We often think of malware as a problem for our computers and perhaps our smartphones. But bad guys love to hack our home routers and IoT devices, as well. Thankfully, purging malware from those types of devices can usually be done just by rebooting them. (There’s a reason tech support always asks you to try turning your device off and back on again.) I’ll explain why this works and what you should do to protect your connected devices.
In other news: I explain why most people are not in danger of their devices blowing up; a new Windows phishing campaign uses fake CAPTCHAs and PowerShell; LinkedIn started training their AI on your data before telling you how to opt out; Oracle’s CEO touts his vision of ubiquitous AI surveillance; Ford seeks a patent to show you ads in your vehicle based on your conversations and other private data; Meta admits to scraping public Instagram and Facebook posts to train its AI; four great new iOS 18 privacy and security features; Apple Intelligence servers are very basic, for a reason; and the FBI shuts down a massive Chinese botnet.
Article Links1. [WIRED] Your Phone Won’t Be the Next Exploding Pager https://www.wired.com/story/exploding-pagers-hezbollah-phones/ 2. [briankrebs] This Windows PowerShell Phish Has Scary Potential https://krebsonsecurity.com/2024/09/this-windows-powershell-phish-has-scary-potential/ 3. [404media.co] LinkedIn Is Training AI on User Data Before Updating Its Terms of Service https://www.404media.co/linkedin-is-training-ai-on-user-data-before-updating-its-terms-of-service/ 4. [theregister.com] Ellison declares Oracle ‘all in’ on AI mass surveillance https://www.theregister.com/2024/09/16/oracle_ai_mass_surveillance_cloud/ 5. [therecord.media] Ford seeks patent for tech that listens to driver conversations to serve ads https://therecord.media/ford-patent-application-in-vehicle-listening-advertising 6. [9to5Mac] Meta scraped all public Facebook and Instagram posts since 2007 for AI training https://9to5mac.com/2024/09/11/meta-scraped-all-public-facebook-and-instagram-posts-since-2007-for-ai-training/ 7. [TechRadar] I’m a privacy expert—here are the 4 iOS 18 features I’m excited about https://www.techradar.com/phones/im-a-privacy-experthere-are-the-4-ios-18-features-im-excited-about 8. [9to5Mac] Apple Intelligence servers are really basic, says Craig Federighi – and that’s deliberate https://9to5mac.com/2024/09/12/apple-intelligence-servers-are-really-basic-says-craig-federighi-and-thats-deliberate/ 9. [Gizmodo] FBI Shuts Down Botnet Run by Beijing-Backed Hackers That Hijacked Over 200,000 Devices https://gizmodo.com/fbi-shuts-down-botnet-run-by-beijing-backed-hackers-that-hijacked-over-200000-devices-2000500627 10. Tip of the Week: Malware Reboot Remedy
Further Info Awareness Campaign Phase 2!: https://fdsd.me/awareness2 * LinkedIn privacy settings: https://www.linkedin.com/mypreferences/d/categories/privacy * Test your ad blocker(s): https://d3ward.github.io/toolz/adblock.html * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
You may be vaguely aware of the term ‘quantum computing’ from media reports. But what you may not have picked up on is that one of the primary uses for quantum computers may be to break data encryption. Furthermore, you may not realize that if three-letter agencies can save off our encrypted emails and messages now, this could mean they could read them in the future when sufficiently powerful quantum computing becomes viable. How does this work? And what can we do about it now to protect our privacy in the future? We’ll dig into all of this today with Brandon Sundh from Tuta (formerly Tutanota), a prominent secure email company, who is already deploying such protections.
Interview Notes* Try Tuta! https://tuta.com/ * Tuta’s quantum-safe crypto: https://tuta.com/blog/post-quantum-cryptography * Quantum mechanics: https://en.wikipedia.org/wiki/Quantum_mechanics * Schrödinger’s cat: https://en.wikipedia.org/wiki/Schr%C3%B6dinger’s_cat * NIST post-quantum standards: https://csrc.nist.gov/projects/post-quantum-cryptography * NSA pays RSA to weaken encryption?: https://www.reuters.com/article/2013/12/20/us-usa-security-rsa-idUSBRE9BJ1C220131220/ * Longer passwords are better: https://firewallsdontstopdragons.com/need-a-bigger-password-haystack/ * Privacy Guides on Proton Wallet: https://www.privacyguides.org/articles/2024/09/08/proton-wallet-review/#why-does-this-exist
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Mis- and disinformation is just a fact of modern life, but certain events can cause the practice to significantly increase – like a big election. This is a good time to review this phenomenon, learning how to recognize it, how to avoid being drawn in, and perhaps most importantly how to reduce its spread.
