PLAY PODCASTS
Firewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast

500 episodes — Page 3 of 10

Episode 400 Special

The first episode of Firewalls Don’t Stop Dragons Podcast aired on March 8, 2017 – almost 8 years ago now. Over that time, I’ve interviewed over 135 unique and amazing people, covered countless cybersecurity and privacy stories, and offered 100’s of tips for protecting your devices and data. To celebrate this momentous occasion, world-renowned cryptography guru Bruce Schneier has returned to for our traditional Podcentennial interview! We discuss several timely topics including the Crowdstrike incident, the pager bombing and supply attacks more generally, US election security, the open market for cyber vulnerabilities, US intelligence agencies’ focus on offense versus defense, how AI might actually benefit democracy and much more! Interview Notes Bruce Schneier’s blog:https://www.schneier.com/ Inrupt’s Solid concept: https://www.inrupt.com/solid Data and Goliath (book): https://www.schneier.com/books/data-and-goliath/ Bruce’s NY Time article on pager bombs: https://www.schneier.com/essays/archives/2024/09/israels-pager-attacks-have-changed-the-world.html Joseph Cox “Anom” interview: https://podcast.firewallsdontstopdragons.com/2024/06/10/anom-the-fbis-phone-company/ WaPo detailed analysis of pager bomb attack: https://www.washingtonpost.com/world/2024/10/05/israel-mossad-hezbollah-pagers-nasrallah/ Restoring Trust in Elections: https://podcast.firewallsdontstopdragons.com/2023/12/11/restoring-trust-in-elections/ Hacking election systems w/ Harri Hursti: https://podcast.firewallsdontstopdragons.com/2021/11/08/restoring-trust-in-our-elections/ Hacker Halted conference info: https://hackerhalted.com/agenda/#day-two-october-31st Further Info Help me reach more people! https://fdsd.me/awareness2 Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:03:53: Interview setup 0:06:21: What should we have learned from the Crowdstrike incident? 0:11:21: Why is it more profitable for products to be brittle? 0:13:59: Do regulations stifle innovation? 0:15:27: Should intelligence agencies focus more on cyber offense or defense? 0:22:29: Should it be legal to buy and sell zero-days on the open market? 0:26:44: How secure are our election systems today? How do we get people to trust the outcomes? 0:35:41: What’s your take on the arrest of Telegram’s CEO? 0:39:18: How do we convince lawmakers not to subvert encrypted communications? 0:43:48: How did the exploding pager attack change our views of supply chain security? 0:49:26: In what ways might AI actually benefit our democracy? 0:58:03: Should there be any guardrails on AI systems? 1:01:17: What’s next for you? What’s the latest on the Solid project? 1:03:49: Interview wrap-up 1:07:51: More info for new listeners 1:13:38: Meet me at Hacker Halted Conference! 1:14:14: Looking ahead

Oct 28, 20241h 14m

Understanding AI Chatbots

Artificial Intelligence (AI) is the buzzword of the day. There are many types of AI, but one particular flavor is getting a lot of press these days: chatbots. Formally referred to as Large Language Models (LLMs), chatbots like ChatGPT, Claude and Gemini are everywhere – either directly or integrated with other popular apps. This technology is real and it’s here to stay, so it’s important that we understand what it is, how it works, and what the limitations are. Today I’ll explore some aspects of LLMs that you probably weren’t aware of. In other news: critical, exploited Firefox bug is fixed (update now!); National Public Data files for bankruptcy after massive breach; hackers target Qualcomm chip zero-day used in many Android phones; China attackers exploit legally-mandated wiretapping backdoor in major telecom systems; new FIDO standard proposed for allowing passkeys to be exported and backed up; a PSA on why you shouldn’t share personal information with AI chatbots. Article Links [The Hacker News] Mozilla Warns of Active Exploitation in Firefox, Urges Users to Update Immediately https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html [therecord.media] National Public Data files for bankruptcy, citing fallout from cyberattack https://therecord.media/national-public-data-bankruptcy-cyberattack [techcrunch.com] Hackers were targeting Android users with Qualcomm zero-day https://techcrunch.com/2024/10/09/hackers-were-targeting-android-users-with-qualcomm-zero-day/ [pluralistic.net] China hacked Verizon, AT&T and Lumen using the FBI’s backdoor https://pluralistic.net/2024/10/07/foreseeable-outcomes/ [appleinsider.com] Future Passkeys will be able to be shared across platforms & password vaults https://appleinsider.com/articles/24/10/15/future-passkeys-will-be-able-to-be-shared-across-platforms-password-vaults [9to5mac.com] PSA: Here’s another reason not to include personal details in AI chats https://9to5mac.com/2024/10/17/psa-heres-another-reason-not-to-include-personal-details-in-ai-chats/ Tip of the Week: Understanding AI Chatbots Further Info Help me reach more people! https://fdsd.me/awareness2 Privacy Not Included chatbot privacy guide: https://foundation.mozilla.org/en/privacynotincluded/articles/how-to-protect-your-privacy-from-chatgpt-and-other-ai-chatbots/ Gandalf AI game: https://gandalf.lakera.ai/baseline  Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:01: Google finally killing uBlock Origin 0:04:07: News preview 0:05:54: Mozilla Warns of Active Exploitation in Firefox 0:08:55: National Public Data files for bankruptcy 0:14:42: Hackers were targeting Android users with Qualcomm zero-day 0:19:14: China hacked Verizon, AT&T and Lumen using the FBI’s backdoor 0:26:10: Future Passkeys will be able to be shared across platforms & password vaults 0:31:08: Here’s another reason not to include personal details in AI chats 0:37:40: Tip of the Week: Understanding Chatbots 0:55:55: Wrapping up 0:56:35: Celebrating 400 episodes!

Oct 21, 202458 min

L0pht Heavy Industries

L0pht Heavy Industries (pronounced “loft”) was one of the most influential hacker groups in history. Unlike many others, L0pht carefully cultivated a relationship with mass media, sold profitable products, started businesses, and even testified before the US Senate. Cris Thomas, aka Space Rogue, was one of the earliest members of the L0pht and he recently published a book chronicling the groups long and storied history called Space Rogue: How the Hackers Known As L0pht Changed the World. Today I sit down with Cris to discuss that history and the impacts that the L0pht and other hacker groups have had on all of us. Interview Notes Space Rogue’s website: https://www.spacerogue.net/ L0pht homepage: https://l0pht.com/  L0phtCrack: https://www.l0phtcrack.com/  Textfiles.com: http://textfiles.com/  L0phy testimony: https://www.youtube.com/watch?v=VVJldn_MmMY  Charlie Rose “Hackers” interview: https://www.youtube.com/watch?v=zbTkOuPv2fo  PicoCTF: https://www.picoctf.org/  Hack the Box: https://help.hackthebox.com/en/articles/5200851-introduction-to-ctfs  Further Info Help me reach more people! https://fdsd.me/awareness2 Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:23: Episode 400 coming soon! 0:01:16: Interview setup 0:03:49: Tell us about your book 0:04:52: What is your origin story? How’d you get into hacking? 0:08:15: How often did you meet your fellow hackers in person? 0:10:49: How did the L0pht get started? 0:15:39: What was the reaction when you “come out” as a hacker to friends and family? 0:20:02: How much did different hacker groups interact back in the day? 0:23:19: L0pht cultivated a relationship with the media – how did that affect the dynamic? 0:28:19: What’s the history behind the infamous L0phtCrack password tool? 0:35:36: What was it like testifying in front of the US Senate? 0:38:32: How did you get away with testifying under your hacker names? 0:45:29: How did Hacker News Network come to be? 0:52:06: How did we avoid a hacker cyber war against China in the late 90s? 0:57:15: Which of L0pht’s many achievements are you most proud of? 0:59:40: What advice would you give to someone wanting to get into cybersecurity? 1:05:39: What’s next for you? 1:06:23: Patron bonus content preview 1:06:52: Post-interview notes 1:08:36: Looking ahead

Oct 14, 20241h 9m

Indicators of Account Compromise

Sometimes it’s obvious when your accounts are hacked. Maybe your money is gone. Maybe you can no longer log in using the password you know is correct. Maybe everyone you know has gotten a scam email from you that you didn’t send. But sometimes bad guys aren’t so obvious. They may lurk around in your accounts to gather information for identity theft or in hopes of gaining access to other more lucrative accounts. I’ll tell you how to find out. In other news: CA governor vetoes opt-out signal bill but signs car privacy bill; 23andMe is in trouble and your data may be, too; PayPal opted you into data sharing without asking; Kaspersky deletes itself and installs UltraAV without asking; 100 million Americans had background data leaked; researchers add facial recognition tech to Meta’s smart glasses; NIST updates password rules to with common sense changes; US & Microsoft seize 100+ web domains used by Russian hackers. Article Links [Ars Technica] Calif. Governor vetoes bill requiring opt-out signals for sale of user data https://arstechnica.com/tech-policy/2024/09/calif-gov-vetoes-attempt-to-require-new-privacy-option-in-browsers-and-oses/ [Teach Privacy] Bankruptcy Sale of DNA Data: From Toysmart to 23andMe https://teachprivacy.com/bankruptcy-sale-of-dna-data-from-toysmart-to-23andme/ [404 Media] Paypal Opted You Into Sharing Data Without Your Knowledge https://www.404media.co/paypal-personalized-shopping-opt-out/ [Bleeping Computer] Kaspersky deletes itself, installs UltraAV antivirus without warning https://www.bleepingcomputer.com/news/security/kaspersky-deletes-itself-installs-ultraav-antivirus-without-warning/ [Tom’s Guide] 100 million Americans just had their background check data exposed https://www.tomsguide.com/computing/online-security/100-million-americans-just-had-their-background-check-data-exposed-online-how-to-stay-safe [404 Media] Someone Put Facial Recognition Tech onto Meta’s Smart Glasses to Instantly Dox Strangers https://www.404media.co/someone-put-facial-recognition-tech-onto-metas-smart-glasses-to-instantly-dox-strangers/ [Ars Technica] NIST proposes barring some of the most nonsensical password rules https://arstechnica.com/security/2024/09/nist-proposes-barring-some-of-the-most-nonsensical-password-rules/ [The Record] California passes car data privacy law to protect domestic abuse survivors https://therecord.media/california-car-data-privacy-law-domestic-abuse-tracking [Semafor] US, Microsoft seize more than 100 websites used by Russian hackers https://www.semafor.com/article/10/03/2024/us-microsoft-seize-more-than-100-websites-used-by-russian-hackers Tip of the Week: Indicators of Account Compromise: https://firewallsdontstopdragons.com/indicators-of-account-compromise/ Further Info Help me reach more people! https://fdsd.me/awareness2 Treasure Chest promotion: https://firewallsdontstopdragons.com/treasure-coin-promo/ How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ My article on removing your data from the web: https://firewallsdontstopdragons.com/osint-remediation/ CISA Cybersecurity Awareness Month resources: https://www.cisa.gov/resources-tools/resources/secure-our-world-resources-cybersecurity-awareness-month-2024-toolkit Stay Safe Online CAM site: https://staysafeonline.org/programs/cybersecurity-awareness-month/ Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:12: Cybersecurity Awareness Month! 0:01:51: Update Apple software 0:03:21: News rundown 0:05:41: CA Governor vetoes bill requiring opt-out signals for sale of user data 0:11:51: Potential Bankruptcy Sale of DNA Data from 23andMe 0:17:22: Paypal Opted You Into Sharing Data Without Your Knowledge 0:22:01: Kaspersky deletes itself, installs UltraAV antivirus without warning 0:28:14: 100 million Americans just had their background check data exposed 0:32:13: Someone Put Facial Recognition Tech onto Meta’s Smart Glasses to Instantly Dox Strangers 0:36:33: NIST proposes barring some of the most nonsensical password rules 0:42:21: California passes car data privacy law to protect domestic abuse survivors 0:45:36: US, Microsoft seize more than 100 websites used by Russian hackers 0:47:49: Tip of the Week 1:04:13: promoting the 400th episode 1:05:42: Patron perks! 1:09:08: Looking ahead

Oct 7, 20241h 9m

TunnelVision, VPNs and You

Two security researchers showed how many modern VPN services are vulnerable to malicious misconfiguration, exposing some or all of your internet traffic. While this is not likely to impact most of us, it does expose the limitations of Virtual Private Networks and why they are not silver bullets for security of privacy – despite many marketing claims to the contrary. Today we’ll discuss how TunnelVision works, how it can be mitigated, and how this affects different privacy threat models with the two researchers from Leviathan Security, Dani Cronce and Lizzie Moratti. Interview Notes Lizzie Moratti: https://www.linkedin.com/in/lmoratti/  Dani Cronce: https://www.linkedin.com/in/danicronce/  TunnelVision: https://www.tunnelvisionbug.com/  ProtonVPN threat model: https://protonvpn.com/blog/threat-model  Dani’s GitHub: https://github.com/superit23  Leviathan Security blog: https://www.leviathansecurity.com/blog  Veilid: https://veilid.com/  Willy Wonka scene: https://www.youtube.com/watch?v=pvS3j8VtanM  Linux network namespaces: https://blog.scottlowe.org/2013/09/04/introducing-linux-network-namespaces/  What is DeFi? https://www.investopedia.com/decentralized-finance-defi-5113835  Further Info Help me brainstorm ways to reach more people!: https://fdsd.me/awareness2 Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:23: Reminder: brainstorming survey 0:01:47: Podcast chapter markers! 0:02:54: Interview setup 0:05:55: What is a VPN and what isits intended purpose? 0:10:27: If most connections are secured today, why do we need a VPN? 0:12:40: Why do we trust a VPN provider more than our internet access provider? 0:17:40: What are you trying to do with a VPN? 0:19:13: Who can see my internet traffic? 0:25:30: What is TunnelVision and what are the implications for VPN users? 0:29:42: What’s a less technical way to understand TunnelVision? 0:33:06: Why might I not want all my traffic to go through the VPN? 0:35:02: How dangerous is TunnelVision for the average person? 0:42:30: How did the VPN companies respond? 0:51:19: What VPN features can mitigate the risk? 0:57:42: Have any VPN makers fixed this problem? Do OS vendors have responsibility here? 1:02:11: Do you have recommendations for VPNs? Is there new tech that might help here? 1:04:00: Would privacy regulations help here? 1:06:24: What are you working on next? 1:08:51: Interview wrap-up 1:13:31: Looking ahead

Sep 30, 20241h 14m

Malware Reboot Remedy

We often think of malware as a problem for our computers and perhaps our smartphones. But bad guys love to hack our home routers and IoT devices, as well. Thankfully, purging malware from those types of devices can usually be done just by rebooting them. (There’s a reason tech support always asks you to try turning your device off and back on again.) I’ll explain why this works and what you should do to protect your connected devices. In other news: I explain why most people are not in danger of their devices blowing up; a new Windows phishing campaign uses fake CAPTCHAs and PowerShell; LinkedIn started training their AI on your data before telling you how to opt out; Oracle’s CEO touts his vision of ubiquitous AI surveillance; Ford seeks a patent to show you ads in your vehicle based on your conversations and other private data; Meta admits to scraping public Instagram and Facebook posts to train its AI; four great new iOS 18 privacy and security features; Apple Intelligence servers are very basic, for a reason; and the FBI shuts down a massive Chinese botnet. Article Links [WIRED] Your Phone Won’t Be the Next Exploding Pager https://www.wired.com/story/exploding-pagers-hezbollah-phones/ [briankrebs] This Windows PowerShell Phish Has Scary Potential https://krebsonsecurity.com/2024/09/this-windows-powershell-phish-has-scary-potential/ [404media.co] LinkedIn Is Training AI on User Data Before Updating Its Terms of Service https://www.404media.co/linkedin-is-training-ai-on-user-data-before-updating-its-terms-of-service/ [theregister.com] Ellison declares Oracle ‘all in’ on AI mass surveillance https://www.theregister.com/2024/09/16/oracle_ai_mass_surveillance_cloud/ [therecord.media] Ford seeks patent for tech that listens to driver conversations to serve ads https://therecord.media/ford-patent-application-in-vehicle-listening-advertising [9to5Mac] Meta scraped all public Facebook and Instagram posts since 2007 for AI training https://9to5mac.com/2024/09/11/meta-scraped-all-public-facebook-and-instagram-posts-since-2007-for-ai-training/ [TechRadar] I’m a privacy expert—here are the 4 iOS 18 features I’m excited about https://www.techradar.com/phones/im-a-privacy-experthere-are-the-4-ios-18-features-im-excited-about [9to5Mac] Apple Intelligence servers are really basic, says Craig Federighi – and that’s deliberate https://9to5mac.com/2024/09/12/apple-intelligence-servers-are-really-basic-says-craig-federighi-and-thats-deliberate/ [Gizmodo] FBI Shuts Down Botnet Run by Beijing-Backed Hackers That Hijacked Over 200,000 Devices https://gizmodo.com/fbi-shuts-down-botnet-run-by-beijing-backed-hackers-that-hijacked-over-200000-devices-2000500627 Tip of the Week: Malware Reboot Remedy Further Info Awareness Campaign Phase 2!: https://fdsd.me/awareness2 LinkedIn privacy settings: https://www.linkedin.com/mypreferences/d/categories/privacy Test your ad blocker(s): https://d3ward.github.io/toolz/adblock.html Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:31: Update Apple devices 0:01:36: Awareness Campaign teaser 0:02:04: News rundown 0:04:08: Your Phone Won’t Be the Next Exploding Pager 0:08:00: This Windows PowerShell Phish Has Scary Potential 0:12:34: LinkedIn Trains AI on Your Data Before Updating Its ToS 0:16:41: Ellison declares Oracle ‘all in’ on AI mass surveillance 0:20:15: Ford seeks patent for tech that listens to driver conversations to serve ads 0:26:32: Meta scraped all public Facebook and Instagram posts since 2007 for AI training 0:30:29: I’m a privacy expert—here are the 4 iOS 18 features I’m excited about 0:35:55: Apple Intelligence servers are really basic – and that’s deliberate 0:40:57: FBI Shuts Down Botnet Run by Beijing-Backed Hackers 0:45:02: Tip of the Week: Malware Reboot Remedy 0:54:29: Ad Block Tester 0:55:43: Awareness Campaign, Phase 2! 1:01:44: Looking ahead

