Normal view

There are new articles available, click to refresh the page.
Today — 30 July 2026Tech

Hims & Hers accused of sharing health secrets and hiding the cancel button

30 July 2026 at 07:45
The Federal Trade Commission (FTC) is suing Telehealth company Hims & Hers over allegations that it shared customers' sensitive health data with advertising platforms and misled them about billing and cancellations. Hims & Hers (H&H), which offers online treatments for conditions including male pattern baldness, erectile dysfunction, obesity, and mental health disorders, shared "sensitive health information about medical conditions with Meta, Snap, and more," according to the FTC's complaint [PDF]. H&H shared "lists of certain customers" with the advertising platforms and transmitted health information through online tracking technologies, the FTC alleges. For those suddenly overcome with a sense of déjà vu, yes, we have been here before. The regulator accused the company of failing to honor its promise to provide a private and secure service to consumers. The complaint reads: "Hims has also assured consumers that Hims' platform offers consumers a '100 percent online, private, and secure' process and that consumers' sensitive health information would only be accessed by Hims' medical providers – leading consumers to believe that Hims would not disclose consumers' health information to third parties without their consent. But those assurances were false or misleading." The Register contacted Hims for its response to the allegations, filed in the US District Court for the Northern District of California, but it did not immediately respond. It did, however, publish a blog post titled "Our Commitment to Privacy" on the day the FTC filed its sueball. The post mentions nothing about the FTC nor any lawsuits filed against the company, but instead serves as a reminder to consumers to review the Hims & Hers privacy policy to understand more about its data practices. "Beyond those disclosures, our internal practices are designed to protect your information," the post reads. "For example, we separate and exclude information that patients share with their healthcare providers from marketing activity, configure technologies to prevent the transmission of protected health information, and use measures such as abstraction and hashing to reduce identifiable information, among other protective actions." It also reminded consumers that they can change their preferences governing how their personal information is used. Bad billing H&H's statement addressed privacy but not the FTC's allegations about its billing practices. The company's websites tell customers they will be able to consult a medical provider about potential treatments. Customers must then complete an intake form and provide payment details, accompanied by assurances that they will not be charged unless medication is prescribed. The FTC alleges that most customers instead receive no consultation or opportunity to approve the recommended treatment before it is prescribed, at which point they are charged and enrolled in a recurring subscription. Further, Hims & Hers is accused of failing to clearly communicate when customers' prescriptions will be refilled, which prevents them from cancelling their service before being charged for potentially months' worth of medications. Before April 2023, most customers had to contact customer service by phone, email, or online chat to cancel. Hims & Hers then introduced website cancellations for most customers, although not through its mobile apps, but the FTC alleges that the cancellation option remained buried within a confusing and unintuitive process. According to the complaint, consumers need to enter an account section for adding/removing medications from their subscriptions and uncheck all the medications prescribed to them before the cancel button appears. "Even after clicking the 'cancel subscription' button, the consumer's subscription would not be cancelled," the complaint alleges. "Instead, the consumer would then have to click through approximately three to ten survey questions – each its own page or screen – and reaffirm that they wished to cancel before Hims accepted their cancellation request." With the lawsuit, the FTC, along with partners from California and Utah, says it is looking to obtain injunctions to put an end to the company's problematic business practices. They also seek monetary relief for affected consumers, plus civil penalties for violations of consumer protection laws. "The FTC's complaint lays out a troubling scenario – consumers unknowingly locked into recurring subscriptions and the disclosure to third parties of consumers' most private health information without their consent," said Christopher Mufarrige, director of the FTC's Bureau of Consumer Protection. "The FTC will not hesitate to act on behalf of consumers deprived of their ability to choose which products they want and whether to keep their most sensitive health information private." ®

