PLAY PODCASTS
Shared Security Podcast

Shared Security Podcast

575 episodes — Page 8 of 12

First Amendment Rights and Twitter, Encryption Backdoors

In episode 123 for June 1st 2020: The controversy continues over fact checking and First Amendment rights on Twitter, and why government mandated encryption backdoors are bad for everyone’s security. ** Show notes and links mentioned on the show ** Trump to sign executive order aimed at cracking down on Facebook and Twitter https://www.cnbc.com/2020/05/28/trump-to-sign-executive-order-aimed-at-cracking-down-on-facebook-twitter.html The law enforcement backdoor debate continues https://www.helpnetsecurity.com/2020/05/26/backdoor-encryption/ OWASP Top 10 2020 Data Analysis Plan https://owasp.org/www-project-top-ten/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post First Amendment Rights and Twitter, Encryption Backdoors appeared first on Shared Security Podcast.

Jun 1, 202020 min

Episode 100 with Rachel Tobac and Kathleen Smith

In episode 100 of our May monthly show we discuss the history of the podcast, some of the most interesting cybersecurity and privacy news and events over the years, and speak with former guest Rachel Tobac, CEO and Co-Founder of SocialProof Security, about what she’s been up to and of course the David Lynch daily weather report! We also catch up with Kathleen Smith, CMO of ClearedJobs.net and CyberSecJobs.com to talk about the current cybersecurity job market, recruiting, and the one thing you need to stop doing with your resume. Interviews start at [38:00]. Be sure to watch the full episode on our YouTube channel. Thank you to all of our sponsors, guests, and listeners over the years helping us achieve this milestone episode! ** Links mentioned on the show ** Previous Episodes of the Shared Security Podcast https://sharedsecurity.net/podcast-episodes/ The David Lynch Daily Weather Report https://www.youtube.com/channel/UCDLD_zxiuyh1IMasq9nbjrA Connect with Rachel Tobac https://twitter.com/RachelTobac SocialProof Security https://www.socialproofsecurity.com/ The Shared Security Podcast Episode 74 – Special Guest Rachel Tobac https://sharedsecurity.net/2018/03/29/the-shared-security-podcast-episode-74-special-guest-rachel-tobac-racheltobac/ Connect with Kathleen Smith https://twitter.com/YesItsKathleen ClearedJobs.net https://clearedjobs.net/ CyberSecJobs.com https://cybersecjobs.com/ Weekly Blaze Episode 84 – Cybersecurity Careers, Recruiting, and Volunteering with Kathleen Smith https://sharedsecurity.net/2019/01/09/cybersecurity-careers-recruiting-and-volunteering-with-kathleen-smith-84/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Episode 100 with Rachel Tobac and Kathleen Smith appeared first on Shared Security Podcast.

May 29, 20201h 14m

Apple’s Law Enforcement Backdoor Dispute, Signal PINs, EasyJet Data Breach

In episode 122 for May 25th 2020: Apple and the US Government dispute over law enforcement backdoors in Apple products, secure messaging app Signal starts to move away from using phone numbers as user IDs, and details on the EasyJet data breach affecting 9 million customers. ** Show notes and links mentioned on the show ** Apple Calls FBI Comments on Lack of Help Unlocking Florida Shooter’s iPhone an ‘Excuse to Weaken Encryption’ https://www.macrumors.com/2020/05/18/apple-fbi-dispute-weaken-encryption/ Signal to move away from using phone numbers as user IDs https://signal.org/blog/signal-pins/ British Airline EasyJet Suffers Data Breach Exposing 9 Million Customers’ Data https://thehackernews.com/2020/05/easyjet-data-breach-hacking.html EasyJet official data breach statement https://otp.investis.com/clients/uk/easyjet1/rns/regulatory-story.aspx?cid=2&newsid=1391756 ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Apple’s Law Enforcement Backdoor Dispute, Signal PINs, EasyJet Data Breach appeared first on Shared Security Podcast.

May 25, 202010 min

Thunderbolt Flaws, WordPress Plugin Vulnerabilities, Patriot Act Vote

In episode 121 for May 18th 2020: A new Thunderbolt flaw could let hackers steal your data in under five minutes, new vulnerabilities in a popular WordPress plugin, and details on why the US Senate just rejected a plan to require a warrant to obtain Americans’ web browsing history. ** Show notes and links mentioned on the show ** Thunderbolt flaw lets hackers steal your data in ‘five minutes’ https://www.wired.com/story/thunderspy-thunderbolt-evil-maid-hacking/ Thunderbolt 3 The USB-C that does it all https://thunderbolttechnology.net/consumer/ Thunderspy tool to test if your PC is vulnerable https://thunderspy.io/ WordPress plugin Page Builder by SiteOrigin patched against code execution attacks https://www.zdnet.com/article/wordpress-plugin-page-builder-by-siteorigin-patched-against-code-execution-attacks/ Page Builder by SiteOrigin Plugin Page https://wordpress.org/plugins/siteorigin-panels/ Senate Votes to Allow FBI to Look at Your Web Browsing History Without a Warrant https://www.vice.com/en_us/article/jgxxvk/senate-votes-to-allow-fbi-to-look-at-your-web-browsing-history-without-a-warrant How to Contact Your Elected Officials https://www.usa.gov/elected-officials/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Thunderbolt Flaws, WordPress Plugin Vulnerabilities, Patriot Act Vote appeared first on Shared Security Podcast.

May 18, 202011 min

GoDaddy Security Incident, Fake Downloaders, Firefox Lockwise

In episode 120 for May 11th 2020: The latest on the GoDaddy security incident affecting 28,000 customers, fake Microsoft Teams notification emails and Zoom downloaders, and details on new features to the Firefox built in password manager. ** Show notes and links mentioned on the show ** GoDaddy notifies users of breached hosting accounts https://www.bleepingcomputer.com/news/security/godaddy-notifies-users-of-breached-hosting-accounts/ GoDaddy email to affected customers https://oag.ca.gov/system/files/Customer%20Notification.pdf How to combine SSH key authentication and two-factor authentication on Linux https://www.techrepublic.com/article/how-to-combine-ssh-key-authentication-and-two-factor-authentication-on-linux/ Fake Microsoft Teams Notification Emails https://www.helpnetsecurity.com/2020/05/04/fake-microsoft-teams-notification/ Fake Zoom Downloaders https://www.zdnet.com/article/hackers-target-remote-workers-with-fake-zoom-downloader/ The Firefox password manager now tells you when you use leaked passwords https://www.zdnet.com/article/the-firefox-password-manager-now-tells-you-when-you-use-leaked-passwords/ World Password Day https://www.daysoftheyear.com/days/password-day/ Our interview with Andrew Shikiar from the FIDO Alliance https://sharedsecurity.net/2020/04/27/the-end-of-passwords-as-we-know-it/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post GoDaddy Security Incident, Fake Downloaders, Firefox Lockwise appeared first on Shared Security Podcast.

May 11, 202010 min

Workplace Surveillance, Apple and Google Contact Tracing Tech, Virtual Cybersecurity Conferences

In episode 119 for May 4th 2020: The use of thermal cameras and other technology to monitor the workplace for COVID-19, more details about Apple and Google’s contact tracing framework, and are virtual security conferences the new normal? ** Show notes and links mentioned on the show ** A new era of workplace surveillance due to COVID-19? https://www.washingtonpost.com/technology/2020/04/27/companies-use-thermal-cameras-speed-return-work-sparks-worries-about-civil-liberties/ Apple and Google provide more technical details about the COVID-19 exposure notification API https://www.washingtonpost.com/technology/2020/04/29/most-americans-are-not-willing-or-able-use-an-app-tracking-coronavirus-infections-thats-problem-big-techs-plan-slow-pandemic/ https://www.apple.com/covid19/contacttracing/ Pros and cons of virtual security events https://www.helpnetsecurity.com/2020/04/29/virtual-events Check out all the great online courses offered by Secure Ideas. Use discount code: SIFRIEND for 25% off! https://secureideas.com/catalog/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Workplace Surveillance, Apple and Google Contact Tracing Tech, Virtual Cybersecurity Conferences appeared first on Shared Security Podcast.

May 4, 202023 min

The End of Passwords as We Know It

In episode 118 for April 27th 2020: A discussion about the end of passwords and what the future may hold with special guest Andrew Shikiar executive director of the FIDO Alliance. ** Show notes and links mentioned on the show ** Find out more about the FIDO Alliance https://fidoalliance.org/ https://twitter.com/fidoalliance How FIDO works and eliminates the need for passwords https://fidoalliance.org/how-fido-works/ Connect with Andrew Shikiar https://www.linkedin.com/in/andrewshikiar/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post The End of Passwords as We Know It appeared first on Shared Security Podcast.

Apr 27, 202021 min

Contact Tracing Controversy, Fighting COVID-19 Criminal Activity

In episode 99 of our April monthly show: Apple and Google’s controversial efforts to create contact tracing technology, fighting COVID-19 criminal activity, and what the new normal means for startup companies. ** Show notes and links mentioned on the show ** Apple and Google to build contact tracing technology https://www.rte.ie/news/business/2020/0410/1129902-apple-and-google-to-build-contact-tracing-technology/ COVID-19 Cyber Threat Coalition https://www.cyberthreatcoalition.org/ Cyber Threat Alliance https://www.cyberthreatalliance.org/ COVID-19 Has United Cybersecurity Experts, But Will That Unity Survive the Pandemic? https://krebsonsecurity.com/2020/04/covid-19-has-united-cybersecurity-experts-but-will-that-unity-survive-the-pandemic/ More cybersecurity and other vendors stepping up with free products for healthcare and other impacted organizations https://www.helpnetsecurity.com/2020/04/15/microsoft-accountguard-healthcare/ https://www.helpnetsecurity.com/2020/04/08/cybersecurity-pandemic-try-solutions/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Contact Tracing Controversy, Fighting COVID-19 Criminal Activity appeared first on Shared Security Podcast.

Apr 24, 202028 min

Zoom Hacked Accounts, North Korean Hackers, Facebook Senior Pictures

In episode 117 for April 20th 2020: More problems for Zoom with tens of thousands of compromised credentials and zero-day exploits, the $5 million dollar reward for information on North Korean hackers, and why it might not be the best idea to post your senior year pictures on Facebook. ** Show notes and links mentioned on the show ** Over 500,000 Zoom accounts sold on hacker forums, the dark web https://www.bleepingcomputer.com/news/security/over-500-000-zoom-accounts-sold-on-hacker-forums-the-dark-web/ Hackers Are Selling a Critical Zoom Zero-Day Exploit for $500,000 https://www.vice.com/en_us/article/qjdqgv/hackers-selling-critical-zoom-zero-day-exploit-for-500000 US offers $5 million reward for information on North Korean hackers https://www.zdnet.com/article/us-offers-5-million-reward-for-information-on-north-korean-hackers/ DPRK Cyber Threat Advisory https://www.us-cert.gov/sites/default/files/2020-04/DPRK_Cyber_Threat_Advisory_04152020_S508C.pdf Have you shared your old senior photo on Facebook? Hackers may be using your post against you https://www.cbsnews.com/news/have-you-shared-your-old-senior-photos-on-facebook-hackers-may-be-using-it-against-you/ Download our free Facebook Privacy & Security Guide! https://sharedsecurity.net/facebook ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Zoom Hacked Accounts, North Korean Hackers, Facebook Senior Pictures appeared first on Shared Security Podcast.