In other news: Telegram’s CEO was arrested in France; too many people keep saying Telegram is an secure messaging app when it’s really not; if you think ads and tracking are bad now, wait till you hear all the ways modern TVs are monetizing their users; sextortion scams are using some new techniques to scam their victims; consumer groups have lobbied the FTC to create clear guidance on ‘software tethering’; and California just approved a new privacy bill that will finally require companies to honor universal opt-out signals from apps and browsers.
Article Links1. BBC] Telegram CEO Pavel Durov arrested at French airport https://www.bbc.com/news/articles/ckg2kz9kn93o 2. [blog.cryptographyengineering.com] Is Telegram really an encrypted messaging app? https://blog.cryptographyengineering.com/2024/08/25/telegram-is-not-really-an-encrypted-messaging-app/ 3. [Ars Technica] Your TV set has become a digital billboard. And it’s only getting worse. https://arstechnica.com/gadgets/2024/08/tv-industrys-ads-tracking-obsession-is-turning-your-living-room-into-a-store/ 4. [briankrebs] Sextortion Scams Now Include Photos of Your Home https://krebsonsecurity.com/2024/09/sextortion-scams-now-include-photos-of-your-home/ 5. [advocacy.consumerreports.org] Consumer Reports, U.S. PIRG, and 15 other groups call on FTC to create clear guidance for ‘software tethering’ https://advocacy.consumerreports.org/press_release/ftc-software-tethering/ 6. [Dark Reading] California Approves Privacy Bill Requiring Opt-Out Tools https://www.darkreading.com/data-privacy/california-privacy-bill-require-opt-out-tools 7. Tip of the Week: Spotting Fake News https://firewallsdontstopdragons.com/the-truth-is-out-there/
Further Info My series on deleting your public data online: https://firewallsdontstopdragons.com/osint-reconnaissance/ * Enabling Global Privacy Control (GPC): https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Proton released three major new products this summer, all within the span of about a couple months: Proton Docs, Proton Wallet and Proton Scribe. Given that Proton is a privacy-focused company, some of these offerings seemed almost at odds with that mission. So today I ask Andy Yen (Proton’s CEO) some questions about the privacy of their Bitcoin wallet and AI editing tool. We also discuss the new Proton Foundation and how it safeguards their privacy mission for the future. Finally, I ask Andy if they would consider acquiring Mozilla to save the Firefox browser and, in the wake of the blow back Signal received about protecting local access to messaging data, how Proton addresses the ‘compromised machine’ threat model.
Interview Notes* Proton Docs: https://proton.me/blog/docs-proton-drive * Proton Wallet: https://proton.me/blog/proton-wallet-launch * Proton Scribe: https://proton.me/blog/proton-scribe-writing-assistant * Proton Foundation: https://proton.me/blog/proton-non-profit-foundation * Techlore on Proton Wallet: https://www.youtube.com/watch?v=tESbBM2LZHM&t=1922s * Seth for Privacy’s Andy Yen interview: https://optoutpod.com/episodes/protonwallet-andy-yen/ * My interview on Easy Prey Podcast: https://www.easyprey.com/firewalls-dont-stop-dragons-with-carey-parker/ * Techlore: https://www.techlore.tech/ * Privacy Guides: https://www.privacyguides.org/ * The New Oil: https://thenewoil.org/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
The headlines have been on fire with stories about 3 billion people’s data being leaked from a company you’ve never heard of. But like many such stories, the mainstream media gets a lot of the important details wrong and glosses over a lot of the important nuances. Today we’re going to dive into what really happened and what you should do about it, whether your data was part of the breach or not.
In other news: Illinois waters down its landmark biometric information law; US court rules geofence warrants are unconstitutional; FTC to investigate :surveillance pricing” and files rule impacting shady product reviews; the CFPB cracks down on some types of consumer data sales; and Consumer Reports evaluates several top data deletion services.
