PLAY PODCASTS
Firewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast

500 episodes — Page 7 of 10

200th Podcast & New Year’s 2021!

The dumpster fire that was 2020 is almost behind us, and it’s time to look forward to a brighter future in 2021! By a stroke of fortuitous coincidence, this is also my 200th podcast! To celebrate these two important milestones, we have a world-renowned security guru for our guest, Bruce Schneier, and I’ll be giving away over $1800 worth of great stuff to help you improve your privacy and security in 2021! And if all of that weren’t enough, I’ll also be sharing with you several top-notch to-do list ideas for your 2021 New Year’s resolutions – not just from myself, but from several top industry experts! It’s an amazing star-studded, prize-riddled, info-packed podcast! Special Guest Appearances By: Bruce Schneier (Chief of Security Architecture at Inrupt) Dr Ann Cavoukian (Executive Director at Global Privacy & Security by Design Centre) Dr Andy Yen (CEO/Co-Founder ProtonMail) Cory Doctorow (author & activist) David Ruiz (Malwarebytes) Helen Horstmann-Allen (COO Fastmail) Beah Burger-Lenehan (Director, Product at DuckDuckGo) Marshall Erwin (Chief Security Officer, Mozilla) Todd Weaver (Founder/CEO Purism) Rich Stokes (Founder/CEO Winston Privacy) Further Info: CONTEST LINK!! http://bit.ly/Firewalls-200 Contest info: https://firewallsdontstopdragons.com/new-years-2021-giveaway/ New Year’s Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/ Inrupt: https://inrupt.com/solid Solid Project: https://solidproject.org/ Follow me on Facebook!! https://bit.ly/Firewalls-Facebook Follow me on YouTube!! https://bit.ly/Firewalls-YouTube

Dec 28, 20201h 19m

Best of 2020!

I’ve painstakingly scoured the last 50 episodes to select the best of the best, the cream of the crop, the top tips for the year 2020! If you’re already a subscriber, this will be a great refresher – and maybe give you a chance to do some of those things you had meant to do but somehow never got around to doing it! And if you’re a new subscriber, then you can catch up on some of what you missed! This would also be a great episode to share with friends and family who you feel might also benefit from improving their cyber security and data privacy! Enjoy! And Happy Holidays!! Further Info Don’t miss the HUGE 200th episode next week! https://firewallsdontstopdragons.com/200th-podcast-a-brighter-future/ Follow me on Facebook!! https://bit.ly/Firewalls-Facebook Follow me on YouTube!! https://bit.ly/Firewalls-YouTube

Dec 21, 20201h 9m

Setting the Digital Standard (Part 2)

One today’s show, Ben Moskowitz from Consumer Reports will tell us about an extremely useful tool they’ve created to help you improve your personal security and privacy, customized to your particular needs, called the Security Scanner. Just answer a few simple questions and it will give you a checklist of specific ways to be more secure, ranked by time, effort and cost. Consumer Reports is also pioneering a comprehensive, open-source program that will allow consumers, manufacturers, advocacy organizations, and more to formally evaluate the privacy and security aspects of products and services. This will allow buyers to compare products more accurately and give manufacturers incentives to make better products. Benjamin Moskowitz is the Director of Consumer Reports’ Digital Lab, a major initiative to expand CR’s work on privacy, digital security, and emerging concerns in digital consumer protection. Previously, he served as Director of Development for Innovation for the International Rescue Committee, where he secured more than $29 million in funding as a founding member of the Airbel Center—a research and development unit that designs, tests, and scales life-changing solutions for refugees and people affected by conflict. Further Info Consumer Reports Security Planner: https://securityplanner.consumerreports.org/  The Digital Standard: https://thedigitalstandard.org/  Virtual screening of Coded Bias: https://action.consumerreports.org/coded_bias  Contribute! https://digital-lab.consumerreports.org/  Become a CR Member: https://www.consumerreports.org/membership  Privacy Front & Center study: https://thedigitalstandard.org/downloads/CR_PrivacyFrontAndCenter_102020_vf.pdf  Best & Worst Gift Guide 2020: https://firewallsdontstopdragons.com/best-worst-gifts-2020/  Follow me on Facebook!! https://bit.ly/Firewalls-Facebook  Follow me on YouTube!! https://bit.ly/Firewalls-YouTube Request book for review: https://form.jotform.com/203127587895064

Dec 14, 202058 min

Setting the Digital Standard (Part 1)

Are consumers really concerned about security and privacy in the products they buy? And if so, how could manufacturers capitalize on these attributes to sell more of their products? Consumer Reports has recently published an important, comprehensive study of consumer attitudes towards privacy and security, including the historical evolution of these feelings. The result is a roadmap which companies can use to better serve this fast-growing market. Today we’ll discuss this study and its implications with Ben Moskowitz from CR’s Digital Lab. Benjamin Moskowitz is the Director of Consumer Reports’ Digital Lab, a major initiative to expand CR’s work on privacy, digital security, and emerging concerns in digital consumer protection. Previously, he served as Director of Development for Innovation for the International Rescue Committee, where he secured more than $29 million in funding as a founding member of the Airbel Center—a research and development unit that designs, tests, and scales life-changing solutions for refugees and people affected by conflict. Further Info: Privacy Front & Center study: https://thedigitalstandard.org/downloads/CR_PrivacyFrontAndCenter_102020_vf.pdf Consumer Reports Security Planner: https://securityplanner.consumerreports.org/ The Digital Standard: https://thedigitalstandard.org/ Virtual screening of Coded Bias: https://action.consumerreports.org/coded_bias Contribute! https://digital-lab.consumerreports.org/ Become a CR Member: https://www.consumerreports.org/membership My new YouTube Channel: https://www.youtube.com/channel/UC0aUElaV7hDubXSpDJkiSrA Request book for review: https://form.jotform.com/203127587895064

Dec 7, 202045 min

Best & Worst Gifts Guide 2020

Looking for fun gifts that won’t also be gifts to hackers and data miners? In today’s show, I’ll list off the top products and services from my annual Naughty & Nice gifts guide! Every year, I review several popular gifts and give you my recommendations on which ones to buy and which ones to avoid like the plague (or the pandemic?). In other news: Spotify has been hacked and you should change your password; Google is looking to add end-to-end encryption to its new Android RCS messaging system; an important new IoT security bill is waiting for the President’s signature; 27.7M Texans’ driver’s license info has been stolen; the IRS and the US military have been doing an end run around the US Constitution to obtain location information on thousands of people including US citizens without a warrant; Apple lowers its App Store commission to 15% for the vast majority of developers; Apple has responded to the blow back concerning its security validation on macOS Big Sur; and now is the time to download and enable your state’s COVID-19 tracing app. Further Info: Best & Worst Gifts for 2020: https://firewallsdontstopdragons.com/best-worst-gifts-2020/  COVID-tracing app story, Washington Post: https://www.washingtonpost.com/technology/2020/11/18/coronavirus-app-exposure-alerts/ Setting up a Pi-Hole server: https://www.smarthomebeginner.com/pi-hole-setup-guide/ 

Nov 30, 20201h 29m

Dark Patterns (Part 2)