Sep 23, 20241h 2m

Post-Quantum Crypto

You may be vaguely aware of the term ‘quantum computing’ from media reports. But what you may not have picked up on is that one of the primary uses for quantum computers may be to break data encryption. Furthermore, you may not realize that if three-letter agencies can save off our encrypted emails and messages now, this could mean they could read them in the future when sufficiently powerful quantum computing becomes viable. How does this work? And what can we do about it now to protect our privacy in the future? We’ll dig into all of this today with Brandon Sundh from Tuta (formerly Tutanota), a prominent secure email company, who is already deploying such protections. Interview Notes Try Tuta! https://tuta.com/  Tuta’s quantum-safe crypto: https://tuta.com/blog/post-quantum-cryptography  Quantum mechanics: https://en.wikipedia.org/wiki/Quantum_mechanics  Schrödinger’s cat:  https://en.wikipedia.org/wiki/Schr%C3%B6dinger’s_cat  NIST post-quantum standards: https://csrc.nist.gov/projects/post-quantum-cryptography NSA pays RSA to weaken encryption?: https://www.reuters.com/article/2013/12/20/us-usa-security-rsa-idUSBRE9BJ1C220131220/ Longer passwords are better: https://firewallsdontstopdragons.com/need-a-bigger-password-haystack/  Privacy Guides on Proton Wallet: https://www.privacyguides.org/articles/2024/09/08/proton-wallet-review/#why-does-this-exist Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:02:50: Some terminology first 0:07:33: What is quantum computing and what’s it good for? 0:16:25: What are the currrent capabilities of quantum computers? 0:22:02: How long have we been working on quantum computers? 0:25:01: If QC is still so far off, why do we need to prepare now? 0:30:53: How do we design encryption to make it safe against quantum computers? 0:36:10: How can we be sure that the NSA isn’t buillding backdoors into these algorithms? 0:41:11: Will post-quantum algorithms replace current ones or augment them? 0:45:51: How soon will quantum-safe crypto be roled out? 0:52:42: Who will be able to own and operate these quantum computers? 0:54:45: Are law enforcement agencies pushing back against quantum-safe crypto? 1:00:34: Who is more likely to win: coder makers or code breakers? 1:04:24: Wrap-up 1:05:55: Looking ahead

Sep 16, 20241h 8m

The Truth is Out There

Mis- and disinformation is just a fact of modern life, but certain events can cause the practice to significantly increase – like a big election. This is a good time to review this phenomenon, learning how to recognize it, how to avoid being drawn in, and perhaps most importantly how to reduce its spread. In other news: Telegram’s CEO was arrested in France; too many people keep saying Telegram is an secure messaging app when it’s really not; if you think ads and tracking are bad now, wait till you hear all the ways modern TVs are monetizing their users; sextortion scams are using some new techniques to scam their victims; consumer groups have lobbied the FTC to create clear guidance on ‘software tethering’; and California just approved a new privacy bill that will finally require companies to honor universal opt-out signals from apps and browsers. Article Links BBC] Telegram CEO Pavel Durov arrested at French airport https://www.bbc.com/news/articles/ckg2kz9kn93o [blog.cryptographyengineering.com] Is Telegram really an encrypted messaging app? https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/ [Ars Technica] Your TV set has become a digital billboard. And it’s only getting worse. https://arstechnica.com/gadgets/2024/08/tv-industrys-ads-tracking-obsession-is-turning-your-living-room-into-a-store/ [briankrebs] Sextortion Scams Now Include Photos of Your Home https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/ [advocacy.consumerreports.org] Consumer Reports, U.S. PIRG, and 15 other groups call on FTC to create clear guidance for ‘software tethering’ https://advocacy.consumerreports.org/press_release/ftc-software-tethering/ [Dark Reading] California Approves Privacy Bill Requiring Opt-Out Tools https://www.darkreading.com/data-privacy/california-privacy-bill-require-opt-out-tools Tip of the Week: Spotting Fake News https://firewallsdontstopdragons.com/the-truth-is-out-there/  Further Info My series on deleting your public data online: https://firewallsdontstopdragons.com/osint-reconnaissance/ Enabling Global Privacy Control (GPC): https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:02:14: News preview 0:05:22: Telegram CEO Pavel Durov arrested at French airport 0:09:47: Is Telegram really an encrypted messaging app? 0:19:57: Your TV set has become a digital billboard. And it’s only getting worse. 0:41:25: Sextortion Scams Now Include Photos of Your Home 0:48:06: Consumer groups call on FTC to create clear guidance for ‘software tethering’ 0:54:33: California Approves Privacy Bill Requiring Opt-Out Tools 0:59:22: Tip of the Week: Dealing with Misinformation 1:11:36: Looking ahead

Sep 9, 20241h 14m

Crazy Proton Summer

Proton released three major new products this summer, all within the span of about a couple months: Proton Docs, Proton Wallet and Proton Scribe. Given that Proton is a privacy-focused company, some of these offerings seemed almost at odds with that mission. So today I ask Andy Yen (Proton’s CEO) some questions about the privacy of their Bitcoin wallet and AI editing tool. We also discuss the new Proton Foundation and how it safeguards their privacy mission for the future. Finally, I ask Andy if they would consider acquiring Mozilla to save the Firefox browser and, in the wake of the blow back Signal received about protecting local access to messaging data, how Proton addresses the ‘compromised machine’ threat model. Interview Notes Proton Docs: https://proton.me/blog/docs-proton-drive  Proton Wallet: https://proton.me/blog/proton-wallet-launch  Proton Scribe: https://proton.me/blog/proton-scribe-writing-assistant  Proton Foundation: https://proton.me/blog/proton-non-profit-foundation  Techlore on Proton Wallet: https://www.youtube.com/watch?v=tESbBM2LZHM&t=1922s  Seth for Privacy’s Andy Yen interview: https://optoutpod.com/episodes/protonwallet-andy-yen/  My interview on Easy Prey Podcast: https://www.easyprey.com/firewalls-dont-stop-dragons-with-carey-parker/ Techlore: https://www.techlore.tech/ Privacy Guides: https://www.privacyguides.org/  The New Oil: https://thenewoil.org/  Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:18: Interview setup 0:04:18: Why did you release so many new products all at once? 0:05:53: Did you develop Proton Docs from scratch? Will we get Proton Sheets, too? 0:10:09: What drove you to add AI features? How do you maintain privacy with AI? 0:17:07: Why did Proton feel the need to create another cryptocurrency wallet? 0:21:37: Who is the target audience for Proton Wallet? 0:28:38: As a privacy company, why go with Bitcoin, which is not really private? 0:39:34: Will you support Monero or Zcash? 0:40:40: Why did you restructure Proton as a foundation? What’s the impact of this? 0:45:41: How is this new foundation different from others like Mozilla or Tor? 0:47:59: Would Proton ever consider acquiring Mozilla to save Firefox? 0:55:43: Does TunnelVision affect Proton VPN? How can we improve VPNs generally? 1:01:35: Signal was bashed for not encrypting local keys. How does Proton handle this? 1:05:25: What’s coming next from Proton? 1:07:48: Interview wrap-up 1:10:54: Couple updates on Wallet, Scribe availability 1:11:50: Recommending other great privacy resources and Proton discussions 1:12:53: Upcoming shows 1:14:29: Upcoming podcast awareness campaign

Sep 2, 20241h 16m

National Public Data Breach

The headlines have been on fire with stories about 3 billion people’s data being leaked from a company you’ve never heard of. But like many such stories, the mainstream media gets a lot of the important details wrong and glosses over a lot of the important nuances. Today we’re going to dive into what really happened and what you should do about it, whether your data was part of the breach or not. In other news: Illinois waters down its landmark biometric information law; US court rules geofence warrants are unconstitutional; FTC to investigate :surveillance pricing” and files rule impacting shady product reviews; the CFPB cracks down on some types of consumer data sales; and Consumer Reports evaluates several top data deletion services. Article Links [Reuters] Illinois governor approves business-friendly overhaul of biometric privacy law https://www.reuters.com/legal/government/illinois-governor-approves-business-friendly-overhaul-biometric-privacy-law-2024-08-05/ [TechCrunch] US appeals court rules geofence warrants are unconstitutional https://techcrunch.com/2024/08/13/us-appeals-court-rules-geofence-warrants-are-unconstitutional/ [Electronic Frontier Foundation] To Fight Surveillance Pricing, We Need Privacy First https://www.eff.org/deeplinks/2024/08/fight-surveillance-pricing-we-need-privacy-first [ftc.gov] Federal Trade Commission Announces Final Rule Banning Fake Reviews and Testimonials https://www.ftc.gov/news-events/news/press-releases/2024/08/federal-trade-commission-announces-final-rule-banning-fake-reviews-testimonials [natlawreview.com] CFPB Forecasts New Rule Cracking Down on Consumer Data Sales https://natlawreview.com/article/cfpb-forecasts-new-rule-cracking-down-consumer-data-sales [Los Angeles Times] Hackers may have stolen the Social Security numbers of every American. How to protect yourself https://www.latimes.com/business/story/2024-08-13/hacker-claims-theft-of-every-american-social-security-number [troyhunt.com] Inside the “3 Billion People” National Public Data Breach https://www.troyhunt.com/inside-the-3-billion-people-national-public-data-breach/ [consumerreports.org] Evaluating People-Search Site Removal Services https://innovation.consumerreports.org/new-report-data-defense-evaluating-people-search-site-removal-services/ Tip of the Week: OSINT Final Steps https://firewallsdontstopdragons.com/osint-final-steps/ Other Helpful Links Have I Been Pwned: https://haveibeenpwned.com/ NPD Data Breach search tool: https://npd.pentester.com/ Privacy Guides data removal tools: https://www.privacyguides.org/en/data-broker-removals/ Techlore video on data removal: https://www.youtube.com/watch?v=tESbBM2LZHM Google’s Results About You: https://myactivity.google.com/results-about-you?pli=1 How to freeze your credit: https://firewallsdontstopdragons.com/credit-freeze-now-is-the-time/ How and why to plant your flag: https://firewallsdontstopdragons.com/why-you-need-to-plant-your-flag/ Strong passwords: https://firewallsdontstopdragons.com/need-a-bigger-password-haystack/ Backing up 2FA codes: https://firewallsdontstopdragons.com/how-to-backup-2fa-seed-codes/ Further Info Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:04:00: News preview 0:06:33: Illinois governor approves business-friendly overhaul of biometric privacy law 0:11:18: US appeals court rules geofence warrants are unconstitutional 0:14:51: To Fight Surveillance Pricing, We Need Privacy First 0:21:56: FTC Announces Final Rule Banning Fake Reviews and Testimonials 0:28:25: CFPB Forecasts New Rule Cracking Down on Consumer Data Sales 0:32:57: Hackers may have stolen the Social Security numbers of every American 0:44:25: Inside the “3 Billion People” National Public Data Breach 1:03:48: CR: Evaluating People-Search Site Removal Services 1:06:36: Tip of the Week: OSINT Final Steps 1:19:55: Wrap-up

Aug 26, 20241h 21m

Dating App Privacy

Finding your soul mate or even just a one-night stand can all be done digitally now – there’s an app for that. Several, in fact. But in order to find the best match, you need to turn over a lot of extremely personal information. You probably also need to let the app track your location, so you’re only matching people within some acceptable distance. You would hope that dating apps would be better than other apps at securing your private data… but are they? And are these services selling my data to advertisers? Today I answer these questions and many more with Zoë MacDonald from Mozilla’s Privacy Not Included team who recently published a full report on this topic. Interview Notes Privacy Not Included report on dating apps: https://foundation.mozilla.org/en/privacynotincluded/articles/data-hungry-dating-apps-are-worse-than-ever-for-your-privacy/ Mozilla Foundation: https://foundation.mozilla.org/en/?form=donate-header Mozilla’s Privacy Not Included: https://foundation.mozilla.org/en/privacynotincluded/ Falling out of love with dating apps: https://www.theguardian.com/lifeandstyle/2023/oct/28/its-quite-soul-destroying-how-we-fell-out-of-love-with-dating-apps Using dating apps to locate someone: https://www.techradar.com/pro/privacy-flaw-in-top-dating-apps-could-have-revealed-user-location-down-to-2-metres How to freeze your credit: https://firewallsdontstopdragons.com/credit-freeze-now-is-the-time/ Further Info Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:57:02: Wrap-up and looking ahead 0:02:06: Freeze your credit! 0:04:19: How do modern dating apps work, exactly? 0:08:19: How do they find compatible matches? 0:10:34: Do these apps require constant access to your current location? 0:14:50: How much information used by these apps is inferred vs explicitly requested? 0:17:59: Do these apps use inferred data to weed out bad actors? 0:20:36: How did you decide which apps to evaluate? 0:23:54: What were your key takeaways and most alarming findings? 0:25:57: Do apps owned by the same parent company have similar privacy policies? 0:27:28: How transparent are these apps about sharing your data? 0:29:08: Was there any correlation between app cost and monetizing your data? 0:31:20: Are dating apps better about securing your personal data? 0:33:53: Do any of the dating apps offer end-to-end encryption of DMs? 0:35:40: Do these services try to keep you from leaving the app? 0:39:03: Once you find a match, can you get a refund for unused subscription time? 0:40:28: How do new AI features on dating apps affect your privacy? 0:43:30: Have there been any major dating service data breaches? 0:45:05: How bad are these apps for romance scams like ‘big butchering’? 0:47:10: If I still want to use a dating app, how do I maximize my privacy? 0:51:19: Can I use a service on the web only (no app)? Can I delete my data? 0:54:20: How well do dating apps actually work, in terms of finding a mate?

Aug 19, 20241h 0m

Hacker Summer Camp 2024

It’s time once again for cybersecurity professionals to make the pilgrimage to the scorching desert of Las Vegas, Nevada for a week of tech conferences that we lovingly refer to as Hacker Summer Camp. Today I’ll bring you my on-the-ground reporting from BSides and DEF CON. I’ll also bring you part 2 of my series on Open Source Intelligence (OSINT) and how to purge your personal data from the web. In the news this week: Vegas hotels search hacker’s rooms; Apple and others fix old but important browser bug; NFL rolls out more facial recognition at stadiums; Ford looks to patent car surveillance tech; automakers sold your data to brokers for pennies; border agents can no longer search your smartphone without a warrant; judge rules that Google is a monopoly. Article Links [404media.co] Hotel to Search Rooms During DEF CON Hacking Conference https://www.404media.co/hotel-to-search-rooms-during-def-con-hacking-conference/ [AppleInsider] Apple has closed an ancient macOS Safari security hole https://appleinsider.com/articles/24/08/07/apple-has-closed-an-ancient-macos-safari-security-hole [therecord.media] NFL to roll out facial authentication software league-wide https://therecord.media/nfl-to-roll-out-facial-authentication-league-wide [therecord.media] Ford wants patent for tech allowing cars to surveil and report speeding drivers https://therecord.media/ford-seeks-patent-cars-surveil-speeders-report-to-police [The New York Times] Automakers Sold Driver Data for Pennies, Senators Say https://www.nytimes.com/2024/07/26/technology/driver-data-sold-for-pennies.html [9to5Mac] Border agents cannot search smartphones without a warrant, rules federal court https://9to5mac.com/2024/07/29/cannot-search-smartphones-without-a-warrant/ [AppleInsider] Judge rules Google is a search and advertising monopoly https://appleinsider.com/articles/24/08/05/judge-rules-that-google-is-a-search-and-advertising-monopoly Tip of the Week: OSINT Remediation https://firewallsdontstopdragons.com/osint-remediation/  Further Info BSides Las Vegas: https://bsideslv.org/  DEF CON 32: https://defcon.org/html/defcon-32/dc-32-index.html UnDisruptible27: https://securityandtechnology.org/undisruptable27/ Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:26: Summer Camp Highlights 0:10:25: Hotel to Search Rooms During DEF CON 0:15:14: Apple has closed an ancient macOS Safari security hole 0:20:00: NFL to roll out facial authentication software league-wide 0:26:25: Ford wants patent for tech allowing cars to surveil and report speeding drivers 0:29:38: Automakers Sold Driver Data for Pennies, Senators Say 0:32:46: Border agents cannot search smartphones without a warrant, 0:36:44: Judge rules Google is a search and advertising monopoly 0:40:52: Tip of the Week: OSINT Remediation 0:54:25: EFF Tech Trivia update

Aug 12, 202459 min

Catch You on the BSide

Jack Daniel is a storyteller, wanderer, comic, bartender, blacksmith, luthier, historian, mechanic, and the world’s oldest millennial. He is also one of the founders of Security BSides. Jack has a colorful and interesting history, and today we’ll learn about how and why he started BSides, delve into a little hacker conference history, talk about modern hackers and cybersecurity conferences and how he’s seen them change over the years, and how hackers and their conferences are vastly different than the others. Interview Notes Jack Daniel: https://www.linkedin.com/in/jackadaniel/ BSides official site: https://bsides.org/ BSides Las Vegas (part of hacker summer camp): https://bsideslv.org/ InfoSecMap: https://infosecmap.com/ Cult of the Dead Cow interview: https://podcast.firewallsdontstopdragons.com/2023/08/07/cult-of-the-dead-cow/ Jeff Moss interview #1: https://podcast.firewallsdontstopdragons.com/2021/08/16/on-a-dark-tangent/ Jeff Moss interview #2: https://podcast.firewallsdontstopdragons.com/2022/08/29/the-night-the-lights-went-out-in-vegas/ CackalackyCon: https://cackalackycon.org/ Further Info Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:49: Interview lingo 0:04:05: How did you get into the world of cybersecurity and hacking? 0:12:40: Why did you start BSides? 0:17:43: What were some of the first BSides talks like? 0:21:42: What are the founding principles of BSides? 0:28:00: What approval do you need to start a BSides conference? 0:34:44: How have other hacker conferences influenced BSides and vice versa? 0:36:53: Is there a beef between BSides and Black Hat? 0:38:58: What’s your connection with ShmooCon? 0:42:42: How have hackers and these conferences changed since the old days? 0:47:40: Discussion on responsible disclosure 0:50:39: Two different kinds of presenters 0:54:02: You might be a hacker if… 1:01:30: What’s the best way to find a local hacker conference? 1:06:50: BSides is about community 1:08:29: Interview wrap-up 1:11:19: Patron content 1:11:53: Looking ahead

