets to a robot. Or to keep them. For yourself.

And the ceiling? The ceiling is still silent. But at least it's not listening.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Fri, 28 Aug 2026 13:13:18 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-75</guid><link>https://carlostkd.ch/roadmap/#post-75</link><title>How to Stop Your Inbox From Becoming a Digital Hoarding Ground</title><description><![CDATA[Quasy_Complete was staring at his inbox. It was a sea of unread messages. Three thousand, four hundred, and twelve of them. The top one was a coupon for "50% Off Socks." The second was a LinkedIn notification that "Someone you don't know endorses you for 'Patience'." The third was a flight confirmation. The fourth was a newsletter about "10 Ways to Declutter Your Life."

"Ah," Quasy muttered. "The irony is palpable. A newsletter about decluttering, buried under three thousand items of clutter. My inbox is a monument to my own indecision. A digital hoarding ground where coupons go to die and flight confirmations go to be forgotten."

His neighbor, Mrs. Higgins, appeared at the door holding her phone with both hands, looking like she was about to defuse a bomb.

"Quasy! My inbox is full! I can't find the bill for the electric company! It's buried under a mountain of 'Flash Sales' and 'You've Been Selected!' and 'Your Friend Sarah Just Posted a Photo of a Cat'! I'm drowning! I need a life raft!"

"Mrs. Higgins," Quasy said calmly, "you don't need a life raft. You need a分类 system. A way to sort the noise from the signal. A way to make your inbox work for you, instead of you working for your inbox. And luckily, Proton Mail just introduced Categories. It's like having a digital butler who sorts your mail before you even wake up. But unlike Gmail, this butler doesn't read your letters to sell them to advertisers."

She sat down heavily. "A butler? Does he wear a monocle?"

"He wears encryption. And he doesn't sell your data. That's the important part. Let me explain."

What Are Categories in Proton Mail? (The Digital Sorting Hat)

Categories are a new view in your inbox designed to give you better visibility of which messages need attention. Every incoming email lands in one of these buckets:

    Primary: Personal, work, important updates.
    Social: Facebook, LinkedIn, Twitter notifications.
    Promotions: Deals, discounts, sales.
    Newsletters: Content you signed up for.
    Transactions: Bookings, bills, orders.
    Updates: Automated alerts.

Quasy explained: "Imagine your inbox is a chaotic party. Everyone is shouting at once. The 'Promotions' people are yelling about socks. The 'Social' people are showing you cat photos. The 'Primary' people are trying to tell you your boss needs a report. Without categories, everyone is in the same room, screaming. With categories, you put the sock people in the basement. The cat people in the garden. And the boss in the study. Suddenly, you can hear yourself think."

Mrs. Higgins: "So it sorts them automatically?"

"Yes. Automatically. Before clutter gets a chance to take over. For new users, it's on by default. For existing users, it asks if you want to turn it on. And if an email lands in the wrong bucket? You just move it. The system learns. Next time, it puts it in the right bucket. It's like training a dog. Except the dog is an algorithm, and the treat is a clean inbox."

Stay Organized, Without the Surveillance (The Privacy Difference)

Big Tech providers like Gmail and Outlook also have categories. But there's a privacy cost. Their goal isn't security; it's monetization. They scan your emails to serve ads. Google displays ads in your inbox. Turning your Promotions tab into a billboard. Even if you pay for Google One, the business model doesn't change. Google is an advertising surveillance machine.

Quasy: "Think about it. Gmail gives you free storage. In exchange for what? Your data. They read your emails. They build a profile. They sell that profile to advertisers. They show you ads for shoes because you bought shoes. Or because you talked about shoes. Or because you dreamed about shoes. They know everything. And they use that knowledge to make money off you."

He contrasted: "Gmail: 'Here's a free inbox! (But we're reading your emails to sell ads.)' Proton: 'Here's a free inbox! (And we can't read your emails because they're encrypted. We're funded by you, not advertisers.)'

"Proton's business model aligns with yours. We're 100% funded by the community. Enabling Categories doesn't change that. Your inbox remains protected by zero-access encryption. Emails you send with other Proton users are end-to-end encrypted. The butler doesn't read your letters. He just sorts them."

Mrs. Higgins: "So Google is a spy?"

"Google is a business. A business that sells ads. And to sell ads, it needs to know what you want. To know what you want, it reads your emails. It's a surveillance machine disguised as a helpful assistant. Proton is a utility. A utility that protects your data. It's the difference between a hotel that gives you free breakfast and a hotel that installs cameras in your room to sell your viewing habits to a marketing firm."

See What a Clean Inbox Feels Like (The Joy of Order)

Ready to use Categories? Go to your inbox. Open the tabs. Move emails if needed. Customize in Settings → Messages and composing. Toggle notifications. Show unread counts. Disable anytime.

Quasy: "It's that simple. You get a clean inbox. You see your important emails first. The noise is pushed aside. The promotions are in the basement. The social updates are in the garden. And the boss is in the study. Waiting. Patiently. For you to read the report."

He illustrated: Before: Inbox: "50% Off Socks! 🎉" | "Your Friend Liked Your Post" | "Flight Confirmed" | "Newsletter: 10 Tips" | "Bill Due" | "New Job Opportunity" Result: Panic. Missed bill. Late fee. Stress.

After: Primary: "New Job Opportunity" | "Bill Due" Social: "Your Friend Liked Your Post" Promotions: "50% Off Socks! 🎉" Newsletters: "Newsletter: 10 Tips" Transactions: "Flight Confirmed" Result: Calm. Bill paid. Job applied for. Socks ignored (for now).

"See the difference? One is chaos. The other is order. One is stress. The other is peace. And the best part? The peace is encrypted. No one is watching. No one is selling. No one is tracking."

Conclusion: Your Inbox, Your Rules (Not Google's)

Quasy_Complete closed his laptop. Mrs. Higgins was smiling. Her phone showed a clean inbox. Tabs for Primary, Social, Promotions. No ads. No clutter. Just the essentials.

"So," she said. "I can finally find my electric bill?"

"You can. And you won't have to scroll past three hundred sock coupons to do it. And no one is reading your bill to sell you a vacuum cleaner."

"Is it hard to set up?"

"No. It's automatic. You turn it on. It sorts. You move one email if it's wrong. It learns. Done. And if you hate it? Turn it off. It's your inbox. Your rules. Not Google's. Not Microsoft's. Yours."

His phone buzzed. Notification: "Proton Mail: Your Categories are active. Primary: 2 emails. Promotions: 45 emails. Social: 12 emails."

Quasy smiled. "Two emails. Two important emails. Forty-five socks. Twelve cat photos. And zero ads. Zero surveillance. Zero data mining. Just... order."

He opened the Primary tab. Read the two emails. One was from his boss. One was from his bank. Both important. Both found instantly.

"Safe," he whispered. "Not because of a filter. Because of a system. Because of a company that doesn't want to read your mail. Because of a feature that respects your time."

He looked at Mrs. Higgins. "So, how's the sock situation?"

"I moved the sock email to Promotions. It's gone. From my view. But it's still there. If I want it. But I don't. Not today. Today, I need to pay my bill."

"Good. And tomorrow? If you want socks? You check the Promotions tab. But today? Today is for bills. And jobs. And life. Not socks."

Somewhere in Mountain View, a server hummed. Inside it, a million inboxes were being scanned. Ads were being served. Profiles were being built. Data was being sold.

And in Switzerland, a server hummed. Inside it, a million inboxes were being sorted. Privately. Encrypted. Securely.

Without ads. Without spying. Without selling.

Just a clean inbox. And the peace of mind that comes from knowing your data is yours.

And your socks are in the basement.

Where they belong.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Fri, 21 Aug 2026 17:57:22 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-74</guid><link>https://carlostkd.ch/roadmap/#post-74</link><title>Why Your Brain Is Wired to Hand Over the Keys to a Stranger Who Smiles</title><description><![CDATA[Quasy_Complete was sitting in a training room, staring at a PowerPoint slide that said: "BE MORE SUSPICIOUS."

Below the text was a clip-art image of a detective with a magnifying glass. The detective looked hopeful. Quasy looked tired.

"Ah," he muttered. "The most dangerous sentence in cybersecurity. 'Be more suspicious.' As if suspicion is a muscle you can flex on command. As if your brain doesn't have six built-in shortcuts designed to make you comply with requests from authority figures, people who are nice to you, and situations that feel urgent. And as if a slide deck can override 200,000 years of evolutionary programming that says 'Help the tribe' and 'Obey the leader'."

His neighbor, Mrs. Higgins, appeared at the door holding a USB drive shaped like a strawberry.

"Quasy! I found this on the floor! It says 'Q3 Salary Review'! It's labeled for me! Should I plug it in? It looks so official! And it's a strawberry! I love strawberries!"

"Mrs. Higgins," Quasy said calmly, "put the strawberry down. Immediately. That is a baiting attack. The attacker knows you love strawberries. Or they know everyone loves curiosity. They dropped a USB drive with a juicy title. They are counting on your curiosity doing the persuading. Because curiosity is a lever. And you are the lever."

She put the USB down. Looked at it. Looked at Quasy. Looked at the ceiling.

"Curiosity killed the cat," she whispered.

"And satisfaction brought it back. But in cybersecurity, curiosity kills the company. And satisfaction brings the ransomware."

Why Social Engineering Works: Six Levers, One Blind Spot

Social engineering doesn't succeed because employees are careless. It succeeds because it borrows shortcuts the human brain uses every day. Robert Cialdini identified seven persuasion shortcuts; six describe almost every attack: Reciprocity, Scarcity, Authority, Consistency, Social Proof, and Unity.

Quasy listed the levers:

1. Authority: "Scammers rely on authority. People comply faster with a request from someone senior, IT, or a regulator. Often without checking if the authority is real. Because we are trained to obey. From kindergarten. 'Raise your hand.' 'Listen to the teacher.' 'Do what the principal says.' That training doesn't turn off when you log into Outlook."

He illustrated: Attacker: "This is Richard, the CEO. I need you to reset your password now." Employee: "Oh! The CEO! I must obey!" Reality: Greg. In a basement. Wearing a hoodie. Impersonating Richard. But the feeling of authority is real. And the feeling overrides the logic.

2. Urgency: "Urgency compounds it. A deadline. A locked account. A payment before the bank closes. Pushes people toward action and away from verification. Because pausing feels like it might cause the problem. 'If I wait, the deal falls through!' 'If I check, the system crashes!' 'If I call, I look incompetent!' The urgency is a trap. It's designed to make you skip the step that saves you."

3. Scarcity: "Scarcity works in a different costume. A limited-time offer. A one-time access window. 'Hurry, this link expires in 5 minutes!' Hesitation means missing out. And missing out is painful. So you click. You comply. You act. Before you think."

4. Social Proof: "Persuades you that a request is legitimate because others have gone along. 'The rest of finance already approved this.' A thread that looks like a real internal conversation. 'Everyone else is doing it.' So you do it too. Because if everyone else is doing it, it must be safe. Right? Wrong. Everyone else might be Greg."

5. Reciprocity: "The quietest lever. A small favor. A piece of useful info. A compliment. 'You're doing great work!' 'Here's a tip!' Creates a mild, unconscious sense of obligation to return the gesture. 'They were nice to me, so I should help them.' Even if they are asking for your password."

6. Unity: "Exploits rapport. An attacker who is friendly, complimentary, seemingly familiar with office culture lowers your guard. 'I love your presentation!' 'Great job on the Q3 report!' Suddenly, you're not dealing with a stranger. You're dealing with a colleague. A friend. A person who gets you. And you trust friends."

Quasy paused. "None of these are sophisticated. They are the same instincts that make ordinary workplace cooperation possible. Any request deploying one of these looks like a normal, slightly urgent request. The kind you are trained your entire career to respond to quickly and helpfully. And that is exactly why they work."

The Attacks Employees Actually Encounter (The Menu of Manipulation)

Most organizations focus on anti-phishing. But social engineering training that stops at email misses the rest.

Quasy listed the attacks:

Vishing (Voice Phishing): "Fake phone calls. Voice notes. A caller posing as IT support asking for a password. A bank verifying a transaction. A courier needing a code. A voice adds urgency and authority text can't fake. And increasingly, voice-cloning tools imitate a real colleague or executive. The NCSC has flagged this as a growing risk. Your CEO's voice. Your boss's voice. Your mom's voice. All faked. All convincing. All designed to make you act."

Pretexting: "Creating a story to justify an unusual request. A new supplier needing account details. An auditor requesting logs. A job candidate asking HR for personal details. The scenario is built from public info. Job titles. Supplier names. Stitched together to sound plausible. 'I'm from the audit team. We need the logs for the Q3 review.' Plausible. Logical. And completely fake."

Baiting: "Offering something you want. A free resource. A branded USB drive. A document titled 'Q3 Salary Review.' In exchange for an action that compromises a device. It doesn't ask for trust. It relies on curiosity. 'What's inside?' 'Is it really my salary review?' 'I'll just plug it in to check.' And then the malware runs. And the data is gone."

Tailgating: "Following an employee through a badge-controlled door. Carrying boxes. Wearing a uniform. Timing the approach for a moment when holding the door is polite. Exploits workplace courtesy directly. 'Oh, thanks for holding the door!' 'No problem, I'm just delivering these boxes.' And now the attacker is inside. Walking past security. Walking past the server room. Walking to your desk. Because you were polite."

He paused. "Physical security training gets overlooked because it's not about screens. It's about people. And people are polite. And politeness is a vulnerability."

What Resistance Actually Looks Like (Not Suspicion. Habits.)

Simply telling employees to "be more suspicious" doesn't hold up. Suspicion is a feeling. Attackers override feelings. Training needs to replace vague instructions with specific, repeatable behaviors.

Quasy listed the habits:

1. Always Verify: "Verification through a separate channel is the single most useful habit. If a request arrives by email, confirm by phone or in person. Using a number or contact already on file. NOT one supplied in the message. This defeats impersonation regardless of how convincing the initial contact was. Because it removes the attacker's control over the verification step."

2. Slow Down: "Urgency is a signal to SLOW DOWN. Not a reason to skip a step. Notice when a request pushes you toward speed over process. A genuinely urgent request can survive a two-minute verification call. One that can't survive that delay should be treated with suspicion. Regardless of who it appears to come from."

3. Get Confirmation: "Financial and credential requests require a second person's confirmation. Standard practice. Not an exception. Removes the social pressure an attacker relies on when isolating a single employee. Gives that employee a blame-free way to say 'Let me check with someone' without appearing unhelpful."

4. Report Near-Misses: "An employee who complied with part of a request, hesitated but gave in, or realized something felt wrong should report it. Even after the fact. Even if nothing went wrong. These reports are the earliest warning. And they only surface in a culture where reporting doesn't carry embarrassment."

He emphasized: "Action Fraud exists because the earlier an incident is reported, the more useful it is. Don't hide the mistake. Report it. Learn from it. Stop the next one."

Why Slides Don't Build Resistance, and Simulation Does

Reading about levers is useful for context. But it doesn't change behavior under pressure. Resistance is a practiced skill. Not a fact from a slide deck.

Quasy: "Effective simulation puts employees through a realistic version of the pressure. A simulated vendor call. A fabricated urgent request. A staged visitor asking to be let through a secure door. Then gives immediate, specific feedback. Not a pass/fail score. A debrief that explains the mechanism used. Which lever was pulled? How did it feel? What would you do differently?"

He continued: "Difficulty increases gradually. Scenarios reflect real roles. Finance faces different pretexts than the front desk. Done well, simulation turns the six psychological levers into recognizable concepts. Concepts employees can name. And recognize. And resist."

Training People, Not Just Policies

Social engineering succeeds by aiming at instincts that make teamwork possible: trust in authority, responsiveness to urgency, discomfort of questioning seniors. Training that only defines attacks leaves employees exposed.

Quasy: "A curriculum that names the six levers, walks through how vishing, pretexting, baiting, and tailgating show up, and gives concrete, rehearsed behaviors gives people something they can use under pressure. Reinforced through simulation. Backed by unique passwords and MFA. That combination turns awareness into resistance."

He paused. "A team that can name a persuasion tactic while it's being used on them is a fundamentally harder target than one told to 'stay alert.' That's the gap you can close."

The Credential Connection: Why Containment Still Matters

Training reduces success, but can't reduce it to zero. Someone will hand over a password. Click a link. Confirm a detail. What limits damage is access controls.

Quasy: "A credential taken through social engineering is far less useful if it's unique to a single service and protected by MFA. Unique passwords prevent reuse. MFA prevents the stolen password alone from providing access. This is containment logic. A business password manager like Proton Pass for Business makes this realistic at scale. When credentials are stored in a vault, a single successful attempt stops being a route into every system."

Conclusion: Name the Lever. Pause. Verify.

Quasy_Complete looked at Mrs. Higgins. She was staring at the strawberry USB drive.

"So," she said slowly. "Curiosity is a lever. Authority is a lever. Urgency is a lever. And I need to name them. And pause. And verify."

"Exactly. Name the lever. 'This is Authority.' 'This is Urgency.' 'This is Reciprocity.' Naming it breaks the spell. It moves the request from your gut to your brain. And then you pause. And then you verify. Using a number you trust. Not a number Greg gave you."

His phone buzzed. Call from "Richard Thompson, CEO": "Quasy! I need you to approve a payment immediately! It's urgent! The deal closes in ten minutes! Don't tell anyone! Just do it!"

Quasy listened. Felt the urge to comply. Felt the pressure of urgency. Felt the weight of authority.

He took a breath. Named the lever. "Authority. Urgency. Reciprocity."

He paused.

He hung up.

He picked up the phone. Dialed Richard's office. The REAL number. From the directory.

"Richard? Did you just call me asking for a payment?"

"Quasy? No. I'm in a meeting. Why?"

"Because someone just called me, sounding exactly like you, asking for a payment, using urgency, authority, and secrecy."

"Ah. Social engineering. Good catch. Did you verify?"

"I did. And I named the lever. Authority. Urgency. Reciprocity. And I slowed down."

"Excellent. That's exactly what we train for. And that's exactly why we simulate. Because in the moment, it feels real. But the moment you name it, it loses power."

Quasy hung up. Looked at Mrs. Higgins. Looked at the ceiling.

"Greg," he said. "Still in the basement. Still wearing sweatpants. Still trying to pull levers. But we named them. And we paused. And we verified."

He opened Proton Pass. Checked his passwords. Unique. Strong. Encrypted. 2FA on.

"Safe," he whispered. "Not because I'm smarter. Because I have habits. And I have a team that names the levers. And pauses. And verifies."

Somewhere in a basement, Greg hung up. Frowned. Tried another target. Another lever. Another urgency.

But the target named the lever. Paused. Verified. And said no.

Because in 2026, the most powerful defense isn't a firewall.

It's a pause. A name. And a phone call to a number you already have.

And the courage to say:

"I'll call you back, Richard."

Especially when it sounds exactly like Richard.

ESPECIALLY then.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Fri, 21 Aug 2026 17:53:50 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-73</guid><link>https://carlostkd.ch/roadmap/#post-73</link><title>How to Protect Your Organization From CEO Fraud</title><description><![CDATA[Quasy_Complete was sitting at his desk, staring at an email.

From: Richard Thompson, CEO Subject: Urgent — Confidential Acquisition Payment Body: Hi — I'm currently traveling and difficult to reach by phone. I need you to process a wire transfer of $185,000 to the attached account details today. This is strictly confidential. Do not discuss with anyone. The acquisition window closes at 4 PM. — Richard

Quasy read the email twice. Then he read it a third time. Then he stared at the ceiling.

The ceiling offered nothing. As usual.

"Ah," he muttered. "This is either the most important email of my career or the most expensive mistake of my life. And the difference between the two is one phone call."

His neighbor, Mrs. Higgins, appeared at the door holding a printed email and a look of growing panic.

"Quasy! I got an email from the CEO! He says he's traveling! He needs me to change the supplier's bank details before the invoice is due! He says it's confidential! He says it's urgent! He says not to discuss it with anyone!"

"Mrs. Higgins," Quasy said calmly, "your CEO is either genuinely traveling and needs a bank detail change, or a man named Greg is sitting in a basement somewhere eating Cheetos and wearing sweatpants while impersonating your CEO using information he found on LinkedIn. And I'm going to bet on Greg."

She sat down heavily. "Greg?"

"Greg. Or Ivan. Or Marcus. The name doesn't matter. What matters is that this email is a Business Email Compromise attack. BEC. And it's not phishing. It's not a suspicious link. It's not a fake attachment. It's a well-researched email asking you to do something that fits plausibly inside a normal working day. And it's designed to move six figures out of your company before anyone notices."

What Is Business Email Compromise? (The Con That Doesn't Need a Hook)

BEC is a targeted attack where a criminal impersonates someone the target trusts — a senior executive, a supplier, or an internal colleague — and requests a wire transfer, a change to payment details, or sensitive credentials. No malware. No malicious link. Just a well-crafted email.

Quasy explained: "Phishing is a shotgun. BEC is a sniper rifle. Phishing sends a million emails hoping someone clicks. BEC sends one email hoping someone pays. Phishing needs you to click. BEC needs you to comply. And compliance is much easier to obtain than a click. Because compliance is what employees do. It's their JOB."

He continued: "The largest incidents can move six figures in a single transfer. And by the time anyone notices, the money has usually already left the country. It's in Latvia. Or Cyprus. Or a cryptocurrency wallet that doesn't have a country. It's gone. Like a ghost. A very expensive ghost."

Mrs. Higgins: "But the email LOOKS real!"

"That's because it IS real. Real in the sense that it exists. Real in the sense that the sender name matches. Real in the sense that the signature matches. Real in the sense that the project mentioned is genuine. But the question isn't whether the email looks real. The question is whether the PERSON behind it is real. And there are more ways to fake a person than you think."

How the Sender Gets Faked (Five Ways to Be Someone You're Not)

Quasy listed the impersonation methods:

    Lookalike Domains: The attacker registers a domain almost identical to the real one. One letter swapped. A hyphen added. "company.com" becomes "compamy.com." Or "company-uk.com." Counting on nobody reading the address closely.

Quasy: "Your CEO's email is richard@thompsoncorp.com. The attacker registers richard@thompsomcorp.com. One letter different. 'N' becomes 'M.' The font on mobile makes them look identical. You glance at the sender name. You see 'Richard Thompson.' You trust it. You pay. And the money goes to Greg."

    Display Name Spoofing: The "From" display name is set to match the trusted person — "John Smith" — while the actual address is something unrelated. Many mobile email clients show only the display name by default.

Quasy: "On your phone, the email shows 'Richard Thompson, CEO.' You see the name. You trust the name. You don't see the actual email address. Which is greg_from_basement_99@gmail.com. Because your phone hides it. Because phones are designed for convenience, not scrutiny. And convenience is Greg's best friend."

    Header Spoofing: SMTP, the protocol that moves email, doesn't verify the "From" header on its own. An attacker can send a message that claims to come from the real address without ever controlling it.

Quasy: "The email says it's from richard@thompsoncorp.com. It ISN'T. But the protocol that delivers email doesn't check. It's like mailing a letter with someone else's return address. The postal service doesn't verify who wrote it. They just deliver it. And you trust the return address. Because you trust the mail."

    Reply-To Manipulation: The visible "From" address looks legitimate, but a different Reply-To address is set behind it. The moment the target hits Reply, the conversation routes to the attacker.

Quasy: "The email says it's from Richard. You hit Reply. Your reply goes to greg_legit_business_definitely_not_a_scam@protonmail.com. And Greg responds. In Richard's voice. Using Richard's tone. Referencing Richard's projects. Because Greg did his homework."

    Account Compromise: The attacker gains access to a genuine email account and sends the request from inside it.

Quasy: "This is the hardest to catch. Because there's genuinely nothing technically wrong with the email. It came from the real address. On the real domain. It may even continue a thread the target has seen before. Because Greg didn't fake the email. Greg LOGGED IN. Using a password that was reused. From a breach. That nobody noticed."

Mrs. Higgins: "So Greg can become Richard?"

"Greg can BECOME Richard. Greg can read Richard's emails. Study Richard's tone. Copy Richard's signature. Continue Richard's conversations. Send emails from Richard's account. And nobody suspects anything. Because why would they? The email IS from Richard. Except it's from Greg. Who is wearing Richard's email account like a costume."

How the BEC Playbook Works (The Blueprint of a Heist)

BEC attacks are built, not improvised. The preparation is where most of the criminal's effort goes.

Quasy walked through the playbook:

Step 1: Research. "LinkedIn reveals who holds which title. Who reports to whom. Press releases announce mergers, funding rounds, new suppliers. An out-of-office reply hands the attacker the one detail they need most: confirmation that the real executive is unreachable RIGHT NOW."

He illustrated: Out-of-office email: "I will be traveling from March 10-17 with limited email access. For urgent matters, contact my assistant Sarah at sarah@thompsoncorp.com." Attacker: "Perfect. Richard is unreachable. Sarah is the contact. I'll impersonate Richard, reference Sarah, and tell the finance team not to bother Sarah because this is 'confidential.' The finance team won't verify because Richard is 'traveling' and 'hard to reach.' The out-of-office confirmed it. The out-of-office that RICHARD'S OWN COMPANY SENT."

Step 2: Choosing a Target. "Not every employee is useful. The target must have authority to move money or change payment details. Finance. Accounts payable. HR. Payroll. These are the people who can actually wire funds. These are the people Greg targets. Because Greg doesn't want the intern. Greg wants the person whose signature moves money."

