PLAY PODCASTS
Firewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast

500 episodes — Page 8 of 10

Why “Free File” Isn’t Free

The IRS already knows what I made, what taxes I’ve paid, and even what my mortgage interest was last year. Why do I have to fill out tax forms? Turns out there’s a very specific reason, and you’re not going to like it. At the turn of the century, tax preparers like TurboTax and H&R Block negotiated a deal with the US government that prevented this very thing. In exchange, these tax companies agreed to offer a “Free File” online tax program for most tax filers. But while perhaps honoring the letter of that agreement, they used dark patterns and other subtle psychological tricks to push tax payers into pricey, unnecessary tax applications. Justin Elliott from ProPublica will explain the sordid history of “free” online tax preparation and the cat-and-mouse game companies like Intuit (maker of TurboTax) have been playing with regulators. Justin Elliott has been a reporter since 2012 with ProPublica, where he has covered money and influence in the Obama and Trump administrations, the American Red Cross and TurboTax maker Intuit. He has produced stories for outlets including The New York Times and National Public Radio, and his work has spurred congressional investigations and changes to federal legislation. Further Info: ProPublica Free File stories: https://www.propublica.org/series/the-turbotax-trap IRS official Free FIle site: https://www.irs.gov/filing/free-file-do-your-federal-taxes-for-free How to file for free: https://www.propublica.org/article/how-to-file-state-federal-taxes-free-2020

Jan 13, 202053 min

Time to Upgrade Windows

It’s not too late! You can still snag a free upgrade to Windows 10 from Microsoft. If you’re still running Windows 7, it’s time to avail yourself of this offer. Microsoft is ending support for Windows 7 on January 24, 2020. That means that you will no longer get software updates – in particular, security fixes. The official offer to upgrade to Windows 10 at no cost supposedly ended in July 2016, but Microsoft still offers a legitimate way to upgrade for free. I’ll tell you how. In other news, cybersecurity experts are on the alert following our lethal attack on a senior Iranian military figure, Facebook was again caught using your two-factor authentication mobile number for non-security purposes, there’s another massive leak of Facebook user data, Amazon blames its customers for Ring device hacks, a bug in GPS watches allows anyone to track your location, and the new California Consumer Privacy Act (CCPA) goes into effect. Further Info: Spread the Word: https://firewallsdontstopdragons.com/spread-the-word/ New Year’s Resolutions: https://firewallsdontstopdragons.com/2020-new-years-resolutions/ Upgrade to Win10 for free: https://www.zdnet.com/article/heres-how-you-can-still-get-a-free-windows-10-upgrade/ Protect Your Privacy on Windows 10: https://spreadprivacy.com/windows-10-privacy-tips/

Jan 6, 202047 min

2020 New Year’s Resolutions

2019 has come and gone, and 2020 is upon us! You know what that means: New Years Resolutions! I’ve put together a Top Ten list of suggestions that will significantly improve your computer security and online privacy! Some of these are easy and some are going to require some effort… but you have a whole year to do them! This will also be a great episode to forward to friends and family, introduce them to the show and help build up our “herd immunity”. Further Info 2020 New Years Resolutions blog: https://firewallsdontstopdragons.com/2020-new-year’s-resolutions/ Give Thanks and Donate: https://firewallsdontstopdragons.com/give-thanks-donate/ Key resources: https://firewallsdontstopdragons.com/resources/ Terms and Conditions May Apply: http://tacma.net/tacma.php Support me! https://www.patreon.com/FirewallsDontStopDragons

Dec 30, 201955 min

Behind the One-Way Mirror (part 2)

We know that we’re tracked, but what remains largely invisible is the massive economy working behind the scenes (or “mirror”) to buy, sell, trade and bid on you and your data. I’ve seen estimates that claim there are up to 4000 data brokers in the US alone. And what’s worse is that they are largely unregulated, making the data market a total free-for-all. What can you do to curb this tracking and selling of data? We’ll discuss that in the conclusion of my interview with the EFF’s Bennett Cyphers. Bennett Cyphers is a staff technologist on the Tech Projects team at the Electronic Frontier Foundation (EFF). He contributes to a variety of different projects within EFF, most of them tied to privacy and competition. In the past year, he’s worked on the tracker-blocking browser extension Privacy Badger, provided technical advice to lawyers and activists, and read and re-read the California Consumer Privacy Act. Before coming to EFF, he was a policy intern at Access Now and earned a Master’s degree for work on privacy-preserving machine learning. In his spare time he designs t-shirts for fake punk rock bands. Further Info EFF’s Behind the One-Way Mirror: https://www.eff.org/wp/behind-the-one-way-mirror  Setting Apple ID to zero (“limit ad tracking”): https://blog.tenjin.com/idfa-sends-all-zeros-on-ios-10-devices-2/ Best & Worst Gifts for 2019: https://firewallsdontstopdragons.com/best-worst-gifts-2019/ The Scoring of America: https://www.worldprivacyforum.org/wp-content/uploads/2014/04/WPF_Scoring_of_America_April2014_fs.pdf Corporate Surveillance in Everyday Life: https://crackedlabs.org/en/corporate-surveillance

Dec 23, 20191h 0m

Behind the One-Way Mirror (part 1)

If you’ve listened to even a handful of my shows, you are well aware that you’re being tracked around the web. But even I was surprised by some of the things I learned in the recent white paper from the Electronic Frontier Foundation entitled “Behind the One-Way Mirror: A Deep Dive Into the Technology of Corporate Surveillance”. One of the prime authors of this report, Bennett Cyphers, came on my show to walk us through the myriad and shocking ways that ad tech companies have found to identity us as we surf the web, use our smartphones, and even walk around the real world. Bennett Cyphers is a staff technologist on the Tech Projects team at the Electronic Frontier Foundation (EFF). He contributes to a variety of different projects within EFF, most of them tied to privacy and competition. In the past year, he’s worked on the tracker-blocking browser extension Privacy Badger, provided technical advice to lawyers and activists, and read and re-read the California Consumer Privacy Act. Before coming to EFF, he was a policy intern at Access Now and earned a Master’s degree for work on privacy-preserving machine learning. In his spare time he designs t-shirts for fake punk rock bands. Further Info EFF’s Behind the One-Way Mirror: https://www.eff.org/wp/behind-the-one-way-mirror Setting Apple ID to zero (“limit ad tracking”): https://blog.tenjin.com/idfa-sends-all-zeros-on-ios-10-devices-2/ Best & Worst Gifts for 2019: https://firewallsdontstopdragons.com/best-worst-gifts-2019/

Dec 16, 20191h 7m

Snail Mail Identity Theft

We don’t often think about the security and privacy of our regular old “snail mail”, but we need to. According to recent activity observed by researchers of the dark web, the bad guys have been regaining interest in identity theft schemes involving physical letters. And in many cases, they can steal your mail without ever opening your mailbox. I’ll tell you what you can do to reduce your risk. In other news, thousands of Disney+ accounts were hacked on the first day, a massive data breach exposed over a billion user records, PayPal is set to acquire shopping platform Honey for $4B, and Avast and AVG browser extensions are spying on Chrome and Firefox users.