Aug 5, 20241h 14m

CrowdStrike Lessons Learned

Last week, we all learned about a company called CrowdStrike that apparently has the capability to single-handedly bring multiple airlines, hospitals and other large companies to their knees in an instant. There are many lessons we should be learning from this incident, though I’m not going to hold my breath. I’ll tell you what happened and what I think we should be doing to avoid a repeat of this incident in the future. In other news: Google finally throws in the towel on blocking third-party cookies; a private organization claims to have gained access to advertising-based location data on Trump’s shooter; Republican VP candidate JD Vance forgets to make his Venmo data private; leaked docs show what phones Cellebrite can and can’t hack; Meta takes down thousands of accounts related to sextortion ring; and for my Tip of the Week, we’ll tackle part 1 of my article on deleting your public data from the web. Article Links [AppleInsider] Google gives up on Chrome plan to ditch third-party cookies https://appleinsider.com/articles/24/07/23/google-gives-up-on-chrome-plan-to-ditch-third-party-cookies [404media.co] Heritage Foundation Claims to Use Location Data to Track Trump Shooter’s Movements https://www.404media.co/heritage-foundation-claims-to-use-location-data-to-track-trump-shooters-movements/ [9to5Mac] J.D. Vance Venmo connections public, as privacy failing still in place six years later https://9to5mac.com/2024/07/19/jd-vance-venmo-connections-public/ [404media.co] Leaked Docs Show What Phones Cellebrite Can (and Can’t) Unlock https://www.404media.co/leaked-docs-show-what-phones-cellebrite-can-and-cant-unlock/ [The Washington Post] Meta takes down thousands of Facebook, Instagram accounts running sextortion scams from Nigeria https://www.washingtonpost.com/business/2024/07/24/meta-nigeria-sextortion-scam-instagram-facebook/fce496c6-49b8-11ef-9149-c75da5dd9201_story.html [Schneier Blog] The CrowdStrike Outage and Market-Driven Brittleness https://www.schneier.com/blog/archives/2024/07/the-crowdstrike-outage-and-market-driven-brittleness.html Tip of the Week:OSINT Reconnaissance: https://firewallsdontstopdragons.com/osint-reconnaissance/ Further Info Book surge results: https://fdsd.me/booksurge Moxie Marlinspike (Signal) on Cellebrite vulnerabilities: https://signal.org/blog/cellebrite-vulnerabilities/ Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:51: AT&T breach update 0:01:44: News rundown 0:03:56: Google gives up on Chrome plan to ditch third-party cookies 0:08:28: Group Claims to Use Location Data to Track Trump Shooter’s Movements 0:13:42: J.D. Vance Venmo connections public 0:19:28: Leaked Docs Show What Phones Cellebrite Can (and Can’t) Unlock 0:27:35: Meta takes down thousands of accounts running sextortion scams 0:31:21: Lessons from the CrowdStrike Outage 0:44:52: Tip of the Week: OSINT Reconnaissance 0:55:20: Book surge report 0:57:06: More help will be needed 0:58:10: Looking ahead

Jul 29, 202459 min

Open Source Intelligence

If someone decided to dig into your life – perhaps even try to ‘dox’ you – how might they go about doing that? What could they find about you right now on the internet? You might be surprised at how much information is readily available from public sources, including your local government agencies and state databases. Today I’ll be talking with Jason Edison from Intel Techniques whose day job is using open source intelligence, or OSINT, to find suspected criminals and whose night job is helping people remove that same information to protect their privacy and even personal security. Interview Notes Intel Techniques: https://inteltechniques.com/ Data Removal Guide: https://inteltechniques.com/workbook.html Data Removal Workbook (PDF): https://inteltechniques.com/data/workbook.pdf Credit Freeze Guide: https://inteltechniques.com/freeze.html MySudo privacy app: https://mysudo.com/ SimpleLogin (Proton) email aliases: https://simplelogin.io/ Private credit cards: https://privacy.com/ Further Info Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:41: Interview setup 0:02:34: What do you do for your day job in law enforcement? 0:05:17: What is open source intelligence, exactly? 0:08:41: What are your primary sources for OSINT? 0:12:01: What is doxing and how might it impact someone? 0:14:56: How does an OSINT specialist also value personal privacy? 0:22:36: How do others in law enforcement view data collection and privacy? 0:28:36: When emotional cases arise, do officials favor privacy rights over catching bad guys? 0:33:32: How do we balance privacy rights vs public safety? 0:39:19: How would you do a full workup on someone? 0:45:18: Where do people overshare or give away the most personal information? 0:52:31: How much of my personal information is available via public records? 0:56:43: Will tooks like AI help us find the needles in the haystacks? 1:00:56: What about data deletion services – are they worth it? 1:07:51: How useful are email and phone aliases for privacy? 1:11:17: How do you prove your identity to deletion sites without giving more info? 1:17:10: What tools can I find at Intel Techniques? 1:19:00: My data deletion journey

Jul 22, 20241h 21m

How & Why to Block Ads

Ads on the web are beyond annoying – they are actually a threat to your privacy and sometimes even your security. Ads pay for a lot of the “free” web content we consume, but until ad networks stop tracking us and selling ad space to phishing and malware groups, we need tools to block them. Today I’ll give you two solid options for doing so. In the news: Australian man charged for WiFi scam on flights; Airbnb reveals 35,000 complaints about hidden cameras; Linksys routers expose WiFi credentials; a massive new hacker list contains 10 billion unique passwords; a new AT&T call and text records data breach; Signal gets flak for response to storing encryption keys in the clear; Mozilla launches “privacy-preserving” ad attribution system (on by default); Proton launches encrypted Google Docs competitor. Article Links [The Hacker News] Australian Man Charged for Fake Wi-Fi Scam on Domestic Flights https://thehackernews.com/2024/07/australian-man-charged-for-fake-wi-fi.html [9to5Mac] 35,000 complaints about hidden cameras in Airbnb properties https://9to5mac.com/2024/07/10/hidden-cameras-in-airbnb-properties/ [stackdiary.com] Linksys Velop routers send Wi-Fi passwords in plaintext to US servers https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ [cybernews.com] RockYou2024: 10 billion passwords leaked in the largest compilation of all time https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/ [TechCrunch] What the AT&T call records data breach means for you https://techcrunch.com/2024/07/12/what-the-att-call-records-data-breach-means-for-you/ [stackdiary.com] Signal under fire for storing encryption keys in plaintext https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/ [Mozilla] Privacy-Preserving Attribution https://support.mozilla.org/en-US/kb/privacy-preserving-attribution [Lifehacker] Why You Should Consider Proton Docs Over Google https://lifehacker.com/tech/why-you-should-consider-proton-docs-over-google Tip of the Week: How & Why to Block Ads https://firewallsdontstopdragons.com/how-and-why-to-block-ads/ Further Info Enter the DEF CON 32 ticket raffle: send email to [email protected] Techlore NextDNS tutorial: https://www.youtube.com/watch?v=WUG57ynLb8I Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:21: Book surge report 0:03:00: News rundown 0:05:06: Australian Man Charged for Fake Wi-Fi Scam on Domestic Flights 0:09:50: 35,000 complaints about hidden cameras in Airbnb properties 0:15:31: Linksys Velop routers send Wi-Fi passwords in plaintext to US servers 0:20:29: 10 billion passwords leaked in the largest compilation of all time 0:26:51: What the AT&T call records data breach means for you 0:32:37: Signal under fire for storing encryption keys in plaintext 0:47:24: Mozilla’s new Privacy-Preserving Attribution 0:58:58: New: Proton Docs! 1:00:18: Tip of the Week: How & Why to Block Ads 1:12:41: Wrap up 1:13:01: Book surge report 1:15:25: DEF CON 32 ticket raffle! 1:17:48: Looking ahead

Jul 15, 20241h 18m

Promising Privacy Tech

We’re generating a ridiculous amount of data every day. Much of it is highly personal and that’s dangerous. But there are actually several Privacy Enhancing Technologies that may allow us to use this personal data to improve our collective quality of life without ruining the privacy of the data subjects. I’ll be discussing these PETs with Irene Knapp who spent five years working in the privacy department at Google. I will also spend a good bit of time asking them about what it’s like working at Google and get some insights about the company’s approach to privacy from the inside. (Spoiler: it’s not good.) Interview Notes Internet Safety Labs: https://internetsafetylabs.org/about-us/ Irene’s Google departure post: https://medium.com/@Irenes/on-the-occasion-of-leaving-google-b8c7029c8d8b Coworker.org: https://coworker.org Google loses privacy chief: https://www.techspot.com/news/103268-google-privacy-chief-head-competition-law-leaving-not.html Further Info BOOK SURGE!! https://fdsd.me/booksurge Send me your questions! https://fdsd.me/qna Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:40: Interview setup 0:03:56: What is Internet Safety Labs and what do you do there? 0:05:45: Why do we not have liability in the software industry? 0:07:02: How did you come to work for Google and what was your experience like there? 0:07:58: What caused you to eventually leave? 0:10:26: How did private policy evolve while you were at Google? 0:12:36: What was happening in Google that impeded your efforts? 0:19:19: How does Google compare to other companies like Facebook? 0:20:56: What’s your take on Google’s new Privacy Sandbox technology? 0:27:24: Can we do some good with all the data we’re collecting? 0:33:51: From where do we derive a legal right to privacy? 0:35:10: How does differential privacy work? 0:38:49: Where might we use differential privacy? 0:41:59: What is homomorphic encryption and how does it work? 0:44:47: Are there any other promising PETs? 0:46:49: How do zero knowledge proofs work? 0:49:20: Which of the PETs seem most promising right now? 0:51:20: Do we need privacy regulations to save us here? 0:56:19: What’s next for you? 0:58:31: Interview wrap-up 1:00:52: BOOK SURGE!!

Jul 8, 20241h 11m

Backing Up Other Data

We’ve talked about how to backup your local device data and how to back up data that is primarily stored in the cloud. But there’s a lot of important, irreplaceable data we take for granted: data owned by others. This might be shared online photo albums, cloud document collaborations, eBooks and other digital media, and even websites you frequently rely on. Today we’ll talk about how you can make local copies of these files in case they should ever go offline. In other news: European politicians’ personal details exposed online; Proton transitions to non-profit corporate structure; lawsuit claims Microsoft tracked sex toy purchases; online ID verification service exposed drivers licenses; new Mac info-stealer served up by Google Ads; law enforcement is spying on Americans’ mail; new ALPR vulnerabilities prove it’s a public safety threat; UK hospital hack leaks 300M patient records; US bans Kaspersky software; Sonos removes promise not to sell its users’ data; Mozilla buys a ‘privacy-centric’ ad firm. Article Links [proton.me] Cyber house of cards – Politicians’ personal details exposed online https://proton.me/blog/politicians-exposed-dark-web [proton.me] Proton is transitioning towards a non-profit structure https://proton.me/blog/proton-non-profit-foundation [404media.co] Lawsuit Claims Microsoft Tracked Sex Toy Shoppers With ‘Recording in Real Time’ Software https://www.404media.co/lawsuit-claims-microsoft-tracked-sex-toy-shoppers-with-recording-in-real-time-software/ [404media.co] ID Verification Service for TikTok, Uber, X Exposed Driver Licenses https://www.404media.co/id-verification-service-for-tiktok-uber-x-exposed-driver-licenses-au10tix/ [Ars Technica] Mac users served info-stealer malware through Google ads https://arstechnica.com/security/2024/06/mac-info-stealer-malware-distributed-through-google-ads/ [The Washington Post] Law enforcement is spying on thousands of Americans’ mail, records show https://www.washingtonpost.com/technology/2024/06/24/post-office-mail-surveillance-law-enforcement/ [Electronic Frontier Foundation] New ALPR Vulnerabilities Prove Mass Surveillance Is a Public Safety Threat https://www.eff.org/deeplinks/2024/06/new-alpr-vulnerabilities-prove-mass-surveillance-public-safety-threat [TechCrunch] US bans sale of Kaspersky software citing security risk from Russia  https://techcrunch.com/2024/06/20/us-bans-kaspersky-software-security-risk-russia/ [AppleInsider] Sonos removes a promise to not sell personal data, gets busted by users https://appleinsider.com/articles/24/06/15/sonos-removes-a-promise-to-not-sell-personal-data-gets-busted-by-users [theregister.com] What’s up with Mozilla buying ad firm Anonym? It’s all about ‘privacy-centric advertising’ https://www.theregister.com/2024/06/18/mozilla_buys_anonym_betting_privacy/ Tip of the Week: Backing Up Other Data https://firewallsdontstopdragons.com/how-to-backup-other-data/  Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:25: Book blitz coming soon 0:00:55: Dear Carey reminder 0:01:38: Bitwarden bug fixed 0:02:28: News rundown 0:04:22: EU politicians’ personal details exposed online 0:10:37: Proton adopts non-profit structure 0:15:15: Lawsuit Claims Microsoft Tracked Sex Toy Shoppers 0:19:28: ID Verification Service Exposed Driver Licenses 0:27:38: Mac users served info-stealer malware through Google ads 0:32:33: Law enforcement is spying on thousands of Americans’ mail 0:37:49: New ALPR Vulnerabilities Prove Mass Surveillance Is a Public Safety Threat 0:45:22: US bans sale of Kaspersky software 0:54:45: Sonos removes a promise to not sell personal data 0:56:21: What’s up with Mozilla buying ad firm Anonym? 1:06:38: Tip of the Week: Backing up other data 1:17:54: Wrap up, look ahead

Jul 1, 20241h 19m

Means of Control

Every day, we generate tons of digital exhaust: our web browsing, GPS location, online and in-store purchases, emails and messages, social media posts and feed viewing habits, and much, much more. Online marketers and data brokers have been living off these breadcrumbs for years. The intelligence and law enforcement agencies have found this data to be incredibly revealing, and they can buy most of this data on the open market without requiring any sort of warrant – and they have. This has important implications for democratic societies that value privacy and freedom. I’ll discuss how this mass surveillance works and what it means for all of us with Byron Tau, author of the book “Means of Control”. Interview Notes Means of Control: https://www.amazon.com/Means-Control-Alliance-Government-Surveillance/dp/0593443225 Byron Tau at NOTUS: https://www.notus.org/byron-tau Puking Monkey’s DEF CON presentation: https://www.youtube.com/watch?v=T43Ti7c11lY Make your EZ Pass “moo”: https://hackaday.com/2013/09/16/modified-e-zpass-detects-reads-far-from-toll-booths/ Official US policy on collecting public info on citizens: https://www.dni.gov/index.php/newsroom/press-releases/press-releases-2024/3815-odni-releases-ic-policy-framework-for-commercially-available-information Further Info Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:58: Update your Windows PCs 0:01:32: Interview setup 0:04:59: How might the collection of online data impact a regular person? 0:10:13: What sorts of things can all this data reveal about us? 0:15:44: How much can we learn by tracking a person’s location? 0:17:38: What is ‘gray data’? 0:22:40: Our data can be saved virtually forever – what are the ramifications? 0:26:30: How are data gathering rules different for law enforcement vs intelligence agencies? 0:32:54: When did data brokers start selling our info to government agencies? 0:39:22: Is it legal for these agencies to act as data brokers themselves? 0:42:12: What laws have impacted this sort of data collection in the US? 0:44:49: How and why do these agencies hide this data collection? 0:51:02: Are governments sharing data to skirt local restrictions? 0:54:54: How have these spy programs evolved since 9/11? 1:00:28: Have government agencies lobbied Congress against federal privacy laws?? 1:03:20: How can we limit data collection and increase our privacy? 1:06:24: Could the Big Tech backlash help get a privacy law passed? 1:08:33: What are you working on next? 1:09:59: Interview follow-up 1:11:36: Looking ahead

