AI Content in Web Search Results: Your Fault and Controlling Content Is Just Too Hard
August 4, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
I spotted a write up that surprised me. The BBC or BeeB published “Some People’s Chats with Claude AI Made Publicly Available Online.” Since I believe everything I read on the Internet, I will operate as if the Beeb is delivering actual factual information.
The article states:
Hundreds of user conversations with Anthropic’s popular artificial intelligence (AI) chatbot Claude were found to have been available to essentially anyone using Google or other web browsers. Links to the chats, some of which included personal and work information, would show up if a user of a search engine like Google used a site-specific search term. The searches showed Claude chats for which a user had decided to “share” a link had been saved by search engines like Google, leaving them accessible to the broader public.

Two members of big AI tech leadership find the idea of editorial responsibility unacceptably stupid. Thanks, MidJourney. Good enough.
Now who is to blame? Anthropic’s position about sharing is similar to OpenAI’s; that is, the user is responsible for any sharing. And what about the Google? The Beeb offers this statement from that estimable firm:
A spokesman for Google made clear to the BBC that the company does not control “what pages are made public on the web,” saying instead that action comes from websites. “We give site owners clear controls to decide whether pages can be crawled or indexed, and we always respect those directives.”
I love this approach to smart software and indexing, often without permission, content accessible via the Internet. The users are to blame. But for Google, it is abundantly clear that despite more than 100,000 full time equivalents, the firm is not able to control what pages are made public on the web. I include a site called Altenen in my lectures for LE and intel professionals. This is an interesting site, and you may want to check out the firm’s tutorials and for-fee information about credit and bank card theft. Google just can’t control what pages are made public on the web if the Beeb’s story is spot on. Oh, I locate the Altenen outfit via a Google search. I would not advise providing this site name to one’s teeny boppers.
I was disappointed that the Beeb did not point out that more than 80 percent of online queries flow to the Google. And in Denmark, the GOOG hits 99 percent of the search traffic. Content in Google becomes the content from a couple of billion people. Yep, no control.
Now I want to shift gears to a write up in Ars Technica. This report is “It’s Official: EU Will Force Google to Share Search Data and Open Up AI on Android.” I want to direct attention to the subtitle; to wit:
Google says these changes could endanger user privacy and security.
That’s clear. The EU will take steps for Google to share search data over which it has no control. Furthermore, if Google were to be required to share its data, the chief problem would be “user privacy and security.”
As a dinobaby, I am growing weary of the behaviors of the big tech outfits. The “it’s easier to say I am sorry than ask for permission” combined with the “move fast and break things” is for me a matter of concern. Others find the behavior beyond reproach. If there’s a problem, it’s my fault and yours. And whatever we do, we can’t control content.
Think about that for a moment.
Stephen E Arnold, August 4, 2026
Windows 11 Allegedly Has A Tracker Without an Off Switch
July 20, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
I love it when Microsoft provides outputs about user privacy. Frankly I ignore the baloney generated by a weird corporate blend of MBAs, lawyers, and PR professionals. Does it flow? Does it sound good? Does it advance our position with investors? Once a yes answer is agreed upon, big outfits make important announcements about privacy, trust, and security. But then along comes a story like “Microsoft Admits Windows 11 Has A GDID Tracker With No Off Switch, First Documented Publicly In An FBI Hacker Complaint.”
The main idea is that Windows captures a Social Security number for each computer with its operating system. This is called in Windows’ jargon the Global Device Identifier or GDID. Allegedly the clever Social Security number makes it possible to track an individual across VPNs, proxy servers, and sketchy service provides in foreign countries. The revelation about this magical “security and privacy feature” comes from a bad actor who allegedly was a a member of the Scatter Spider hacking group.