Dec 9, 201938 min

Best & Worst Gifts for 2019

It’s that time of year again – time to see which popular gifts make my privacy/security Naughty and Nice lists! You want to make sure that when you’re giving gifts to your loved ones that you’re not also giving gifts to hackers and data miners! I’ll also start to catch you up on several of the news stories from the past few weeks including Google’s access to private medical info of tens of millions of people, a researcher finding 146 different Android bugs coming right out of the box, more creepy updates on the Ring Doorbell, and a very welcome federal court ruling about your rights at the US border.

Dec 2, 201959 min

Data vs. Democracy (Part 2)

Today in part 2 of my deeply insightful interview with author Kris Shaffer, we discuss how marketers and foreign powers have been capturing our attention and even manipulating our responses. We’ll discuss how these techniques were used in the 2016 US presidential election and in other critical voting situations. In many cases, it’s sufficient to make people stay home or to sow doubt in the election results. But we’ll also discuss whether some of these sames tools and techniques can be used to expose manipulation and tip the scales back in our favor. Kris Shaffer, PhD (Yale University, 2011), is a data scientist and Senior Computational Disinformation Analyst for Yonder. He co-authored “The Tactics and Tropes of the Internet Research Agency”, a report prepared for the United States Senate Select Committee on Intelligence about Russian interference in the 2016 U.S. presidential election. Kris has consulted for multiple U.S. government agencies, non-profits, and universities on matters related to digital disinformation, data ethics, and digital pedagogy. Kris is the author of Data versus Democracy: How Big Data Algorithms Shape Opinions and Alter the Course of History, published July 2019 by Apress. Further Info Data versus Democracy: https://www.apress.com/us/book/9781484245392 Kris Shaffer’s website: https://pushpullfork.com Weapons of Math Destruction: https://weaponsofmathdestructionbook.com/ Automating Inequality: https://virginia-eubanks.com/ The Great Hack: https://www.thegreathack.com/ Give Thanks and Donate: https://firewallsdontstopdragons.com/give-thanks-donate/

Nov 25, 201943 min

Data vs. Democracy (Part 1)

They say we are in the Information Age and that data is the new oil. But many (including my guest, Kris Shaffer) are saying that was is truly valuable today is attention, not information. Information is so plentiful now that it almost has no value. And because just about everything on the internet is free, we’re paying for it with our attention. Marketers have gone to great lengths to study human behavior and they know exactly how to get and keep our attention. Unfortunately, these techniques can also be used to distract us and manipulate us. We’ll discuss this and much more in today’s interview (part 1 of 2). Kris Shaffer, PhD (Yale University, 2011), is a data scientist and Senior Computational Disinformation Analyst for Yonder. He co-authored “The Tactics and Tropes of the Internet Research Agency”, a report prepared for the United States Senate Select Committee on Intelligence about Russian interference in the 2016 U.S. presidential election. Kris has consulted for multiple U.S. government agencies, non-profits, and universities on matters related to digital disinformation, data ethics, and digital pedagogy. Kris is the author of Data versus Democracy: How Big Data Algorithms Shape Opinions and Alter the Course of History, published July 2019 by Apress. Further Info Data versus Democracy: https://www.apress.com/us/book/9781484245392 Kris Shaffer’s website: https://pushpullfork.com Carey’s Best & Worst Gifts for 2019: https://firewallsdontstopdragons.com/best-worst-gifts-2019/

Nov 18, 201932 min

The Rise of Browser Fingerprinting

Marketing companies have come up with may clever ways to track our travels around the web, hoping to garner as much information about us as they can. At the same time, privacy-conscious organizations have given us tools to maintain our anonymity by countering these tracking technologies. It’s the usual arms race – one that privacy advocates were mostly winning, with VPN’s, blocking third party cookies, and privacy-enhancing browser plugins. But now we’re faced with the nuclear option: browser fingerprinting. Our browsers cough up dozens of detailed bits of information about us: OS type and version, browser type and version, fonts and plugins installed, monitor resolution, and much more. When taken together, this information creates a fingerprint of our system – one that is often very unique. Preventing this sort of fingerprinting is extremely difficult, making most of the above privacy-enhancing techniques useless. I’ll tell you how it works and what you can do to mitigate this. In other news: Facebook sues NSO Group for using WhatsApp to track people; Google buys FitBit (and all its data); Apple’s privacy website is revamped; Microsoft Office is building in much-needed protections against infected files; and researchers figure out how to hack Siri, Alexa and Google Home from afar using lasers.

Nov 11, 201938 min

Preventing & Mitigating Identity Theft

How are our identities stolen? What happens to our identity information after its been stolen? Once we realize we’ve been hacked, what can we do to mitigate the damage and recover from the consequences? I’ll discuss this and much more with Amyn Gilani from 4iQ – including why you shouldn’t be participating in all those fun social media quizzes. Amyn Gilani leads strategy and product at 4iQ. Previously, he was a Chief Technologist at Booz Allen Hamilton where he provided expertise to federal and commercial clients focusing on incident response, red teaming, threat hunting, and cybersecurity operations engineering. Prior to joining Booz Allen, Amyn was a Vice President in Information Security at Goldman Sachs where he led Red Team Operations and emulated sophisticated attacks against securities trading platforms and payment systems. He began his career serving in the United States Air Force as an intelligence analyst and was on detail at National Security Agency and United States Cyber Command. Further Info: 4iQ: https://4iq.com/ Report identity theft and other resources: https://www.identitytheft.gov/ Defending Digital podcast: https://defendingdigital.com/carey-parker-firewalls-dont-stop-dragons/

Nov 4, 201950 min

Dropping Dropbox

I’ve been a Dropbox user for many, many years. But recently, they’ve gotten really pushy – trying to get me to save all my photos and docs there, integrating with MS Office when I didn’t ask it to, and pushing me to upgrade. Now it tells me I need to deactivate all but three devices (I have probably 7-8). I’ve been looking for a secure and (more importantly) private alternative for a while now, and this pushed me to move. Today I’ll compare several cloud sync services and tell you why I picked Sync.com. In other news: Firefox keeps delivering excellent privacy features and gets top ranks in two new reports; NordVPN was “hacked” but you shouldn’t be worried; ISP are lobbying hard to stop DNS over HTTPS in browsers; some clever researchers show how to create legitimate Amazon Echo and Google Home apps that can eavesdrop and phish for passwords; and macOS Catalina arrives with several bugs but also several welcome new security features. Further Info: Sign up for Sync.com (referral gets us both 1GB extra); http://www.sync.com/get-started?_sync_refer=bd7921700 Switch to Firefox: https://www.mozilla.org/en-US/firefox/new/

Oct 28, 201952 min

Risky Business (Part 2)