Jun 24, 20241h 12m

Backup Your Cloud Data

Until recently, most of our important data lived primarily on our devices. Backing up that data often meant choosing a cloud backup service. But today, many of our most important photos and files are actually stored in the cloud. While cloud servers are supposed to be more robust than home computers with flaky hard drives and smartphones that get lost or stolen, it also means that someone else is in control of that data. Cloud services go offline, get bought out or even shut down. We now need to be sure to back up our cloud data, too. In other news: 23andMe breach under investigation by US and Canada; cops release personal location info to FOIA request; hacker gains access to Tile customer data; more car privacy updates; Microsoft Recall backlash highlights our distrust; report shows Microsoft favoring profits over security; Mac Bartender app shadily changes ownership; new Apple privacy features coming. Article Links [malwarebytes.com] 23andMe data breach under joint investigation in two countries https://www.malwarebytes.com/blog/news/2024/06/23andme-data-breach-under-joint-investigation-in-two-countries [theregister.com] Crooks threaten to leak 3B personal records ‘stolen from background check firm’ https://www.theregister.com/2024/06/03/usdod_data_dump/ [404media.co] Cops Released a Car’s Travel History to a Total Stranger https://www.404media.co/cops-released-a-cars-travel-history-to-a-total-stranger/ [404media.co] Hacker Accesses Internal ‘Tile’ Tool That Provides Location Data to Cops https://www.404media.co/hacker-accesses-internal-tile-tool-that-provides-location-data-to-cops/ [The New York Times] Is Your Driving Being Secretly Scored? https://www.nytimes.com/2024/06/09/technology/driver-scores-insurance-data-apps.html [Windows Central] A PR disaster: Microsoft has lost trust with its users, and Windows Recall is the straw that broke the camel’s back https://www.windowscentral.com/software-apps/windows-11/microsoft-has-lost-trust-with-its-users-windows-recall-is-the-last-straw [ProPublica] Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says https://www.propublica.org/article/microsoft-solarwinds-golden-saml-data-breach-russian-hackers [AppleInsider] Adobe’s new terms of service unacceptably gives them access to all of your projects, for free https://appleinsider.com/articles/24/06/06/adobes-new-terms-of-service-unacceptably-gives-them-access-to-all-of-your-projects-for-free [MacRumors] PSA: Bartender Mac App Under New Ownership, But Lack of Transparency Raises Concerns https://www.macrumors.com/2024/06/04/bartender-mac-app-new-owner/ [9to5Mac] iOS 18 includes these new privacy features: Lock and hide apps, improved contact permissions, more https://9to5mac.com/2024/06/10/ios-18-includes-these-new-privacy-features-lock-and-hide-apps-improved-contact-permissions-more/ Tip of the Week: Backup Your Cloud Data: https://firewallsdontstopdragons.com/how-to-backup-cloud-data/  Further Info Under New Management plugin: https://github.com/classvsoftware/under-new-management Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:52: News preview 0:03:11: 23andMe data breach under joint investigation in two countries 0:07:01: Crooks threaten to leak 3B personal records ‘stolen from background check firm’ 0:09:52: Cops Released a Car’s Travel History to a Total Stranger 0:14:22: Hacker Accesses Internal ‘Tile’ Tool That Provides Location Data to Cops 0:20:50: Is Your Driving Being Secretly Scored? 0:29:24: Microsoft has lost trust with its users, and Recall is the straw that broke the camel’s back 0:38:13: Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack 0:45:44: Bartender Mac App Under New Ownership, But Lack of Transparency Raises Concerns 0:51:43: iOS 18 includes these new privacy features 0:55:27: Tip of the Week: Backup Your Cloud Data 1:04:36: Looking ahead

Jun 17, 20241h 6m

Anom: The FBI’s Phone Company

Encrypted communications are important for everyone, even if you have nothing to hide. But they’re also important when you’re trying to hide global criminal operations. Drug smugglers and money launderers have special needs when it comes to secure messaging. Several phone companies were created to address this market. Unfortunately for the criminals, the most popular one – Anom – was secretly run by the FBI. Today Joseph Cox from 404 Media will tell us about this astoundingly audacious sting operation, which is the basis for his book, Dark Wire. Interview Notes Order Dark Wire: https://a.co/d/h9o7ump Anom website (right before take down): https://web.archive.org/web/20210507151115/http://anom.io/ Phantom Secure website (circa 2017): https://web.archive.org/web/20170330122723/http://phantomsecure.com/  Vice Anom story: https://www.vice.com/en/article/n7b4gg/anom-phone-arcaneos-fbi-backdoor Anom phone video: https://www.youtube.com/watch?v=EA1KS-xh0n0  Operation Trojan Shield: https://en.wikipedia.org/wiki/Operation_Trojan_Shield Trojan Shield press conference: https://www.youtube.com/watch?v=S89O0nis_ss  Encrochat: https://en.wikipedia.org/wiki/EncroChat  Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:54: Migrating to Mastodon 0:02:24: Embracing the dark… mode 0:02:45: Countdown to 400 0:03:28: Interview setup 0:04:30: How did this all start with you on an obscure forum for criminals? 0:08:34: What was Operation Trojan Shield? 0:10:49: How did the FBI start a secure phone company? 0:12:41: What were some of Anom’s key tech features? 0:15:26: Where did they get the Arcane Operating System? 0:17:56: How did the ‘duress’ feature work? 0:20:18: How did Anom copy encrypted messages without being detected? 0:24:35: How were these phones marketed to criminals? 0:28:10: What does these phones cost? 0:30:09: What were the legal aspects for this multi-national operation? 0:34:49: How did they use this intelligence without revealing the source? 0:39:38: Did the criminals ever suspect the phones? 0:42:04: How did this all come to an end? 0:46:14: So, are we ‘going dark’ or not? 0:49:27: What lessons did the FBI take away from all this? 0:51:36: Can we still trust things like Signal and Proton? 0:55:39: What’s your next big story or book? 0:58:09: Interview end notes 1:03:12: Looking ahead

Jun 10, 2024

Migrate to Mastodon

Most major social media platforms are a hot mess. Your feed is filled with tons of crap you never asked to see and your data is mined mercilessly to serve you targeted ads. The promise of having a place to trade interesting posts with friends and family is now muddied up with sponsored content chosen by hidden algorithms optimized to keep you scrolling. It doesn’t have to be that way. I’ve found something much better, and I’m inviting you to come join me. In other news: Ticketmaster breach leaks data on half a billion users; the iOS bug that resurrected deleted photos explained; GPT-4 can write working malware based only on CVE bug descriptions; Slack customers upset to learn that their data was being used to train AI systems; WiFi location service can be used to track mobile routers; police are trialing new devices that can track and identify you based on multiple electronic signals; new Windows AI feature records everything you do on your PC; Microsoft rolling out welcome changes to admin privilege use; Google adding several privacy and security features to Android 15; and iVerify how has an Android app. Article Links [Mashable] Ticketmaster hacked. Breach affects more than half a billion users. https://mashable.com/article/ticketmaster-data-breach-shinyhunters-hack [9to5Mac] Security Bite: Here’s the iOS 17.5 bug that resurfaced deleted photos https://9to5mac.com/2024/05/26/security-bite-heres-the-ios-17-5-bug-that-resurfaced-deleted-photos/ [Dark Reading] GPT-4 Can Exploit Most Vulns Just by Reading Threat Advisories https://www.darkreading.com/threat-intelligence/gpt-4-can-exploit-most-vulns-just-by-reading-threat-advisories [securityweek.com] User Outcry as Slack Scrapes Customer Data for AI Model Training https://www.securityweek.com/user-outcry-as-slack-scrapes-customer-data-for-ai-model-training/ [9to5Mac] Apple Location Services vulnerability can enable troop movements to be tracked https://9to5mac.com/2024/05/24/apple-location-services-vulnerability/ [Forbes] New Police Tech Can Detect Phones, Pet Trackers And Library Books In A Moving Car https://www.forbes.com/sites/thomasbrewster/2024/05/14/police-car-surveillance-tech-uncovers-phones-pet-trackers-and-library-books/ [Ars Technica] New Windows AI feature records everything you’ve done on your PC https://arstechnica.com/gadgets/2024/05/microsofts-new-recall-feature-will-record-everything-you-do-on-your-pc/ [PCWorld] Microsoft battens security hatches on Windows admin accounts https://www.pcworld.com/article/2344405/microsoft-battens-security-hatches-on-oft-used-windows-admin-accounts.html [Lifehacker] Google Is Rolling Out Some Great Privacy Features to Android This Year https://lifehacker.com/tech/google-is-rolling-out-some-great-privacy-features-with-android-15 [iverify.io] iVerify Basic is now on Android! https://www.iverify.io/post/iverify-basic-is-now-on-android Tip of the Week: Move to Mastodon https://firewallsdontstopdragons.com/how-to-move-to-mastodon/ Further Info Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:02:34: Ticketmaster hacked, breach affects more than half a billion users 0:05:59: Here’s the iOS 17.5 bug that resurfaced deleted photos 0:12:28: GPT-4 Can Exploit Most Vulns Just by Reading Threat Advisories 0:17:36: User Outcry as Slack Scrapes Customer Data for AI Model Training 0:23:12: Apple Location Services vulnerability can enable troop movements to be tracked 0:34:15: New Police Tech Can Detect Phones, Pet Trackers And Library Books In A Moving Car 0:41:02: New Windows AI feature records everything you’ve done on your PC 0:46:36: Microsoft battens security hatches on Windows admin accounts 0:51:06: Google Is Rolling Out Some Great Privacy Features to Android This Year 0:55:08: iVerify Basic is now on Android 0:56:00: Tip of the Week: Migrate to Mastodon 1:03:21: Looking ahead

Jun 3, 20241h 5m

Why Privacy Matters

Our privacy has never been more threatened. While some of us are vaguely aware of this, most of the rampant data collection and sharing is completely opaque. And the consequences are more dire than most of us realize. We can’t afford to be complacent. We need to push back, to ask questions, and make better choices. Privacy-respecting apps and services do exist today. Making a deliberate and overt decision to use them will force the market (and our elected representatives) to take notice. My guest Naomi Brockwell from NBTV will make a compelling case for privacy and reclaiming control of our data, including several top notch tips for doing so. Interview Notes Naomi Brockwell’s NBTV: https://www.nbtv.media/ A World Without Privacy: https://www.nbtv.media/episodes/a-world-without-privacy A Beginner’s Introduction to Privacy: https://www.amazon.com/Beginners-Introduction-Privacy-Naomi-Brockwell-ebook/dp/B0BQHS8MFS Who can access your car remotely? https://www.youtube.com/watch?v=Ff9pmaSdZV8 Naomi Brockwell on All Things Secured: https://www.youtube.com/watch?v=D0WjIWBQEBM Michael Bazzell’s Extreme Privacy resources: https://inteltechniques.com/links.html Try Proton! https://firewallsdontstopdragons.com/its-time-to-try-proton/ Try Signal! https://firewallsdontstopdragons.com/how-to-switch-to-signal/ Further Info Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:02:58: How did you become a privacy evangelist? 0:06:51: What are some of the most mind-blowing ways we leak personal data? 0:09:56: What were some of Orwell’s most prescient predictions in 1984? 0:15:49: How is surveillance different in real life from 1984? 0:22:23: How does data collection skew the power balance between citizens and authorities? 0:26:36: How do you counter the “I have nothing to hide” argument? 0:29:55: Why is it so important to normalize the use of privacy tools? 0:33:46: What changes do you recommend and what are the impacts for making them? 0:45:48: If you’ve given away tons of personal data already, is it too late? 0:50:07: What can we do to push vendors to respect our privacy more? 0:57:49: What’s the future of privacy look like? 1:00:15: Post-interview notes 1:06:11: Looking ahead

May 27, 20241h 7m

How to Choose a PIN

Security experts talk at length about how to choose a good password – but we don’t often talk about how to choose a good PIN code. A recent analysis by a researcher shows popular patterns humans use when choosing PIN codes, and therefore what you should avoid doing. In the news: MediSecure e-Rx firm hit by data breach; CISA warns of active D-Link router exploit; a couple cases of insecure APIs being abused; 53k Nissan employees’ SSN’s leaked; new macOS malware called Cuckoo; Ascension Healthcare suffers cyberattack; Proton user’s poor OpSec gives him away; TunnelVision VPN attack exploits DHCP feature; Maryland & Vermont pass data privacy laws; tracker detection feature debuts on iPhone & Android. Article Links [BleepingComputer] MediSecure e-script firm hit by ‘large-scale’ data breach https://www.bleepingcomputer.com/news/security/medisecure-e-script-firm-hit-by-large-scale-ransomware-data-breach/ [The Hacker News] CISA Warns of Actively Exploited D-Link Router Vulnerabilities https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-d-link.html [Ars Technica] How I upgraded my water heater and discovered how bad smart home security can be https://arstechnica.com/gadgets/2024/05/how-i-upgraded-my-water-heater-and-discovered-how-bad-smart-home-security-can-be/ [BleepingComputer] Dell API abused to steal 49 million customer records in data breach https://www.bleepingcomputer.com/news/security/dell-api-abused-to-steal-49-million-customer-records-in-data-breach/ [infosecurity-magazine.com] 53,000 Nissan Employees’ Social Security Numbers Exposed https://www.infosecurity-magazine.com/news/employees-social-security-nissan/ [Tom’s Guide] New Cuckoo macOS malware can take over all Macs and steal your passwords https://www.tomsguide.com/computing/malware-adware/new-cuckoo-macos-malware-can-take-over-all-macs-and-steals-your-passwords-too-dont-fall-for-this [Dark Reading] Ascension Healthcare Suffers Major Cyberattack https://www.darkreading.com/cyberattacks-data-breaches/ascension-healthcare-hit-by-cyberattack [restoreprivacy.com] Proton Mail Discloses User Data Leading to Arrest in Spain https://restoreprivacy.com/protonmail-discloses-user-data-leading-to-arrest-in-spain/ [Ars Technica] Novel attack against virtually all VPN apps neuters their entire purpose https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ [mullvad.net] Evaluating the impact of TunnelVision https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision [epic.org] Vermont Passes Landmark Data Privacy Bill https://epic.org/vermont-passes-landmark-data-privacy-bill/ [epic.org] Governor Moore Signs Maryland Online Data Privacy Act https://epic.org/governor-moore-signs-maryland-online-data-privacy-act/ [9to5Mac] Here’s how the new Cross-Platform Tracking Detection works https://9to5mac.com/2024/05/13/cross-platform-tracking-detection-ios-17-5/ Tip of the Week: How to Choose a PIN https://firewallsdontstopdragons.com/how-to-choose-a-pin/ Further Info Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:34: Update Apple devices, Chrome 0:01:16: A note on supporting Firefox 0:03:48: News preview 0:07:00: MediSecure hit by large-scale data breach 0:09:01: CISA Warns of Actively Exploited D-Link Router Vulnerabilities 0:13:14: How I upgraded my water heater and discovered how bad smart home security can be 0:19:46: Dell API abused to steal 49 million customer records 0:23:11: 53,000 Nissan Employees’ Social Security Numbers Exposed 0:27:06: New Cuckoo macOS malware can take over all Macs and steal your passwords 0:32:41: Ascension Healthcare Suffers Major Cyberattack 0:35:22: Proton Mail Discloses User Data Leading to Arrest in Spain 0:43:35: Novel attack against virtually all VPN apps neuters their entire purpose 0:47:28: Mullvad: Evaluating the impact of TunnelVision 0:55:48: Vermont & Maryland Pass Data Privacy Laws 0:58:27: Here’s how the new Cross-Platform Tracking Detection works 1:01:50: Tip of the Week: How to Choose a PIN 1:10:12: Looking ahead

May 20, 20241h 11m

Inside Ukraine’s IT Army

Russia has been hacking Ukraine for at least a decade now, but since the invasion of Ukraine in February of 2022, the cyber war has changed. Instead of being a tactical element, cyber war is now a full-fledged strategic aspect of the conflict, on both sides. At the outset, Ukraine put out an official call to enlist cyber warriors from around the globe to their cause in what’s been called the IT Army of Ukraine. Today we’ll look at how this group was formed, how it operates, and what we should all be learning from what’s happening there. My guest is Dina Temple-Raston from The Record, the Click Here Podcast, and formerly NPR. Interview Notes Dina Temple-Raston at The Record: https://therecord.media/author/dina-temple-raston  Click Here podcast: https://therecord.media/podcast  Click Here, Episode 98: “Lessons from the world’s first hybrid war”: https://podcasts.apple.com/us/podcast/click-here/id1225077306?i=1000639045741  NPR’s I’ll Be Seeing You: https://www.npr.org/series/760566025/ill-be-seeing-you  Operation Glowing Symphony: https://www.npr.org/2019/09/26/763545811/how-the-u-s-hacked-isis  Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:04:50: How did you get into covering cybersecurity and cyber warfare? 0:06:48: When and how did Russian cyber attacks begin in Ukraine? 0:15:40: What is the IT Army of Ukraine and what is its origin? 0:20:47: Have we seen other cyberwar volunteer organizations? 0:23:05: How are information and communications being utilized by the IT Army? 0:26:53: How has Russia responded to this? 0:28:34: How are IT Army members recruited and vetted? 0:30:17: How are objectives coordinated? 0:31:20: Where are IT Army members coming from? 0:32:03: Do we know if Western military members are participating in the IT Army? 0:36:30: What are the military lessons to be learned here? 0:42:11: What should civilians be learning from all of this? 0:46:01: What’s next for you and Click Here? 0:47:14: Wrap-up and looking ahead