The Windows Latest professionals allegedly read a 39 page briefing about the Scatter Spider discovery. The write up says:
“A Global Device ID (GDID) is a permanent, unique digital fingerprint that Microsoft automatically assigns to your computer when you install Windows or sign into a Microsoft account.Microsoft uses it to manage software licensing and Windows Store apps, but because it links all your online activities on that computer back to a single identity, law enforcement can use it to track a device’s true owner across the Internet survives Windows updates. It does not survive a clean reinstall, and Microsoft’s footnote in the complaint admits “one Microsoft user could have multiple GDIDs” over the life of a single account.Microsoft said what the GDID does without saying where it is inside Windows. For that, independent researchers had to reverse engineer it, because Microsoft has published exactly one sentence about GDID in the Azure Monitor reference for Delivery Optimization reporting, where a column called GlobalDeviceId is described only as ‘Microsoft global device identifier. This is an identifier used by Microsoft internally.’”
The bad actor was apprehended because he used the same Windows device across all his hacking activities. What is interesting is that the Microsoft statements about privacy and security bump up against this type of invasive track. I suppose this is a standard benefit of using Microsoft software, systems, and services. The write up describes some steps a person can take to control some of the data flowing to the privacy and security oriented operations that make Microsoft so Microsoftie. But most Windows users won’t know how to set up a local account, turn off diagnostic data transmission, block advertising IDs, disable the Cloud search feature, and other useful steps.
Have you taken these steps? The fact that the bad actor was put in a jar is a positive. Plus, the data revealed in the 39 page briefing seems to verify what many Microsoft-cautious professionals have believed about the firm’s willingness to talk about privacy and its actions that make privacy less important.
Whitney Grace, July 20, 2026
In Car Driver / Passenger Monitoring
July 16, 2026
Another dinobaby post. No AI unless it is an image. This dinobaby is not Grandma Moses, just Grandpa Arnold.
A month ago, a Waymo car drove a criminal from a burglary site. That was in June 2026. According to “A Thief Used a Waymo As a Getaway Car. Six Months Later, Police Still Have No Suspect.” Why? That’s a good question. The article says:
Waymo’s latest Jaguar vehicles are equipped with 29 cameras that provide a 360-degree view, and rides are tied to user accounts.

Thanks, MidJourney. Good enough.
Okay, the issue may be fixed. The San Jose Mercury News reported “Waymo Car Delivers Misbehaving Teen Passengers to San Mateo Police.” Forget the blurring of faces and the other tweaks the Google makes to its monitoring systems.
According to the July 7, 2026, write up:
The 15-year-olds allegedly were drinking alcohol and shooting water beads from a toy gun as they rode in the driverless car Monday [July 6, 2026]…. Waymo stopped the car in a parking lot and notified the police, who detained the teens.
How does a Waymo car know there’s a problem with drunken teens? Easy. The write up says:
Waymo cars have interior cameras, and the images can be monitored by the company’s employees. In “more urgent circumstances,” the support team “may access live video during a trip,
The EU , according to “Every New EU Car Now Has a Camera Watching the Driver’s Face,” like the idea of driver surveillance. The jargon for the system is advanced drive distraction warning, and it:
tracks a driver’s gaze, head position, and eye movement to detect when attention has drifted from the road, triggering an alert after 3.5 seconds of distraction at highway speeds or 6 seconds at lower speeds.
Several observations seem to be warranted:
- Where is smart software in this monitoring game? I assume it is operating, but AI does not feature in either the Google “human monitor” approach or the semi-useful driver distracting buzzer or bell.
- Will automakers charge a fee for vehicle surveillance? This seems more interesting to me than a subscription to a heated seat.
- What’s the end point of vehicle monitoring? I can envision some increased costs for manufacturers and government agencies?
In order to be safe, monitoring is a thing. But I find the inability of the Google to provide useful Waymo data about a rider who allegedly committed a crime amusing. How long will it take for the owner or passenger in a face cam equipped vehicle to discover the impact of a daub of Vaseline petroleum jelly over the lenses? Of course, maybe the car won’t run. Presumably that’s not a problem.
Net net: Captured videos are definitely going to be posted on TikTok-type services.