You’ve got ransomware! Now what? If you had the foresight to create safe backups, you can restore your data and move on. Sometimes the hackers screw up and you can actually recover your files directly without paying for the key. But in many cases, you have no real choice but to pay. Cyber insurance can not only help you cover those costs, but insurers can deal directly with the hackers for you and help you with the restoration process. Joshua Motta is the CEO and Co-founder of Coalition, the fastest-growing provider of cyber insurance for small to medium sized businesses. Having worked at the intersection of the intelligence, finance, and technology sectors at the CIA, Goldman Sachs, and most recently as an early employee and CxO of Cloudflare, he gained valuable insights into the minds of hackers and how — and why — they target specific organizations, as well as how organizations can most effectively manage cyber risk. He founded Coalition to provide a better way to protect small and midsize businesses from breaches and cyber incidents. Further Info: Coalition Cyber Insurer: https://www.thecoalition.com/ Help with ransomware: https://www.nomoreransom.org/en/index.html

Oct 21, 201931 min

Risky Business (Part 1)

As our world becomes increasingly technical and interconnected, we become more susceptible to technical misfortunes and feel more impact when they inevitably occur. In the first half of my interview with Joshua Motta, we’ll talk about the recent rise in ransomware attacks: how people and companies get infected, what we know about the hackers, and why ransomware is such an effective and debilitating attack. Joshua will even explain how ransomware has become a cottage industry unto itself. Joshua Motta is the CEO and Co-founder of Coalition, the fastest-growing provider of cyber insurance for small to medium sized businesses. Having worked at the intersection of the intelligence, finance, and technology sectors at the CIA, Goldman Sachs, and most recently as an early employee and CxO of Cloudflare, he gained valuable insights into the minds of hackers and how — and why — they target specific organizations, as well as how organizations can most effectively manage cyber risk. He founded Coalition to provide a better way to protect small and midsize businesses from breaches and cyber incidents. Further Info: Coalition Cyber Insurer: https://www.thecoalition.com/ Help with ransomware: https://www.nomoreransom.org/en/index.html

Oct 14, 201934 min

Don’t Forget to Wipe Your Data

What happens to all the files, photos, songs and other data on your devices when you resell them or throw them away? Well, if you don’t do anything, all that data is still there, waiting for someone else to access it. A recent study showed that 60% of used hard drives still had accessible data on them. Today I’ll tell you how to properly wipe the data from your smartphones and computers before you get rid of them. And there were a lot of other news items this week, including severe bugs in both Apple and Android smartphones, Cloudflare’s wonderful new free mobile VPN app called Warp, a bug in WhatsApp that could allow complete takeover of your device, how to pronounce “GIF”, the SIMJacker hack that affects well over a billion phones, and yet around call by the government to “backdoor” our encrypted communications. Further Info: Hope to Wipe Your Data: https://firewallsdontstopdragons.com/wipe-data-before-dumping-devices/ Windows 10 privacy settings: https://spreadprivacy.com/windows-10-privacy-tips/

Oct 7, 201954 min

Not Just a Face in the Crowd (Part 2)

So what happens when your face print (or any biometric info) is stolen from a server? You can’t change your face like you can change your password. Is there anything you can do to avoid your face being scanned or prevent your face from being recognized? What can you do right now to halt the use of facial recognition technologies while we sort out all the social implications? The answers to these questions and more in the second half of my interview with EPIC’s Jeramie Scott! Jeramie Scott is Senior Counsel at EPIC and Director of the EPIC Domestic Surveillance Project. His work focuses on the privacy issues implicated by domestic surveillance programs with a particular focus on drones, AI, biometrics, and social media monitoring. Mr. Scott regularly litigates open government cases and cases arising under the Administrative Procedure Act. He is also a co-editor of “Privacy in the Modern Age: The Search for Solutions” and the author of “Social Media and Government Surveillance: The Case for Better Privacy Protections of Our Newest Public Space.” Prior to joining EPIC, Mr. Scott graduated from the New York University Law School where he was a clinic intern at the Brennan Center’s Liberty and National Security Program. His work at the Brennan Center focused on civil liberty issues arising from local law enforcement surveillance. Further Info: Electronic Privacy Information Center (EPIC): https://epic.org Privacy in the Modern Age: The Search for Solutions: https://www.amazon.com/Privacy-Modern-Age-Search-Solutions/dp/1620971070 Glenn Greenwald’s TED Talk on Privacy: https://www.ted.com/talks/glenn_greenwald_why_privacy_matters Petition to ban the use of FRT: https://www.banfacialrecognition.com/

Sep 30, 201940 min

Not Just a Face in the Crowd (Part 1)

Use of facial recognition technology (FRT) is exploding around the globe. While touted as a convenience for checking in for a flight or crossing the border, the opportunities for abuse are staggering. People act differently when they feel they’re being watched. There’s a reason we have sayings like “dance like no one is watching”. But US agencies like TSA and CBP have gained access to treasure troves of faces from DMV and passport databases, without ever asking our permission, and they’re rolling out FRT across the nation. There are no laws or regulations on the use of this technology, and little thought being given to how constant, mass surveillance will affect our democratic and human rights. In the first part of my two-part interview with Jeremie Scott (EPIC), we’ll discuss how we got here. Jeramie Scott is Senior Counsel at EPIC and Director of the EPIC Domestic Surveillance Project. His work focuses on the privacy issues implicated by domestic surveillance programs with a particular focus on drones, AI, biometrics, and social media monitoring. Mr. Scott regularly litigates open government cases and cases arising under the Administrative Procedure Act. He is also a co-editor of “Privacy in the Modern Age: The Search for Solutions” and the author of “Social Media and Government Surveillance: The Case for Better Privacy Protections of Our Newest Public Space.” Prior to joining EPIC, Mr. Scott graduated from the New York University Law School where he was a clinic intern at the Brennan Center’s Liberty and National Security Program. His work at the Brennan Center focused on civil liberty issues arising from local law enforcement surveillance. Further Info: Electronic Privacy Information Center (EPIC): https://epic.org Privacy in the Modern Age: The Search for Solutions: https://www.amazon.com/Privacy-Modern-Age-Search-Solutions/dp/1620971070

Sep 23, 201937 min

Google’s Not-So-Private Sandbox

No doubt sensing the impending US privacy regulations, Google has released a plan to “enhance” user privacy… by finding different ways to track you. Instead of relying on cookies and fingerprinting, Google proposes that we just come out in the open and formalize tracking technologies. While that could give users more transparency and a modicum of control, the bottom line is that Google is really just trying desperately to save its business model (ads based on tracking). While there are actually some good ideas in their proposal, many of the technologies they’re putting forward could be even worse for your privacy than the current schemes. Today I’ll walk through the EFF’s excellent analysis of these propositions and give my own take. Further Info: EFF: Don’t Play in Google’s Privacy Sandbox: https://www.eff.org/deeplinks/2019/08/dont-play-googles-privacy-sandbox-1 EFF’s Panopticlick tool: https://panopticlick.eff.org/