May 13, 202449 min

Please Quit Chrome

Google’s Chrome browser has dominated the planet – both on desktop computers and mobile devices. Furthermore, many other popular web browsers are actually based on the same Google-made Chromium browser engine, including Microsoft Edge and Brave Browser. This gives Google an inordinate amount of influence on web standards, in particular preventing better privacy protections. We need to support privacy-forward alternatives lest they disappear. In other news: US passes expanded mass surveillance policies instead of curbing them; TikTok ban bill becomes law giving Bytedance a year to sell it; UK’s Investigatory Powers Bill amendment passes; photo-sharing app will use users’ uploaded images to train AI; Health insurers Kaiser and Change Healthcare are hacked; antivirus software service installs malware on user’s systems; FCC fines telecom’s $200M; CISA director pushes for vendor accountability; CISA’s proactive protection programs are making positive impacts; UK becomes first country to enforce strong and strict IoT security requirements; net neutrality is back; Google again delays killing third party cookies. Article Links [Electronic Frontier Foundation] U.S. Senate and Biden Administration Shamefully Renew and Expand FISA Section 702, Ushering in a Two Year Expansion of Unconstitutional Mass Surveillance https://www.eff.org/deeplinks/2024/04/us-senate-and-biden-administration-shamefully-renew-and-expand-fisa-section-702-0 [TechCrunch] Biden signs bill that would ban TikTok if ByteDance fails to sell the app https://techcrunch.com/2024/04/24/biden-signs-bill-that-would-ban-tiktok-if-bytedance-fails-to-sell-the-app/ [theregister.com] UK’s Investigatory Powers Bill to become law despite tech world opposition https://www.theregister.com/2024/04/26/investigatory_powers_bill/ [TechCrunch] Photo-sharing community EyeEm will license users photos to train AI if they don’t delete them https://techcrunch.com/2024/04/26/photo-sharing-community-eyeem-will-license-users-photos-to-train-ai-if-they-dont-delete-them/ [TechCrunch] Health insurance giant Kaiser notifies millions of a data breach https://techcrunch.com/2024/04/25/kaiser-permanente-health-plan-millions-data-breach/ [TechCrunch] Change Healthcare hackers broke in using stolen credentials — and no MFA, says UHG CEO https://techcrunch.com/2024/04/30/uhg-change-healthcare-ransomware-compromised-credentials-mfa/ [Ars Technica] Hackers infect users of antivirus service that delivered updates over HTTP https://arstechnica.com/security/2024/04/hackers-infect-users-of-antivirus-service-that-delivered-updates-over-http/ [BleepingComputer] FCC fines carriers $200 million for illegally sharing user location https://www.bleepingcomputer.com/news/technology/fcc-fines-carriers-200-million-for-illegally-sharing-user-location/ [cybersecuritydive.com] CISA director pushes for vendor accountability and less emphasis on victims’ errors https://www.cybersecuritydive.com/news/cisa-highlights-vendors-errors/714300/ [therecord.media] More than 800 vulnerabilities resolved through CISA ransomware notification pilot https://therecord.media/vulnerabilities-resolved-through-cisa-pilot [therecord.media] UK becomes first country to ban default bad passwords on IoT devices https://therecord.media/united-kingdom-bans-defalt-passwords-iot-devices [WIRED] Net Neutrality Returns to a Very Different Internet https://www.wired.com/story/fcc-net-neutrality-rules-vote/ [Ars Technica] Google delays third-party cookie death again: Now scheduled for 2025 https://arstechnica.com/gadgets/2024/04/google-delays-third-party-cookie-death-again-now-scheduled-for-2025/ Tip of the Week: https://firewallsdontstopdragons.com/its-time-to-quit-chrome/ Further Info Under New Management plugin: https://github.com/classvsoftware/under-new-management Donate to Mozilla (Firefox): https://foundation.mozilla.org/en/donate/ Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:29: Updates on previous stories 0:02:38: Newsletter DMARC fixed 0:03:34: News preview 0:07:05: U.S. Shamefully Renews and Expands FISA Section 702 0:14:03: Biden signs bill that would ban TikTok if ByteDance fails to sell 0:16:36: UK’s Investigatory Powers Bill to become law 0:20:29: EyeEm will license users photos to train AI if they don’t delete them 0:27:46: Health insurance giant Kaiser notifies millions of a data breach 0:30:42: Change Healthcare hackers broke in using stolen credentials 0:34:42: Hackers in

May 6, 20241h 12m

The Rise of CBDC

AI has been grabbing all the tech headlines, but cryptocurrency is still innovating and changing. One of the primary goals of cryptocurrency was to be decentralized and therefore not controlled by governments like fiat currency. That is about to change. Central Bank Digital Currency (CBDC) is a new type of cryptocurrency that is created and governed by nation states, which comes with serious implications for privacy and global economics. Thankfully I’ve got cryptocurrency expert Seth for Privacy on the show to explain how CBDC works and how it will affect us. Interview Notes Opt Out Podcast: https://optoutpod.com/  Freedom.Tech: https://freedom.tech/  Foundation.xyz: https://foundation.xyz/  CBDC tracker: https://cbdctracker.hrf.org/home Buying Monero: https://freedom.tech/buying-monero-privately/ Samourai Wallet 1: https://freedom.tech/how-samourai-worked/  Samourai Wallet 2: https://freedom.tech/samourai-to-sparrow/ Cryptocurrency 101 interview: https://podcast.firewallsdontstopdragons.com/2022/06/06/cryptocurrency-101/  Further Info Treasure & Coin Promo: https://fdsd.me/promo424  Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:30: Promo update 0:01:42: News preview 0:04:34: AT&T now says over 50M accounts were compromised 0:11:37: Apple password reset notification attack 0:16:04: Outlook is Microsoft’s new data collection service 0:22:40: Kobold letters 0:29:27: Backdoor in XZ Utils That Almost Happene 0:39:42: OpenAI and Google reportedly used transcriptions of YouTube videos to train their AI models 0:45:57: How to Turn Off Meta AI on their various apps 0:49:07: Vulnerabilities Identified in LG WebOS 0:52:14: Roku Says More Than 500,000 Accounts Were Compromised 0:56:05: X May Charge New Users a ‘Small Fee’ to Post, Like and Reply 1:00:04: DuckDuckGo Is Taking Its Privacy Fight to Data Brokers 1:04:19: Google Launches Android Find My Device Network 1:07:29: The CFPB wants to rein in data brokers 1:12:23: Tip of the Week: Freeze Your Credit 1:18:05: Wrap-up 1:19:06: Looking ahead

Apr 29, 20241h 8m

Just Do It: Freeze Your Credit

You’ve heard people like me recommend this for years. It’s time to just do it: freeze your credit report. There are really no downsides at this point. For example, it’s now free everywhere in the US, by law. It’s also free to temporarily “thaw” your credit. And it’s gotten a lot easier to do, too. Freezing your credit is your main defense against financial identity theft. And with the sheer number of data breaches (like the recent massive AT&T leak), the personal information needed to commit identity theft is out there already. In other news: AT&T now says 51 million past and current customers’ data were leaked; beware of a new password reset ‘bomb’ campaign; Microsoft is using Outlook to harvest and share your data; a new email scam alters their content after forwarding; a devious and devastating supply chain attack was thwarted in the nick of time; AI organizations are using sneaky techniques to train their models on your data; Meta is lacing its apps with AI, and there’s not much you can do about it; LG TVs are hacked; Roku is breached again, this time affecting over 500,000 accounts; Twitter/X looking to charge new users a small fee to try to curb bot accounts; DuckDuckGo unveils trio of new for-pay privacy services; Google launches their own Find My network; and various US government agencies, lacking a real privacy law, attempt to curb privacy abuses using existing powers. Article Links [BleepingComputer] AT&T now says data breach impacted 51 million customers https://www.bleepingcomputer.com/news/security/att-now-says-data-breach-impacted-51-million-customers/ [AppleInsider] If you’re getting dozens of password reset notifications, you’re being attacked https://appleinsider.com/articles/24/03/27/if-youre-getting-dozens-of-password-reset-notifications-youre-being-attacked [proton.me] Outlook is Microsoft’s new data collection service https://proton.me/blog/outlook-is-microsofts-new-data-collection-service [Lutra Security] Kobold letters https://lutrasecurity.com/en/articles/kobold-letters/ [Schneier Blog] Backdoor in XZ Utils That Almost Happened https://www.schneier.com/blog/archives/2024/04/backdoor-in-xz-utils-that-almost-happened.html [Engadget] OpenAI and Google reportedly used transcriptions of YouTube videos to train their AI models https://www.engadget.com/openai-and-google-reportedly-used-transcriptions-of-youtube-videos-to-train-their-ai-models-163531073.html [Lifehacker] How to Turn Off Meta AI on Facebook, Instagram, Messenger, and WhatsApp https://lifehacker.com/tech/how-to-turn-off-meta-ai-on-facebook-instagram-messenger-whatsapp [bitdefender.com] Vulnerabilities Identified in LG WebOS https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/ [Lifehacker] Roku Says More Than 500,000 Accounts Were Compromised in a Cyberattack https://lifehacker.com/tech/roku-cyberattack-compromises-accounts [MacRumors] X May Charge New Users a ‘Small Fee’ to Post, Like and Reply https://www.macrumors.com/2024/04/15/x-small-fee-new-users/ [WIRED] DuckDuckGo Is Taking Its Privacy Fight to Data Brokers https://www.wired.com/story/duckduckgo-vpn-data-removal-tool-privacy-pro/ [MacRumors] Google Launches Android Find My Device Network https://www.macrumors.com/2024/04/08/google-android-find-my-device-network-2/ [ftc.gov] Proposed FTC Order will Prohibit Telehealth Firm from Using or Disclosing Sensitive Data for Advertising Purposes https://www.ftc.gov/news-events/news/press-releases/2024/04/proposed-ftc-order-will-prohibit-telehealth-firm-cerebral-using-or-disclosing-sensitive-data [The Verge] The CFPB wants to rein in data brokers https://www.theverge.com/2024/4/15/24131354/cfpb-data-brokers-fair-credit-reporting-act [therecord.media] Automakers and FCC square off over potential regulations for connected cars https://therecord.media/fcc-automakers-connected-cars-regulation-mvnos Tip of the Week: https://firewallsdontstopdragons.com/credit-freeze-now-is-the-time/  Further Info Treasure & Coin Promo: https://fdsd.me/promo424  Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:30: Promo update 0:01:42: News preview 0:04:34: AT&T now says over 50M accounts were compromised 0:11:37: Apple password reset notification attack 0:16:04: Outlook is Microsoft’s new data collection service 0:22:40: Kobold letters 0:29:27: Backdoor in XZ Utils That Almost Happene 0:39:42: OpenAI and Google reportedly used transcriptions of

Apr 22, 20241h 20m

Protecting Kids Online

There’s a lot of nasty stuff online – things we would prefer our kids not see, at least not until they’re mature enough to handle it. Our elected representatives have proposed various regulations to try to protect kids online, and while this is obviously a laudable goal, the devil is always in the details. Many of the proposed solutions have serious negative consequences for both kids and adults, chilling free speech and blocking useful content. I’ll discuss the latest iteration of these proposed solutions in the US called the Kids Online Safety Act (KOSA) as well as the similar Online Safety Act in the UK. With me is Joe Mullin, senior policy analyst at the Electronic Frontier Foundation (EFF). Interview Notes Joe Mullin (EFF): https://www.eff.org/about/staff/joe-mullin EFF on KOSA: https://www.eff.org/deeplinks/2024/02/dont-fall-latest-changes-dangerous-kids-online-safety-act EFF on KOSA in depth: https://www.eff.org/deeplinks/2024/03/analyzing-kosas-constitutional-problems-depth Contact Congress: https://www.eff.org/congress EFF on CA ballot initiative: https://www.eff.org/deeplinks/2024/02/eff-opposes-california-initiative-would-cause-mass-censorship EFF submission to Ofcom: https://www.eff.org/deeplinks/2024/03/effs-submission-ofcoms-consultation-illegal-harms Santa Clara Principles for online content moderation: https://santaclaraprinciples.org/ Further Info Treasure & Coin Promo: https://fdsd.me/promo424 Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:56: Eclipse! 0:01:50: Treasure & Coin promo update 0:02:29: Interview preview 0:03:41: What are the primary concerns today with kids on the internet? 0:08:24: What laws already exist to protect kids online? 0:17:05: What are the key provisions of KOSA? 0:25:04: What content is KOSA trying to restrict based on age? 0:34:22: What did we learn from the UK’s Online Safety Act? 0:38:47: Doesn’t KOSA interfere with Section 230? 0:44:41: How does KOSA impact content access for adults? 0:50:17: Are our representatives seeking insights from groups like EFF? 0:54:58: Are there onlione safety regulations EFF could support? 0:58:55: Do you have any advice for parents on protecting their kids online? 1:06:55: Interview wrap-up 1:08:59: Patron bonus content 1:09:28: Looking ahead

Apr 15, 20241h 10m

Answering Listener Questions

Today I answer some of the most interesting listener questions from the past several months, including: how to do you get SMS 2FA codes while traveling abroad; should I periodically change all my passwords; how do hackers attack IoT devices inside my home network; can a website fingerprint me based on a hardware security key; can you recommend an email client that protects your privacy; if I give my IoT device permission to see my local network, does that include the guest network; how to hackers find vulnerabilities and figure out how to attack them; why can’t I use my VPN on an airplane to stream Netflix; how can I protect my cryptocurrency and smartphone. Also, I give my take on the crazy TikTok ban legislation. Links New Year’s Resolutions for 2024: https://firewallsdontstopdragons.com/new-years-resolutions-for-2024/  GRC’s Shields Up! Tool: https://www.grc.com/shieldsup  Secure your home network: https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/ My Take on TikTok Ban: https://firewallsdontstopdragons.com/my-take-on-tiktok-ban/ The TikTok Situation is a Mess: https://lifehacker.com/tech/the-tiktok-situation-is-a-mess  EFF on TikTok: https://www.eff.org/deeplinks/2024/03/5-big-unanswered-questions-about-tiktok-bill   The US Wants to Ban TikTok: https://www.404media.co/the-u-s-wants-to-ban-tiktok-for-the-sins-of-every-social-media-company/ Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:38: Couple quick updates 0:02:37: Getting SMS 2FA codes while traveling abroad 0:07:37: Should I periodically change all my passwords? 0:13:23: How do hackers attack IoT devices inside my home network? 0:19:10: Can a website fingerprint me based on a hardware security key? 0:24:42: Can you recommend an email client that protects your privacy? 0:29:30: If I give my IoT device permission to see my local network, does that include the guest network? 0:33:18: How to hackers find vulnerabilities and figure out how to attack them? 0:37:35: Why can’t I use my VPN on an airplane to stream Netflix? 0:43:57: How can I protect my cryptocurrency and smartphone? 0:50:05: AT&T breach update 0:50:56: My Take on TikTok 0:57:28: Wrap-up

Apr 8, 202458 min

He Said She Said

Today I talk with Justin and Jodi Daniels about that state of privacy today, how we can help consumers and companies better understand the importance of privacy and security, and how companies are dealing with these aspects internally. We talk about the state of privacy regulations (or the lack thereof), why companies are failing to protect their customers, and what we can do about that. Justin and Jodi host a podcast together called She Said Privacy, He Said Security. They’ve also co-written a book called “Data Reimagined: Building trust one byte at a time”. Interview Notes Justin & Jodi Daniels’ podcast: https://redcloveradvisors.com/podcasts/ Justin Daniels: https://www.linkedin.com/in/justinsdaniels/ Jodi Daniels: https://www.linkedin.com/in/jodihoffmandaniels/  Red Clover Advisors: https://redcloveradvisors.com/ Baker Donelson: https://www.bakerdonelson.com/ Data Reimagined book: https://redcloveradvisors.com/book-sales/  International Association of Privacy Professionals (IAPP): https://iapp.org/  Information Commissioner’s Office (ICO): https://ico.org.uk/  YourAdChoices (AboutAds.info): https://youradchoices.com/  How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/  Jeff Jockisch top 10: https://www.linkedin.com/posts/jozian_privacypodcast-peopleschoice-privacyawards-activity-7155591864593637376-Q3bi/  Further Info Coin & Treasure Promo: https://fdsd.me/promo424 Send me your questions: https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:33: Interview setup 0:03:31: Tell me about your podcast and how you got into this space. 0:06:40: How do you explain privacy to regular, everyday people? 0:09:37: How can we help people better understand the need for privacy? 0:11:10: What are the newest threats to our privacy? 0:14:58: So how do we know what to trust? 0:17:07: What mistakes do companies make when crafting and implementing privacy policies? 0:21:37: How should companies embrace privacy? 0:25:51: What’s life like for a Chief Privacy Officer today? 0:30:22: Can we blame companies for monetizing our data since it’s legal to do so? 0:34:01: How do we combat privacy problems with security tech? 0:37:11: Why can’t the US government pass a federal privacy law? 0:42:54: Would it help to pass laws that mandate transparency? 0:46:11: What about a universal opt-out mechanism? 0:47:24: Is mainstream media covering privacy and security properly? 0:49:36: What are some promising Privacy Enhancing Technologies? 0:53:50: What are some of your top resources to learn more about privacy? 0:56:09: Any final thoughts? 0:57:30: Interview follow-up 0:59:25: Looking ahead

Apr 1, 20241h 0m

Account Security is Broken

Passwords, two-factor authentication and even passkeys don’t matter if you can access someone’s account by answering three simple account recovery questions. Also, just about every account today has a way to reset your password, no matter how strong it is, if you can gain access to someone’s email account. Until we can remove these weak links, it doesn’t matter how secure our regular authentication schemes are. In the news: old A&T breach data is making the rounds; Apple Silicon chips have a security flaw baked into the hardware; two very popular digital safe locks come with backdoor codes; Twitter/X is failing to properly check posted links that redirect to scam sites; a court rules that external continuous camera surveillance of your house doesn’t require a warrant; searches for VPNs spike after PornHub pulls out of Texas; a blockbuster NY Times article brings much needed attention to data collection in cars; AirBnB implements a blanket camera ban. And I announce a killer new patron promotion! Click this link! https://fdsd.me/promo424 Article Links [restoreprivacy.com] AT&T Investigating Potential Breach Following Leak of 73.4 Million Records https://restoreprivacy.com/att-investigating-breach-following-leak-of-73-4-million-records/ HaveIBeenPwned.com: https://haveibeenpwned.com/  [9to5Mac] Unpatchable security flaw in Apple Silicon Macs breaks encryption https://9to5mac.com/2024/03/22/unpatchable-security-flaw-mac/ [404media.co] Massively Popular Safe Locks Have Secret Backdoor Codes https://www.404media.co/massively-popular-safe-locks-have-secret-backdoor-codes/ [Lifehacker] It’s Not Safe to Click Links on X https://lifehacker.com/tech/its-not-safe-to-click-links-on-x [Gizmodo] The Feds Can Film Your Front Porch for 68 Days Without a Warrant, Says Court https://gizmodo.com/feds-can-film-your-front-porch-without-warrant-1851352414 [CNN] Searches for VPNs spike in Texas after Pornhub pulls out of the state https://www.cnn.com/2024/03/15/tech/vpn-searches-spike-texas-pornhub [The New York Times] Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies https://www.nytimes.com/2024/03/11/technology/carmakers-driver-tracking-insurance.html [Lifehacker] Airbnb’s New Security Camera Ban Is a Big Deal https://lifehacker.com/tech/airbnbs-new-security-camera-ban Tip of the Week: https://firewallsdontstopdragons.com/account-security-is-broken/ Further Info Become a Patron! (promo): https://fdsd.me/promo424  Lock & Code Podcast: https://www.malwarebytes.com/blog/podcast/2024/03/securing-your-home-network-is-long-tiresome-and-entirely-worth-it-with-carey-parker-lock-and-code-s05e07 Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:04:05: News preview 0:06:12: AT&T Investigating Potential Breach Following Leak of 73.4 Million Records 0:11:24: Unpatchable security flaw in Apple Silicon Macs breaks encryption 0:16:34: Massively Popular Safe Locks Have Secret Backdoor Codes 0:21:57: It’s Not Safe to Click Links on X 0:30:28: The Feds Can Film Your Front Porch for 68 Days Without a Warrant, Says Court 0:33:28: Searches for VPNs spike in Texas after Pornhub pulls out of the state 0:38:35: Automakers Are Sharing Consumers’ Driving Behavior With Insurance 0:47:36: Airbnb’s New Security Camera Ban Is a Big Deal 0:49:57: Tip of the Week: Account Security is Broken 0:55:49: Dragon Coin promotion details