So, what can we do about these dark patterns? Are there technical solutions to this problem? Or will this require regulations? Or perhaps we just need to train our engineers and consumers better? In part 2 of my interview with Dr. Colin Gray of Purdue University, we talk about some possible solutions to the dark patterns problem, as well as tips and tricks for avoiding them. Colin also shares several interesting resources for further study. Colin M. Gray is an Assistant Professor at Purdue University in the Department of Computer Graphics Technology. He is program lead for an undergraduate major and graduate concentration in UX Design. He holds a PhD in Instructional Systems Technology from Indiana University Bloomington, a MEd in Educational Technology from University of South Carolina, and a MA in Graphic Design from Savannah College of Art & Design. He has worked as an art director, contract designer, and trainer, and his involvement in design work informs his research on design activity and how design capability is learned. His research focuses on the ways in which the pedagogy and practice of designers informs the development of design ability, particularly in relation to ethics, design knowledge, and professional identity formation. Further Info: Colin’s home page: https://colingray.me Dark Patterns: https://darkpatterns.uxp2.com Dark Patterns (Brignull): https://darkpatterns.org/ Give Thanks: https://firewallsdontstopdragons.com/give-thanks-donate/ Rachel Maddow’s plea: https://www.nbcnews.com/feature/nbc-out/rachel-maddow-says-her-partner-has-covid-19-one-point-n1248375 COVID-19 risk assessment tool: https://covid19risk.biosci.gatech.edu/ Facebook’s Social Contagion experiment: https://www.forbes.com/sites/kashmirhill/2014/06/30/facebook-only-got-permission-to-do-research-on-users-after-emotion-manipulation-study/ Evil By Design: https://www.amazon.com/Evil-Design-Interaction-Lead-Temptation/dp/1118422147 Design Justice: https://design-justice.pubpub.org/ Data Feminism: https://data-feminism.mitpress.mit.edu/ Michael Sandel’s Justice course: http://justiceharvard.org/justicecourse/

Nov 23, 202055 min

Dark Patterns (Part 1)

Are you tired of being pestered to allow notifications or access to your location? Do you wonder why you have to give your credit card number in order to sign up for “free” trials? Why weren’t you told about the shipping costs until the very last screen in the purchase process? Are you sure that you didn’t intend to sign up for all those newsletters? You’re not alone, and you’re not simply being subjected to clever marketing. You’ve been the victim of dark patterns: specific, scientifically-proven techniques designed to favor shareholder value over user value. In part 1 of my interview with Dr. Colin Gray, we’ll discuss all the ways in which we’re being manipulated and why, as mere humans, we’re horribly outmatched. Colin M. Gray is an Assistant Professor at Purdue University in the Department of Computer Graphics Technology. He is program lead for an undergraduate major and graduate concentration in UX Design. He holds a PhD in Instructional Systems Technology from Indiana University Bloomington, a MEd in Educational Technology from University of South Carolina, and a MA in Graphic Design from Savannah College of Art & Design. He has worked as an art director, contract designer, and trainer, and his involvement in design work informs his research on design activity and how design capability is learned. His research focuses on the ways in which the pedagogy and practice of designers informs the development of design ability, particularly in relation to ethics, design knowledge, and professional identity formation. Further Info: Dr. Colin Gray’s home page: https://colingray.me Dark Patterns: https://darkpatterns.uxp2.com Dark Patterns (Brignull): https://darkpatterns.org/ Facebook’s Social Contagion experiment: https://www.forbes.com/sites/kashmirhill/2014/06/30/facebook-only-got-permission-to-do-research-on-users-after-emotion-manipulation-study/

Nov 16, 202052 min

Zoom: Now with Actual Privacy

Zoom went from an obscure teleconferencing company to a household word when the pandemic hit. Zoom wasn’t the best videoconferencing app by any means. But it was dead simple to use and kinda fun to say. For better or worse, it became the de facto tool for many of us to keep in touch. Over that time, Zoom has made many important improvements. This week it has finally rolled out what appears to be true end-to-end encryption (E2EE). Today I’ll tell you how to enable this new feature. In other news: Be sure to update your iPhones to iOS 14.2; also be sure to keep Google Chrome and Windows 10 up to date; Adobe Flash is finally almost gone; police in Jackson, Mississippi are trialing a program to directly tap into people’s private security cameras like Ring video doorbells; the NSA and FBI have been burned by the very backdoors they added; and California’s Prop 24 passes, beefing up privacy protections for its citizens (and probably for all of us). Further Info (for podcast page) How to enable Zoom end-to-end encryption: https://firewallsdontstopdragons.com/zoom-now-with-actual-privacy/ Best & Worst Gifts from last year: https://firewallsdontstopdragons.com/best-worst-gifts-2019/ Please add a nice review on my new book!! https://www.amazon.com/gp/product/1484261887

Nov 9, 202044 min

The Ebb & Flow of the Internet

For better or for worse, the internet today is funded by advertising. While ads can be annoying, the real issue isn’t having to watch ads – it’s when then ads watch us. AdTech today is premised on invasive personal data collection. Companies like Google and Facebook amass voluminous dossiers on each of us, and sell highly-targeted ads based on our income, gender, age, location, buying habits, personal interests, sexual orientation, and much, much more. But it doesn’t have to be that way. And Cloudflare is going to show us how. Today, I’ll talk again with the CTO, John Graham-Cumming, about Cloudflare Radar and much more. John Graham-Cumming is a British software engineer and writer best known for starting a successful petition to the Government of the United Kingdom asking for an apology for its persecution of Alan Turing. As of 2020, he serves as Chief Technology Officer (CTO) at Cloudflare. Further Info: Cloudflare Radar: Election 2020 https://radar.cloudflare.com/election-2020 Cloudflare 1.1.1.1 DNS and Warp VPN: https://1.1.1.1/ VOTE! https://www.vote.org/

Nov 2, 202051 min

Big Proctor is Watching You (part 2)

In the second half of my interview with the EFF’s Lindsay Oliver and Jason Kelley, we talk about how these draconian surveillance systems put several students at a distinct disadvantage and how the teacher themselves feel about all of this. How might all of this normalize surveillance for young people? Can the invisible hand of the market resolve some of these issues? What should the policies be around proctoring and the use of these surveillance apps? How can we push back and demand change most effectively? Lindsay Oliver is the Project Manager for EFF’s activism team, and works on the self-help resource Surveillance Self-Defense, Security Education Companion, and student privacy. Jason Kelley guides EFF’s social media tactics and develops EFF’s online digital advocacy, and writes about various forms of governmental and private surveillance and tracking. Further Info: VOTE! https://www.vote.org/ Cybersecurity & Infrastructure Security Agency tip sheets: https://www.cisa.gov/national-cybersecurity-awareness-month-resources Surveillance Self Defense for students: https://ssd.eff.org/en/module/privacy-students Electronic Frontier Alliance: https://supporters.eff.org/join-efa This article has TONS of student privacy resources: https://www.eff.org/deeplinks/2020/09/students-are-pushing-back-against-proctoring-surveillance-apps

Oct 26, 20201h 6m

Big Proctor is Watching You (part 1)

In this time of COVID19, we’ve all had to learn to work and learn from home. But how do our bosses know we’re not screwing around instead of working? How do our teachers know we’re not cheating? It turns out that they’re both willing to go to extremely intrusive measures to try to figure that out. Home and mobile device surveillance technology is booming thanks to this global pandemic, as we will learn from talking to the EFF’s Lindsay Oliver and Jason Kelley. They have been investigating the serious impacts these products and services are having on our privacy and overall fairness for students and employees. Lindsay Oliver is the Project Manager for EFF’s activism team, and works on the self-help resource Surveillance Self-Defense, Security Education Companion, and student privacy. Jason Kelley guides EFF’s social media tactics and develops EFF’s online digital advocacy, and writes about various forms of governmental and private surveillance and tracking. Further Info: Surveillance Self Defense for students: https://ssd.eff.org/en/module/privacy-students Electronic Frontier Alliance: https://supporters.eff.org/join-efa This article has TONS of student privacy resources: https://www.eff.org/deeplinks/2020/09/students-are-pushing-back-against-proctoring-surveillance-apps National Cybersecurity Awareness Month: https://www.cisa.gov/national-cybersecurity-awareness-month-resources

