"Ask the EFF" Panel
David Greene, Katharine Trendacosta, Samantha Baldwin, Cooper Quintin (EFF)
BSidesSF 2026 · Day 1 · AMC Theatre 12
Overview
The "Ask the EFF" panel at BSides SF 2026 offered a unique and unfiltered look into the critical work of the Electronic Frontier Foundation (EFF) at the intersection of technology, law, and activism. Featuring a diverse panel of EFF experts—a senior staff technologist, a policy and research technologist, a senior counsel, and a director of policy and advocacy—the session deviated from traditional presentations, opting for an interactive "Ask Us Anything" format driven by audience questions via Slido. This approach allowed the panelists to address the most pressing concerns of the security community directly, covering a broad spectrum of topics from the implications of artificial intelligence to the existential threats to a free and open internet.

Key moments
- 1:00 EFF's mission: defending civil liberties in the digital world.
- 2:10 Cooper Quintin details projects: Privacy Badger, Threat Lab, Ray Hunter.
- 4:10 Samantha Baldwin explains policy work: reviewing legislation for digital rights.
- 5:10 David Greene on EFF's legal team, litigation, and free speech.
- 7:00 Katharine Trendacosta on activism, policy, and Surveillance Self-Defense Guide.
- 7:30 Understanding EFF's three core branches: technology, legal, and activism.
"Ask the EFF" Panel
Speakers: David Greene, Senior Counsel, EFF; Katharine Trendacosta, Director of Policy and Advocacy, EFF; Samantha Baldwin, Policy and Research Staff Technologist, EFF; Cooper Quintin, Senior Staff Technologist, EFF
Conference: BSides SF
YouTube: https://www.youtube.com/watch?v=Af_gn3xROxI
Overview
The "Ask the EFF" panel at BSides SF 2026 offered a unique and unfiltered look into the critical work of the Electronic Frontier Foundation (EFF) at the intersection of technology, law, and activism. Featuring a diverse panel of EFF experts—a senior staff technologist, a policy and research technologist, a senior counsel, and a director of policy and advocacy—the session deviated from traditional presentations, opting for an interactive "Ask Us Anything" format driven by audience questions via Slido. This approach allowed the panelists to address the most pressing concerns of the security community directly, covering a broad spectrum of topics from the implications of artificial intelligence to the existential threats to a free and open internet.
The discussion served as a vital platform for understanding EFF's multifaceted strategy in defending digital civil liberties and human rights. Panelists shared their insights on the evolving landscape of surveillance, the challenges posed by corporate monopolies, and the legislative battles impacting privacy. The candid exchange highlighted not only the technical complexities of these issues but also their profound societal and human rights dimensions, underscoring EFF's commitment to empowering individuals and advocating for a more secure and equitable digital future.
The talk is particularly relevant for anyone concerned with the future of privacy, free speech, and digital rights in an era of rapid technological advancement and increasing government and corporate surveillance. By directly engaging with the audience's questions, the EFF panel provided actionable insights and illuminated the ongoing struggles and victories in the fight for a truly open and democratic internet.
Background
▶ Watch: EFF's mission: defending civil liberties in the digital world. (1:00)
The Electronic Frontier Foundation (EFF) has been a stalwart defender of civil liberties, human rights, and privacy in the digital world for over 36 years, operating as a member-supported non-profit organization. Their work spans three core branches: technology, legal, and activism, each contributing to a comprehensive approach to digital advocacy. This panel brought together representatives from each of these pillars to provide a holistic view of the challenges and EFF's responses.