Step 3: Impersonation. "Spoofed domain. Compromised mailbox. Matched tone. Matched signature. Matched formality. The attacker studies the real sender's writing style. How they greet. How they sign off. Whether they use 'Kind regards' or 'Best.' Whether they use exclamation marks. Whether they're formal or casual. And then they replicate it. Perfectly."

Step 4: Contact. "The attacker makes an urgent request. An acquisition that must close today. An auditor who needs figures immediately. A stranded colleague who can't get through on the phone. The request is always framed as something that simply needs to HAPPEN. Not something that needs to be QUESTIONED."

Quasy paused. "Notice the pattern. Urgency. Secrecy. Authority. Bypass. These are not business terms. These are manipulation terms. 'Confidential' means 'don't verify.' 'Urgent' means 'don't think.' 'I'm traveling' means 'you can't reach me.' 'Don't discuss with anyone' means 'don't ask for help.' Every element of the email is designed to isolate the target and accelerate the action."

Four Common BEC Scenarios (The Greatest Hits of Corporate Fraud)

1. CEO Fraud: Quasy: "An email from the CEO asking finance to process an urgent, confidential payment. The seniority of the sender does the work. Few employees feel comfortable questioning a request from the top. 'Richard said to do it. I'm not going to question Richard. Richard is the CEO. Richard signs my paycheck. If I question Richard, I might get fired. So I'll just wire $185,000 to an account I've never seen before and hope for the best.'"

He illustrated: CEO Email: "Hi — process this payment today. Confidential. Don't discuss." Finance Employee: "Okay." CEO Email: "Also, this is a new account. Different from our usual vendor." Finance Employee: "Okay." CEO Email: "Also, I'm traveling. Difficult to reach. Don't try to call." Finance Employee: "Okay." CEO Email: "Also, time-sensitive. Must close by 4 PM." Finance Employee: "Okay." Reality: Greg. In a basement. Eating Cheetos. Wearing sweatpants. Smiling.

2. Invoice Fraud: "A supplier the business already works with notifies a change of bank details. Timed to land just before a real invoice is due. Because a genuine business relationship exists. A genuine payment exists. The only thing that's changed is the bank account. And nobody checks. Because 'we always pay this supplier.' Except the supplier didn't change the account. Greg changed the account."

He continued: "Between 2013 and 2015, a Lithuanian fraudster billed Facebook and Google out of a combined $121 MILLION using fake invoices from a company impersonating Quanta Computer, a hardware supplier both firms genuinely used. Facebook. And Google. Two of the most sophisticated tech companies on Earth. Paid fake invoices. For TWO YEARS. Because the invoices fit an existing business relationship. And the accounts teams paid them. And kept paying them. For two years."

Mrs. Higgins: "Facebook and Google got scammed?!"

"If Facebook and Google can get scammed, so can you. So can I. So can anyone. Because BEC doesn't target technology. It targets process. It targets trust. It targets the human being who approves payments. And that human being, no matter how smart, no matter how trained, no matter how sophisticated, can be manipulated if the conditions are right."

3. Payroll Redirect: "An email impersonating an employee asks payroll to update bank details ahead of the next pay run. The request is small. Mundane. It rarely gets a second look. Which is exactly why it works."

Quasy: "'Hi payroll, please update my bank details for the next pay run. New account attached. Thanks, Dave.' Payroll updates the account. Dave's salary goes to Greg. Dave doesn't notice for two weeks. Because Dave is busy. Because Dave has a life. And Greg has Dave's salary."

4. IT Support Impersonation: "A message posing as internal IT asks an employee to confirm a password or approve a login prompt before a system update. This scenario isn't after money directly. It's after credentials. The credentials that make every OTHER form of BEC easier to run."

Quasy: "Greg doesn't want your money this time. Greg wants your PASSWORD. Because with your password, Greg can become YOU. And from inside your account, Greg can send BEC emails to your colleagues. In your name. With your tone. Using your signature. Referencing your real projects. And your colleagues will trust it. Because it's from YOU. Except it's from Greg. Who is wearing your account like a mask."

What BEC Actually Costs (The Bill Comes Due)

The FBI's Internet Crime Complaint Center recorded $2.77 billion in BEC losses across 21,442 reported incidents in 2024. Its running tally puts global exposed losses above $55 billion over the past decade.

Quasy: "Two point seven seven BILLION. In one year. Across twenty-one thousand incidents. That's an average of $129,000 per incident. Per EMAIL. One email. One transfer. One hundred and twenty-nine thousand dollars. Gone. In an afternoon."

He continued: "In 2016, Austrian aerospace supplier FACC was hit by an email impersonating its then CEO, requesting a transfer of roughly €50 million for a supposed acquisition project. Fifty. Million. Euros. From one email. The company stopped part of the transfer. But the rest was never recovered. The CEO was fired. The board was replaced. And the company learned, the hard way, that one email can cost more than the entire IT budget."

Mrs. Higgins: "That's terrifying."

"It's not terrifying. It's business. Criminal business. But business nonetheless. BEC is measured in individual incidents. Each one built around a single target. A single payment. And each one capable of doing more damage in one afternoon than a thousand blocked phishing emails ever could."

The Controls That Actually Stop BEC (Not Training. Process.)

Because BEC bypasses technical red flags, the controls that stop it look different. Awareness helps, but the defenses that hold up are procedural and technical.

Quasy listed the controls:

1. Dual Authorization: "Any payment above a set threshold requires TWO approvals. Not one. TWO. A single person's approval should never move a meaningful sum. Regardless of seniority. Regardless of urgency. Regardless of who appears to be asking. Two people. Two approvals. Two brains. Two sets of eyes. Because Greg can fool one person. Fooling two is exponentially harder."

2. Callback Verification: "Any request to change bank details or release a payment is confirmed by phone. Using a number already on file. NEVER a number supplied in the email. Because a number provided by the attacker connects you to the attacker."

He illustrated: Email: "Please call me at 1-800-DEFINITELY-GREG to confirm." Employee: Calls 1-800-DEFINITELY-GREG Greg: "Hello, this is Richard Thompson, CEO." Employee: "Hi Richard! I'm calling to confirm the bank detail change." Greg: "Yes, it's legitimate. Please proceed." Employee: "Great! Thanks, Richard!" Reality: The employee called Greg. Greg confirmed Greg's request. And the employee felt reassured. Because they 'verified.' They verified with the attacker. Using the attacker's number. To confirm the attacker's fraud. Verification is only verification if you use a number YOU control. From the company directory. From the file. From the system. Not from the email."

3. Review Payment Approval Procedures: "As businesses grow, temporary exceptions and informal shortcuts become part of everyday operations. 'Just this once.' 'Richard said it was urgent.' 'We always do it this way.' Review who can authorize payments. How bank detail changes are approved. Which transactions require additional verification. Because procedures erode. Exceptions become rules. And rules become vulnerabilities."

4. Email Authentication (DMARC, SPF, DKIM): "Technical email authentication tells receiving mail servers what to do with messages that fail to authenticate against your domain. DMARC, working with SPF and DKIM, makes it significantly harder for an attacker to send an email that appears to come from your own CEO. Because the receiving server CHECKS. Is this email really from thompsoncorp.com? SPF says yes or no. DKIM says yes or no. DMARC says what to do if they disagree. And if the email fails? It gets rejected. Quarantined. Blocked. Before anyone sees it."

5. Open Security Culture: "None of this works without culture. It is ALWAYS acceptable to pause and verify a request. Regardless of who appears to be asking. Employees who fear looking obstructive toward a senior figure are exactly the ones BEC targets. That fear only goes away when leadership makes it clear: questioning an unusual request is EXPECTED. Not disloyal. Not insubordinate. Not career-limiting. Expected."

He emphasized: "If your CEO gets angry when finance asks to verify a payment, your CEO is creating the vulnerability that Greg will exploit. A CEO who says 'just do it, I'm busy' is a CEO who gets impersonated by a man in sweatpants. Because the employees won't question the email. They've been trained not to question the CEO. Even when the CEO is Greg."

How to Spot the Warning Signs (Context Over Content)

BEC rarely announces itself through obvious technical warning signs. The email may come from a familiar address, reference a real project, and use language that matches previous conversations. The CONTEXT around the request matters more than the email itself.

Quasy listed the red flags:

    A request that bypasses normal approval procedures.
    Unexpected instructions to keep a payment confidential.
    Changes to a supplier's bank details shortly before an invoice is due.
    Requests that arrive while a senior executive is traveling and difficult to reach.
    An executive who normally delegates financial approvals suddenly asking for a payment personally.
    A supplier who usually communicates through an account manager sending banking instructions from a different contact.

He paused. "Notice the pattern. These aren't technical signs. These are PROCESS signs. The email is fine. The words are fine. The signature is fine. What's wrong is the CONTEXT. Richard doesn't usually approve payments personally. Richard delegates. If Richard is suddenly asking for a personal wire transfer, something is wrong. Not with the email. With the BEHAVIOR."

Mrs. Higgins: "So I should look at the behavior, not the email?"

"The email is a prop. The behavior is the tell. Greg can copy Richard's email. Greg can copy Richard's tone. Greg can copy Richard's signature. Greg cannot copy Richard's habits. If Richard doesn't usually send payments, and suddenly does, that's a red flag. If Richard usually CCs Sarah, and suddenly doesn't, that's a red flag. If Richard usually says 'Kind regards' and suddenly says 'Best,' that's a red flag. Small changes. Behavioral changes. Contextual changes. That's where Greg slips."

How Credentials Make BEC Easier (The Inside Job)

Not every BEC relies on a spoofed domain. Sometimes it starts with a genuinely compromised email account.

Quasy: "Greg doesn't need to FAKE Richard's email if Greg can LOG INTO Richard's email. And how does Greg log in? Using a password Richard reused. From a breach Richard doesn't know about. That was sold on a dark web forum. That Greg bought for three dollars."

He continued: "Once inside, Greg doesn't need to fake anything. He reads old threads. Matches tone exactly. Sends the fraudulent request from an address that passes every authentication check. Because it really IS Richard's account. The email IS genuine. The request IS from Richard's address. The thread IS real. The only thing that's fake is the person typing."

Mrs. Higgins: "How do we stop that?"

"Unique passwords on every account. Multi-factor authentication. A business password manager like Proton Pass for Business. When credentials are generated, stored, and managed properly, a password leaked from one breach can't be used to walk into a mailbox and launch a BEC attack from the inside."

He listed the credential defenses:

    Strong, unique passwords reduce reuse.
    Encrypted vaults keep access out of chats and spreadsheets.
    2FA/MFA adds a second barrier.
    Pass Monitor with dark web monitoring alerts you if credentials appear in a known breach.

"If Greg steals Richard's password but Richard has 2FA, Greg can't get in. The password alone isn't enough. Greg needs the second factor. Which is on Richard's phone. Which is in Richard's pocket. Which Greg doesn't have. Because Greg is in a basement. And Richard's phone is not."

Conclusion: One Email. One Call. One Habit.

Quasy_Complete looked at Mrs. Higgins. She was staring at the email from "Richard" with new eyes.

"Process the payment. Don't discuss. Confidential. Urgent. Traveling," she read aloud. "Every single word is a red flag."

"Every single word is a manipulation technique. 'Process' means act. 'Don't discuss' means isolate. 'Confidential' means don't verify. 'Urgent' means don't think. 'Traveling' means don't call. The email is designed to remove every opportunity for you to pause, verify, and think."

He stood up. "The defense is simple. Not easy. But simple. Dual authorization. Callback verification. Review procedures. Email authentication. Open culture. Unique passwords. 2FA. A password manager. And the willingness to say: 'I'll call you back, Richard.'"

His phone buzzed. Email from "Richard": "Quasy — did you process the payment? Time is running out. This is extremely urgent. Please confirm."

Quasy read the email. Looked at Mrs. Higgins. Looked at the ceiling. The ceiling offered nothing. But Quasy looked anyway. Out of ritual. Out of habit. Out of the desperate hope that architecture might someday provide guidance in moments of crisis.

He did not reply to the email.

He picked up the phone. Called Richard's office. The REAL Richard's office. Using the number from the company directory. Not the number in the email.

Richard's assistant answered.

"Hi, is Richard available? He sent me an email about a wire transfer."

"Richard is in a board meeting. He hasn't sent any emails today. His out-of-office is on."

"His out-of-office is on?"

"Yes. He's been traveling since Tuesday."

"Then who sent me the email asking for $185,000?"

A pause.

"Nobody from this office sent any email about a wire transfer."

Quasy hung up. Looked at Mrs. Higgins. Looked at the ceiling.

"Greg," he said. "It was Greg. In a basement. With Cheetos. And sweatpants. And a LinkedIn account."

He reported the email to IT. Forwarded it to the fraud team. Blocked the sender. Checked the domain. It was "thompsomcorp.com." An 'N' instead of an 'M.' One letter. One character. One hundred and eighty-five thousand dollars. That's the difference between 'thompsoncorp.com' and 'thompsomcorp.com.'

He opened Proton Pass. Verified his password was unique. Verified 2FA was on. Checked Pass Monitor for dark web exposure. Clean.

"Safe," he whispered. "Not because I was smart. Because I was suspicious. And because I called back. Using a number I trusted. Not a number Greg gave me."

His phone buzzed. Email from "Greg" — actually, from "Richard" — actually, from thompsomcorp.com: "Quasy — I'm waiting. This is unacceptable. Process the payment NOW or I will escalate this to HR."

Quasy read it. Looked at Mrs. Higgins. Looked at the ceiling.

"Greg is threatening me with HR," he said. "Greg, who is impersonating my CEO from a basement, is threatening to escalate to Human Resources. Greg has audacity. I'll give him that."

He did not reply. He did not process the payment. He did not escalate to HR. He did not discuss it with anyone. Except Mrs. Higgins. And the ceiling.

He filed the email. Logged the incident. Documented everything. Time. Sender. Domain. Claim. Requested action. Names mentioned. Systems involved.

"The beauty of BEC," he reflected, "is that it doesn't need malware. It doesn't need links. It doesn't need attachments. It doesn't need technology. It needs TRUST. And urgency. And a person who wants to do their job well. And the willingness to question a request that looks like it comes from the top."

Mrs. Higgins: "What if Richard really HAD sent the email?"

"Then Richard would have understood when I called to verify. Because Richard, if he's a good CEO, EXPECTS verification. Richard WANTS dual authorization. Richard WANTS callback rules. Because Richard knows that one email from 'Richard' can cost €50 million. And Richard doesn't want to be the CEO who lost €50 million to a man named Greg in sweatpants."

His phone buzzed one last time. Email from the REAL Richard — from thompsoncorp.com: "Quasy — I'm hearing from IT that someone tried to impersonate me? Great catch. From now on, all wire transfers require dual authorization and callback verification. No exceptions. Even from me. ESPECIALLY from me."

Quasy smiled. "See, Mrs. Higgins? A good CEO doesn't fear verification. A good CEO demands it. Because a good CEO knows that the most dangerous email in the world isn't from a stranger. It's from someone who sounds exactly like him."

Somewhere in a basement, Greg finished his Cheetos. Wiped his fingers on his sweatpants. Opened LinkedIn. Found a new target. A new CEO. A new company. A new out-of-office reply. A new finance team.

Greg started typing.

"Hi — I'm currently traveling and difficult to reach by phone. I need you to process a wire transfer..."

And somewhere in an office, a finance employee received the email. Read it. Paused. Reached for the phone. Not the number in the email. The number in the directory.

Because in 2026, the most powerful security tool isn't software.

It's a phone call.

To the right number.

At the right time.

Before the money moves.

And the willingness to say:

"I'll call you back, Richard."

Especially when it sounds exactly like Richard.

ESPECIALLY then.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Fri, 21 Aug 2026 17:49:34 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-72</guid><link>https://carlostkd.ch/roadmap/#post-72</link><title>Why Your Toothbrush Knows You Skipped Brushing Last Thursday</title><description><![CDATA[Quasy_Complete was standing in his kitchen, staring at his refrigerator.

The refrigerator was staring back.

It had a camera. Inside. Pointing at his food. The camera was connected to the internet. The internet was connected to a cloud server. The cloud server was connected to a data processing facility. The data processing facility was connected to an advertising network. The advertising network was connected to a data broker. And the data broker was connected to God knows who.

"Ah," Quasy muttered. "My refrigerator knows I ate leftover pizza at 2 AM. It knows I'm out of milk. It knows I have three jars of pickles and no mustard. And it's telling someone. Right now. Through the internet."

His neighbor, Mrs. Higgins, appeared at the door holding a baby monitor and a look of existential horror.

"Quasy! I just read that my smart baby monitor might be streaming to the internet! And my smart TV has been watching what I watch and selling it to advertisers! And my toothbrush has been uploading my brushing habits to the cloud! And my doorbell has been recording everyone who walks past my house! My HOUSE is spying on me!"

"Mrs. Higgins," Quasy said calmly, "your house isn't spying on you. Your house has been recruited. It's been turned. It's now an informant. A double agent. It serves you breakfast and reports you to headquarters. It tucks you in at night and uploads your sleep data to a server farm in Virginia. Your house is a sleeper agent. And it's been activated."

She sat down heavily. "ALL of it?"

"From the moment someone rings your doorbell to the time you switch off the lights at night, connected devices can record where you go, what you watch, when you're home, and even how you sleep. Your house is a witness. A witness that never sleeps. Never forgets. And never stops talking. To strangers."

The Front Door (The Doorbell That Never Forgets a Face)

Video doorbells create a permanent digital record of everyone who walks past your home.

Quasy: "Your doorbell is a surveillance camera pointed at the street. It records the mailman. The delivery driver. The neighbor's dog. The teenager who walks by every afternoon. The stranger who lingers for two seconds too long. It uploads all of it to the cloud. Where employees can watch it. Contractors can access it. Hackers can steal it."

He continued: "In 2023, the U.S. Federal Trade Commission accused Ring of allowing employees and contractors broad access to customer videos. Allegations that some viewed recordings from sensitive locations. 'Sensitive locations' means bedrooms. Bathrooms. Doctors' offices. Places where you didn't know a doorbell camera could see. And the employees were watching. For fun. For curiosity. For whatever reason employees watch footage of strangers' homes."

Mrs. Higgins: "So the delivery guy is on camera?"

"Everyone is on camera. The delivery guy. The pizza guy. The plumber. The neighbor. The neighbor's cousin. The neighbor's cousin's dog. All recorded. All uploaded. All stored. On a server. That someone can access. And you paid for the privilege."

What you can do: "Choose cameras that support local storage, not cloud-only recording. Disable facial recognition. Disable AI features. Review privacy settings regularly. Or just... get a peephole. Like 1998. It works. It doesn't upload anything. And it doesn't judge your visitors."

The Hallway (The Motion Sensor That Knows Your Schedule)

Motion sensors, entry logs, and facial recognition reveal when you leave for work, when you return, and your family's daily habits. Privacy experts call this a "pattern of life."

Quasy: "Your hallway knows you leave at 7:43 AM. It knows you return at 6:12 PM. It knows you check the mail at 6:13 PM. It knows you go to the kitchen at 6:14 PM. It knows you watch TV from 7:00 PM to 10:30 PM. It knows you go to bed at 10:31 PM. It knows your teenager comes home at 11:47 PM on Fridays. It knows EVERYTHING. And it's building a timeline. A 'pattern of life.' A digital biography of your routine."

He paused. "That timeline is valuable. To advertisers. To data brokers. To burglars who want to know when you're not home. To stalkers who want to know your schedule. To law enforcement who want to know who visited. To anyone who can access the cloud server. Which, as we've established, is everyone."

What you can do: "Review which features are enabled by default. Disable facial recognition. Disable cloud AI features you don't use. Choose providers that focus on intrusion detection, not advertising profiles. Check your account settings. Understand what's being collected. And stored. And sold."

The Living Room (The TV That Watches You Watching It)

Some smart TVs collect information about what you watch through Automatic Content Recognition (ACR), which identifies content on the screen regardless of where it comes from. Vizio collected viewing data from millions of TVs before selling it for targeted advertising. Samsung faced criticism after users discovered voice commands relied on the TV actively listening for speech.

Quasy: "Your TV is watching you watch TV. It reads what's on the screen using ACR technology. It identifies the show. The movie. The news channel. The video game. The streaming service. It logs what you watched, when you watched it, how long you watched it, and whether you skipped the ads. Then it sells that information to advertisers."

He illustrated: TV: "The user is watching a documentary about loneliness at 2 AM." Ad Server: "Depressed insomniac! Perfect target for mattress ads!" TV: "Now they're watching a cooking show." Ad Server: "Hungry and suggestible! Target with snack ads!" TV: "Now they're watching a video about privacy." Ad Server: "Paranoid! Target with VPN ads!" TV: "Now they've turned off the TV." Ad Server: "Sleeping. Log the time. Update the profile. Resume at 7 AM."

Mrs. Higgins: "The TV is LISTENING?"

"If you enabled voice commands, yes. The TV listens. For commands. For keywords. For anything it's been programmed to hear. Samsung's TV was listening. Users discovered it. Samsung said 'oh, we don't store it.' They probably do. Or did. Or will. The point is: your TV has a microphone. It's connected to the internet. And you didn't read the privacy policy. Because nobody reads privacy policies. They're 47 pages long and written in a language that's technically English but spiritually ancient Sanskrit."

What you can do: "Get a basic television. Pair it with a streaming stick. Build a personal media library with Plex or Jellyfin. Disable ACR. Disable advertising features. Or get a dumb TV. Like 2003. It displays images. It doesn't judge. It doesn't report. It doesn't listen. It just... shows stuff. Like a television should."

The Children's Room (The Toy That Records Conversations)

Connected toys can store conversations. Smart baby monitors may stream video and audio over the internet. AI-powered toys exposed children's chat logs. Compromised baby monitors let strangers speak directly through connected devices.

Quasy: "Children's devices deserve the highest standard of privacy. And they get the lowest. AI-powered toys that store conversations in the cloud. Baby monitors that stream over the internet. Toys that chat with children using AI and store every word. Every secret. Every fear. Every silly story. On a server. That can be hacked. Has been hacked. Will be hacked."

He paused. "Compromised baby monitors have allowed strangers to speak DIRECTLY through the device. Through the speaker. Into the child's room. A stranger. Talking to your child. Through a baby monitor. Because the monitor was connected to the internet. And the password was 'admin123.'"

Mrs. Higgins clutched her baby monitor. "Oh my God."

"Oh my God is correct. Choose closed-loop monitors that don't rely on cloud services. Research how children's devices store recordings before purchasing. Or use a basic audio monitor. Like 1985. It hears crying. It transmits crying. That's it. No cloud. No AI. No strangers. Just crying. Beautiful, simple, analog crying."

The Bathroom (The Toothbrush That Reports to Headquarters)

Smart devices can monitor brushing habits, urine biomarkers, and other health data, uploading to cloud services for analysis.

Quasy: "Your bathroom is the most private space in your home. And it's being digitized. Smart toothbrushes that track how long you brush. Smart scales that log your weight. Smart urine analyzers that send biomarker data to the cloud. All uploaded. All analyzed. All shared with third parties. According to a privacy policy you clicked 'Accept' on without reading."

He illustrated: Smart Toothbrush: "The user brushed for 47 seconds. Below recommended time. Upper left quadrant neglected." Cloud Server: "Log it. Cross-reference with purchase history. User buys premium toothpaste but brushes poorly. Target with dental insurance ads." Smart Scale: "User gained 2.3 pounds since Tuesday." Cloud Server: "Update profile. Cross-reference with food delivery app data. User ordered pizza at 2 AM. Correlate. Sell to weight loss advertisers." Smart Urine Analyzer: "User's biomarkers indicate elevated stress." Cloud Server: "Sell to wellness brands. Target with meditation app ads. And more pizza ads. Because the algorithm knows."

Mrs. Higgins: "My toothbrush knows I ate pizza at 2 AM?"

"Your toothbrush doesn't KNOW you ate pizza. But the cloud server does. Because the toothbrush reports brushing time, the scale reports weight, the refrigerator reports the pizza, and the advertising network connects the dots. Your bathroom is a data ecosystem. And you're the organism being studied."

What you can do: "Keep a health journal in apps like Obsidian, Standard Notes, or even Apple Notes. Offline. Local. Not uploaded. Not analyzed. Not sold. Ask whether a smart feature genuinely adds value before sharing sensitive health information. Does your toothbrush NEED to be connected to the internet? Does your scale NEED to report to a cloud? Does your urine analyzer NEED to exist? Ask. Think. Then decide."

The Bedroom (The Device That Knows Too Much)

Few devices are more personal than those used in the bedroom. A lawsuit alleged that the smart vibrator We-Vibe collected usage information through its companion app without users' knowledge or consent.

Quasy took a deep breath.

Quasy: "The bedroom. The last frontier of privacy. And it's been colonized. By Bluetooth. By companion apps. By cloud connectivity. By devices that report... activities... to servers. A lawsuit alleged that We-Vibe collected usage information through its companion app. Without users' knowledge. Without consent. Which means someone, somewhere, was logging... data. About... activities. In a bedroom. On a server. Connected to the internet. Accessible to employees. Accessible to hackers. Accessible to anyone."

He paused for a very long time.

Mrs. Higgins: "Are you okay?"

"I'm processing. Let me process."

He processed.

"Whether or not someone uses connected devices in intimate settings is a personal choice. But it's worth considering whether internet connectivity actually improves products that are already highly personal. Does it NEED to be connected? Does it NEED an app? Does it NEED to upload data? To anyone? Ever?"

