Sign in

Wolfie Christl

@wchr.bsky.social
4.8K followers 362 following 516 posts

Public-interest researcher at Cracked Labs | Research fellow at Citizen Lab | Vienna, Austria | Tech and society. Tracking, surveillance, data economy, platform power, algorithmic decisions, datafication of work. wolfie.crackedlabs.org/en

PostsRepliesMedia
Wolfie Christl @wchr.bsky.social · 16h
Youtube wird neu hochgeladen, wie ich höre. Anyway, eh viel besser, das Video gibts ganz ohne YT/Tracking auch hier: tube.moment.at/w/38HawnMtwB...
tube.moment.at
Wolfie Christl: Illegale Massenüberwachung mit App- und Werbedaten – re:publica Vienna 2026
Eine Untersuchung des Wall Street Journal hat 2020 erstmals aufgedeckt, dass staatliche Behörden - wie die US-Abschiebebehörde ICE - Daten aus der Online-Werbung und von Smartphone-Apps für Überwac...
051
Wolfie Christl @wchr.bsky.social · 19h
Staatliche Behörden kaufen Standort- und Verhaltensdaten aus der Online-Werbung für Überwachung - in den USA, El Salvador, Ungarn und auch in Österreich. Wie funktioniert das? Warum ist das (grund)rechtlich ein einziges Desaster? Mein Vortrag auf der re:publica Wien: www.youtube.com/watch?v=cahD...
youtube.com
Wolfie Christl: Illegale Massenüberwachung mit App- und Werbedaten – re:publica Vienna 2026
YouTube video by re:publica Vienna
192
Wolfie Christl @wchr.bsky.social · 07/10/2026
Noteworthy. In recent years, this adtech/data group named Infillion acquired the ruins of adint supplier UberMedia, assets from DrawBridge, MediaMath, retail data broker Catalina and location data brokers Fysical, Gimbal, Foursquare, including Placed, Factual. www.adexchanger.com/marketers/in...
adexchanger.com
Infillion Acquires Foursquare, Adding More Location Data To Its Ever-Growing Ad Tech Stack | AdExchanger
Infillion checked in with its latest acquisition on Friday: Foursquare. Terms of the deal were nor disclosed.
003
Reposted by Wolfie Christl
Roland Meyer @bildoperationen.bsky.social · 05/10/2026
Social media is a paranoia machine. It makes connections explicit, though not transparent. It not only allows you to trace ties between people, institutions, and events, but also continually produces new ties. On social media, everything becomes connected, and thus potentially suspicious
215545
Reposted by Wolfie Christl
Sebastian Meineck @sebmeineck.bsky.social · 06/10/2026
Kirchen, Moscheen, Synagogen: Datenhändler gefährden Gläubige in Deutschland. Dahinter stecken frei verkäufliche Handy-Standortdaten. @roofjoke.netzpolitik.org & ich haben mehr als eine Million Standortdaten an Glaubensorten gefunden. #DatabrokerFiles netzpolitik.org/2026/kirchen... 1/3
netzpolitik.org
Datenhändler gefährden Gläubige in Deutschland
Religiöse Menschen lassen sich mit frei verkäuflichen Handy-Standortdaten der Werbe-Industrie ausspionieren. Mehr als eine Million Standortdaten an Glaubensorten fand netzpolitik.org in kostenlosen Vo...
12312
Wolfie Christl @wchr.bsky.social · 03/10/2026
So now everyone must use "Superintelligence", in quotes?
120
Wolfie Christl @wchr.bsky.social · 02/10/2026
LLM chatbot surveillance advertising is going to be next-level disastrous, on every level.