Article Links1. [Reuters] Illinois governor approves business-friendly overhaul of biometric privacy law https://www.reuters.com/legal/government/illinois-governor-approves-business-friendly-overhaul-biometric-privacy-law-2024-08-05/ 2. [TechCrunch] US appeals court rules geofence warrants are unconstitutional https://techcrunch.com/2024/08/13/us-appeals-court-rules-geofence-warrants-are-unconstitutional/ 3. [Electronic Frontier Foundation] To Fight Surveillance Pricing, We Need Privacy First https://www.eff.org/deeplinks/2024/08/fight-surveillance-pricing-we-need-privacy-first 4. [ftc.gov] Federal Trade Commission Announces Final Rule Banning Fake Reviews and Testimonials https://www.ftc.gov/news-events/news/press-releases/2024/08/federal-trade-commission-announces-final-rule-banning-fake-reviews-testimonials 5. [natlawreview.com] CFPB Forecasts New Rule Cracking Down on Consumer Data Sales https://natlawreview.com/article/cfpb-forecasts-new-rule-cracking-down-consumer-data-sales 6. [Los Angeles Times] Hackers may have stolen the Social Security numbers of every American. How to protect yourself https://www.latimes.com/business/story/2024-08-13/hacker-claims-theft-of-every-american-social-security-number 7. [troyhunt.com] Inside the “3 Billion People” National Public Data Breach https://www.troyhunt.com/inside-the-3-billion-people-national-public-data-breach/ 8. [consumerreports.org] Evaluating People-Search Site Removal Services https://innovation.consumerreports.org/new-report-data-defense-evaluating-people-search-site-removal-services/ 9. Tip of the Week: OSINT Final Steps https://firewallsdontstopdragons.com/osint-final-steps/
Other Helpful Links* Have I Been Pwned: https://haveibeenpwned.com/ * NPD Data Breach search tool: https://npd.pentester.com/ * Privacy Guides data removal tools: https://www.privacyguides.org/en/data-broker-removals/ * Techlore video on data removal: https://www.youtube.com/watch?v=tESbBM2LZHM * Google’s Results About You: https://myactivity.google.com/results-about-you?pli=1 * How to freeze your credit: https://firewallsdontstopdragons.com/credit-freeze-now-is-the-time/ * How and why to plant your flag: https://firewallsdontstopdragons.com/why-you-need-to-plant-your-flag/ * Strong passwords: https://firewallsdontstopdragons.com/need-a-bigger-password-haystack/ * Backing up 2FA codes: https://firewallsdontstopdragons.com/how-to-backup-2fa-seed-codes/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Finding your soul mate or even just a one-night stand can all be done digitally now – there’s an app for that. Several, in fact. But in order to find the best match, you need to turn over a lot of extremely personal information. You probably also need to let the app track your location, so you’re only matching people within some acceptable distance. You would hope that dating apps would be better than other apps at securing your private data… but are they? And are these services selling my data to advertisers? Today I answer these questions and many more with Zoë MacDonald from Mozilla’s Privacy Not Included team who recently published a full report on this topic.
Interview Notes* Privacy Not Included report on dating apps: https://foundation.mozilla.org/en/privacynotincluded/articles/data-hungry-dating-apps-are-worse-than-ever-for-your-privacy/ * Mozilla Foundation: https://foundation.mozilla.org/en/?form=donate-header * Mozilla’s Privacy Not Included: https://foundation.mozilla.org/en/privacynotincluded/ * Falling out of love with dating apps: https://www.theguardian.com/lifeandstyle/2023/oct/28/its-quite-soul-destroying-how-we-fell-out-of-love-with-dating-apps * Using dating apps to locate someone: https://www.techradar.com/pro/privacy-flaw-in-top-dating-apps-could-have-revealed-user-location-down-to-2-metres * How to freeze your credit: https://firewallsdontstopdragons.com/credit-freeze-now-is-the-time/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
It’s time once again for cybersecurity professionals to make the pilgrimage to the scorching desert of Las Vegas, Nevada for a week of tech conferences that we lovingly refer to as Hacker Summer Camp. Today I’ll bring you my on-the-ground reporting from BSides and DEF CON. I’ll also bring you part 2 of my series on Open Source Intelligence (OSINT) and how to purge your personal data from the web.