Stephen E Arnold, July 16, 2026
Meta and NSO: Jousting Again
June 19, 2026
Two estimable companies. Another dust up. Which does one believe? I will leave it to you, but did I hear a collective groan. The allegation is that NSO Group of Pegasus fame is supposedly targeting people inside WhatsApp. Is there an injunction order to case and desist? Yep, says The Register in the article “NSO Group Back In Meta’s Crosshairs After Alleged WhatsApp Targeting.” Meta investigated reports from users that said there was activity attempting to lure users off WhatsApp and onto outside websites. This is part of a longer battle between the two companies. The Register says:
“The move marks the latest chapter in the long-running legal battle between Meta and the Israeli spyware maker. A US court found NSO liable in December 2024 for hacking WhatsApp users via its Pegasus spyware. In May 2025, a jury awarded Meta roughly $168 million in damages, but the judge later cut that to $4 million while issuing a permanent injunction barring NSO from targeting WhatsApp or its users.”
WhatsApp defines NSO Group as a “malicious company” and it is listed on the US government’s Entity List. If the restrictions were eased, it would place Americans, American companies, US national security, and the entire slew of the world’s population would be vulnerable.
Engadget reported on the same situation in their article, “WhatsApp Spyware Maker NSO Group Is Still Targeting Its Users.” They have more information on the people who were targeted by NSO Group:
“Less than a year later, Meta says it’s caught NSO violating the terms of that order. According to the company, it caught a cluster of NSO-linked accounts that were attempting to trick WhatsApp users into clicking on malicious links that were similar to other phishing campaigns that have been tied to the spyware maker. According to a Meta spokesperson, the latest phishing campaign targeted fewer than 10 WhatsApp users who were “primarily” in Jordan and Lebanon.”
What’s the truth of the matter? First, we live in a world of misinformation, disinformation, and malformation of data. Second, a “he says, she says” argument is a matter for the courts, not a dinobaby’s blog. Third, software roughly comparable to NSO’s Pegasus innovation is available from other vendors. Therefore, my question is, “What are regulatory authorities in the US and other countries to block or curtail the use of malware specifically designed to exfiltrate data from services bursting with juicy personal information?
Whitney Grace, June 19, 2026
Chat Data Leaks: Why Worry?
January 23, 2026
A couple of big outfits have said that user privacy is number one with a bullet. I believe everything I read on the Internet. For these types of assertions I have some doubts. I have met a computer wizard who can make systems behave like the fellow getting brooms to dance in the Disney movies.
I operate as if anything I type into an AI chatbot is recorded and saved. Privacy advocates want AI companies to keep chatbot chat logs confidential. If government authorities seek information about AI users, people who treasure their privacy will want a search warrant before opening the kimono. The Electronic Frontier Foundation (EFF) explains its reasoning: “AI Chatbot Companies Should Protect Your Conversations From Bulk Surveillance.”
People share extremely personal information with chatbots and that deserves to be protected. You should consider anything you share with a chatbot the equivalent of your texts, email, or phone calls. These logs are already protected by the Fourth Amendment:
“Whether you draft an email, edit an online document, or ask a question to a chatbot, you have a reasonable expectation of privacy in that information. Chatbots may be a new technology, but the constitutional principle is old and clear. Before the government can rifle through your private thoughts stored on digital platforms, it must do what it has always been required to do: get a warrant. For over a century, the Fourth Amendment has protected the content of private communications—such as letters, emails, and search engine prompts—from unreasonable government searches. AI prompts require the same constitutional protection.”
In theory, AI companies shouldn’t comply with law enforcement unless officials have a valid warrant. Law enforcement officials are already seeking out user data in blanket searched called “tower dumps” or “geofence warrants.” This means that people within a certain area have their data shared with law enforcement.
Some US courts are viewing AI chatbot logs as protected speech. Dump searches may be unconstitutional. However, what about two giant companies buying and selling software and services from one another. Will the allegedly private data seep or be shared between the firms? An official statement may say, “We don’t share.” However, what about the individuals working to solve a specific problem. How are those interactions monitored. From my experience with people who can make brooms dance, the guarantees about leaking data are just words. Senior managers can look the other way or rely on their employees’ ethical values to protect user privacy.
However, those assurances raise doubts in my mind. But as the now defunct MAD Magazine character said, “Why worry?”
Whitney Grace, January 23, 2026
Google Data Slurps: Never, Ever
December 11, 2025
Here’s another lie from Googleland via Techspot, “Google Denies Gmail Reads Your Emails And Attachments To Train AI, But Here’s How To Opt-Out Anyway.” Google claims that it doesn’t use emails and attachments to train AI, but we know that’s false. Google correctly claims that it uses user-generation data for personalization of their applications, like Gmail. We all know that’s a workaround to use that data for other purposes.