02013
Wolfie Christl @wchr.bsky.social · 02/10/2026
Plus, OpenAI's new integration with LiveRamp (acquired by Publicis) enables profiling and targeting using population-scale identity records linking names, postal, email, phone, and digital IDs associated with devices, browsers and platform user accounts: liveramp.com/blog/bringin...
liveramp.com
Bringing the Power of RampID Globally to Custom Audiences in ChatGPT Ads
Bringing the power of RampID globally to Custom Audiences in ChatGPT Ads
1159
Wolfie Christl @wchr.bsky.social · 02/10/2026
The web and mobile apps of major conversational AI engines transmit prompts, titles and conversation permalinks to advertising data firms, alongside device IDs, hashed email and other persistent identifiers. Comprehensive analysis, like always from this team: jorgegarciaherrero.com/wp-content/i...
26667
Wolfie Christl @wchr.bsky.social · 30/09/2026
Übermorgen Freitag um 16:45 sprech ich bei der @re-publica.com in Wien zum Thema "Illegale Massenüberwachung mit App- und Werbedaten" und zum hochproblematischen Kauf des Überwachungsystems "Webloc" durch das österreichische Innenministerium: vienna.re-publica.com/de/session/i...
083
Wolfie Christl @wchr.bsky.social · 24/09/2026
Selbst wenn das Dienstgerät gesichert ist, reicht es immer noch, wenn das private Gerät in die Nähe entsprechender Standorte kommt. Und wenn das konsequent vermieden wird, gibts immer noch Familie & Friends. Solange mobile Geräte unkontrolliert personenbezogene Daten an hunderte Actors rausblasen...
100
Wolfie Christl @wchr.bsky.social · 24/09/2026
Hier mein Thread zum Webloc-Kauf durch das BMI vom Juni: bsky.app/profile/wchr... Nächste Woche mach ich einen Vortrag zum Thema bei @re-publica.com Wien, 2.10.2026 um 16:45 Uhr: vienna.re-publica.com/de/session/i...
1102
Wolfie Christl @wchr.bsky.social · 24/09/2026
Seit Juni 2026 ist klar: AT ist das zweite EU-Land, für das der Kauf von - m.E. illegal weitergegebenen - Werbedaten bestätigt ist. Ich hab eine Studie zum vom BMI genutzten Überwachungssystem Webloc geleitet, im April veröffentlicht vom Citizen Lab an der Uni Toronto: citizenlab.ca/research/ana...
citizenlab.ca
Uncovering Webloc: An Analysis of Penlink’s Ad-Based Geolocation Surveillance Tech
Location data collected from mobile apps and digital advertising can reveal habits, interests and almost any other aspect of someone's life. In this report, we uncover how a geolocation surveillance s...
1100
Wolfie Christl @wchr.bsky.social · 24/09/2026
Der dem Innenministerium unterstehende Verfassungsschutz/DSN, dessen Mitarbeiter sich im Datensatz fand, müsste das wissen. Denn das BMI selbst kauft Werbedaten für Überwachungszwecke und legitimiert damit diese illegalen Datenpraktiken. Zweiter Teil der News-Recherche: www.news.at/investigativ...
news.at
Wie Österreichs Innenministerium Menschen überwachen kann
Schon mit einfachen Mitteln und eingeschränkten Datensätzen lassen sich Menschen über Standortdaten ausforschen. Mit professioneller Software und teuren Abos ist noch viel mehr möglich. Neben der US-B...
3176
Wolfie Christl @wchr.bsky.social · 24/09/2026
Der Datensatz ist einer von vielen. Nach wie vor sammeln tausende Werbedatenfirmen Profildaten über ganze Bevölkerungen. Die DSGVO wird nicht durchgesetzt. Das ist ein massiver Eingriff in die Rechte von uns allen - und ein nationales Sicherheitsrisiko, wie die News-Recherche einmal mehr zeigt.
1143
Wolfie Christl @wchr.bsky.social · 24/09/2026
News hat Beschäftigte von österreichischen Inlands- und Militärgeheimdiensten identifiziert, ihre Wohnhäuser, Arzt- und Friseurbesuche - auf Basis eines kommerziell erwerbbaren Datensatzes aus der digitalen Werbung, der Standortdaten von 562.448 Smartphones in AT enthält: www.news.at/investigativ...
