▲ 4 r/PrivacyToolbox+1 crossposts

Here is the email sent to the 678 000 victims of the cyberattack targeting France’s Directorate General of Public Finances.

Hello X Y,

Wednesday, August 12, 2026, a malicious actor claimed to have gained access, in June and July of this year, to data from the information systems of the French Directorate General of Public Finances (DGFiP), using the stolen credentials of a DGFiP employee combined with those of a third party authorized by the DGFiP.

You are receiving this message because you are affected by this malicious act.

What data may have been accessed?

Your tax identification number, civil status, contact details (postal address, telephone number and email address), your tax situation (family situation, number of dependents, number of tax shares, reference taxable income, withholding tax rate), and the list of messages you exchanged with the DGFiP through the messaging system on impots.gouv.fr.

Important: your password for accessing your Public Finances account on impots.gouv.fr has not been compromised. Your tax returns and tax notices were not accessed.

What is the main risk?

The main risk is that you may be targeted by fraud attempts, particularly through messages (“phishing”) or phone calls made more convincing by the use of the stolen personal information.

To a lesser extent, you could also be targeted by identity theft attempts. For this, however, the malicious actors would also need to have a copy of your identity documents or obtain them through another means.

In any event, your bank details are not affected by this data theft.

How can you protect yourself?

You should be particularly cautious about any contact — by phone call, email, SMS, instant messaging, social media, etc. — from people or organizations claiming to know you based on the stolen information and asking you to:

  • provide confidential information (codes, passwords, bank card numbers, copies of identity documents, etc.);
  • approve banking transactions (in particular, someone pretending to be your bank advisor); or
  • provide your password to access your Public Finances account.

The DGFiP will never ask you to provide information outside your secure account.

You are also advised to remain vigilant and regularly check transactions on your bank accounts.

What measures has the DGFiP taken?

The access credentials used by the malicious actor were immediately disabled in June and then in July. Unfortunately, we did not detect the data theft at the time, as the data was stolen by bypassing the usual channels.

The security of your tax account is being strengthened immediately, including through particular monitoring of any changes that may be made to it over the coming months (postal address, bank account details, etc.).

Please be assured that our teams are fully mobilized. If you would like more information, you can consult our dedicated page on impots.gouv.fr:

https://www.impots.gouv.fr/actualite/acces-illegitimes-au-systeme-dinformation-de-la-dgfip

You can also contact us on 0809 401 401 or through your impots.gouv.fr secure messaging system. Alternatively, you can visit your local Public Finances office; its contact details are available in your secure account and on your tax notices.

This data theft will be subject to a lessons-learned review and additional security measures, which are being implemented without delay.

We sincerely apologize.

The Directorate General of Public Finances

reddit.com
▲ 3 r/PrivacyToolbox+1 crossposts

France to use AI to test government cybersecurity after recent hacker attack

France wants to use AI tools to scan for cybersecurity flaws following that massive tax agency hack. I grew up in France and still have to log into those administrative portals... the backend is probably held together by duct tape and legacy code from 1998... you can barely load a medium size PDF without the page crashing.

I am not sure you can just plug AI into bad data architecture and expect it to fix fundamental security gaps. I wonder if this will be a real structural overhaul or just an expensive consulting contract.

Has anyone seen automated vulnerability scanning actually fix a government system?

Source in comment.

reddit.com
▲ 5 r/PrivacyToolbox+1 crossposts

Historical flaws of password complexity rules highlight need for password managers

So many sites are enforcing the rule where your password needs a capital letter, a number and a special character but do people know this entire standard came from a guy named Bill Burr in 2003 who admitted he just guessed ? He wrote a legacy NIST appendix without any data on human behavior.

So now my local cinema forces me to reset my login every 90 days. What do normal people actually do ? They just change "Matrix!2023" to "Matrix!2024". Automated cracking tools chew through these predictable patterns in literal seconds. The guy who wrote the rule actually apologized for it years later because it objectively made security worse.

If you are still memorizing passwords, it might be better to stop. Get a browser-independent password manager. Generate a random 20 character string of absolute garbage, save it, and forget it.