Apr 20, 202011 min

Contact Tracing Apps, Business Email Compromise Scams, SPAM Phone Calls

In episode 116 for April 13th 2020: Privacy concerns with COVID-19 contact tracing apps, the FBI’s new warnings about business email compromise scams, and how to prevent unwanted and SPAM phone calls. ** Show notes and links mentioned on the show ** Help speed up contact tracing with TraceTogether https://www.gov.sg/article/help-speed-up-contact-tracing-with-tracetogether COVID-19 contact tracing: Canadian company says authorities not interested in app that could help with virus https://www.msn.com/en-ca/news/canada/covid-19-contact-tracing-canadian-company-says-authorities-not-interested-in-app-that-could-help-with-virus/ar-BB12lAyG?li=AAggXBV FBI warns again of BEC scammers exploiting cloud email services https://www.bleepingcomputer.com/news/security/fbi-warns-again-of-bec-scammers-exploiting-cloud-email-services/ CEO Fraud – What is a BEC scam? https://fraudwatchinternational.com/expert-explanations/what-is-a-bec-scam/ Study: State of Robocalls in the U.S. https://www.roboshield.com/blog/dealing-with-unwanted-calls/ The FCC’s Push to Combat Robocalls & Spoofing https://www.fcc.gov/about-fcc/fcc-initiatives/fccs-push-combat-robocalls-spoofing ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Contact Tracing Apps, Business Email Compromise Scams, SPAM Phone Calls appeared first on Shared Security Podcast.

Apr 13, 202012 min

Another Marriott Data Breach, Zoom-Bombing, Economic Stimulus Scams

In episode 115 for April 6th 2020: The latest on yet another Marriott data breach, what you need to know about Zoom-Bombing and other Zoom privacy concerns, and new warnings about US economic stimulus payment scams. ** Show notes and links mentioned on the show ** Marriott discloses another security breach that may impact over 5 million guests https://www.theverge.com/2020/4/1/21203313/marriott-database-security-breach-5-million-guest Marriott International: Incident Notification https://mysupport.marriott.com/ Zoom to iPhone users: We’re no longer sending your data to Facebook https://www.zdnet.com/article/zoom-to-iphone-users-were-no-longer-sending-your-data-to-facebook/ Zoom to iPhone users: We’re no longer sending your data to Facebook https://www.yahoo.com/news/trolls-started-invading-public-zoom-211626623.html Zoom Lets Attackers Steal Windows Credentials, Run Programs via UNC Links https://www.bleepingcomputer.com/news/security/zoom-client-leaks-windows-login-credentials-to-attackers/ Zoom Meetings Aren’t End-to-End Encrypted, Despite Misleading Marketing https://theintercept.com/2020/03/31/zoom-meeting-encryption/ Zoom: We’re freezing all new features to sort out security and privacy https://www.zdnet.com/article/zoom-were-freezing-all-new-features-to-sort-out-security-and-privacy/ IRS Warns of Surge in Economic Stimulus Payment Scams https://www.bleepingcomputer.com/news/security/irs-warns-of-surge-in-economic-stimulus-payment-scams/ Official IRS Coronavirus Relief Webpage https://www.irs.gov/coronavirus ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Another Marriott Data Breach, Zoom-Bombing, Economic Stimulus Scams appeared first on Shared Security Podcast.

Apr 6, 202011 min

Staying Secure When Working From Home

In episode 114 for March 30th 2020: Co-host Tom Eston is joined with frequent guest Kevin Johnson to discuss how to stay more secure when working from home. If you find yourself working from home because of COVID-19 this is one episode you don’t want to miss! ** Show notes and links mentioned on the show ** Social isolation is a risk factor for scam loss https://www.helpnetsecurity.com/2020/03/24/risk-scams/ The State of Cybersecurity Training and Certifications with Kevin Johnson https://sharedsecurity.net/2019/04/25/the-state-of-cybersecurity-training-and-certifications-with-kevin-johnson/ How I Became a Security Consultant: AbsoluteAppsec Interview https://blog.secureideas.com/2020/03/how-i-became-a-security-consultant-absoluteappsec-interview.html Secure Ideas Affordable Cybersecurity Training Offerings https://secureideas.com/training ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Staying Secure When Working From Home appeared first on Shared Security Podcast.

Mar 30, 202019 min

Click Armor Demo, Podcast Survey Results, Google Geofence Warrants

In episode 98 of our monthly show co-host Scott Wright shows us a demo of Click Armor which is a gamified cybersecurity awareness platform, Tom presents the results of our listener survey, and we have a discussion about the privacy concerns with geofence warrants. ** Show notes and links mentioned on the show ** Take the Click Armor 3-minute interactive assessment: Can I be Phished? https://www.clickarmor.ca/canibephished Google tracked his bike ride past a burglarized home. That made him a suspect. https://www.nbcnews.com/news/us-news/google-tracked-his-bike-ride-past-burglarized-home-made-him-n1151761 ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post Click Armor Demo, Podcast Survey Results, Google Geofence Warrants appeared first on Shared Security Podcast.

Mar 25, 202045 min

COVID-19 Mass Surveillance, New Coronavirus Cyber-Attacks, Encryption Backdoors

In episode 113 for March 23rd 2020: Israel passes an emergency law to use mobile data to track people infected with COVID-19, the latest coronavirus cyber-attacks to be aware of, and how governments world-wide could be putting backdoors into secure messaging apps. ** Show notes and links mentioned on the show ** Israel passes emergency law to use mobile data for COVID-19 contact tracing https://www.bbc.com/news/technology-51930681 To Track Virus, Governments Weigh Surveillance Tools That Push Privacy Limits https://www.wsj.com/articles/to-track-virus-governments-weigh-surveillance-tools-that-push-privacy-limits-11584479841 WhatsApp And Signal Replaced By New Mystery Messaging App for EU Diplomats https://www.forbes.com/sites/zakdoffman/2020/02/27/whatsapp-and-signal-replaced-by-new-mystery-messaging-app-this-eu-change-matters-heres-why/#4cea89017ba9 The EARN IT Bill Is the Government’s Plan to Scan Every Message Online https://www.eff.org/deeplinks/2020/03/earn-it-bill-governments-not-so-secret-plan-scan-every-message-online Hackers Created Thousands of Coronavirus (COVID-19) Related Sites As Bait https://thehackernews.com/2020/03/covid-19-coronavirus-hacker-malware.html CovidLock: Android Ransomware Walkthrough and Unlocking Routine https://www.zscaler.com/blogs/research/covidlock-android-ransomware-walkthrough-and-unlocking-routine ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/c/SharedSecurityPodcast The post COVID-19 Mass Surveillance, New Coronavirus Cyber-Attacks, Encryption Backdoors appeared first on Shared Security Podcast.

Mar 23, 20209 min

COVID-19 Cybersecurity Impact, Hacking the Hackers, Whisper App Data Leak

In episode 112 for March 16th 2020: The cybersecurity impact of COVID-19, who’s hacking the hackers, and details on a data leak of the secret sharing app Whisper. ** Show notes and links mentioned on the show ** Resilient in Times of Disruption https://www.rsa.com/en-us/blog/2020-03/resilient-in-times-of-disruption COVID-19 coronavirus outbreak and a security conference tries to play it down https://www.zdnet.com/article/covid-19-outbreak-and-a-security-conference-tries-to-play-it-down/ Cybercriminals leveraging coronavirus outbreak to execute ransomware attacks https://www.helpnetsecurity.com/2020/03/11/coronavirus-ransomware-attacks Employees Are Working From Home — Do You Know Where Your Remote Work Policy Is? https://securityintelligence.com/employees-are-working-from-home-do-you-know-where-your-remote-work-policy-is/ Hackers are targeting other hackers by infecting their tools with malware https://techcrunch.com/2020/03/09/hacking-the-hackers https://www.cybereason.com/blog/whos-hacking-the-hackers-no-honor-among-thieves Whisper, an anonymous secret-sharing app, failed to keep messages or profiles private https://www.zdnet.com/article/whisper-an-anonymous-secret-sharing-app-failed-to-keep-messages-profiles-private/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post COVID-19 Cybersecurity Impact, Hacking the Hackers, Whisper App Data Leak appeared first on Shared Security Podcast.

Mar 16, 202011 min

IoT Device Attacks, FCC Fines Mobile Carriers, Let’s Encrypt Certificate Bug

In episode 111 for March 9th 2020: A new report shows that attacks on Internet of Things devices are on the rise, the FCC fines major mobile carriers for selling users’ location data, and details on what happens when 3 million HTTPS certificates need to be revoked because of coding error. ** Show notes and links mentioned on the show ** Take our podcast listener survey and be entered to win a $25 Amazon gift card! https://sharedsecurity.net/survey Attacks are targeting default passwords on IoT devices https://www.zdnet.com/article/these-are-the-top-passwords-hackers-will-try-when-attacking-your-device/ https://blog.f-secure.com/attack-landscape-h2-2019-an-unprecedented-year-cyber-attacks/ Basic rules for securing IoT devices at home https://krebsonsecurity.com/2018/01/some-basic-rules-for-securing-your-iot-stuff/ The FCC fines wireless companies for selling users’ location data https://www.wired.com/story/fcc-fines-wireless-companies-selling-users-location-data/ T-Mobile data breach notification https://www.t-mobile.com/responsibility/consumer-info/cpni-notice Let’s Encrypt discovers CAA bug, must revoke customer certificates https://www.theregister.co.uk/2020/03/03/lets_encrypt_cert_revocation/ https://community.letsencrypt.org/t/revoking-certain-certificates-on-march-4/114864 https://arstechnica.com/information-technology/2020/03/lets-encrypt-holds-off-on-revocation-of-certificates/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post IoT Device Attacks, FCC Fines Mobile Carriers, Let’s Encrypt Certificate Bug appeared first on Shared Security Podcast.

Mar 9, 202010 min

You’ve Been Hacked! Now What?

In episode 110: Tyler Hudak, Incident Response Practice Lead at TrustedSec, joins us to talk about what you should do (and more importantly what you shouldn’t do) if you find out you’ve been hacked! ** Show notes and links mentioned on the show ** Take our podcast listener survey and be entered to win a $25 Amazon gift card! https://sharedsecurity.net/survey Connect with Tyler https://twitter.com/secshoggoth https://www.linkedin.com/in/tylerhudak https://secshoggoth.blogspot.com/ Find out more about TrustedSec https://www.trustedsec.com/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post You’ve Been Hacked! Now What? appeared first on Shared Security Podcast.