Cooper Quintin, a Senior Staff Technologist with 12 years at EFF, has been instrumental in developing privacy-enhancing tools like Privacy Badger, a browser add-on designed to block online trackers. His work extends to investigating sophisticated threats, including nation-state malware campaigns by cyber mercenaries like Dark Caracall, which targeted EFF clients and later partnered with ransomware gangs. Quintin also leads EFF's Threat Lab, a crucial initiative providing cybersecurity research and assistance to often-ignored communities such as sex workers, undocumented individuals, and those in abusive relationships. This lab has uncovered malware on low-end children's tablets and actively fought the spouseware industry. Currently, his primary focus is on law enforcement surveillance tools, notably the Ray Hunter project, which uses free software on a $20 mobile hotspot to detect cell site simulators (IMSI catchers or fake cell towers) in real-time. He is also conducting new research on Celbrite and phone cloning, and has investigated license plate readers.
Samantha Baldwin, a Policy and Research Staff Technologist, works on the public interest technology team. Her role involves reviewing federal, state, and municipal legislation to ensure it protects digital rights and privacy, often engaging in reverse engineering and device porting for projects like Ray Hunter. She emphasizes the critical need for technologists to inform lawmakers who often lack technical expertise.
David Greene, EFF’s Senior Counsel since 2013, represents the organization's legal team. His work primarily involves litigating in U.S. courts on issues at the intersection of human rights and technology, with approximately 14 active cases at any given time. The legal team also files amicus curiae briefs (friend of the court briefs) to offer expert insights in significant cases and provides internal legal counsel to EFF's technologists and activists. Greene's individual expertise lies in freedom of speech and First Amendment issues, leading much of EFF's work in this area both domestically and, occasionally, internationally.
Katharine Trendacosta, the Director of Policy and Advocacy, is a senior member of EFF's activism team. She combines subject matter expertise with generalist skills in messaging and grassroots organizing. Trendacosta contributes to resources like the Surveillance Self-Defense Guide and specializes in federal legislation related to copyright, net neutrality, free speech, competition, and the complex implications of AI.
The panel structure, an open Q&A facilitated by Slido, was designed to foster direct engagement with the audience's most pressing concerns, reflecting EFF's commitment to transparency and responsiveness to the digital rights community.
Key Findings
▶ Watch: Samantha Baldwin explains policy work: reviewing legislation for digital rights. (4:10)
The panel discussion illuminated several critical issues and EFF's perspectives on them, offering profound insights into the current state of digital rights and the challenges ahead:
- AI as an Exacerbator, Not a Creator, of Harms: The panelists, particularly Katharine Trendacosta and David Greene, emphasized that Artificial Intelligence primarily amplifies existing concerns about surveillance, data privacy, and societal biases due to its speed and volume. It doesn't typically introduce entirely new legal questions but rather magnifies the scale at which harms can occur. David Greene highlighted that legal frameworks for addressing harms like false information generally don't need to change just because AI was the tool used to create them.
- AI's Role in Policing and "AI Absolution": Cooper Quintin and Katharine Trendacosta raised serious concerns about AI's deployment in law enforcement. They noted that AI crime prediction software often replicates and exacerbates existing biases by predicting crime where it has historically been reported (often in low-income, over-policed neighborhoods), leading to further over-policing. The opacity of AI decision-making processes ("we don't really have any idea how it comes to its conclusions") and its propensity to "hallucinate" facts can lead to wrongful arrests and ruined lives. Trendacosta coined the term "AI absolution" or "civil rights laundering," where institutions claim objectivity because "the AI did it," effectively absolving human responsibility for biased or harmful outcomes.
- Mandated Age Restrictions: An Existential Threat to the Internet: David Greene identified the global momentum behind mandated age restrictions online as "the single biggest existential threat" to a free and open internet. He stressed that such measures fundamentally alter the internet's nature, creating significant political and practical challenges. Samantha Baldwin and Katharine Trendacosta further elaborated on the technical and societal flaws of OS-level age verification, including privacy loss, creation of data honeypots, increased attack surface, and the potential end of online anonymity. They also pointed out that such laws often rest on flawed assumptions about device ownership, access to government IDs, and non-abusive parenting, disproportionately harming vulnerable populations.
