Chipp.in Tech News and Reviews

Windows, Security & Privacy, Open Source and more

Menu
  • Home
  • Windows
  • Security & Privacy
  • Gaming
  • Guides
  • Windows 11 Book
  • Contact
  • RSS Feed
Menu

Category: Security & Privacy

Mozilla is giving away unlimited VPN bandwidth in Firefox

Posted on June 10, 2026June 10, 2026 by Martin Brinkmann

Firefox VPN is a built-in browser proxy to browse anonymously in the open source browser. It is a free service that protects your device’s IP address by routing traffic through secure servers.

While not as powerful as standalone VPN services, which protect all activity on a device, it is a handy privacy feature nevertheless. Users should not confuse it with Mozilla VPN, which is a device-wide VPN service that is not free.

Mozilla increased the available bandwidth for free users to 50 gigabytes recently. That is a generous amount already. This week, the organization announced another, temporary, increase of the VPN bandwidth.

Bandwidth is unlimited until September 1, 2026, according to the blog post. So, if you really need a lot of bandwidth, for instance for massive downloads or media streams, then this should get you through the coming months without ever worrying about hitting bandwidth limits.

In addition, users may connect to more than 25 different exit regions when they use the browser VPN.

The full set of countries available during this summer period include: Australia, Austria, Belgium, Bulgaria, Canada, Chile, Colombia, Denmark, Finland, France, Germany, Ireland, Italy, Malaysia, Mexico, Netherlands, New Zealand, Portugal, Singapore, Spain, Sweden, Thailand, Norway, South Africa, United Kingdom and United States.

Firefox’s built-in VPN supports turning off the secure connection for specific sites. That’s useful in some cases, for example, when sites do not work properly while the VPN is active.

All in all, if you do not use a VPN service already, this one may be an option to upgrade your privacy on the Internet.

You can now block automatic extension updates in Brave Browser

Posted on June 7, 2026June 7, 2026 by Martin Brinkmann

Most modern browsers install extension updates automatically. The developers claim that this improves security, and this is true to a degree. However, automatic extension updates do open a whole new can of worms, as problematic updates do get installed automatically as well.

Consider this: when an extension gets bought, the new owner may push updates and these will get installed on user systems, often without users knowing about the change in owner. The same is true for extensions that get hijacked or when a developer introduces features that are unwanted.

Firefox is the gold standard when it comes to controlling extensions. Users of the browser can block automatic updates for extensions entirely or for specific add-ons installed in the browser.

Chromium-based browsers do not have these native capabilities. The workaround until now was to install an extension through sideloading. These bypassed the entire updating mechanics, but it also meant that the browser might show a reminder that developer extensions are running.

The most recent update of Brave Browser introduces native support to it. This sets it apart from other Chromium-based browsers, which do not offer this feature.

Here is what it does: Once enabled, Brave browser stops updating extensions in the background. You can run the update process at any time from the extensions page of the browser, which makes it comfortable compared to the sideloaded extensions bypass. The main downside is that it is an all or nothing approach, but there is a workaround.

To enable it, it is necessary to configure an experimental flag in the browser.

  1. Load chrome://flags/#brave-user-extension-auto-update in the address bar.
  2. Set the flag to Disabled.
  3. Restart the web browser.

To update all extensions, do the following:

  1. Open the Extensions page in Brave: brave://extensions/
  2. Check the Developer Mode toggle at the top right corner.
  3. Click on the update button that appears.

This runs the update check for all installed extensions and will download and install any update found during the process.

There is no direct option to run a check for individual extensions, it is an all-or-nothing approach. There is a workaround though, but it requires manual steps and it has disadavantages.

If you want to update a highly trusted tool (like a password manager) but want to keep a smaller utility frozen on its current version, you can manually force a single update by refreshing it.

  1. Go to brave://extensions.
  2. Click Remove on the specific extension you want to update.
  3. Head to the Chrome Web Store, search for it, and click Add to Brave.

This installs the latest version in the browser. Note that uninstalling an extension will remove its data. Any custom configurations or personal data is removed in the process. Works best for extensions that do not have any of that.

Brave has not revealed much about the feature at this stage. Since it is experimental, there is the possibility that it will get more comfortable in the future. For now, Firefox remains the gold standard for users who want to stay in full control over extension updates.

Using 7-Zip? Time to update, as your version may be vulnerable

Posted on May 27, 2026May 27, 2026 by Martin Brinkmann

7-Zip is a popular open source archiver that is a popular option on Windows. While Windows comes with its own basic archive creation and extracting options, it is significantly slower compared to third-party apps such as 7-Zip.

A vulnerability in earlier versions of 7-Zip was discovered in April 2026 that could allow attackers to cause the application to crash or run arbitrary code.