In the news this week: Vegas hotels search hacker’s rooms; Apple and others fix old but important browser bug; NFL rolls out more facial recognition at stadiums; Ford looks to patent car surveillance tech; automakers sold your data to brokers for pennies; border agents can no longer search your smartphone without a warrant; judge rules that Google is a monopoly.
Article Links1. [404media.co] Hotel to Search Rooms During DEF CON Hacking Conference https://www.404media.co/hotel-to-search-rooms-during-def-con-hacking-conference/ 2. [AppleInsider] Apple has closed an ancient macOS Safari security hole https://appleinsider.com/articles/24/08/07/apple-has-closed-an-ancient-macos-safari-security-hole 3. [therecord.media] NFL to roll out facial authentication software league-wide https://therecord.media/nfl-to-roll-out-facial-authentication-league-wide 4. [therecord.media] Ford wants patent for tech allowing cars to surveil and report speeding drivers https://therecord.media/ford-seeks-patent-cars-surveil-speeders-report-to-police 5. [The New York Times] Automakers Sold Driver Data for Pennies, Senators Say https://www.nytimes.com/2024/07/26/technology/driver-data-sold-for-pennies.html 6. [9to5Mac] Border agents cannot search smartphones without a warrant, rules federal court https://9to5mac.com/2024/07/29/cannot-search-smartphones-without-a-warrant/ 7. [AppleInsider] Judge rules Google is a search and advertising monopoly https://appleinsider.com/articles/24/08/05/judge-rules-that-google-is-a-search-and-advertising-monopoly 8. Tip of the Week: OSINT Remediation https://firewallsdontstopdragons.com/osint-remediation/
Further Info BSides Las Vegas: https://bsideslv.org/ * DEF CON 32: https://defcon.org/html/defcon-32/dc-32-index.html * UnDisruptible27: https://securityandtechnology.org/undisruptable27/ * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Jack Daniel is a storyteller, wanderer, comic, bartender, blacksmith, luthier, historian, mechanic, and the world’s oldest millennial. He is also one of the founders of Security BSides. Jack has a colorful and interesting history, and today we’ll learn about how and why he started BSides, delve into a little hacker conference history, talk about modern hackers and cybersecurity conferences and how he’s seen them change over the years, and how hackers and their conferences are vastly different than the others.
Interview Notes* Jack Daniel: https://www.linkedin.com/in/jackadaniel/ * BSides official site: https://bsides.org/ * BSides Las Vegas (part of hacker summer camp): https://bsideslv.org/ * InfoSecMap: https://infosecmap.com/ * Cult of the Dead Cow interview: https://podcast.firewallsdontstopdragons.com/2023/08/07/cult-of-the-dead-cow/ * Jeff Moss interview #1: https://podcast.firewallsdontstopdragons.com/2021/08/16/on-a-dark-tangent/ * Jeff Moss interview #2: https://podcast.firewallsdontstopdragons.com/2022/08/29/the-night-the-lights-went-out-in-vegas/ * CackalackyCon: https://cackalackycon.org/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Last week, we all learned about a company called CrowdStrike that apparently has the capability to single-handedly bring multiple airlines, hospitals and other large companies to their knees in an instant. There are many lessons we should be learning from this incident, though I’m not going to hold my breath. I’ll tell you what happened and what I think we should be doing to avoid a repeat of this incident in the future.
In other news: Google finally throws in the towel on blocking third-party cookies; a private organization claims to have gained access to advertising-based location data on Trump’s shooter; Republican VP candidate JD Vance forgets to make his Venmo data private; leaked docs show what phones Cellebrite can and can’t hack; Meta takes down thousands of accounts related to sextortion ring; and for my Tip of the Week, we’ll tackle part 1 of my article on deleting your public data from the web.