Sep 16, 201940 min

Ring’s Orwellian Doorbell

Today we speak with EFF’s Matthew Guariglia about the creepy new partnership between Amazon’s Ring Doorbell division and local law enforcement. Recent disclosures reveal that Amazon has partnered with over 400 police agencies to market their product and share surveillance footage. While these footage requests can supposedly be refused by the Ring owners, there appear to be circumstances where Amazon will provide footage without consent. The marketing of Ring has changed from convenience to an automated neighborhood watch program, where the police have been coached in how to drum up interest in the product and to assuage fears over sharing their private footage. Matthew Guariglia is a policy analyst for surveillance and privacy at the Electronic Frontier Foundation. He is also a visiting research scholar at the University of California-Berkeley and holds a PhD in U.S. history. His work focuses on the relationship between race, immigration, policing and government surveillance in the past and present. You can find his writing in the Washington Post, VICE, and the Freedom of information-centered outlet MuckRock. To find his writing you can follow him on Twitter at @mguariglia or visit MatthewGuariglia.com. Further Info EFF’s Street Level Surveillance : https://www.eff.org/issues/street-level-surveillance Protecting Civic Spaces: https://privacyinternational.org/long-read/2852/protecting-civic-spaces

Sep 9, 201950 min

Choosing a VPN Provider

Evaluating VPN providers on privacy is really, really hard. Even if you read all their privacy claims, how do you know if they’re telling the truth? I’ve read many reviews on many sites, but the recent review from The Wirecutter is the most comprehensive and helpful review I’ve ever come across. It focused first and foremost on privacy – something many other reviews fail to do, instead focusing on more readily verifiable aspects like speed, number of servers, and cost. In recent years, some top VPN providers have turned to third party, independent auditors to verify their privacy claims and published the results. This is what allows for a truly privacy-focused review. Many top contenders like ExpressVPN and NordVPN didn’t make the cut due to lack of transparency compared to the providers that topped Wirecutter’s list. Who won? Listen to today’s show to find out. In other news, iPhones have been vulnerable to some nasty website hacks for several years, Facebook finally releases a tool to manage your “off-Facebook” data (though it fails), Kaspersky antivirus products have been marking all their users with a unique, trackable ID, and Kazakhstan tries to implement mass surveillance of its citizens and ends up being foiled (thankfully) by the three major browser makers. Further Info: Choosing a VPN Provider: https://firewallsdontstopdragons.com/choosing-a-vpn-service/

Sep 2, 201949 min

The Great Cellular Sellout (Part 2)

In the second half of my interview with EFF’s Aaron Mackey, we’ll discuss why our federal agencies are not enforcing the laws already on the books that should be protecting your privacy, the real implications of tracking someone’s location, other ways in which we’re tracked, and how you – as a consumer and citizen – can best defend yourself and advocate for better enforcement and protections. Aaron Mackey works on free speech, privacy, government surveillance and transparency. Before joining EFF in 2015, Aaron was in Washington, D.C. where he worked on speech, privacy, and freedom of information issues at the Reporters Committee for Freedom of the Press and the Institute for Public Representation at Georgetown Law. Aaron graduated from Berkeley Law in 2012, where he worked for EFF while a student in the Samuelson Law, Technology & Public Policy Clinic. He also holds an LLM from Georgetown Law. Prior to law school, Aaron was a journalist at the Arizona Daily Star in Tucson, Arizona. He received his undergraduate degree in journalism and English from the University of Arizona in 2006, where he met his amazing wife, Ashley. They have two young children. Further Info: Donate to EFF: https://supporters.eff.org/donate/ Surveillance Self Defense Guide: https://ssd.eff.org EFF’s California lawsuit: https://www.eff.org/cases/geolocation-privacy Report abused location information: [email protected] EFF IMSI Catcher white paper: https://www.eff.org/files/2019/07/09/whitepaper_imsicatchers_eff_0.pdf

Aug 26, 201939 min

The Great Cellular Sellout (Part 1)

In January 2019, Motherboard broke a story about how cellular providers were allowing your location information to be sold to several third parties, effectively allowing anyone to buy the real-time location of any cell phone. The Electronic Frontier Foundation has brought a suit against AT&T and others, claiming that this practice broke several state and federal laws. Today in part one of my interview with the EFF’s Aaron Mackey, we’ll discuss this case and why our location data can expose so much about us. Aaron Mackey works on free speech, privacy, government surveillance and transparency. Before joining EFF in 2015, Aaron was in Washington, D.C. where he worked on speech, privacy, and freedom of information issues at the Reporters Committee for Freedom of the Press and the Institute for Public Representation at Georgetown Law. Aaron graduated from Berkeley Law in 2012, where he worked for EFF while a student in the Samuelson Law, Technology & Public Policy Clinic. He also holds an LLM from Georgetown Law. Prior to law school, Aaron was a journalist at the Arizona Daily Star in Tucson, Arizona. He received his undergraduate degree in journalism and English from the University of Arizona in 2006, where he met his amazing wife, Ashley. They have two young children. Further Info: Donate to EFF: https://supporters.eff.org/donate/ Surveillance Self Defense Guide: https://ssd.eff.org EFF’s California lawsuit: https://www.eff.org/cases/geolocation-privacy Report abused location information: [email protected]

Aug 19, 201938 min

The Tyranny of the Default

Marketing firms love to tell us that we control our privacy – you simply need to opt out of tracking! Like Dorothy, we’ve had the power all along. Just click your heels three times and uncheck all those pesky tracking options under Settings… somewhere. Which, statistically speaking, no one ever does. It’s the Tyranny of the Default. I’ll discuss why it’s so hard. (Spoiler alert, it’s on purpose.) Also in today’s show: Apple massively expands its bug bounty program; several “air gapped” US elections systems found on the internet; Instagram pulls a Cambridge Analytica move; watch out for fake Equifax settlement sites; another sex hook-up app exposes its user’s private information; and it’s time to update your Android devices (if you can). Further Info: Instagram data leak: https://www.businessinsider.com/startup-hyp3r-saving-instagram-users-stories-tracking-locations-2019-8 Election Systems exposed online: https://www.vice.com/en_us/article/3kxzk9/exclusive-critical-us-election-systems-have-been-left-exposed-online-despite-official-denials Official FTC/Equifax settlement site: https://ftc.gov/equifax or https://www.equifaxbreachsettlement.com/ Changing WiFi Router (and other IoT) default passwords: https://firewallsdontstopdragons.com/the-s-in-iot-is-for-security/ The Cop Out that is Opt Out: https://firewallsdontstopdragons.com

