Smart Glasses Hit a Privacy Reckoning, Plus 3 Stories
A camera on a phone has a little social friction built into it. You have to take the phone out, point it at somebody and hold it there. Smart glasses remove most of that friction, and we’re starting to learn what happens when a camera looks almost exactly like a normal pair of glasses.
The smart glasses privacy debate isn’t theoretical anymore.
Smart glasses are running into the privacy problem everyone knew was coming
Paris prosecutors have opened at least one criminal investigation into suspected sexual harassment connected to a social-media trend of using smart glasses to film women on the street without their consent and post the videos online. Prosecutors haven’t identified the brand involved, and that matters: there are several products in this category, so this shouldn’t be turned into “Meta glasses caused this crime” without evidence.
Meta and EssilorLuxottica are still the obvious center of the broader discussion because their glasses dominate the market. Reuters reports roughly 76% global share and 7 million units sold last year. Meta says its glasses turn on a capture LED when recording and are designed not to take photos or video if that light is covered. Its own responsible-use guidance tells wearers to ask permission before recording and to avoid capturing people in sensitive or private places.
Those are reasonable safeguards. They don’t solve the social problem by themselves.
France’s CNIL says it has received fewer than 10 workplace complaints involving smart glasses and is increasingly hearing from businesses that want to know whether they can ban them at work. Australia is considering barring camera-equipped smart glasses from government workplaces. In a CNIL survey of 2,128 French adults, 67% said smart glasses pose a privacy risk.
I think the difference from a phone camera is pretty straightforward. If somebody pulls out a phone and points it at you, you generally know what is happening. A pair of glasses may look like a pair of glasses until a tiny light comes on. And, as one French internet-safety advocate put it, seeing the light doesn’t mean you consented to the recording or to having it distributed afterward.
None of this means smart glasses are useless or that every pair should be banned. Hands-free photography, translation, accessibility features and visual assistance can be genuinely useful. But businesses probably need a policy before the first awkward incident rather than after it. Confidential meetings, medical settings, HR conversations, changing areas and customer spaces where people reasonably expect privacy are the obvious places to start.
The camera got smaller. The privacy question didn’t.
The rules around technology matter too
Platforms, privacy, speech, competition, surveillance, copyright, and regulation increasingly determine what technology companies can build and what the rest of us have to live with. Browse more Raymond Tec News for practical coverage of technology policy and digital rights.
An Acronis backup plugin can turn a small foothold into root access
If you manage Linux hosting servers with cPanel & WHM or Plesk and use Acronis backup integration, this one deserves attention today.
CVE-2026-87886 is a local privilege-escalation vulnerability caused by insecure file permissions. Acronis says it has seen limited, targeted exploitation against its cPanel & WHM plugin. It says it has not seen exploitation against the Plesk extension. CISA has added the vulnerability to its Known Exploited Vulnerabilities catalog, with a September 19 remediation deadline for federal agencies.
“Local privilege escalation” sounds less frightening than remote code execution, but context matters. An attacker needs some level of access to the server first. On a shared hosting system, however, low-privilege accounts are part of the design. A compromised website or hosting account is one possible way somebody could obtain that foothold, although there is no public evidence that this is how the attacks Acronis observed began.
From there, the vulnerability can allow that lower-privileged user to become root.
That’s a particularly ugly boundary to lose on a backup system. Backup software may have visibility into many customer accounts, configuration files and stored data. A problem that begins inside one account can become a server-wide problem if privilege separation fails.
Acronis says the cPanel plugin is fixed in build 1.9.3.1021, released as 1.9.3 HF3. The Plesk extension is fixed in 1.8.11.638. If you’re running an older affected build, update it now.
Then look.
The public reporting doesn’t identify the attackers or explain what they did after gaining higher privileges. That uncertainty is exactly why patching shouldn’t be the end of the response for a system that may have been exposed. Review unexpected privilege changes, unfamiliar processes and accounts, changes to backup configuration and whatever useful logs you have outside the affected host. A patch closes the door. It doesn’t tell you whether somebody already walked through it.
Technical discovery & auditing
The public page doesn’t tell you much about the machinery behind it. Raymond Tec audits inherited and long-running projects to uncover the plugins, integrations, data, dependencies, and old decisions that determine what the next change will really involve.