Article Links1. [AppleInsider] Google gives up on Chrome plan to ditch third-party cookies https://appleinsider.com/articles/24/07/23/google-gives-up-on-chrome-plan-to-ditch-third-party-cookies 2. [404media.co] Heritage Foundation Claims to Use Location Data to Track Trump Shooter’s Movements https://www.404media.co/heritage-foundation-claims-to-use-location-data-to-track-trump-shooters-movements/ 3. [9to5Mac] J.D. Vance Venmo connections public, as privacy failing still in place six years later https://9to5mac.com/2024/07/19/jd-vance-venmo-connections-public/ 4. [404media.co] Leaked Docs Show What Phones Cellebrite Can (and Can’t) Unlock https://www.404media.co/leaked-docs-show-what-phones-cellebrite-can-and-cant-unlock/ 5. [The Washington Post] Meta takes down thousands of Facebook, Instagram accounts running sextortion scams from Nigeria https://www.washingtonpost.com/business/2024/07/24/meta-nigeria-sextortion-scam-instagram-facebook/fce496c6-49b8-11ef-9149-c75da5dd9201_story.html 6. [Schneier Blog] The CrowdStrike Outage and Market-Driven Brittleness https://www.schneier.com/blog/archives/2024/07/the-crowdstrike-outage-and-market-driven-brittleness.html 7. Tip of the Week:OSINT Reconnaissance: https://firewallsdontstopdragons.com/osint-reconnaissance/
Further Info Book surge results: https://fdsd.me/booksurge * Moxie Marlinspike (Signal) on Cellebrite vulnerabilities: https://signal.org/blog/cellebrite-vulnerabilities/ * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
If someone decided to dig into your life – perhaps even try to ‘dox’ you – how might they go about doing that? What could they find about you right now on the internet? You might be surprised at how much information is readily available from public sources, including your local government agencies and state databases. Today I’ll be talking with Jason Edison from Intel Techniques whose day job is using open source intelligence, or OSINT, to find suspected criminals and whose night job is helping people remove that same information to protect their privacy and even personal security.
Interview Notes* Intel Techniques: https://inteltechniques.com/ * Data Removal Guide: https://inteltechniques.com/workbook.html * Data Removal Workbook (PDF): https://inteltechniques.com/data/workbook.pdf * Credit Freeze Guide: https://inteltechniques.com/freeze.html * MySudo privacy app: https://mysudo.com/ * SimpleLogin (Proton) email aliases: https://simplelogin.io/ * Private credit cards: https://privacy.com/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Ads on the web are beyond annoying – they are actually a threat to your privacy and sometimes even your security. Ads pay for a lot of the “free” web content we consume, but until ad networks stop tracking us and selling ad space to phishing and malware groups, we need tools to block them. Today I’ll give you two solid options for doing so.
In the news: Australian man charged for WiFi scam on flights; Airbnb reveals 35,000 complaints about hidden cameras; Linksys routers expose WiFi credentials; a massive new hacker list contains 10 billion unique passwords; a new AT&T call and text records data breach; Signal gets flak for response to storing encryption keys in the clear; Mozilla launches “privacy-preserving” ad attribution system (on by default); Proton launches encrypted Google Docs competitor.
Article Links1. [The Hacker News] Australian Man Charged for Fake Wi-Fi Scam on Domestic Flights https://thehackernews.com/2024/07/australian-man-charged-for-fake-wi-fi.html 2. [9to5Mac] 35,000 complaints about hidden cameras in Airbnb properties https://9to5mac.com/2024/07/10/hidden-cameras-in-airbnb-properties/ 3. [stackdiary.com] Linksys Velop routers send Wi-Fi passwords in plaintext to US servers https://stackdiary.com/linksys-velop-routers-send-wi-fi-passwords-in-plaintext-to-us-servers/ 4. [cybernews.com] RockYou2024: 10 billion passwords leaked in the largest compilation of all time https://cybernews.com/security/rockyou2024-largest-password-compilation-leak/ 5. [TechCrunch] What the AT&T call records data breach means for you https://techcrunch.com/2024/07/12/what-the-att-call-records-data-breach-means-for-you/ 6. [stackdiary.com] Signal under fire for storing encryption keys in plaintext https://stackdiary.com/signal-under-fire-for-storing-encryption-keys-in-plaintext/ 7. [Mozilla] Privacy-Preserving Attribution https://support.mozilla.org/en-US/kb/privacy-preserving-attribution 8. [Lifehacker] Why You Should Consider Proton Docs Over Google https://lifehacker.com/tech/why-you-should-consider-proton-docs-over-google 9. Tip of the Week: How & Why to Block Ads https://firewallsdontstopdragons.com/how-and-why-to-block-ads/
Further Info Enter the DEF CON 32 ticket raffle: send email to dc24@firewallsdontstopdragons.com * Techlore NextDNS tutorial: https://www.youtube.com/watch?v=WUG57ynLb8I * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
We’re generating a ridiculous amount of data every day. Much of it is highly personal and that’s dangerous. But there are actually several Privacy Enhancing Technologies that may allow us to use this personal data to improve our collective quality of life without ruining the privacy of the data subjects. I’ll be discussing these PETs with Irene Knapp who spent five years working in the privacy department at Google. I will also spend a good bit of time asking them about what it’s like working at Google and get some insights about the company’s approach to privacy from the inside. (Spoiler: it’s not good.)