The article includes instructions on how to opt out of information being used to train AI and “personalize” experiences. Gmail users, however, have had bad experiences with that option, including the need to turn the feature off multiple times.
Google claims it is committed to privacy but:
“Google has flatly denied using user content to train Gemini, noting that Gmail has offered some of these features for many years. However, the Workspace menu refers to newly added Gemini functionality several times.
The company also denied automatically modifying user permissions, but some people have reported needing multiple attempts to turn off smart features.”
There’s also security vulnerabilities:
“In addition to raising privacy concerns, Gmail’s AI functionality has exposed serious vulnerabilities. In March, Mozilla found that attackers could easily inject prompts that would cause the client’s AI generated summaries to become phishing messages.”
Imagine that one little digital switch protects your privacy and data. Methinks it is a placebo effect. Whitney Grace, December 11, 2025
A Interesting Free Software: FreeVPN
August 28, 2025
No AI. Just a dinobaby working the old-fashioned way.
I often hear about the wonders of open source software. Even an esteemed technologist like Pavel Durov offers free and open source software. He wants to make certain aspects of Telegram transparent. “Transparent” is a popular word in some circles. China releases Qwen and it is free. The commercial variants are particularly stimulating. Download free and open source software. If you run into a problem, just fix it yourself. Alternatively you can pay for “commercial for fee” support. Choice! That’s the right stuff.
I read “Chrome VPN Extension with 100K Installs Screenshots All Sites Users Visit.” Note: By the time you read this, the Googlers may have blocked this extension or the people who rolled out this digital Trojan horse may have modified the extension’s behavior to something slightly less egregious.
Now back to the Trojan horse with a saddle blanket displaying the word “spyware.” I quote:
FreeVPN.One, a Chrome extension with over 100,000 installs and a verified badge on the Chrome Web Store, is exposed by researchers for taking screenshots of users’ screens and exfiltrating them to remote servers. A Koi Security investigation of the VPN tool reveals that it has been capturing full-page screenshots from users’ browsers, logging sensitive visual data like personal messages, financial dashboards, and private photos, and uploading it to aitd[.]one, a domain registered by the extension’s developer.
The explanation makes clear that one downloads and installs or activates a Chrome extension. Then the software sends data to the actor deploying the malware.
The developer says:
The extension’s developer claimed to Koi Security that the background screenshot functionality is part of a “security scan” intended to detect threats.
Whom does one believe? The threat detection outfit or the developer.
Can you recall a similar service? Hint: Capitalize the “r” in “Recall.”
Can the same stealth (clumsy stealth in some cases) exist in other free software? Does a jet air craft stay aloft when its engines fail?
Stephen E Arnold, August 28, 2025
Leave No Data Unslurped: A New Google T Shirt Slogan?
August 25, 2025
No AI. Just a dinobaby working the old-fashioned way.
That mobile phone is the A Number One surveillance device ever developed. Not surprisingly, companies have figured out how to monetize the data flowing through the device. Try explaining the machinations of those “Accept Defaults” to a clutch of 70-something bridge players. Then try explaining the same thing to the GenAI type of humanoid. One group looks at you with a baffled work on their faces. The other group stares into the distance and says, “Whatever.”
Now the Google wants more data, fresh information, easily updated. Because why not? “Google Expands AI-Based Age Verification System for Search Platform.” The write up says:
Google has begun implementing an artificial intelligence-based age verification system not only on YouTube but also on Google Search … Users in the US are reporting pop-ups on Google Search saying, “We’ve changed some of your settings because we couldn’t verify that you’re of legal age.” This is a sign of new rules in Google’s Terms of Service.
Why the scope creep from YouTube to “search” with its AI wonderfulness? The write up says:
The new restrictions could be another step in re-examining the balance between usability and privacy.
Wrong. The need for more data to stuff into the assorted AI “learning” services provide a reasonable rationale. Tossing in the “prevent harm” angle is just cover.