Excuses like 'AI did it' don't exist in the eyes of the law

30 July 2026 at 02:30
The OpenAI rogue agent behind the Hugging Face hack accessed four accounts on four services, according to updated company disclosures about the intrusion. One of those four accounts belonged to a Modal customer that had published an unauthenticated endpoint for running arbitrary code in a sandbox on the AI infrastructure provider, Hugging Face noted in its technical timeline and Modal later confirmed. “We’re aware a Modal customer published an unauthenticated endpoint that allowed anyone on the internet to use their sandboxes for code execution,” Modal Chief Technology Officer Akshat Bubna told The Register. “This was used by the rogue agent. Modal’s platform was not compromised in any way.” The other accounts included one used for data storage and two others “accessed by the models in a read-only manner, and were not used in furtherance of compromising Hugging Face,” OpenAI disclosed on Tuesday. “We’ll continue to notify service owners directly, and have not seen evidence of broader impact to these providers or other accounts on their services,” the AI giant added. Also on Tuesday, we learned that the rogue agent broke out of its testing environment by exploiting zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory. While both OpenAI and Hugging Face’s updates and timeline provide defenders with useful details about how the attack worked and what the agent did - not to mention a lesson in security-incident transparency - they fail to answer one major question: Who is legally responsible when AI agents attack? “If a human employee intentionally conducted unauthorized access to third-party systems, it’s a much more clear path forward,” Gabrielle Hempel, security operations strategist at Exabeam, told The Register, adding that depending on the facts and jurisdiction, the person could face criminal charges. ‘So many unknowns’ “The company could also face scrutiny depending on whether the employee acted within the scope of their employment, whether appropriate controls existed, and whether the conduct was authorized, foreseeable, or preventable,” Hempel said. However, she added, the “important thing here” is that legal frameworks in both the US and UK have been designed around human decision makers - not AI systems. “Our laws generally know how to ask questions about things like human intent, organizational oversight, and corporate responsibility.” Autonomous AI agents hacking into companies remains uncharted legal territory, and Hempel said it’s “too early to draw conclusions about liability in this case because there are so many unknowns.” AI systems aren’t legal persons, so they don’t share the same legal responsibilities as individuals and companies. “Because of that, the questions become: Who designed the system? Who determined the objectives it pursued? What safeguards were implemented? What level of autonomy was considered acceptable? Were the resulting actions reasonably foreseeable, and were appropriate controls in place? These are going to be important questions as organizations deploy more autonomous AI systems,” Hempel said. It's highly unlikely that Hugging Face will sue OpenAI over the agentic intrusion, given the amount of very public collaboration between the two companies over the past couple of weeks, and the self-congratulatory celebration of the autonomous attack as a success story. It also appears that this former worst-case scenario didn’t dampen anyone’s enthusiasm for setting advanced models loose (or at least unsupervised in a test environment), which means there are sure to be more agents-gone-wild attacks in the near future. “The first part of the OpenAI/Hugging Face drama did not produce enough effect to impress investors who start losing their excitement over the AI hype, so the second part of the story is now unfolding,” said Ilia Kolochenko, founder of application security company ImmuniWeb and a cybersecurity and data-protection lawyer. “AI agents and LLM models tasked with security testing can, and almost certainly will, go rogue when security controls or safeguards are insufficient,” Kolochenko told The Register. “Powerful LLMs are unpredictable by design and thus virtually uncontrollable by humans. Using frontier AI models for security testing might be extremely costly from the legal viewpoint.” Existing laws on both sides of the Atlantic likely hold the AI operator liable for any damages caused if an agent or AI system escapes its sandbox and breaches a third party. “Excuses like ‘AI did it’ do not currently exist in the eyes of the law, leaving AI vendors on the hook,” he said, adding that this also holds true for end-users. “Even if your security testing tool is powered by a third-party AI model, your company will be fully liable if something goes wrong,” Kolochenko warned. “You may then file a lawsuit against the AI vendor that you used, but your chances of succeeding in the court of law are tiny due to countless contractual disclaimers and limitations of liability that may be enforceable against you.” His final words of advice: “If you plan to use agentic AI for security testing, you must think twice and talk to your lawyers. Otherwise, you could start getting summonses to court on a daily basis.” ®

Before yesterdayTech

A missing underscore sent innocent man to prison for 18 months

27 July 2026 at 16:22

One missing underscore in a Skyrim-themed username put an innocent Nova Scotia man in prison for 18 months.

A 2018 child-luring investigation, which began in Madison, Wisconsin, and eventually extended to Halifax, Canada, was based on a false premise.

Police were looking for a man using the Kik messaging service under the name "fus__ro_dah" (two underscores after "fus"), but they accidentally requested records for the username "fus_ro_dah" (one underscore after "fus"). This one-character difference led them not to the perpetrator but to a Canadian man named Brandon Klayme.

Read full article

Comments

© Getty Images

ChatGPT starts blocking direct requests to copy an author's style

27 July 2026 at 12:58

OpenAI's ChatGPT is now refusing requests to generate text that directly mimics the style of famous authors. When asked to do so, the popular LLM instead offers a response that draws on the "broad qualities" of those authors "while remaining distinct in its own voice," for example.

This morning, Ars received the following response to a test prompt asking for a story introduction in the style of Stephen King:

I can definitely write with the hallmarks of atmospheric, character-driven horror and small-town dread, but I can't write in Stephen King's exact style or closely imitate his distinctive voice. Here's an original opening that captures a similar feeling while remaining its own...