Russia’s MAX app shows why a super-app has to be trusted more than the apps inside it
A super-app is basically an operating environment inside your operating environment. The main application handles identity, storage, network access and common services, while smaller “mini-apps” run inside it.
That architecture is convenient. It also means the host app is not merely another app sitting next to the others. It’s the landlord.
Researchers studying Russia’s MAX super-app found that the host can capture a mini-app’s user interface, read and write its local storage, inject JavaScript, mediate its network traffic and control authentication context in ways that can enable silent impersonation. Their paper is a technical demonstration of what MAX’s architecture allows.
There is an important qualification here, because the headline “Russian super-app can spy on users” is easy to turn into a stronger claim than the research proves. The researchers demonstrated capability and a very powerful trust relationship. They did not prove that the Russian government has exercised every one of those capabilities against every MAX user.
The political context still matters. MAX is operated by VK and has been pushed deeper into Russian public life, including schools, universities and government services. The Guardian reports that some students have been told they need MAX-based QR codes to enter university buildings and dormitories. Russia has also blocked WhatsApp while promoting MAX as a domestic alternative.
But the larger lesson isn’t that Russian software has invented some uniquely sinister category of architecture. Any super-app that hosts mini-apps sits in a privileged position over them. If you’re building a mini-app for one of these platforms, the host itself belongs in the threat model. Encryption between your mini-app and your own server helps, but it doesn’t erase the fact that the host may control the interface, execution environment and authentication context before that traffic ever leaves the device.
Convenience centralizes trust. MAX is a particularly stark demonstration of what that means.
Technology is rarely just about the technology
Some of the most important technology stories aren’t product launches at all. They’re about health, privacy, education, law, accessibility, work, and what happens when technology reaches ordinary people. Browse more Raymond Tec News for the stories worth understanding without the hype.
Claude is helping build the next Claude — but it isn’t doing it alone
Anthropic has finally put a number on a question the AI industry usually answers with some variation of “a lot.”
The company says Claude now “leads” 26% of the AI research and development work measured inside Anthropic and collaborates with humans on more than 90% of it. Under the Epoch AI automation scale Anthropic is using, “leads” means the system can complete most of a task from a high-level prompt while a human supervises. It does not mean the AI is operating fully autonomously. Anthropic says none of the measured work reached the fully autonomous level.
So, no, this isn’t “AI is building itself now.”
But the less dramatic number may actually be more important. Reuters reports that the share of work Claude was leading was only about 1% in March. By August it was 26%. That’s a very fast change in how the people building frontier AI are doing their own work, and it helps explain why Anthropic CEO Dario Amodei was talking earlier this week about slowing the rate of capability improvement.
Anthropic says roughly 30,000 AI agents were doing research and engineering work on its main internal platform at any given time in August. Every action is screened before execution, and about one in 47,000 decisions was blocked. The company also says about 6% of AI-research compute in a sampled July week went to safety work, rising to 12% for AI-driven AI R&D.
Those measurements deserve some skepticism because Anthropic is measuring Anthropic with systems Anthropic built, and the company acknowledges limitations in the methodology and the need for outside verification. Still, this is much more useful than another vague claim that “AI is moving incredibly fast.” It gives us something measurable to watch: how much of the next model’s research is being led by the current model, how much human oversight remains, and whether the monitoring keeps pace as those percentages rise.
The scary version of recursive self-improvement is a model autonomously designing and building its successor. Anthropic says that is not what is happening today. The less cinematic version — humans using AI to make AI research move substantially faster — very clearly is.
Still in a reading mood? The Raymond Tec News archive covers security, AI, small-business technology, policy, and the places technology collides with ordinary life — without requiring a computer-science degree to get through it.
Sources / Further Reading
- Reuters — France probes misuse of smart glasses in sexual harassment cases
- CNIL — Smart glasses: CNIL calls for vigilance
- Meta — Responsible Innovation in AI Glasses & Quest
- Acronis — Security advisory SEC-10986
- SecurityWeek — Acronis patches exploited cPanel backup plugin flaw
- CISA — Known Exploited Vulnerabilities Catalog
- Priyanka et al. — Don’t Trust the Super-App: A Case Study of Russia’s Max
- The Guardian — How Russia uses mobile super-app Max
- Anthropic — Measurements for understanding the pace of AI development inside frontier labs
- Reuters — Claude now leads a quarter of work building Anthropic’s next AI models