Aug 12, 201944 min

The Great Hack

In today’s show, I’ll discuss the Capitol One hack that affected over 100 million card users and applicants. I’ll also cover the latest in the backlash against Apple, Google and Amazon over humans listening in on your private digital assistant voice recordings. The Ring doorbell, whose parent company was bought by Amazon, is quickly becoming a darling of local law enforcement agencies due to its ability to share surveillance footage. School districts are being hit with ransomware and being bilked for hundreds of thousands of dollars. And finally, Netflix has created a sobering documentary about the Facebook and Cambridge Analytics scandal, covering not just the 2016 US elections but also Brexit and many other voter influence campaigns around the globe. Further Info: The Great Hack on Netflix: https://www.netflix.com/Title/80117542 RSA Conference Blog book review: https://www.rsaconference.com/blogs/bens-book-of-the-month-review-of-firewalls-dont-stop-dragons-a-step-by-step-guide-to-computer-security-for-non-techies Apress Beginner’s Book series: https://www.amazon.com/stores/page/7383A13D-EAFC-426B-A944-5B6C1B6886E9

Aug 5, 201936 min

Get Your Equifax Settlement

Two years after the massive Equifax breach, the Federal Trade Commission (FTC) has reached a tentative settlement that will purportedly provide some restitution to the 148 million Americans who whose data was leaked. Unfortunately, there are lots of little devils in the details – not to mention the this settlement has yet to be approved. However, you can (and probably should) go ahead and submit your claim. I’ll give you all the details and tell you how do it. In other news, Firefox is coming out with a premium, for-pay version of its privacy-centric web browser, the Pentagon has revealed technology that will allow them to identify people surreptitiously from up to 200 meters away, some of your Apple’s Siri recordings are being listened to by real humans, I’ll give my take on the FaceApp scandal, and finally, if you have a Logitech wireless keyboard or mouse, you’re going to watch to update the software to patch a nasty bug. Further Info: Logitech Wireless Keyboard/Mouse security update: https://support.logi.com/hc/en-001/community/posts/360032078393-Logitech-Response-to-Research-Findings Equifax settlement claim site: https://www.equifaxbreachsettlement.com/ Free (official) annual credits reports: https://www.annualcreditreport.com/index.action

Jul 29, 201946 min

Privacy in a Box (Part 2)

In the second half of my interview with Winston Privacy CEO Richard Stokes, we talk about why your data is so valuable to advertisers and what you can do to limit all this tracking. In particular, we’ll discuss the Winston box which acts as a sort of force field around your home network, preventing all your “smart” and “internet of things” devices from reporting on your every move. Richard is the CEO and founder of Winston Privacy. Previously, he was the founder of AdGooroo.com, one of the first digital market research services, and later became the Global Head of Innovation for Kantar Media. He founded Winston Privacy in response to the increasing abuses of privacy taking place in the AdTech industry. Additionally, he’s the author of “The Ultimate Guide to Pay-Per-Click Advertising”. He has a Computer Science degree from the University of Illinois at Champaign-Urbana and an MBA from Kellogg / Northwestern University. Further Info: Winston Privacy: https://winstonprivacy.com/ Pre-Order: https://www.indiegogo.com/projects/winston-take-back-control-of-your-online-privacy#/

Jul 22, 201937 min

Privacy in a Box (Part 1)

Protecting your privacy today is hard. It’s really hard. It’s too hard. Every ‘smart’ device you own is tattling on you, constantly, to dozens of companies. Your phone, your tablet, your PC, your TV, your streaming box, your DVR, your smart thermostat, your internet-connected medical devices… The list goes on and it gets longer every day. What if you could not only see all these illicit communications but also block them all, in one feel swoop? In part one of my interview with Richard Stokes, this former AdTech CEO will reveal what finally caused him to not only leave the industry but to develop a promising new product that puts users back in control of their privacy. Richard is the CEO and founder of Winston Privacy. Previously, he was the founder of AdGooroo.com, one of the first digital market research services, and later became the Global Head of Innovation for Kantar Media. He founded Winston Privacy in response to the increasing abuses of privacy taking place in the AdTech industry. Additionally, he’s the author of “The Ultimate Guide to Pay-Per-Click Advertising”. He has a Computer Science degree from the University of Illinois at Champaign-Urbana and an MBA from Kellogg / Northwestern University. Further Info: Winston Privacy: https://winstonprivacy.com/ Pre-Order: https://www.indiegogo.com/projects/winston-take-back-control-of-your-online-privacy#/

Jul 15, 201935 min

Big Brother 2.0

The US government is once again looking to break or hobble encrypted communications in the name of national security and law enforcement. They claim that we’re “going dark” – that modern end-to-end encryption used in apps like Signal and Wickr that protect user privacy are preventing them from keeping us safe and bringing the bad guys to justice. Cryptographers and technology companies have soundly squashed the idea of putting “backdoors” in these systems that supposedly only the “good guys” can go through. But now these agencies have come up with a proposal that neatly sidesteps these issues: they simply want to be added as another “end” to the end-to-end scrambled session. A “ghost” in the chat, and BCC that neither of the original participants are made aware of. But this has several problems, as well. In other news, FigLeaf has conducted a survey of users about online privacy that shows major shifts in thinking since just before the Cambridge Analytica/Facebook scandal; “pre-saving” new releases on Spotify and other music streaming services is allowing music companies unbelievable access to your personal info; and Mozilla (maker of Firefox) has created a creative tool that let’s you fool online advertisers into thinking you’re someone completely different.

Jul 8, 201948 min

Set Warp Factor 1.1.1.1

Why do most VPN apps suck so badly? How do you know which VPN service providers you can trust with your privacy? How is it that our internet service providers know so much about our web surfing habits? Today I explore these questions and more with John Graham-Cumming, the CTO of the internet performance and security company. He will also tell us about a new VPN service coming soon from Cloudflare called Warp that may finally address all of these problems. John is a computer programmer and author. He studied mathematics and computation at Oxford and stayed for a doctorate in computer security. As a programmer he has worked in Silicon Valley and New York, the UK, Germany, and France. His open source POPFile program won a Jolt Productivity Award in 2004. John is the author of a travel book for scientists published in 2009 called The Geek Atlas. Further Info: Cloudflare’s 1.1.1.1 App: https://1.1.1.1/ Cloudflare’s Crypto Week Blog: https://blog.cloudflare.com/welcome-to-crypto-week-2019/ Big Brother 2.0: https://firewallsdontstopdragons.com/big-brother-2-0/

Jul 1, 201942 min

The Internet of Junk

How many of your “smart” devices are smart enough to update their own software? For that matter, how many of them can upgrade at all? It’s a good bet that most of them run some flavor of the free and open-source Linux operating system. A nasty bug was just found that affects almost all Linux systems, allowing a simple remote command to bring the system to its knees. There have been other bugs found in Linux and there will be more. If your device’s software can’t be updated, it will always be vulnerable. I’ll go over some basic IoT security tips to mitigate your vulnerability, but in the end, older IoT devices that can’t be upgraded should just be pitched. In other news, Firefox just patched two critical vulnerabilities, Dell’s built-in remote assistance software can be remotely hacked, Venmo transactions are still painfully public by default, a Spanish soccer apps turns its fans into unwitting narcs, and Facebook has launched a new cryptocurrency called Libra.