Oct 19, 202046 min

National Cybersecurity Awareness Month

October is National Cybersecurity Awareness Month! The theme this year is: if you connect it, protect it! And given how popular IoT devices are these days, and also how horrid their security usually is, this advice has never been more important. In today’s show, I’ll walk through some top cyber tips for protecting your devices and your home network. And there’s a TON of news, as well: I’ll update you on the “App Fairness” campaign from Epic, Protonmail, Spotify and others; watch out for fake Android messaging apps made to look like Threema or Telegram; Google’s Chrome browser gets slammed for its poor privacy protections; Google is now giving out lists of people who searched on particular terms to law enforcement; Amazon is adding some new privacy options to their Alexa products, while also introducing a super-creepy home spy drone; should you let your insurance company track you? (spoiler: no); and Apple’s T2 chip is found to have a severe, unfixable security flaw. Further Info: Cybersecurity & Infrastructure Security Agency (CISA) tip sheets: https://www.cisa.gov/publication/national-cybersecurity-awareness-month-publications Get 20% off my new book at Apress using code Dragons2020. https://www.apress.com/us/book/9781484261880 Google Chrome: the Anti-Privacy Browser: https://theprivacy.com/2020/09/14/google-chrome-the-anti-privacy-browser/?hss_channel=tw-976856456740864004 Coalition for App Fairness’s 10 principles examined: https://appleinsider.com/articles/20/10/05/breaking-down-the-coalition-for-app-fairness-issues-with-apple

Oct 12, 202055 min

Apple’s Epic Battle Royale (Part 2)

What do Apple, Tyson Foods and Worldwide Wrestling (WWE) all have in common? And what is “chickenization”? In part 2 of my interview with Cory Doctorow, he explains how some markets in the US economy are completely distorted by dominant sellers as well as dominant buyers. Seeing all of these specific markets as facets of a single economic problem, we can find common cause and perhaps a common solution. Cory Doctorow (craphound.com) is a science fiction author, activist, and journalist. He is the author of RADICALIZED and WALKAWAY, science fiction for adults, a YA graphic novel called IN REAL LIFE, the nonfiction business book INFORMATION DOESN’T WANT TO BE FREE, and young adult novels like HOMELAND, PIRATE CINEMA and LITTLE BROTHER. His latest book is POESY THE MONSTER SLAYER, a picture book for young readers. His next book is ATTACK SURFACE, an adult sequel to LITTLE BROTHER. He maintains a daily blog at Pluralistic.net. He works for the Electronic Frontier Foundation, is a MIT Media Lab Research Affiliate, is a Visiting Professor of Computer Science at Open University, a Visiting Professor of Practice at the University of North Carolina’s School of Library and Information Science and co-founded the UK Open Rights Group. Born in Toronto, Canada, he now lives in Los Angeles. Further Info: Buy Attack Surface: https://us.macmillan.com/books/9781250757531 Back Attack Surface audio book: https://www.kickstarter.com/projects/doctorow/attack-surface-audiobook-for-the-third-little-brother-book Buy Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Watch The Social Dilemma!: https://www.netflix.com/title/81254224 Donate to EFF: https://supporters.eff.org/donate/join-4 Be very wary of disinformation right now: https://firewallsdontstopdragons.com/fake-news-be-highly-wary-right-now/ VOTE!! https://www.vote.org/

Oct 5, 202039 min

Apple’s Epic Battle Royale (Part 1)

Apple and Epic Games are locked in an epic legal (and PR) battle that may determine the future of the App Store, the Google Play Store, and several other game distribution networks. At the heart of this debate is the disproportionate influence the app store owner has over the apps in their store, including demanding a hefty cut of the app maker’s profits. How did we get to this place? How does this distort the market for software? When did “contempt of business model” become a felony? Today I’ll discuss this and more with EFF’s Cory Doctorow. Cory Doctorow (craphound.com) is a science fiction author, activist, and journalist. He is the author of RADICALIZED and WALKAWAY, science fiction for adults, a YA graphic novel called IN REAL LIFE, the nonfiction business book INFORMATION DOESN’T WANT TO BE FREE, and young adult novels like HOMELAND, PIRATE CINEMA and LITTLE BROTHER. His latest book is POESY THE MONSTER SLAYER, a picture book for young readers. His next book is ATTACK SURFACE, an adult sequel to LITTLE BROTHER. He maintains a daily blog at Pluralistic.net. He works for the Electronic Frontier Foundation, is a MIT Media Lab Research Affiliate, is a Visiting Professor of Computer Science at Open University, a Visiting Professor of Practice at the University of North Carolina’s School of Library and Information Science and co-founded the UK Open Rights Group. Born in Toronto, Canada, he now lives in Los Angeles. Further Info: Buy Attack Surface: https://us.macmillan.com/books/9781250757531 Back Attack Surface audio book: https://www.kickstarter.com/projects/doctorow/attack-surface-audiobook-for-the-third-little-brother-book Enter to win a free copy of my book: https://bit.ly/firewalls4 Buy Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Watch The Social Dilemma!: https://www.netflix.com/title/81254224 Donate to EFF: https://supporters.eff.org/donate/join-4 VOTE!! https://www.vote.org/

Sep 28, 202044 min

Take Out the (Windows) Trash

If you’re a Windows PC user, you know the term “bloatware”, or maybe “crapware”. Every consumer PC comes chock full of it. Free trials of games, cloud storage services and antivirus software. Half a dozen “helper” apps from the PC manufacturer. Pre-installed calling, chat, and shopping services. It’s a mess. But they’re not just annoying. They can slow down your computer’s startup and shutdown, and waste precious battery life on laptops. Today I’ll share two ways to take out this trash. In other news: Android 11 and iOS 14 are out, and have neat new security and privacy features; Google is blocking W3C efforts to improve your privacy while also blocking resource-hogging ads in Chrome and blocking stalkerware apps in the Google Play Store; the FBI is now worried that video doorbells may actually let people spy on them; Facebook will try to ban deepfake political videos; and the US House unanimously passes a much-needed IoT security bill.

Sep 21, 202052 min

It’s a Trap!

Enterprising scammers have found some very clever ways to trick you into believing your computer needs fixing, when in reality it’s just fine. Using various techniques, fake web pop-up alerts can cause your browser or computer to seem sluggish or malfunctioning. And then you get a helpful pop-up alerting you of a serious problem and offering to help you fix it – for a fee. I’ll tell you how to spot these fakes and how to recover from the issues they’ve inflicted. In other news: there’s a new and nasty Bluetooth bug, Emotet malware infections are spiking, Apple accidentally notarized malware in its App Store, Apple chooses to delay it’s key privacy feature on iOS 14 due to push back from marketing companies like Facebook, the Epic/Apple battle ratchets up yet again, a US circuit court rules that warrantless wiretapping is illegal, Portland enacts the country’s strictest ban on facial recognition technology, and the secure messaging app Threema has decided to go open source. Further Info: Order the 4th edition of my book: https://www.apress.com/us/book/9781484261880 Enter my book giveaway! http://bit.ly/firewalls4

Sep 14, 202053 min

Firefox Privacy (Part 2)