13529
Reposted by Wolfie Christl
The Citizen Lab @citizenlab.ca · 23/09/2026
Join senior researcher @wchr.bsky.social at @re-publica.com in Vienna on October 2nd to discuss how government agencies are accessing behavioural data from online advertising for surveillance purposes. Register here: tickets.infield.live/event/re-pub...
0127
Reposted by Wolfie Christl
Ailo @airavn.eurosky.social · 21/09/2026
It’s been 8 years since we published our report on how Google tricks people into extensive location tracking, and simultaneously filed complaints against Google. Today the decision from the Irish Data Protection Commission arrived: a €400 million euros fine. www.forbrukerradet.no/siste-nytt/d...
forbrukerradet.no
Google Fined €403 Million Following Consumer Council Report
Google has been fined €403 million by the Irish Data Protection Commission after the Norwegian Consumer Council exposed how the company manipulated users into accepting extensive tracking.
45937
Reposted by Wolfie Christl
Wurzelmann (Herbst era) @wurzelmann.at · 15/09/2026
Endlich ein sinnvoller Artikel über "KI" und die ganze unnötige Marketing-Scheiße, die von anderen Medien/Journalist*innen einfach ohne Recherche abgeschrieben werden. Schön zusammengefasst, gute Quellen, sinnvoll erklärt und objektiv besprochen. So geht das, danke @sukahiroaki.bsky.social!
derstandard.at
Von wegen KI-Apokalypse: Das Problem sind verantwortungslose Unternehmen, nicht magische KI
Warum die Diskussion über existenzielle Risiken durch KI an den realen Problemen vorbeigeht und die Hersteller von ihrer Verantwortung befreit
413266
Wolfie Christl @wchr.bsky.social · 14/09/2026
Proud I helped create the website for a 2002 Vienna conference where she discussed her stuff 🙃
041
Wolfie Christl @wchr.bsky.social · 12/09/2026
"On May 25, IAB Europe revoked AdNow’s right to deliver ads through the centralized real-time bidding system. From that moment on, AdNow stopped delivering ads in Romania and the rest of the EU. However, we identified other undeclared servers through which ads continue to be distributed" #tcf
021
Wolfie Christl @wchr.bsky.social · 12/09/2026
"This investigation reveals what data is harvested from Romanians, who ends up receiving it, and why the ads shown on platforms with conspiratorial and extremist content are among the most valuable to this network", based on analyzing 100k ads shown across 131 websites, by @victorilie.bsky.social:
snoop.ro
The Kremlin’s Digital Pirates: How Russian Tracking Pixels Harvest Romanians’ Data to Fund Conspiracies and Extremism - Snoop
This investigation reveals what data is harvested from Romanians, who ends up receiving it, and why the ads shown on platforms with conspiratorial and extremist content are among the most valuable to ...
255
Wolfie Christl @wchr.bsky.social · 10/09/2026
"when you design these systems, you're building a pinball machine for words, with different levers interacting to bounce the steel ball of language moving against other levers and mechanisms…you have to be aware of how your levers interact with each other and the people pulling them" Great metaphor
mail.cyberneticforests.com
Models Don't Go Rogue
Stochastic Flocks & Cybersecurity 'Pandemonium' 💡This essay was drafted from my appearance on Mél Hogan's podcast, The Data Fix, discussing the OpenAI / Hugging Face hack. Embedded below or find it o...
12611
Wolfie Christl @wchr.bsky.social · 09/09/2026
4 years after our investigation into profiling in UK online gambling, and 2 years after the ICO confirmed UK GDPR breaches based on our findings, a new study found "widespread dark patterns and non-compliance of GDPR requirements on UK online gambling sites": www.sciencedirect.com/science/arti...
193
Wolfie Christl @wchr.bsky.social · 09/09/2026
Via @jshermcyber.bsky.social: www.csis.org/analysis/eur...
csis.org
The European Front in Commercial Data Exploitation
Commercial location data remains a major hole in European—and especially in American—security that adversaries such as Russia and China are primed to exploit.