Jun 24, 201937 min

The Rise of Stalkerware

In today’s show I have a sobering discussion with the EFF’s Eva Galperin about the rise of stalkerware (sometimes called “spouseware”). It’s become all too easy for abusive, unscrupulous people to spy on their significant others, tracking their every move, monitoring all their communications. We’ll talk about how our phones can be subverted and what measures you can take to prevent it. Eva also provides practical and prudent advice for people who suspect they may be victims of stalkerware. Eva Galperin is EFF’s Director of Cybersecurity. Prior to 2007, when she came to work for EFF, Eva worked in security and IT in Silicon Valley and earned degrees in Political Science and International Relations from SFSU. Her work is primarily focused on providing privacy and security for vulnerable populations around the world. To that end, she has applied the combination of her political science and technical background to everything from organizing EFF’s Tor Relay Challenge, to writing privacy and security training materials (including Surveillance Self Defense and the Digital First Aid Kit), and publishing research on malware in Syria, Vietnam, Kazakhstan. When she is not collecting new and exotic malware, she practices aerial circus arts and learning new languages. Further Info Surveillance Self Defense: https://ssd.eff.org/ EFF Newsletter: https://supporters.eff.org/subscribe Donate to the EFF: https://supporters.eff.org/donate/

Jun 17, 201938 min

A Tale of Two Browsers: Chrome vs Firefox

Google Chrome is the most popular web browser on the planet by far, used by about two thirds of all web surfers. But Google is an advertising company and ad blockers are a direct threat to their business model. Google is planning to make a highly controversial change to Chrome’s plugin framework that would break some popular ad blocking extensions like uBlock Origin, forcing them to use much less effective techniques for blocking ads. Compare that to Mozilla’s Firefox browser, which just announced even more built-in tracking and ad-blocking capabilities – many of which will be on by default. The evidence is clear: Firefox respects your privacy and is giving your more and more tools with which to protect it; Chrome is doing the opposite. It’s time to switch to Firefox and ditch Chrome. In other news, Maine has just signed bill into law which will require internet service providers to get your explicit consent before collecting and selling your web surfing data, Apple has announced several privacy-enhancing features to debut in iOS 13 this fall, and Windows Remote Desktop Services are under attack by hackers. Further Info: Patch your old Windows Systems Now! https://firewallsdontstopdragons.com/a-worrisome-windows-worm/ Switch from Google Chrome to Firefox: https://firewallsdontstopdragons.com/its-time-switch-to-firefox/ Firefox’s content blocking settings: https://support.mozilla.org/en-US/kb/content-blocking

Jun 10, 201948 min

Polling on Privacy (Pt2)

Is it possible to hide your tracks online? Is it even worth the effort to try? How do you know which companies, products and services you can trust? Is government regulation the answer? We’ll address all of these questions today in part 2 of my interview with David Ruiz. David will give you several great resources for getting more informed and also for getting more involved in the fight for privacy. David Ruiz is a pro-privacy, pro-security writer for Malwarebytes Labs, where he covers online privacy, legislation, and the interplay between technology and the law. Further Info Who Has Your Back? https://www.eff.org/who-has-your-back-2018 Privacy Not Included: https://foundation.mozilla.org/en/privacynotincluded/ Terms of Service; Didn’t Read: https://tosdr.org/ Malwarebytes poll on privacy: https://blog.malwarebytes.com/security-world/2019/03/labs-survey-finds-privacy-concerns-distrust-of-social-media-rampant-with-all-age-groups/ Top 6 Takeaways from poll: https://blog.malwarebytes.com/101/2019/05/the-top-six-takeaways-for-user-privacy/ Help me to help you! https://www.patreon.com/FirewallsDontStopDragons

Jun 3, 201936 min

Polling on Privacy (Pt1)

In January of this year, Malwarebytes (a world-class antivirus software maker) conducted a massive poll on privacy that included 4000 people from 66 different countries. On today’s show, I will delve into the key takeaways from this poll and some rather (pleasantly) surprising results. (Tune in next week for part 2.) David Ruiz is a pro-privacy, pro-security writer for Malwarebytes Labs, where he covers online privacy, legislation, and the interplay between technology and the law. Further Info Malwarebytes poll on privacy: https://blog.malwarebytes.com/security-world/2019/03/labs-survey-finds-privacy-concerns-distrust-of-social-media-rampant-with-all-age-groups/ Top 6 Takeaways from poll: https://blog.malwarebytes.com/101/2019/05/the-top-six-takeaways-for-user-privacy/

May 27, 201935 min

Google Knows What You Buy

It shouldn’t surprise you to learn that Google can read your Gmail. You may even realize that Google is scanning your emails for things like trip itineraries, which allows them to automatically add flights and hotel reservations to your Google Calendar, for example. But you may not realize how much other juicy info is there to be mined, like online purchases. Every email receipt you’ve received since you’ve had your Gmail account has almost surely been parsed and indexed. In today’s show, I’ll tell you how you can view this history and even delete it (painful as it may be). In other news, an FCC commissioner has released an update on the selling of location data by cell phone providers, San Francisco is poised to become the first major US city to ban the government use of facial recognition systems, and many popular games have been found to give away tons of user data. Further Info Check your Google purchase history: https://myaccount.google.com/purchases

May 20, 201930 min

Time to Break Up Facebook

Facebook co-founder Chris Hughes makes a heartfelt and cogent argument for breaking up the world’s dominant social media company, Facebook. The litmus test for the US Government has focused too much on impact to consumer pricing, which has little to do with “free” services such as Facebook. It’s time to also consider social and consumer impact. In other news, a photo storage service has been caught using your images to train facial recognition systems without proper disclosure, Google has unveiled plans to allow users to auto-delete certain sensitive user data after a specified number of months, and Facebook has cranked up the creepy factor by encouraging you to identity up to nine of your friends that you are secretly crushing on. Further Info New York Times Privacy Project: https://www.nytimes.com/2019/05/07/opinion/google-sundar-pichai-privacy.html It’s Time to Break Up Facebook: https://www.nytimes.com/2019/05/09/opinion/sunday/chris-hughes-facebook-zuckerberg.html Firewalls Don’t Stop Dragons links & errata: https://github.com/Apress/firewalls-dont-stop-dragons

May 13, 201921 min

Health Apps Behaving Badly

A disturbing study in the JAMA Network Open journal showed that almost all of 36 mental health apps they downloaded were sharing your data to some extent – many without proper or even any disclosure. Many shared basic data with Facebook and Google, and a few shared very sensitive information like health diaries and self reports of substance abuse. I’ll give you some tips on how you can protect yourself. In other news, Firefox plugins were all shut off over the weekend due to a Mozilla certificate expiring, bad guys are using Google ads to trick you into paying money to fake customer support sites, data from 80M US households was found lying around on Microsoft servers, and Princeton has a cool new app that will tell you which of your IoT devices may be snitching on you. Further Info Terms of Service; Didn’t Read: https://tosdr.org/ Princeton IoT Inspector: https://iot-inspector.princeton.edu/ Spring Cleaning for you apps: https://firewallsdontstopdragons.com/close-security-holes/