Did you know that Google’s search can track you on a non-Chrome browser, even if you block third party cookies? And did you also know that there’s a gaping privacy hole in web surfing that even a VPN may not fix? Is it possible to defeat browser fingerprinting? In the second half of my interview with Mozilla’s Chief Security Officer Marshall Erwin, we’ll answer these questions and much more. Marshall will give us his personal privacy tips and tell us about some upcoming Firefox features. And perhaps most importantly, he’ll tell us what we can do to support Mozilla and Firefox. Marshall Erwin is the Chief Security Officer at the Mozilla Corporation, where he leads teams responsible for protecting Mozilla and its users. He also drives policy initiatives on encryption, government vulnerability disclosure, malicious online content, and online political advertising, as well as product initiatives to protect people from pervasive web tracking. Prior to joining Mozilla, Marshall worked in a variety of positions related to technology policy, cybersecurity, and national security more broadly. He began his career in national security, an analyst covering counterterrorism and cybersecurity. He also served as the counterterrorism and intelligence adviser on the Senate Homeland Security and Government Affairs Committee and as the intelligence specialist at the Congressional Research Service, focusing on National Security Agency surveillance programs and legislative changes to FISA statute. Marshall is a current Non-Residential Fellow at Stanford Law School’s Center for Internet & Society. Further Info: Download the Firefox browser: https://www.mozilla.org/en-US/firefox/new/ Donate to Mozilla Foundation: https://donate.mozilla.org/en-US/ Pre-order the 4th edition of my book: https://www.amazon.com/gp/product/148426188 Enter my book giveaway! http://bit.ly/firewalls4

Sep 7, 202038 min

Firefox Privacy (Part 1)

If you really care about online privacy, you can’t use Google’s Chrome browser. Google is an advertising company. Everything else they do is in support of that core business. If you want a secure, fast browser that is actually focused on protecting your privacy, you want to be using Mozilla’s Firefox browser. Today I’ll be speaking with Mozilla’s Chief Security Officer, Marshall Erwin. We’ll trace Firefox’s heritage back to the stalwart Netscape Navigator and then dive into the ugly world of ubiquitous web tracking, by both governments and corporations. Are we really going dark? Why is privacy important? Are targeted ads really worth that much more than “dumb” ads? Marshall Erwin is the Chief Security Officer at the Mozilla Corporation, where he leads teams responsible for protecting Mozilla and its users. He also drives policy initiatives on encryption, government vulnerability disclosure, malicious online content, and online political advertising, as well as product initiatives to protect people from pervasive web tracking. Prior to joining Mozilla, Marshall worked in a variety of positions related to technology policy, cybersecurity, and national security more broadly. He began his career in national security, an analyst covering counterterrorism and cybersecurity. He also served as the counterterrorism and intelligence adviser on the Senate Homeland Security and Government Affairs Committee and as the intelligence specialist at the Congressional Research Service, focusing on National Security Agency surveillance programs and legislative changes to FISA statute. Marshall is a current Non-Residential Fellow at Stanford Law School’s Center for Internet & Society. Further Info: Firefox browser: https://www.mozilla.org/en-US/firefox/new/ Donate to Mozilla Foundation: https://donate.mozilla.org/en-US/ Pre-order the 4th edition of my book: https://www.amazon.com/gp/product/1484261887

Aug 31, 202036 min

Apple’s Epic Battle

Epic – the maker of the massively popular game Fortnite – has thrown down the proverbial gauntlet. It has decided that it no longer wishes to cut Apple in for 30% of its profits… Which is exactly what all app developers do – and have explicitly and contractually agreed to do – in return for using Apple’s platform, tools, software development kits, and security testing. Apple provides this and access to billions of users. Microsoft, Sony and Google charge the same 30% in their app stores. But Epic claims that Apple’s cut is too much, and has deliberately picked a legal fight with Apple (and Google) to try to get more favorable terms or be allowed to run a private Epic store. It’s complex and nuanced, but I’ll wade into the muddy and turbulent waters on today’s show. In other news: There’s a tricky new Outlook email phishing scam going around, Jack Daniels has been hacked and asked to pay millions in ransom, Google had a big outage, your location data is for sale to corporations as well as government agencies (bypassing the need for court orders and warrants), and I’ll cover a couple interesting Android security stories from the recent DEFCON and BlackHat security conferences. Further Info: Scan suspicious files online: www.virustotal.com

Aug 24, 20201h 0m

This is Why We Can’t Have Nice Things (part 2)

Can Facebook or Google really promise to keep your data private in this era of mass surveillance by the likes of the NSA and GCHQ? Max Schrems doesn’t think so, and he’s convinced the EU Court of Justice of the same thing. There’s no way to protect user data when intelligence agencies are hoovering up all our communications and storing them on massive server farms forever. In part 2 of my chat with EFF’s Danny O’Brien, we’ll talk about the two Shrems cases in the EU and what the recent ruling against Privacy Shield will mean for all of us. Danny O’Brien has been an activist for online free speech and privacy for over 20 years. In his home country of the UK, he fought against repressive anti-encryption law, and helped found the Open Rights Group, Britain’s own digital rights organization. He was EFF’s activist from 2005 to 2007, its international outreach coordinator from 2007-2009, and international director from 2013-2019. He now supervises EFF’s medium and long-term strategy, with an eye to maintaining the organization’s global impact and reputation. Further Info: EU Court Again Rules That NSA Spying Makes U.S. Companies Inadequate for Privacy: https://www.eff.org/deeplinks/2020/07/eu-court-again-rules-nsa-spying-makes-us-companies-inadequate-privacy None of Your Business: https://noyb.eu/en  Donate to EFF: https://supporters.eff.org/donate/join-eff-today

Aug 17, 202038 min

This is Why We Can’t Have Nice Things (part 1)

What good are privacy laws when we all know that intelligence agencies don’t play by the rules? How can any company promise to keep our data safe when we know that agencies like the NSA and GCHQ are hoovering it all up? That’s the essential argument behind the Max Schrems cases at the European Court of Justice. And the EU court agrees. In part 1 of my interview with EFF’s Danny O’Brien, we’ll talk about how we got here and how the parallel development of data mining and mass surveillance led us to these (successful) court challenges. Danny O’Brien has been an activist for online free speech and privacy for over 20 years. In his home country of the UK, he fought against repressive anti-encryption law, and helped found the Open Rights Group, Britain’s own digital rights organization. He was EFF’s activist from 2005 to 2007, its international outreach coordinator from 2007-2009, and international director from 2013-2019. He now supervises EFF’s medium and long-term strategy, with an eye to maintaining the organization’s global impact and reputation. Further Info: EU Court Again Rules That NSA Spying Makes U.S. Companies Inadequate for Privacy: https://www.eff.org/deeplinks/2020/07/eu-court-again-rules-nsa-spying-makes-us-companies-inadequate-privacy Donate to EFF: https://supporters.eff.org/donate/join-eff-today

Aug 10, 202041 min

The Pros & Cons of Antivirus Software

When most people think of protecting their computers, they think of antivirus software. Viruses are a real problem, of course, but how well do antivirus (AV) apps protect you? And are there any downsides to using AV software? Turns out there are plenty – so many that the cons probably outweigh the pros for most people, on Apple Mac or on Windows PC. Don’t believe me? Listen to this show and then decide. In other news: Google is finally bringing its Google One storage app to iOS, but don’t use it; Netgear has declared that at least 45 of their highly vulnerably routers will never be fixed; and if you’ve purchased anything from Amazon, you have a public profile – and you should review what others can see about you. Further Info: Cryptomator: https://cryptomator.org/ Sync.com secure cloud storage Netgear routers you should get rid of: https://www.tomsguide.com/news/netgear-routers-no-fixes My “pros & cons of AV” article: https://firewallsdontstopdragons.com/the-pros-and-cons-of-anti-virus-software/