- The Perils of Tech Monopolization: Katharine Trendacosta articulated that the existence of only a few dominant tech companies creates severe "choke points," making the internet less "wonderful and weird" and easier to influence. This monopolization stifles competition and incentivizes business models focused on market dominance, leading to fewer choices for users and greater difficulty in advocating for change. She argued that robust privacy and antitrust laws are essential to counteract this trend.
- Combating "Privacy Nihilism" and Misinformation: Cooper Quintin expressed deep concern about the narrative that "ubiquitous surveillance is needed and is happening and...that it works," leading to privacy nihilism. This belief that privacy is impossible or futile can cause self-censorship and fear, undermining democratic participation. He emphasized the need for activists and the public to understand the actual limits of surveillance technologies and to counter misinformation (e.g., "Signal is broken," "ICE can hack anyone anywhere") that fuels this fear.
- Importance of OpSec and Empowerment: The panel collectively stressed the importance of practical operational security (OpSec) for activists. Cooper Quintin highlighted the need to threat model against government agencies like ICE, understand their technological limitations, and avoid spreading rumors that empower adversaries. David Greene and Katharine Trendacosta advised specific actions like enabling disappearing messages on Signal, turning off biometric unlocks (face/fingerprint) during protests, and consulting resources like EFF's Surveillance Self-Defense Guide (ssd.eff.org).
- Victories and Hope for Decentralization: Despite the significant challenges, the panelists shared several "wins." David Greene noted the legal team's success against the U.S. Department of Justice and a victory against the Sacramento Municipal Utility District for smart meter spying, as well as EFF's role in defending the independence of the legal profession. Katharine Trendacosta highlighted successful local activism against Automated License Plate Readers (ALPRs) and the death of many invasive privacy bills. Cooper Quintin expressed optimism about the decentralization of the internet through platforms like Mastodon and Blue Sky, mesh networking projects like Meshtastic and Meshcore, and frameworks for secure peer-to-peer applications like Veil. He also noted the "rebirth of independent journalism" as a positive trend.
Technical Deep Dive
▶ Watch: David Greene on EFF's legal team, litigation, and free speech. (5:10)
The discussion touched upon several technical concepts and tools central to EFF's work and the broader digital rights landscape.
Privacy Badger: Cooper Quintin's early work at EFF involved Privacy Badger, a browser add-on designed to automatically block invisible trackers that follow users across the web. This tool works by learning which domains appear to be tracking users without their consent and then blocking content from those domains, thereby enhancing user privacy by limiting cross-site tracking.
Dark Caracall: Quintin detailed his involvement in uncovering Dark Caracall, a sophisticated cyber mercenary group. This entity was found to be developing and deploying nation-state malware, initially targeting EFF clients, and later identified as a "cyber mercenary" willing to work for various countries. Disturbingly, Dark Caracall has since been observed in league with one of the ransomware gangs, highlighting the evolving and increasingly blurred lines between state-sponsored and financially motivated cyber threats.
Threat Lab and Spouseware: EFF's Threat Lab acts as a cybersecurity research division focusing on vulnerable populations often ignored by mainstream cybersecurity. This lab has conducted critical investigations, including uncovering malware on low-end children's tablets, which poses significant privacy risks to young users. A major focus has been combating the spouseware industry—spyware specifically designed for covert surveillance of a spouse or partner. The Threat Lab's work has been instrumental in exposing these tools and advocating for their cessation.
Ray Hunter Project: Quintin's current primary focus is on law enforcement surveillance tools, exemplified by the Ray Hunter project. This initiative aims to detect cell site simulators, commonly known as IMSI catchers or fake cell towers, which mimic legitimate cell towers to intercept mobile phone communications or track device locations. Ray Hunter is described as a free software solution that runs on a readily available $20 mobile hotspot. It allows individuals to monitor the cellular network in real-time for suspicious activity, providing an accessible tool for community-level surveillance detection. Samantha Baldwin contributes to this project through reverse engineering and device porting, adapting the software to various hardware platforms. Quintin also mentioned upcoming research on Celbrite, a prominent mobile forensics tool, and phone cloning, indicating ongoing efforts to understand and counter advanced surveillance capabilities.