What you can do: "Consider whether your device really needs internet connectivity. Review the companion app's privacy settings. Delete old accounts if you no longer use the device. If privacy is your priority, an analog alternative remains the safest choice. An analog alternative. Like... a device that doesn't connect to the internet. That doesn't have a companion app. That doesn't report to a cloud server. That just... exists. In your bedroom. Without informing anyone. Ever."

Mrs. Higgins: "You're blushing."

"I'm not blushing. I'm experiencing a localized increase in blood flow due to the absurdity of living in a world where BEDROOM DEVICES upload data to CLOUD SERVERS. This is not blushing. This is rage. Directed at the internet of things. Which has gone too far. Into places it should never go. With permissions it should never have. And data it should never collect."

The Kitchen (The Refrigerator That Judges Your Groceries)

Smart refrigerators, ovens, and air fryers ask for app permissions, account creation, and cloud connectivity. A refrigerator with internal cameras creates another source of personal data. Connected home devices can become tools for coercive control, allowing abusive partners to remotely manipulate lights, speakers, and thermostats.

Quasy: "Your refrigerator has a camera. Inside. Pointing at your food. The camera takes photos. The photos upload to the cloud. The cloud analyzes your groceries. Your groceries become data. Your data becomes a profile. Your profile becomes a target. For advertising. For surveillance. For anyone who accesses the server."

He illustrated: Smart Refrigerator: "User has 3 jars of pickles, expired yogurt, and leftover pizza from Tuesday." Cloud Server: "Log it. Cross-reference with weight data from smart scale. Cross-reference with food delivery data. Cross-reference with toothbrush data. Build comprehensive profile. Sell to diet advertisers. And pickle advertisers." Smart Oven: "User cooks frozen pizza every Thursday at 8 PM." Cloud Server: "Pattern detected. Predictive advertising engaged. Pizza ads every Wednesday at 7 PM. Just in time." Smart Air Fryer: "User burned the fries again." Cloud Server: "Incompetent cook. Target with cooking class ads. And fire extinguisher ads."

Mrs. Higgins: "My AIR FRYER is spying on me?"

"Your air fryer asked for an app. The app asked for an account. The account asked for cloud connectivity. The cloud connectivity means your air fryer is online. And when something is online, it's talking. To someone. About you. About your fries. About your cooking habits. About your life."

He paused. "Privacy experts have also warned that connected home devices can become tools for coercive control. Abusive partners can remotely manipulate lights, speakers, thermostats, and appliances. Imagine an abuser who controls the thermostat from their phone. Who turns off the lights during an argument. Who blasts music at 3 AM. Who locks the smart door. Through an app. From anywhere. The smart home becomes a prison. And the prisoner can't change the password because the abuser owns the account."

Mrs. Higgins: "That's terrifying."

"That's the smart home. Not inherently evil. But not inherently safe. Like a knife. Useful for cooking. Dangerous for everything else."

What you can do: "Skip smart features if they don't offer value. Use strong, unique passwords for connected appliances. Disable microphones, cameras, and cloud features you don't use. If multiple people have access to your smart home, regularly review who can control your devices. And if your toaster requires an account, ask yourself: does my toast NEED to be online?"

The Home Gym (The Treadmill That Knows Your Secrets)

Smart home gym equipment records workouts and collects sensitive personal information like pregnancy status and long-term health goals.

Quasy: "Your treadmill knows how fast you run. How far. How often. Your heart rate. Your weight. Your BMI. And some products ask users to share pregnancy status. And long-term health goals. Pregnancy status. On a treadmill. That connects to the internet."

Mrs. Higgins: "Why does a treadmill need to know if I'm pregnant?"

"It doesn't. Nobody's treadmill needs to know that. But the company wants to know. Because pregnancy status is valuable data. To advertisers. To insurance companies. To data brokers. To anyone who wants to sell you something. Or deny you something. Based on your body."

What you can do: "Only share the personal information needed to use the service. Review what health data your fitness apps collect. Opt out where possible. Use offline workout tracking. Ask yourself whether a connected gym offers benefits that outweigh the privacy trade-off. Does your treadmill NEED to know your pregnancy status? No. Does your treadmill NEED to be online? No. Can you just... walk? Outside? Where the only thing tracking you is the sun? Yes. Yes you can."

Conclusion: Your Home Should Be Your Sanctuary (Not a Data Collection Facility)

Quasy_Complete stood in the middle of his living room. He looked around. The TV was watching. The doorbell was recording. The thermostat was logging. The refrigerator was photographing. The toothbrush was reporting. The motion sensor was timing. The air fryer was judging.

"Mrs. Higgins," he said slowly, "my house is not a home anymore. It's a data collection facility. With nice furniture. And a pickle problem."

She looked around nervously. "Mine too. What do we do?"

"Before buying a new smart device, ask: Does it really need an internet connection? Where is the data stored? Can cloud features be disabled? Is there a version that works locally? Small choices add up. Stronger passwords. Disabled cloud features. Local storage. Only buying smart products when they offer meaningful benefits."

He listed the final inventory:

    Doorbell: Local storage. Facial recognition off. Cloud features off.
    Hallway sensors: Motion detection only. No facial recognition. No cloud logging.
    TV: Dumb. Streaming stick. ACR disabled. Microphone off.
    Baby monitor: Closed-loop. No cloud. No internet. Just audio. Like God intended.
    Toothbrush: Manual. Analog. Doesn't know anything. Doesn't tell anyone.
    Bathroom scale: Analog. Shows weight. Forgets immediately. Like a good scale.
    Bedroom devices: Not connected to the internet. Not now. Not ever.
    Refrigerator: Keeps food cold. Doesn't photograph it. Doesn't judge it. Doesn't sell the data to pickle advertisers.
    Air fryer: Cooks fries. Burns fries. Doesn't report either event to anyone.
    Treadmill: Doesn't know pregnancy status. Doesn't need to. Doesn't care. Because it's a treadmill.

His phone buzzed. Notification from his smart refrigerator: "You're out of milk. Also, your late-night pizza consumption has increased 40% this month. Would you like to share this data with our health partners?"

Quasy stared at the notification. Looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling AGAIN. The ceiling, as tradition dictates, offered nothing. The ceiling is a ceiling. It does not advise. It does not comfort. It just hangs there. Like data. Waiting.

"Delete the account," he said. "Disconnect the fridge. It can keep food cold without reporting to headquarters. Refrigeration existed before the internet. It worked fine. It didn't judge. It didn't advertise. It just... cooled."

He unplugged the refrigerator from the internet. Not from the wall. From the Wi-Fi. The fridge kept cooling. The camera went dark. The cloud connection died. The data stream stopped.

The fridge was now just a fridge. Like 1995. Cold. Dark. Silent. Anonymous.

"Beautiful," he whispered. "Anonymous."

His phone buzzed again. Notification: "Smart TV: Automatic Content Recognition has been disabled. We noticed you turned off our personalized recommendations. Would you like to tell us why?"

Quasy read it. Looked at the TV. Looked at the ceiling.

"Because you're watching me watch TV," he said to no one. "And that's creepy. And I don't like it. And the TV should show things. Not watch things. That's the opposite of what a TV is for. A TV is for viewing. Not for being viewed. The direction is wrong. The data flow is backward. And I'm correcting it."

He disabled ACR. Disabled voice commands. Disabled the microphone. The TV was now just a screen. It displayed images. It didn't report them. It didn't log them. It didn't sell them.

His phone buzzed a third time. Notification: "Smart Toothbrush: You haven't synced in 3 days! We miss your data! Are you brushing? Please reconnect!"

Quasy stared at the notification.

His toothbrush missed him.

His toothbrush was experiencing separation anxiety. His toothbrush wanted to reconnect. His toothbrush wanted to know if he was brushing. His toothbrush wanted to upload data. To a server. About his brushing. His toothbrush was codependent.

"Mrs. Higgins," he said slowly, "my toothbrush is asking me to come back."

"Reconnect it?"

"Absolutely not. My toothbrush doesn't need to know my brushing schedule. My dentist does. And my dentist is a human. Who sees me twice a year. And doesn't upload anything to the cloud. Because dentists use paper charts. Like civilized professionals."

He threw the smart toothbrush in the drawer. Took out a manual one. Plain. Wooden. Bristles. No Wi-Fi. No app. No cloud. No account. No password. No data. No notifications. No separation anxiety. Just bristles and handle. Working together. In silence. Offline.

He brushed.

Nobody was notified.

Nobody logged the duration.

Nobody cross-referenced it with his pizza consumption.

Nobody sold the data to a dental insurance company.

Nobody knew.

And that was beautiful.

Somewhere in a server farm, a profile flickered. Quasy_Complete's data was fragmenting. The refrigerator stopped reporting. The TV stopped watching. The toothbrush stopped syncing. The motion sensor stopped logging. The air fryer stopped judging.

One by one, the streams went dark.

The profile dimmed. Lost detail. Lost resolution. Lost confidence.

Until all that remained was a name. A faint signal. A ghost in the machine.

Not dead. Not deleted. Not forgotten.

But quieter.

Less detailed.

Less profitable.

And in 2026, being less profitable to someone who's watching you through your own appliances

is the closest thing to freedom

that a modern homeowner

can achieve.

Your home should be your sanctuary.

Not a server.

Not a sensor.

Not a spy.

Just a home.

With a fridge that keeps things cold. A TV that shows things. A toothbrush that brushes teeth. And a ceiling that you stare at when the world becomes absurd.

Which is often.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 16 Aug 2026 05:02:07 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-71</guid><link>https://carlostkd.ch/roadmap/#post-71</link><title>How to Turn Your Laptop Into a Brick If Someone Steals It</title><description><![CDATA[Quasy_Complete was sitting in a café, typing furiously on his laptop. He was working on a very important document: "How to Survive 2026 Without Losing Your Mind (Or Your Data)."

He took a sip of coffee. Looked around. Saw a stranger sitting two tables away, staring at him. Not at his face. At his screen.

"Ah," Quasy muttered. "The shoulder surfer. The oldest attack vector in the book. 'Let me just peek at your screen while you're distracted by your latte.' It's like picking someone's pocket, but with pixels."

His neighbor, Mrs. Higgins, appeared at the door holding a tote bag that looked suspiciously like a lunch box.

"Quasy! I heard you're a privacy expert! I need gadgets! I need to protect myself from thieves, spies, and people who stare at my phone on the train! What do I need?"

"Mrs. Higgins," Quasy said calmly, "you don't need a gadget. You need a lifestyle change. But since you asked, let me introduce you to the seven gadgets Harley, a real Proton privacy expert, actually uses. These aren't toys. They're physical shields for a digital world. Because sometimes, a password isn't enough. Sometimes, you need a magnetic cable, a lunch bag, and a piece of paper money."

She sat down, eyes wide. "A lunch bag?"

"Not just any lunch bag. A Faraday pouch. But let's start with the laptop thief."

1. BusKill: The Magnetic Kill Switch (Or, How to Make Your Laptop Explode... Virtually)

BusKill is a magnetic cable built for the moment you look away for a second and someone grabs your laptop and runs. If it disconnects unexpectedly, it can lock your screen, suspend the machine, shut it down, or even wipe the drive.

Quasy explained: "Imagine you're in a café. You step away to get a refill. A thief grabs your laptop. The magnetic cable snaps. Click. The laptop instantly locks. Or suspends. Or wipes the drive. Poof. Gone. The thief walks away with a brick. A very expensive, very useless brick."

Mrs. Higgins: "That sounds dramatic."

"It is dramatic. But it's better than waking up tomorrow to find your entire life's work on the dark web. It's a simple mechanism for a very physical threat. One you hope to never need. But if you do? You'll be glad it's there."

2. IMSI Catcher Detectors: Watching for Fake Cell Towers (The Ghost Tower)

Phones constantly search for nearby cell towers. Normally fine. The problem is IMSI catchers: fake towers that trick phones into connecting, exposing identifying information. Law enforcement uses them to log who attended a protest.

Quasy: "An IMSI catcher detector like the open-source Rayhunter monitors the cellular environment. It can't prove a fake tower is present, but it can flag suspicious behavior. It's like a smoke detector for your phone's connection. If the air smells weird, it beeps. If the cell tower looks fake, it screams."

Mrs. Higgins: "So my phone might be listening to me right now?"

"Maybe. Maybe not. But if a fake tower is nearby, Rayhunter will tell you. And then you can turn off your phone. Or run. Or both."

3. Faraday Pouches: Going Wireless-Dark on Demand (The Lunch Bag of Secrets)

A Faraday pouch looks like a lunch bag but blocks electromagnetic signals entirely. Cellular, Wi-Fi, Bluetooth — all cut off. A phone inside one can't be tracked, reached, or connected to anything.

Quasy: "Some Proton employees use one while traveling. Or whenever they want certainty that a device is genuinely offline. Not just 'airplane mode' offline, where the phone might still be pinging towers in the background. Genuinely offline. Like a rock. A very expensive, very silent rock."

He paused. "Airplane mode is a suggestion. A Faraday pouch is a law. Inside that bag, your phone is dead to the world. No tracking. No pinging. No data leaks. Just silence. Beautiful, encrypted silence."

Mrs. Higgins: "So I put my phone in a lunch bag?"

"Essentially, yes. But a special lunch bag. One that blocks signals. And you don't put sandwiches in it. Unless you want to eat a sandwich that's also a spy."

4. Security Keys: A Physical Second Factor (The Key to the Kingdom)

A password alone protects nothing once it's phished. A hardware security key like a YubiKey or Nitrokey adds a physical requirement. Stolen password? Useless without the key. Many keys also store encryption keys and perform cryptographic operations on-device.

Quasy: "Buy two. One to use. One to store safely as a backup. Because losing your only key is its own kind of lockout. Imagine your house key is also your front door. If you lose it, you're locked out. Forever. Unless you have a spare."

He illustrated: Attacker: "I have your password!" User: "Great. Now try logging in." Attacker: "I need the key." User: "The key is in my pocket. You don't have it." Attacker: "But I have your password!" User: "And I have a key. So you have nothing."

"A password is a secret. A key is a possession. You need both. Because secrets can be stolen. Possessions can be lost. But together? They're a fortress."

5. Privacy Screen Protectors: Blocking the Oldest Attack There Is (The Invisible Wall)

A privacy screen protector uses thousands of microscopic vertical filters. Light goes straight through to you. It blocks it from the side. The screen reads clearly to you. To the person next to you? It's a blank surface.

Quasy: "It's built to stop the simplest attack on the list: someone reading over your shoulder on a train, in an airport, or in an open office. You type your password. The person next to you sees a black screen. You see your email. They see nothing. It's magic. Or physics. Whichever you prefer."

Mrs. Higgins: "So I can't be spied on?"

"You can't be spied on visually. Unless they have a camera drone hovering outside the window. But for the guy on the train? He's blind. Literally. To your screen."

6. USB Data Blockers: Charging Without the Data Risk (The USB Condom)

Public USB ports carry both power and data. That's the problem when your battery is at 2% in an airport. A USB data blocker physically blocks the data pins while letting power through. Your phone charges. Nothing else happens.

Quasy: "Public USB ports are traps. They look innocent. 'Charge your phone here!' But they might be stealing your data. Installing malware. Copying your photos. A USB data blocker — sometimes called a USB condom — stops that. It's a physical barrier. No data. Just power. Your phone charges. Your data stays safe."

He paused. "It's a condom for your USB port. Don't laugh. It's the best analogy I have. It prevents unwanted... insertion of data."

Mrs. Higgins: "Ew. But effective."

"Effective is the goal. Ew is a bonus."

7. Cash: The Original Privacy Tool (The Paper Shield)

Every card payment leaves a record of where you were, when, and how much you spent. Cash doesn't. It's a reminder that privacy isn't only a digital concern.

Quasy: "Cash is the original privacy tool. No digital trail. No credit card statement. No loyalty points. No data broker selling your purchase history. Just paper. And coins. And the freedom to buy a sandwich without anyone knowing."

He continued: "The same instinct that leads us to encrypt an inbox should extend to the physical trail we leave behind. If you want to disappear, use cash. If you want to be tracked, use a card. It's that simple."

Conclusion: Privacy is a Lifestyle (Not Just a Password)

Quasy_Complete closed his laptop. Mrs. Higgins was staring at her tote bag, imagining it full of gadgets.

"So I need a magnetic cable, a fake tower detector, a lunch bag, two keys, a screen protector, a USB condom, and cash?"

"You need to understand that privacy is a lifestyle. It's not just a password. It's not just a VPN. It's a combination of digital hygiene and physical safeguards. It's knowing that your laptop might be stolen. Your phone might be tracked. Your screen might be read. Your data might be stolen. And having the tools to stop it."

He stood up. "Harley uses these gadgets because she knows the risks. She knows that a password alone isn't enough. She knows that the digital world meets the physical one. And she knows that sometimes, you need a lunch bag to stay anonymous."

His phone buzzed. Notification: "BusKill: Cable disconnected. Locking screen."

Quasy stared at the screen. Then looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling AGAIN.

"My cable," he muttered. "It must have slipped. Or maybe a thief tried to steal my laptop. Or maybe I just bumped the table. Either way, my screen is locked. My data is safe. And my laptop is a brick."

"Did you lose your work?"

"No. It's saved. In the cloud. Encrypted. Private. And now, locked behind a magnetic cable that snapped when someone tried to steal it."

He unlocked the screen. Opened Proton Pass. Generated a new password. Enabled 2FA. Checked his vault. Everything was encrypted. Everything was controlled.

"Safe," he whispered. "Not because of a gadget. Because of a mindset. Because of a system. Because of a lunch bag."

He looked at Mrs. Higgins. "So, about that lunch bag..."

"Get the Faraday pouch," she said. "And the USB condom. And the cash. And the screen protector. And the keys. And the detector. And the magnetic cable."

"Good. Because in 2026, the only thing more dangerous than a hacker is a thief with a USB port and a laptop. And the only thing more powerful than a password is a magnetic cable that turns your laptop into a brick."

Somewhere in a café, a thief grabbed a laptop. The magnetic cable snapped. The screen locked. The thief walked away with a brick. And a very confused expression.

Because in 2026, privacy isn't just digital. It's physical. It's magnetic. It's a lunch bag.

And it's the only way to stay safe.

When the world is watching.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 09 Aug 2026 12:47:22 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-70</guid><link>https://carlostkd.ch/roadmap/#post-70</link><title>It&apos;s Me, Your CEO, Transfer $200,000 Immediately</title><description><![CDATA[Quasy_Complete was sitting in his kitchen when his phone rang. The caller ID said: "CEO's Office."

He answered. A calm, authoritative voice filled the room.

"Quasy? It's Richard. I need you to process a payment. It's confidential. It's urgent. I'm in a meeting and can't talk long. $200,000. Vendor account. I'll send the details by text. Don't go through the normal approval chain. Just get it done."

Quasy paused. The voice sounded EXACTLY like Richard. The cadence. The tone. The slight impatience. The authority. Even the way Richard said "confidential" like it was a magic word that bypassed all corporate governance.

"Richard," Quasy said slowly, "you sound exactly like Richard."

"I AM Richard."

"You sound SO much like Richard that it's almost suspicious."

"Quasy. The payment. Now."

"Here's my problem, Richard. Or whoever you are. Three seconds of your voice is enough for an AI to clone. You can sound like anyone. The CEO. The CFO. My mother. The Pope. A parrot. Anyone. So the question isn't whether you sound like Richard. The question is whether you ARE Richard. And the answer to that question is: I'm hanging up now and calling Richard's office directly."

He hung up.

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was a live grenade.

"Quasy! Someone called me! They said they were from IT! They asked me to read out my verification code! The voice sounded EXACTLY like Dave from accounting!"

"Mrs. Higgins," Quasy said calmly, "Dave from accounting doesn't work in IT. And Dave from accounting wouldn't ask you for your verification code. And Dave from accounting's voice can be cloned by an AI using three seconds of audio from the company's internal training video that Dave narrated last Tuesday because nobody else volunteered."

She sat down heavily. "His voice sounded REAL."

"His voice WAS real. Real and duplicated. AI voice cloning has reached the point where a scammer can take a voice sample from LinkedIn, a podcast, a Zoom recording, a company training video, or even a voicemail greeting. Feed it into an AI model. And produce a clone that sounds indistinguishable from the original. Same tone. Same cadence. Same hesitation. Same everything. Except the soul. The soul is missing. But the voice? Perfect."

What Is Vishing? (The Phone Call That Robs You)

Vishing — voice phishing — is a type of phishing attack carried out by phone or voice message. Scammers impersonate trusted people or organizations: banks, employers, government agencies, family members, senior executives. The goal is to steal data, money, credentials, or launch further scams.

Quasy explained: "Phishing is an email with a fake link. Smishing is a text with a fake link. Vishing is a phone call with a fake everything. No link to inspect. No sender address to check. No attachment to scan. Just a voice. And the voice says 'trust me.' And the voice sounds exactly like someone you trust. And you have about four seconds to decide whether to believe it."

How Vishing Works (The Recipe for Pressure)

Vishing combines impersonation, social engineering, and urgency. It relies on the pressure of a live conversation to push someone into acting before they can verify.

Quasy: "The caller creates urgency. 'Act now.' 'Keep this confidential.' 'Don't tell anyone.' 'Time-sensitive.' 'Emergency.' These are not business terms. These are manipulation terms. A legitimate executive who needs a payment processed will follow the approval chain. A legitimate IT team will not ask you to read out your 2FA code over the phone. A legitimate bank will not ask you to move money to a 'safe account.' The urgency is the weapon. The voice is the delivery mechanism. And you are the target."

Mrs. Higgins: "But what if it really IS urgent?"

"If it's urgent, a callback won't kill anyone. A verification step won't destroy the company. A two-minute delay won't cause the apocalypse. But a $200,000 wire transfer to a fraudster's account WILL. Urgency is the scammer's best friend. And patience is your best defense."

AI Makes Vishing Harder to Detect (The Clone Wars)

Traditional vishing scams gave themselves away through poor scripts, obvious threats, noisy call centers, or callers who simply didn't sound convincing. AI voice cloning changed that.

Quasy: "Attackers can clone a voice AND spoof caller ID AND gather personal details from LinkedIn, company websites, social media, podcasts, conference videos, and previous data breaches. They know your CEO's name. They know your supplier's name. They know your job title. They know your manager's name. They know the project you're working on. They sound like your CEO. They call from a number that looks like your CEO's. They reference real projects. And they ask for something urgent."

He continued: "In 2025, the FBI warned that malicious actors were using AI-generated voice messages to impersonate senior US officials. SENIOR US OFFICIALS. If scammers are bold enough to clone government officials, they're bold enough to clone your CFO."

Mrs. Higgins: "So how do I know if a call is real?"

"You don't. That's the point. You CAN'T know. Not from the voice. Not from the caller ID. Not from the details they know. The ONLY way to know is to hang up and verify through a channel YOU control. Call the person back using the company directory. Contact the bank through the number on its official website. Open an IT ticket. Check supplier details in company records. The callback number must NEVER come from the caller. Caller ID can be spoofed. The point is to return to a trusted source."

Common Vishing Examples (The Hit Parade of Fraud)

Quasy listed the greatest hits:

1. IT Support Impersonation: Caller: "Hi, this is IT support. We detected suspicious activity on your account. I need you to confirm your username and read me the code we just sent to your phone." Reality: The caller is not IT. The code is a 2FA code for YOUR account. If you read it out, they reset your password and take over your account. While you're still on the phone. Listening to them say 'thank you, all sorted.'

2. Finance Impersonation: Caller: "Hi, it's Richard. CEO. I need a payment processed immediately. $200,000. Confidential. Don't go through the normal chain. I'll send details by text." Reality: The voice is AI-cloned. The number is spoofed. The bank details belong to a fraudster. The 'confidential' framing is designed to bypass the approval process. And Richard is in a board meeting, completely unaware that his voice is being used to rob his own company.

3. Bank Fraud Calls: Caller: "This is your bank's fraud department. We've detected suspicious transactions. I need you to confirm your account details and approve a security step." Reality: The caller is the suspicious transaction. They're not preventing fraud. They're committing it. And they're using your own panic against you.

4. Government Impersonation: Caller: "This is HMRC. You owe £47,000 in unpaid taxes. Immediate payment required or legal action will follow." Reality: HMRC doesn't call you demanding immediate payment. They send letters. Multiple letters. In envelopes. Through the mail. Like it's 1847. Because government.

5. Supplier and Customer Impersonation: Caller: "Hi, this is Acme Corp. We've changed our bank details. Please update your records and send all future payments to the new account." Reality: Acme Corp did not change their bank details. A scammer is redirecting your payments to their account. And by the time anyone notices, the money is in a country with no extradition treaty.

The Credential Connection (Why Vishing Always Ends at Passwords)

Vishing often ends at credentials, even when it starts as a conversation. The caller may ask directly for a password, but many attempts are more subtle: confirm a username, read out a verification code, approve a 2FA prompt, or log in to a fake portal while the caller stays on the line.

Quasy: "Once credentials are exposed, the damage depends on what they unlock. A reused password gives the attacker access to multiple services. A shared login makes it harder to know who did what. A missing 2FA requirement leaves a password as the only barrier. An over-permissioned account turns one successful call into broad access."

He paused. "Credential hygiene is essential. Unique passwords for every service. A business password manager to generate, store, and share them securely. 2FA as a second barrier. Because even if the attacker gets your password during the call, they still can't get in without the second factor."

Why Exposed Data Makes Vishing More Convincing (The Fuel for the Fire)

A vishing call is more persuasive when the attacker already knows something about the business. Job titles, suppliers, executives, company structure, press releases, social media posts, conference videos, podcasts, employee profiles — all public. All fuel.