Aug 3, 202042 min

The Great Twitter Hack

Last week, Twitter was massively hacked – apparently just to launch a Bitcoin scam (though that story is still developing). Famous people’s accounts were taken over, including Joe Biden, Barack Obama, Bill Gates, Elon Musk and several popular brand name accounts. (President Trump’s account was not taken over due to enhanced security measures.) But beyond the details of the hack, we need to look at the bigger picture and what this hack should be telling us about these totally unregulated social media giants with zero accountability. We’ll dig into that in today’s show. In other news: account credential dumps have significantly increased on the dark web, including over 140 million MGM Resort creds; Windows 10 suffers another maddening bug, but there’s a workaround; Signal has stirred up a lot of controversy with a recent change; a massive wifi router study revealed widespread security problems; and I’ll go over some of the cool new privacy features coming in iOS 14 and macOS Big Sur. Further Info: Windows 10 “No Internet Connection” workaround: https://lifehacker.com/how-to-fix-windows-10s-latest-no-internet-connection-bu-1844458254 Fraunhofer Institute router security report: https://github.com/fkie-cad/embedded-evaluation-corpus/blob/master/2020/FKIE-HRS-2020.md

Jul 27, 202054 min

Your Money or Your Data (part 2)

In the second part of my interview with Renee Dudley from ProPublica, we delve into the cyber insurance and ransomware incident response industries, including how some of these companies are being less than forthcoming about their services. In fact, it appears that several “incident response” companies are simply paying the ransom and then charging companies a fee on top of that. We’ll talk about how cyber insurance works and how to decide whether or not it’s for you. And Renee will also give us some tips on choosing an incident response firm and what red flags to watch out for. Renee Dudley is a tech reporter at ProPublica. Before joining ProPublica in 2018, she was a member of the enterprise team at Reuters, where she reported extensively on issues with college-entrance exams. Before joining Reuters in 2015, she worked as a reporter in New York for Bloomberg News and in South Carolina for The (Charleston) Post and Courier and The (Hilton Head) Island Packet. At Bloomberg, she uncovered questionable accounting and unauthorized sales practices at Walmart Inc. In Charleston, her reporting led to the indictment and resignation of South Carolina’s most powerful politician. She received the Society of Professional Journalists’ Pulliam Award in 2010 for her work upholding First Amendment rights while reporting for The Island Packet. Further Information: ProPublica on ransomware: https://www.propublica.org/article/the-extortion-economy-how-insurance-companies-are-fueling-a-rise-in-ransomware-attacks Mike Gillespie to the rescue: https://www.propublica.org/article/the-ransomware-superhero-of-normal-illinois ID Ransomware: https://id-ransomware.malwarehunterteam.com/ No More Ransom: https://www.nomoreransom.org/ Bleeping Computer: https://www.bleepingcomputer.com/

Jul 20, 202032 min

Your Money or Your Data (part 1)

Unless you’ve been living under a rock, you know that ransomware is one of the most common and most lucrative cybersecurity rackets today. But despite all the press, ransomware is massively under-reported because companies don’t want bad press. And in most cases, unless it can be proven that data was actually stolen, companies are under no legal obligation to inform the data subjects (you) of these hacks. In part one of my interview with Renee Dudley from ProPublica, we’ll discuss the current state of the ransomware problem and the emergence of cyber insurance and incident response companies to deal with the threat and recover from attacks. And we’ll also see that not all players are above board about what they do. Renee Dudley is a tech reporter at ProPublica. Before joining ProPublica in 2018, she was a member of the enterprise team at Reuters, where she reported extensively on issues with college-entrance exams. Before joining Reuters in 2015, she worked as a reporter in New York for Bloomberg News and in South Carolina for The (Charleston) Post and Courier and The (Hilton Head) Island Packet. At Bloomberg, she uncovered questionable accounting and unauthorized sales practices at Walmart Inc. In Charleston, her reporting led to the indictment and resignation of South Carolina’s most powerful politician. She received the Society of Professional Journalists’ Pulliam Award in 2010 for her work upholding First Amendment rights while reporting for The Island Packet. Further Information: ProPublica on ransomware: https://www.propublica.org/article/the-extortion-economy-how-insurance-companies-are-fueling-a-rise-in-ransomware-attacks Mike Gillespie to the rescue: https://www.propublica.org/article/the-ransomware-superhero-of-normal-illinois ID Ransomware: https://id-ransomware.malwarehunterteam.com/ No More Ransom: https://www.nomoreransom.org/ Bleeping Computer: https://www.bleepingcomputer.com/

Jul 13, 202033 min

TikTok Boom

TikTok is the hot new social media service (Snapchat and Instragram are so last year), particularly in Asian countries like India. But India just banned this and several other apps from China over privacy concerns – and I have a feeling they won’t be the last. The TikTok app was just revealed to be copying the user’s clipboard contents every few seconds for some completely unknown reason (and TikTok’s explanation was lame). While it has supposedly “fixed” this, another researcher claims to have reverse engineered the TikTok app and found that it’s pulling all sorts of other user data – enough to put Facebook and Google to shame. Short answer? Delete this app. And there’s a ton of other news this week: Zoom changes course on end-to-end encryption for free users, with a couple catches; I have more info on the recent Netgear router vulnerability affecting dozens of their products; Adobe Flash will be erased from the Earth by year’s end; Oracle’s BlueKai data mining subsidiary left a ton of personal data exposed with no password; Sen. Sherrod Brown (D-Ohio) has a wonderful privacy proposal that will probably never pass Congress; new Mac malware uses a trick to get around Apple’s app security; Microsoft shoves its new Edge browser down its users’ virtual throats; and Comcast is the first ISP to qualify for Mozilla’s Trusted Recursive Resolver program (DNS over HTTPS) and might switch out Cloudflare without asking you. Further Info: Netgear router fix info: https://bit.ly/netgear-fix https://bit.ly/netgear-passwords Humble Bundle – LAST CHANCE! https://www.humblebundle.com/books/protect-your-stuff-apress-books

Jul 6, 202053 min

COVID19 Privacy: Pro Tips (part 2)

In the second half of my interview with Eduard Goodman and Adam Levin from Cyberscout, we discuss the privacy aspects of our new work- and learn-from-home reality. How much privacy should you really expect? What are your legal rights? What should we beware of when using a single device for both work and personal things? How much should companies be willing to spend to make sure their employees and intellectual property are well protected while working from home? How do we avoid, as a democracy, giving up too much privacy with hopes it will make us more secure? Will we ever get that privacy back? We discuss all of this and much more! Eduard Goodman is the Chief Legal Counsel and Global Privacy Officer for CyberScout, a global leader in identity theft resolution, data defense and employee benefits services. An internationally trained attorney and data protection expert, Goodman has more than twenty years of experience in global privacy law and cybersecurity. Adam Levin is a consumer advocate with more than 30 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. He is also the author of the book Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves. Further Info: CyberScout: https://www.cyberscout.com/en My Apress Humble Bundle: https://www.humblebundle.com/books/protect-your-stuff-apress-books Patreon: https://www.patreon.com/FirewallsDontStopDragons

Jun 29, 202043 min

COVID19 Security: Pro Tips (part 1)

Today I speak with not one but two experts on security and privacy to get their insights, stories and tips on staying safe from scammers and hackers in our new COVID19 pandemic reality. These guys have dealing with cyber incidents every day and bring some unique perspectives. In some ways, it’s same stuff, different day; but the pandemic, economy woes and general civil unrest have given the bad guys some fertile material for working their craft. Eduard Goodman is the Chief Legal Counsel and Global Privacy Officer for CyberScout, a global leader in identity theft resolution, data defense and employee benefits services. An internationally trained attorney and data protection expert, Goodman has more than twenty years of experience in global privacy law and cybersecurity. Adam Levin is a consumer advocate with more than 30 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. He is also the author of the book Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves. Further Info: CyberScout: https://www.cyberscout.com/en My Apress Humble Bundle: https://www.humblebundle.com/books/protect-your-stuff-apress-books Patreon: https://www.patreon.com/FirewallsDontStopDragons