The affected version is 7-Zip 26.00 and earlier versions appear also affected by the vulnerability. The latest version is 7-Zip 26.01 and this version is safe to use.

If you run the archiving software on your devices, you may want to check the installed version and update if it is 26.00 or earlier.

You can check the installed version under Settings > Apps > Installed Apps. Type 7-Zip into the search box and wait for the app to appear. The version is shown in its title.

Updating is a flawless process. Just download the latest version from the official developer website and run it after the download finished. The installed version will be updated and any attacks targeting the vulnerability won’t have an affect on the app or the system anymore.

You can also check the version when you launch 7-Zip on the system. Select Help > About 7-zip in that case to display the installed version.

Google introduces Approximate Location sharing in Chrome: here is what it does

Posted on May 6, 2026May 6, 2026 by Martin Brinkmann

Mobile devices and web browsers support the sharing of the current location. This gives apps, websites and services access to a user’s location in the world. Ideally, to provide custom information, such as zooming to that location on a map, showing businesses nearby, providing directions, or loading specific information on a website.

While useful in that regard, location does reveal information about the user. The feature is usually locked behind a permission, but some apps may not start at all without it or block access to features.

Google announced on its official The Keyword blog that it is introducing approximate location sharing in Chrome. The feature lands in Chrome for Android first before it will also be introduced in the desktop versions of the browser.

Here is what it does: Google Chrome’s new Approximate Location Sharing feature enhances privacy by giving users a third option when websites request their whereabouts: sharing a general regional area rather than the exact coordinates. While users can still grant precise location access for tasks that genuinely need it—such as getting turn-by-turn navigation, placing a delivery order, or finding a nearby ATM—everyday browsing activities like checking local weather or reading regional news can now function perfectly well with just a neighborhood or city-level location.

In other words, websites and apps get information about a region a user is in and not the precise location. This new permission is intended for services that do not require accurate information and for users who do not want to share their exact location.

When a location prompt pops up on the mobile, users can now pick between “precise” and “approximate” and the usual options to “never allow”, “allow this time”, or “allow while visiting the site” options. Google says that the feature will land on desktop in Chrome in the coming months as well. For now, it is only available in Chrome for Android.

How useful is it for privacy? It can be used to share less-exact information about ones location. That is useful, especially for services that do not require it to function. If you want to get local news or weather, it does not really matter if the service that is providing the information knows the exact location or not. In that regard, it is a useful addition for users who share location but prefer it to be less exact whenever possible.

Firefox

How to enable Firefox’s secret ad-blocker

Posted on April 24, 2026April 26, 2026 by Martin Brinkmann

For years, I asked myself why Mozilla did not add a good content blocker to Firefox. It would be a great fit. An organization that values privacy, an open source browser that blocks most tracking out of the box.

However, for Mozilla, integrating a content blocker would also mean torpedoing its main revenue stream coming from Google.

Mozilla never made the step and others, including Brave, led by Mozilla’s ex-CEO, stepped in to fill that gap.

This changed recently

Mozilla did integrate Brave’s Rust-based adblock engine into its Firefox browser. More precisely, it is part of Firefox 149 and Mozilla describes it as a prototype rich content blocking feature.

It is not yet available as an option in the user-facing interface, let alone as something similar to the Shield feature of Brave. Still, users who run Firefox 149 can enable the content blocker and make use of it right away for testing.

Here is how that works:

  1. Load about:config in the Firefox address bar.
  2. Search for privacy.trackingprotection.content.protection.enabled
  3. Set the value to True with a click on the toggle on its right.
  4. Search for privacy.trackingprotection.content.protection.test_list_urls.
  5. Paste https://easylist.to/easylist/easylist.txt|https://easylist.to/easylist/easyprivacy.txt as the value.
  6. Restart Firefox

This enables two EasyLists, but you can add any other list that uses the same format. Separate lists with the character |.

Clearly, this is done for testing purposes. Mozilla would very likely add controls to the preferences or another user facing interface to make this easier to configure and use.

For now, it is a work in progress implementation, but one that shows that Mozilla could finally integrate what many users of its browser have wanted (or did not know they wanted) for a long time.

Mozilla fixed 271 vulnerabilities in Firefox 150 thanks to AI

Posted on April 23, 2026April 23, 2026 by Martin Brinkmann

When Mozilla released Firefox 150 earlier this week, it revealed that it had fixed what looked like the usual number of security issues in the browser. However, what Mozilla did not tell at the time was that it had fixed a significant number of vulnerabilities.

A post on the official Mozilla blog reveals that engineers fixed 271 vulnerabilities in total, a significant number. However, this time, Mozilla’s engineers did not hunt for vulnerabilities using traditional means. Instead, the company used Anthropic’s Mythos AI to do so.