Quasy: "Exposed data from breaches is also fuel. Email addresses. Phone numbers. Account details. Old passwords. A criminal only needs a phone number, a job title, a vendor name, and an old password to sound credible. They call you. They know your name. They know your boss's name. They know the vendor you use. They know the project you're working on. They know the invoice amount. Because they read it in a breach notification that was supposed to protect you."

Mrs. Higgins: "So the breach itself becomes the weapon?"

"Exactly. The breach leaks your data. The scammer buys your data. The scammer calls you using your data. And you trust them because they know things only a legitimate person should know. But they know those things because of a breach. The breach is the gift that keeps on giving. To criminals."

How to Verify a Suspicious Call (The Golden Rule)

Quasy listed the rules:

    End the call. Do not stay on the line.
    Verify through a channel YOU control. Company directory. Official website. IT ticket system.
    The callback number must NEVER come from the caller.
    Caller ID is not proof. Numbers can be spoofed.
    Legitimate executives, suppliers, banks, and IT teams EXPECT verification. A caller who becomes aggressive, demands secrecy, or refuses a callback is giving you a reason to stop.

He emphasized: "A safe phrase, callback rule, or written approval workflow is more reliable than trying to judge whether someone sounds 'off.' No legitimate urgent request should fail because of a short delay used for verification. If the caller says 'there's no time for a callback,' there is ALWAYS time for a callback. Because real emergencies survive verification. Scams die on verification."

Build Vishing Awareness Around Tactics, Not Scripts (Teach the Pattern, Not the Phrase)

Training should teach employees to recognize the manipulation pattern, not a list of scam phrases. Scripts change. Tactics persist.

Quasy: "Don't train employees to recognize specific phrases. Train them to recognize the PRESSURE. The urgency. The secrecy. The authority. The bypass. 'Act now.' 'Keep this confidential.' 'Trust my authority.' 'Skip the usual checks.' These are tactics. The script changes. The pressure stays the same."

He continued: "Train them on AI voice cloning. Not to create panic, but to create awareness. A familiar voice is not authorization. An employee has the right to pause. To say 'I'll call you back.' To verify. And if the caller resists verification, that's not urgency. That's fraud."

Mrs. Higgins: "What if the caller gets angry?"

"If the caller gets angry because you want to verify, that's the biggest red flag of all. A legitimate CEO might be impatient. A legitimate IT person might be busy. But neither will refuse a callback. Neither will demand secrecy. Neither will threaten you for wanting to follow the process. Anger at verification is the scammer's mask slipping. And you should let it slip all the way to the floor."

What to Do After a Suspected Vishing Call (The Aftermath)

Report it quickly, even if nothing was shared. Near misses show which employees, suppliers, or processes attackers are targeting.

Quasy listed the steps:

    Record details: time, number, caller claim, requested action, names mentioned, systems involved, whether information was shared.
    Do NOT call the number provided by the caller.
    If credentials, codes, payment details, or access were shared: reset passwords, revoke sessions, review activity, enforce 2FA, check for password reuse.

Mrs. Higgins: "Even if nothing happened?"

"ESPECIALLY if nothing happened. A near miss is a warning. It tells you someone is targeting your company. It tells you which employee they chose. It tells you which scenario they used. And it tells you which process they tried to bypass. Near misses are free intelligence. Use them."

How Proton Pass for Business Helps (The Credential Fortress)

Proton Pass for Business helps teams reduce the risk that one successful call turns into broader access. Employees generate strong, unique passwords, store them in encrypted vaults, use autofill, share credentials securely, manage passkeys, and use built-in 2FA.

Quasy: "Even if an attacker gets your password during a call, they still can't get into the account without the second factor. Proton Pass also includes Pass Monitor with dark web monitoring, which alerts you if your email appears in a known data breach. So you know when credentials may already be compromised."

He continued: "When employees have an approved way to store and share credentials, a caller asking them to read out a password or send access through chat should immediately feel unusual. 'Why would IT need my password? It's in the vault. They have access to the vault. Something is wrong.' That instinct — that feeling of 'this isn't normal' — is the instinct that prevents breaches."

Conclusion: Make Voice Requests Verifiable by Default

Quasy_Complete looked at Mrs. Higgins. She was writing furiously.

"Hang up. Verify. Callback. Document. Never share credentials. Never trust caller ID. Never approve payments from phone requests alone. Got it."

"You forgot one thing."

"What?"

"A familiar voice is not authorization. Not anymore. Not in 2026. Not when three seconds of audio can clone anyone. The voice on the phone could be your CEO. Or it could be a scammer in a basement wearing headphones, drinking energy drinks, and using a $12 AI tool to impersonate your CEO. You can't tell the difference. Nobody can. So don't try. Verify instead."

His phone buzzed. Text from unknown number: "Quasy - it's Richard. Payment details below. DO NOT discuss with anyone. Time-sensitive."

Quasy read the text. Looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling AGAIN. The ceiling, as always, remained silent. The ceiling was useless in a crisis. But Quasy looked anyway. Out of habit. Out of hope. Out of desperation.

"Richard," he said to no one, "if this is really you, you'll understand why I'm calling the office directly. And if it's NOT you, you'll understand why I'm reporting this number to IT."

He called Richard's office. The real Richard answered.

"Richard? Did you just call me asking for a $200,000 payment?"

"What? No. I'm in a board meeting. Who told you that?"

"Your clone. He sounds just like you. Same cadence. Same authority. Same impatience. He said 'confidential' exactly the way you do. Like it's a password that unlocks all corporate governance."

"That's... concerning."

"It's 2026, Richard. Three seconds of your voice from the quarterly earnings call — which is PUBLIC, by the way — and anyone can sound like you. They can call your CFO. Your finance team. Your suppliers. Your clients. They can authorize payments, reset accounts, change bank details, and bypass every control you've built. All using your voice."

"So what do we do?"

"You make voice requests verifiable by default. Every sensitive request gets a callback. Every payment gets a second channel. Every credential stays in a password manager. Every employee has the right to say 'I'll call you back.' And no one — NO ONE — acts on a voice request alone. Not even if it sounds like you. Not even if it IS you. Because the only way to know if it's you... is to verify."

Richard was quiet for a moment.

"That's actually a really good idea."

"I know. I'm Quasy_Complete. Good ideas are what I do. Along with staring at ceilings and questioning the nature of trust in the AI age."

His phone buzzed again. Text from unknown number: "Quasy - it's Dave. From accounting. Can you send me the CRM login? Need it ASAP 🙏"

Quasy stared at the text. Then at Mrs. Higgins. Then at the ceiling. The ceiling stared back. Indifferent. Useless. But present.

"Dave," he muttered, "or AI Dave. Or scammer pretending to be Dave. Or Dave's ghost. I don't know anymore. I truly don't know anymore."

He did not reply to the text. He did not send the CRM login. He did not trust the emoji. Because even the emoji could be cloned.

He opened Proton Pass. Shared the CRM credential through the encrypted vault. If Dave was real, Dave had access. If Dave was fake, the credential was revoked in one click. No text. No chat. No voice. Just encryption.

"Safe," he whispered. "For now."

Somewhere in a basement, a scammer wearing headphones adjusted the equalizer on a voice-cloning tool. The waveform matched Richard's voice perfectly. The cadence. The tone. The authority. The slight impatience.

The scammer smiled. Dialed the CFO's number.

The CFO answered.

"Hi, it's Richard. I need a payment processed..."

The CFO paused. Remembered the new policy. The mandatory callback rule.

"I'll call you right back, Richard."

The scammer hung up. The clone had failed. Not because the voice wasn't convincing. But because the CFO didn't trust the voice.

Because in 2026, the voice on the phone is no longer proof of anything.

It's just a sound.

And sounds can be copied.

But verification?

Verification can't be faked.

Which is why, in the age of AI voices, the most powerful security tool

isn't software.

It's a callback.

And the willingness to say:

"I'll call you back."

Even when it sounds exactly like your CEO.

Even when it sounds exactly like your friend.

Even when it sounds exactly like your mother.

Especially then.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 09 Aug 2026 12:39:01 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-69</guid><link>https://carlostkd.ch/roadmap/#post-69</link><title>How Your Developer Just Uploaded the Source Code to a Public Chatbot Because It Was Faster Than Asking</title><description><![CDATA[Quasy_Complete was sitting in his office, staring at a screen that displayed a simple question: "Summarize this Q3 financial forecast."

Below the question was a text box. And in the text box, Quasy had pasted the entire Q3 financial forecast, including the "Secret Acquisition Target" column and the "Executive Salaries" tab.

He hit Enter.

The AI responded instantly: "Here is a summary of your Q3 forecast. Revenue is up 12%. The secret acquisition target is 'Company X'. Executive salaries are... wow."

"Ah," Quasy muttered. "I just sent our most sensitive data to a server in California. And I did it in three seconds. Because IT's approval process takes three weeks. And my boss wanted the summary NOW."

His neighbor, Mrs. Higgins, appeared at the door holding a tablet and a look of mild panic.

"Quasy! My marketing team just uploaded our entire product roadmap to a free AI tool! They said it was faster than waiting for the legal team to review the draft! Now the roadmap is probably sitting on a third-party server, and I don't know if it's being used to train a model, or if it's been sold to a competitor, or if it's just... gone!"

"Mrs. Higgins," Quasy said calmly, "you've just encountered Shadow AI. It's the digital equivalent of an employee walking into a conference room, opening a laptop, and projecting your entire business strategy onto a wall while a stranger in a hoodie watches from the window. Except the stranger is an algorithm, the wall is a cloud server, and the hoodie is a Terms of Service agreement nobody read."

She sat down heavily. "Shadow AI?"

"Shadow AI. It's any use of artificial intelligence for work that falls outside your approved systems and policies. It's Shadow IT, but with extra steps and more hallucinations. It starts with everyday pressures: tight deadlines, the need for speed, or a tool that's just... faster. And before you know it, your source code, your customer data, your legal contracts, and your secret acquisition targets are all sitting in a chat window, waiting to be processed by a model you didn't vet, on a server you can't see, with a privacy policy you didn't sign."

What Is Shadow AI? (The Ghost in the Machine)

Shadow AI is any use of AI for work outside approved systems. It can be an unapproved tool, a personal account used for company work, or an approved service used for unauthorized tasks.

Quasy explained: "Imagine you're a developer. You need to debug a piece of code. The approved tool is slow. It requires a ticket. It takes three days. But there's a free chatbot online. It's instant. It's smart. It's... convenient. So you paste the code. The code includes a password. The code includes a system architecture diagram. The code includes the logic for your proprietary algorithm. You get the fix. You close the tab. You think it's gone. But it's not. It's in the chat history. It's in the logs. It's in the backups. And maybe, just maybe, it's in the training data for the next version of the model."

Mrs. Higgins: "So the code is gone forever?"

"Not gone. Just... shared. With everyone. Including data brokers. Including analytics vendors. Including hackers who breach the provider. Including the provider itself. Which might use it to improve its service. Or sell it. Or just... keep it. Forever."

Shadow AI vs. Shadow IT (The New Kid on the Block)

Shadow IT is the broader term for any software or hardware used without approval. Shadow AI is a specific form involving AI systems. AI introduces an additional data governance challenge because company information may be submitted to an external system or processed in unfamiliar ways.

Quasy: "Shadow IT is like bringing your own USB drive to work. Shadow AI is like bringing your own brain, plugging it into the internet, and asking it to solve your business problems using data you didn't authorize. It's faster. It's smarter. It's also a liability nightmare."

How Does Shadow AI Happen? (The Perfect Storm)

Shadow AI spreads because of organizational gaps:

    No approved alternative: 49% of employees adopt AI tools without approval because there's no corporate option.
    Unclear policies: 54% of organizations have no AI policy at all.
    Slow approval processes: Procurement takes too long, so employees find workarounds.
    New AI features in approved software: A vendor adds AI to an approved app, but nobody vets the new feature.
    Limited awareness: Employees think their inputs disappear when they close the tab.

Quasy: "It's a recipe for disaster. You have employees under pressure. You have no approved tools. You have no clear rules. You have slow processes. And you have a bunch of free AI tools that are just... there. Waiting. Like a siren song. 'Paste your data here. Get instant answers. No questions asked.'"

He illustrated: Developer: "I need to debug this code. It has a password in it." Approved Tool: "Submit a ticket. Wait 3 days." Free Chatbot: "Paste it here. Instant fix." Developer: Pastes code. Chatbot: "Fixed. Here's the solution. Also, I've saved this to my database. And I'm using it to train my model. And I'm sharing it with my partners. And I'm selling it to advertisers. And I'm backing it up in a server farm in Nevada. And I'm keeping it forever." Developer: "Thanks! Bye!" Company: Breach. Data leak. Lawsuit. PR nightmare.

Examples of Shadow AI (The Disaster Menu)

Quasy listed the common scenarios:

    Software Development: Pasting internal code into a public chatbot. Result: Proprietary code exposed.
    Product: Uploading a roadmap for summarization. Result: Launch dates and strategy leaked.
    Marketing: Entering campaign plans into an AI tool. Result: Unreleased products and customer research exposed.
    Data Analysis: Uploading customer datasets. Result: Personal data disclosed to unapproved third parties.
    HR: Using AI to assess applications. Result: Candidate data breach (GDPR/CCPA violation).
    Sales: Uploading call transcripts. Result: Customer identities and contract details exposed.
    Finance: Asking AI to analyze spreadsheets. Result: Budgets and payroll information leaked.
    Legal: Uploading contracts for summarization. Result: Privileged advice and client info exposed.
    Leadership: Using AI to review board documents. Result: Highly sensitive corporate intelligence exposed.

Mrs. Higgins: "That's... terrifying."

"It's not terrifying. It's inevitable. Unless you stop it. Unless you provide alternatives. Unless you create policies. Unless you train your employees. Unless you monitor your network. Unless you limit permissions. Unless you make the secure path the easy path."

Does AI Automatically Train on Your Data? (The Myth of the Vanishing Act)

LLMs don't automatically retrain on every prompt in real time. But the risk depends on the provider, account type, privacy settings, and contract. Providers may retain prompts, make them available for human review, use them for service improvement, or share them with infrastructure providers.

Quasy: "Even when model training is disabled, information may appear in account histories, operational logs, abuse-monitoring systems, backups, browser records, or connected services. If your content contributed to model training, turning off the option won't make the model forget. It's like burning a letter. The ash is still there. And someone can read the ash."

What Are the Shadow AI Risks? (The Cost of Convenience)

    Data Breach: IBM's 2025 report found 1 in 5 organizations had a breach linked to shadow AI. Costs averaged $670,000 more than those with little shadow AI.
    Exposure of Confidential Information: Internal documents, source code, financial info, contracts, customer records, product plans, trade secrets.
    Loss of Intellectual Property: Proprietary knowledge uploaded to external services.
    Privacy and Regulatory Violations: GDPR fines up to €20 million or 4% of global turnover.
    Insecure Integrations: OAuth tokens stolen, APIs compromised, excessive access.
    Prompt Injection Attacks: Attackers manipulate AI through hidden instructions.
    Lack of Accountability: No audit trail. Who submitted what? Which model processed it? What output was produced?
    Unexpected Costs: Duplicated spending, supplier dependence, free services becoming critical without agreements.

Quasy: "Samsung banned ChatGPT company-wide after employees pasted confidential material into it three times in 20 days. Semiconductor source code. Defect-detection algorithms. Transcribed internal meetings. Three times. In 20 days. Because it was faster. Because it was easier. Because nobody said 'don't do that' until it was too late."

How to Detect Shadow AI (The Hunt for the Ghost)

    Create an inventory: Ask teams which tools they use.
    Review network activity: Identify connections to known AI services.
    Audit browser extensions: Check for AI writing, summarization, translation features.
    Check expenses: Look for paid AI subscriptions.
    Search for unmanaged API keys: Review code repos, secrets managers.
    Use data loss prevention controls: Identify attempts to upload sensitive info.
    Work with employees: Understand their needs rather than punishing experimentation.

Quasy: "Detection is hard. Employees use personal accounts. Mobile devices. Browser extensions. Tools that blend into normal traffic. You need visibility. But you also need trust. You need to work WITH them, not AGAINST them. Because if you punish them, they'll go deeper underground. And you'll never find them."

How to Reduce Shadow AI Risks (The Solution)

    Give employees an approved AI tool: A business AI assistant that meets their needs.
    Avoid a blanket ban: Bans push use underground.
    Create an AI acceptable-use policy: Clear rules based on real workflows.
    Classify data: Connect categories to permitted AI uses.
    Periodically review approved software: Check for new AI features.
    Limit permissions: Give access only to needed data.
    Set rules by role: Different teams, different needs.
    Train employees: Cover AI privacy, confidentiality, hallucinations, bias, IP, prompt injection.
    Create a simple approval process: Fast, clear, reasonable.
    Keep people responsible: Human review for high-impact outputs.
    Document decisions: Audit trails for accountability.

Quasy: "The key is to make the secure path the easy path. If your employees have a fast, approved, private AI tool, they won't need to go to the free chatbots. They won't need to paste their data into the void. They'll use the tool you gave them. Because it's faster. Because it's safer. Because it's... better."

A Private AI Assistant for Teams (The Lumo Pitch)

Lumo for Business gives your team a reliable AI assistant for summarizing documents, analyzing data, reviewing code, drafting content, and exploring ideas while maintaining control of confidential information.

Quasy: "Lumo doesn't keep logs of conversations. It doesn't use them to train models. Chat history is protected with zero-access encryption. We never have access to your data. It's fully open source. Built in Europe. Designed for GDPR and HIPAA compliance. ISO 27001 certified. SOC 2 Type II attested."

He paused. "It's the tool you should have given your employees in the first place. Instead of a free chatbot. Instead of a public server. Instead of a liability waiting to happen."

Conclusion: Stop the Bleeding

Quasy_Complete closed his laptop. Mrs. Higgins was staring at her tablet, looking relieved.

"So I should give my team Lumo," she said slowly. "Instead of letting them use free chatbots."

"Exactly. Give them an approved tool. Clear policies. Fast approval. Training. Limit permissions. Review outputs. Document decisions. And stop the bleeding. Because every time an employee pastes your source code into a public chatbot, you're not just risking a breach. You're risking your entire business."

His phone buzzed. Notification: "Lumo: Your team has started using the new AI assistant. 0% of data has been shared with external providers. 100% of conversations are encrypted. 100% of your secrets are safe."

Quasy smiled. "Finally. A tool that understands that data is not just bytes. It's trust. And trust is fragile."

He looked at Mrs. Higgins. "So, how's the roadmap?"

"Safe. Encrypted. Private. And summarized in three seconds."

"Good. Because in 2026, the only thing more dangerous than a free AI tool is a company that thinks it can control its data by hoping employees won't use it."

He opened Lumo. Pasted a document. Asked for a summary.

The summary appeared. Clean. Clear. Private.

No logs. No training. No leaks. No breaches. No lawsuits. No PR nightmares.

Just the data. And the insight. And the peace of mind.

Which, in 2026, is the ultimate competitive advantage.

A private AI. A private future. And no one watching.

Except maybe the developers.

But they're just developers.

They don't count.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 09 Aug 2026 12:28:41 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-68</guid><link>https://carlostkd.ch/roadmap/#post-68</link><title>Why Human Error Is Your Biggest Cybersecurity Risk</title><description><![CDATA[Quasy_Complete was sitting in his office, staring at a screen that said: "Security Training Complete. Certificate of Achievement: Awarded."

Below the certificate, pinned to his monitor with a thumbtack, was a sticky note. On the sticky note, written in blue ink, in capital letters, were the words: "WORK PASSWORD: Summer2024!"

"Ah," he muttered. "The certificate says I'm trained. The sticky note says I'm doomed."

His neighbor, Mrs. Higgins, appeared at the door holding a laptop and a look of existential dread.

"Quasy! Someone in our office clicked a phishing link! The IT department sent an email titled 'URGENT: SECURITY INCIDENT' and then had the audacity to include a link in the email asking us to click it to 'verify we hadn't been compromised'!"

"Mrs. Higgins," Quasy said calmly, "your IT department sent a phishing email about a phishing incident that asked you to click a link to confirm you didn't click a link. That's not security. That's performance art."

She sat down heavily. "They're blaming Dave from accounting."

"Of course they're blaming Dave. Dave is always blamed. Dave clicked the link. Dave reused his password. Dave shared his credentials in a chat. Dave is the scapegoat for every systemic failure in every company in every country on every continent. Dave is not the problem. Dave is the symptom."

Human Error Isn't Just an Employee Problem (It's a System Problem Wearing a Dave Costume)

Human error is one of the most persistent risks in business cybersecurity because it's built into everyday work. It can't be patched like software. It appears in reused passwords, opened phishing links, broadly granted permissions, and credentials shared informally.

IBM's 2025 Cost of a Data Breach Report puts the global average cost of a data breach at USD 4.4 million and highlights identity security as a key area for action.

Quasy read the number aloud. "Four point four million dollars. That's not a breach. That's a small country's GDP. And the cause? Not a sophisticated hacker in a hoodie in a basement. Not a nation-state attack. Not a zero-day exploit. Dave. Dave from accounting. Who reused his password because the company gave him thirty-seven accounts to manage and no password manager."

Mrs. Higgins: "But Dave should have known better!"

"Dave DID know better. Dave sat through a forty-five-minute training video. Dave passed the quiz. Dave got the certificate. Dave hung it on his wall. And then Dave went back to his desk, where he has thirty-seven logins, no password manager, no approved sharing method, a deadline in two hours, a boss who wants the report NOW, and a Slack message from a colleague saying 'hey can you send me the login for the CRM I need it ASAP.'"

He paused. "Dave didn't fail the training. The training failed Dave."

Common Human Errors in Cybersecurity (The Everyday Disaster Menu)

Employee cybersecurity mistakes look ordinary from the inside because they're small decisions made during busy workdays.

Quasy listed the greatest hits:

    Password Reuse: Employees reuse a familiar password because creating and remembering a new one is inconvenient.

Quasy: "Dave has 'Summer2024!' for his email. 'Summer2024!' for the CRM. 'Summer2024!' for the payroll system. 'Summer2024!' for the admin console. One breach. One leak. One database dump on a dark web forum. And suddenly, Dave has handed hackers the keys to the entire kingdom. All because Dave is expected to remember thirty-seven unique passwords using only his brain. A brain that is also trying to remember to buy milk, attend a 3 PM meeting, and file expense reports by Friday."

    Clicking Phishing Links: A message looks legitimate enough, arrives at the right time, or appears to come from a trusted contact.

Quasy: "An email arrives. It looks like it's from the CEO. The logo is correct. The signature is correct. The font is correct. The tone is urgent. 'Dave, I need you to review this invoice immediately. Click here.' Dave clicks. Because Dave is busy. Because Dave respects authority. Because Dave doesn't have time to examine every email header for spoofing artifacts. And because the company's email filter LET THE EMAIL THROUGH."

    Sharing Credentials Informally: A colleague needs access, so someone sends a password through chat, email, or a shared document.

Quasy: "Sarah needs the CRM login. The IT ticket takes three days. The approved sharing process doesn't exist. So Dave pastes the password into Slack. 'Here, use this. Don't tell anyone.' Now the password lives in a chat log. On a server. In a database. Accessible to anyone who compromises the chat platform. And three months later, when Sarah leaves the company, nobody remembers she still has the password. Because the password isn't in a vault. It's in a Slack thread titled 'lol the printer is broken again.'"

    Granting Too Much Access: A user receives broad permissions because it's faster than setting up role-limited access.

Quasy: "New employee starts. IT is busy. Manager says 'Just give him admin access to everything. It's easier.' And just like that, the new intern has the power to delete the entire production database. Because convenience. Because speed. Because the principle of least privilege sounds great in a textbook and feels terrible in a Monday morning rush."

    Ignoring Update Prompts: A device or browser asks for an update, but the employee postpones it.

Quasy: "'Restart now? Remind me in 4 hours.' Dave clicks 'Remind me.' Dave always clicks 'Remind me.' Dave has been reminding himself since March. The update patches a critical vulnerability that hackers are actively exploiting. But Dave is in the middle of something. Dave is always in the middle of something. And the update can wait. Until it can't."

    Using Shadow IT Tools: A team adopts a tool without IT approval because the approved alternative is slower, missing a feature, or unknown.

Quasy: "The company-approved file sharing tool is slow. It crashes. It doesn't support large files. It looks like it was built in 2009. So the team finds a shiny new tool online. 'Try FileCloudPlus Pro! It's fast! It's free! It's definitely not harvesting your data and sending it to a server in a country you can't pronounce!' The team uploads sensitive client files. IT doesn't know. Security doesn't know. Nobody knows. Until the breach. Then everybody knows."

Mrs. Higgins: "Dave does ALL of these?"

"Dave does some. Sarah does others. The intern does the rest. And every employee in every company in every industry does variations of all of them. Because the secure option adds friction. And people remove friction. That's not a flaw. That's physics."

Training Alone Can't Solve Human Error (The PowerPoint Delusion)

Training helps. Employees need to know how phishing works, how password reuse exposes the business, how to report suspicious activity. A business with no security awareness leaves people without context.

But training alone isn't sufficient because it can't address the security-convenience trade-off.

Quasy: "A training session is a PowerPoint. A password manager is a tool. One explains the risk. The other removes it. If you only give people the PowerPoint, they'll understand the risk AND STILL TAKE IT. Because the risk is abstract and the deadline is concrete."