Jun 22, 202041 min

From Mailbox to Ballot Box

With the US general election just over 20 weeks away and no vaccine in sight for the coronavirus, it’s time to think very seriously about how you’re going to vote. Even if you think you want to vote in person this November, you should have a backup plan: voting by mail. This means that you’ll need to register for an absentee ballot – and the sooner you do so, the better prepared your state and county will be. I’ll tell you everything you need to know to get your absentee ballot. In other news: Microsoft, IBM and Amazon have taken very welcome steps to curbing the use of facial recognition for law enforcement purposes; the FBI is once again warning us about banking hacks, this time related to mobile apps; the Brave browser was busted “accidentally” trying to cash in on your browsing; Google is being sued for $5B over its Chrome browser tracking while in incognito mode; and Zoom is rolling out full end-to-end encryption on its video conferencing solution… if you’re willing to pay. Further Info: Get your absentee ballot: https://www.vote.org/ Support election reform: https://www.verifiedvoting.org/ Support fair and open voting: https://fairfight.com/ Vote at home: https://www.voteathome.org/

Jun 15, 202045 min

Fiber For Our Future (part 2)

We’ve established that we have a high speed internet access problem – now what can we do about it? In part 2 of my interview with the EFF’s Ernesto Falcon, we’ll talk about how broadband fiber-based internet is a critical piece of national infrastructure, not unlike the highway system. It enables and supports industry and innovation, and ubiquitous access would greatly increase our ability to learn and work remotely. We talk about the politics and economics behind all of this, including some interesting solutions involving both the government and private corporations. Ernesto Falcon is Senior Legislative Counsel at the Electronic Frontier Foundation with a primary focus on intellectual property, open Internet issues, broadband access, and competition policy. He represents EFF’s advocacy, on behalf of its members and all consumers, for a free and open Internet before state legislatures and Congress. Ernesto’s work includes pushing the state of California to pass the strongest net neutrality law in the country in response to federal repeal efforts, as well as leading EFF’s research and advocacy to promote universally available, affordable, and competitive fiber broadband networks. Further Info: Electronic Frontier Foundation: https://www.eff.org/ Why cable companies hate California’s SB1130 bill: https://www.eff.org/deeplinks/2020/05/why-cable-companies-oppose-californias-universal-fiber-effort-sb-1130

Jun 8, 202034 min

Fiber For Our Future (part 1)

The COVID-19 era has exposed several weaknesses in American infrastructure and exacerbated the gulf between the haves and the have-nots. Perhaps nowhere is this more evident than the digital divide: access to high speed internet. While much of the country was able to work and learn from home, for too many communities this was simply not an option due to poor or non-existent broadband access. In today’s show, Ernesto Omar Falcon from the EFF explains the political and economic reasons we got into this mess. Ernesto Falcon is Senior Legislative Counsel at the Electronic Frontier Foundation with a primary focus on intellectual property, open Internet issues, broadband access, and competition policy. He represents EFF’s advocacy, on behalf of its members and all consumers, for a free and open Internet before state legislatures and Congress. Ernesto’s work includes pushing the state of California to pass the strongest net neutrality law in the country in response to federal repeal efforts, as well as leading EFF’s research and advocacy to promote universally available, affordable, and competitive fiber broadband networks. Further Info: Electronic Frontier Foundation: https://www.eff.org/ Why cable companies hate California’s SB1130 bill: https://www.eff.org/deeplinks/2020/05/why-cable-companies-oppose-californias-universal-fiber-effort-sb-1130

Jun 1, 202033 min

Apple vs FBI, Part 2

The FBI is once again trash-talking Apple for not helping them in their investigation of a terrorist – this time, the alleged perpetrator of the Pensacola shooting. However, like the San Bernardino shooting a few years ago, Apple has actually done everything in its power to aid law enforcement. The issue is the “in its power” part. The FBI and DOJ would prefer that Apple (and therefore they) would have more power to unlock and decrypt iOS devices. We’ll discuss this and a recent ruling against the FBI in another phone-related case. In other news: the Senate narrowly defeated a bill amendment that would protect your web history from government surveillance; 83% of users store their passwords in their heads (meaning their passwords suck); Firefox will soon tell you when sign-up forms are truncating your long passwords; Microsoft warns of a nasty new COVID-19-related phishing scheme that can take over your entire computer; and secure messaging app Signal has added a new security PIN to protect your account and make transferring to a new device easier.

May 25, 202038 min

Beware the Evil Maid

Intel created the Thunderbolt protocol to give us blazingly fast data transfer and other interesting features. Thunderbolt usually comes with the newer USB-C ports, common on laptops, especially Macbooks. Unfortunately, researchers have found a major flaw affecting all computers that will allow bad guys to gain access to your computer in just a few minutes with a few hundred dollars of common equipment. Most computers built in 2019 and later are capable of blocking this attack, but not many have implemented it. Apple computers are safe, unless they’re in Bootcamp mode running Windows or Linux. I’ll go over the details of this “evil maid” attack and provide several tips for securing your computers. In other news: Mozilla is adding a couple cool new privacy features to Firefox; Microsoft is rolling out some security and privacy in its coming May release; Google Authenticator finally provides a way to transfer accounts (sorta); Clearview AI is quickly backpedaling is data collection on Illinois residents; and Bruce Schneier explains why the Apple/Google contact tracing app will be basically useless. Further Info: My Duke OLLI lecture on COVID19 scams and privacy: https://duke.zoom.us/rec/share/-pFnFpPwz31LZ9Lg72CPX58rIdTaX6a82ncZ_qAKnn7ycTkgCcknURAXsgLmOR0

May 18, 202046 min

COVID19 Security & Privacy Tips (Part 2)

In part two of my interview with Malwarebyte’s David Ruiz, he tells us how to avoid the scams we discussed last week. And then we move on to discuss the potentially serious privacy issues that could come from the emerging surveillance regimes, designed to help us curb the spread of the coronavirus. David Ruiz is a content writer for Malwarebytes, covering online privacy, cybersecurity, and the laws – and proposed legislation – that regulate how data is stored, shared and accessed. He previously worked for Electronic Frontier Foundation, where he wrote and analyzed policy about NSA surveillance, encryption, and cross-border data transfer. Further Info: Malwarebytes blog: https://blog.malwarebytes.com/author/davidruiz/ Malwarebytes antivirus: https://www.malwarebytes.com/for-home/products/ Malwarebytes “Lock and Code” podcast: https://podcasts.apple.com/us/podcast/lock-and-code/id1500049667

May 11, 202036 min

COVID19 Security & Privacy Tips (Part 1)

In times of great fear and anxiety, we need to be especially vigilant against snail oil salesmen. Never letting a good crisis go to waste, the bad guys are capitalizing on the chaos to lure us into downloading malware and buying fraudulent (or even harmful) advice and products. In part one of my interview with Malwarebyte’s David Ruiz, we talk about the explosion of COVID-19-related phishing scams and malware campaigns, including tips on how to avoid being a victim. David Ruiz is a content writer for Malwarebytes, covering online privacy, cybersecurity, and the laws – and proposed legislation – that regulate how data is stored, shared and accessed. He previously worked for Electronic Frontier Foundation, where he wrote and analyzed policy about NSA surveillance, encryption, and cross-border data transfer. Further Info: Malwarebytes blog: https://blog.malwarebytes.com/author/davidruiz/ Malwarebytes antivirus: https://www.malwarebytes.com/for-home/products/

May 4, 202033 min

Have You Been Pwned?