Mar 2, 202015 min

Ring Mandates Two-Factor Authentication, License Plate Reader Data Sharing, RSA Conference Coronavirus Fears

In episode 109 for February 24th 2020: Kevin Johnson joins us to discuss how Ring made two-factor authentication mandatory following recent hacking incidents, California police have been caught illegally sharing license plate reader data, and details on IBM and other companies pulling out of the RSA conference due to coronavirus fears. ** Show notes and links mentioned on the show ** Take our podcast listener survey and be entered to win a $25 Amazon gift card! https://sharedsecurity.net/survey Ring Makes 2-Factor Authentication Mandatory Following Recent Hacks https://thehackernews.com/2020/02/ring-cameras-cybersecurity.html https://www.eff.org/deeplinks/2020/02/ring-updates-device-security-and-privacy-ignores-larger-concerns California Police Have Been Illegally Sharing License Plate Reader Data https://www.vice.com/en_us/article/y3mb8b/california-police-have-been-illegally-sharing-license-plate-reader-data IBM pulls out of the RSA conference due to coronavirus fears https://www.rsaconference.com/novel-coronavirus-update ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Ring Mandates Two-Factor Authentication, License Plate Reader Data Sharing, RSA Conference Coronavirus Fears appeared first on Shared Security Podcast.

Feb 24, 202022 min

Chinese Hackers, Coronavirus Phishing Attacks, How to Stay (Almost) Anonymous Online

In episode 97 of our monthly show we discuss how Chinese hackers caused the Equifax data breach, new coronavirus phishing attacks to be aware of, and how to stay (almost) anonymous online. ** Show notes and links mentioned on the show ** U.S. Charges 4 Chinese Military Officers in 2017 Equifax Hack https://krebsonsecurity.com/2020/02/u-s-charges-4-chinese-military-officers-in-2017-equifax-hack/ Phishers impersonate WHO, exploit coronavirus-related anxiety https://www.helpnetsecurity.com/2020/02/07/coronavirus-fake-emails/ 8 steps to being (almost) completely anonymous online https://www.csoonline.com/article/2975193/9-steps-completely-anonymous-online.html ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Chinese Hackers, Coronavirus Phishing Attacks, How to Stay (Almost) Anonymous Online appeared first on Shared Security Podcast.

Feb 21, 202042 min

Equifax Hacked by China, Israeli Voter Registry Exposed, How the CIA Owned Encryption

In episode 108 for February 17th 2020: The US charges four Chinese military hackers in the Equifax data breach, how Israel’s entire voter registry was exposed, and details on the encryption provider that was secretly owned by the CIA for the last fifty years. ** Show notes and links mentioned on the show ** U.S. charges four Chinese military hackers in 2017 Equifax breach https://www.reuters.com/article/us-usa-justice-cyber-idUSKBN2041RT https://krebsonsecurity.com/2020/02/u-s-charges-4-chinese-military-officers-in-2017-equifax-hack/ Netanyahu’s party left Israel’s entire voter registry exposed https://www.engadget.com/2020/02/09/likud-left-israel-voter-database-exposed/ https://www.nytimes.com/2020/02/10/world/middleeast/israeli-voters-leak.html CIA Secretly Owned Global Encryption Provider, Built Backdoors, Spied On 100+ Foreign Governments https://www.washingtonpost.com/graphics/2020/world/national-security/cia-crypto-encryption-machines-espionage/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Equifax Hacked by China, Israeli Voter Registry Exposed, How the CIA Owned Encryption appeared first on Shared Security Podcast.

Feb 17, 202010 min

Preventing Tax Identity Theft, FTC and Robocallers, Google Photos Incident

In episode 107 for February 10th 2020: preventing tax identity theft and other tax scams, the FTC taking a stand against companies that support robocallers, and details on the incident where videos from Google Photos were being sent to strangers. ** Show notes and links mentioned on the show ** Preventing Tax Identity Theft and other Tax Scams https://www.consumer.ftc.gov/features/tax-identity-theft-awareness FTC warns VoIP providers that help robocallers: we can and will sue https://nakedsecurity.sophos.com/2020/02/03/ftc-warns-voip-providers-that-help-robocallers-we-can-and-will-sue/ Google Photos accidentally sent people’s private videos to strangers https://www.technologyreview.com/f/615140/google-accidentally-sent-peoples-private-videos-to-strangers/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Preventing Tax Identity Theft, FTC and Robocallers, Google Photos Incident appeared first on Shared Security Podcast.

Feb 10, 20208 min

Off-Facebook Activity Tool, Ring App Third-Party Trackers, Wawa Credit Card Breach

In episode 106 for February 3rd 2020: What you need to know about Facebook’s new off-Facebook activity tool, details about the Ring Android app sending user data to third party trackers, and new developments in the Wawa credit card breach. ** Show notes and links mentioned on the show ** Off-Facebook Activity is a Welcome but Incomplete Move https://www.eff.org/deeplinks/2020/01/facebook-history-welcome-incomplete-move How to Change Your Off-Facebook Activity Settings https://www.eff.org/deeplinks/2020/01/how-change-your-facebook-activity-settings Link to Facebook to change your Off-Facebook Activity Settings https://www.facebook.com/off_facebook_activity Ring Android App Sent Sensitive User Data to 3rd Party Trackers https://www.eff.org/deeplinks/2020/01/ring-doorbell-app-packed-third-party-trackers Wawa card breach may rank as one of the biggest of all times https://www.zdnet.com/article/wawa-card-breach-may-rank-as-one-of-the-biggest-of-all-times/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Off-Facebook Activity Tool, Ring App Third-Party Trackers, Wawa Credit Card Breach appeared first on Shared Security Podcast.

Feb 3, 20209 min

Voting by Smartphone, Jeff Bezos Hacked, Microsoft Security Breach

In episode 96 of our monthly we discuss the controversy of voting by smartphone in our elections, the Jeff Bezos hacking incident, and the recent Microsoft support security breach. ** Show notes and links mentioned on the show ** Seattle-Area Voters To Vote By Smartphone In 1st For U.S. Elections https://www.npr.org/2020/01/22/798126153/exclusive-seattle-area-voters-to-vote-by-smartphone-in-1st-for-u-s-elections Saudi Prince Allegedly Hacked World’s Richest Man Jeff Bezos Using WhatsApp https://thehackernews.com/2020/01/saudi-prince-allegedly-hacked-worlds.html Microsoft discloses security breach of customer support database https://www.zdnet.com/article/microsoft-discloses-security-breach-of-customer-support-database/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Voting by Smartphone, Jeff Bezos Hacked, Microsoft Security Breach appeared first on Shared Security Podcast.

Jan 31, 202031 min

Dark Web Fraud and Cybercrime with Emily Wilson

In episode 105 for January 27th 2020: What are the new forms of fraud and cybercrime being found on the Dark Web? We discuss this fascinating topic with Emily Wilson, VP of Research at Terbium Labs. ** Show notes and links mentioned on the show ** Emily’s Dark Reading Article: Fraud in the New Decade https://www.darkreading.com/application-security/fraud-in-the-new-decade/a/d-id/1336671 Terbium Labs https://terbiumlabs.com/ https://twitter.com/TerbiumLabs Connect with Emily https://twitter.com/thirdemily https://www.linkedin.com/in/emily-e-wilson/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Dark Web Fraud and Cybercrime with Emily Wilson appeared first on Shared Security Podcast.

Jan 27, 202016 min

Critical Windows Vulnerability, Dating App Security Risk, Apple iOS Privacy Features

In episode 104 for January 20th 2020: Details on the new critical Microsoft Windows vulnerability, why dating apps could pose a national security risk, and how new Apple privacy features are changing the way your data is sold. ** Show notes and links mentioned on the show ** Major Windows flaw was discovered and reported by the NSA https://www.cnet.com/news/major-windows-10-flaw-was-reportedly-discovered-by-the-nsa/ https://media.defense.gov/2020/Jan/14/2002234275/-1/-1/0/CSA-WINDOWS-10-CRYPT-LIB-20190114.PDF https://www.us-cert.gov/ncas/alerts/aa20-014a https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0601 Windows 7 end of life announcement https://support.microsoft.com/en-us/help/4057281/windows-7-support-ended-on-january-14-2020 Apple’s new privacy features have further rattled the location-based ad market https://digiday.com/marketing/apples-new-privacy-features-rattle-location-based-ad-market ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Critical Windows Vulnerability, Dating App Security Risk, Apple iOS Privacy Features appeared first on Shared Security Podcast.

Jan 20, 202010 min

Iranian Cyber-Attacks, Ring Class-Action Lawsuit, Preventing Calendar SPAM

In episode 103: The US Department of Homeland Security warns of Iranian cyber-attacks, Ring gets hit with a $5 million dollar class action lawsuit, and some quick tips on how to prevent calendar SPAM. ** Show notes and links mentioned on the show ** Iran maintains a robust cyber program and can execute cyber-attacks against the US https://www.us-cert.gov/ncas/alerts/aa20-006a https://sharedsecurity.net/2019/07/01/us-cyber-attack-on-iran-poor-government-cybersecurity-malvertising-campaigns/ https://www.dallasnews.com/news/politics/2020/01/07/texas-officials-fear-iranian-cyber-attack-attempts-may-be-increasing/ https://twitter.com/campuscodi/status/1213641008556265472 Ring faces a $5 million proposed class action lawsuit https://abcnews.go.com/US/amazon-ring-face-million-proposed-class-action-lawsuit/story?id=67948687 Preventing Calendar SPAM https://the-parallax.com/2019/08/29/how-to-stop-calendar-spam/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Iranian Cyber-Attacks, Ring Class-Action Lawsuit, Preventing Calendar SPAM appeared first on Shared Security Podcast.

Jan 13, 202010 min

New California Data Privacy Law, Wyze Data Leak, ToTok Spy App

In episode 102: Details on the new California data privacy law, the Wyze data leak, and what is the ToTok app and could it be spying on you? ** Show notes and links mentioned on the show ** Enter our Silent Pocket New Year’s Giveaway – Deadline to enter: January 11th 2020 https://kingsumo.com/g/jsz2pk/silent-pocket-faraday-bag-new-years-giveaway Details on the new California data privacy law https://www.npr.org/2019/12/30/791190150/california-rings-in-the-new-year-with-a-new-data-privacy-law https://news.yahoo.com/california-apos-privacy-law-finally-110223203.html Wyze leaked personal data of 2.4 million users https://www.engadget.com/2019/12/30/wyze-leak-2-4-million-users/ https://www.bleepingcomputer.com/news/security/wyze-exposes-user-data-via-unsecured-elasticsearch-cluster/ https://ipvm.com/reports/wyze-employee https://forums.wyzecam.com/t/updated-12-27-19-data-leak-12-26-2019/79046 What is ToTok and is it a spy app? New York Times Article Twitter response from ToTok about the Google and Apple app store ban ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post New California Data Privacy Law, Wyze Data Leak, ToTok Spy App appeared first on Shared Security Podcast.

Jan 6, 202010 min

Top 10 Cybersecurity and Privacy Resolutions

In episode 101: Start the new year off right by following our top 10 cybersecurity and privacy resolutions! ** Show notes and links mentioned on the show ** Recommended Password Managers KeePass (free and open source): https://keepass.info/ Dashlane: https://www.dashlane.com/ 1Password: https://1password.com/ See if your site or service offer’s two-factor or multi-factor authentication https://twofactorauth.org/ Silent Pocket Faraday bag to protect your smartphone or laptop (use discount code “sharedsecurity” and get 15% off your order!) https://silent-pocket.com The new Firefox web browser offers blocking of third-party trackers by default https://www.mozilla.org/en-US/firefox/new/ https://blog.mozilla.org/press/2019/10/latest-firefox-brings-privacy-protections-front-and-center-letting-you-track-the-trackers/ Recommended Web Browser Ad Blockers and Privacy Plugins https://github.com/gorhill/uBlock https://www.eff.org/privacybadger Freeze your credit to prevent credit card fraud https://krebsonsecurity.com/2015/06/how-i-learned-to-stop-worrying-and-embrace-the-security-freeze/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Top 10 Cybersecurity and Privacy Resolutions appeared first on Shared Security Podcast.