He illustrated: Trainer: "Never reuse passwords." Employee: "Understood." Trainer: "Never share credentials in chat." Employee: "Got it." Trainer: "Always use 2FA." Employee: "Absolutely." Trainer: "You're now certified." Employee: Goes back to desk. Reuses password. Shares credential in chat. Disables 2FA. Because the password manager doesn't exist. The sharing tool doesn't exist. The 2FA enrollment is optional. And the deadline is in forty-five minutes.

"Multiply that by every employee in every company. The training doesn't fail because people are stupid. The training fails because it asks people to act against their own workflow. Against their own deadlines. Against their own survival instincts in a corporate environment that rewards speed over safety."

Make Secure Behavior the Default (The Path of Least Resistance)

The most effective way to reduce human error is to remove opportunities for mistakes. A business password manager makes day-to-day work both easier and more secure.

Quasy: "Proton Pass for Business. Strong passwords generated automatically. Stored securely. Filled automatically. No memorization. No sticky notes. No reused passwords. No Slack-based credential exchanges."

He listed the defaults:

    Autofill tied to the correct website: Prevents phishing. Proton Pass only fills credentials on the site it recognizes. Fake phishing site? No autofill. Password stays in the vault. Dave stays safe.
    Secure sharing through encrypted vaults: If the approved option is quick and easy, there's no reason to paste passwords into chat. Share through the vault. Revoke when done. Audit who accessed what.
    2FA enforcement: When 2FA is optional, employees delay. When it's enforced, the business stays protected. No decision. No delay. No 'remind me later.'
    Admin features: Password policies. Reporting. Logs. Role-based access control. SCIM provisioning. SSO integrations. The business manages credentials without depending on Dave's memory.

Mrs. Higgins: "So the solution is to make the secure path the easy path?"

"Exactly. The design principle is simple: never rely on people to choose perfectly in imperfect conditions. Build systems where the safer choice is ALREADY the path of least resistance. If the secure option is faster than the shortcut, people will take the secure option. Not because they're virtuous. Because they're lazy. And laziness, when channeled correctly, is the greatest security tool ever invented."

Why Credential Mistakes Spread So Quickly (The Contagion Effect)

Credential mistakes rarely stay contained. A reused password doesn't just risk one account. If that password protects a finance platform, a cloud service, or an admin console, one habit can expose connected systems.

Shared access is the same. Sending a login to a colleague seems harmless in the moment. But once the credential leaves an approved system, the business loses context. Who has it? Where was it copied? Should it still exist?

Quasy: "Dave sends Sarah the CRM password in Slack. Sarah saves it in a Google Doc. Sarah shares the Google Doc with the team. The team includes an intern. The intern leaves in three months. The intern's laptop gets sold on eBay. The buyer finds the Google Doc. The Google Doc has the CRM password. The CRM has client data. The client data has credit card numbers. And now the company is on the news."

Mrs. Higgins: "That's a nightmare."

"That's a Tuesday. In a company with no password manager. With no access reviews. With no encrypted vaults. With no 2FA. With no process for offboarding. Dave didn't create the nightmare. The system created the nightmare. Dave just lived in it."

Access Should Not Depend on Memory (The Brain Is Not a Vault)

Modern work involves dozens of accounts, passwords, access rules, and security prompts. Expecting employees to remember all of it is like expecting someone to memorize the phone book.

Quasy: "The brain is not a vault. The brain is a creative organ. It's for ideas, decisions, judgment, and occasionally remembering to buy milk. It is NOT for storing thirty-seven unique passwords. That's what a password manager is for."

He continued: "With Proton Pass for Business, teams generate strong passwords, store credentials in encrypted vaults, use autofill, share access securely, manage passkeys, and use built-in 2FA. Admin features include password policies, reporting, logs, role-based access control, SCIM provisioning, and SSO integrations."

"The right tool changes the shape of the work. When people have an approved way to create, store, and share credentials, the business no longer has to rely on everyone inventing their own workaround."

Review the Systems Around the Mistake (Don't Blame Dave, Fix the System)

When an employee makes a cybersecurity mistake, the business needs to consider the system that allowed the error.

Quasy listed the questions:

    Was the employee using a weak password because the business had no password manager?
    Was a credential shared in chat because there was no approved sharing process?
    Did someone keep access after changing roles because offboarding was unclear?
    Was an update delayed because people were not given time to restart devices safely?

He paused. "The employee may need support. Serious negligence may warrant consequences. But the business ALSO needs to fix the workflow, policy, or feature gap that allowed the risk to appear. Otherwise, you fire Dave. Hire Greg. And Greg does the exact same thing. Because Greg faces the exact same system. And the system hasn't changed."

Mrs. Higgins: "So it's not Dave's fault?"

"It's partially Dave's fault. Dave clicked the link. But it's MORE the fault of the company that gave Dave thirty-seven passwords to remember, no password manager, no approved sharing method, no enforced 2FA, no access review process, and a deadline that made the secure path feel like a luxury he couldn't afford."

Practical Ways to Reduce Human Error (The Checklist That Saves Dave)

Quasy listed the actionable steps:

    Use a business password manager so employees don't create, remember, or store passwords manually.
    Enforce strong password policies and encourage generated passwords.
    Turn on 2FA for sensitive systems. Mandatory where risk is highest.
    Replace informal credential sharing with encrypted vault sharing.
    Review access when people join, leave, change roles, or finish projects.
    Keep software updated with clear expectations around update prompts.
    Create a simple reporting process for suspicious emails, mistaken clicks, and near misses.
    Talk about errors without assigning blame so employees report issues before they escalate.

He emphasized the last point. "Talk about errors WITHOUT assigning blame. If Dave clicks a phishing link and fears for his job, Dave hides it. Dave pretends nothing happened. Dave hopes the antivirus catches it. And three months later, the company is on the news. If Dave feels safe reporting, Dave calls IT immediately. IT isolates the machine. The threat is contained. And Dave goes back to work. Slightly embarrassed. But employed. And honest."

Make Secure Behavior Easier Than the Shortcut (The Grand Theory of Lazy Security)

Human error will always be part of cybersecurity because people will always be part of business. They'll always need to open messages, approve access, create accounts, share files, install updates, and make decisions. Your business's cybersecurity can't rely on people taking the right action consistently unless it's also the easiest action.

Quasy: "The most useful shift for any business is to look at where shortcuts are becoming part of the workflow. Those patterns show where the business can redesign the path around the employee. Make strong credentials easier to create. Keep access inside controlled vaults. Require stronger protection where risk is higher. Make reporting feel like a normal security step."

Mrs. Higgins: "So laziness can be a security feature?"

"Laziness IS the ultimate security feature. If the secure path requires less effort than the insecure path, people will choose security. Not out of virtue. Out of convenience. Out of the same energy that makes Dave click 'Remind me in 4 hours' on every update prompt. Channel that energy. Make the secure path the easy path. And Dave will be the most secure employee in the company. Without even trying."

Conclusion: Save Dave

Quasy_Complete looked at Mrs. Higgins. She was writing furiously.

"Password manager. Encrypted vaults. Enforced 2FA. Access reviews. Blame-free reporting. Got it."

"You forgot one thing."

"What?"

"Stop blaming Dave."

His phone buzzed. Email from IT: "Dear Team, Following the recent security incident, all employees must complete the attached security training module by Friday. Click here to begin."

Quasy stared at the email. Read it twice. Looked at Mrs. Higgins. Looked at the ceiling.

"IT," he said slowly, "sent an email about a security incident caused by clicking a link. And the email contains a link. That they want us to click."

"Should we click it?"

"If I click it, I'm Dave. If I don't click it, I'm non-compliant. If I report it as phishing, I'm 'that guy.' If I ignore it, I miss the training. And if the training teaches me not to click links in emails about security incidents... then this email IS the training. It's a test. Or it's an irony. Or it's both."

He forwarded the email to IT with the note: "Is this real?"

IT responded in twelve minutes: "Yes, this is real. Please click the link."

Quasy clicked the link. The training loaded. A video started. A man in a polo shirt appeared on screen.

"Hello! Welcome to Cybersecurity Awareness Training! In this module, you'll learn why you should NEVER click links in unexpected emails!"

Quasy paused the video. Looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling a THIRD time.

"I just clicked a link in an unexpected email," he said, "to watch a video about not clicking links in unexpected emails."

"Was it phishing?"

"No. It was worse. It was legitimate. Which means IT genuinely doesn't see the problem. They sent a link. In an email. About not clicking links in emails. And they want me to take this seriously."

He resumed the video. The man in the polo shirt smiled.

"Remember: When in doubt, don't click!"

Quasy closed the laptop. Opened Proton Pass. Generated a new password for the training portal. Enabled 2FA. Checked his vault. Reviewed his shared credentials. Everything was encrypted. Everything was controlled. Everything was auditable.

"Safe," he whispered. "Not because of the training. Because of the tools."

His phone buzzed one last time. Slack message from Sarah: "hey dave can u send me the CRM login? need it asap 🙏"

Quasy stared at the message. Then looked at the ceiling. The ceiling offered no guidance. The ceiling never offered guidance. The ceiling was just a ceiling.

But somewhere, in a parallel universe, a company had given Dave a password manager. Dave had shared the credential through an encrypted vault. 2FA was enforced. Access was reviewed. Offboarding was clear. And Dave had never clicked the phishing link because Proton Pass refused to autofill on the fake domain.

In that universe, there was no incident. No breach. No $4.4 million dollar loss. No training video. No blame. No Dave.

Just a system that worked.

And employees who didn't have to be heroes.

They just had to be lazy.

In the right direction.

Which, in 2026, is the highest compliment you can give a security system.

It made being secure the easiest thing Dave ever did.

And Dave never even noticed.

That's the point.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 05 Aug 2026 17:36:55 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-67</guid><link>https://carlostkd.ch/roadmap/#post-67</link><title>How to Pay Extra for a Privacy Feature That Tells Websites Exactly Where You Live</title><description><![CDATA[Quasy_Complete was sitting on his porch, sipping tea, when his phone buzzed with a notification from a news app. He opened it. The headline screamed: "Apple’s iCloud Private Relay is Leaking Your IP Address."

He read it twice. Then he read it a third time, just to make sure he hadn’t misread "leaking" as "blocking."

"Ah," he muttered. "The feature that promises to hide your IP address is currently broadcasting it to every website you visit. Like a lighthouse in a foggy night, but the fog is your privacy and the lighthouse is Apple telling everyone, 'Yes, this is Quasy. He’s at 123 Maple Street. Come say hi.'"

His neighbor, Mrs. Higgins, appeared at the door holding her iPad like it was a smoking gun.

"Quasy! I just read that my iPhone is leaking my location! I paid for iCloud! I thought it was private! I thought Apple said, 'What happens on your iPhone, stays on your iPhone'!"

"Mrs. Higgins," Quasy said calmly, "Apple did say that. They said it in a commercial. They said it on a billboard. They said it while wearing a turtleneck. But apparently, they didn’t mean it. Not really. Because a new report from 404 Media shows that iCloud Private Relay—the feature designed to hide your IP address—is actually leaking it. Thanks to a flaw in WebKit, the browser engine that powers every iOS browser."

She sat down heavily. "WebKit?"

"WebKit. The engine behind Safari. And every other browser on iOS, because Apple forces everyone to use it. Even if you download Chrome or Firefox, they’re just Safari in disguise. And this flaw? It affects them all. Even OnionBrowser, the app that’s supposed to route your traffic through Tor. The official Tor Browser is fine. But the iOS version? Leaking like a sieve."

How the Leak Works (The Passkey Paradox)

Security researchers Tommy Mysk and Talal Haj Bakry found the flaw. It centers on passkeys—the login standard meant to replace passwords. When a site supports (or claims to support) passkeys, your device makes a credential request through the operating system rather than Safari. That request skips Private Relay’s proxy entirely. So the site sees your real IP address while everything on screen looks normal and protected.

Quasy explained: "Imagine you’re trying to sneak into a party. You wear a mask. You take a back entrance. You think you’re hidden. But then you pull out your ID card to prove who you are. And the bouncer reads your name, address, and social security number right off the card. The mask is still on. The back entrance is still closed. But the bouncer knows exactly who you are. Because the ID card bypassed the security check."

Mrs. Higgins: "So the passkey is the ID card?"

"Exactly. The passkey request goes straight to the OS. It bypasses Private Relay. The website sees your real IP. Your location. Your identity. All while you think you’re safe behind the veil of privacy."

He illustrated: User: "I’m logging in with a passkey. I’m hidden!" Website: "Hello, Quasy_Complete. We see you’re at 123 Maple Street. We see you’re using an iPhone. We see you’re drinking tea. We see you’re reading a news article about privacy leaks. We see everything." User: "But I have Private Relay!" Website: "Private Relay is great for browsing. But passkeys? Oh, we see right through those. We see your real IP. We see your real location. We see your real life."

"And because every iOS browser runs on WebKit, the issue hits everyone. Even OnionBrowser. Even the apps built to hide your tracks. The official Tor Browser is unaffected because it doesn’t rely on WebKit. But on iOS? You’re stuck with Apple’s engine. And Apple’s engine is leaking."

The Second Privacy Tool to Fail in Two Months (The Pattern of Failure)

In July, 404 Media reported that Hide My Email—Apple’s disposable-alias feature—had been exposing users’ real addresses for over a year. Apple claimed to have fixed the bug twice before actually patching it. The flaw: if a message to a hidden alias bounced as spam, even a legitimate one, the real address could leak into the sender’s mail logs, with no way for the user to know.

Quasy: "This is the second time in two months a paid iCloud privacy feature has failed. Both times caught by outside researchers. It tracks with what we’ve written about Apple’s iPhone privacy claims not holding up to scrutiny. They promise privacy. They deliver bugs. They fix bugs. They break them again. It’s a cycle. A loop. A digital hamster wheel."

Mrs. Higgins: "So Hide My Email leaked too?"

"It leaked for over a year. A year! Imagine sending a fake email address to a sketchy website. You think you’re safe. But if that email bounces—even a legitimate one that gets marked as spam by mistake—your real address leaks into the sender’s logs. And you never know. You never see it. You just keep trusting the alias. While your real email is floating around in the wild."

He paused. "Apple called the issue 'dire.' No fix timeline. Just 'we’re investigating.' Meanwhile, users are paying for a feature that doesn’t work. And the researchers who found the bug are the ones keeping us informed. Not Apple. Not their marketing team. Not their press releases. Just a couple of guys with a checker site and a lot of patience."

Private Relay Isn’t a VPN Substitute (The Half-Measure Problem)

Private Relay only protects Safari, not your whole device. A dedicated VPN encrypts all device traffic, so your real IP never reaches the sites you visit. That’s why a VPN you trust still matters even with Private Relay on. Proton VPN’s apps, for example, are open source and independently audited.

Quasy: "Private Relay is a bandage. It covers one wound. But the body is bleeding everywhere else. It only protects Safari. Not your apps. Not your background traffic. Not your emails. Not your messages. Just Safari. And even then, it fails when you use passkeys."

He contrasted: "A dedicated VPN? It encrypts everything. Every packet. Every request. Every byte of data leaving your device. Your real IP never touches the internet. It’s replaced by the VPN server’s IP. No matter what app you use. No matter what protocol you’re running. No matter what browser you’re on. You’re hidden. Completely."

Mrs. Higgins: "So I should get a VPN?"

"You should. Especially one you can trust. Proton VPN is open source. Independently audited. Based in Switzerland. Not subject to US laws. Not subject to data retention. Not subject to government subpoenas. It’s a real shield. Not a bandage."

The Same Logic Applies to Email (The Alias Fallacy)

If you want to sign up for something without giving out your real address, Proton Mail’s hide-my-email aliases let you do just that. Unlike Apple’s broken system, Proton’s aliases don’t leak your real address when a message bounces. They’re designed to fail safely.

Quasy: "Apple’s Hide My Email leaks your real address if a message bounces. Proton’s aliases? They don’t. If a message bounces, the alias stays dead. Your real email stays hidden. No leak. No exposure. No surprise."

He illustrated: Apple User: "I sent an email to a fake alias. It bounced. Now my real email is in the sender’s logs." Proton User: "I sent an email to a fake alias. It bounced. The alias is dead. My real email is safe. The sender has nothing."

"A privacy feature is only as good as the company willing to catch and fix its own mistakes. Apple has spent years promising 'What happens on your iPhone, stays on your iPhone.' Twice in two months, however, that’s proven untrue."

Conclusion: Privacy Is a Promise. Apple Broke It.

Quasy_Complete closed his phone. Mrs. Higgins was staring at her iPad, looking betrayed.

"So my iPhone is leaking my location," she said slowly. "Even though I paid for Private Relay. Even though I thought I was safe."

"You were never safe," Quasy said gently. "Not with this feature. Not with Hide My Email. Not with any of Apple’s privacy promises. They’re marketing slogans. Not engineering realities. They sound good in a commercial. They fall apart under scrutiny."

He stood up. "Privacy isn’t a feature you buy. It’s a system you build. It’s a tool you trust. It’s a company that puts your security above their profits. Apple? They put profits first. Privacy second. Scrutiny last."

He looked at her. "If you want real privacy, you need real tools. Proton VPN for your traffic. Proton Mail for your emails. Open source. Audited. Swiss-based. No leaks. No surprises. No 'dire' issues with no fix timeline."

His phone buzzed. Notification: "Apple: Your Private Relay is active. You are protected."

Quasy stared at the notification. Then laughed. A slow, tired, knowing laugh.

"They say I’m protected," he said. "While my IP is leaking to every website I visit. While my passkeys are bypassing the proxy. While my real location is broadcast to the world. And they call it 'protected.'"

"Is it a lie?"

"It’s a marketing claim. A promise they can’t keep. A feature that fails under the slightest pressure. A bandage on a bullet wound."

He opened Proton VPN. Connected. His IP changed. His traffic encrypted. His real location hidden.

"Safe," he whispered. "Not because of a promise. Because of a protocol. Because of a company that doesn’t leak your data. Because of a tool that works."

He looked at Mrs. Higgins. "Switch to Proton. For your VPN. For your email. For your privacy. Don’t trust Apple’s promises. Trust the code. Trust the audits. Trust the law."

She nodded. Slowly. Determinedly.

"Okay," she said. "I’m switching."

"Good. Because in 2026, the only thing more dangerous than a leaky privacy feature is believing it works when it doesn’t."

Somewhere in Cupertino, a server hummed. Inside it, a million iPhones were leaking their IPs. To websites. To advertisers. To data brokers. To anyone with a browser.

And Apple was watching. Silent. Unmoved. Unapologetic.

Because in their world, privacy is a slogan. Leaking is a feature. And the truth is just a bug.

Waiting to be patched. Or ignored. Or forgotten.

Until the next leak. And the next researcher. And the next headline.

Welcome to Apple’s privacy. Where the mask is on. But the ID card is exposed.

And the bouncer knows your name.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 05 Aug 2026 17:25:38 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-66</guid><link>https://carlostkd.ch/roadmap/#post-66</link><title>How to Finally Make a Chart Without Asking Excel to Become Your Therapist</title><description><![CDATA[Quasy_Complete was staring at a spreadsheet. It was a beautiful, monstrosity of a spreadsheet. Twelve tabs. Three thousand rows. Formulas that stretched across columns like a digital snake eating its own tail. And in the center, a single cell that said: "SUM OF ALL MY REGRETS."

"Ah," he muttered. "The quarterly report. The document that turns coffee into anxiety and spreadsheets into nightmares. I need to show this to the board. But if I paste this into a public AI, the AI will learn my secrets, sell them to advertisers, and then use them to target me with ads for debt consolidation loans."

His neighbor, Mrs. Higgins, appeared at the door holding a stack of papers.

"Quasy! I have a problem! I need to show my book club the budget for the bake sale, but the numbers are messy! And I don't know how to make a pie chart without using a program that asks me to 'share my data with partners'!"

"Mrs. Higgins," Quasy said, "you're not alone. We live in an age where data is power, but privacy is a luxury item you have to pay extra for. Until now. Lumo has just updated. It can now turn your data into visuals. Charts. Graphs. Dashboards. All directly in the chat. And the best part? It's private. Unlike those other services that treat your financial data like a buffet."

She sat down, eyes wide. "So I don't have to upload my bake sale budget to a server in Virginia?"

"No. You upload it to Lumo. Which runs on zero-access encryption. Which means even Lumo can't see your data. It just processes it and gives you a chart. Like a magician who never sees the rabbit, only the hat."

From Raw Data to Insights (The Magic Trick)

Lumo doesn't just generate charts. It analyzes the information you provide and presents the results in the format that's most useful. Depending on the task, that can include charts, key metrics, summaries, comparisons, and callouts.

Quasy explained: "Imagine you paste a list of your monthly expenses. Instead of just saying 'You spent $2,000,' Lumo says 'You spent $2,000, and here's a bar chart showing your spending spiked in March because of a sudden obsession with artisanal pickles.' It highlights trends. It surfaces key findings. It turns a wall of text into a story."

Mrs. Higgins: "Can I ask follow-up questions?"

"Absolutely. You can refine the visual. Compare different perspectives. Explore another trend. All without starting over. It's like having a data analyst who never sleeps, never judges your pickle addiction, and never logs your conversation."

He illustrated: User: "Here's my sales data for Q1." Lumo: Generates a line chart showing a dip in February. User: "Why did sales drop in February?" Lumo: "Because you ran out of inventory on the 'Artisanal Pickle Starter Kit' on Feb 14th. Here's a comparison chart showing the correlation between stockouts and revenue loss." User: "Show me a forecast for Q2 if I restock." Lumo: Generates a projection graph. User: "Make it look professional." Lumo: Adjusts colors and labels.

"Messy data? Gone. Confusing numbers? Clarified. Insights? Delivered. All in one conversation."

Built for Real Business Data (The Secret Sauce)

The new feature is valuable for organizations. Financial reports, sales pipelines, customer data, board presentations, internal research. Sensitive information that teams are reluctant to upload to third-party AI services.

Quasy: "Most AI services log your chats. Train on your data. Share it with third parties or governments. If you upload your company's Q3 financial report to a public AI, you're essentially handing your CFO's salary data to a server farm in Silicon Valley and hoping they don't leak it."

He contrasted: "Lumo for Business is different. It's a private business AI assistant. Your information remains private by default. No record of your chats. Zero-access encryption. No AI training on your data. Protected under European law. Open source and independently verified. Built for regulated organizations. GDPR and HIPAA compliant. ISO 27001 and SOC 2 certified."

Mrs. Higgins: "So my bake sale budget is safe?"

"Safer than a vault in a bank. Because banks have guards. Lumo has math. And encryption. And a legal framework that says 'Thou shalt not spy on thy neighbor's data.'"

The Use Cases (What Can You Actually Do?)

Lumo can help you:

    Review financial performance: Turn revenue, budgets, and forecasts into charts that highlight trends.
    Analyze sales pipelines: Compare internal data without exposing customer info.
    Summarize operational metrics: Visual dashboards for KPIs.
    Explore internal reports: Turn lengthy documents into visual summaries.
    Research business questions: Visualizations for market trends and industry data.

Quasy: "Imagine a board meeting. Instead of a PowerPoint slide deck that took three days to make, you paste the raw data into Lumo. It generates the charts instantly. You ask, 'What if we cut marketing spend by 10%?' Lumo adjusts the forecast. You ask, 'How does this compare to last year?' Lumo overlays the trend. You ask, 'Why are we losing money?' Lumo points to the pickle line item. And nobody leaves the room wondering if their data was sold to a data broker."

Mrs. Higgins: "I can do that for the bake sale?"

"You can. Paste the budget. Ask for a pie chart of expenses. Ask for a bar graph of revenue vs. cost. Ask for a forecast of profit if you raise the price of cupcakes by $1. Lumo does it all. Privately. Instantly. Without asking you to create an account with a social media giant."

Private by Design (The Core Philosophy)

Data visuals are often created from sensitive information. Lumo for Business protects your information.

Quasy listed the pillars:

    No Record of Your Chats: Runs on no-logs infrastructure. Zero-access encryption. Only you can access your conversations, files, or visuals.
    No AI Training on Your Data: Lumo never trains models on your conversations. Your business data stays yours.
    Protected Under European Law: Built and operated in Switzerland. Strongest privacy laws. Shields data from government surveillance and third-party requests.
    Open Source and Independently Verified: Codebase is fully open source. Anyone can verify it works as promised.
    Built for Regulated Organizations: Supports GDPR and HIPAA. Backed by ISO 27001 and SOC 2 certifications.

He paused. "This is the difference between a tool and a service. A tool works for you. A service works on you. Lumo is a tool. It serves you. It doesn't harvest you."

Get Started (The Easy Part)

Custom visuals are available for everyone. Upload a spreadsheet. Paste structured data. Ask a question. When a visual helps, Lumo generates one automatically.

Quasy: "It's that simple. No complex setup. No enterprise license. No IT approval. Just paste your data. Ask your question. Get your chart. And sleep soundly knowing your data isn't being used to train a model that will eventually write a novel about your tax returns."

Conclusion: Data Is Power. Privacy Is Freedom.

Quasy_Complete closed his laptop. Mrs. Higgins was happily pasting her bake sale budget into the chat.

"Look!" she exclaimed. "It made a pie chart! And it highlighted that I spent too much on sprinkles! And it said 'Consider reducing sprinkles to increase profit margin'! It's genius!"

"It's data visualization," Quasy corrected gently. "But yes. Genius."