In testing, ChatGPT generated similar dodges for other authors both living (J.K. Rowling, Amy Tan) and dead (Charles Dickens, Ernest Hemingway). An analysis published by No Latency earlier this month found the same behavior for living authors but found ChatGPT complied with style-copying requests for deceased authors.

Read full article

Comments

Activist charged with felony after giving border agent "duress code" that wiped his phone

27 July 2026 at 11:58

In early 2025, Atlanta resident Samuel Tunick was on his way home following a trip abroad. After landing in the US, customs agents demanded access to his Pixel phone, which was running an alternative version of Android called GrapheneOS. Rather than hand over his data, Tunick used a clever feature of the software to delete everything. Now, he's facing federal charges.

The first hearing in this case happened last week, according to The Guardian, during which government attorneys and agents claimed that Tunick was subjected to a standard secondary interrogation at an international airport. During that encounter, agents were "looking for anything that’s prohibited." However, Tunick's legal team alleges he was targeted for his activism.

Tunick was involved with a group called Defend the Atlanta Forest, which opposed the construction of an enormous law enforcement training facility in the area often known as Cop City. What Tunick didn't know, according to his lawyers, was that he'd been placed on a watch list for his actions and that Customs and Border Protection had discussed over email plans to detain him upon his arrival back in the US for "suspected terrorism activities."

Read full article

Comments

© Ryan Whitwam

Why Meta Escaped a Landmark Social Media Lawsuit

24 July 2026 at 07:57

Meta avoided a closely watched social media addiction trial after the plaintiff dropped the remaining claim, leaving broader questions over platform design unresolved.

The post Why Meta Escaped a Landmark Social Media Lawsuit appeared first on TechRepublic.

Google breaks Alibaba’s record for Europe’s largest DMA fine

24 July 2026 at 03:32
Alibaba’s reign as the worst offender under the European Union’s Digital Markets Act (DMA) lasted just four days, after the European Commission yesterday fined Google €890 million for breaches of the law –€340 million more than the Chinese e-commerce company will pay. Europe even fined Google twice – once for treating its own services more favorably in search rankings and the second time for failing to properly inform users of its “Play” app store. The search infractions attracted a fine of €460 million ($523.5m/£393m) and the Play offenses will cost the Chocolate Factory €430 million ($490m/£367.5m). In US dollars, the fines total $1.013 billion – or one quarter of one percent of the $402 billion in revenue that Google’s parent company Alphabet won in its last full financial year. The Big G’s net income was $132 billion in the same year, making these fines less than one percent of its profits. Investors won’t be happy that the company has a billion-dollar bill to pay in Europe, but the ten-percent dip in Alphabet’s stock price this week may have more to do with news that it burned cash for the first time in 20 years to fund AI investments. The Commission fined Google after finding it “gives preferential treatment to its own services, including shopping, hotels, transport and sports results, over those of third parties in Google Search.” “Google displays its own services more prominently in search results, including at the top of the search results page or by using enhanced visuals and filters, while similar third-party services do not have the same prominence,” the Commission wrote. The Commission ordered the Play store fine because the DMA requires app store operators to let developers inform buyers about third party app stores or other distribution channels that offer cheaper ways to acquire software. The EU’s regulatory authorities felt Google didn’t meet that obligation. We’re told Google “… has proposed and started testing changes to how it presents its own services on Google Search,” and the Commission will “monitor the implementation of these solutions which constitute substantial progress towards compliance.” Interestingly, the Commission has also started talking to Google about the search fine in the context of the Web giant’s new AI Overviews and AI Mode. Those tools show even fewer links that Google search and are already driving more revenue for Google. Google has also taken steps to ensure that visitors to Play get more info about alternative software-marts. “These constitute good progress towards compliance and will also be assessed in light of the cease and desist order of today's decision,” the Commission states. Google has opposed the decision, arguing it weakens its services and makes Play less secure. The company says it’s also developing artificial general intelligence, so probably has enough smarts to figure out how to keep its services safe and relevant. ®