Dec 30, 20198 min

Rebecca Herold “The Privacy Professor”

In episode 95 of our monthly show we’re joined by special guest Rebecca Herold, the “Privacy Professor”. Rebecca is a well known expert in the privacy and cybersecurity community and gives us an update on what she’s been working on, what her thoughts are on the current state of privacy regulations (CCPA, GLBA, etc), and what we may see in 2020 from a privacy perspective. We also talk about Rebecca’s favorite books and her encounter with famed author Cliff Stoll who wrote “The Cuckoo’s Egg”. Thanks to Rebecca for joining us again on the show! ** Show notes and links mentioned on the show ** Rebecca’s previous interview on episode 71 (January 2018) Rebecca’s work on the NIST Privacy Framework Rebecca’s podcast “Data Security & Privacy with the Privacy Professor You should read The Cuckoo’s Egg (this is a must read for anyone in privacy or cybersecurity!) Find out more about Rebecca and her work at privacyprofessor.com Follow Rebecca on Twitter and LinkedIn ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Rebecca Herold “The Privacy Professor” appeared first on Shared Security Podcast.

Dec 27, 201942 min

The Year in Review and 2020 Predictions with Kevin Johnson

In episode 100: Kevin Johnson, CEO of SecureIdeas joins us in this very special milestone episode to discuss the year that was 2019 and what Kevin’s “predictions” are for cybersecurity and privacy 2020. Thank you to Kevin for being our special guest! ** Show notes and links mentioned on the show ** The Nerf Dart “head-shot” that will live in infamy (yes, Kevin..it’s in the show notes) Professionally Evil CISSP Mentorship Class – Starting in January https://training.secureideas.com/course/cissp-mentor/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post The Year in Review and 2020 Predictions with Kevin Johnson appeared first on Shared Security Podcast.

Dec 23, 201916 min

The Password Reuse Problem, US Government IoT Recommendations, Smart Lock Security Disaster

In episode 99: Password reuse is still a very large problem, US government recommendations for securing Internet of Things devices, and yet another smart lock device security disaster. ** Show notes and links mentioned on the show ** Password reuse continues to be a major problem https://www.microsoft.com/securityinsights/Identity https://resources.hypr.com/top-recommendations/password-usage-study https://www.nbcnews.com/news/us-news/man-hacks-ring-camera-8-year-old-girl-s-bedroom-n1100586 US government recommendations for securing Internet of Things devices https://www.bleepingcomputer.com/news/security/fbi-recommends-securing-your-smart-tvs-and-iot-devices/ https://www.bleepingcomputer.com/news/security/ftc-advises-checking-smart-toy-features-before-buying/ Another “smart” lock device security disaster https://www.helpnetsecurity.com/2019/12/11/keywe-smart-lock/ https://sharedsecurity.net/2019/10/14/hong-kong-protests-instagrams-anti-phishing-tool-smart-device-fail/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com to check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Help support the show ** Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/   The post The Password Reuse Problem, US Government IoT Recommendations, Smart Lock Security Disaster appeared first on Shared Security Podcast.

Dec 16, 201911 min

How You’re Tracked Online, New Mass Surveillance Concerns, Malicious Android App Hijack

In episode 98: A new report from the EFF details how we are tracked online by third-party corporations, more mass surveillance concerns in China and Australia, and a malicious app hijack attack on Android to be aware of. ** Show notes and links mentioned on the show ** How You’re Tracked Online – Must Read Research from the EFF https://www.eff.org/press/releases/eff-report-exposes-explains-big-techs-personal-data-trackers-lurk-social-media https://www.eff.org/wp/behind-the-one-way-mirror EFF’s Privacy Badger uBlock Origin New Privacy Concerns in China and Australia https://www.engadget.com/2019/12/01/china-requires-face-scans-for-mobile-service-users/ https://www.engadget.com/2019/12/01/australia-rolls-out-ai-cameras-to-spot-drivers-using-their-phone/ Malicious Android Apps in the Wild https://www.zdnet.com/article/android-new-strandhogg-vulnerability-is-being-exploited-in-the-wild/ ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com and check out Silent Pocket’s amazing line of Faraday Bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post How You’re Tracked Online, New Mass Surveillance Concerns, Malicious Android App Hijack appeared first on Shared Security Podcast.

Dec 9, 201910 min

Top 25 Most Dangerous Vulnerabilities, Smart City Privacy, DuckDuckGo vs. Google

In episode 94 of our monthly show for November 2019: The 25 most dangerous vulnerabilities, the privacy of new “smart cities”, and which search engine keeps your searches more private? It’s DuckDuckGo vs. Google! ** Show notes and links mentioned on the show ** Snapshot: Top 25 Most Dangerous Software Errors https://www.dhs.gov/science-and-technology/news/2019/11/26/snapshot-top-25-most-dangerous-software-errors https://www.theregister.co.uk/2019/09/18/the_25_most_dangerous_software_weaknesses/ Google’s “smart city” in Toronto: what it wanted, what it will now get – and why it’s still problematic for privacy Toyota, Lexus owners warned about thefts that use ‘relay attacks’ I ditched Google for DuckDuckGo. Here’s why you should too Sign-up for Rebecca Herold’s privacy newsletter – It’s great! Check out the interview with co-host Tom Eston who was interviewed on the Infosec Career Podcast ** Thank you to our sponsors! * Silent Pocket Visit https://silent-pocket.com check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Top 25 Most Dangerous Vulnerabilities, Smart City Privacy, DuckDuckGo vs. Google appeared first on Shared Security Podcast.

Dec 6, 201932 min

Phone and Voice Fraud, Twitter Account Purge, Adobe Magento Marketplace Data Breach

In episode 97 for December 2nd 2019: How to prevent phone and voice fraud, Twitter’s inactive account purge, and the Adobe Magento Marketplace data breach. ** Show notes and links mentioned on the show ** Don’t become a victim of phone and voicemail fraud https://www.darkreading.com/7-ways-to-hang-up-on-voice-fraud—/d/d-id/1336427 Twitter’s inactive account purge https://www.cnn.com/2019/11/27/tech/twitter-inactive-account-delete/index.html https://twitter.com/TwitterSupport/status/1199777313300209664 Adobe Magento Marketplace data breach https://nakedsecurity.sophos.com/2019/11/29/adobes-magento-marketplace-suffers-data-breach/ https://magento.com/blog/magento-news/magento-marketplace-security-update https://nakedsecurity.sophos.com/2019/04/05/patch-now-magento-e-commerce-sites-targeted-by-sqli-attacks/ ** Thank you to our sponsors! * Silent Pocket Visit https://silent-pocket.com check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Phone and Voice Fraud, Twitter Account Purge, Adobe Magento Marketplace Data Breach appeared first on Shared Security Podcast.

Dec 2, 20199 min

Disney+ Hacked Accounts, Black Friday Scams, Android Camera Exploits

In episode 96: Thousands of Disney+ accounts have been hacked, Black Friday and Cyber Monday scams to watch out for, and the latest on new Android camera exploits affecting Google and Samsung smartphones. ** Show notes and links mentioned on the show ** Disney+ accounts hacked shortly after the service launched https://www.zdnet.com/article/thousands-of-hacked-disney-accounts-are-already-for-sale-on-hacking-forums/ Find out which apps and sites offer two-factor authentication https://twofactorauth.org/ KeyPass – free password manager https://keepass.info/ List of popular password managers https://en.wikipedia.org/wiki/List_of_password_managers Black Friday and Cyber Monday scams to watch out for https://www.msn.com/en-us/money/personalfinance/black-friday-2019-how-scammers-use-gift-cards-hot-toy-deals-to-trick-you/ar-BBX2xEV?li=AA30Nm How attackers could hijack your Android camera to spy on you https://www.checkmarx.com/blog/how-attackers-could-hijack-your-android-camera https://thehackernews.com/2019/11/android-camera-hacking.html ** Thank you to our sponsors! ** Silent Pocket Visit https://silent-pocket.com check out Silent Pocket’s amazing line of faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Edgewise Networks Find out how Edgewise can stop lateral threat movement and prevent data breaches. Visit https://edgewise.net and request a demo! ** Subscribe and follow the show ** Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, full transcripts of each weekly episode, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe Contact us: https://sharedsecurity.net/contact Website: https://sharedsecurity.net Twitter: https://twitter.com/sharedsec Facebook: https://facebook.com/sharedsec Instagram: https://instagram.com/sharedsecurity YouTube: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/ The post Disney+ Hacked Accounts, Black Friday Scams, Android Camera Exploits appeared first on Shared Security Podcast.

Nov 25, 201910 min

Google’s Health Record Storage Controversy, US Border Search Ruling, Zelle Scams

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 95 for November 18th 2019: Google’s access to the medical records of millions of Americans, a new ruling on suspicionless searches at the US border, and details on a new scam using the popular money sharing app Zelle. This week I read a news article about how more schools are either outright banning the use of smart phones or having kids put their phones in their lockers while in class. And while some kids may complain that they can’t use their device, teachers and school administrators are noticing that when there are no smart phones in school kids seem more engaged with their friends, less distracted, and even less stressed. I think this is a great idea and hope more schools start implementing similar polices but did you know that as adults we have the power to do the same thing? When was the last time you “docked” your phone during the day so you could be more engaged and less distracted. Well Silent Pocket has the perfect solution for this and it’s called a Faraday Bag. Simply place your smart phone in one of their stylish faraday bags and you have instant silence, privacy, and quick way to be more engaged with the people around us. Pick up one today at silentpocket.com and use discount code “sharedsecurity” at checkout to receive 15% off your order. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. I realize that just a few weeks ago I talked about Facebook’s new preventive health tool that is apparently not collecting patient data, but this past week it was reported that Google actually does have access to detailed medical records on tens of millions of Americans. But don’t worry, Google says that it promises to not mix patient data with all of the other massive amounts of data that Google collects about its users. The Wall Street Journal reported that Google has partnered with a company called Ascension, which is the second largest healthcare system in the US, on a project to “collect and crunch the detailed personal-health information of millions of people across 21 states.” According to a statement from Ascension they say they are partnering with Google to improve the tools used by patients and caregivers as well as “explore artificial intelligence and machine learning applications that will have the potential to support improvements in clinical quality and effectiveness.” So what kind of healthcare data are we talking about? Well, pretty much everything including names, birthdates, addresses, family members, allergies, immunizations, radiology scans, hospitalization records, lab tests, medications, medical conditions, and even some billing claims. Shockingly, it seems that this partnership does not violate HIPAA (the Health Insurance Portability and Accountability Act) as the law does allow hospitals to share data with business partners as long as the data is used to help carry out its health care functions. Personally, I think this is a fine line that Google and Ascension are walking here. I mean, does anyone else find it ironic that Google also just purchased FitBit for $2.1 billion dollars? Don’t you think that it’s going to be really tempting for Google to find ways to combine or analyze Fitbit data with the detailed health care data of tens of millions of Americans? Even though it’s not too terribly shocking that Google is working with health care organizations but with the risk of data breaches and the constant mishandling of privacy information by the large tech firms, are we willing to let Google handle our health care data too? Perhaps we have no choice in the matter but at least the government does. In breaking news last week the Department of Health and Human Services stated that they will be opening up an investigation with Google to ensure that HIPPA protections were fully implemented. In privacy news this week, a federal court in Boston ruled that supicionless searches of travelers’ electronic devices by federal agents at airports and other US ports of entry are unconstitutional. The ruling stemmed from a lawsuit made by the ACLU and the EFF on behalf of 11 travelers who had their laptops and smart phones searched at US ports of entry without being suspected of any crime. This new ruling means that the Customs and Border Control and Immigration and Customs Enforcement agencies need to now demonstrate individualized suspicion of illegal digital contraband before they can search a travelers device. As we’ve reported on previous episodes of the podcast, these agencies have been searching the devices of international tra