Interview Notes* Internet Safety Labs: https://internetsafetylabs.org/about-us/ * Irene’s Google departure post: https://medium.com/@Irenes/on-the-occasion-of-leaving-google-b8c7029c8d8b * Coworker.org: https://coworker.org * Google loses privacy chief: https://www.techspot.com/news/103268-google-privacy-chief-head-competition-law-leaving-not.html
Further Info BOOK SURGE!! https://fdsd.me/booksurge* * Send me your questions! https://fdsd.me/qna * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons
Table of ContentsUse these timestamps to jump to a particular section of the show.
We’ve talked about how to backup your local device data and how to back up data that is primarily stored in the cloud. But there’s a lot of important, irreplaceable data we take for granted: data owned by others. This might be shared online photo albums, cloud document collaborations, eBooks and other digital media, and even websites you frequently rely on. Today we’ll talk about how you can make local copies of these files in case they should ever go offline.
In other news: European politicians’ personal details exposed online; Proton transitions to non-profit corporate structure; lawsuit claims Microsoft tracked sex toy purchases; online ID verification service exposed drivers licenses; new Mac info-stealer served up by Google Ads; law enforcement is spying on Americans’ mail; new ALPR vulnerabilities prove it’s a public safety threat; UK hospital hack leaks 300M patient records; US bans Kaspersky software; Sonos removes promise not to sell its users’ data; Mozilla buys a ‘privacy-centric’ ad firm.
Article Links1. [proton.me] Cyber house of cards – Politicians’ personal details exposed online https://proton.me/blog/politicians-exposed-dark-web 2. [proton.me] Proton is transitioning towards a non-profit structure https://proton.me/blog/proton-non-profit-foundation 3. [404media.co] Lawsuit Claims Microsoft Tracked Sex Toy Shoppers With ‘Recording in Real Time’ Software https://www.404media.co/lawsuit-claims-microsoft-tracked-sex-toy-shoppers-with-recording-in-real-time-software/ 4. [404media.co] ID Verification Service for TikTok, Uber, X Exposed Driver Licenses https://www.404media.co/id-verification-service-for-tiktok-uber-x-exposed-driver-licenses-au10tix/ 5. [Ars Technica] Mac users served info-stealer malware through Google ads https://arstechnica.com/security/2024/06/mac-info-stealer-malware-distributed-through-google-ads/ 6. [The Washington Post] Law enforcement is spying on thousands of Americans’ mail, records show https://www.washingtonpost.com/technology/2024/06/24/post-office-mail-surveillance-law-enforcement/ 7. [Electronic Frontier Foundation] New ALPR Vulnerabilities Prove Mass Surveillance Is a Public Safety Threat https://www.eff.org/deeplinks/2024/06/new-alpr-vulnerabilities-prove-mass-surveillance-public-safety-threat 8. [TechCrunch] US bans sale of Kaspersky software citing security risk from Russia https://techcrunch.com/2024/06/20/us-bans-kaspersky-software-security-risk-russia/ 9. [AppleInsider] Sonos removes a promise to not sell personal data, gets busted by users https://appleinsider.com/articles/24/06/15/sonos-removes-a-promise-to-not-sell-personal-data-gets-busted-by-users 10. [theregister.com] What’s up with Mozilla buying ad firm Anonym? It’s all about ‘privacy-centric advertising’ https://www.theregister.com/2024/06/18/mozilla_buys_anonym_betting_privacy/ 11. Tip of the Week: Backing Up Other Data https://firewallsdontstopdragons.com/how-to-backup-other-data/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Every day, we generate tons of digital exhaust: our web browsing, GPS location, online and in-store purchases, emails and messages, social media posts and feed viewing habits, and much, much more. Online marketers and data brokers have been living off these breadcrumbs for years. The intelligence and law enforcement agencies have found this data to be incredibly revealing, and they can buy most of this data on the open market without requiring any sort of warrant – and they have. This has important implications for democratic societies that value privacy and freedom. I’ll discuss how this mass surveillance works and what it means for all of us with Byron Tau, author of the book “Means of Control”.