Automated License Plate Readers (ALPRs): The panel discussed ALPRs, which are cameras designed to read license plates and track vehicle movements. While seemingly straightforward, the integration of these systems with large language models or government surveillance AIs significantly exacerbates privacy concerns. Samantha Baldwin pointed out a specific technical detail: even if a vehicle (like a motorcycle) doesn't display a plate, ALPRs can still identify it using characteristics such as "a green Honda," leveraging advanced image recognition capabilities. Local activism, as highlighted by Katharine Trendacosta, has successfully led to local governments discontinuing ALPR contracts, demonstrating the power of public awareness and advocacy against these pervasive surveillance technologies.
AI in Policing and "Hallucinations": The technical limitations of AI, particularly its tendency to "hallucinate" (generate plausible but false information) and the black-box nature of its conclusions, were central to the critique of its use in policing. The "garbage in, garbage out" principle implies that biased training data—reflective of historical policing patterns in certain neighborhoods—will lead to biased outputs, perpetuating and scaling over-policing in specific communities. The panel stressed that the lack of transparency in AI's decision-making makes accountability nearly impossible when it leads to wrongful outcomes.
Age Verification in the Operating System: The technical implications of mandated age verification at the OS level were thoroughly explored. Samantha Baldwin noted that integrating demographic information directly into the operating system creates a honeypot of sensitive data, making it available to a wider array of application developers and significantly increasing the attack surface for potential breaches. The example of Discord's ID store being breached was cited as a real-world precedent for the risks involved. The panelists also raised concerns about the ambiguity of such laws, particularly in California, regarding their applicability to open-source operating systems like Linux, questioning whether they would be forced to implement such verification, thus undermining the open-source ethos. The practical challenges of shared devices (smart TVs, cars, even smart refrigerators) in multi-generational households were also discussed, illustrating how technical implementations often fail to account for real-world user behavior and disproportionately affect vulnerable communities.
Decentralization and Peer-to-Peer Technologies: Cooper Quintin expressed optimism about the decentralization of the internet as a key strategy to move away from corporate control. He highlighted several technologies:
- Mastodon and Blue Sky: Examples of federated social media platforms that offer alternatives to centralized corporate giants, allowing for greater user control and diverse communities.
- Meshtastic and Meshcore: Projects focused on mesh networking, enabling devices to communicate directly with each other without relying on central internet infrastructure, crucial for resilience and privacy.
- Veil: Described as an "amazing project" building a framework for secure peer-to-peer applications that operate without servers or corporate infrastructure. This represents a fundamental shift towards self-sovereign digital interactions.
These technical discussions underscore EFF's deep engagement with both the problems and potential solutions in the digital realm, from actively monitoring and countering surveillance tools to advocating for and supporting the development of a more open, private, and resilient internet.
Demo / Proof of Concept
▶ Watch: Katharine Trendacosta on activism, policy, and Surveillance Self-Defense Guide. (7:00)
This "Ask the EFF" panel was structured as an interactive question-and-answer session rather than a formal technical presentation or demonstration. Therefore, no live demonstration or proof of concept was conducted during this specific talk.
However, it is important to note that the work described by the panelists often involves tangible tools and research. For instance, Cooper Quintin's Ray Hunter project is a practical application of free software running on a $20 mobile hotspot designed to detect cell site simulators. While not demonstrated during this panel, its existence highlights EFF's commitment to developing and deploying accessible, open-source tools that empower individuals to monitor and protect their digital environments. The discussion also implicitly referenced the practical application of reverse engineering and device porting by Samantha Baldwin in her work with Ray Hunter, and the actionable advice provided in EFF's Surveillance Self-Defense Guide, which serves as a living "proof of concept" for effective digital security practices.