Nov 18, 201911 min

Facebook Data Leaks, Smart Speaker Laser Attack, BlueKeep in the Wild

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 94 for November 11th 2019: Facebook’s Group API data leak and 7,000 pages of leaked Facebook documents, lasers that can control your smart speakers, and details about the BlueKeep vulnerability now being exploited in the wild. Are you like most of us that have to be constantly checking our smart phones for the latest Tweet or Facebook update? How many of us are actually doing this while we’re driving? Distracted driving is one of the most common ways accidents and even deaths happen on the road these days and a lot of states in the US have started enacting laws prohibiting the complete use of smart phones while driving. It’s just not worth putting ourselves and others at risk so I’ve committed to not use my smart phone while driving, and so should you. One easy solution I recommend is to store your smart phone in a Silent Pocket Faraday Sleeve. It’s small enough to store in your glove compartment or arm rest and it’s quick and easy to use. Pick one up today by visiting silentpocket.com and receive 15% off your order at checkout using discount code “sharedsecurity”. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. It seems that we can’t go a single week from reporting news about yet another Facebook data leak or controversy. This week is no exception as Facebook disclosed details about a leak of private group information such as post details, number of group users, and depending if group users opted-in: names and profile pictures. This data may have been accessed by about 100 partners which had video streaming and social media management apps integrated into certain Facebook Groups. Apparently, the issue happened when Facebook was restricting access to the Groups API back in 2018. Facebook said that they believe 11 of these partners had accessed group information in the last 60 days and that they would kindly ask all 100 partners to delete any Facebook user data that they may have collected. Facebook also stated that there has been no evidence that Facebook user data was abused in any way but will be conducting audits to confirm that said partners have deleted user data as requested. In other Facebook news, NBC News released close to 7,000 pages of leaked documents that showed how Facebook was using user data as a bargaining chip with third-party developers. The data, which included 4000 internal Facebook emails, web chats, and documents show that Facebook would give certain types of user data to certain high-value customers while also restricting certain types of user data to rival companies. For example, Amazon got special access to more user data because they were paying for ads on Facebook and another company called MessageMe was completely cut off from user data because Facebook felt it was a competitor to its own Messenger product. Meanwhile, it was revealed that Facebook was using these moves to publicly show that they were protecting user privacy. This latest news is once again leaving Facebook in hot water with a continuing onslaught of lawsuits by former customers and government inquires. Oh and on top of this all this news, Facebook announced a new logo which I’m certain will make all of their privacy problems go away. The new logo, which is attempting to show that all of the Facebook “property” apps are similar, seems to be an attempt to make it harder for government regulators to breakup Facebook if that day ever comes. And now a word from our sponsor, Edgewise Networks. The biggest problem in security that remains unsolved is unprotected attack paths that allow threats to compromise vulnerable targets in the cloud and data center. But traditional microsegmentation is too complex and time consuming, and offers limited value that’s hard to measure. But there’s a better approach… Edgewise “Zero Trust Auto-Segmentation.” Edgewise is impossibly simple microsegmentation … delivering results immediately, with a security outcome that’s provable, and management that’s zero touch. At the core of Edgewise Auto-Segmentation is Zero Trust Identity, which automatically builds unique identities for all communicating software and devices by combining cryptographic properties of the workload with risk classifications. Edgewise protects any application, in any environment, without any architectural changes. Edgewise provides measurable improvement by quantifying attack path risk reduction and demonstrates isolation between critical services—so that your applications can’t be breached. Visit edgewise.net to find out more about how Edgewise can help stop data breaches. I&#821

Nov 11, 201911 min

WhatsApp’s NSO Group Lawsuit, This Week in Data Breaches, Office 365 Voicemail Phishing

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 93 for November 4th 2019: The WhatsApp NSO group lawsuit plus details on Facebook’s preventive health tool, this week’s data breach news, and how attackers are using a voicemail to phish Microsoft Office 365 users. Halloween may be over but this time of year doesn’t have to be scary when it comes to protecting your digital privacy. Silent Pocket makes it easy to protect your devices with their full line of faraday bags, wallets, and other accessories that will block all wireless signal. As a special treat for our podcast listeners you can receive 15% off your order right now at silentpocket.com using discount code “sharedsecurity” during checkout. No tricks involved in this exclusive offer. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. Will Cathcart, the head of WhatsApp which is a Facebook company, wrote an opt-ed for the Washington Post stating that WhatsApp has filed a complaint in US federal court against the infamous Israeli company, the NSO Group. You may remember that several months ago a serious vulnerability was found in WhatsApp in which malicious code was delivered via a seemingly innocent video call compromising the app and device. Through WhatsApp’s own investigation, in partnership with activist group Citizen Lab, they detailed how NSO Group servers, Internet-hosted services and certain WhatsApp accounts were traced back to the NSO Group during their investigation of the attacks. In addition, it was discovered that at least 100 human-rights defenders and journalists were targeted using this NSO spyware, most likely a form of Pegasus ,which is known as the spyware of choice for nation states to target specific individuals. Of course, the NSO Group as expected, has denied any involvement in the attack. Check out our show notes for the link to the full federal complaint to read the details for yourself. In other Facebook news, Facebook announced that they are developing new partnerships and programs to support people that want to connect with resources to support their health. One of those resources is something called the “Preventive Health Tool” available in the US. This new tool will allow Facebook users to find doctors, set appointment reminders to schedule tests, note them as completed, and much more. Facebook says that their reason for doing this is to spread more awareness about preventive care for things like cancer screenings. Now I’m sure the first thing you’re thinking is, will Facebook now have access to my health care data? Well Facebook says quote “Preventive Health allows you to set reminders for your future checkups and mark them as done, but it doesn’t provide us, or the health organizations we’re working with, access to your actual test results. Personal information about your activity in Preventive Health is not shared with third parties, such as health organizations or insurance companies, so it can’t be used for purposes like insurance eligibility” end quote. Now your next question is probably about how many more heath care related ads will I start seeing on Facebook if I use this tool? Well Facebook has an answer to that and says quote “We don’t show ads based on the information you provide in Preventive Health — that includes things like setting a reminder for a test, marking it as done or searching for a healthcare location. As always, other actions that you take on Facebook could inform the ads you see, for example, liking the Facebook page of a health organization or visiting an external website linked to or from Preventive Health.” end quote And that last sentence is key. Ultimately, the more time you spend on Facebook, the more opportunity you have to see ads in general, but by also liking a page of a health care organization or visiting an external website you are still giving Facebook little pieces of information that can be used to track you and eventually, serve you…guess what? More ads. And now a word from our sponsor, Edgewise Networks. The biggest problem in security that remains unsolved is unprotected attack paths that allow threats to compromise vulnerable targets in the cloud and data center. But traditional microsegmentation is too complex and time consuming, and offers limited value that’s hard to measure. But there’s a better approach… Edgewise “Zero Trust Auto-Segmentation.” Edgewise is impossibly simple microsegmentation … delivering results immediately, with a security outcome that’s provable, and management that’s zero touch. At the core of Edgewise Auto-Segmentation is Zero Trust Identity, w

Nov 4, 201910 min

Firewalla Review, 15 Most Dangerous Apps for Kids, Rise of the Deepfake

In episode 93 of our monthly show we review the Firewalla home network device, talk about the 15 most dangerous (or scary) apps for kids that parents need to be aware of, and the rise of the “deepfake”! Watch the recording of our live stream on YouTube (we’re not sure what happened with Scott’s out-of-sync and choppy video so we apologize for our technical difficulties): Here are the show notes and links to articles discussed during the show: Tom’s review of the Firewalla home network protection device Description of the Firewalla Blue and Firewalla Red Firewalla router compatibility list Information about compatibility with mesh routers like Google WiFi Charts and graphs regarding network usage in the mobile app Information about activity and parental controls Buy one on Amazon 15 Most Dangerous Apps for Kids Article with the list of apps mentioned on the show The Rise of the Deepfake Deepfake video of Mark Zuckerberg Guardian article about “The rise of the deepfake and the threat to democracy” which also has the clips of the Jimmy Fallon deepfake and Nancy Pelosi edited video (not a deepfake) Please support our sponsors, Silent Pocket and Edgewise Networks: Looking to up your privacy and security game while you travel? Then you need to check out Silent Pocket’s patented product line of faraday bags, wallets, backpacks, and other accessories at silentpocket.com. Be sure to use discount code “sharedsecurity” at checkout to receive 15% off your order. The biggest problem in security that remains unsolved is unprotected attack paths that allow threats to compromise vulnerable targets in the cloud and data center. But traditional microsegmentation is too complex and time consuming, and offers limited value that’s hard to measure. But there’s a better approach… Edgewise “Zero Trust Auto-Segmentation.” Edgewise is impossibly simple microsegmentation … delivering results immediately, with a security outcome that’s provable, and management that’s zero touch. At the core of Edgewise Auto-Segmentation is Zero Trust Identity, which automatically builds unique identities for all communicating software and devices by combining cryptographic properties of the workload with risk classifications. Edgewise protects any application, in any environment, without any architectural changes. Edgewise provides measurable improvement by quantifying attack path risk reduction and demonstrates isolation between critical services—so that your applications can’t be breached. Visit edgewise.net to find out more about how Edgewise can help stop data breaches. Be sure to follow the Shared Security Podcast on Facebook, Twitter and Instagram for the latest news and commentary. If you have feedback or topic ideas for the show you can email us at feedback[aT]sharedsecurity.net. First time listener to the podcast? Please subscribe on your favorite podcast listening app or watch and subscribe on our YouTube channel. The post Firewalla Review, 15 Most Dangerous Apps for Kids, Rise of the Deepfake appeared first on Shared Security Podcast.