Mar 25, 20241h 3m

Health Data Privacy

The United States has no general data privacy laws. However, we do have some sector-specific regulations, including HIPAA for health data. But there are many misconceptions about HIPAA. For example, the “P” in HIPAA does not stand for Privacy – it stands for Portability. So, what information does HIPAA cover? Which healthcare and related service providers are governed by HIPAA? And most importantly, what can you do to protect your medical and health data? Today we’ll dive deep into this subject with Kate Black, a data, privacy & health lawyer and a strategic advisor in the health data field. Interview Notes Kate Black: https://www.linkedin.com/in/kate-black-sfo/  Washington’s My Health, My Data law: https://hintzelaw.com/blog/2023/4/9/wa-my-health-my-data-act-pt1-overview  HIPAA rights: https://www.hhs.gov/hipaa/for-individuals/guidance-materials-for-consumers/index.html  STAT medical news: https://www.statnews.com/  Further Info Check out my dragon challenge coins! https://fdsd.me/coin2 Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/ Table of Contents Use these timestamps to jump to a particular section of the show. 0:03:29: What is covered by HIPAA? What isn’t covered? 0:06:51: Can I sign away my HIPAA rights? 0:08:08: Who in my medical provider’s office can access my data? 0:10:23: How audits HIPAA compliance? 0:11:47: How is my health data shared between providers? 0:14:49: Are certain types of health data treated differently? 0:15:23: How does health privacy work for minors? 0:16:53: Outside of health providers, who else can access my data? 0:20:56: How does HIPAA compare to other sector-specific privacy laws? 0:22:20: Do secondary providers share back with my primary care physician? 0:24:42: Who stores and protects my digital medical records? 0:27:46: How are third party providers audited for privacy and security? 0:29:56: Are HIPAA security requirements keeping up with the times? 0:33:13: Do I have full access to my complete medical record? 0:36:52: How do marketers get my health data? 0:39:51: What laws govern inferred health information? 0:45:48: Do pharmacies sell health data to marketers? 0:48:57: How private are online medical portals and checkin services? 0:53:35: How concerned should we be about using DNA analysis services? 0:59:17: How can we improve our health privacy laws? 1:00:30: What are your personal tips for protecting health data? 1:02:37: If I think someone has abused my data, what can I do? 1:04:13: Interview wrap-up 1:06:49: Looking ahead

Mar 18, 20241h 8m

Backing Up 2FA Seeds

Two-factor authentication (2FA) is a fantastic way to improve the security of your online accounts. However, if you lose access to the device containing your authenticator app, you may lose access to your 2FA-protected accounts. You need to backup the seed codes used to set up each account. I’ll give you several methods for doing this. In the news: FBI uses smartphone push notifications to track down criminals; Roku TVs block all access until users consent to force arbitration; cheap video doorbells have horrible security; AI can be used to determine where photos were taken; vending machine caught using facial recognition; what happens to your data when a data broker goes bankrupt; your personal information that is publicly available; New Jersey passes motor vehicle data deletion law; Proton Mail’s new email aliasing feature; in Canada, police now need warrant to get a person’s IP address; US cracks down on commercial spyware firm; NSO Group forced to hand over source code to Meta in legal case; Authy is shutting down its desktop app. Article Links [The Washington Post] The FBI’s new tactic: Catching suspects with push alerts https://www.washingtonpost.com/technology/2024/02/29/push-notification-surveillance-fbi/ [TechCrunch] Roku disables TVs and streaming devices until users consent to forced arbitration https://techcrunch.com/2024/03/05/roku-disables-tvs-and-streaming-devices-until-users-consent-to-forced-arbitration/ [Consumer Reports] These Video Doorbells Have Terrible Security https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/ [NPR] Artificial intelligence can find your location in photos, worrying privacy experts https://www.npr.org/2023/12/19/1219984002/artificial-intelligence-can-find-your-location-in-photos-worrying-privacy-expert [Ars Technica] Vending machine error reveals secret face image database of college students https://arstechnica.com/tech-policy/2024/02/vending-machine-error-reveals-secret-face-image-database-of-college-students/ [The Markup] What Happens to Your Sensitive Data When a Data Broker Goes Bankrupt? – The Markup https://themarkup.org/privacy/2024/02/23/what-happens-to-your-sensitive-data-when-a-data-broker-goes-bankrupt [Lifehacker] All of Your Information That’s Publicly Available (and What You Can Do About It) https://lifehacker.com/tech/all-your-information-thats-publicly-available-what-to-do-about-it [privacy4cars.com] “Motor Vehicle Data Deletion Act” of New Jersey https://privacy4cars.com/nj-law/ [Lifehacker] Proton Mail Now Lets You Hide Your Real Email Address https://lifehacker.com/tech/how-to-set-up-email-aliases-proton-mail [CBC] Police now need a warrant to get a person’s IP address, Supreme Court rules https://www.cbc.ca/news/politics/supreme-court-privacy-ipaddress-1.7130727 [The Hacker News] U.S. Cracks Down on Predatory Spyware Firm for Targeting Officials and Journalists https://thehackernews.com/2024/03/us-cracks-down-on-predatory-spyware.html [9to5Mac] iPhone spyware company NSO suffers major defeat in US court, in Meta lawsuit https://9to5mac.com/2024/03/01/iphone-spyware-company-nso-must-reveal-code/ [The Verge] Authy is shutting down its desktop app https://www.theverge.com/2024/1/8/24030477/authy-desktop-app-shutting-down Tip of the Week: Backing Up Your 2FA Seed Codes https://firewallsdontstopdragons.com/how-to-backup-2fa-seed-codes/ Command line tool to extract codes from Authy: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93 Further Info Check out my dragon challenge coins! https://fdsd.me/coin2  Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:55: Upcoming promotion 0:01:35: News rundown 0:04:15: The FBI’s new tactic: Catching suspects with push alerts 0:10:44: Roku disables TVs and streaming devices until users consent to forced arbitration 0:14:23: These Video Doorbells Have Terrible Security 0:20:34: Artificial intelligence can find your location in photos 0:25:47: Vending machine error reveals secret face image database 0:28:46: What Happens to Your Sensitive Data When a Data Broker Goes Bankrupt? 0:32:40: All of Your Information That’s Publicly Available 0:38:03: “Motor Vehicle Data Deletion Act” of New Jersey 0:40:17: Proton Mail Now Lets You Hide Your Real Email Address 0:44:09: Supreme Court of Canada: Police need warrant to get a person’s IP address 0:45:33: U.S. Cracks Down on Predatory Spyware Firm for Targeting O

Mar 11, 20241h 6m

How Our Data is Abused

With the rise of IoT and tracking technologies (both online and in the real word), we are generating staggering amounts of highly personal information. This massive trove of juicy data has drawn the attention of several interested parties outside the realm of consumer marketing. Like chum in the water, it’s created a feeding frenzy from data aggregators as well as from law enforcement and intelligence agencies, both foreign and domestic. The journalists at 404 Media have published several blockbuster articles on this data ecosystem which have triggered backlashes from lawmakers and consumers alike. Today I’ll speak with two of the founders: Joseph Cox and Jason Koebler. Interview Notes 404 Media: https://www.404media.co/  404 Media podcast: https://www.404media.co/the-404-media-podcast/ 404 Media support: https://www.404media.co/faq/  Formation of 404 Media: https://www.nytimes.com/2023/08/22/business/media/404-media-vice-motherboard.html  Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:03: Interview setup 0:02:45: How did 404 Media come to be? 0:12:00: When do we think law enforcement started buying our data? 0:15:39: What’s up with companies listening to our conversations? 0:23:01: Where does law enforcement go to get our data? 0:27:46: How are video feeds being gathered and sold? 0:34:23: Can’t all this data also be used by “bad guys”? 0:39:13: Is it legal for law enforcement to buy data from foreign sources? 0:44:28: Have your stories triggered responses from the US government? 0:50:01: Trust in media is low these days – how can we fix that? 0:59:37: How can we support good work like yours? 1:03:22: Wrap-up

Mar 4, 20241h 7m

Mitigating AI Risks

Artificial Intelligence is the buzzword of the day. Since the launch of ChatGPT in November 2022, there has been a flood of AI-based tools and services. Many tech firms are racing to build AI into their products without considering the consequences, let alone taking the time to build in guardrails for privacy and security. Today, I’ll tell you about some of the risks, how to mitigate them and explain why you should spend some time playing with AI tools so we can understand how they do (and don’t) work. In other news: Wyze home webcams had yet another security breach; Poland’s PM calls out illegal use of Pegasus spyware by opposition party; US military finally notifies 20,000 of email data breach; Skiff was bought by Notion and will shut down services; FTC fines Avast antivirus $16.5M for mining user data; Backdoors in encryption violate human rights according to EU court; LockBit ransomware servers were taken over by multinational law enforcement efforts; Apple’s iMessage gaining quantum computer resistant encryption; Signal finally allows users to hide cell phone numbers via usernames; new Android secure browsing features announced. Article Links [Lifehacker] Wyze Had a Security Breach (Again) https://lifehacker.com/tech/wyze-security-breach-again [The Associated Press] Poland’s prime minister says authorities widely used spyware under the previous government https://apnews.com/article/poland-government-pegasus-spyware-tusk-duda-78420fc7099401926d28b5be98669192 [TechCrunch] US military notifies 20,000 of data breach after cloud email leak https://techcrunch.com/2024/02/14/department-defense-data-breach-microsoft-cloud-email/ [The Cut] The Day I Put $50,000 in a Shoe Box and Handed It to a Stranger https://www.thecut.com/article/amazon-scam-call-ftc-arrest-warrants.html https://pluralistic.net/2024/02/05/cyber-dunning-kruger/  [restoreprivacy.com] Skiff Mail Shutting Down in 6 Months (Try These Alternatives) https://restoreprivacy.com/skiff-shutting-down-alternatives-to-skiff-mail/ [404media.co] FTC Fines Avast $16.5 Million For Selling Browsing Data Harvested by Antivirus https://www.404media.co/impact-ftc-fines-avast-16-5-million-for-selling-browsing-data-harvested-by-antivirus/ [Ars Technica] Backdoors that let cops decrypt messages violate human rights, EU court says https://arstechnica.com/tech-policy/2024/02/human-rights-court-takes-stand-against-weakening-of-end-to-end-encryption/ [Ars Technica] LockBit ransomware group taken down in multinational operation https://arstechnica.com/information-technology/2024/02/lockbit-ransomware-group-taken-down-in-multinational-operation/ [WIRED] Apple’s iMessage Is Getting Post-Quantum Encryption https://www.wired.com/story/apple-pq3-post-quantum-encryption/ [signal.org] Keep your phone number private with Signal usernames https://signal.org/blog/phone-number-privacy-usernames/ [Lifehacker] These New Android Features Will Keep You Safer Online https://lifehacker.com/tech/android-safer-browsing-and-live-threat-detection-rolling-out Tip of the Week: Mitigating AI Risks https://firewallsdontstopdragons.com/how-to-mitigate-the-risks-of-ai/ Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:44: AT&T outage, hot take 0:03:08: News rundown 0:04:44: Wyze Had a Security Breach (Again) 0:07:27: Poland’s PM says authorities used spyware under the previous government 0:10:19: US military notifies 20,000 of data breach after cloud email leak 0:13:50: The Day I Put $50,000 in a Shoe Box and Handed It to a Stranger 0:22:37: Skiff Mail Shutting Down in 6 Months 0:27:14: FTC Fines Avast $16.5 Million For Selling Browsing Data 0:32:20: Backdoors that let cops decrypt messages violate human rights, EU court says 0:36:18: LockBit ransomware group taken down in multinational operation 0:39:41: Apple’s iMessage Is Getting Post-Quantum Encryption 0:45:02: Keep your phone number private with Signal usernames 0:49:20: These New Android Features Will Keep You Safer Online 0:52:12: Tip of the Week: Mitigating AI Risks 1:04:25: Wrap up

Feb 26, 20241h 5m

Car Privacy is Horrid

Modern cars are chock full of sensors and connected to the internet via built-in cellular modems. That’s a recipe for massive data collection. Last September, Mozilla’s Privacy Not Included team released a blockbuster report how much data our cars were gathering and it was absolutely staggering. According to the hard-to-find privacy policies, your car can collect extremely personal information including precise location, contact lists from your phone, call and message data, and – believe it or not – even “sexual activity”. Today, I’ll walk through this report and its implications with the head of Mozilla’s Privacy Not Included project, Jen Caltrider. Interview Notes Mozilla’s Privacy Not Included: https://foundation.mozilla.org/en/privacynotincluded/  Mozilla’s car report: https://foundation.mozilla.org/en/privacynotincluded/articles/its-official-cars-are-the-worst-product-category-we-have-ever-reviewed-for-privacy/ Mozilla’s report on AI chatbots: https://foundation.mozilla.org/en/privacynotincluded/articles/happy-valentines-day-romantic-ai-chatbots-dont-have-your-privacy-at-heart/ Donate to Mozilla Foundation: https://donate.mozilla.org/  Mozilla layoffs: https://techcrunch.com/2024/02/13/mozilla-downsizes-as-it-refocuses-on-firefox-and-ai-read-the-memo/ Sign the petition to stop car data gathering! https://foundation.mozilla.org/en/privacynotincluded/articles/car-companies-stop-your-huge-data-collection-programs-en/  Bruce Schneier article in Slate: https://slate.com/technology/2023/12/ai-mass-spying-internet-surveillance.html  Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Send me your questions! https://fdsd.me/qna  Support our mission! https://fdsd.me/support  Subscribe to the newsletter: https://fdsd.me/newsletter  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Table of Contents Use these timestamps to jump to a particular section of the show. 0:02:39: What were some top finding from your car privacy report? 0:05:14: Which cars did you review and how did you evaluate them? 0:09:44: How was I notified and how did I consent to my car’s privacy policy? 0:10:39: What are cars tracking? Are electric cars any worse than gas cars? 0:13:55: What third party data mining is going on in my car? 0:20:41: Is there a way to opt out of data sharing? 0:24:10: Is less data collected in Europe? 0:26:02: Where is all my data stored? Locally, in the cloud, or both? 0:28:52: Is the data at least secured? 0:29:48: Can dealerships access my data? What about law enforcement? 0:32:28: What about rental or fleet cars? What about passengers? 0:37:24: Do car dealers disclose this data collection to shoppers? 0:39:11: What are some of the security problems with this data collection? 0:45:55: How did car makers and legislators respond to your report? 0:48:36: Do modern privacy laws cover auto data? 0:50:48: So what can we do about this today? 0:54:30: What will Privacy Not Included tackle next? 0:58:40: Wrap-up

Feb 19, 20241h 4m

Avoiding Tax Scams

It’s tax time here again in the USA, and therefore it’s also time for tax scams. I’ll explain how to recognize common tax scams, how to respond to them, how to prevent scammers from taking over your IRS account and even filing fraudulent tax returns in your name. In other news: the Mother of All Breaches (MOAB) contains 26 billion records; 23andMe is in trouble after massive data breach and pending class action lawsuits; a viral story about a smart toothbrush botnet isn’t true… but could have been; a clever hack of older computer TPM modules could expose encrypted hard drive data (but it’s not easy to do); Malwarebytes has issued their 2024 malware report; the FBI and CISA are raising the alarm over Chinese hackers and key US infrastructure, as well as taking action to prevent it; you might want to consider creating a family password to defeat voice clone scams; Mozilla has released a new data deletion service; and Privacy4Cars has an interesting new mechanism for universally opting out of data collection. Article Links [cybernews] Mother of all breaches reveals 26 billion records https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/ [Fast Company] 23andMe at risk of being delisted from the Nasdaq as lawsuits mount https://www.fastcompany.com/91020738/23andme-risk-delisted-nasdaq-class-action-lawsuits [404media.co] The Viral Smart Toothbrush Botnet Story Almost Certainly Isn’t Real https://www.404media.co/the-viral-toothbrush-ddos-botnet-story-almost-certainly-isnt-real/ [Tom’s Hardware] YouTuber breaks BitLocker encryption in less than 43 seconds with sub-$10 Raspberry Pi Pico https://www.tomshardware.com/pc-components/cpus/youtuber-breaks-bitlocker-encryption-in-less-than-43-seconds-with-sub-dollar10-raspberry-pi-pico [9to5Mac] Report: Mac security threats on the rise, here’s what to watch out for https://9to5mac.com/2024/02/06/report-mac-security-threats-on-the-rise/ [NBC News] FBI director to warn Chinese hackers aim to ‘wreak havoc’ on US critical infrastructure https://www.nbcnews.com/politics/national-security/fbi-director-warn-chinese-hackers-aim-wreak-havoc-us-critical-infrastr-rcna136524 [Ars Technica] Chinese malware removed from SOHO routers after FBI issues covert commands https://arstechnica.com/security/2024/01/chinese-malware-removed-from-soho-routers-after-fbi-issues-covert-commands/ [cisa.gov] CISA and FBI Release Secure by Design Alert Urging Manufacturers to Eliminate Defects in SOHO Routers https://www.cisa.gov/news-events/alerts/2024/01/31/cisa-and-fbi-release-secure-design-alert-urging-manufacturers-eliminate-defects-soho-routers [9to5Mac] FCC outlaws voice cloning robocalls after AI-generated voice claimed to be President Biden https://9to5mac.com/2024/02/08/voice-cloning-robocalls/ [Electronic Frontier Foundation] Worried about AI voice clone scams? Create a family password https://www.eff.org/deeplinks/2024/01/worried-about-ai-voice-clone-scams-create-family-password  [The Verge] Firefox maker Mozilla has a new subscription to keep your info out of data brokers’ clutches https://www.theverge.com/2024/2/6/24062765/mozilla-monitor-plus-firefox-paid-subscription-privacy-data-broker-removal-requests [optoutcode.com] A Privacy4Cars Universal Opt-Out Concept https://optoutcode.com/ Tip of the Week: Avoiding Tax Scams https://firewallsdontstopdragons.com/how-to-avoid-tax-scams/ Further Info Secure Your Network: https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/  Davos speech, original: https://www.youtube.com/watch?v=fJoEPRQMBuY  Davos speech, translated: https://www.youtube.com/live/6Fwv9Cek2F4?feature=shared&t=98 How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/  How to send files securely: https://firewallsdontstopdragons.com/how-to-send-files-securely-like-tax-info/  Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:57: News rundown 0:04:04: Mother of all breaches reveals 26 billion records 0:07:36: 23andMe at risk of being delisted from the Nasdaq as lawsuits mount 0:10:20: Viral Smart Toothbrush Botnet Story Isn’t Real 0:13:22: YouTuber breaks BitLocker encryption in less than 43 seconds with sub-$10 Raspberry Pi Pico 0:18:31: Mac security threats on the rise 0:22:27: FBI director to warn Chinese hackers aim to ‘wreak havoc’ on US critical infrastructure 0:23:55: Chinese malware removed from SOHO routers after FBI issues covert commands 0:29:48: CI