Interview Notes* Means of Control: https://www.amazon.com/Means-Control-Alliance-Government-Surveillance/dp/0593443225 * Byron Tau at NOTUS: https://www.notus.org/byron-tau * Puking Monkey’s DEF CON presentation: https://www.youtube.com/watch?v=T43Ti7c11lY * Make your EZ Pass “moo”: https://hackaday.com/2013/09/16/modified-e-zpass-detects-reads-far-from-toll-booths/ * Official US policy on collecting public info on citizens: https://www.dni.gov/index.php/newsroom/press-releases/press-releases-2024/3815-odni-releases-ic-policy-framework-for-commercially-available-information
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Until recently, most of our important data lived primarily on our devices. Backing up that data often meant choosing a cloud backup service. But today, many of our most important photos and files are actually stored in the cloud. While cloud servers are supposed to be more robust than home computers with flaky hard drives and smartphones that get lost or stolen, it also means that someone else is in control of that data. Cloud services go offline, get bought out or even shut down. We now need to be sure to back up our cloud data, too.
In other news: 23andMe breach under investigation by US and Canada; cops release personal location info to FOIA request; hacker gains access to Tile customer data; more car privacy updates; Microsoft Recall backlash highlights our distrust; report shows Microsoft favoring profits over security; Mac Bartender app shadily changes ownership; new Apple privacy features coming.
Article Links1. [malwarebytes.com] 23andMe data breach under joint investigation in two countries https://www.malwarebytes.com/blog/news/2024/06/23andme-data-breach-under-joint-investigation-in-two-countries 2. [theregister.com] Crooks threaten to leak 3B personal records ‘stolen from background check firm’ https://www.theregister.com/2024/06/03/usdod_data_dump/ 3. [404media.co] Cops Released a Car’s Travel History to a Total Stranger https://www.404media.co/cops-released-a-cars-travel-history-to-a-total-stranger/ 4. [404media.co] Hacker Accesses Internal ‘Tile’ Tool That Provides Location Data to Cops https://www.404media.co/hacker-accesses-internal-tile-tool-that-provides-location-data-to-cops/ 5. [The New York Times] Is Your Driving Being Secretly Scored? https://www.nytimes.com/2024/06/09/technology/driver-scores-insurance-data-apps.html 6. [Windows Central] A PR disaster: Microsoft has lost trust with its users, and Windows Recall is the straw that broke the camel’s back https://www.windowscentral.com/software-apps/windows-11/microsoft-has-lost-trust-with-its-users-windows-recall-is-the-last-straw 7. [ProPublica] Microsoft Chose Profit Over Security and Left U.S. Government Vulnerable to Russian Hack, Whistleblower Says https://www.propublica.org/article/microsoft-solarwinds-golden-saml-data-breach-russian-hackers 8. [AppleInsider] Adobe’s new terms of service unacceptably gives them access to all of your projects, for free https://appleinsider.com/articles/24/06/06/adobes-new-terms-of-service-unacceptably-gives-them-access-to-all-of-your-projects-for-free 9. [MacRumors] PSA: Bartender Mac App Under New Ownership, But Lack of Transparency Raises Concerns https://www.macrumors.com/2024/06/04/bartender-mac-app-new-owner/ 10. [9to5Mac] iOS 18 includes these new privacy features: Lock and hide apps, improved contact permissions, more https://9to5mac.com/2024/06/10/ios-18-includes-these-new-privacy-features-lock-and-hide-apps-improved-contact-permissions-more/ 11. Tip of the Week: Backup Your Cloud Data: https://firewallsdontstopdragons.com/how-to-backup-cloud-data/
Further Info Under New Management plugin: https://github.com/classvsoftware/under-new-management * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Encrypted communications are important for everyone, even if you have nothing to hide. But they’re also important when you’re trying to hide global criminal operations. Drug smugglers and money launderers have special needs when it comes to secure messaging. Several phone companies were created to address this market. Unfortunately for the criminals, the most popular one – Anom – was secretly run by the FBI. Today Joseph Cox from 404 Media will tell us about this astoundingly audacious sting operation, which is the basis for his book, Dark Wire.