Source in comment.

reddit.com
u/Miserable-Stretch114 — 3 days ago

SafePal breach : 40k order records leaked

SafePal just confirmed they lost order details for almost 40,000 customers. The records are already on hacking forums.

They keep saying the hardware wallets themselves are secure. Yes, your seed phrase is safe but attackers now have a massive list of names, emails (phishing emails incoming) and physical addresses of confirmed crypto holders... You really do not want strangers knowing you have crypto hardware sitting in your flat. Next time use a PO box.

reddit.com
u/Miserable-Stretch114 — 4 days ago
▲ 8 r/PrivacyToolbox+1 crossposts

Proton Launches "AI Paper Trail" Tool to Reveal AI Chatbot Data Leakage

I consider myself pretty locked down online. I block trackers and keep my digital footprint small. I still use Claude and ChatGPT once and a while.

Proton just released a free tool where you upload your exported AI chat logs and it gives you an exposure score. It breaks down exactly what these companies have pieced together about you.

I tried this morning and it says they delete the logs immediately after generating the local report and the results are genuinely uncomfortable : I knew I was giving them data. I just didn't realise how easily a local script could parse out my daily habits and literal financial goals from casual prompts over the last year. It even calculates a monetary value of what your specific profile is worth to data brokers. Seeing my random questions aggregated into a clean profile of my life was jarring... Going to nuke my OpenAI history tonight and stick to temporary chats.

reddit.com
u/Miserable-Stretch114 — 5 days ago
▲ 4 r/PrivacyToolbox+1 crossposts

pCloud World Photography Day Campaign Offers 500GB Free Swiss Secure Storage

Saw this promo pop up today. pCloud is running a World Photography Day campaign until August 22. You get 500GB of storage for three months and you don't even need to put in a credit card.

I do want to clarify something about their privacy claims. The promo mentions Swiss privacy laws and zero-knowledge encryption. Swiss jurisdiction is undeniably good. Your data falls under some very strict local laws. The encryption part requires attention. Standard pCloud storage is just encrypted at rest on their end. They keep the keys. Actual zero-knowledge client side encryption is normally a paid addon called pCloud Crypto. AFAIK this free 500GB tier does not include that Crypto folder...

Don't just dump highly sensitive personal data in there thinking it is completely blind to the server. If you need to store private stuff, just run the files through Cryptomator first.

u/Miserable-Stretch114 — 6 days ago
▲ 2 r/PrivacyToolbox+1 crossposts

The Inventory Analyzes Internxt's 10TB Lifetime Cloud Storage Deal

The Inventory just made an article about the lifetime 10TB Internxt deal for $360.

Pros: The price is absurdly low. You pay once and avoid endless Dropbox subscription fees.

Cons: The StackSocial license actually strips out several core features you get with a regular Internxt subscription.

Then there is the usual lifetime risk. If they run out of funding in three years, you lose your storage and have to migrate terabits of encrypted data anyway. A sustainable privacy setup requires paying for server upkeep. I would just skip it.

u/Miserable-Stretch114 — 6 days ago

Is Gmail secure ?

Just read a new report (source) breaking down webmail security and it made me realise how often people confuse a secure server with a private inbox.

Yes, Google has insane server side protections. Nobody is brute forcing their way into their data centres anytime soon. But what good is an impenetrable fortress if the landlord is sitting inside reading all your letters ? Gmail lacks default end-to-end encryption. Google holds the encryption keys and they actively scan your mail to build profiles for ad targeting.

For exemple, if you manage your entire financial life online and move between different countries, letting an ad company index your tax documents and bank correspondence is a massive blind spot. We act like this is just the normal cost of free email.

The report brings up platforms like Internxt building post quantum end-to-end encryption into their mail clients now. Som people think worrying about quantum decryption is overkill for everyday stuff but I kind of disagree. The "harvest now, decrypt later" threat model is real. Even if you ignore quantum threats entirely, standard E2E encryption needs to be the baseline.