Feb 12, 202453 min

Securing Your Mac

Are Macs really safer than PCs? What should you do to make your Mac more secure? How do you know if your Mac has a virus? And how do you know which security apps you can trust? I’ll dig into all of these questions and more today with Mac security guru Patrick Wardle. Patrick Wardle is the founder of the Objective-See Foundation. Having worked at NASA and the NSA, as well as presented at countless security conferences Patrick is passionate about all things related to macOS security, writing books on macOS malware, and releasing free open-source security tools to protect Mac users. Interview Notes Objective See (free Mac tools): https://objective-see.org/  The Art of Mac Malware (book): https://taomm.org/ Objective by the Sea conference: https://objectivebythesea.org/  Apple’s Malware protections: https://support.apple.com/guide/security/protecting-against-malware-sec469d47bd8/1/web/1  Reinstall macOS in Recovery Mode: https://support.apple.com/en-us/HT204904  Jamf presentation on Apple anti-malware tools: https://www.jamf.com/resources/videos/a-closer-look-at-macos-built-in-security-tools/  Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Send me your questions! https://fdsd.me/qna  Support our mission! https://fdsd.me/support  Subscribe to the newsletter: https://fdsd.me/newsletter  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:45: Interview setup 0:04:06: What have you been up to since we last had you on the show? 0:13:40: Are Macs safer than PCs? 0:17:34: How effective are modern antivirus programs? 0:22:25: Which are the better AV software programs? 0:24:45: Tell us about the Mac security apps that you created 0:27:53: How does Lulu differ from a regular firewall? 0:32:00: How do you know which security software you can trust? 0:38:00: How do we combat security fatigue? 0:43:22: Does the Apple App Store protect me from bad apps? 0:52:09: What’s your take on Apple’s new Lockdown Mode? 0:53:34: How do I know if my computer is infected with malware? 0:58:03: What should I do to protect my brand new Mac? 1:01:23: What worries you most right now? What gives you hope? 1:04:43: What’s next for you? 1:10:31: Wrap-up

Feb 5, 20241h 13m

Data Privacy Week 2024

While every week is Data Privacy Week here at Firewalls Don’t Stop Dragons, the rest of the world stops to join us in focusing on how and why to protect your personal data. I’ll give you some of my top privacy tips and refer you to a lot of top privacy resources. In the news: Microsoft executives’ emails are hacked by a nation-state actor; Facebook is gathering even more data with the help of other companies; a company is using real-time bidding to track us and sell to intelligence agencies; Mozilla outlines how incumbent browser owners tilt the playing field in favor of the owner; the EU is driving major changes to how iOS will work (but only in the EU); Brave browser simplifies its anti-fingerprinting options; Facebook limits how adult strangers can DM minors; FTC brings actions against GoodRx and Intuit; Samsung matches Google’s 7-year OS update update promise; and Apple rolls out Stolen Device Protection feature. Article Links [msrc.microsoft.com] Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/ [Consumer Reports] Each Facebook User Is Monitored by Thousands of Companies https://www.consumerreports.org/electronics/privacy/each-facebook-user-is-monitored-by-thousands-of-companies-a5824207467/ [404media.co] Inside a Global Phone Spy Tool Monitoring Billions https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/ [Mozilla] Platform Tilt: Documenting the Uneven Playing Field for an Independent Browser Like Firefox https://blog.mozilla.org/netpolicy/2024/01/19/platform-tilt [MacRumors] Here Are All the iPhone Changes Coming to EU Users by March 6 https://www.macrumors.com/2024/01/26/iphone-changes-coming-to-eu-users/ [brave.com] Brave browser simplifies its fingerprinting protections https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/ [9to5Mac] Adult strangers won’t be able to send DMs to teens on Instagram or Facebook https://9to5mac.com/2024/01/25/teens-on-instagram-safeguards/ [ftc.gov] FTC Statement on Intuit TurboTax Case https://www.ftc.gov/news-events/news/press-releases/2024/01/statement-samuel-levine-director-ftc-bureau-consumer-protection-regarding-commissions-order-opinion [ftc.gov] FTC Enforcement Action to Bar GoodRx from Sharing Consumers’ Sensitive Health Info for Advertising https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising [9to5Google] Samsung Galaxy S24 follows Google Pixel 8’s lead with 7 years of Android updates https://9to5google.com/2024/01/17/samsung-galaxy-s24-android-updates-policy/ [AppleInsider] How to use Stolen Device Protection https://appleinsider.com/articles/24/01/23/how-to-use-stolen-device-protection Tip of the Week: Data Privacy Checklist https://fdsd.me/dpc  Further Info Carey’s Data Privacy Checklist (just updated!): https://fdsd.me/dpc  Proton’s mention: https://www.linkedin.com/posts/protonprivacy_protonprivacyreadinglist-activity-7155246272273170432-XlM0 Jeff Jockisch’s Best Privacy Podcast results: https://www.linkedin.com/posts/jozian_privacypodcast-peopleschoice-privacyawards-activity-7146196804940820481-yB-P Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:29: Recent accolades 0:03:09: News preview 0:05:14: Microsoft’s Midnight Blizzard attack 0:08:48: Each Facebook User Is Monitored by Thousands of Companies 0:16:06: Inside a Global Phone Spy Tool Monitoring Billions 0:23:38: Platform Tilt: Documenting the Uneven Playing Field for Independent Browsers 0:29:25: iPhone Changes Coming to EU Users by March 6 0:38:09: Brave browser simplifies its fingerprinting protections 0:45:53: Adult strangers won’t be able to send DMs to teens on Instagram or Facebook 0:47:46: FTC Statement on Intuit TurboTax Case 0:50:54: FTC Enforcement Action to Bar GoodRx from Sharing Sensitive Health Info for Ads 0:54:45: Samsung Galaxy S24 follows Google Pixel 8’s lead with 7 years of Android updates 0:57:24: How to use Apple’s Stolen Device Protection 1:03:37: Tip of the Week: Data Privacy Checklist 1:06:10: Wrap up

Jan 29, 20241h 7m

Rise of the Slaughterbots

Drones are everywhere today. Cheap and tiny accelerometers, gyroscopes and processors have allowed us to create drones that anyone can afford and everyone can fly. Drones have been used by law enforcement and military forces, as well – for surveillance but also for killing. With the rapid development of AI technologies, what happens when we make these drones autonomous? What are the implications for privacy and security? I’ll discuss this and more with Nick Weaver, computer and cybersecurity expert, and chief mad scientist at Skerry Technologies. Interview Notes Nick Weaver: https://www1.icsi.berkeley.edu/~nweaver/  NYPD drone use: https://www.washingtonpost.com/nation/2023/09/01/drones-labor-day-parties-new-york/  AI drone “kills” its operator: https://www.reuters.com/article/factcheck-ai-drone-kills/fact-check-simulation-of-ai-drone-killing-its-human-operator-was-hypothetical-air-force-says-idUSL1N38023R/  The Future of Drone Warfare: https://www.schneier.com/blog/archives/2023/10/the-future-of-drone-warfare.html Betaflight: https://github.com/betaflight/betaflight Ardupilot: https://github.com/ArduPilot/ardupilot PX4: https://github.com/PX4/PX4-Autopilot  Small Business Innovation Research: https://www.sbir.gov/  Further Info Data Privacy Week: https://staysafeonline.org/programs/data-privacy-week/  Carey’s Data Privacy Checklist (just updated!): https://fdsd.me/dpc  Nominate someone for a challenge coin: https://fdsd.me/quest  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Send me your questions! https://fdsd.me/qna  Support our mission! https://fdsd.me/support  Subscribe to the newsletter: https://fdsd.me/newsletter  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:21: Data Privacy Week teaser 0:01:11: Apple backdoor clarification 0:03:14: Interview setup 0:07:15: What first got you interested in autonomous drone technology? 0:10:27: What technologies have enabled the explosion of cheap drones? 0:15:22: What are the capabilities of modern consumer drones? 0:17:54: Are there any legal restrictions on flying drones? 0:20:44: Are there privacy laws around drone surveillance? 0:22:24: How are drones used by law enforcement? 0:25:14: How are drones being used for criminal purposes? 0:27:12: What level of autonomy or AI can be found in consumer drones today? 0:29:41: How hard is it to turn a DJI drone into an autonomous killbot? 0:35:49: What sorts of countermeasures have we developed against drones? 0:45:11: What roles have drones played in modern warfare? 0:48:40: Can you detect drones on radar? 0:50:22: Have drones influenced modern military tactics? 0:52:33: Are there treaties restricting automomous killing machines? 0:55:51: What’s the future of automonous drone tech? 0:58:46: Is it difficult today to make your own drone? 1:06:24: Interview wrap-up 1:09:08: Annual listener survey update

Jan 22, 20241h 10m

New Year’s Resolutions: 2024

The new year is here! And I’ve got a handful of solid tips for you that you should absolutely plan to accomplish in 2024! I also have a lot of news to catch you up on: 23andMe blames its customers for their data breach; Burger King in Brazil using facial recognition to offer discounts based on how hungover you look; Russian agents hack live webcams to hone in on targets in Ukraine; fake celebrity ads for medicare scam on YouTube; Facebook’s Link History is a confusing new tracking feature; FTC orders location data broker to stop selling your info; Google new location history changes may spell the end for geofence warrants; AirDrop anonymity cracked by China; well-hidden iPhone backdoor discovered by Kaspersky; UK tries to further expand surveillance capabilities; the Beeper Mini messaging saga is over; and a marketing company is offering to listen in on real time conversations to target ads. Article Links [TechCrunch] 23andMe tells victims it’s their fault that their data was breached https://techcrunch.com/2024/01/03/23andme-tells-victims-its-their-fault-that-their-data-was-breached/ [Dark Reading] Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv https://www.darkreading.com/ics-ot-security/russian-agents-use-residential-webcams-to-gather-info-for-missile-attack-on-kyiv [404media.co] Deepfaked Celebrity Ads Promoting Medicare Scams Run Rampant on YouTube https://www.404media.co/joe-rogan-taylor-swift-andrew-tate-ai-deepfake-youtube-medicare-ads/ [Gizmodo] Meet ‘Link History,’ Facebook’s New Way to Track the Websites You Visit https://gizmodo.com/meet-link-history-facebook-s-new-way-to-track-the-we-1851134018 [ftc.gov] FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data [Electronic Frontier Foundation] Is This the End of Geofence Warrants? https://www.eff.org/deeplinks/2023/12/end-geofence-warrants [9to5Mac] AirDrop cracked by China, revealing phone number and email address of sender https://9to5mac.com/2024/01/09/airdrop-cracked-by-china/ [Schneier Blog] New iPhone Exploit Uses Four Zero-Days https://www.schneier.com/blog/archives/2024/01/new-iphone-exploit-uses-four-zero-days.html Security Now, Ep955: https://youtu.be/fJHzq4YOv68?si=WTdyr5LCXV4xJh-k&t=2105  [POLITICO Europe] Britain’s got some of Europe’s toughest surveillance laws. Now it wants more https://www.politico.eu/article/uk-bulking-up-spying-regime-breakneck-speed/ [MacRumors] Beeper Mini Resorts to Jailbreaking iPhones to Rescue Blue Bubbles https://www.macrumors.com/2023/12/21/beeper-mini-jailbroken-iphones-rescue-imessage/ [404media.co] Marketing Company Claims That It Actually Is Listening to Your Phone and Smart Speakers to Target Ads https://www.404media.co/cmg-cox-media-actually-listening-to-phones-smartspeakers-for-ads-marketing/ Tip of the Week: https://firewallsdontstopdragons.com/new-years-resolutions-for-2024/  Further Info Take the annual listener survey! https://fdsd.me/survey2024  Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:38: Listener survey 0:01:57: News rundown 0:04:35: 23andMe blames victims for their data breach 0:09:39: Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv 0:15:19: Deepfaked Celebrity Ads Promoting Medicare Scams Run Rampant on YouTube 0:21:31: Meet ‘Link History,’ Facebook’s New Way to Track You 0:29:41: FTC Order Prohibits Data Broker from Selling Sensitive Location Data 0:33:13: Is This the End of Geofence Warrants? 0:36:57: AirDrop cracked by China, revealing phone number and email address of sender 0:43:11: New iPhone Exploit Uses Four Zero-Days 0:51:58: UK trying to expand surveillance powers 0:55:25: The Beeper Mini saga 1:01:25: Marketing Company Claims That It Actually Is Listening to Your Phone to Target Ads 1:07:44: Tip of the Week: New Year’s Resolutions! 1:19:43: Looking ahead

Jan 15, 20241h 21m

Investigating Data Leaks

Data breaches are usually produced by hackers looking for financial gain. Data leaks, on the other hand, are usually published by whistleblowers or perhaps accidentally disclosed via negligence. Journalists today are inundated by such data leaks – to the point where specialized tools and techniques are required to parse through the piles of digital detritus to ascertain the value and import that they may represent. Micah Lee has been performing this function for The Intercept for many years, including analyzing the Snowden documents. And he has just released a book that outlines the tools, techniques and procedures he uses for this arduous process. Today we discuss the importance and impact of whistleblowers, the state of data leaks today, and how it has impacted modern journalism. Interview Notes Micah’s book: https://hacksandleaks.com/  Excerpt article: https://theintercept.com/2023/12/16/hacked-datasets-verification/  Micah’s GIthub project: https://github.com/micahflee/hacks-leaks-and-revelations  COINTELPRO documentary: https://en.wikipedia.org/wiki/1971_(2014_film)  “The Burglary” book: https://www.amazon.com/Burglary-Discovery-Edgar-Hoovers-Secret/dp/0307962954  EFF’s Surveillance Self-Defense Guide: https://ssd.eff.org/  Further Info Take the annual listener survey! https://fdsd.me/survey2024  Vote for my show as the best privacy podcast! http://tinyurl.com/PPPCAwards2024   Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Become a patron! https://www.patreon.com/FirewallsDontStopDragons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:29: Pre-show notes 0:03:32: Interview prep 0:05:57: Tell us more about the book and why you wrote it. 0:08:11: What’s the difference between a data breach and a data leak? 0:10:02: What are some of history’s most importank leaks? 0:16:14: How do journalists typically obtain leaked data? 0:22:04: You’ve just obtained a massive blob of data. How do you analyze it? 0:27:05: How do you handle leaked data ethnically? 0:30:14: Do you warn the owners of leaked data before you reveal it? 0:32:23: I want to blow the whistle? What should I do? What shoudn’t I do? 0:36:28: I’ve extracted my data. How do I securely share it with a journalist? 0:38:57: What are the legal ramifications of whistleblowing? 0:41:57: How hard is it to analyze digital data? What tools do you use? 0:44:39: Are there dangers to analyzing leaked data? 0:46:43: How do organizations try to identify data leakers? 0:49:42: Will AI tools like ChatGPT help to analyze data leaks? 0:52:19: What can the average person take away from all of this? 0:54:15: How do you know which news sources you can trust today? 0:56:08: Interview wrap-up 0:57:10: Micah blocked on Twitter? 0:57:55: Text parsing tools 0:58:30: Show links 0:58:53: Bonus podcast preview 0:59:42: Annual listener survey raffle info

Jan 8, 20241h 3m

Best of 2023 Bonus Content

Every week, I record a special, private bonus podcast for my patrons. Until today, all of that content was restricted to my supporters. But today I’ve got a sampler platter of some of the best snippets from my bonus Q&A with my interview guests, along with an episode of my more-technical bonus series I call Merlin’s Musings. You’ll hear from Josh Corman (CISA and I Am the Cavalry), Ernesto Falcon (EFF and CA Senate candidate), Omega and Deth Veggie (Cult of the Dead Cow), Michael Littman (AI expert from Brown Univ) and Cory Doctorow (author and activist), plus the strange story of the ProxyHam. Podcast Links These are links to the public podcasts associated with the bonus clips I played today along with some related links. Ep332, Josh Corman: https://podcast.firewallsdontstopdragons.com/2023/07/10/national-cyber-strategy/  Cyberattacks on hospitals are growing threats to patient safety, experts say : https://abcnews.go.com/Health/cyberattacks-hospitals-growing-threats-patient-safety-experts/story?id=99115898 Ep334, Ernesto Falcon: https://podcast.firewallsdontstopdragons.com/2023/07/24/the-politics-of-privacy/  Ep336, Cult of the Dead Cow: https://podcast.firewallsdontstopdragons.com/2023/08/07/cult-of-the-dead-cow/  Ep338, Michael Littman: https://podcast.firewallsdontstopdragons.com/2023/08/21/demystifying-ai/ Ep348, Cory Doctorow: https://podcast.firewallsdontstopdragons.com/2023/10/30/reclaiming-the-internet/ Wired article on ProxyHam: https://www.wired.com/2015/07/online-anonymity-project-proxyham-mysteriously-vanishes/  Hackaday ProxyHam: https://hackaday.com/tag/proxyham/  ProxyGambit: https://github.com/samyk/proxygambit  Further Info Become a patron! https://www.patreon.com/FirewallsDontStopDragons Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:02:41: Josh Corman: analog back and sci-fi table top exercises 0:12:51: Ernesto Falcon: raising money and CA influence 0:19:19: Cult of the Dead Cow: Agent Steal 0:23:44: Michael Littman: Superintelligent AI risks vs reality 0:33:03: Cory Doctorow: Burning Man 0:41:00: Merlin’s Musings: ProxyHam 0:53:37: Wrapup & patron perks