Every time there’s a data breach at a company or service where you do business, there’s a chance that the bad guys will reverse engineer your password. And once they do that, they will almost surely try to use that email and password combination to log into dozens of other sites – a hacking technique called credential stuffing. And why do they do this? Because they know most people reuse the same password over and over again. Troy Hunt has created a free service called “Have I Been Pwned” that collects information from all of these breaches so that we can find out whether our email address has been included in any of these hacks. I originally interviewed Troy over a year ago on the topic of database breaches and how to protect yourself against them, and sadly this is just as relevant today as it was then. So I brought this back as an encore performance! Troy Hunt is an Australian Microsoft Regional Director and Microsoft Most Valuable Professional for Developer Security. You’ll regularly find Troy in the press talking about security and even testifying before US Congress on the impact of data breaches. Further Info HaveIBeenPwned.com Ethics of running a data breach search service: https://www.troyhunt.com/the-ethics-of-running-a-data-breach-search-service/ Authentication evolved: https://www.troyhunt.com/passwords-evolved-authentication-guidance-for-the-modern-era/

Apr 27, 202054 min

Phish Spotting 101

The bad guys are having a field day with all the coronavirus hubbub, using our fears and anxieties to trick us into clicking bad links, downloading infected files, or installing malware. While the topic is new, the techniques are the same: phishing. Using cleverly disguised emails and text messages, bad guys trick us into giving up credit card and social security numbers, login credentials, and other sensitive information. In today’s show, I’ll give you several ways to spot these scams. In other news: a new massive data breach contains records on 1.2 billion people; Microsoft released a new version of Windows Defender which is broken for some people; there’s been an attack on some Linksys routers; and as if regular ransomware wasn’t bad enough, the bad guys are now using a new “double extortion” tactic that really puts you in a bind. Further Info: Flatten the Curve Summit: https://flattenthecurve.tech/

Apr 20, 202042 min

Contact Tracing, Privately

As health services and society in general struggle to cope with the coronavirus pandemic, people are desperately seeking new and inventive ways to curb the spread of the disease. A tried and true tool of epidemiologists is contact tracing: interviewing infected subjects in order to create lists of people they’ve had contact with in recent days and weeks. But people’s memories are notoriously sketchy and they may not even know all the names, let alone contact information. Google and Apple have united to propose a technical solution. Android phones and iPhones will silently record anonymous identifiers of every other device they come near, in hopes of eventually notifying those device owners if a person later tests positive for COVID-19. But doing this in a way that preserves privacy and resists mass surveillance is difficult. I’ll walk through the technical and social implications of their proposal. In other news: Zoom is working hard to fix their privacy and security issues (and repair their reputation); bad guys are capitalizing on Zoom’s popularity to trick users into installing malware along with the app; smart locks can actually be pretty stupid (and insecure); and now that we’re all working from home, it’s a good time to review standard security practices to keep your company’s data and devices secure. (And by the way, this is good practice for your personal stuff, too.) Further Info: Remote working security checklist: https://doist.com/blog/security-checklist-remote-workers/ VeraCrypt hard drive encryption app: https://www.veracrypt.fr/

Apr 13, 202046 min

Secure & Private Social Distancing

During our global COVID-19 self-quarantining, video conferencing usage has exploded. I’ve tried to find hard statistics, but they’re rising so fast that anything I post now will be stale tomorrow. That said, I’ve seen usage growth figures as high as 400%. And since we’re all staying home now (right?), video chatting is a great way to get some some social time with friends and family. But many of the most popular video chat services are lacking in security, privacy, or both (I’m looking at you, Zoom). I’ll give you a handful of good options that are all end-to-end encrypted. In other news: over 12,000 Android apps were found to have some sort of backdoor; Cloudflare introduces 1.1.1.1 for Families; Marriott announces yet another major data breach; Google is using its vast hoard of location data to track our social distancing success (or failure); EFF issues some timely warnings about guarding our civil liberties when responding to this crisis; and the FBI is warning us to watch out for coronavirus-related scams. Further Info: Zoom alternatives and online gaming: https://firewallsdontstopdragons.com/secure-private-zoom-alternatives/ Flatten the Curve Summit: https://flattenthecurve.tech/ 1.1.1.1 for Families: https://blog.cloudflare.com/introducing-1-1-1-1-for-families/

Apr 6, 202035 min

Privacy by Design

Wouldn’t it be nice if privacy wasn’t an afterthought? What if user privacy was built in from the get go? What if the entire design assumed that you didn’t want anyone selling your data – and respected those wishes? That’s the world of Privacy by Design – a concept pioneered in the mid-1990’s by Dr. Ann Cavoukian. This may seem like an unattainable Utopian future, but Ann’s infectious optimism may just convince you otherwise. Adding privacy doesn’t mean sacrificing security or functionality, if done properly. Today we discuss the concepts of Privacy by Design and how we can achieve it. Dr. Ann Cavoukian is recognized as one of the world’s leading privacy experts. Dr. Cavoukian served an unprecedented three terms as the Information & Privacy Commissioner of Ontario, Canada. There she created Privacy by Design, a framework that seeks to proactively embed privacy into the design specifications of information technologies. In 2010, International Privacy Regulators unanimously passed a Resolution recognizing Privacy by Design as an International Standard. Since then, PbD has been translated into 40 languages! In 2018, PbD was included in a sweeping new law in the EU: the General Data Protection Regulation. Dr. Cavoukian is now the Executive Director of the Global Privacy & Security by Design Centre. Further Info: Global Privacy & Security: https://gpsbydesigncentre.com/about-us/ Fight the EARN IT Act: https://act.eff.org/action/protect-our-speech-and-security-online-reject-the-graham-blumenthal-bill

Mar 30, 202047 min

Beware COVID-19 Scams

Never let a good crisis go to waste. Though normally applied to politics, it can be equally applied to opportunistic cyber criminals. With the world transfixed by and anxious about this nasty virus, bad guys are seizing on our fears to make a quick buck. From ransomware-laden virus tracking apps to actually threatening to infect families directly with the actual virus, COVID-19 is becoming a gold mine for unscrupulous hackers. We need to be extra vigilant and warn our loved ones to do the same. In other news… connected cars are tapping into your driving data to make more money; a $3 robot lawyer can help you exercises your CCPA rights; the Brave browser will be implementing some novel fingerprinting protections; Firefox had created a privacy container for Facebook; and not to miss a good crisis, the US government is looking to weaken our civil liberties in the name of virus tracking.

Mar 23, 202054 min

The CCPA and You (Part 2)

In part 1 of this interview, Hayley Tsukayama walked us through the details of the new California Consumer Privacy Act (CCPA). In part 2, we discuss how this law will affect many of us who are not California residents and how it’s influencing potential legislation in other states and even at the federal level. We also discuss how CCPA can synergize with other state laws and be used as a tool for journalists to expose data brokers to the light of scrutiny. Hayley Tsukayama is a legislative activist for the Electronic Frontier Foundation, focusing on state legislation. Prior to joining EFF, she spent nearly eight years as a consumer technology reporter at The Washington Post writing stories on the industry’s largest companies. Hayley has an MA in journalism from the University of Missouri and a BA in history from Vassar College. She was a 2010 recipient of the White House Correspondents’ Association scholarship. Further Info Donate to the EFF: https://supporters.eff.org/donate/ Robot Lawyer to sue data hoarders: https://fortune.com/2020/03/05/delete-location-data-privacy-personal-information-donotpay/ My book is on sale for $18: https://www.apress.com/us/book/9781484238516

Mar 16, 202028 min

The CCPA and You (Part 1)

On January 1st, 2020, the California Consumer Privacy Act (CCPA) went into effect. While not perfect, the CCPA is a landmark piece of legislation for the United States, even though legally it only protect California residents. I will dig into the details of this bill – both the good and the bad – in part one of my delightful interview with Hayley Tsukayama from the EFF. Hayley Tsukayama is a legislative activist for the Electronic Frontier Foundation, focusing on state legislation. Prior to joining EFF, she spent nearly eight years as a consumer technology reporter at The Washington Post writing stories on the industry’s largest companies. Hayley has an MA in journalism from the University of Missouri and a BA in history from Vassar College. She was a 2010 recipient of the White House Correspondents’ Association scholarship. Further Info Donate to the EFF: https://supporters.eff.org/donate/ Robot Lawyer to sue data hoarders: https://fortune.com/2020/03/05/delete-location-data-privacy-personal-information-donotpay/