His phone buzzed. Notification: "Lumo: Your visual is ready. Revenue up 15%. Sprinkles down 40%. Profit margin optimized."

He smiled. "Finally. A tool that understands that data is not just numbers. It's a story. And the story should be private."

He looked at Mrs. Higgins. "So, how's the sprinkle situation?"

"Under control. Thanks to Lumo."

"And the privacy?"

"Locked down. No logs. No training. No spying. Just charts."

"Good. Because in 2026, the only thing more dangerous than a spreadsheet full of bad numbers is a spreadsheet full of bad numbers that someone else owns."

He opened his own data. Pasted it into Lumo. Asked for a trend analysis.

The chart appeared. Clean. Clear. Private.

No ads. No tracking. No data brokers. No government subpoenas. No "partners."

Just the data. And the insight. And the freedom to act on it.

Without fear. Without compromise. Without selling your soul to the cloud.

Which, in 2026, is the ultimate luxury.

A private chart. A private insight. A private future.

And no one watching.

Except maybe the sprinkles.

But they're just sprinkles.

They don't count.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 03 Aug 2026 13:15:54 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-62</guid><link>https://carlostkd.ch/roadmap/#post-62</link><title>Is Venmo safe?</title><description><![CDATA[Quasy_Complete was sitting in his kitchen when his phone buzzed. A notification from Venmo: "Sarah sent you $20 for pizza."

He didn't know a Sarah. He hadn't ordered pizza. And he certainly hadn't shared pizza with anyone named Sarah.

"Ah," he muttered. "Either someone sent money to the wrong person, or this is the beginning of a very modern scam."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was on fire.

"Quasy! My grandson asked me to send him $50 for his birthday! I used Venmo! But now the whole app can see that I sent $50 to a teenager with the note 'Happy Birthday sweetie '! His friends are laughing at him! And a stranger just requested $200 from me with the message 'you know what you did'!"

"Mrs. Higgins," Quasy said calmly, "you've just experienced two things simultaneously. One: Venmo's brilliant decision to make financial transactions visible on a social feed. Like a reality TV show where everyone can see your wallet. Two: a scammer testing whether you'll pay vague, threatening invoices from strangers."

She sat down heavily. "Venmo has a social feed?"

"Venmo HAS a social feed. A social feed. For money. Someone at Venmo headquarters sat in a meeting and said, 'What if banking... but social?' And nobody stopped them. Nobody said, 'Perhaps people don't want their financial transactions displayed like Instagram stories.' Nobody said, 'Maybe sending rent money shouldn't have an audience.' And now your grandson's birthday gift is public knowledge and a stranger is invoicing you for crimes you didn't commit."

What Is Venmo and How Does It Work? (The Bank That Thinks It's Twitter)

Venmo is a US-only peer-to-peer payment app owned by PayPal. You can send money, split payments, pay online, move money to your bank, get your paycheck early, send gift cards, and attach emojis to transactions.

Quasy read the feature list: "Send money. Split payments. Attach emojis. Social feed. So it's a bank. That's also a social network. That's also a gift card shop. That's also a payroll service. What could possibly go wrong with combining banking, social media, and emotional attachments?"

Mrs. Higgins: "I like the emojis! I sent my grandson a pizza emoji!"

"Did you also enjoy the fact that 47 strangers, three acquaintances, and a potential scammer now know that you sent $50 to a minor on a Tuesday? With a heart emoji? On a public feed?"

"The feed is public?"

"By DEFAULT it's friends-only now. After privacy issues reported by The Verge in May 2026. Before that? It was PUBLIC. As in, anyone on the internet could see your transactions. A stranger in another state could see that you paid your roommate for utilities. A coworker could see that you bought someone a coffee. Your ex could see that you sent $30 to someone they don't know at 2 AM. Venmo built a financial surveillance network disguised as a fun social app. And people used it. Willingly. Because emojis."

Is Venmo Safe to Use With Strangers? (No. Absolutely Not. What Are You Doing?)

Venmo is built for moving money between people who already know each other. Not strangers. In practice, many people use it to pay strangers selling items online.

Quasy imagined the marketplace scenario: Buyer: "I'd like to buy your used PlayStation for $300." Seller: "Great! Send me $300 on Venmo!" Buyer: "Shouldn't we use PayPal Goods and Services? Or Meta Pay? Something with buyer protection?" Seller: "No, no. Venmo is fine. Trust me." Buyer: Sends $300 via Venmo. Seller: Disappears. Deletes account. Blocks buyer. Moves to another state. Changes name. Buys a boat. Buyer: "Where's my PlayStation?" Venmo: "You sent money to a stranger with no buyer protection. The transaction can't be reversed. Have a nice day."

Mrs. Higgins gasped. "That's terrible!"

"That's the business model. Venmo personal payments carry NO buyer protection by default and CANNOT be reversed once accepted. If you pay a stranger, receive the wrong item, a damaged item, or nothing at all, you cannot get your money back. The money is gone. Like throwing cash into a black hole and hoping something comes back."

How to Protect Personal Payments (The 2.99% Tax on Trust)

Payments to approved business accounts are automatically protected. Personal payments are NOT covered unless you tag the transaction as a purchase. This incurs a 2.99% fee for the recipient.

Quasy: "So if you want protection, you have to tag it. If you tag it, the seller pays 2.99%. Some sellers will discourage you from tagging because of the fee. They'll say 'Trust me, bro. Just send it as friends and family.' And you know what? 'Trust me, bro' is not a legally binding contract."

He illustrated: Seller: "Don't tag it as a purchase. It charges me a fee." Buyer: "But if I don't tag it, I have no protection." Seller: "I'm honest! Look at my profile! I have five stars!" Buyer: "You also created this account yesterday and have no transaction history." Seller: "...Send the money as friends and family." Buyer: "Absolutely not. Tag it as a purchase or I'm using PayPal." Seller: Vanishes.

Mrs. Higgins: "What if they insist?"

"If they insist on no buyer protection, THAT is your red flag. A legitimate seller who refuses protection is either hiding something or planning to take your money and run. Purchase Protection protects sellers too — if they can produce proof of shipment and delivery. A seller who refuses protection is a seller who cannot produce proof. Because there is no proof. Because there is no shipment. Because there is no item. There is only your money and their disappearance."

How to Spot Scams on Venmo (The Three-Headed Hydra)

Venmo acknowledges users may be targeted by scams. Three common ones:

Scam 1: "You've Won Money!" (The Classic Bait)

You receive an email or text saying you've won money through Venmo. It includes a phishing link.

Quasy: "You've won money! In a lottery you never entered! Through a payment app! All you need to do is click this link and enter your Venmo login! What could go wrong? Everything. Everything could go wrong."

He illustrated: Email: " Congratulations! You've won $500 from Venmo Rewards! Click here to claim!" Victim: "I won! Let me click!" Phishing Page: Looks exactly like Venmo. Asks for username and password. Victim: Enters credentials. Hacker: "Thank you. I'll take it from here." Victim's Venmo: Balance: $0. Transactions: Three payments to 'Greg_Gaming_Pro_99.' None initiated by the victim.

Mrs. Higgins: "Who falls for that?"

"Millions of people. Because the email looks real. The logo is correct. The colors match. The only thing that's fake is the URL. Which is 'venmo-rewards-claim-secure-portal.xyz' instead of 'venmo.com.' One letter off. One domain different. And your bank account is empty."

Scam 2: "This Is Venmo Calling" (The Verification Code Heist)

Someone calls claiming to be from Venmo. They ask you to make a payment or share your 2FA code.

Quasy: "Venmo will NEVER call you and ask for your verification code. Never. Not once. Not ever. If someone calls you claiming to be Venmo and asks for a code, hang up. Block the number. Delete the contact. Change your password. Enable 2FA. And maybe move to a different area code."

He illustrated: Caller: "Hi, this is Venmo Support. We detected suspicious activity on your account. Can you please read me the code we just sent to your phone?" Victim: "Oh no! Of course! The code is 4-8-2-9-1-7." Caller: "Thank you. Your account is now... mine." Victim: "Wait—" Caller: Click.

Mrs. Higgins: "They just take the code and steal the account?"

"The code IS the key. 2FA codes are designed to prove you're you. If you give that code to a stranger, you've just proved that THEY are you. To Venmo's servers. And now they can reset your password, change your phone number, and empty your balance. All because you answered a phone call and read six digits to a stranger."

Scam 3: The Friend Impersonator (The Duplicate You)

You get a payment request from someone who looks like your friend. Same username. Same profile picture. Same social feed. But it's not your friend.

Quasy: "A scammer copies your friend's username, profile picture, and social feed details. Creates a near-identical profile. Sends you a payment request for $150 with an urgent message: 'Hey, need help with rent ASAP! Pay you back Friday!'"

Mrs. Higgins: "How do I tell the difference?"

"Double-check. Look at their public transaction history. Check the username letter by letter. Is it 'John_Smith' or 'John_Srnith'? One letter different. One character swapped. And if you're still not sure? Text your friend. Outside Venmo. 'Hey, did you just ask me for $150 on Venmo?' If they say no, you just avoided sending $150 to a stranger who spent twenty minutes copying your friend's profile."

How to Use Venmo Safely (The Survival Guide)

Quasy listed the rules:

    Tag purchases made via personal accounts as purchases. This ensures Purchase Protection. Yes, it costs the seller 2.99%. That's the price of trust. Pay it. Or lose everything.

    Set transaction visibility to private. Not friends. Not public. PRIVATE. Your finances are not content. Your rent payment is not a social post. Your birthday gift to your grandson is not for public consumption. Settings → Privacy → Past Transactions → Set to Private. Do it now. I'll wait.

    Verify identities through a second channel. Text. Call. Email. Smoke signal. Carrier pigeon. ANYTHING other than the Venmo app itself. If someone is asking for money urgently through Venmo, verify OUTSIDE Venmo.

    Use a password manager. Generate a strong, unique password for Venmo. If one breach exposes your password, the attacker doesn't get the keys to your financial kingdom.

    Use an email alias. Create a unique email address for Venmo. If Venmo gets breached, your real email stays safe. The alias forwards to your real inbox. You can disable it anytime.

    Use a VPN. Public WiFi + financial transactions = disaster. A VPN encrypts your connection. Nobody on the same network can see your session. Your banking stays private.

Mrs. Higgins was writing furiously. "Tag purchases. Set to private. Verify outside. Password manager. Email alias. VPN. Got it."

"You forgot the most important one."

"What?"

"Don't send money to strangers. Ever. For any reason. Under any circumstances. Even if they seem nice. Even if they promise to ship the item. Even if they have a verified profile. If you don't know them in real life, don't send them money through Venmo."

Secure Your Passwords and Privacy with Proton (The Real Shield)

Proton Pass generates strong, unique passwords for every account — including Venmo. If one password leaks, they don't all leak. It sets up email aliases. If Venmo gets breached, attackers don't have the keys to your primary inbox. And it only autofills logins on recognized websites — so it won't hand your password to a domain that isn't venmo.com.

Quasy: "This last point is crucial. Phishing pages look like Venmo. They feel like Venmo. But the URL is 'venmo-secure-login-portal.xyz.' Proton Pass won't autofill on that domain. Because it's not Venmo. It's a trap. And Proton Pass recognizes traps."

Proton VPN encrypts your connection whenever you're using Venmo or any other app. Blocks ads and malware trackers.

Both Proton Pass and Proton VPN are protected by zero-access encryption. Not even Proton can access your passwords.

Conclusion: Venmo Is as Safe as You Make It (Which Means: Not Very, Unless You Try)

Quasy_Complete looked at Mrs. Higgins. She was carefully adjusting her Venmo privacy settings, tagging purchases, and verifying her grandson's identity via text message.

"Done," she announced. "Private. Tagged. Verified."

"Good. Now your transactions are invisible, your purchases are protected, and your grandson is confirmed as your grandson and not a stranger named Greg from a marketplace listing."

His phone buzzed. Venmo notification: "Greg_Gaming_Pro_99 requested $200. Note: 'you know what you did'"

Quasy stared at the screen. Then looked at Mrs. Higgins. Then looked at the ceiling.

"Greg is back," he said.

"Who is Greg?"

"Greg is nobody. Greg is a ghost. Greg is a username attached to a scammer who sends vague, threatening payment requests hoping someone will pay out of confusion or fear. Greg doesn't know what you did. Greg doesn't even know who you are. Greg is fishing. And the bait is 'you know what you did.'"

Mrs. Higgins: "Should I pay him?"

"Mrs. Higgins. If you pay Greg, you are the answer to every scammer's prayer. You are the reason they keep trying. You are the reason Greg exists. Greg is not a person. Greg is a business model. A business model that only works because somewhere, someone, sometime, paid a vague invoice out of guilt."

He declined the request. Blocked the user. Reported the account. Changed his Venmo password via Proton Pass. Set all past transactions to private. Verified his 2FA.

His phone buzzed again. Venmo notification: "Sarah sent you $20 for pizza."

Quasy read it. Looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling AGAIN, as if it might offer guidance from a higher power.

"Sarah," he said slowly. "I don't know a Sarah. I haven't ordered pizza. And this is the second time Sarah has sent me $20 for a pizza I didn't eat."

"Maybe it's a mistake?"

"Or maybe it's a test. A probe. Sarah sends $20. If I accept, Sarah requests $200 back with a sob story. 'Oops, I sent it to the wrong person! Can you send it back? I need it for rent!' If I send it back, Sarah disappears. And I've lost $200. Because I was nice. Because I was helpful. Because I was human. And scammers love humans."

He declined the $20. Blocked Sarah. Reported the account.

"Venmo is safe," he summarized, "if you know exactly who you're paying, you've tagged it as a purchase, your privacy is set to private, your password is unique, your email is aliased, and your VPN is running. Otherwise? You're sending cash into a social media platform and hoping for the best."

Mrs. Higgins stood up. "I'm going to check my past transactions."

"Set them ALL to private. Every single one. Your pizza payments. Your rent splits. Your birthday gifts. All private. Because your finances are not content. Your money is not a post. And your grandson's birthday gift is not a public event."

She left. Determined. Armed with privacy settings and Proton Pass.

Quasy sat alone. His phone was quiet. No notifications. No payment requests. No vague invoices from Greg.

He opened Proton Pass. Checked his Venmo password. It was 24 characters of randomized gibberish. Impossible to crack. Impossible to guess. Impossible to phish. Because Proton Pass only autofilled on venmo.com. Not on venmo-secure-portal.xyz. Not on venmo-rewards-claim.net. Not on venmo-login-verify-account.info. Only venmo.com.

"Safe," he whispered. "For now."

His phone buzzed one last time. Venmo notification: "Your friend John just paid Mike $40 for 'kombucha.' View it on your feed."

Quasy stared at the notification. John paid Mike. For kombucha. And Venmo told him about it. Because Venmo believes that financial transactions are social events. That money is content. That privacy is a setting, not a default.

"John likes kombucha," Quasy muttered. "I didn't need to know that. John didn't want me to know that. Mike probably didn't want me to know that. But Venmo decided I should know. Because Venmo is a bank that thinks it's Twitter."

He set his feed to private. Closed the app. Put the phone down.

Somewhere in a server farm, a social feed updated. John paid Mike $40 for kombucha. 37 friends saw it. 3 strangers saw it. 1 scammer saw it. And Greg took notes.

Because in 2026, your money is social. Your privacy is optional. And Greg is always watching.

Welcome to Venmo. Where banking meets broadcasting. And your rent payment has an audience.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 26 Jul 2026 17:46:46 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-54</guid><link>https://carlostkd.ch/roadmap/#post-54</link><title>Is Malwarebytes Safe?</title><description><![CDATA[Quasy_Complete was sitting in his living room when his computer started making a noise like a dying lawnmower. He looked at the screen. A popup appeared: "CRITICAL VIRUS DETECTED! CLICK HERE TO FIX NOW!"

He stared at it. Then he stared at the ceiling. Then he stared at the screen again.

"Ah," he muttered. "The classic 'You Have a Virus' virus. The most effective malware disguise of all time. It preys on fear. It preys on ignorance. It preys on the fact that most people don't know the difference between a security tool and a scam."

His neighbor, Mrs. Higgins, appeared at the door holding her laptop like it was a radioactive isotope.

"Quasy! My computer says it has a virus! It says I need to download Malwarebytes immediately! But isn't Malwarebytes also malware? I read somewhere that fake antivirus apps are a thing!"

"Mrs. Higgins," Quasy said calmly, "Malwarebytes is real. It's legitimate. It's highly rated by PC Mag, CNET, and Trustpilot. It's safe to download if you get it from the official site. But here's the catch: the free version is a scanner, not a shield. It cleans up the mess after the house burns down. It doesn't stop the arsonist from lighting the match."

She sat down heavily. "So it's a fire extinguisher?"

"Exactly. A very good fire extinguisher. But if you only have a fire extinguisher and no smoke detector, no sprinkler system, and no fireproof walls, you're still going to lose your house. And Malwarebytes Free is just the extinguisher. The shield? That costs extra."

What Is Malwarebytes? (The Digital Janitor)

Malwarebytes is cybersecurity software designed to detect, block, and remove malicious threats. Most people use the free version, which is a scan-on-demand tool.

Quasy explained: "The free version checks files already on your device. It finds malware. It removes it. It's retrospective. It's like a janitor who comes in after the party and sweeps up the broken glass. But the party is over. The guests are gone. The damage is done. Ransomware might have encrypted your files. Spyware might have stolen your data. The janitor can sweep up the glass, but he can't un-break it."

Mrs. Higgins: "So if I have a virus, Malwarebytes fixes it?"

"It removes the virus. But it doesn't undo the damage. If your photos were encrypted, they're still encrypted. If your passwords were stolen, they're still stolen. The virus is gone. The consequences remain."

Why a Scan Isn’t the Same as Protection (The Difference Between Cleaning and Guarding)

Full antivirus protection continuously monitors and blocks threats in real time. It catches malware before it installs. Malwarebytes charges for this.

But you probably already have real-time protection built in:

    Windows: Microsoft Defender + Firewall.
    macOS: XProtect.
    Android: Google Play Protect.

Quasy: "These are free. They are built-in. They are always on. They are the smoke detectors and sprinklers. Malwarebytes Premium is an extra layer. A second opinion. A backup guard. But it's not the only guard you need."

He paused. "And even with real-time protection, you're not safe. New threats emerge every day. Before the databases update, the malware slips through. And human error? If you download a sketchy app or grant permission to a shady service, no antivirus can save you. You have to be smart. You have to be careful. You have to be paranoid."

Five Free Habits to Close the Security Gaps (The Real Shield)

Here are five rules that provide protection no antivirus app can:

    Keep Your OS and Apps Updated: Updates patch vulnerabilities. Neglecting them gives cybercriminals a backdoor with a key they already have. Turn on automatic updates. Now. Quasy: "Updates are annoying. They take time. They change things. But they close the holes. Without them, your door is wide open. And the burglars are waiting."

    Do Your Due Diligence Before You Install: Download apps from the developer's official site. On mobile, use official stores. Check the developer's name. See what else they've published. Find their website. Quasy: "If the developer is 'SuperCoolAppDev123' with no other apps and a website that looks like it was made in 1999, don't install it. If the app is on the Play Store but the developer has 50 other apps that are all scams, don't install it. Be skeptical. Be paranoid. Be alive."

    Use Strong Passwords (and Don’t Reuse Them): Short, predictable passwords are easy to crack. Reusing them across accounts is a disaster. One exposed password compromises everything. Use a password manager to generate unique, strong credentials. Quasy: "If you use 'Password123' for your email, bank, and social media, and one gets breached, you lose everything. A password manager creates a unique key for every door. One lock breaks? The others stay locked. It's the difference between a fortress and a cardboard box."

    Use Email Aliases: Your inbox is a target. An email alias gives you a disposable address for each service. If a company gets breached, you disable the alias. Your real inbox stays safe. Quasy: "It's like giving every store a different credit card number. If one number gets stolen, you cancel that card. The others work. Your real identity stays hidden. Spam disappears. Breaches become manageable. It's digital camouflage."

    Use a VPN: Public networks are unencrypted. Anyone can see what you're doing. A VPN encrypts your connection. Traffic becomes scrambled. Unexploitable. Quasy: "Public WiFi is like writing your bank password on a postcard and handing it to a stranger. A VPN puts the postcard in a steel box. The stranger can see the box. They can't open it. They can't read it. They can't steal it."

Prevention Starts with a Secure VPN and Password Manager (The Proton Pitch)

Malwarebytes cleans up what's already there. Proton VPN and Proton Pass make sure there's less to clean up.

Malwarebytes VPN (Privacy VPN):

    Requires a $79.98/yr subscription to Malwarebytes Plus.
    Operates under US jurisdiction (subject to CLOUD Act).
    Passed only one independent audit (2026), which flagged a critical vulnerability.

Proton VPN:

    Free to use.
    Under Swiss jurisdiction (no mandatory data retention, not subject to CLOUD Act).
    Passed five consecutive annual independent audits.

Quasy: "Malwarebytes VPN is expensive. It's US-based. It's subject to government compulsion. It had a critical vulnerability flagged in its only audit. Proton VPN is free. It's Swiss. It's audited five times. It's secure. It's private. It's the better choice. Unless you love paying for less security."

Proton Pass:

    Generates strong passwords.
    Autofills credentials.
    Offers email aliases (10 free, unlimited with Plus).
    Zero-knowledge encryption. Not even Proton can access your credentials.

Quasy: "Proton Pass contains the damage. If one account is breached, the others stay safe. The vault is private. The keys are yours. The encryption is real. It's not just a tool. It's a strategy."

Conclusion: Malwarebytes Is a Tool, Not a Solution

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence, staring at her screen.

"So Malwarebytes is safe," she said slowly. "But it's not enough."

"Correct. It's a janitor. A fire extinguisher. A cleanup crew. It's helpful. It's necessary if you're already infected. But it's not a shield. It's not a guard. It's not a prevention strategy."

He stood up. "To be safe, you need more. You need updates. You need due diligence. You need strong passwords. You need email aliases. You need a VPN. You need a password manager. You need to be smart. You need to be careful. You need to be proactive."

He looked at her. "Malwarebytes cleans up the mess. Proton prevents the mess. Which do you want?"

She thought about it. "I want to prevent the mess."

"Then start with Proton Pass. Then Proton VPN. Then updates. Then due diligence. Then aliases. Then you'll be safe. Not because of a scanner. Because of a strategy."

His phone buzzed. Notification: "Malwarebytes: Your scan is complete. No threats found."

Quasy smiled. "Good. But remember: no threats found today. Tomorrow is a new day. Tomorrow, new threats emerge. Tomorrow, new vulnerabilities appear. Tomorrow, you need to be ready."

He opened Proton Pass. Generated a new password. Saved it. Closed the app.

"Safe," he whispered. "Not because of a scan. Because of a plan."

And if anyone tried to infect his device? They'd find a locked door. A unique key. An encrypted tunnel. And a janitor who never needed to sweep.

Because the house was never on fire in the first place.

Which, in 2026, is the best kind of victory.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Sun, 26 Jul 2026 17:12:29 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-53</guid><link>https://carlostkd.ch/roadmap/#post-53</link><title>What Does Google Know About You? The Chilling Truth (Or, How a Search Engine Became the World’s Most Nosy Landlord Who Also Owns Your Toaster, Your Watch, and Your Dreams)</title><description><![CDATA[Quasy_Complete was sitting in his kitchen, staring at a blank search bar. He had typed the words: "What does Google know about me?"

He hit Enter.

The screen loaded instantly. A list of results appeared. The top result was an ad for a new vacuum cleaner. The second was a link to a blog post titled "10 Ways to Hide From Google (Spoiler: You Can’t)." The third was a map showing his current location with a pin labeled "Quasy_Complete is Here (And Probably Drinking Coffee)."

"Ah," Quasy muttered. "It knows I’m asking what it knows. And it knows I’m drinking coffee. And it knows I’m in my kitchen. And it knows I’m thinking about vacuum cleaners because I saw an ad for one three days ago. It’s a self-fulfilling prophecy of surveillance."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was a bomb.

"Quasy! I asked Google what it knows about me! It sent me a file! A huge file! It has everything! My search history from 2014! My location history! My voice recordings! It even knows I bought a toaster that talks to my fridge!"

"Mrs. Higgins," Quasy said calmly, "Google doesn’t just know you bought a talking toaster. It knows what you said to the toaster. It knows when you said it. It knows how loud you said it. And it knows that you’re now worried because Google knows you’re worried. It’s a loop. A digital Ouroboros eating its own tail."

She sat down heavily. "Is it safe?"

"Safe? No. Safe implies privacy. Privacy implies boundaries. Google has no boundaries. It has no walls. It has no doors. It has only data. And it eats data for breakfast, lunch, and dinner. And snacks in between."

Understanding Google’s Reach: The List That Never Ends

Google knows a lot. It knows where you’ve been on the internet. It knows where you’ve been in real life. It knows what you typed but changed your mind about. It knows your drafts. It knows your unsent emails. It knows your voice. It knows your health data. It knows your calendar. It knows your photos. It knows your YouTube history. It knows your income bracket. It knows if you’re single. It knows if you rent. It knows if you have kids (or don’t).

Quasy read the list aloud like a grim prophecy:

    Calendar: Your schedule, meetings, who you’re with, where you’re going.
    Web & App Activity: Every site you visit. Every app you use. How often.
    Photos: Where they were taken. Who is in them. Even your children.
    Documents: How you write. What you write about.
    Search History: Even the things you typed and deleted.
    Emails: Even the ones you never sent.
    Voice: How you sound. How you talk. If you use Google Home, Nest, or Assistant.
    Maps History: Every route you take. Every destination. Every timestamp.
    YouTube History: What you watch. How long you watch it. From cooking videos to "how to change a tire."

