LIVE · cybersecurity feed
Live wire
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructureOpenAI locks down Astra over potential critical cyber capabilitiesCritical Flaws Discovered in Belgian eID Software Used by 2 Million PeopleSecurity Affairs newsletter Round 589 by Pierluigi Paganini – INTERNATIONAL EDITIONWebmail CSS Attacks Expose a New Risk for AI-Powered Email ToolsMetabase Zero-Day Exploited in the Wild, Exposing Admin Access and Sensitive DataCritical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise DataCVE-2026-8037 · CISA Adds Progress LoadMaster Command Injection Flaw to KEV CatalogSensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It AllAtlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
security

How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)

This week on the Lock and Code podcast, we speak with Chris Parr about his inventive and all-too-funny stress-test of surveillance pricing.

zeroday.news ·

Dynamic pricing strategies, sometimes referred to as "surveillance pricing," have reportedly led to consumers being offered different prices for identical goods or services based on various personal data points. These data points can include a user's operating system, geographic location, or proximity to competing retailers.

In 2012, reports indicated that the travel booking site Orbitz presented Mac users with hotel options that were, on average, 30% more expensive than those shown to PC users, based on an observed spending trend among Mac users. The same year, Staples.com was reported to display higher prices to customers located further from an Office Depot store.

Further investigation in 2015 revealed that The Princeton Review offered its premier test preparation course at prices ranging from $6,600 to $8,400, depending on the customer's zip code. This geographic pricing approach reportedly resulted in Asian customers being nearly twice as likely to be quoted a higher price.

Other alleged instances of surveillance pricing include the Target app showing higher television prices to customers physically present in a Target parking lot, and Home Depot customers in affluent areas reportedly paying less for certain items. Delta Airlines reportedly discontinued a similar pricing practice following public criticism.

The prevalence of these practices has led to numerous online claims suggesting that minor alterations to a user's digital footprint, such as using a VPN to change an IP address or shopping from a public library computer, could result in lower prices. However, verifying these claims has proven challenging.

Video journalist Chris Parr, known as Chris the Producer on YouTube, conducted an experiment to test the impact of surveillance pricing. Rather than simple IP address changes, Parr established a new consumer persona by registering an LLC in Wyoming, complete with its own credit card and phone.

To create a realistic data trail for this new persona, Parr enlisted an actor. His experiment included unusual methods, such as using a drone to purchase a White Castle Crave Case from airspace above a wealthy neighborhood. Parr noted that from the perspective of data collectors, the phone's geolocation would simply indicate its presence in that area, without revealing its aerial position.

ShareXLinkedInWhatsAppFacebook

More News

view all →
security

Everything we launched during Agents Week

Our latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets to Radar.

ransomware

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

vulnerability

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped.

phishing

North Korean spies are running local LLMs to cause AI mischief

Kimsuky's phishing attacks get an AI boost

nation-state

Coruna, DarkSword iOS Exploits Proliferate Globally

Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.

malware

Gym rat asks AI agent to book him a class, it hacks a waitlist API to bump him up the list

What wouldst thou ask of the monkey's paw?