I see guys spending hours tweaking secure networks just to stream movies, only to drop their guard and use Gmail for their main banking accounts...

u/Miserable-Stretch114 — 7 days ago
▲ 2 r/PrivacyToolbox+1 crossposts

Bucket0 Launches S3-Compatible Encrypted Cloud Storage and 'AgentBucket' File System for AI Agents

Bucket0 dropped a new S3-compatible cloud storage platform today. They're pushing the privacy angle hard. End to end encryption by default and a strict guarantee that your data is never scraped to train AI models. All sounds great. I'm exactly the kind of paranoid guy who spends way too much time obsessing over encrypted backups, so they have my attention.

But then I read about their AgentBucket feature. It's supposed to act as a semantic memory file system for AI agents. You plug your storage directly into Cursor or Claude, and the agent can search and recall your files across different sessions based on context.

Here's my problem. If the bucket is actually E2EE, how exactly is a third party LLM reading the files? Where is the decryption happening ? Are we just passing our private keys to Anthropic and hoping for the best ? Because if the storage server does the decrypting before passing the text to the API then the server has the keys. That breaks the whole E2EE promise.

I actually want to use this to manage my messy R2 and Azure buckets under one dashboard. Does anyone knows how this works ?

reddit.com
u/Miserable-Stretch114 — 9 days ago

PCMag Review: Kanary Personal Data Removal

I miss the days when being online didn't mean your life was instantly scraped and sold by brokers. You used to just log on, watch a film, and log off. Now we need subscriptions just to delete our own phone numbers.

PCMag just reviewed Kanary. They gave it good marks for the dashboard UI. But paying their premium price feels excessive ($250 per year). AFAIK Optery and Incogni seems to do the exact same job for way less money. Has anyone actually tried it ?

u/Miserable-Stretch114 — 9 days ago

EuroAlternative Evaluates Top Privacy-First E2EE Alternatives to Google Photos

EuroAlternative just dropped a guide (link) on European-hosted alternatives to Google Photos today. They pointed out Zeitkapsl and Proton Drive. It is great to see more options for zero-knowledge cloud ecosystems. Standard cloud services just sit there scanning your entire camera roll. No thanks.

But there is a huge usability wall when you move photos to an E2EE service. If the server is blind to your files, you lose the algorithmic search completely. On Google, you search a keyword and the app pulls up exactly what you want. With true E2EE, your device encrypts the media before the upload even starts. The host provider has absolutely nothing to scan.

How are you guys managing massive photo libraries on zero-knowledge platforms? Local indexing on the device? Or do you just spend hours making hyper-specific folders? I know I am basically demanding advanced data analysis and total privacy at the exact same time, but maybe there is a client-side solution out there...

u/Miserable-Stretch114 — 11 days ago
▲ 7 r/PrivacyToolbox+1 crossposts

A reality check on IronVault's zero-knowledge analysis (and endpoint security in general)

The recent IronVault analysis about zero-knowledge encryption limitations is something a lot of people in the privacy community need to read. We get so obsessed with keeping cloud providers blind to our data that we forget the actual weakest link is the machine sitting right in front of us...

Yes, AES-256-GCM client-side encryption is great. Deriving keys locally with PBKDF2 works. IronVault and similar E2EE tools do exactly what they claim to do for data in transit and at rest on their servers. But none of that helps you if your local endpoint is compromised.

I see some people here constantly recommending zero-knowledge cloud storage as an absolute shield. It creates a massive false sense of security. If you download a dodgy subtitle file for a movie and it drops a keylogger on your system, your master password is gone. If someone spikes your laptop with malware while you leave it unlocked at a cafe for two minutes to grab a coffee, client-side encryption is completely useless. The malware just reads the decrypted files straight from your active memory.

Zero-knowledge simply shifts the burden of trust from the server entirely onto your own OPSEC. If your local machine is dirty, your files are compromised. When your entire financial setup and daily life rely on digital privacy, you realize the cloud isn't the main threat.

So I am curious how we should all handle this side of the equation. Should we use separate physical devices for sensitive files and daily media consumption or just rely on good habits and hope for the best... ?