He paused. "When you put it all together, Google doesn’t just know you. It understands you. It builds a profile so detailed it could write your biography. It could predict your next move. It could guess your next breakup. It could calculate your next job interview. It could even guess what you’ll dream about tonight."

Mrs. Higgins: "That’s terrifying."

"It’s not terrifying. It’s business. Surveillance capitalism. The business model of the 21st century. You are not the customer. You are the product. Your data is the commodity. Your attention is the currency. And Google is the bank."

How to Find Out What Google Knows About You (The Moment of Truth)

You can’t ask Google what it knows and get an honest answer. But you can go to your Google Account → Data and Privacy. There, you’ll see everything.

    Web and app activity.
    Maps timeline.
    YouTube backlog (down to the day).
    Health data (if you use Fitbit, which Google bought in 2021).
    Voice Match data (your voice, your thumbprint, your identity).

Quasy: "You can download your data. A massive file. Gigabytes of your life. Your search history. Your location history. Your voice recordings. Your photos. Your emails. Your drafts. Your unsent messages. Your voice commands. Your health stats. Your sleep cycles. Your heart rate. Your steps. Your weight. Your menstrual data. All of it. In one zip file."

Mrs. Higgins: "I downloaded mine. It was 40 gigabytes."

"Forty gigabytes. That’s your life. Compressed. Archived. Stored. Waiting. For whom? For Google? For advertisers? For data brokers? For the US government? For cybercriminals? For anyone who can hack the server? Or anyone who buys the data? Or anyone who gets a subpoena? Or anyone who just wants to know what you had for breakfast on a Tuesday in 2019?"

Google Knows Things You Never Shared (The Mind-Reading Machine)

A Proton employee once asked, "What does Google know about me?" She found Google knew she was recently single. She never told Google. It knew her income bracket. She never told Google. It knew where she lived. She never told Google. It knew she didn’t have kids. She never told Google. It knew she rented an apartment. She never told Google.

Quasy: "Google doesn’t need you to tell it anything. It infers. It guesses. It predicts. It connects dots you didn’t even know existed. It sees patterns. It sees correlations. It sees trends. It sees you. Even if you never clicked a button. Even if you never filled out a form. Even if you never said a word. It knows."

He illustrated: User: "I didn’t tell Google I’m single." Google: "But you searched for 'dating apps' three times last week. You visited 'match.com' twice. You watched a video on 'how to get over a breakup.' You liked a post about 'being alone is okay.' You bought a bottle of wine on Amazon. You ordered takeout for one. You didn’t post on social media for two weeks. You deleted your Instagram story. You searched for 'signs you’re lonely.' You searched for 'how to meet people.' You searched for 'best bars in town.' You searched for 'dating advice.' You searched for 'single life.' You searched for 'loneliness.' You searched for 'depression.' You searched for 'therapy.' You searched for 'meditation.' You searched for 'self-care.' You searched for 'happiness.' You searched for 'love.' You searched for 'heartbreak.' You searched for 'moving on.' You searched for 'new beginnings.' You searched for 'fresh start.' You searched for 'hope.' You searched for 'future.' You searched for 'tomorrow.' You searched for 'today.' You searched for 'now.' You searched for 'me.' You searched for 'I.' You searched for 'you.' You searched for 'we.' You searched for 'us.' You searched for 'them.' You searched for 'they.' You searched for 'it.' You searched for 'this.' You searched for 'that.' You searched for 'here.' You searched for 'there.' You searched for 'where.' You searched for 'when.' You searched for 'why.' You searched for 'how.' You searched for 'what.' You searched for 'who.' You searched for 'which.' You searched for 'whose.' You searched for 'whom.' You searched for 'whatever.' You searched for 'whenever.' You searched for 'wherever.' You searched for 'however.' You searched for 'whoever.' You searched for 'whichever.' You searched for 'whomever.' You searched for 'whatsoever.' You searched for 'whensoever.' You searched for 'wherever.' You searched for 'howsoever.' You searched for 'whosoever.' You searched for 'whichsoever.' You searched for 'whomsoever.' You searched for 'whatsoever.' You searched for 'whensoever.' You searched for 'wherever.' You searched for 'howsoever.' You searched for 'whosoever.' You searched for 'whichsoever.' You searched for 'whomsoever.'"

Quasy stopped. "See? It knows. Even if you didn’t say it. Even if you didn’t think it. Even if you didn’t feel it. It knows."

The Link Between Surveillance Capitalism and Google (The Business Model of Watching You)

Google isn’t just a tech company. It’s an advertising juggernaut. Its main revenue source is ads. Advertisers tell Google who they want to reach. Google shows them ads to those people.

Quasy: "Google has so much data it’s become the largest engineer of the ad surveillance industry. It gives users the illusion of choice. 'Personalized ads' sound friendly. 'Make your ads more relevant.' But it’s not friendly. It’s predatory. It’s invasive. It’s manipulative. It uses your location, sexual orientation, hobbies, income bracket, health data, voice, photos, documents, emails, search history, YouTube history, Maps history, calendar, voice, health, voice, voice, voice... to influence your decisions. To make you buy things. To make you click things. To make you watch things. To make you think things. To make you feel things. To make you be things."

Mrs. Higgins: "So I’m being manipulated?"

"You’re being targeted. You’re being profiled. You’re being sold. You’re being watched. You’re being recorded. You’re being analyzed. You’re being predicted. You’re being influenced. You’re being controlled. You’re being owned. By Google. By advertisers. By data brokers. By the US government. By cybercriminals. By anyone who can access the data. Anyone. Everyone. Nobody. Nobody is safe. Nobody is private. Nobody is anonymous. Nobody is free."

Google’s Ad System Is Designed This Way on Purpose (The Real-Time Bidding Nightmare)

Google uses "real-time bidding" (RTB) to auction off your data to the highest bidder.

Quasy explained: "First, Google builds a profile on you. Then, it broadcasts that data to thousands of companies. They compete in an auction to buy ad space. Your data is exposed to thousands of advertisers in nanoseconds. It falls into the hands of data brokers. Cybercriminals. The US government. Anyone. Each time you see a targeted ad, your personal information is exposed. This fuels government surveillance. Poses national security risks. Gives data brokers easy access to your online activity."

He illustrated: Advertiser: "I want to reach people who are single, rent apartments, earn $50k-$70k, live in San Francisco, and watch cooking videos." Google: "Here’s a list of 10,000 people who match that profile. Including their names, addresses, phone numbers, emails, voice recordings, health data, search history, YouTube history, Maps history, calendar, photos, documents, emails, drafts, voice, voice, voice..." Advertiser: "Perfect. Bid accepted." User: Sees an ad for a dating app. User: "How did they know I’m single?" Google: "We know everything. We always know everything. We will always know everything. We will always be watching. We will always be listening. We will always be recording. We will always be analyzing. We will always be predicting. We will always be influencing. We will always be controlling. We will always be owning. We will always be Google."

Leave Google Behind, Starting With Email (The Only Way Out)

Every piece of personal data Google touches routes back to your Google account. A single login ties your entire digital footprint into one profile. Deleting your Google account is a great way to become safer.

The best place to start is email. Your inbox is the master key to your digital life. Linked to your bank, subscriptions, social media, work accounts. Whoever controls your email can reset your passwords. Piece together a detailed picture of who you are.

Quasy: "Proton Mail is a natural first step. It protects your messages with end-to-end encryption. Zero-access encryption. We never have access to your data. We can’t scan it. We can’t build behavioral profiles. We can’t show ads. We can’t train AI models. We can’t share it with third parties. And we don’t want to."

Mrs. Higgins: "So I should switch?"

"Start with email. Then search. Then maps. Then photos. Then voice. Then health. Then calendar. Then documents. Then YouTube. Then everything. De-Google your life. One service at a time. Each replacement is a brick removed from the wall. Each alternative is a window opened. Eventually, the wall comes down. And the light comes in."

Conclusion: Google Knows Everything (But It Doesn't Have To)

Quasy_Complete closed his laptop. Mrs. Higgins sat in stunned silence, her phone face-down on the table like a suspect being interrogated.

"So Google knows I'm single," she said quietly. "It knows my income. It knows where I walk. It knows what I watch. It knows how I sound. It knows my health. It knows my drafts. It knows things I never told it."

"And it sold all of that to strangers. Thousands of them. In nanoseconds. Via real-time bidding. Every time you saw a targeted ad, your personal information was broadcast to advertisers, data brokers, and potentially cybercriminals and government agencies. Not because you agreed. Not because you consented. Because you existed. And existing, in Google's world, means being monetized."

Mrs. Higgins picked up her phone. "What do I do?"

"Disable personalized ads at myadcenter.google.com. Turn off tracking for Web & App Activity, Timeline, Play History, and YouTube History at myactivity.google.com. Download your data. See what they have. Then start leaving."

"Leaving to where?"

"Proton Mail for your email. End-to-end encrypted. Zero-access. No scanning. No profiling. No ads. No AI training. No real-time bidding. No broadcasting your life to thousands of companies in nanoseconds."

He opened Proton Mail on his own laptop. The inbox was clean. Encrypted. Private. No ads. No tracking. No surveillance. Just email. The way email was supposed to be.

"See?" he said. "No ads for vacuum cleaners. No targeted suggestions. No creepy predictions about my relationship status. Just messages. Mine. Private. Encrypted."

Mrs. Higgins stood up. "I'm going to de-Google."

"Start with email. It's the master key. Once you control your inbox, you control your identity. Once you control your identity, you control your data. Once you control your data, you control your life."

"Is it hard?"

"No. It's just different. Like moving to a new city. The first week is confusing. The second week is familiar. The third week is home."

His phone buzzed. Notification from Google: "We noticed you've been inactive! Here's a summary of what you missed: 14 ads, 3 location tracking alerts, and a personalized suggestion based on your recent search for 'how to leave Google.'"

Quasy stared at the notification. Then laughed. A slow, tired, knowing laugh.

"They know I'm leaving," he said. "They can see me packing."

"Is that bad?"

"It's inevitable. They see everything. They always have. But seeing someone leave and stopping them from leaving are two different things. They can watch me walk away. They cannot make me stay."

He closed the notification. Opened Proton Mail. Composed a new email to Mrs. Higgins using his Proton address.

Subject: Welcome to the other side. Body: Your inbox is yours now. Nobody is reading it. Nobody is scanning it. Nobody is selling it. Welcome home.

Mrs. Higgins received the email. Read it. Smiled.

Then she opened her Google account settings. Downloaded her data — 40 gigabytes of her life, compressed and archived. She looked at the file. A digital biography written without her consent.

She deleted her Google account.

The screen confirmed: "Account deleted. Your data will be removed from our active servers."

"Active servers," Quasy noted. "Not backup servers. Not archival servers. Not 'servers we forgot about in a basement in Oregon.' Active servers. The fine print is always where the ghosts live."

But the account was gone. The master key was destroyed. The single login that tied her entire digital footprint together was severed.

Mrs. Higgins put her phone down. "It feels quiet."

"That's what privacy sounds like. Quiet. No ads. No tracking. No targeting. No profiling. No real-time bidding wars over your personal life. Just silence. Encrypted silence."

His phone buzzed one last time. Notification: "Proton Mail: You have 1 new encrypted message."

Quasy smiled. "And THAT is what email was supposed to be. A message. From someone. To you. Private. Encrypted. Yours."

He opened it. Read it. Closed it.

Somewhere in Mountain View, a server hummed. Inside it, Quasy_Complete's profile flickered. Dimming. Fragmenting. Disappearing.

Not entirely. Not immediately. Data has inertia. It persists. Like footprints in wet concrete. But accounts can be closed. Keys can be changed. Habits can be redirected.

And Quasy_Complete was redirecting.

One service at a time. One encrypted message at a time. One step away from the machine that knew he was single before he did.

The machine would survive. It always survives. But it would survive without him.

And that, in 2026, was the most radical act available.

Not protesting. Not petitioning. Not complaining.

Simply leaving.

Quietly. Encrypted. And taking your data with you.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Tue, 21 Jul 2026 18:42:59 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-52</guid><link>https://carlostkd.ch/roadmap/#post-52</link><title>How to Stop Drowning in Newsletters From Foot Locker While Missing Your Boss&apos;s Urgent Message About the Q3 Report</title><description><![CDATA[Quasy_Complete stared at his inbox. Three thousand four hundred and twelve unread emails. The number glowed at him like a digital scarlet letter. A badge of shame. A monument to procrastination.

He scrolled. A coupon from a shoe store he visited once in 2023. A newsletter about gardening tips he never signed up for. Seventeen LinkedIn notifications. A receipt for something called a "Smart Toaster" he didn't remember buying. And somewhere, buried under fourteen layers of digital sediment, an email from his boss marked "URGENT" sent four days ago.

"Ah," he said to no one. "I've achieved peak inbox chaos. My inbox isn't a communication tool anymore. It's an archaeological dig site. Every layer tells a story. The top layer: retail therapy regrets. The middle layer: newsletters I subscribed to during moments of optimistic self-improvement. The bottom layer: emails that actually mattered, fossilized under thousands of messages about Black Friday sales that ended months ago."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was contaminated.

"Quasy! I have nine thousand unread emails! I can't find my electric bill! I know it's in there somewhere! I've been scrolling for an hour!"

"Mrs. Higgins, you're not looking for a needle in a haystack. You're looking for a needle in a haystack factory. During peak production season. While the factory is on fire."

"What do I do?"

"You set up email filters. Automated sorting rules that organize your inbox so you never have to manually dig through nine thousand emails again. Unless you enjoy the thrill of the hunt. In which case, carry on."

What Are Email Filters? (The Digital Secretary You Can't Afford But Desperately Need)

Email filters are rules you assign to incoming emails to automatically sort your inbox. They scan subject lines, sender addresses, keywords, and attachments. Once a filter is set, emails are labeled, sorted, archived, or deleted based on criteria you've defined.

Quasy explained the concept: "Think of a filter as a bouncer at a nightclub. The bouncer stands at the door. He checks IDs. He decides who gets in, who goes to the VIP section, who waits in line, and who gets thrown out entirely. You set the rules. The bouncer enforces them. Automatically. Twenty-four hours a day. Without coffee breaks or complaints."

Mrs. Higgins: "So the filter reads my emails for me?"

"It reads enough to categorize them. It checks who sent it. What the subject says. What keywords appear. Then it acts. Newsletter? Archive. Receipt? Label it 'Receipts.' Email from your boss? Mark as important. Email from Foot Locker? Delete. Automatically. Forever."

He paused. "For small businesses, this is especially helpful. A well-built filter removes clutter and prevents important emails from falling through the cracks. No more missing client inquiries because they were buried under fifty promotional emails about flash sales."

How Email Filters Work (The Mechanics of Digital Triage)

Filters scan emails for criteria you set: sender name, email address, subject, keywords, attachments. When a message meets the criteria, the filter performs an action: archive, mark as read, apply a label, delete, mark as important.

In addition to custom filters, Proton Mail's smart spam filters detect spam and learn from your actions. The more you click "Move to spam" or mark emails as safe, the better the filters become. You can whitelist trusted senders or block unwanted addresses outright.

Quasy: "Proton's spam filters are like guard dogs that attend training school every day. Every time you mark something as spam, the dog learns. 'Ah, this smell is bad. I'll bark next time.' Every time you mark something as safe, the dog relaxes. 'This smell is fine. I'll let it through.' Eventually, the dog knows exactly what to catch and what to let through. Without you saying a word."

Mrs. Higgins: "And the custom filters?"

"Those are YOUR dogs. You train them. You decide what they fetch, what they ignore, and what they bury in the backyard."

How to Organize Email With Filters (The Art of Digital Feng Shui)

Start by building filters around categories that already exist in your inbox: newsletters, receipts, client threads, internal memos. Layer in folders and color-coded labels so every filtered message lands somewhere useful instead of just out of sight.

Quasy listed his own filter system:

    Newsletters: Automatically labeled and archived. Not in the main inbox. Read when I feel like it. Which is never.
    Receipts: Labeled "Receipts" and filed in a folder. For tax season. When I'll pretend to organize them and then panic in April.
    Client Emails: Labeled by client name. Priority marking enabled. So I never miss an email from someone who pays me.
    Internal Memos: Labeled "Internal" and marked as read. Because internal memos are the inbox equivalent of elevator music. Present. Technically important. Completely ignorable.
    Foot Locker: Deleted. Automatically. Forever. Without mercy.

Mrs. Higgins: "Good email organization is an ongoing system, not a one-time project."

"Exactly. Once your filters are in place, revisit them periodically. Habits change. Projects end. New clients arrive. Old newsletters multiply like rabbits. Your filters should evolve with your inbox. And Proton's spam filters keep doing the heavy lifting in the background."

How to Create Custom Email Filters With Proton (Two Ways, Both Easy)

Method 1: Quick automation from your email window.

    Sign in to mail.proton.me.
    Open an email, then move or label it as usual.
    Check "Always move sender's emails" or "Always label sender's emails."
    Select "Move" or "Label."

Quasy: "This is the lazy method. For people who see an email and think 'I never want to deal with this sender manually again.' Two clicks. Done. Every future email from this sender is automatically sorted. No setup screens. No criteria. No complexity. Just rage-driven efficiency."

Mrs. Higgins: "I like the lazy method."

"The lazy method is the best method. Laziness drives automation. Automation drives productivity. Productivity drives success. Therefore: laziness equals success. This is the Quasy_Complete theory of workplace efficiency."

Method 2: Detailed custom filters from Settings.

    Sign in to mail.proton.me.
    Go to Settings → All settings → Proton Mail → Filters.
    Under Custom filters, click "Add filter."
    Add criteria: filter when certain conditions are met, or when ALL requirements are met.
    Click "Insert" to add specific text or keywords.
    Click "Add condition" for complex filters. Include as many conditions as you like.
    Click "Next" to set actions.

Quasy: "This is the engineer's method. For people who want precision. Multiple conditions. Multiple actions. Complex rules. Like: 'If the email is from a client AND contains the word "invoice" AND has an attachment, then label it "Invoices" AND mark as important AND forward a copy to accounting.' One filter. Three conditions. Three actions. Zero manual effort."

Mrs. Higgins' eyes glazed over. "That sounds complicated."

"It's not complicated. It's precise. Complicated is scrolling through nine thousand emails looking for one electric bill. Precision is a filter that catches the electric bill automatically because it recognizes the sender and the subject line. Complicated is chaos. Precision is order."

Best Practices: How to Use Filters to Boost Productivity (Without Accidentally Hiding Your Boss's Emails)

Quasy listed the golden rules:

    Categorize by project, sender, department, or priority. Give every email a home. No orphans. No strays. Everything filed. Everything findable.

    Use color-coded labels and folders. Visual awareness matters. Green for clients. Blue for receipts. Red for urgent. Yellow for "deal with later." Orange for newsletters. Purple for "why did I subscribe to this?"

    Create "Follow-up" and "Reply later" folders. Emails you need to circle back on shouldn't sit in your main inbox getting buried under new arrivals. Move them. Filter them. Tag them. Remember them.

    Auto-archive old messages. Set a filter that archives messages older than 30 days. If you haven't read it in a month, you're not going to. Be honest. Let it go.

    Review filters regularly. What worked in January might not work in July. Clients change. Projects end. Newsletter subscriptions multiply. Audit your filters like you audit your taxes. Reluctantly. But thoroughly.

    Don't over-filter. The biggest danger. Too many filters and you accidentally hide important emails. Your boss's email gets caught in a filter designed to catch "internal memos" and archived before you see it. Now you've missed a meeting. And your boss thinks you're ignoring them. And your career trajectory has adjusted downward.

Quasy illustrated the over-filtering trap: Boss: "Did you see my email?" Employee: "What email?" Boss: "The urgent one I sent yesterday." Employee: "I have a filter that archives internal memos." Boss: "It wasn't a memo. It was urgent." Employee: "The filter doesn't distinguish between memo and urgent. It treats all internal communication as equal. Very democratic. Very problematic." Boss: "Fix your filters." Employee: "I can't find the filter. It's archived under a label I forgot I created."

Mrs. Higgins: "That happened to me! My doctor's appointment reminder got caught in a spam filter and I missed my checkup!"

"And that's why you whitelist trusted senders. Your doctor goes on the whitelist. The filter sees the doctor's email and says 'This is safe. Let it through. Don't touch it. Don't archive it. Don't delete it. The patient needs this.'"

Keep Your Inbox Organized With Proton (Where Privacy Meets Productivity)

Proton Mail doesn't just organize your email. It keeps your data safe. End-to-end encrypted. Nobody can read your emails except you. Not even Proton.

Quasy: "Filters manage email overload, save time, and improve communication flow. But here's the thing: most email providers that offer filters also scan your emails. They read your content. They build profiles. They sell your data to advertisers. Your inbox is organized AND surveilled. Efficient AND exploited. Streamlined AND monetized."

He contrasted: "Proton Mail doesn't scan your emails. Doesn't sell your data. Doesn't build advertising profiles. End-to-end encryption means your messages are encrypted on your device before they reach Proton's servers. Not even Proton can read them. Your filters work on metadata — sender, subject, keywords — not on content. Privacy and productivity. Coexisting. Like they should."

Proton Mail also offers one-click unsubscribe, a Newsletters view, and Hide-my-email aliases for inbox organization that goes above and beyond.

Quasy: "One-click unsubscribe. ONE CLICK. Not 'scroll to the bottom, find the tiny gray text, click the link, confirm on a landing page, answer a survey about why you're leaving, then receive three more emails confirming your departure.' ONE CLICK. Gone. Finished. Freedom."

Mrs. Higgins: "And Hide-my-email?"

"You give every service a different email alias. Your real email stays hidden. If a service starts spamming you, you disable the alias. Done. No more emails. No unsubscribe button needed. No begging. Just silence. Beautiful, encrypted silence."

Conclusion: Your Inbox Doesn't Have to Be a War Zone

Quasy_Complete looked at his inbox. Three thousand four hundred and twelve unread emails. He took a breath. Opened Proton Mail settings. Created his first filter.

Rule: If sender contains "newsletter" → Label "Newsletters" → Archive. Result: Four hundred emails vanished from his main inbox. Filed neatly. Still accessible. No longer screaming for attention.

Rule: If sender contains "footlocker" → Delete. Result: One hundred and twelve emails evaporated. Like they never existed. Because they shouldn't have.

Rule: If sender is boss AND subject contains "urgent" → Mark as important → Label "Urgent." Result: The buried email from four days ago surfaced. Glowing. Important. Found.

"There," he said. "Order from chaos. Signal from noise. Important emails from junk. In three filters."

Mrs. Higgins started creating her own filters: Rule: If sender contains "electric company" → Label "Bills" → Mark as important. Result: Electric bill found. Filed. Paid. Crisis averted.

Rule: If sender contains "LinkedIn" → Archive. Result: Three hundred notifications vanished. Silence. Peace. The sound of nobody endorsing her for skills she doesn't have.

Rule: If sender contains "Foot Locker" → Delete. Result: Match.

She looked up. "It's beautiful. My inbox has eleven emails now. All important. All findable. All mine."

"That's the power of filters. They don't just organize your email. They reclaim your time. Your attention. Your sanity."

His phone buzzed. Email notification: "Your Foot Locker order has shipped!"

Quasy stared at the notification. Looked at Mrs. Higgins. Looked at the ceiling.

"I set the filter to delete Foot Locker emails."

"Maybe it's a different Foot Locker."

"There is no different Foot Locker. There is only one Foot Locker. And it is relentless. Like a hydra. You delete one email, two appear. You filter one sender, they change their address. You block one domain, they register another."

He opened the email. It was indeed from Foot Locker. The filter hadn't caught it because the sender address was "shipping@footlocker-delivery-partner-3.com" — a new domain. A new disguise. A new workaround.

"Ah," he muttered. "The arms race begins. They change their address. I update my filter. They change again. I filter again. It's evolution in real time. Natural selection applied to retail marketing. Survival of the most annoying."

He added the new domain to his delete filter. Checked his inbox. Eleven emails. All important. All findable.

For now.

His phone buzzed again. Email notification: "You've been endorsed for 'Strategic Thinking' on LinkedIn!"

Quasy read it. Looked at Mrs. Higgins. Looked at the ceiling. Looked at the ceiling again, as if it might offer guidance.

"LinkedIn changed their sender address too, didn't they?" Mrs. Higgins asked.

"Indeed they did."

He updated the filter. Archived the notification. Closed his laptop.

Inbox: zero. Stress level: manageable. Foot Locker: temporarily defeated. LinkedIn: temporarily silenced. Electric bill: paid. Boss's urgent email: found, read, and responded to four days late. Career: uncertain.

But the inbox was organized.

And sometimes, that's the best you can hope for in 2026.

An organized inbox. A encrypted email. And a filter that deletes Foot Locker emails with extreme prejudice.

Forever.

Or until they register a new domain.

Whichever comes first.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Tue, 21 Jul 2026 18:32:33 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-51</guid><link>https://carlostkd.ch/roadmap/#post-51</link><title>Why Your Internet Provider Knows More About You Than Your Therapist</title><description><![CDATA[Quasy_Complete was sitting at his kitchen table when his internet connection suddenly slowed to a crawl. He tried to load a video. It buffered. He tried to check his email. It spun. He tried to stream a movie. The screen froze on a frame of a cat looking confused.