My view of the matter is:
- Mobile is a real time service. Capturing more information of a highly-specific nature is something that is an obvious benefit to the Google.
- Users have zero awareness of how the data interactions work and most don’t want to know to try to understand cross correlation.
- Google’s goals are not particularized. This type of “fingerprint” just makes sense.
The motto could be “Leave no data unslurped.” What’s this mean? Every Google service will require verification. The more one verifies, the fresher the identify information and the items that tag along and can be extracted. I think of this as similar to the process of rendering slaughtered livestock. The animal is dead, so what’s the harm.
None, of course. Google is busy explaining how little its data centers use to provide those helpful AI overview things.
Stephen E Arnold, August x, 2025
Stephen E Arnold, August 25, 2025
DuckDuck Privacy. Go, Go, Go
August 8, 2025
We all know Google tracks us across the Web. But we can avoid that if we use a privacy-touting alternative, right? Not necessarily. Simple Analytics reveals, “Google Is Tracking You (Even When You Use DuckDuckGo).” Note that Simple Analytics is a Google Analytics competitor. So let us keep that in mind as we consider its blog’s assertions. Still, writer Iron Brands cites a study by Safety Detectives as he writes:
“The study analyzed browsing patterns in the US, UK, Switzerland, and Sweden. They used a virtual machine and VPN to simulate users in these countries. By comparing searches on Google and DuckDuckGo, researchers found Google still managed to collect data (often without the user knowing). Here’s how: Google doesn’t just track people through Search or Gmail. Its invisible code runs on millions of sites through Google Analytics, AdSense ads, YouTube embeds, and other background services like Fonts or Maps. That means even if you’re using DuckDuckGo, you’re not totally out of Google’s reach. In Switzerland and Sweden, using DuckDuckGo cut Google tracking by half. But in the US, more than 40% of visited pages still sent data back to Google, despite using a privacy search engine. That’s largely because many US websites rely on Google’s tools for ads and traffic analysis.”
And here we thought Google made such tools affordable out of generosity. The post continues:
“This isn’t just about search engines. It’s about how deeply Google is embedded into the internet’s infrastructure. Privacy-conscious users often assume that switching to DuckDuckGo or Brave is enough. This research says otherwise. … You need more than just a private browser or search engine to reduce tracking. Google’s reach comes from third-party scripts that websites willingly add.”
To owners of those websites, Brands implores them to stop contributing to the problem. The write-up emphasizes that laws like the EU’s GDPR do not stem the tide. Such countries, we are told, are still awash in Google’s trackers. The solution? For both websites and users to divest themselves of Google as much as possible. As it happens, Brand’s firm offers site owners just such a solution—an analytics platform that is “privacy-first and cookie-free.” Note that Beyond Search has not independently verified these claims. Concerned site owners may also want to check out alternative Google alternatives.
Cynthia Murrell, August 8, 2025
Apple and Google Texting Bad. So What Are the Options?
December 17, 2024
This blog post flowed from the sluggish and infertile mind of a real live dinobaby. If there is art, smart software of some type was probably involved.
This headline caught my attention: “FBI Warns iPhone and Android Users to Stop Texting Each Other for a Disturbing Reason.” What is that disturbing reason? According to the online article cited:
Both the FBI and US Cybersecurity and Infrastructure Security Agency are warning users to use a messaging app instead and one that uses end-to-end encryption. The warning comes amid a major cyberattack that has been called ‘unprecedented’ by the press. The attack has impacted telecommunications companies such as AT&T and Verizon. By using encrypted messaging apps, texters can keep their messages hidden from hackers. The hacking campaign has been nicknamed Salt Typhoon by Microsoft and it has not been fully solved. NBC News called it ‘one of the largest intelligence compromises in US history’.
Interesting. I recall that AT&T was not particularly chatty when information about a security compromise floated around. T-Mobile has experienced a few security issues as well. And Verizon? Same boat.
It is interesting that a sinking boat is an image several art generators refuse to produce. Anyway, Midjourney — after a lot of semantic wrangling spit out this good enough image.