Nov 1, 201934 min

Nord VPN Security Incident, Smart Speaker Phishing, Apple iOS 13 Privacy Features

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 92 for October 28th 2019: Details on the Nord VPN security incident, using Amazon Echo and Google Home smart speakers for phishing attacks, and new privacy features in Apple iOS 13 you should know about. What does it mean to go off the grid? For most of us that are constantly relying on our phones, tablets, and laptops it means shutting them off and doing some other activity like enjoying nature or spending valuable time with friends and family. I don’t know about you but I struggle with turning off or putting down my phone because I’ve become so tied to it. I mean, have you ever forgotten your phone at home while you were driving to work or did you happen to find yourself in the wilderness or somewhere where you can’t get a cell phone signal? How did this make you feel? I know I have had that awkward feeling of “what if someone tried to message me?” or “how will anyone get ahold of me in an emergency”? In fact, how many of you would drive back home to retrieve your phone or walk around until you found a cell phone signal out in the middle of nowhere? Look it’s hard to go off the grid but the good news is that there are products that can help. That’s why I recommend using a Silent Pocket Faraday bag which can instantly block are wireless signals, quickly taking you off the grid. Check out their full product line at silentpocket.com. And because you listen to this podcast remember to use discount code “sharedsecurity” at checkout to receive 15% off your order. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. Popular VPN service provider Nord VPN disclosed that they were the victim of a security incident which happened about 16 months ago, back in March 2018. The attack compromised a server in Finland in which attackers were able to access encryption keys which could have been used to potentially decrypt user traffic, launch man-in-the-middle attacks, and even impersonate the nordvpn.com website. Attackers were able to access the server by exploiting an unnamed remote management system that was being used by the data center that housed one of the Nord VPN servers. One of the certificates the attackers gained access to was one that provides HTTPS encryption for nordvpn.com. This certificate wasn’t set to expire until October 2018, seven months after the breach. This means that for months, attackers could have been luring unsuspecting victims to phishing sites thinking they were signing up or accessing nordvpn.com. And to make matters worse details about the incident have been apparently floating around underground forums on the Internet since May of 2018. Nord VPN posted a blog about the incident and stated that no user accounts or user data was affected or that anyone attempted to monitor user traffic in any way. They also stated that the only attack possible would have been a personalized and highly sophisticated man-in-the-middle attack to intercept a single connection. And also restating that they are a “no logs” VPN provider so there would be nothing for an attacker to see anyway. This is contrary to what others in the media and security research community are saying noting that man-in-the-middle attacks are not that hard to pull off and that these types of attacks are actually what VPNs are supposed to help protect users from. The Nord VPN blog post also seemed to pass complete blame of the incident on the third-party datacenter which housed the server that was accessed. Nord VPN also stated that they did not disclose the breach to their customers and to the public quote “until we could be sure that such an attack could not be replicated anywhere else on our infrastructure. ” They also stated that they are preparing a bug bounty program and also conducting internal and external audits of all systems. In related news, two other VPN providers, TorGuard and VikingVPN also disclosed that they too had been hacked where encryption keys were also stolen around the same time period. The lesson here is that, besides a VPN provider perhaps not disclosing a breach or incident in a timely manner, the bigger issue here is twofold. First, understand that a VPN is not an end all be all solution to protect your privacy, contrary to what many of these VPN companies may say in their advertising. As seen with this incident, anyone can become a victim when there is a third-party involved, like an insecure remote management application which is managed by someone else. One perspective is that this incident wasn’t Nord VPNs fault, especially since they had no cont

Oct 28, 201913 min

Pitney Bowes Ransomware Attack, Samsung Galaxy S10 Fingerprint Bypass, Top Technology Fears

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 91 for October 21st 2019: Pitney Bowes becomes the latest ransomware victim, what are the top technology fears, and the latest on the vulnerability that allows a Samsung Galaxy S10 to be unlocked with anyone’s fingerprint. Smart phones and other mobile devices have truly become integrated with our daily lives. So much in fact, these devices are causing a new type of stress injury called “text neck”. Text neck is a stress injury which causes pain in your neck caused by excessive use or texting on a mobile device over a long period of time. This condition is increasingly concerning given that all of us seem to be looking down at our devices every minute of every day. Just take a look around you whenever you’re out in public. Our mobile devices have truly become a “pain in our neck”. So if you want an easy way to prevent this condition, try taking more breaks away from your device and simply just put your device down so you are less tempted to use it. And if you want an easy way to get off the grid for a while, put it in a Silent Pocket faraday bag. The nice thing about this solution is that you don’t even have to power off your device! Check out Silent Pocket’s full line of faraday bags and wallets at silentpocket.com and recieve 15% off your order during checkout using discount code “sharedsecurity”. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. Last week shipping and postage provider Pitney Bowes, which serves 90% of businesses in the Fortune 500, was the victim of a ransomware attack preventing customers from adding postage to packages and may have even impacted some mail delivery at the US Postal Service. In a statement the company said quote “Pitney Bowes was affected by a malware attack that encrypted information on some systems and disrupted customer access to some of our services. At this time, the company has seen no evidence that customer or employee data has been improperly accessed.” end quote Pitney Bowes is most known for its postage meters which can automate the painful process of putting postage on envelopes and packages. Some customers took to Twitter during the outage showing postage meters and associated software with errors and confusing messages about “system faults”. Apparently the meters would still work up until you had to refill funds in order to print out more postage. Check out our show notes for a link to the latest updates from Pitney Bowes on the status of their systems. In related news, late last week business credit rating agency Moody’s issued a “credit negative” event note regarding the ransomware attack meaning the credit agency is cautiously watching the incident but has yet to issue a ratings downgrade. Rating’s agencies like Moody’s are commonly referenced by investors and negative ratings can make it more difficult for a company to raise money and can drive the stock value down. This news is pretty significant in that ratings agencies are now monitoring companies for data breaches and other cybersecurity incidents and issuing ratings adjustments based on the impact of the incident. Just last May, Moody’s downgraded Equifax’s outlook to negative because of the massive data breach that we all know and love. And ironically, Equifax’s outlook remains negative for the foreseeable future. Ransomware attacks like these are continuing to rise, mostly because a lot of companies are paying the ransom because they feel they are left with no other option. The more companies pay, the more incentive there is for attackers to continue finding victims. The advice from law enforcement and the cybersecurity community is to never pay the ransom because there is no guarantee that you will get your data back. Rather, contact law enforcement or a third-party cybersecurity professional to help get your data back in other ways. For example, there is a site run by a security researcher called “ID Ransomware” which (as of this podcast recording) can decrypt 771 different types of ransomware by uploading the ransom note or sample encrypted file. This is a free service by the way and you have a much better chance of getting your data back by using a free service like this than ever paying the ransom. A recent survey of about 1,000 Americans from security solutions company Cove revealed people’s modern day safety and cybersecurity fears by gender, generation, and political party. Some of the most interesting findings say that four in five parents said that they were worried about raising

Oct 21, 201910 min

Hong Kong Protests, Instagram’s Anti-Phishing Tool, Smart Device Fail

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston In episode 90 for October 14th 2019: How protesters in Hong Kong are avoiding facial recognition, Instagram’s new anti-phishing tool, and my recent epic smart device failure incident. Being a frequent traveler myself, I’m always surprised at how many people at airports are not very aware of their privacy. Just last week while I was waiting for my flight I listened as someone was giving their credit card number over the phone, and another person had their laptop open and I was able to see a presentation they were working on which looked to have very sensitive business information. The message here is that we always need to be aware of our surroundings and be careful what you say or expose when you’re in a public place like an airport. And if you’re a privacy aware traveler like me I highly recommend using Silent Pocket’s product line of faraday bags, backpacks and wallets which are built with your digital privacy in mind. Check them out at silentpocket.com and receive 15% off your order at checkout using discount code “sharedsecurity” Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use” Violent protests continued in Hong Kong last week with the local authorities implementing a new anti-mask law which targets protestors wearing masks to avoid being recognized by the police and surveillance cameras. Now such bans are nothing new as Sri Lanka, France, the Netherlands, and Canada have similar controversial bans as well. Some protesters have even been seen wearing face paint in the form of Pepe the Frog which has recently been adopted as an international symbol of liberation for the Hong Kong protesters. Some protesters are even using laser pointers as a way to disable or make facial recognition technology harder to identify themselves. In related news, Apple has been criticized for removing an app from the Apple App Store because of pressure from the Chinese government. The app allowed protesters to crowdsource the locations of police. Apple is just the latest US based company joining the ranks of the NBA, and the video game company Blizzard who have given into Chinese pressure. This is very unfortunate and while I don’t bring up politics too much on this show, freedom loving people and companies should be supporting the protesters. And as a reminder, you as a consumer, have a choice on what products and entertainment you spend your money on. Now I bring up the Hong Kong protests because we all need to know that the technology that governments possess in order to identify protesters should be concerning to all of us. So when does the use of this technology truly become an invasion of our privacy all in the name of more security? Perhaps we’re already there. The good news is that we are seeing more privacy laws that several states in the US are now implementing. Just last week the state of California signed a bill into law that prevents police from using facial recognition technology on video recordings gathered by police officers. The bill states that quote “The use of facial recognition and other biometric surveillance is the functional equivalent of requiring every person to show a personal photo identification card at all times in violation of recognized constitutional rights.” end quote I think this is a positive sign that, at least in the US, facial recognition is beginning to become more regulated. Instagram has added a new security feature which will help you identify if an email was sent by Instagram or may be a phishing email. Here’s how this feature works. Let’s say you receive an email claiming to be from Instagram. You can now see if Instagram sent you that email by going into the “Emails from Instagram” option in your app’s settings. Within this setting you’ll be able to see every email that was sent to you by Instagram over the last 14 days. The new feature also separates emails into two categories; security emails and other. If you see an email that matches with what’s in your inbox than you can assume that this was a legitimate email. As you know, phishing emails are a constant threat and some recent Instagram phishing attacks are looking so legitimate that it’s very difficult to identify a real email vs. a fake one. Be on the lookout for this new and welcome security feature to show up in your Instagram account over the next several weeks. And now a word from our sponsor, Edgewise Networks. The biggest problem in security that remains unsolved is unprotected attack paths that allow threats to compromise vulnerable targets in the cloud and data

Oct 14, 201912 min

Microsoft OneDrive Personal Vault, Google’s New Privacy and Security Controls, REAL ID Deadline