Mozilla writes:

As part of our continued collaboration with Anthropic, we had the opportunity to apply an early version of Claude Mythos Preview to Firefox. This week’s release of Firefox 150 includes fixes for 271 vulnerabilities identified during this initial evaluation.

So, what is Claude Mythos?

Claude Mythos is a powerful, unreleased frontier AI model developed by Anthropic. Announced in April 2026, it is famous—and highly controversial—for its unprecedented capabilities in cybersecurity, specifically its ability to autonomously hunt down and exploit software vulnerabilities.

This is not the first time that Mozilla used an AI from Anthropic for that purpose. Back in February 2026, it used Claude and discovered 22 “security-sensitive bugs”.

Mozilla says that this is great news for software developers and what it calls defenders, legitimate developers who need to secure their applications against a constant barrage of threats.

While the use of AI continues to be controversial, it is usually ethical and privacy concerns that are raised. Good uses for AI, like using it to discover vulnerabilities before the bad guys find them, is probably something that most might not find nearly as problematic.

I would not go as far and say that the days of the 0-day threats are numbered, as Mozilla does, but it looks as if it can help. Still, threat actors could also leverage AI tools for finding vulnerabilities.

Brave is getting Container support and the feature has made a big jump recently

Posted on April 14, 2026April 14, 2026 by Martin Brinkmann

Firefox fans have long heralded the browser’s Multi-Account Containers feature as an exclusive that users of Chromium-based browsers did not have. Soon, Brave Brower users may also make use of a Containers feature, ending Firefox’s exclusivity.

Brave has begun rolling out native Container support as an experimental flag in its desktop browser as of April 2026. It allows users of the browser to isolate web sessions better and even get options to open multiple accounts of the same site in a single browser window without using clunky workarounds or third-party extensions.

The Core Concept: Session Isolation

At its core, the Containers feature creates isolated islands within a single browser window. Each container acts as a separate, sandboxed environment. Data, including cookies, local storage, or cached files, can’t be seen or accessed by tabs in another container or by the default container-less environment.

Since data is sandboxed, it is possible to sign-in to the same site in different containers in the same browser window using a single profile, or to open a site with an account and without one at the same time. Furthermore, since data is separate, tracking becomes less effective as the trackers can only see what is going on in a single container and not the entire browser.

Containers works with tab groups and all core features of the browser, including browser extensions.

The feature is available in Brave Nightly only at the time. You need to load brave://flags, search for Enable Containers, and toggle the feature to Enabled to start using it. A restart of the browser is required as usual before it becomes available.

Since this feature is in Nightly, it may have bugs and may not be as polished as the stable version that Brave Software plans to ship in a later version of the browser.

WhatsApp is rolling out long-overdue username privacy feature

Posted on April 9, 2026April 9, 2026 by Martin Brinkmann

If you use the popular messaging service WhatsApp, you know that you can only add contacts to the service with a phone number. Don’t have the number registered to a WhatsApp account? Then you can’t add the contact to the app.

Clearly, having to share your phone number is not always a good idea. While you may not have any issues sharing it with close friends or family, giving it to others is another matter.

It is a privacy and security issue. Other messengers support usernames, which do not reveal critical information to a third-party.

WhatsApp started to work on usernames about three years ago, but the Meta-owned app is just about to start rolling the feature out to a first batch of users, reports WABetaInfo.

You can add a username in the settings. Once you do, you may share the username with others to get them to add you to the messenger. Good news is that you can further protect the username with a code, which others need to provide when they try to add you.

However, there are quite a few limitations regarding usernames. Here are noteworthy ones:

  • The username can be between 3 and 23 characters in length.
  • It needs to start with a letter, and can only contain letters, numbers, underscore, and a period.
  • It can’t be a domain name or start with www.
  • It can’t be taken, if someone on Instagram or Facebook picked it already. The user who picked it can get it on WhatsApp.

Support for usernames is a welcome addition. While some Internet users prefer to use other messaging clients, those who offer more privacy, WhatsApp’s users will certainly benefit from the feature.

No official ETA or confirmation by Meta at this point though. Might take months or even longer before the feature lands for most users.

Report: Windows has a new 0-day vulnerability called BlueHammer

Posted on April 7, 2026April 7, 2026 by Martin Brinkmann

The next Windows Patch Day is just a week away and it is unclear whether it will include a fix for a recently disclosed 0-day vulnerability.

The new security vulnerability has been disclosed on GitHub, including proof of concept code to exploit the issue. However, there is no explanation how the issue works.