051
Wolfie Christl @wchr.bsky.social · 09/09/2026
Germany's domestic intelligence agency, the Verfassungsschutz, refers to the sale of mobile app location data as a "grave privacy intrusion" and warns that foreign actors may use the data to approach or attack individuals in the security/defense industries: www.verfassungsschutz.de/SharedDocs/p...
12614
Wolfie Christl @wchr.bsky.social · 04/09/2026
"The Army said ... that advertising IDs had been blocked on Windows computers 'since before 2021' but that Android and Apple ​mobile devices had only had it disabled by default 'since at least February 2026'." So US military phones were widely exposed until 2026? www.reuters.com/business/med...
reuters.com
EXCLUSIVE: US military turns off ad trackers on devices amid Middle East targeting reports
The effort to ​reduce the location data generated by smartphones comes as military officials weigh increasingly strict restrictions on phone use overall.
083
Wolfie Christl @wchr.bsky.social · 02/09/2026
The descriptions of LexisNexis Risk's investigative products for law enforcement including Accurint Virtual Crime Center, Data API and Public Safety Marketplace on its current website leave it unclear whether ThreatMetrix data is included. The description of 'LexID Digital' however is pretty clear.
130
Wolfie Christl @wchr.bsky.social · 01/09/2026
LexisNexis/RELX stated already in 2018 to combine data harvested from 4.5bn devices linked to 1.4bn 'online identities' (from its ThreatMetrix subsidiary embedded in 40,000 major websites and apps) with names, postal addresses, emails, phone numbers and public records: www.relx.com/~/media/File...
182
Wolfie Christl @wchr.bsky.social · 01/09/2026
LexisNexis Risk is a data broker that operates a kind of private population registry for the US, aggregating myriads of public records and other identity+risk assessment data on everyone. Combining that with device and network data is yet another level. s3.documentcloud.org/documents/28...
181
Wolfie Christl @wchr.bsky.social · 01/09/2026
The notice also suggests that LexisNexis Risk's identity surveillance systems provides API connections with "ICE applications, such as but not limited to, Palantir platform, PenLink, and ICE Data Analytics". It's not clear whether 'PenLink' refers to Tangles, Webloc, PLX or other Penlink products.
141
Wolfie Christl @wchr.bsky.social · 01/09/2026
This is significant. The requirements listed in a recent procurement notice for ICE's renewed purchase of LexisNexis Risk's LexID and Accurint Virtual Crime Center products mention inferring identity from "behavioral indicators, device metadata, network signatures, commercial telemetry data".
23032
Wolfie Christl @wchr.bsky.social · 01/09/2026
The Northern California Regional Intelligence Center (NCRIC) showed interest in buying Penlink's ad-based geolocation mass surveillance system Webloc, according to FOI records obtained by @shawnsegal.bsky.social, which also contain a recent Webloc promo brochure: fineprint.report/feed/ncric-p...
fineprint.report
A Bay Area Fusion Center Asked PenLink to Test Ad-ID Location Tracking on an Active San Jose PD Case
On August 5, 2026, an Assistant Deputy Director at the Northern California Regional Intelligence Center (NCRIC) emailed PenLink asking about a trial of Webloc,
051
Wolfie Christl @wchr.bsky.social · 22/08/2026
The Dutch GDPR regulator fined Uber €825m for deactivating driver accounts through automated systems. Paul-Olivier Dehaye, founder of a group that helped drivers access data, "eventually leading to the Dutch investigation", said they're preparing a class-action suit: www.reuters.com/world/dutch-...
reuters.com
EXCLUSIVE: Dutch regulator fines Uber $966 million for automating driver suspensions
The Dutch Data Protection Authority has fined Uber €825 million ($966 ‌million) for deactivating driver accounts through automated systems without adequately informing them, according to an August 17 ...