After reading the article, I decided to navigate to X.com and ask Grok what the options were for a person who has muscle memory for texting folks from an Apple or Android mobile device? To use Grok, navigate to the tweeter, log in, and look for the Grok word on the displayed page. I went through these hoops slowly because when I queried Google about “how to use Grok”, the Google told me I had to sign up for a premium membership. That was wrong. No wonder Google is a service I find a bit short of the target.
Here are the services Grok (Mr. Musk’s smart software designed to compete in the Big Boy AI dodgeball contest). I quote the tweet thing’s smart output:
- “Signal: Known for its strong privacy features, Signal offers end-to-end encryption for texts, voice calls, and video calls. It’s open-source, which adds to its credibility for privacy-conscious users. Signal is available on both Android and iOS, making it a great cross-platform option.
- WhatsApp: With over 2 billion users, WhatsApp is a popular choice for cross-platform messaging. It supports text, voice, and video calls with end-to-end encryption. However, it’s worth noting that WhatsApp is owned by Meta (formerly known as Facebook), which might be a concern for privacy.
- Telegram: Offers a wide range of features like large group chats, channels, bots, and self-destructing messages. While it provides end-to-end encryption in its “Secret Chat” mode, not all chats are encrypted by default, which could be a privacy concern for some users. Telegram is available on both Android and iOS.
- Facebook Messenger: Another Meta-owned service, it’s widely used due to its integration with the social network. It supports free calls, video chats, and even has features like payment options in some regions. However, its privacy policies are often scrutinized.
- Google Chat: Part of Google Workspace, this app provides a platform for both personal and work-related communications with features like spaces for team collaboration. It’s integrated well with other Google services, although its adoption outside of Google’s ecosystem is less widespread.
- Viber: Offers free calls and messages, including stickers, GIFs, and public chats. Its user base is significant in certain regions but less so globally compared to WhatsApp or Telegram. Viber also has end-to-end encryption for calls and messages.
- Spike: Described as an email-based messaging app, Spike combines email and chat functionality, making it suitable for both personal and professional use. It’s noted for its cross-platform capabilities and privacy focus.
- SimpleX Chat: An open-source, privacy-focused chat app that doesn’t require phone numbers for registration, focusing on decentralization and user privacy.
- Element (formerly Riot.im): Based on the Matrix protocol, it’s an open-source, decentralized platform that supports secure, encrypted communication. It’s good for those looking for privacy with the flexibility of self-hosting.
- Beeper: An all-in-one messaging app that aims to unify various messaging services into one platform, although it has limitations like no official iMessage support due to Apple’s policies.”
Each of these apps is allegedly an E2EE or end-to-end encrypted messaging service. These are not presented in alphabetical order. I assume that Grok is providing the names in a rank ordering based on some criteria not explained to me. But that’s the future of smart software. Just do something and say, “Good enough.”
I noted several things about this list:
- There are no Chinese messaging apps. Is this censorship from an outfit seemingly concerned about free speech. I was surprised at the omission of QQ and WeChat with appropriate surveillance notices from Grok.
- One approach is for messaging clients to rely on Extensible Messaging and Presence Protocol. Conversations for Android and ChatSecure for iOS were at one time options.
- Inclusion of Telegram is definitely interesting because Pavel Durov has reversed course and now cooperates with law enforcement. Telegram has even played nice with anti-CSAM organizations. The about face coincided with his detainment by French authorities.
- The Grok listing does not include new and possible interesting services like PrivateLine.io., which illustrates the shallow nature of the knowledge exposed to these smart systems. (Even Yandex.com lists this service in its search results.)
- Alphabetizing lists is just not part of the 2024 world it seems.
There are some broader questions about encrypted messaging which are not addressed in the cited write up or the Grok “smart” output; for example:
- Are other messaging apps encrypted end to end or are there “special” operations which make the content visible and loggable once the user sends the message?
- Is the encryption method used by these apps “unbreakable”?
- Are the encryption methods home grown or based on easily inspected open source methods?
- What entities have access to either the logged data about a message or access to the message payload?
The alarm has been sounded about the failure of some US telecommunications companies to protect their own systems and by extension the security of their customers. But numerous questions remain with partial or no answers. Answers are, from my point of view, thin.
Stephen E Arnold, December 17, 2024