Jan 1, 202458 min

Classic Replay: Lavabit

Today, I dip back into the archives to bring you a classic interview from the first year of this podcast. In Episode 21 (Aug 2017) I interviewed Ladar Levison, the founder of the secure email service Lavabit. He started Lavabit in 2004 as one of the first truly secure, end-to-end encrypted email services focused on the privacy of users, almost ten years before Proton Mail launched. But when the FBI came (literally) knocking in 2013 asking him to subvert the encryption so that they could monitor his users (in particular a guy named Edward Snowden), Ladar decided to shut down Lavabit instead of complying. Ladar relaunched Lavabit in 2021 and I interviewed him that summer about his company, the right to privacy, the story of the shutdown, and much more. It’s as relevant today as it was then. Interview Notes Lavabit: https://lavabit.com/  Lavabit history: https://en.wikipedia.org/wiki/Lavabit  Mr Peaboy and the Wayback Machine: https://en.wikipedia.org/wiki/Mister_Peabody  Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:29: Set the Wayback Machine for 2017! 0:04:10: Episode 1 intro 0:06:47: Ladar Levison episode intro 0:09:43: How and why did you start Lavabit? 0:13:24: Why did you shut Lavabit down in 2013? 0:18:36: How did the Snowden FBI request differ from the previous ones? 0:22:56: Why is privacy important for democracy? 0:26:56: Why don’t people seem to believe privacy is important? 0:28:32: Why should we fight for our right to privacy? 0:30:51: What is the legal basis for email searches? 0:35:12: How should we allow law enforcement access to private data? 0:39:29: Do you worry about losing access to encryption technology? 0:51:25: Is secure email an oxymoron? 0:53:30: How do we protect users from themselves? 0:55:30: Who should be using encrypted email? 0:59:35: What is the new Lavabit service like? 1:01:33: How does Lavabit work with non-Lavabit recipients? 1:02:25: Is the new Lavavit service available now? 1:04:08: Does using E2EE services get you on some watch list? 1:05:56: How can people best support the right to privacy? 1:07:56: Wrap-up and look ahead

Dec 25, 20231h 9m

Best of 2023

I’ve culled through the podcasts from the last year and put together an hour’s worth of the best content! Here’s a nice little charcuterie sampler of the top interview segments from 2023. Episode Links Ep347 (Oct 16) What’s Your Threat Model? https://podcast.firewallsdontstopdragons.com/2023/10/16/whats-your-threat-model/  Ep342 (Sep 18) Your Face Belongs to Us https://podcast.firewallsdontstopdragons.com/2023/09/18/your-face-belongs-to-us/  Ep336 (Aug 7) Cult of the Dead Cow https://podcast.firewallsdontstopdragons.com/2023/08/07/cult-of-the-dead-cow/  Ep348 (Oct 30) Reclaiming the Internet https://podcast.firewallsdontstopdragons.com/2023/10/30/reclaiming-the-internet/  Ep324 (May 15) – Probing the Ministry of Truth https://podcast.firewallsdontstopdragons.com/2023/05/15/probing-the-ministry-of-truth/  Ep338 (Aug 21) Demystifying AI https://podcast.firewallsdontstopdragons.com/2023/08/21/demystifying-ai/  Further Info Send me your questions! https://fdsd.me/qna  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Subscribe to the newsletter: https://fdsd.me/newsletter  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Support our mission! https://fdsd.me/support  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:02:09: Andy Yen, CEO Proton: LastPass breach 0:07:22: Kashmir Hill, NY Times: Clearview Ai 0:17:25: Omega and Deth Veggie, Cult of the Dead Cow: being a hacker 0:39:43: Cory Doctorow, author/activist: ensh*tification 0:49:42: Vincent Hendricks, author: social media 0:58:32: Michael Littman, Brown Univ: Dangers of AI 1:04:46: Wrap-up and look ahead

Dec 18, 20231h 7m

Restoring Trust in Elections

We here in the US like to believe that we’re the gold standard for democracy. And yet, in recent years, much of the electorate has lost faith in the outcome of our elections. Many security researchers have found concerning vulnerabilities in our voting systems, and yet we have no evidence that those vulnerabilities have actually been exploited. Many people believe that people are voting multiple times or that ineligible people are voting, and yet study after study shows that voter fraud is nearly non-existent. How can we restore trust in our election results? What changes must we make to our election systems and processes to promote complete transparency and remove doubt? Today I’ll dig deep into this complicated topic with Ben Adida, founder and Executive Director of VotingWorks. Interview Notes VotingWorks: https://www.voting.works/ Risk Limiting Audits with ARLO:  https://www.voting.works/risk-limiting-audits  Verified Voting, Verifier tool: https://verifiedvoting.org/verifier/  Ben’s PhD thesis defense (Verifying a Secret-Ballot Election with Cryptography) and much more: https://ben.adida.net/presentations/  Voluntary Voting System Guidelines (VVSG) 2.0: https://www.eac.gov/sites/default/files/TestingCertification/Voluntary_Voting_System_Guidelines_Version_2_0.pdf  Harri Hursti interview: https://podcast.firewallsdontstopdragons.com/2021/11/08/restoring-trust-in-our-elections/  ElectionGuard interview: https://podcast.firewallsdontstopdragons.com/2021/12/06/defending-democracy-with-technology/  DEF CON Voting Village videos: https://www.youtube.com/@defconvotingvillage/videos  Further Info Give the gift of privacy and security: https://fdsd.me/coupons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Send me your questions! https://fdsd.me/qna  Support our mission! https://fdsd.me/support  Subscribe to the newsletter: https://fdsd.me/newsletter  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:03:28: What is the mission of VotingWorks and what drove you to found it? 0:04:39: How do election work, exactly, here in the US? 0:12:26: How are all the votes tabulated and reported? 0:14:11: Where are US elections most vulnerable to influence? 0:19:52: How does accessibility impact security in elections? 0:24:27: How can we harden the election systems and processes? 0:31:16: How to risk-limiting audits work? 0:33:11: How vulnerable are election computers to hacking? 0:36:37: If our systems are vulnerable, why haven’t they been hacked? 0:43:37: How can we best convince people that our election outcomes are valid? 0:51:30: How prevelent is voter fraud in the US? 0:53:56: Do we have federal minimum guidelines for election security? 0:56:52: Why aren’t election systems open for third party review? 0:58:25: How do I learn about my local election systems and processes? 1:04:22: Wrap-up 1:07:34: Looking ahead

Dec 11, 20231h 8m

Using Email Aliases

Your online account credentials have two parts: a user name and a password. Today, most online providers force you to use your email address for your user name. This gives the service provider a guaranteed way to contact (and spam) their users, but it also means that bad guys know half of all your credentials and data brokers have a unique ID to track you across all your accounts. Today I’ll explain the value of using email aliases for your online user names. In other news: Iranian hackers attack US water plant; CISA launches program to address critical infrastructure threats; Google Drive users report missing data; Plex users fear new feature will leak p0rn watching habits; several articles on the ease of using data broker tools to spy on just about anyone, creating privacy and national security problems; smart mattress company CEO inadvertently reveals extent of data collection; concerns about IoT device sold with a home; overblown fears over Apple’s new NameDrop feature; Zelle offering refunds to some scam victims; and Malwarebyte’s survey of people’s security practices (spoiler: it’s bad). Article Links [The Hacker News] Iranian Hackers Exploit PLCs in Attack on Water Authority in U.S. https://thehackernews.com/2023/11/iranian-hackers-exploit-plcs-in-attack.html [Dark Reading] CISA Launches Pilot Program to Address Critical Infrastructure Threats https://www.darkreading.com/ics-ot/cisa-launches-pilot-program-critical-infrastructure-threats [AppleInsider] Google Drive users complain of missing files, months of data disappearing https://appleinsider.com/articles/23/11/27/google-drive-users-complain-of-missing-files-months-of-data-disappearing [404media.co] Plex Users Fear New Feature Will Leak Porn Habits to Their Friends and Family https://www.404media.co/plex-users-fear-discover-together-week-in-review-feature-will-leak-porn-habits-to-their-friends-and-family/ [Rolling Stone] We Spied on Trump’s ‘Southern White House’ From Our Couches https://www.rollingstone.com/culture/culture-features/data-brokers-trump-tech-spying-privacy-threat-1234897098/ [9to5mac.com] Data brokers selling even more sensitive info; national security risk, says report https://9to5mac.com/2023/11/14/data-brokers-sensitive-info/ [MIT Technology Review] The US military’s privacy problem in three charts https://www.technologyreview.com/2023/11/13/1083262/the-us-militarys-privacy-problem-in-three-charts/ [therecord.media] Court rules automakers can record and intercept owner text messages https://therecord.media/class-action-lawsuit-cars-text-messages-privacy [404media.co] CEO Reminds Everyone His Company Collects Customers’ Sleep Data to Make Zeitgeisty Point About OpenAI Drama https://www.404media.co/ceo-reminds-everyone-eightsleep-pod-collects-sleep-data-to-make-zeitgeisty-point-about-openai-drama/ [sdmmag.com] Who Is Gonna “Own” the IoT? https://www.sdmmag.com/articles/93730-who-is-gonna-own-the-iot [TechRadar] NameDrop in iOS 17 doesn’t have to be a privacy nightmare – here’s how to control it https://www.techradar.com/phones/ios/namedrop-in-ios-17-doesnt-have-to-be-a-privacy-nightmare-heres-how-to-control-it [9to5mac.com] Zelle scams: App now starting limited refunds, under pressure from lawmakers https://9to5mac.com/2023/11/13/zelle-scams/ [malwarebytes.com] 3 crucial security steps people should do, but don’t https://www.malwarebytes.com/blog/news/2023/10/the-3-crucial-security-steps-people-should-do-but-dont OwnCloud hack: https://www.helpnetsecurity.com/2023/11/28/cve-2023-49103/  Pros & Cons of Antivirus Software: https://firewallsdontstopdragons.com/the-pros-and-cons-of-anti-virus-software/  Tip of the Week: https://firewallsdontstopdragons.com/how-to-use-email-aliases-part-1/ Further Info Give the gift of privacy and security: https://fdsd.me/coupons  Send me your questions! https://fdsd.me/qna  Support our mission! https://fdsd.me/support  Subscribe to the newsletter: https://fdsd.me/newsletter  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Table of Contents Use these timestamps to jump to a particular section of the show. 0:00:57: Important software updates 0:01:56: News run down 0:05:18: Iranian Hackers Exploit PLCs in Attack on Water Authority in U.S. 0:07:49: CISA Launches Pilot Program to Address Critical Infrastructure Threats 0:09:38: Google Drive users complain of missing files, data 0:14:55: Plex Users Fear New Feature Will Leak P*rn Habits to Their Friends and Family 0:19:34: We Spied on Trump’s ‘Southern White House’ From Our Couches 0:23:36: Data brokers selling even more sensitive info creating national security risk 0:26:48: The US military’s privacy problem in three charts 0:30:33: Court rules automakers can record and intercept owner text messages 0:32:49: CEO Reminds Everyone His Company Collects Customers’ Sleep Data via Tweet 0:39:09: Transferring IoT devices in a home sale 0:43:30: NameDrop in

Dec 4, 20231h 11m

Smart City Blues

City governments are relying more and more on a vast network of sensors to tell them what’s going on: stop light cameras, gunshot detectors, air quality sensors, license plate readers, automated toll booths, and much more. While these technologies can help the powers that be allocate precious resources and gain helpful insights, they can also lead to over-policing, chilling of free speech and mass warrantless surveillance. Today I’ll discuss the dangers of smart cities with Eleni Manis from the Surveillance Technology Oversight Project (STOP). Interview Notes Surveillance Technology Oversight Project: https://www.stopspying.org/  S.T.O.P.’s Beginner’s Guide to the All-Too-Dumb World of Smart Cities: www.justcities.tech  CCOPS laws: https://www.eff.org/issues/community-control-police-surveillance-ccops  Further Info Best & Worst Gifts for 2023: https://firewallsdontstopdragons.com/best-worst-gifts-2023/ Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Send me your questions! https://fdsd.me/qna  Support our mission! https://fdsd.me/support  Subscribe to the newsletter: https://fdsd.me/newsletter  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Generate secure passphrases! https://d20key.com/#/  Table of Contents Use these timestamps to jump to a particular section of the show. 0:04:38: What got you into researching smart cities? 0:09:03: What are the positive aspects of smart cities? 0:13:06: How ubiquitous are these smart city technologies? 0:15:32: What are some of the most concerning smart city technologies? 0:16:45: is this data being shared between local and federal agencies? 0:19:14: Can students opt out of school surveillance? 0:20:48: How can the police access footage from video doorbells? 0:24:20: How is this tech used for predictive policing? 0:26:31: Do these predictive policing systems actually work? 0:27:29: How does this mass surveillance affect people? 0:28:58: What about use of surveillance tech in neighborhoods? 0:33:56: Who operates these sensor networks? Who can access the data? 0:37:49: Is it possible to anonymize this data properly? 0:42:06: Can government agencies access our cellular data? 0:45:22: Can you refuse to hand your cell phone over to authorities? 0:48:04: Can we find ways to collect this data without ruining privacy? 0:49:42: How do I find out what smart city tech is being used in my area? 0:53:29: Wrap-up 0:54:57: Preview of upcoming shows

Nov 27, 202357 min

Best & Worst Gifts for 2023

The holiday gift-giving season is upon us – and therefore it’s time for my annual guide on the best and worst gifts for your loved ones, at least in terms of security and privacy. There are some perennial favs on the nice and naughty lists, but there are some newcomers, as well. And I’ve got some top tips for how to shop for privacy-respecting, security-protecting products! I’ve even got some ideas for free and helpful stocking stuffers. In the news: FCC tried to protect consumers from SIM-swap attacks; cheap children’s tablet came with malware and data mining software; medical transcription service has data of 9M patients exposed; hackers hold data from plastic surgeon patients for ransom, including nude photos; FTC filing in Kochava case unsealed showing ‘staggering’ amount of data for sale; Bitwarden announces support for passkeys; Article 45 of eIDAS 2.0 bill will completely undermine internet security in the EU. Article Links [The Hacker News] FCC Enforces Stronger Rules to Protect Customers Against SIM Swapping Attacks https://thehackernews.com/2023/11/fcc-enforces-stronger-rules-to-protect.html [TechCrunch] Children’s tablet has malware and exposes kid’s data, researcher finds https://techcrunch.com/2023/11/16/childrens-tablet-has-malware-and-exposes-kids-data-researcher-finds/ [BleepingComputer] PJ&A says cyberattack exposed data of nearly 9 million patients https://www.bleepingcomputer.com/news/security/pj-and-a-says-cyberattack-exposed-data-of-nearly-9-million-patients/ [8newsnow.com] Hackers target Las Vegas plastic surgeons, post patient information, naked photos online https://www.8newsnow.com/investigators/hackers-target-las-vegas-plastic-surgeons-post-patient-information-naked-photos-online/ [Ars Technica] Data broker’s “staggering” sale of sensitive info exposed in unsealed FTC filing https://arstechnica.com/tech-policy/2023/11/data-brokers-staggering-sale-of-sensitive-info-exposed-in-unsealed-ftc-filing/ [bitwarden.com] Bitwarden launches passkey management https://bitwarden.com/blog/bitwarden-launches-passkey-management/ [Electronic Frontier Foundation] Article 45 Will Roll Back Web Security by 12 Years https://www.eff.org/deeplinks/2023/11/article-45-will-roll-back-web-security-12-years Best & Worst Gifts for 2023: https://firewallsdontstopdragons.com/best-worst-gifts-2023/  Further Info Give Thanks!: https://firewallsdontstopdragons.com/give-thanks-donate/  Consumer Reports Naughty List: https://foundation.mozilla.org/en/privacynotincluded/articles/our-longest-naughty-list-ever-the-2023-holiday-buyers-guide-is-here/  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Give the gift of privacy and security: https://fdsd.me/coupons  Send me your questions! https://fdsd.me/qna  Support our mission! https://fdsd.me/support  Subscribe to the newsletter: https://fdsd.me/newsletter  Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book  Table of Contents Use these timestamps to jump to a particular section of the show. 0:01:37: News run-down 0:03:18: FCC Enforces Stronger Rules to Protect Against SIM Swapping 0:06:39: Children’s tablet has malware and exposes kid’s data 0:11:22: Cyberattack exposed data of nearly 9 million patients 0:15:16: Hackers target plastic surgeons, post patient info, naked photos online 0:22:37: Data broker’s “staggering” sale of sensitive info exposed in unsealed FTC filing 0:27:10: Bitwarden launches passkey management 0:30:45: Article 45 Will Roll Back Web Security by 12 Years 0:39:00: Best & Worst Gifts for 2023 0:42:38: The Naughty List 0:47:50: The Nice List 0:59:14: Give thanks! 1:00:03: FDSD Merch sale! 1:00:25: Upcoming shows & promotion

Nov 20, 20231h 1m