0104
Reposted by Wolfie Christl
Zach Edwards @thezedwards.bsky.social · 12/08/2026
So proud to launch our new startup today -- decryptads.com -- check out the coverage today from @josephcox.bsky.social and the team at @404media.co about why we're tackling this important privacy, ad tech and security challenge.
162
Reposted by Wolfie Christl
Jeremy White @jeremywired.bsky.social · 12/08/2026
SECRET SAUCE: @thiccreese.bsky.social wanted to find out what data McDonald’s loyalty program had on him. He got back a 515-page file that was equal parts amusing and concerning, even showing how the brand's algorithm predicts his next purchase. Full piece on @wired.com www.wired.com/story/mcdona...
wired.com
McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There
I requested a copy of my data from McDonald’s loyalty program and received an extensive, personalized report that algorithmically predicts my next purchase.
614557
Reposted by Wolfie Christl
Sebastian Meineck @sebmeineck.bsky.social · 11/08/2026
Ein Werkzeug namens #Webloc kann Menschen mit Daten aus dem Werbe-Tracking teils metergenau orten und verfolgen. Bislang war nur bekannt, dass staatliche Stellen das nutzen. Jetzt zeigen Recherchen: Die Technologie wird offenbar auch Unternehmen angeboten. #ADINT netzpolitik.org/2026/angebot...
netzpolitik.org
Gefährliches Überwachungs-Werkzeug breitet sich aus
Ein Werkzeug namens Webloc kann Menschen mit Daten aus dem Werbe-Tracking teils metergenau orten und verfolgen. Bislang war nur bekannt, dass staatliche Stellen das nutzen. Jetzt zeigen Recherchen: Di...
7189132
Wolfie Christl @wchr.bsky.social · 07/08/2026
I think execs and engineers should be criminally liable when they carelessly set up self-reinforcing software services that somehow execute cyberattacks, like everyone else who executes cyberattacks. If you cannot reliably control the behavior of your software environment then just don't set it up.
23410
Wolfie Christl @wchr.bsky.social · 06/08/2026
"advertising SDKs don’t just allow developers to share location data–they often encourage it" Excellent investigation by Lena Cohen and @legind.bsky.social into mobile app SDK vendors that share data on millions with third parties, feat InMobi, BidMachine, Verve, Huawei: www.eff.org/deeplinks/20...
eff.org
Developers: Beware of Ad Libraries that Betray Your Users’ Location Privacy
An EFF investigation identified several advertising software development kits (SDKs) that publicly acknowledge collecting and sharing users’ location by default when embedded in apps granted location ...
165
Wolfie Christl @wchr.bsky.social · 03/08/2026
Penlink's intrusive ad-based surveillance system Webloc was offered to French businesses (!) via the security firm Amarante, and deployed for the benefit of a subsidiary of the French luxury goods giant LVMH, according to an investigation by @yphilippin.bsky.social and @anttonrouget.bsky.social:
1129
Reposted by Wolfie Christl
Ron Deibert @rondeibert.bsky.social · 03/07/2026
NEW @citizenlab.ca report: Member of 🇪🇺 Euro Parliamentary committee (#PEGA) tasked with investigating spyware abuses himself hacked with Pegasus spyware 👇 citizenlab.ca/research/mem...
citizenlab.ca
Espionage Against the European Parliament: Member of Committee Investigating Spyware Hacked with Pegasus - The Citizen Lab
We found that former Member of the European Parliament Stelios Kouloglou was hacked with Pegasus spyware while serving on the PEGA committee, which investigated Pegasus and other spyware abuses in Eur...
01813
Reposted by Wolfie Christl
netzpolitik.org @netzpolitik.org · 30/06/2026
Das Werkzeug Webloc soll Menschen anhand ihrer Handy-Standorte ausspionieren können. Zu den bislang bekannten Kunden gehören die US-Abschiebemiliz ICE und die abgewählte Orbán-Regierung in Ungarn. Jetzt ist klar: Auch Österreich hat zugegriffen. netzpolitik.org/2026/million...
netzpolitik.org
Regierung in Österreich will Menschen mit illegalen Daten orten können
Das Werkzeug Webloc soll Menschen anhand ihrer Handy-Standorte ausspionieren können. Zu den bislang bekannten Kunden gehören die US-Abschiebemiliz ICE und die abgewählte Orbán-Regierung in Ungarn. Jet...