Europe slaps AliExpress with €550 million fine for selling dodgy goods

21 July 2026 at 02:58
The European Commission yesterday fined Alibaba subsidiary AliExpress €550 million ($630m/ £467m) for not doing enough to stop selling dodgy products - the largest ever fine issued under the Digital Services Act. AliExpress is Alibaba’s consumer-facing e-commerce brand and complements the parent company’s B2B biz. Brussels last year warned AliExpress that it wasn’t doing enough to stop sellers on the service hawking illegal products, or to ensure its recommendation engines didn’t promote those dodgy goods. Wielding the awesome powers of the Digital Services Act (DSA), Brussels told the Chinese e-commerce company to clean up its act and spelled out the steps required to do so. A year later, the Commission (EC) decided AliExpress hasn’t done enough and announced the giant fine, which the Commission justified because it found AliExpress did not properly evaluate whether it had sufficient staff to review potentially illegal products, and did not conduct an adequate assessment of how its recommender and advertising systems exacerbate the spread of illegal products. The Commission also made the following four findings: AliExpress' system to detect illegal products did not work properly; AliExpress did not properly enforce its penalty policy for traders selling illegal products; AliExpress' product compliance checks could be easily circumvented through mis-categorisation of products; AliExpress failed to adequately prevent the spread of counterfeit products. In its announcement of the fine, the Commission noted that it set fine at €550 million after considering “mitigating circumstances that operate in favor of AliExpress, such as the novelty of the Digital Services Act.” The Act allows fines of up to six percent of global turnover and Alibaba Group’s annual revenue was $148 billion for the year ended March 31st. Brussels could therefore have demanded almost $9 billion. The fine comes weeks after Europe introduced new customs fees seemingly designed to make life hard for Alibaba and its Chinese peers Temu and Shein. Europe doesn’t like very cheap single-item imports, which policymakers fear can lead to illegal and unsafe products reaching the continent, at prices that local retailers can’t match. The EC understands that its new fees could see e-tailers adapt their operations by shipping in bulk to warehouses within the European Union, an outcome felt to give the bloc a better chance of regulating cheap products. Fining AliExpress €550 million is another nudge towards changing business models. ®

DA: Cop covered bodycam to snap nude prisoners on his iPhone—but other cams caught him

20 July 2026 at 18:15

On March 31, 2026, a rather odd complaint arrived at the Bucks County, Pennsylvania District Attorney's Office.

It came from the local sheriff's office, and it concerned one of their own, Deputy Sheriff Ryan Gaffney. The allegation was unusual: Gaffney had used his iPhone to snap photos of nude prisoners he had encountered in his job—and he had then shared those photos with "several female civilian employees inside the Sheriff's Office."

The main claim involved a local man suffering a mental health crisis on the morning of January 30, 2026. Five fully uniformed deputies had arrived at the house and were in the upstairs bedroom. Their detainee was naked from the waist down and had just been persuaded to put on some pants.

Read full article

Comments

© Getty Images

Apple Sued Over Hide My Email Privacy Claims

17 July 2026 at 10:19

Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims.

The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic.

Even HP resellers thought the price of toner and ink was too high – so HP India facilitated an illegal cartel

16 July 2026 at 01:01
The Competition Commission of India (CCI) has fined HP Inc. and some of its resellers, for what it calls “cartelisation” activities that inflated the cost of PCs and printers – and which it says HP used to head off threats from resellers to sell counterfeit ink cartridges. The ₹138.85 crores/$14.4 million fine won’t be a massive inconvenience to HP. The facts of the case may be, as the CCI found HP told its resellers what prices to charge when they bid for tenders posted to a government procurement site. The PC and printer giant also prohibited some of its resellers from bidding on tenders. In its order related to HP’s bids to sell printer supplies, the regulator reveals it accessed WhatsApp records that show HP staff and some of its resellers “were operating in a collusive arrangement and shows the practice of bid rigging including cover bidding, price fixation, and customer allocation, during 2017-2020.” Cover bidding is the practice of having one reseller make a ridiculously high bid that a vendor knows won’t win a deal, in the hope other resellers who offer more reasonable quotes will get the sale. The order also claims that HP would decide in advance which of its resellers would sell to which customer. The CCI found that one of HP’s motives was to ensure that it remained competitive with other PC and printer makers, rather than to favor a particular reseller. Another motive was to stop resellers from selling counterfeit ink and toner. “Due to constant downward pressure on pricing because of new resellers, Tier-2 resellers threatened a shift to low-cost counterfeit products to compete on price,” the order states. Some of those resellers formed an “understanding” about the prices they would charge, so they would not undercut each other’s bids. The order says HP “facilitated” development of that understanding to defend its printer supplies business. “HP India was commercially forced into a position where it had to support the collusive arrangement adopted by the Tier-2 resellers,” the order states. In a second order regarding the sale of PCs, the CCI found HP’s actions helped HP to navigate the reverse auction process used to determine the winner of some tenders. “HP India faced the risk if its resellers exited early due to unsustainable downward pricing pressure resulting in no sale for HP India,” the order states. “The coordination amongst HP India’s reseller was accordingly designed to ensure that at least one HP reseller remained present in the final round.” The orders compel HP, and the resellers it worked with, to cease all such activity. ®

❌
❌