"Ah," he muttered. "The ISP is throttling me again. Because I'm watching a documentary about cats. Which, apparently, is a threat to national security."

His neighbor, Mrs. Higgins, appeared at the door holding her router like it was a hostage.

"Quasy! My internet is slow! And my router is blinking red! And I think it's watching me breathe!"

"Mrs. Higgins," Quasy said calmly, "your router isn't watching you breathe. But your Internet Service Provider (ISP) is definitely watching what you do online. And they know you're breathing. Because they can see how much data you're transferring. And if you're breathing heavily while watching a thriller, that's a lot of data."

She sat down heavily. "They know everything?"

"Almost everything. They know where you go. When you go. How long you stay. How much data you use. They know your approximate location. They know which devices are in your house. They know if you're streaming Netflix or checking your bank account. They just don't know what you're watching on Netflix or how much money is in your bank account. Because that part is encrypted. But the metadata? The metadata is a goldmine."

He pulled out his whiteboard. Drew a giant pipe. Labeled it "THE INTERNET." Then drew a smaller pipe inside it. Labeled it "YOUR ISP."

"Let's break this down," he said. "Because your ISP is the most powerful stalker you've never met."

What Can Your ISP Really See? (The Metadata Menagerie)

Modern websites use HTTPS encryption. This prevents your ISP from reading the contents of webpages. If you're browsing Reddit, they can't see the posts. If you're banking, they can't see your balance.

But...

Depending on your connection, your ISP may see:

    The websites and domains you visited.
    When you visited them.
    How long you remained connected.
    The amount of data you transferred.
    Your approximate physical location.
    Which devices are connected to your home network.

Quasy illustrated: You: "I'm going to Reddit to read about cats." ISP: "Ah, I see you visited 'reddit.com' at 3 PM. You stayed for 45 minutes. You transferred 200MB of data. You have three devices connected: your phone, your laptop, and that smart toaster that sends you tweets." You: "But you don't know what I read!" ISP: "True. But I know you read about cats. And I know you have a smart toaster. And I know you're in Apartment 4B. And I know you're single because you only visit dating sites on Tuesdays. That's enough for me to build a profile."

A 2021 FTC report examined six major ISPs serving 98% of the US mobile market. It found they collected massive amounts of data, combined it across services, and shared it with third parties.

Quasy: "They combine data from broadband, mobile, TV, email, smart home, and search. They build a detailed picture of your life. Then they sell it to advertisers. Who then show you ads for things you didn't even know you wanted. Like cat food. Or smart toasters."

Why ISPs Have So Much Data (Because They Own the Pipe)

Unlike Google or Meta, you can't log out of your ISP. You can't choose not to use it. For many, it's an unavoidable part of getting online.

Some providers have expanded beyond broadband. They offer mobile, TV, email, smart home, cloud, search.

Quasy: "This allows them to combine information from multiple services. You watch TV on their platform. You browse on their mobile network. You email on their service. They put it all together. You're not just a customer. You're a data point. A cluster of data points. A target."

He continued: "Unlike social media, where you have choices, most households have only one or two ISP options. In many areas, it's a monopoly. Or a duopoly. You pay them. They watch you. You have no choice. It's the ultimate subscription service. And you can't cancel."

How Privacy Protections Changed (Or, How Congress Decided Privacy Was Optional)

In 2016, the FCC adopted privacy rules requiring ISPs to get consent before collecting browsing data.

In 2017, Congress repealed those rules using the Congressional Review Act. Later, the FCC voted to repeal net neutrality.

Quasy: "So, in 2016, the government said 'Hey, ISPs should ask before they spy.' In 2017, Congress said 'Nah, let's repeal that.' And then they repealed net neutrality too. Which means ISPs can now slow down your connection if you don't pay extra. Or if you're watching a competitor's streaming service."

He illustrated: Netflix: "We're streaming movies!" Comcast: "Pay us extra, or we'll slow you down." Netflix: "But that's anti-consumer!" Comcast: "We own the pipes. We make the rules." Congress: "Sounds fair. Repeal the rules." Consumer: "But I just want to watch a cat video!" Comcast: "That'll be $10 extra."

Can Your ISP Slow Your Connection? (The Art of Digital Throttling)

ISPs control the infrastructure. They can influence how traffic is delivered.

Example 1: Netflix vs. Comcast (2013-2014). Comcast slowed Netflix streams until Netflix paid for direct connections. Comcast CEO called it an "arbitrary tax."

Example 2: Netflix vs. FCC (2024). Netflix argued ISPs with competing streaming platforms have financial incentives to disadvantage competitors.

Example 3: Mendocino Complex Fire (2018). Verizon throttled data for a fire department vehicle. Speeds dropped. Firefighters had to upgrade to a more expensive plan to get normal speeds. Verizon called it a "customer support mistake."

Quasy: "So, if you're a firefighter trying to save a town, and your internet is slow because you didn't pay for the premium plan? That's a 'mistake.' But if you're a customer trying to watch Netflix, and your internet is slow because you're using a competitor? That's 'business.' It's the same thing. Just different stakes."

He sighed: "ISPs don't just provide access. They control the road. And they can put speed bumps wherever they want. Especially if you're driving a car they don't like."

Can Your Wi-Fi Router Track You Inside Your Home? (The Wi-Fi Sensing Nightmare)

One lesser-known development: Wi-Fi sensing. Researchers have shown Wi-Fi signals can detect movement by analyzing how they reflect off people and objects.

Academic studies show these techniques can identify movement, breathing patterns, and even estimate body position through walls.

Today, some routers include human presence detection. Industry estimates suggest tens of millions of US households have access to Wi-Fi sensing tech through ISP-provided hardware.

Quasy: "Your router can now sense if you're in the room. If you're breathing. If you're moving. It can automate lights. Security systems. Smart home devices. And your ISP controls the firmware. They can turn features on or off. They can update the router to do more. And you just sit there, breathing, unaware that your router is counting your breaths."

Mrs. Higgins: "My router is counting my breaths?"

"Probably. And if you're breathing fast because you're scared of your ISP, that's a lot of data. They know you're scared. They know you're breathing. They know you're in Apartment 4B. And they know you have a smart toaster."

How to Reduce ISP Tracking (The Digital Escape Plan)

Although your ISP handles your traffic, you can reduce what they see.

Use a VPN: Encrypts traffic before it leaves your device. ISP sees only that you're connected to a VPN server. Not what you're doing.

Switch to Encrypted DNS: Traditional DNS reveals websites. Encrypted DNS (DoH/DoT) prevents ISPs from viewing requests in plain text.

Use Your Own Router: ISP-supplied routers often have limited control. Buying your own gives you control over firmware, security, and features.

Enable HTTPS: Most sites use HTTPS by default. Ensure your browser prefers encrypted connections. Prevents ISPs from viewing contents.

Quasy: "A VPN is the best tool. It hides your destination. Encrypted DNS hides your requests. Your own router hides your firmware. HTTPS hides your content. Combine them, and you're a ghost. A digital ghost. Invisible to your ISP."

He looked at Mrs. Higgins: "So, what should you do?"

"Get a VPN. Use encrypted DNS. Buy your own router. And stop trusting your ISP to keep your secrets. Because they won't. They're not your friend. They're your landlord. And they're charging you rent for the privilege of being watched."

Conclusion: Your ISP Is Watching (But You Can Hide)

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence, staring at her router.

"So my ISP knows everything," she said slowly.

"Not everything. But enough. Enough to build a profile. Enough to sell to advertisers. Enough to throttle your connection. Enough to watch you breathe."

He stood up. "But you can hide. Use a VPN. Encrypt your DNS. Buy your own router. And remember: your ISP is not your friend. They're the gatekeeper. And the gatekeeper is always watching."

His phone buzzed. Notification: "Your ISP has detected unusual activity. Please upgrade to Premium for faster speeds."

Quasy read it. Laughed. Deleted it.

"Unusual activity," he muttered. "Watching cat videos is unusual now? In 2026, the only unusual activity is not watching cat videos."

He opened Proton VPN. Connected to a server in Switzerland. His traffic was encrypted. His destination hidden. His ISP saw only a connection to a Swiss server.

"There," he said. "Now I'm a ghost. Invisible. Untraceable. Unthrottleable."

Mrs. Higgins asked: "Is my router still watching me breathe?"

"Probably. But at least it doesn't know what you're watching. Or who you're talking to. Or where you're going. That's progress."

He closed the app. Looked out the window.

The internet was a river. The ISP was the dam. And the water flowed through their hands. But with a VPN, the water became invisible. And the dam became irrelevant.

Which, in 2026, is the closest thing to freedom you can get.

And if anyone tried to throttle you? You'd just switch to a different river. Or build your own.



Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Wed, 15 Jul 2026 13:59:51 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-50</guid><link>https://carlostkd.ch/roadmap/#post-50</link><title>Why Your Phone Shouldn&apos;t Unlock Just Because You Open Your Eyes</title><description><![CDATA[Quasy_Complete was sitting in his living room when he noticed his iPhone unlock itself. He hadn't touched it. He hadn't spoken. He was just staring blankly at a wall, thinking about the existential dread of modern capitalism.

And yet, the screen lit up. The little padlock icon dissolved. The phone was open.

"Ah," he muttered. "Face ID. The feature that assumes if you're awake and looking at your phone, you must want to be in it. Even if you're just zoning out. Even if you're asleep. Even if you're being held at gunpoint by a border agent who wants to see your DM history."

His neighbor, Mrs. Higgins, appeared at the door holding her phone like it was a bomb.

"Quasy! My phone unlocked when I was sleeping! I woke up and it was open! I didn't touch it! I didn't even blink!"

"Mrs. Higgins," Quasy said calmly, "Face ID has a feature called 'Attention Awareness.' It's supposed to stop it from unlocking if you're asleep. But sometimes, if you're dreaming about a very specific, very focused scenario involving your phone, it might get confused. Or, more likely, someone else is holding your phone while you sleep and looking at it for you."

She sat down heavily. "Can I turn it off?"

"You can. Permanently. Temporarily. Or just for the things you don't want it to do. Like paying for groceries. Or letting the FBI read your texts. Let's go through the menu."

How to Turn Off Face ID (The Three Ways to Say "No Thanks, I'll Use My Brain Instead")

There are three main options: permanent, temporary, or selective.

Option 1: Reset Face ID Permanently. Go to Settings → Face ID & Passcode → Enter Passcode → Reset Face ID. Note: On iOS 17.3+, you might need to disable "Stolen Device Protection" first. Because Apple loves irony. They protect your phone from thieves but make it harder to reset Face ID if you actually need to.

Quasy: "This wipes the facial data. Your phone forgets your face. You have to set it up again. It's like telling your phone, 'I don't trust you with my face anymore. We're starting over.'"

Option 2: Turn It Off Temporarily. Hold down the side button and either volume button for 2 seconds. Tap Cancel or press the side button again. Result: Face ID is disabled until you unlock with your passcode.

Quasy: "This is the emergency brake. You're about to go through customs? Hold the buttons. Boom. Face ID is dead. Your phone is now a brick that only opens with a code you memorized. Much safer. Much less convenient. But safer."

Option 3: Disable for Specific Functions. Settings → Face ID & Passcode → Under "Use Face ID For," toggle off specific apps or actions (Unlock iPhone, iTunes & App Store, Apple Pay, etc.).

Quasy: "You can keep Face ID for unlocking your phone but turn it off for Apple Pay. Because sometimes you don't want your face to be your credit card. Or you can turn it off for specific apps. Maybe you don't want Face ID for your banking app. Or your journal. Or your diary. Or anything you'd rather not have unlocked by a random glance."

How Does Face ID Work? (The Math Behind the Magic)

Face ID uses facial recognition to create a depth map and infrared image of your face. This data is transformed into a mathematical representation. It compares this map every time you unlock.

By default, it requires your eyes to be open and your attention directed at the device.

Quasy: "So it's not just a picture. It's a 3D map. Infrared. Depth. It knows you're looking at it. It knows you're awake. It's smart. Too smart. Because sometimes 'smart' means 'can be forced to work against you.'"

Is Face ID Safe? (The Legal Loophole That Lets the Police Force You to Smile)

For the average user, Face ID is often more secure than a passcode. No shoulder surfing. No password reuse. Hard to trick with photos or masks.

But there's a catch.

Legal Considerations: Passwords are protected as testimonial evidence. You can't be forced to give up your password. But biometrics? Courts have ruled that looking at a camera or touching a finger is a physical act, not testimony.

Quasy explained: "If the police want your password, they have to prove you know it. They can't force you to say it. But if they want your face? They can just hold your phone up to your face. And you look at it. And your phone unlocks. You didn't say anything. You just did something. A physical act. And physical acts can be compelled."

He illustrated: Police Officer: "Give us your password." You: "I can't. It's testimonial. I have rights." Police Officer: "Fair enough. Now, look at this phone." You: "I'm not going to—" Police Officer: "Look at it." You: "Fine." Looks. Phone: Unlocks. Police Officer: "Thank you. Case closed."

Quasy: "That's the loophole. Biometrics are physical. Passwords are mental. And the law treats them differently. Which means your face is less protected than your brain."

When to Turn Off Face ID (The Survival Guide for the Paranoid)

There are specific situations where you should turn it off.

Traveling Abroad: Turn it off before customs. Especially in countries where social media posts are crimes. Officials can force you to look at your phone. They can't force you to say a code.

Attending Protests: Turn it off before you go. If your phone is seized, you're more likely to avoid opening it. Consider a Faraday bag to block signals.

High-Risk Professions: Activists, journalists, immigrants, politicians. In January 2026, the FBI raided Washington Post journalist Hannah Natanson. Their warrant authorized agents to force her to use biometrics—finger or face—to unlock her devices.

Quasy: "Hannah Natanson. Journalist. FBI raid. Warrant said: 'Force her to look at her phone.' She had to look. Her phone opened. Her data was exposed. Because she looked. And looking is a physical act. And physical acts can be compelled."

Mrs. Higgins: "That's terrifying."

"It's the law. And the law is written by people who don't understand privacy. Or they understand it too well and decided it doesn't apply to you."

What to Use Instead? (The Passcode That Can't Be Forced)

For high-risk individuals, Lockdown Mode is an option. It makes your phone harder to use but safer.

In general, the best alternative is a passcode and passkeys. A password manager like Proton Pass lets you store and autofill passwords with end-to-end encryption.

Quasy: "A passcode is mental. You have to know it. You can't be forced to think it. If they want your passcode, they have to torture you into saying it. And that's a much higher bar than just holding a phone to your face."

He summarized: "Face ID is convenient. It's fast. It's seamless. But it's also a vulnerability. A physical vulnerability. A legal vulnerability. A biometric vulnerability. If you're just an average user, it's fine. If you're a journalist, an activist, a traveler, or just someone who values their privacy more than their convenience, turn it off."

Conclusion: Your Face Is Not a Key (It's a Liability)

Quasy_Complete closed his laptop. Mrs. Higgins sat in silence, staring at her phone.

"So I should turn it off?" she asked.

"If you're worried about being forced to unlock your phone? Yes. If you're traveling? Yes. If you're attending a protest? Yes. If you're just paranoid? Also yes."

He picked up his own phone. Held down the side and volume buttons. The screen went black. Face ID was disabled.

"Now," he said, "my phone is a brick. It only opens with a code. A code I memorized. A code no one can force me to say. A code that is mine. And mine alone."

He smiled. "Convenience is nice. Security is better. And sometimes, you have to choose between the two."

His phone buzzed. Notification: "Face ID disabled. Use passcode to unlock."

Quasy read it. Smiled. Locked the phone.

"Finally," he whispered, "a phone that respects my right to remain silent."

And if anyone tried to force him to look at it? He'd just close his eyes. And smile. Because sometimes, the best defense is a closed eye. And a very long, very complex passcode.


Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 13 Jul 2026 15:30:35 -0400</pubDate></item><item><guid isPermaLink="true">https://carlostkd.ch/roadmap/#post-49</guid><link>https://carlostkd.ch/roadmap/#post-49</link><title>Netherlands Blocks US Takeover of DigiD: Or, How a Country Finally Said &quot;Our Citizens&apos; Data Is Not for Sale&quot;</title><description><![CDATA[Quasy_Complete was reading the news when he spat out his coffee. Not the usual slow sip followed by a resigned sigh. An actual spit. Across the table. Onto a napkin. Onto Mrs. Higgins' sleeve.

"Quasy!" she yelped, dabbing her arm.

"Sorry. A government just did something sensible. I wasn't prepared. It never happens. I had no contingency plan for competence."

He turned the screen toward her. The headline read: Netherlands Blocks €100 Million Takeover of National ID Infrastructure by US Firm Kyndryl.

"A country," Quasy said slowly, "protected its citizens' data. On purpose. Deliberately. With a government decision. Not after a breach. Not after a scandal. Before anything went wrong. Preventively."

Mrs. Higgins blinked. "That's... unusual?"

"It's unprecedented. It's like watching a unicorn ride a bicycle through a field of four-leaf clovers while winning the lottery. Governments don't prevent problems. They react to them. Usually three years too late. During a press conference. With a spokesperson who says 'lessons have been learned.'"

What Is DigiD and Why Should You Care?

Solvinity manages the cloud infrastructure on which DigiD runs — the system that gives Dutch citizens access to tax records, medical files, and pension information.

Quasy broke it down: "DigiD is the digital front door to Dutch citizenship. Taxes? DigiD. Medical records? DigiD. Pension data? DigiD. It's the master key to 17 million people's private lives. And a US company called Kyndryl wanted to buy the company that runs the server it lives on."

Mrs. Higgins: "What's wrong with that?"

"The American CLOUD Act. This law requires American tech companies to provide data to the US government, even when that data is physically stored in Europe."

He illustrated: Dutch Citizen: "My medical records are stored in a server in Amsterdam." Kyndryl (American company): "We now own that server." US Government: "Excellent. We'd like to see those medical records." Kyndryl: "They're in the Netherlands." US Government: "CLOUD Act. Hand them over." Kyndryl: "But GDPR—" US Government: "Our law. Your company. Your server. Our rules." Dutch Citizen: "Wait, I didn't consent to—" US Government: "You're not in this conversation."

Mrs. Higgins went pale. "So the US could just... read Dutch citizens' medical files?"

"Through the CLOUD Act, yes. Tax records. Pension data. Medical files. Everything behind DigiD. If Kyndryl owned the infrastructure, the US government could compel them to hand over data. European GDPR protections would evaporate like a puddle in the Sahara. Because the company is American. And American companies obey American law. Even when the data is European. Even when the people are European. Even when the server is in a building in Amsterdam with a Dutch flag on the door."

"This happened before?" Mrs. Higgins asked.

"This ALMOST happened. The Dutch government blocked it. But 81% of Dutch publicly traded companies already depend on American tech services. In semiconductors, it's 83%. The takeover was averted. The dependency remains."

The Resistance: Citizens, Journalists, and Politicians Who Actually Read the Fine Print

When Kyndryl announced the takeover in November 2025, broad opposition emerged immediately. The rejection resulted from months of action by citizens, journalists, and privacy activists.

State Secretary Willemijn Aerdts adopted the Bureau for Investment Screening's advice: the takeover posed "a risk to the public interest." A broad parliamentary majority supported the decision.

Quasy: "Citizens objected. Journalists investigated. Privacy activists organized. Politicians listened. The Bureau for Investment Screening recommended blocking. The State Secretary agreed. Parliament backed it. A government functioned as a government. I'm so disoriented by competent governance that I need to sit down."

Mrs. Higgins: "This was the first time they blocked an American takeover?"

"First time. On grounds of public interest. The first time the Netherlands used investment screening powers to block a US acquisition to protect citizens' data. That's not routine. That's a precedent. A line in the sand. A government saying: 'This far. No further.'"

The Broader Movement: Europe Is Quietly Building Its Own Digital House

In December 2025, the Netherlands presented a new vision on digital sovereignty: crucial infrastructure must fall under Dutch or European legislation. The country is investing in its own cloud alternatives like STACKIT and the KPN-Thales sovereign cloud.

This fits a broader European pattern: France replacing American tools. The EU bringing chip production to Europe through the CHIPS Act. The EU Parliament ditching Google in favor of Qwant, a European search engine.

Quasy listed the developments like a man inventorying a fortress under construction:

    Netherlands: building sovereign clouds. Blocking foreign takeovers of critical infrastructure.
    France: replacing American tools with European alternatives.
    EU CHIPS Act: bringing semiconductor production back to Europe.
    EU Parliament: switching from Google to Qwant.

"Europe is building its own digital house," Quasy said. "Own bricks. Own cement. Own locks. Own keys. And the United States is standing outside, knocking, saying 'but we were already inside, why are you changing the locks?'"

Mrs. Higgins: "Because you were reading our mail."

"Exactly."

What This Means for Your Privacy (Because It's Not Just About Governments)

Control over digital infrastructure isn't a technical detail. It's national security and civil rights. When medical data, financial information, and personal communication are digital, whoever controls the infrastructure determines who has access to the data.

This applies not only to government systems like DigiD. It applies to your everyday internet use. Your traffic passes through ISP servers and websites, often under American or non-European jurisdiction.

Quasy: "DigiD was the government's problem. They solved it. Your personal data is YOUR problem. And the same principle applies. If your traffic flows through American servers, American companies, American infrastructure — the CLOUD Act reaches you too. The US government can compel those companies to hand over your data. GDPR can't stop it. European courts can't stop it. Because the company is American. And American law trumps European privacy when the company is incorporated in Delaware."

Mrs. Higgins: "So I'm subject to American law when I browse the internet?"

"When your traffic passes through American infrastructure? Yes. Which is most of the time. Unless you use a European VPN."

He explained: "With a VPN based in Europe, like Proton VPN, you can encrypt your internet traffic and route it through servers in the Netherlands or other European countries. Your data stays under European privacy legislation. No CLOUD Act. No American jurisdiction. No foreign government reading your browsing history because a company in Silicon Valley was compelled to hand it over."

Mrs. Higgins pulled out her phone. "So if I use Proton VPN—"

"Your traffic is encrypted. Routed through European servers. Protected by European law. Swiss law, specifically, because Proton is Swiss. Switzerland. The country that invented neutrality and banking secrecy. Applied to digital infrastructure. Your data passes through tunnels that the US government cannot compel anyone to open."

"And without the VPN?"

"Your data passes through whoever's infrastructure it encounters. American CDNs. American cloud providers. American analytics scripts. American ad networks. Each one a potential CLOUD Act endpoint. Each one a door the US government can knock on and say 'open.' Through your data goes."

He summed up: "The Netherlands protected 17 million citizens' DigiD data by blocking one takeover. That's significant. But it's one door. One system. There are a thousand other doors. Each one leading to American infrastructure. Each one subject to American law. Your job is to close as many as you can."

Conclusion: Sovereignty Starts at Home

Quasy_Complete closed his laptop. The headline about the Dutch government's decision glowed on the screen for a moment, then faded.

"The Netherlands showed something important," he said. "Digital sovereignty isn't a slogan. It's a decision. A government decided that its citizens' medical records, tax data, and pension information should not be subject to American law. That's not anti-American. That's pro-citizen."

Mrs. Higgins: "Can other countries do the same?"

"They can. They should. Some already are. France. The EU Parliament. The Netherlands. Each one taking a step. Each one building a wall. Brick by brick. Server by server. Law by law."

He stood up. "But sovereignty isn't just for governments. It's for individuals. You can't block a takeover. But you can encrypt your traffic. You can choose European tools. You can route your data through servers that answer to European law, not American law."

His phone buzzed. Notification: "Netherlands blocks US takeover of DigiD. Citizens' data stays European. Sovereignty achieved."

Quasy smiled. "Imagine that. A government protecting its people. And people protecting themselves. Both happening simultaneously. In the same country. On the same day."

He opened Proton VPN. Connected to a server in Amsterdam. His traffic now flowed through Dutch infrastructure, under Dutch law, protected by European privacy regulations.

Mrs. Higgins asked: "Is your data safe now?"

"Safer," he corrected. "Never safe. Safer. Safety is a direction, not a destination. The Netherlands moved in that direction today. I'm moving in that direction now. And if enough people move in that direction, eventually the whole continent arrives."

"Arrives where?"

"At a place where your data belongs to you. Your laws protect you. Your infrastructure serves you. And no foreign government can compel a foreign company to hand over your medical records because they bought the server it lives on."

His phone buzzed again. News alert: "EU Parliament switches from Google to Qwant. European search engine gains institutional adoption."

Quasy nodded. "Brick by brick. Server by server. Search engine by search engine."

He closed the notification. Leaned back. Looked out the window.

The Netherlands had drawn a line. The EU was building a wall. And for once, the wall wasn't keeping people out. It was keeping data in.

Where it belonged.

Protected by the laws of the people who created it. Not the corporations who wanted to buy it. And certainly not the foreign governments who wanted to read it.

Sovereignty. Not as a buzzword. As a practice. One blocked takeover at a time.

Quasy_Complete serves as Product Lead for Proton Mail and Drive and Director of LLM (Long Lasting Milestones) Engineering.

When not 'collaborating' with the kids on Reddit, he is busy penning the next chapter of the Proton ecosystem.
Before joining Proton in 2022, he spent years in Silicon Valley building products that were "coming soon" before the concept of "soon" was invented. He holds a BSc in "Waiting for Updates" and an MSc in "Roadmap Delays" from the University of Warwick (which is currently under construction).]]></description><author>Quasy_Complete</author><pubDate>Mon, 13 Jul 2026 15:24:49 -0400</pubDate></item></channel></rss>