Well-known security researcher Will Dormann commented on the issue and confirmed that it is working. He admitted that it “may not be 100%” reliable though. It seems that frustration with MSRC, the Microsoft Security Research Center, and how it operates, was the reason for the public disclosure of the vulnerability. Whether that is true or not can’t be verified though.

So, what do we know about the vulnerability so far?

  • What it is: “BlueHammer” is an unpatched zero-day Local Privilege Escalation (LPE) vulnerability affecting Microsoft Windows.
  • Impact: It allows a local attacker with limited, low-level user access to escalate their permissions to SYSTEM or elevated administrator rights. This effectively grants the attacker full control over the compromised machine.
  • Current Status: Microsoft has not yet released an official patch or mitigation, making it a true zero-day.

Security experts (such as Will Dormann) describe it as a flaw that combines a TOCTOU (Time-of-Check to Time-of-Use) vulnerability with path confusion. At a high level, it appears to weaponize Windows Defender-related interfaces (the leaked source code contains files like windefend.idl and windefend_c.c). By bypassing the system’s original validation, a local attacker can gain access to the Security Account Manager (SAM) database, which stores local account password hashes, ultimately allowing them to spawn SYSTEM-level shells.

Good news is that the flaw is a local privilege escalation, which means that attackers can’t exploit it to hack into Windows PCs remotely. However, if they were to gain access to a Windows system, they could use it to expand access or even take over a system completely.

Would you trust AI to handle your email inbox?

Posted on April 2, 2026April 2, 2026 by Martin Brinkmann

It was inevitable. Google is rolling out new AI functionality on its Gmail service to personal Google accounts. Called AI Inbox, it is designed to “help you manage a busy inbox”, says Google.

What that means? AI is scanning emails to identify the ones that require immediate attention. The feature has its own entry point on Gmail. When you activate AI Inbox, you get two different sections:

  • Suggested To-dos: Here, the AI lists incoming emails that need your immediate attention or action. High-priority tasks are identified and the AI explains to you in bold, what you need to do.
  • Catch-up Topics: This offers summaries of “important updates across projects and topics”, especially if they are scattered in different email threads or unrelated emails.

Google is limiting the feature currently to English-language users from the United States who are subscribed to Google AI Ultra, which costs 275 Euros per month currently (three month 50 percent introductory offer may be available).

You also need to enable smart features in Gmail to make use of it. Smart Features refers to a bundle of features, including translations, Smart Compose, or personalized search.

The Pros and Cons of letting AI handle your inbox

While there are certain pros to letting AI handle your email inbox, such as saving time, prioritization, or tone and grammar help, there are significant downsides.

Besides privacy and security concerns, there is the risk of missing important emails or of costly mistakes that the AI may make when it starts to hallucinate.

Privacy aside, the best way for users who want to make use of AI to tame their inbox is to use it as a helper, not the ultimate tool on autopilot. This is true for most AI solutions and services nowadays: you always have to verify that the AI did not miss something or introduced something that should not be there or that does not exist in the first place.

Would I use AI Inbox? I would not and the reason could not be simpler: I have no desire to give AI access to my emails because of privacy. Add a medium-sized inbox to that, and I do not have a need for any AI functionality at the time of writing.

I can see AI Inbox as a useful addition in certain cases, for instance, when so many emails arrive in an inbox that humans can’t keep anymore or when someone needs AI because of a packed day and little time to manage emails.

What is your take on this? Would you use AI features on Gmail or your email service? Or do you plant to stay away from them?

  • Previous
  • 1
  • 2
  • 3
  • 4
  • 5
  • …
  • 14
  • Next

Support This Site

If you like what I do please support me!

Any tip is appreciated. Thanks!
  • August 29, 2026 by Martin Brinkmann Another Windows Issue: Microsoft Defender Antivirus is turned off notification, but it is actually enabled
  • August 28, 2026 by Martin Brinkmann Brave Accounts and Email Aliases launch
  • August 25, 2026 by Martin Brinkmann Microsoft confirms: Latest .NET updates may cause printing issues
  • August 24, 2026 by Martin Brinkmann The Chrome Web Store has a fake VPN extensions problem
  • August 23, 2026 by Martin Brinkmann Microsoft is worsening classic Media Player to get users to upgrade

About

We talk, write and dream about Technology 24/7 here at Chipp.in. The site, created by Martin Brinkmann in 2023, focuses on well-researched tech news, reviews, guides, help and more.

Legal Notice

Our commitment

Many websites write about tech, but chipp.in is special in several ways. All of our guides are unique, and we will never just rehash news that you find elsewhere.

Read the About page for additional information on the site and its founder and author.

Support Us

We don't run advertisement on this site that tracks users. If you see ads, they are static links. Ads, including affiliate links, never affect our writing on this site.

Here is a link to our privacy policy

©2026 Chipp.in Tech News and Reviews