May 6, 201934 min

Further Facebook Fiascos

Facebook has once again gone too far and, when caught, asked for forgiveness and promised to change. First it was revealed that Facebook has been requesting since May 2016 that new users provide their email account passwords in order to verify their email addresses – without giving any obvious way to opt out. When caught, they said they would stop doing this. However, it was then revealed that Facebook “unintentionally” hoovered up the email contact lists of 1.5 million Facebook users that gave them their email passwords! I’ll tell you how you can review and delete any contacts you’ve shared (intentionally or otherwise) with Facebook… as well as how to just delete Facebook! In other news, Microsoft has dropped the requirement to periodically change your password in Windows 10, another IoT vulnerability has been found that affects millions of devices, I have an update on the supposed Amazon employee Echo spying, and finally I’ll explain why browser makers are throwing in the towel and allowing ‘ping’ tracking (and how you can still block this).

Apr 29, 201936 min

Swiped: Identity Theft (Pt 2)

How do you deal with the threat of identity theft? Follow Adam Levin’s 3 M’s: 1) minimize your exposure, 2) monitor your accounts, and 3) manage the damage. We discuss these techniques and much more in part two of my interview with Adam Levin, author of Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves. Adam Levin is a consumer advocate with more than 40 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. You may have seen Adam on one of his several TV appearances, as well. Further Info: Adam Levin’s website: https://adamlevin.com/ Adam’s book, Swiped: https://adamlevin.com/swiped-book-adam-levin/ CyberScout: https://www.cyberscout.com/ Bruce Schneier’s Data and Goliath Kevin Mitnick’s The Art of Invisibility Brian Kreb’s Spam Nation and his blog Identity Theft Resource Center Consumer Federation of America Privacy Rights Clearinghouse

Apr 22, 201935 min

Swiped: Identity Theft (pt 1)

Identity theft is arguably one of the worst cyber crimes in terms of deep and lasting impact to the victim. This runs the gamut from simple credit card fraud to committing crimes in someone else’s name. We’ll talk about the entire spectrum today in part one of my interview with Adam Levin, author of Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves. Adam Levin is a consumer advocate with more than 40 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. You may have seen Adam on one of his several TV appearances, as well. Further Info: Adam Levin’s website: https://adamlevin.com/ Adam’s book, Swiped: https://adamlevin.com/swiped-book-adam-levin/ CyberScout: https://www.cyberscout.com/

Apr 15, 201945 min

Spotting Scare Scams

Bad guys have been using scary emails and pop-up messages to bilk unsuspecting victims of millions of dollars for a long time now. But recent scams purporting to be from the CIA have taken things to a new level. In today’s show, I’ll walk you through one variant of this scam and teach you how to spot similar scare scams. In other news, government spyware has made its way into everyday apps on the Google Play Store, WinRAR has a serious bug that you need to patch, hundreds of millions of Facebook records were found lying around unprotected in the cloud, ASUS computer users were targeted by ShadowHammer malware, and Cloudflare has a new mobile VPN app you should take a look at. Further Info Install and configure Cloudflare’s 1.1.1.1 DNS: https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/ ASUS malware checker: https://shadowhammer.kaspersky.com/

Apr 8, 201938 min

Fix It Already!

How often have you run across something so obviously bad or behind the times that you just want to scream: Hey, fix this already! Electronic Frontier Foundation to the rescue! Gennie Gebhart explains the EFF’s new #FixItAlready campaign – a “most wanted” list of no-brainer bugs and shortcomings in today’s most popular services and products that just should not be. Examples include no end-to-end encryption of Twitter DMs, using two-factor Facebook phone numbers for marketing, and not being able to set your own password on iCloud or Windows 10 hard drive encryption. Gennie Gebhart is the Associate Director of Research at the Electronic Frontier Foundation, where she does research and advocacy on consumer privacy and security issues. She holds a Master of Library and Information Science from the University of Washington. Further Info: Fix It Already! https://fixitalready.eff.org/ Donate to EFF: https://supporters.eff.org/donate/join-eff-4

Apr 1, 201948 min

Preparing for Your Digital Afterlife

What happens to your digital life when you die? The answer is only slightly less philosophical than what happens to your soul. The laws, as least in the US, haven’t kept up with the times and there aren’t clear rules for who has legal rights to your online accounts or the files you’ve stored in the cloud. In today’s episode, I’ll tell you how to prepare for your inevitable digital afterlife. In other news, Facebook revealed that 100’s of millions of its users passwords were left open on internal servers, ransomware has hit one of the world’s largest producers of aluminum, the Pwn2Own bug hunt contest shows us how to do responsible disclosures, a critical flaw has been found in implanted defibrillators leaving them vulnerable to hacking, and DARPA is hoping to fix our broken voting systems. Further Reading My blog article on Digital Afterlife: https://firewallsdontstopdragons.com/preparing-for-your-digital-afterlife/ Facebook’s password screwup: https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/ Critical defibrillator bugs: https://arstechnica.com/information-technology/2019/03/critical-flaw-lets-hackers-control-lifesaving-devices-implanted-inside-patients

Mar 25, 201940 min

Enter the Panopticon (Part 2)

In second half of my interview with EFF’s Bill Budington, Bill helps us understand how we can at least attempt to disguise ourselves on the web and basically try to blend in with the crowd. We’ll also see how tools like EFF’s Panopticlick can hep us pinpoint the things that are making us stand out, which enables us to be tracked more easily. Finally, we’ll discuss several browsers and plugins that can help you preserve your privacy. If you missed Part 1, you can listen to it here: http://podcast.firewallsdontstopdragons.com/2019/03/10/enter-the-panopticon-pt1/. Guest Bio: Bill is a Senior Staff Technologist at the Electronic Frontier Foundation (EFF). He works on privacy and security-enhancing projects, such as the HTTPS Everywhere browser add-on and Panopticlick, a tool that alerts users users to how vulnerable they are to browser tracking. He has also contributed to projects such as Let’s Encrypt and SecureDrop. Further Info: Is your browser giving you away? EFF’s Panopticlick will tell you: https://panopticlick.eff.org EFF’s Surveillance Self Defense guide – learn how to keep yourself safe online! https://ssd.eff.org/ Help EFF to help you: https://supporters.eff.org/

Mar 18, 201948 min

Enter the Panopticon (Part 1)