PS: I'm not knocking IronVault. I actually respect that they published this instead of pretending their software fixes everything.

u/Miserable-Stretch114 — 11 days ago
▲ 5 r/PrivacyToolbox+1 crossposts

Hacker Connor Moucka pleads guilty to hacking U.S. cloud storage provider

165 companies breached and this 26yo gets up to 32 years. Are we really just blaming him?
Connor Moucka just pleaded guilty for the Snowflake breach. Billions of records stolen from AT&T and Ticketmaster.

Obviously the guy broke the law but I am tired of massive companies acting like victims. They demand our personal info and then leave the door wide open.

Honestly I manage my own opsec better than AT&T does. Shouldn't the corporations be on trial too?

justice.gov
u/Miserable-Stretch114 — 13 days ago

Apple Challenges New UK Demand for Access to Encrypted iCloud Data

Apple just filed a complaint at the Investigatory Powers Tribunal because the UK Home Office issued a secret notice. They want Apple to break Advanced Data Protection and backdoor encrypted iCloud backups specifically for British users. They tried this globally a while ago and backed down. Now they think a geofenced backdoor is somehow fine...

If you force a tech company to build an encryption backdoor for one specific country, you ruin the math for everyone else. Hackers do not care about passports. State intelligence agencies will absolutely exploit a vulnerability meant for the British police. And if the UK wins this, the EU will try it next.

I am just totally impatient with these endless legal loops. Politicians keep trying to legislate math and it just exposes a massive lack of technical understanding.

reddit.com
u/Miserable-Stretch114 — 15 days ago
▲ 1 r/Nomad+1 crossposts

Monzo bank launching eSIMs

Saw the news about Monzo Mobile launching eSIM-only plans. Managing data packages directly inside a banking app sounds super usefull no ? Hopefully European neobanks copy this soon.

Are any of you based in UK going to use it ?

reddit.com
u/Miserable-Stretch114 — 1 month ago
▲ 2 r/Nomad

Korea's new nomad visa is actually realistic now.

So Korea finally made their digital nomad visa usable for normal humans. The old pilot programme requiring double the GNI (like $70k+) was ridiculous. Now, if you are under 35 and stay outside the Seoul bubble, the requirement is down to about $37k. Plus they extended the stay to three years.

I’m currently based in Spain but I’m seriously eyeing Busan or Jeju for my next move. Seoul is fun, but living by the coast with a decent surf community is way more my speed anyway.

reddit.com
u/Miserable-Stretch114 — 1 month ago
▲ 2 r/Nomad

France finally clarified the "visiteur" visa for remote workers. It’s official.

No more guessing games with random consulates. France officially confirmed, a few days ago, that the Visiteur Visa is legal for remote workers employed outside the country. You just need to show about 1,478 euros a month (I wonder why this specific number) and sign a paper saying you won't touch the local market.

A few friends have been waiting for a solid way to move closer to the Pyrenees, let's see if they actually pack their crash pads or if the red tape was just an excuse...

reddit.com
u/Miserable-Stretch114 — 1 month ago
▲ 1 r/Nomad

Bali authorities vs content creators on touristic visas

So Bali is officially cracking down on digital nomads again. This time they are targeting "unpaid barters" on tourist visas. If you tag a hotel or a cafe on social media in exchange for a free night or a discount, it is now legally considered unauthorized work and you can get deported.

Can you imagine the actual interrogation rooms in Denpasar right now?

"Ma'am, we noticed you tagged a villa in Canggu and used the hashtag #blessed. What's your plan with that?"

reddit.com
u/Miserable-Stretch114 — 2 months ago

Lyca eSims in the US

I saw Lyca US finally rolled out prepaid eSIMs you can activate online and I am heading to Southern California next month to work async for a few weeks. Being able to set this up from Barcelona beforehand is a massive help and they apparently bumped their high-speed cap to 50 GB too.

Has anyone tested their network coverage around San Diego or Orange County lately? I know they run on T-Mobile, but I want to make sure the speeds are solid for upload-heavy work before I rely on it.

reddit.com
u/Miserable-Stretch114 — 2 months ago