Defensive Implications
▶ Watch: Understanding EFF's three core branches: technology, legal, and activism. (7:30)
The insights shared by the EFF panel offer crucial defensive implications for individuals, activists, and the broader tech community:
- Critical Assessment of AI Deployments: Defenders must adopt a highly skeptical and critical stance towards the use of AI, particularly in sensitive domains like law enforcement and government decision-making. Recognize that AI is not objective; it reflects the biases of its training data and can "hallucinate" information. Demand transparency in AI algorithms and accountability for their outputs. Advocate against the deployment of AI systems that lack explainability or have been shown to perpetuate or exacerbate existing societal biases, especially those impacting vulnerable communities.
- Vigilance Against Ubiquitous Surveillance: The panel's warning against privacy nihilism is a call to action. Defenders should actively counter the narrative that ubiquitous surveillance is inevitable or effective. Instead, focus on understanding the actual capabilities and limitations of surveillance technologies (e.g., ICE's tools are "not magic"). Educate communities on these realities to prevent fear from leading to self-censorship and reduced civic engagement. Cooper Quintin's work on Ray Hunter provides a model for community-driven detection of surveillance infrastructure.
- Strong OpSec for Activists and Vulnerable Groups: For activists and individuals in vulnerable positions, robust operational security (OpSec) is paramount. This includes:
- Secure Communications: Utilize end-to-end encrypted messaging apps like Signal, and critically, activate disappearing messages for all chats.
- Biometric Security: Disable biometric unlocks (face ID, fingerprint) on devices when attending protests or in situations where physical device access might be compelled by authorities.
- Threat Modeling: Understand specific risks and tailor security practices accordingly. This involves knowing what technologies adversaries (e.g., ICE, abusive partners) might use and their limitations.
- Educational Resources: Regularly consult and disseminate resources like EFF's Surveillance Self-Defense Guide (ssd.eff.org), which provides up-to-date, actionable advice on digital security.
- Advocacy Against Age Verification: Recognize mandated age verification systems, especially at the operating system level, as a fundamental threat to online anonymity and privacy. Actively oppose legislation that proposes such systems, highlighting their technical flaws (honeypot risks, increased attack surface, impact on open source) and their disproportionate harm to marginalized groups. Support efforts to develop privacy-preserving alternatives for content access control that don't rely on universal identity verification.
- Fighting Tech Monopolies and Promoting Decentralization: Defenders should advocate for stronger antitrust laws and policies that promote competition in the tech sector. Simultaneously, support and contribute to the development of decentralized internet infrastructure and peer-to-peer technologies (e.g., Mastodon, Blue Sky, Meshtastic, Meshcore, Veil). Investing in these alternatives helps reduce reliance on corporate-controlled platforms, fostering a more resilient and censorship-resistant internet.
- Supporting Legal and Legislative Advocacy: Understand that technological defenses alone are insufficient. Support organizations like EFF that engage in impact litigation and legislative advocacy to establish legal precedents and shape policy that protects digital rights. This includes advocating for comprehensive privacy laws and ensuring that technologists' voices are heard in legislative drafting processes.
- Empowering Independent Journalism: Recognize the role of independent journalism in a healthy digital ecosystem. Support journalistic co-ops and alternative media platforms (e.g., 404 Media, The Coyote, Substack) that are less beholden to corporate or government interests and can provide critical reporting on surveillance and digital rights issues.
By adopting these defensive strategies, individuals and communities can collectively push back against the erosion of digital civil liberties and work towards a more secure, private, and open digital future.
Key Takeaways
- AI Exacerbates, Doesn't Invent, Privacy Harms: Artificial intelligence primarily amplifies existing surveillance and data privacy concerns due to its speed and volume, rather than creating fundamentally new legal issues. However, its use in policing poses significant risks by scaling existing biases and leading to potentially unjust outcomes due to AI's opaque decision-making and tendency to "hallucinate" facts.