110457
Reposted by Wolfie Christl
Wolfie Christl @wchr.bsky.social · 26/06/2026
Das österreichische Innenministerium kauft große Mengen hochsensibler Daten von Smartphone-Apps über die Standorte, Bewegungen und andere Verhaltensweisen der halben Bevölkerung für: Überwachungszwecke. Vermutlich schon seit 2024, illegal nach der DSGVO, verfassungsrechtlich fragwürdig. Thread:
derstandard.at
Was macht das Innenministerium mit einer Überwachungssoftware, die auch die US-Behörde ICE einsetzt?
Lizenzen für umstrittene Systeme wurden verlängert. Datenschützer warnen vor Überwachung, das Ministerium hält sich bedeckt. Was können diese Systeme?
35135
Wolfie Christl @wchr.bsky.social · 26/06/2026
Public records confirm that the Austrian Ministry of the Interior bought Webloc, a geolocation mass surveillance system based on data from mobile apps and digital advertising = almost certainly illegal under the GDPR. Austria is now - after Hungary - the second EU state known to use such a system.
14820
Wolfie Christl @wchr.bsky.social · 26/06/2026
Was aus meiner Sicht passieren muss: - Die österreichische Datenschutzbehörde muss eine Untersuchung einleiten - Das BMI muss endlich offenlegen, wie Webloc genutzt wurde und wird, und auf welcher Rechtsgrundlage dies erfolgt - Wenn nicht hinreichend, muss die Nutzung sofort gestoppt werden
060
Wolfie Christl @wchr.bsky.social · 26/06/2026
Getrennt zu betrachten: haben das BMI bzw. der Verfassungsschutz selbst eine Rechtsgrundlage für die Nutzung der Daten? Juristische ExpertInnen, mit denen ich gesprochen hab, bezweifeln, dass die bestehenden Rechtsgrundlagen im ausreichen, um diesen schweren Grundrechtseingriff zu rechtfertigen.
130
Wolfie Christl @wchr.bsky.social · 26/06/2026
Es ist nicht einmal ausjudiziert, ob die Nutzung der Daten für Werbezwecke legal ist. Die Nutzung für einen völlig anderen Zweck geht sich sicher nicht aus. Das BMI setzt ein Überwachungswerkzeug ein, das auf personenbezogenen Daten beruht, die von allen Beteiligten illegal weitergegeben werden.
130
Wolfie Christl @wchr.bsky.social · 26/06/2026
Warum ist Webloc illegal nach der DSGVO? Niemand in der Datenlieferkette - tausende Apps, Zwischenhändler, der Webloc-Anbieter Penlink - hat eine gültige Einwilligung für den Zweck "Weitergabe für Überwachung durch Behörden". Eine andere DSGVO-Rechtsgrundlage als die Einwilligung ist kaum denkbar.
140
Wolfie Christl @wchr.bsky.social · 26/06/2026
Das ist anlasslose Massenüberwachung. In den USA wird Webloc eingesetzt, um gerichtliche Kontrolle zu umgehen. Auch wenn Webloc "nur" zur Überwachung von Einzelnen genutzt wird, sammelt und analysiert es täglich Daten über Millionen Unbeteiligte. Diese Nutzung von Werbedaten ist ein Dammbruch.
140
Wolfie Christl @wchr.bsky.social · 26/06/2026
Webloc bietet Zugriff auf Daten über bis zu 500 Mio Menschen weltweit, bis zu 3 Jahre zurück. Es dient u.A. der Ortung von Personen und erstellt Bewegungsprofile. Das ermöglicht Rückschlüsse über Wohnort, Arbeitsplatz, Familie, Freunde und viele andere sensible Verhaltensweisen und Lebensbereiche.
160