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 89 for October 7th 2019: Microsoft’s new OneDrive personal vault, updated privacy and security controls announced by Google, and the TSA’s announcement about the REAL ID deadline next year. I have a question for you. What’s in your daily carry? Now I’m not talking about your concealed weapon of choice (if you do legally choose to do so) but I’m talking about your wallet, backpack, clutch, or other travel accessory. If you’re looking to upgrade to something that’s high quality, fashionable, and built with your digital privacy in mind you need to check out Silent Pocket. Visit their full line of products at silentpocket.com and use discount code “sharedsecurity” at checkout to take 15% off your order. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. Microsoft has increased the security and privacy of its OneDrive cloud storage service with a new feature called a “Personal Vault” which is now available worldwide for all OneDrive users except for those on business plans. Personal Vault is a protected area in OneDrive that requires additional authentication, like biometrics, a PIN code, or SMS-based two-factor authentication in order to access and store files. Microsoft has stated that on Windows 10 devices files that are stored in Personal Vault are synced by default to Bitlocker-encrypted locations, and that the vault will lock automatically in 20 minutes by default. I think the real security advantage here is on mobile devices where the OneDrive app will let you scan files or take pictures and video and store it directly into your Personal Vault instead of your camera roll. And because data that is stored in OneDrive is encrypted at rest and in transit, it seems to be a nice addition to increase the security and privacy of your most sensitive data like storing a picture of your driver’s license, passport, birth certificate, or other electronic documents you should protect. One disappointment though, if you have a free OneDrive account or one that you recently upgraded to one of Microsoft’s standalone 100 GB plans, you can only store a maximum of three files in your Personal Vault. To store more, you’ll need to upgrade to an Office 365 Personal or Home subscription. I guess according to Microsoft, much needed personal file security and privacy comes with an additional cost. There were lots of new privacy and security updates from Google last week which includes new features and improvements to give you more control over your data and to make privacy and security controls more seamless across all of Google’s products. First up is the new feature which allows you to auto-delete your YouTube browsing history at a set time period of 3 months, 18 months, or the ability to just delete your history manually. Next, Google has integrated a password checkup tool into the Google Password Manager which will let you know if your passwords are weak, reused, or have been compromised in a previous data breach. This is similar functionality to what Firefox rolled out a few months ago by integrating with Troy Hunt’s ‘Have I been pwnd’ service. In addition to these improvements you’ll be able to tell the Google Assistant to delete what you just said or delete a recording from a specific time period, like last week, and Google has added incognito or private mode to Google Maps which removes any personalization and search history which won’t be linked back to your Google account. In other related Google news, Google has been lobbying congress to let them start forcing Chrome users to automatically use DNS over HTTPS. If you’re not familiar with what DNS over HTTPS is, well it means is that when you type a URL like google.com into your web browser, the query for google.com gets encrypted, therefore, not allowing your ISP (or someone else monitoring your Internet connection) to view the sites you’re going to on the Internet. Keep in mind that this is slightly different than full HTTPS encryption where the contents of data that you send and receive from sites on the Internet is encrypted. Think of DNS over HTTPS as an add-on that will increase the overall security and privacy of the Internet. My take is that I think this and all the recent changes that Google is making is really needed. I don’t know about you but I feel lately that perhaps Amazon, Apple, and now Google are playing a game of “privacy catch up” given how data breaches and privacy concerns are all over the news as of late. Let’s hope this trend continues.

Oct 7, 20199 min

Amazon Smart Glasses, Webkey Social Engineering, Erase Your Old Hard Drives!

In episode 92 of our monthly show Tom and Scott talk about Amazon’s new smart glasses that work with Alexa, what webkey’s are and how they could be used for social engineering, and why you should always erase old hard drives and other data storage before selling or giving away computers and other electronics. Looking to up your privacy and security game while you travel? Then you need to check out Silent Pocket’s patented product line of faraday bags, wallets, backpacks, and other accessories at silentpocket.com. Be sure to use discount code “sharedsecurity” at checkout to receive 15% off your order. Here are the show notes and links to articles discussed during the show: Give a listen to our 10 year anniversary episode, and our interviews with Aaron Zar from Silent Pocket, and Max Krohn from Keybase.io. A first look at Amazon’s new AirPods competitor, smart glasses and ring “Another experimental product is Echo Frames, but I think these have legs. These aren’t augmented reality glasses like Microsoft’s Hololens or Google Glass — there’s no display on them, and no camera like Glass had. Instead, you talk to the glasses and Alexa talks back to you. They make more sense than the Echo Loop, since the speakers are right near your ears and you don’t need to raise a hand up to listen Amazon has had lots of privacy issues around Alexa recordings including how contractors have been listening to these recordings and that you can only manually delete your recordings one at a time. Amazon’s privacy policies are starting to change! Check out our latest episode of the Weekly Blaze for more details. What is a Webkey? “USB webkeys( USB web keys ) are a great way of getting people to remember your logo, yet it saves the trouble of remembering a lengthy URL. Plug the Webkey into a USB port and your pre-programmed website automatically launches — just like magic! If you’ve read Harry Potter, you’ll appreciate this Muggle equivalent of the Portkey. The USB Web key is a low cost alternative to USB flash memory devices, and an effective way of promoting your company, new product launch, training material, or recruitment campaign. It’s available in various shapes. The USB Web key is pre-programmed with the URL (may up to 110pcs characters) that you provide. Every device is guaranteed to be virus free.” Here’s the Twitter thread that Scott mentioned on the show about the webkey given out at the information security conference: A great physical/cyber #socialEngineering experiment. A honey webkey! Wonder how many inserted this? Did the #InformationSecurity folks approve of this marketing tactic? Hey, @agent0x0 @streetsec the next gen beyond #HoneySticks => #HoneyPhones for you. https://t.co/u9B1vR6Iaj — Rebecca Herold (@PrivacyProf) August 22, 2019 Study: 3 in 5 secondhand hard drives still contain previous owner’s data “59 percent of secondhand hard disks sold on marketplaces like eBay are not properly wiped and still contain data from their previous owners, according to a new study by the University of Hertfordshire and commissioned by Comparitech.We purchased 200 used hard drives from online marketplaces, secondhand shops, and conventional auctions: 100 in the USA and 100 in the UK. University researchers then performed forensic analysis to determine whether any attempt had been made at deleting the contents of the drive and whether those attempts were successful. We uncovered a wide range of sensitive and private information left by previous owners. The remnant data included, among other things, employment and payroll records, family and holiday photos, business documents, visa applications, resumes and job applications, lists of passwords, passport and driver’s license scans, tax documents, bank statements, and lists of students attending senior high schools.” Here’s a great guide we talked about on how to erase/wipe most electronic storage including SD cards. Be sure to follow the Shared Security Podcast on Facebook, Twitter and Instagram for the latest news and commentary. If you have feedback or topic ideas for the show you can email us at feedback[aT]sharedsecurity.net. First time listener to the podcast? Please subscribe on your favorite podcast listening app or watch and subscribe on our YouTube channel. The post Amazon Smart Glasses, Webkey Social Engineering, Erase Your Old Hard Drives! appeared first on Shared Security Podcast.

Oct 1, 201932 min

DoorDash Data Breach, Voice Assistant Privacy Changes, Limiting Ad Tracking

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 88 for September 30th 2019: DoorDash announces a data breach affecting 4.9 million people, recent voice assistant privacy changes, and ways that you can limit ad tracking on your mobile device. Are you a frequent traveler that wants a high-quality, fashionable backpack that keeps your digital privacy in mind? Then you need to check out Silent Pocket’s new Faraday Bag Waterproof Backpack. Check it out at silentpocket.com as well as their other products built to protect your privacy. Don’t forget, as a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. Popular food delivery company DoorDash said in a blog post late last week that 4.9 million customers, delivery workers, and merchants had their information stolen through a third-party service provider who was not named. Data stolen included name, email and delivery address, order history, phone numbers, last four digits of their credit card or bank account, and hashed (and salted) passwords. Users who joined the service prior to April 5th 2018 were affected by this breach and to add insult to injury about 100,000 delivery works also had their driver’s license information stolen as well. And if that wasn’t enough, this news ironically comes almost a year after many DoorDash users complained that their accounts were hacked. At the time, DoorDash denied that there was a breach and blamed it on credential stuffing attacks, where attackers use user names and passwords previously exposed through known data breaches, then use those credentials on other sites like DoorDash. This is basically a way to pass blame to the user for selecting poor passwords. I think DoorDash has a little bit of explaining to do as we now add this latest breach to the long list or breaches that we’ve had just this year alone. If you happen to be a DoorDash customer check out our show notes to a link to the official news release about the breach for more information. Several weeks ago on the podcast I talked about how Apple was changing the way that contractors were analyzing recordings from Siri as part of their “grading” program due to privacy concerns around sensitive and private conversations that were recorded. You may recall that this was also a huge problem for Amazon and Google’s voice assistants as well. Well this past week, Google announced significant changes to how their product, the Google Assistant, handles voice recordings. First, Google says that your audio data is not stored by default and that if you do want it stored, so that it can be used to help improve the Google Assistant, than you can opt-in to this feature. Second, Google has updated their audio settings to highlight that when you choose to opt-in you can choose to opt-out and for existing users that have chosen this already, a chance to review and change the setting if you would prefer. Third, Google said that recordings are never linked to a particular user and that only .2% of all audio recordings are ever analyzed by someone. Lastly, the Google Assistant will automatically delete any audio data when it realizes that it was activated unintentionally. In addition, Google is making changes to their data retention policy so that audio data is deleted older than a few months. And in late breaking news last week, Amazon released several new Echo related products to the market and also announced several new privacy improvements as well. First, Amazon has added two new commands to its Alexa voice assistant in which you can now say “Alexa, tell me what you heard” and, “Alexa, why did you do that?”. The tell me what you heard command lets you know what exactly Alexa is listening to and “why did you do that” is meant to give you more information if Alexa does something random like play a song out of nowhere. In addition, Amazon will now allow people to delete Alexa voice recordings on a rolling 3-month or 18-month basis and is allowing users to opt-out of human reviews of voice recordings. These changes now put Amazon along the same lines as Apple and now Google with current privacy settings of these popular voice assistants. And now a word from our sponsor, Edgewise Networks. The biggest problem in security that remains unsolved is unprotected attack paths that allow threats to compromise vulnerable targets in the cloud and data center. But traditional microsegmentation is too complex and time consuming, and offers limited value that’s hard to measure. But there’s

Sep 30, 20199 min

Aaron Zar, Co-Founder and CEO of Silent Pocket

On this special edition of the podcast we speak with Aaron Zar, co-founder and CEO of Silent Pocket. Silent Pocket has been a long time sponsor of the show and it was great to catch up with Aaron to get his thoughts on the current state of digital privacy. On the show we also discuss: Why privacy isn’t dead and how Aaron responds to people that say “Who cares about privacy! I have nothing to hide!” How Silent Pocket products are helping people protect their digital privacy and stay more secure The history of Silent Pocket, their first products, and how Aaron started his career What products are recommended for the average person? What new and innovative products are in the pipeline? It was a pleasure having Aaron on the show and we hope you enjoy this episode as much as we did! Check out Silent Pocket’s great line of faraday bags, wallets, and other gear including their new Faraday Bag Waterproof Backpack which we discuss on the show. Don’t forget, because you listen to this podcast, you receive 15% off your order using discount code “sharedsecurity” during checkout at silentpocket.com. The post Aaron Zar, Co-Founder and CEO of Silent Pocket appeared first on Shared Security Podcast.