In the first part of my discussion with Bill Budington from the EFF, we’re going to talk about some of the key ways in which we are tracked around the web as we surf from site to site. I’ll ask Bill who is tracking up, why they’re tracking us, and we’ll get into some of the clever and downright devious methods by which we are tracked and recognized on the web. In part 2 (next week) Bill will help us understand why it’s so hard to disguise ourselves on the web and how tools like EFF’s Panopticlick can show us what’s going on under the covers. We’ll also offer up some solutions or at least mitigations for all this tracking. Guest Bio: Bill is a Senior Staff Technologist at the Electronic Frontier Foundation (EFF). He works on privacy and security-enhancing projects, such as the HTTPS Everywhere browser add-on and Panopticlick, a tool that alerts users users to how vulnerable they are to browser tracking. He has also contributed to projects such as Let’s Encrypt and SecureDrop. Further Info: Is your browser giving you away? EFF’s Panopticlick will tell you: https://panopticlick.eff.org EFF’s Surveillance Self Defense guide – learn how to keep yourself safe online! https://ssd.eff.org/ Help EFF to help you: https://supporters.eff.org/donate/join-4

Mar 11, 201950 min

Account Defense in Depth

The Mayor of Tampa, Florida, had this Twitter account hacked due to “the usual weaknesses, including poor passwords.” The hackers used the account to tweet pornographic images and even an incoming ballistic missile alert. Comcast’s Xfinity Mobile service used a default account security PIN of “0000”, which allowed several customers to have their accounts taken over. You not only need strong passwords, you need strong second factor authentication. That’s defense in depth. In other news, Microsoft’s Edge browser was found to have a whitelist for almost 60 websites that bypass the Flash Player click-to-run protections, a Canadian province is allowing the mass sale of anonymized medical records, the fast Thunderbolt USBC ports are found to be vulnerable to a memory access hack called Thunderclap.

Mar 4, 201936 min

Guiding the Development of AI

Artificial Intelligence (AI) has been around for decades, but has only recently begun to fulfill the promise of truly replicating human-like decision making. The Information Age has generated enormous quantities of data and modern technology has given us unprecedented power to ingest and analyze this data. AI systems today control airplanes, financial and insurance systems, and even criminal sentencing recommendations. We can use AI to conduct law enforcement and intelligence gather operations. AI has even generated audio, video and photos that are completely fake but nearly impossible for a human to detect. Our guest today, Lorraine Kisselburgh, is working with international organization to define common-sense guidelines for the creation and use of these AI systems, to maximize potential and minimize abuse. Lorraine Kisselburgh (Ph.D., Purdue University) is a Scholar with the Electronic Privacy Information Center in Washington, D.C., a former professor of media, technology, and society, and a visiting lecturer in the Center for Entrepreneurship at Purdue University. She studies the social implications of emerging technologies, including privacy and ethics in emerging technology contexts. Her research has been awarded funding from the National Science Foundation and the Department of Homeland Security, and recognized by the National Academy of Engineering. She currently serves on the executive committee of Association of Computing Machinery’s (ACM) US Technology Policy Committee (USTPC) and was a member of the ACM Task Force on Code of Ethics. Email: [email protected] Website: www.lkisselburgh.net Twitter: @lkisselburgh, @EPICPrivacy Facebook: EPICPrivacy Further Information: Universal Guidelines for AI: https://thepublicvoice.org/AI-universal-guidelines/ Electronic Privacy Informantion Center (EPIC): https://www.epic.org/ “Deep Fake” Obama PSA: https://www.youtube.com/watch?v=cQ54GDm1eL0 Lyrebird fake Trump and Obama voices: https://soundcloud.com/user-535691776/dialog OpenAI fake news articles: https://arstechnica.com/information-technology/2019/02/researchers-scared-by-their-own-work-hold-back-deepfakes-for-text-ai/ AI Now Institute: https://ainowinstitute.org/ Berkman Klein Center for Internet and Society: https://cyber.harvard.edu/ Data & Society Intelligence and Autonomy Initiative: https://autonomy.datasociety.net/ WEF’s AI and Machine Learning: https://www.weforum.org/communities/artificial-intelligence-and-machine-learning

Feb 25, 20191h 17m

Toying With Security

The European Union has recalled a GPS smart watch meant to be worn by children so that their parents can keep tabs on them. Unfortunately, due to horrible security, anyone can track these watches – and even send messages to the children. The Internet of Things (IoT) is well-known for having lax or non-existent security protections. Connecting our children’s toys to the internet in this manner is raising serious (and valid) privacy concerns. In other news, there’s a devious new Facebook and Google phishing scam that would fool many pros, the Chrome browser will soon help you spot fake look-alike websites, Apple cracks down on apps that surreptitiously record their users’ interactions with their apps, and many modern Android phones are vulnerable to hacking simply by loading a malicious image. Help Me to Help You! Visit my page on Patreon for details: https://www.patreon.com/FirewallsDontStopDragons

Feb 18, 201930 min

You Must Stop Reusing Passwords

Last week I told you about the literally billions of email addresses and passwords that were released by hackers as “Collections 1-5”. I also told you how you can check to see if your information was contained in these (or other dumped data) by checking haveibeenpwnd.com. And today I’m interviewing the man behind this wonderful, free service: Troy Hunt! He tells us how he gets his hands on all of this data and what we should be doing to mitigate the damage from these inevitable breaches. The worst thing you can do? Reusing passwords on multiple sites! In today’s episode, I also reveal the winners of my Pod-Centennial contest! Five lucky people will be getting signed copies of my book, signed copies of Bruce Schneier’s latest book (Click Here to Kill Everybody), and a selection of other cybersecurity books! Troy Hunt is an Australian Microsoft Regional Director and Microsoft Most Valuable Professional for Developer Security. You’ll regularly find Troy in the press talking about security and even testifying before US Congress on the impact of data breaches. Further Info HaveIBeenPwned.com Ethics of running a data breach search service: https://www.troyhunt.com/the-ethics-of-running-a-data-breach-search-service/ Authentication evolved: https://www.troyhunt.com/passwords-evolved-authentication-guidance-for-the-modern-era/

Feb 11, 201956 min

You Have Been Pwned

Last week we saw perhaps the single largest data breach dump in history, close on the heels of another massive data disclosure from the same group. Dubbed “Collections 1-5”, together these data dumps represent literally billions of unique user email addresses and passwords. Using the online tool Have I Been Pwned will tell you whether your email address or password is contained in this hacker’s treasure trove. I will also tell you how you can mitigate the damage from this and future breaches. In other news, Apple’s FaceTime app contains a huge bug that could let other people eavesdrop on you and potentially even view you through your camera; Google and Firefox are offering competing visions of browser privacy with controversial new features; and a recent Mac malvertising campaign is using a classic technique called steganography to disguise its malicious intentions. Further Information Have I Been Pwned: https://haveibeenpwned.com/ Pod-Centennial Contest Details: https://firewallsdontstopdragons.com/celebrate-my-pod-centennial/ CLICK HERE TO ENTER the PodCentennial Contest!

Feb 4, 201937 min