- Mandated Age Verification Threatens Foundational Internet Principles: The global push for mandatory age verification, especially at the operating system level, is considered a major existential threat to a free and open internet. It jeopardizes online anonymity, creates massive data honeypots ripe for breaches, increases attack surfaces, and disproportionately harms vulnerable populations by making flawed assumptions about device ownership and access to identification.
- Tech Monopolies Undermine Digital Freedom: The concentration of power among a few large tech companies creates critical choke points, making it easier for governments to exert control and harder for individuals to protect their rights. This corporate centralization stifles innovation and competition, necessitating stronger antitrust measures and a shift towards more diverse, decentralized digital ecosystems.
- Effective OpSec Requires Discerning Fact from Fear: Protecting digital rights, especially for activists, hinges on accurate threat modeling and dispelling misinformation. It's crucial to understand the actual limitations of government surveillance technologies (they are "not magic") and to adopt practical security measures like using Signal with disappearing messages and disabling biometric unlocks in sensitive situations, rather than succumbing to "privacy nihilism."
- Decentralization Offers Hope for a Better Internet: Despite pervasive challenges, there is significant optimism in the movement towards internet decentralization. Projects like Mastodon, Blue Sky, Meshtastic, Meshcore, and Veil are building alternative peer-to-peer infrastructure and platforms that are not controlled by large corporations, fostering a more resilient, private, and user-controlled digital future.
- A Multi-Faceted Defense is Essential: The EFF's integrated approach, combining technological development (e.g., Privacy Badger, Ray Hunter), legal advocacy (litigation, amicus briefs), and grassroots activism (Surveillance Self-Defense, legislative lobbying), is crucial for effectively defending digital civil liberties. This comprehensive strategy is vital for countering evolving threats and preserving fundamental rights in the digital age.
About the Speaker(s)
Cooper Quintin is a Senior Staff Technologist at the Electronic Frontier Foundation (EFF), where he has worked for 12 years. He began his tenure developing tools like Privacy Badger and has since expanded his expertise to include investigating nation-state malware (such as Dark Caracall), leading the Threat Lab to provide cybersecurity support to underserved communities, and researching law enforcement surveillance tools. His current work includes the Ray Hunter project, which detects cell site simulators, and upcoming research on Celbrite and phone cloning.
Samantha Baldwin serves as a Policy and Research Staff Technologist on EFF's public interest technology team. Her primary responsibilities involve reviewing federal, state, and municipal legislation to ensure it protects digital privacy and rights. She also contributes technical expertise, including reverse engineering and device porting, to projects like Ray Hunter.
David Greene is EFF's Senior Counsel, having joined the organization in the summer of 2013. He leads EFF's legal team, focusing on impact litigation in U.S. courts concerning human rights and technology, filing amicus curiae briefs, and providing legal counsel to his EFF colleagues. Greene's individual expertise lies in freedom of speech and First Amendment issues.
Katharine Trendacosta holds the title of Director of Policy and Advocacy at the Electronic Frontier Foundation. As a senior member of the activism team, she is a subject matter expert in federal legislation, particularly in areas such as copyright, net neutrality, free speech, competition, and the implications of artificial intelligence. She also contributes to EFF's Surveillance Self-Defense guide and is involved in grassroots organizing and messaging.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A competent panel-lane session that delivers genuine utility — real EFF practitioners, honest OpSec advice, and some signal on Ray Hunter and age-verification threats that practitioners can act on. Nothing here will redefine the conversation, but it's not pretending to; it's a well-executed community Q&A that respects the audience's time.
Heather Calloway (CISO) — SOLID
A credible, wide-ranging EFF roundtable that covers real threats — age verification, AI in policing, surveillance tooling, privacy nihilism — with genuine expertise behind each. But the Q&A format trades depth for breadth, and none of the threads get pulled far enough to produce a decision or a changed posture for the security leaders, policymakers, or operators who most need to act on this material.