Sep 27, 201932 min

Apple iOS 13, Venmo Scams, Simjacking Attacks

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 87 for September 22nd 2019: Everything you need to know about Apple iOS 13, Venmo scams you need to be aware of, and new details about “Simjacking” attacks This week I had the pleasure of interviewing Aaron Zar, co-founder and CEO of our sponsor Silent Pocket. Aaron’s a great guy and I think you’ll enjoy hearing how he started Silent Pocket and his take on why our digital privacy is more important than ever. We’ll be publishing this episode soon so be on the lookout for it. And if you haven’t taken a look at Silent Pocket’s great product line of stylish faraday bags and wallets I highly recommend you check them out at silentpocket.com. Don’t forget because you listen to this podcast you can take 15% off your order using discount code “sharedsecurity”. Welcome to the Shared Security Weekly Blaze Podcast where we update you on this week’s most important cybersecurity and privacy news. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. Last week Apple released iOS 13 to the public which also happened to include a passcode bypass vulnerability which allows you to view the contacts on a locked Apple device. In order to conduct the attack you would need access to someone’s device and go through a series of steps, which by the way, would not be that easy to pull off by someone who had physical access to your device. Steps include replying to an incoming call with a custom message, enabling and disabling the VoiceOver feature, adding a new contact to a custom message, and then viewing the contacts information. This of course is not the first time we’ve seen passcode bypass vulnerabilities in Apple iOS, there were two that were patched in iOS 12 as well. Apple will most likely patch this vulnerability in the first update to iOS 13 which will probably happen in the next few weeks. Besides this particular issue, the iOS 13 update comes with several new privacy enhancements including the much anticipated “Sign in with Apple” feature which can create an anonymous email address for you when signing up for new apps and services. Also, phone calls from apps like Facebook Messenger and WhatsApp will have more restrictions in the way that they run in the background to prevent them from collecting user data without permission. Speaking of permissions, someone noticed while testing the new iOS update that an unexpected notification popped up on their device stating that Facebook would like to use your Bluetooth wireless. Why on Earth would Facebook need access to your Bluetooth? Well apparently, some apps are tracking your physical location and the proximity you are to other people’s smartphones. Potential uses of this data could include deeper analysis of the people around you and their relationships. Not only that but it could also be used to serve you ads and I could even see the potential use in Facebook’s new dating service in which having location services turned on is a requirement. Now this “feature” has been going on for quite some time and it’s not just Facebook. YouTube just so happens to be doing the same thing. Do you use the popular peer-to-peer payment app, Venmo? If you are, then you need to be aware of a new text message based phishing scam that directs you to a fake Venmo website. Here’s how it works. You’ll receive a text message saying that your Venmo account is about to be charged and if you want to cancel the withdrawal, you need to login to your account and decline it. When clicking the link, a site that looks just like Venmo will ask you for your phone number and password, then prompt you to enter in your bank card and other personal and financial information. In another, more advanced variation that is most likely tied to criminal money laundering, you may receive a legitimate text message from Venmo staying that you just received money from someone you don’t know. This is typically a large amount like $1,000. If you accept the payment, later down the road the scammer will ask you for the money back due to an error on their part and even ask you to keep $50 or so for your “trouble”. When you return the money back to the scammer, the scammer will contact Venmo to “correct” their mistake in which Venmo may also reverse the payment again or put you on the hook for accepting a fraudulent transaction. The best advice, of course, is to never accept money from people you don’t know and to never enter in financial details through a link that comes through a text message. Scams like these that leverage text messages are only going to increase because payment services like Venmo are rapidly growing in popularity. Just in Q1 of thi

Sep 23, 20199 min

End-to-End Encryption with Max Krohn from Keybase.io

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 86 for September 16th 2019: All about end-to-end encryption with Max Krohn from Keybase.io. Are you looking for the very best products to protect your digital privacy? Well, Silent Pocket has everything you need to mind the grid with their patented product line of faraday bags and wallets. Visit silentpocket.com today and receive 15% off your order with discount code “sharedsecurity”. The Shared Security Podcast is also sponsored by Edgewise Networks. Visit edgewise.net to find out about how Edgewise can help stop data breaches. In this special edition of the Weekly Blaze, Tom interviews Max Krohn co-founder of Keybase.io to discuss the current state of encryption and why end-to-end encryption is so important. Here are the topics that we covered with Max on the show: Who is Max Krohn and what is Keybase.io? What is end-to-end encryption and how is it different than other types of encryption? Recent news about governments asking tech companies to build in “encryption backdoors” into services and products to prevent terrorism and mass shootings. Max’s take on the controversial talk given by Crown Sterling at the Black Hat USA security conference on the “discovery” of quasi-prime numbers. Is this snake oil or real research that will change encryption forever? Find out more about Keybase.io and follow Max on Twitter Visit our website, SharedSecurity.net for previous episodes, links to our social media feeds, our YouTube channel, and to sign-up for our email newsletter. First time listener to the podcast? Please subscribe where ever you like to listen to podcasts and if you like this episode please it share with friends and colleagues. Thanks for listening and see you next week for another episode of the Shared Security Weekly Blaze. The post End-to-End Encryption with Max Krohn from Keybase.io appeared first on Shared Security Podcast.

Sep 16, 201919 min

New Firefox Privacy Protections, Apple iOS Zero-Days, Facebook User Phone Numbers Exposed

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 85 for September 9th 2019: Firefox will now block all third-party tracking cookies and more by default, serious vulnerabilities found in Apple iOS, and the latest on the huge database of Facebook users’ phone numbers found online. Did you know that all electronic devices emit a form of electromagnetic radiation? Well recently we’re starting to see more scientific research come out about the potential health effects of using our mobile devices and other wireless electronics so close to our body. In fact, just recently a class action lawsuit was filed against Apple and Samsung for exceeding the radiation limit on the smartphones that they sell. And while this research is debatable in some circles, more and more experts are recommending keeping our smartphones away from our bodies. If this is something that concerns you one product that can help is a Silent Pocket faraday bag which can block all wireless signals emitting from a device. Visit silentpocket.com to check out their great line of faraday bags and other products to protect your digital privacy. Don’t forget, as a listener of this podcast you receive 15% off your order at checkout using discount code “sharedsecurity”. Hi everyone, welcome to the Shared Security Weekly Blaze where we update you on the top 3 cybersecurity and privacy topics from the week. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. It should be no surprise that I’m a huge fan of Firefox. In my opinion it’s probably the best web browser out there that is truly focused on your privacy. And with the latest release of Firefox, version 69, Mozilla has made a change to its enhanced tracking protection feature by enabling this for all users by default. Enhanced Tracking Protection is a privacy control which blocks all third-party tracking cookies and more. Back in June Firefox enabled this feature only for new users but over the last few months of testing and improvements they are finally ready to enable this setting for everyone which is a huge benefit from a privacy perspective. Enhanced Tracking Protection works behind-the-scenes to keep websites from developing a profile of you based on how they are tracking your web browser behavior across different websites. These profiles are then collected and even sold to third-party marketing companies without your consent. In addition, Firefox is also now blocking cryptominers by default too. Cryptominers access your computer’s CPU slowing it down and draining your battery to generate cryptocurrency for someone else to profit from. Oh and if that wasn’t enough, Fingerprinting scripts are being blocked too but not by default. These scripts attempt to harvest information about your computers configuration when you visit a website. If you want to take advantage of blocking these types of scripts you’ll need to enable “Strict Mode” within your Firefox privacy settings. Eventually, Firefox plans on turning this blocking on by default in the near future. Now I’ve also been recommending the EFF’s Privacy Badger as a great add-on for Firefox too. So it will be interesting to see how Privacy Badger compares to Enhanced Tracking Protection built in now by default into Firefox. Perhaps, we’ll do a comparison for you in a future episode of the podcast but in the meantime, if you are using Firefox make sure you update to the latest version to take advantage of these great new privacy protections. The big news being discussed in the cybersecurity community recently was the big reveal from Google’s Project Zero vulnerability research team which found that over a dozen Apple iOS vulnerabilities have been exploited by attackers for at least two-years to steal everything on a vulnerable device including passwords, photos, text messages, and more. Most surprising though is the method used to infect iOS devices which was by simply visiting certain websites which would exploit the vulnerabilities without you even knowing it. The researchers did not disclose the websites that were used but said that these sites received thousands of visitors per week. Oh, and the exploit only persisted until you rebooted your iOS device but like many of us you remember the last time you powered off or rebooted your device? What’s also interesting is that typically iOS zero-days like this would be used by nation states to target specific groups or individuals but in this case the attackers didn’t have a particular target in mind, rather was a mass attack on any Apple device running iOS 10 through iOS 12. This also brings into question how secure Apple devices really are given that they have a reputation of iOS being one of the hardest operating systems to com

Sep 9, 201910 min

Android “Ghost Click” Apps, New Apple Siri Privacy Protections, Credit Card Spying

You’re listening to the Shared Security Podcast, exploring the trust you put in people, apps, and technology…with your host, Tom Eston. In episode 84 for September 2nd 2019: “Ghost click” Android apps found on the Google Play Store, new privacy protections for Apple’s Siri voice assistant, and did you know that your credit card may spying on you? I have a question for you. How often do you carry your laptop with you? If you’re a frequent traveler, the answer may be all day and every day. So if you are carrying your laptop around, how are you doing it? If you’re like most of us we use some cheap neoprene laptop sleeve or just throw it in a backpack. But what if I told you there is a better approach? Well Silent Pocket makes a fantastic solution called a faraday laptop and tablet sleeve. I have one and I love it. Their laptop sleeve comes in waterproof nylon or beautiful leather to provide protection for your laptop from not only the elements but also by blocking all wireless signals making your laptop instantly secure. Check out Silent Pocket’s Farady Laptop and Tablet Sleeve for yourself at silentpocket.com. And as a listener of this podcast be sure to use discount code “sharedsecurity” to receive 15% off your order. Hi everyone, welcome to the Shared Security Weekly Blaze where we update you on the top 3 cybersecurity and privacy news topics from the week. These podcasts are published every Monday and are 15 minutes or less quickly giving you “news that you can use”. Did you know that Android app developers have found creative ways to load ads or conduct “ghost clicks” within an app so that the ad is never shown to you and that you never have to click an ad on the screen? Well last week it was discovered by researchers from Symantec that an Android app developer called “Idea Master” had two apps, a notepad app called “Idea Note: OCR Text Scanner, GTD, Color Notes” and a fitness app called “Beauty Fitness: Daily Workout, Best HIIT Coach”, were downloaded over 1.5 million times in the Google Play Store for close to a year were using this very tactic. According to Symantec researchers, the code to do all of this was hidden due to the way that the apps were compiled. Typically, researchers can easily reverse engineer Android apps to view the source code but in this case a “packer” was used to purposely obfuscate the code. These packers are typically used by app developers to protect intellectual property in their code. How this attack works is that the developer first makes sure the ads show up just outside the viewable area of the of the screen and then they program the app to initiate an automated ad-clicking process that runs in the background. Not only will this drive up ad revenue for the app developer but it has the side-effect of slowing down your Android device and drains your battery. There is also the potential for these developers to use similar tactics to load malicious content or open up websites so that more dangerous things could be installed on your phone. So how can you prevent something like this from happening on your Android device? First, keep your mobile device up-to-date, only install apps from trusted sources, and pay close attention to the permissions that are requested when you install an app. And if you see your battery or data usage spike after installing an app, that should also be a clue that an app may be doing something malicious on your device. Remember on a recent previous episode how I talked about Amazon, Apple, and Google having major privacy issues regarding what was being recorded from their voice assistants like Siri, Amazon Echo, and Google Home? In all of these assistants, recordings were found to have contained very private conversations that were being analyzed by contractors hired to improve the technology behind these digital assistants. Several weeks ago Apple suspended what they call their Siri “grading” program due to privacy concerns with the use of contractors and the very private conversations which included everything from financial data, medical, and other very personal details when Siri was accidentally triggered. This past week Apple has now announced that they will be resuming this program in the Fall but only after some privacy changes are made. These changes include that Apple will no longer retain recordings of Siri interactions and instead will use computer generated transcripts to help Siri improve. Second, users will be able to opt in to have audio samples from Siri analyzed with the option to opt out at any time. And third, for customers that do opt-in, only Apple employees will be allowed to listen to audio samples and that they will delete any recording which happened to be an inadvertent trigger of Siri. Now, let’s see of Google and Amazon follow Apple’s lead to fix some of these recent privacy co

Sep 2, 201912 min