Mar 9, 202035 min

Hacked: A Clearer View of Clearview

A few weeks ago, the New York Times published a bombshell article about a small startup called Clearview AI who was using a massive database of three billion faces scraped from several social media sites to offer a creepy facial recognition app. Just one snapshot of some stranger’s face could immediately identify that person – not just name, but potential location, age, other images, social media pages, and even a list of friends and family. Clearview claimed to only sell this service to law enforcement agencies, mostly in the US and Canada. However, this week Buzzfeed News obtained the company’s client list, and it contained several non-law enforcement agencies and dozens of clients outside of North America. In other news: the latest Windows 10 update has caused many serious problems; leaked documents show how big companies are buying our credit card data; up to a billion WiFi devices have a critical security bug; the FCC says it will fine the four big US cellular carriers $200M for selling your location data; and several news bits about browsers: Brave, Chrome and Firefox. Further Info: The Secretive Company That Might End Privacy as We Know It: https://www.nytimes.com/2020/01/18/technology/clearview-privacy-facial-recognition.html Public DNS providers supporting DNS over HTTPS: https://github.com/curl/curl/wiki/DNS-over-HTTPS WaPo: The Intelligence Coup of the Century: https://www.washingtonpost.com/graphics/2020/world/national-security/cia-crypto-encryption-machines-espionage/ WNCU Livestream (Sun Mar 8, 6:30pm ET): http://www.wncu.org/listen-live/ The Measure of Everyday Life podcast: https://podcasts.apple.com/us/podcast/the-measure-of-everyday-life/id956844695

Mar 2, 202048 min

Adversarial Interoperability (Part 2)

it’s not cheap or easy to get your iPhone repaired – largely because there’s not a lot of real competition in the iPhone repair market. That’s no accident. Owners of modern John Deere tractors have really only one option: John Deere. Why? There’s no good technical reason. There’s really no good legal reason either, but laws like the Digital Millennium Copyright Act (DMCA) and the Computer Fraud and Abuse Act (CFAA) have been abused to give these companies inordinate say over who can perform repairs on their products. In part 2 of my interview with the EFF’s Cory Doctorow, we discuss the right to repair and wrap up our overall discussion with possible solutions and action items for the concerned consumer. Cory Doctorow is a science fiction author, activist, journalist and blogger. He’s the author of several novels including HOMELAND, LITTLE BROTHER and WALKAWAY. He is the former European director of the Electronic Frontier Foundation and co-founded the UK Open Rights Group. Further Info: Adversarial Interoperability: https://www.eff.org/deeplinks/2019/10/adversarial-interoperability Donate to EFF: https://supporters.eff.org/donate Electronic Frontier Alliance: https://www.eff.org/fight

Feb 24, 202030 min

Adversarial Interoperability (Part 1)

Here’s a riddle for you: when does something you paid good money not actually belong to you? Answer: when that device is part of the Internet of Things. Why? Because without the express permission and continued support of the company that sold you that device, it becomes a worthless piece of junk. All of our modern “smart” devices are inextricably tied to their cloud-based services and automatic software updates. In part 1 of my interview with Cory Doctorow, we’ll talk about how we got into this situation, including several shocking examples. Cory Doctorow is a science fiction author, activist, journalist and blogger. He’s the author of several novels including HOMELAND, LITTLE BROTHER and WALKAWAY. He is the former European director of the Electronic Frontier Foundation and co-founded the UK Open Rights Group. Further Info: Adversarial Interoperability: https://www.eff.org/deeplinks/2019/10/adversarial-interoperability Donate to EFF: https://supporters.eff.org/donate

Feb 17, 202048 min

Tax Time Brings Tax Scams

It’s that time of year again: tax time! And that means it’s also time for tax scams. I’ll give you some tips on how to avoid them, and also help you find the real “Free File” versions of your favorite online tax filing software. In other news: a German man fooled Google Maps with a wagon full of phones; Hue smart bulbs patched a serious vulnerability; Ring doorbell offers more security and privacy controls; a nasty Android Bluetooth vulnerability found and fixed; extracting data from a computer using screen brightness; and the US government’s use of third-party location trackers. Further Info ProPublica interview on history of Free File: http://podcast.firewallsdontstopdragons.com/2020/01/13/why-free-file-isnt-free/ Free File: https://firewallsdontstopdragons.com/how-to-really-free-file-your-taxes/ Avoid tax scams: https://firewallsdontstopdragons.com/preventing-tax-return-fraud/ Winston Privacy: https://winstonprivacy.com/

Feb 10, 202051 min

Just Say No (to Sharing)

We install antivirus software to protect us, not exploit us. Like a bodyguard, AV programs needs full, unfettered access to everything in order to properly do the job. That requires complete and absolute trust. And probably a non-disclosure agreement. Unfortunately, antivirus software doesn’t offer you an NDA promise. Avast, the maker of one of the top five AV software applications, has recently been shown to collect and sell entensive customer information to third parties. While they claim to anonymize the data, it’s often easy to re-identify people when correlating this data with other databases. Thanks to some reporting by Vice and PCMag, Avast is shutting down this lucrative side business after a serious backlash. I’ll tell you how you can mitigate your exposure to rampant data sharing. In other news, Sonos angers many long-time customers by declaring an end to supporting older devices; over 250M customer records have been exposed on five public servers with zero protections for about 14 years; Clearview, the company boasting a database of 3B face photos, has come under fire from social media companies and the US Congress; iOS 13 and Android 10 location privacy restrictions have dropped location tracking by nearly 70%; and Mozilla has banned almost 200 plugins for tracking users and violating its malware policies.

Feb 3, 202043 min

Data Privacy Day 2020

Happy Data Privacy Day! My guest today is none other than Bruce Schneier: world renowned security guru and author of several great books, including the Data and Goliath and Click Here to Kill Everybody! Bruce and I discuss the current state of data privacy and what it’s going to take to rein in the corporations that are buying and selling our data with abandon. Bruce Schneier is an internationally renowned security technologist Bruce Schneier has authored over one dozen books–most recently Click Here to Kill Everybody–and hundreds of articles, essays, and academic papers. His influential newsletter Crypto-Gram and his blog Schneier on Security are read by over 250,000 people. Further Information: Transcript of my interview with Bruce Schneier: http://podcast.firewallsdontstopdragons.com/wp-content/uploads/2019/01/Ep100-interview.txt Data Privacy Day Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/

Jan 27, 202050 min

Clearview Knows Who You Are

A small company has amassed over 3 billion online photos from social media and other public sources, creating perhaps the largest facial database in existence – far larger than even the FBI’s database. The images are often connected to a person’s full name, address, and people they know. The company, called Clearview, has sold access to this database to over 600 law enforcement agencies, allowing them to quickly identify someone from a single picture. While this has allowed them to solve several cases, it also means that we have basically lost the ability to be anonymous in public. There are no rules around this – but there need to be. In other news, if you haven’t updated Windows in the last week, you need to do it right now; same goes for Internet Explorer (though you should really just switch to Firefox); Apple and FBI are once again facing off over iPhone encryption; the vast majority of modern cable modems are vulnerable to a devastating hack; and for at least this year, you shouldn’t abbreviate with just “20” on anything important. Further Info: NY Times article on Clearview: https://www.nytimes.com/2020/01/18/technology/clearview-privacy-facial-recognition.html Sandboxie: https://www.sandboxie.com/ VirtualBox: https://www.virtualbox.org/ CableHaunt: https://cablehaunt.com/

Jan 20, 202031 min