Interview Notes Order Dark Wire*: https://a.co/d/h9o7ump * Anom website (right before take down): https://web.archive.org/web/20210507151115/http://anom.io/ * Phantom Secure website (circa 2017): https://web.archive.org/web/20170330122723/http://phantomsecure.com/ * Vice Anom story: https://www.vice.com/en/article/n7b4gg/anom-phone-arcaneos-fbi-backdoor * Anom phone video: https://www.youtube.com/watch?v=EA1KS-xh0n0 * Operation Trojan Shield: https://en.wikipedia.org/wiki/Operation_Trojan_Shield * Trojan Shield press conference: https://www.youtube.com/watch?v=S89O0nis_ss * Encrochat: https://en.wikipedia.org/wiki/EncroChat
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Most major social media platforms are a hot mess. Your feed is filled with tons of crap you never asked to see and your data is mined mercilessly to serve you targeted ads. The promise of having a place to trade interesting posts with friends and family is now muddied up with sponsored content chosen by hidden algorithms optimized to keep you scrolling. It doesn’t have to be that way. I’ve found something much better, and I’m inviting you to come join me.
In other news: Ticketmaster breach leaks data on half a billion users; the iOS bug that resurrected deleted photos explained; GPT-4 can write working malware based only on CVE bug descriptions; Slack customers upset to learn that their data was being used to train AI systems; WiFi location service can be used to track mobile routers; police are trialing new devices that can track and identify you based on multiple electronic signals; new Windows AI feature records everything you do on your PC; Microsoft rolling out welcome changes to admin privilege use; Google adding several privacy and security features to Android 15; and iVerify how has an Android app.
Article Links1. [Mashable] Ticketmaster hacked. Breach affects more than half a billion users. https://mashable.com/article/ticketmaster-data-breach-shinyhunters-hack 2. [9to5Mac] Security Bite: Here’s the iOS 17.5 bug that resurfaced deleted photos https://9to5mac.com/2024/05/26/security-bite-heres-the-ios-17-5-bug-that-resurfaced-deleted-photos/ 3. [Dark Reading] GPT-4 Can Exploit Most Vulns Just by Reading Threat Advisories https://www.darkreading.com/threat-intelligence/gpt-4-can-exploit-most-vulns-just-by-reading-threat-advisories 4. [securityweek.com] User Outcry as Slack Scrapes Customer Data for AI Model Training https://www.securityweek.com/user-outcry-as-slack-scrapes-customer-data-for-ai-model-training/ 5. [9to5Mac] Apple Location Services vulnerability can enable troop movements to be tracked https://9to5mac.com/2024/05/24/apple-location-services-vulnerability/ 6. [Forbes] New Police Tech Can Detect Phones, Pet Trackers And Library Books In A Moving Car https://www.forbes.com/sites/thomasbrewster/2024/05/14/police-car-surveillance-tech-uncovers-phones-pet-trackers-and-library-books/ 7. [Ars Technica] New Windows AI feature records everything you’ve done on your PC https://arstechnica.com/gadgets/2024/05/microsofts-new-recall-feature-will-record-everything-you-do-on-your-pc/ 8. [PCWorld] Microsoft battens security hatches on Windows admin accounts https://www.pcworld.com/article/2344405/microsoft-battens-security-hatches-on-oft-used-windows-admin-accounts.html 9. [Lifehacker] Google Is Rolling Out Some Great Privacy Features to Android This Year https://lifehacker.com/tech/google-is-rolling-out-some-great-privacy-features-with-android-15 10. [iverify.io] iVerify Basic is now on Android! https://www.iverify.io/post/iverify-basic-is-now-on-android 11. Tip of the Week: Move to Mastodon https://firewallsdontstopdragons.com/how-to-move-to-mastodon/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Our privacy has never been more threatened. While some of us are vaguely aware of this, most of the rampant data collection and sharing is completely opaque. And the consequences are more dire than most of us realize. We can’t afford to be complacent. We need to push back, to ask questions, and make better choices. Privacy-respecting apps and services do exist today. Making a deliberate and overt decision to use them will force the market (and our elected representatives) to take notice. My guest Naomi Brockwell from NBTV will make a compelling case for privacy and reclaiming control of our data, including several top notch tips for doing so.
Interview Notes* Naomi Brockwell’s NBTV: https://www.nbtv.media/ * A World Without Privacy: https://www.nbtv.media/episodes/a-world-without-privacy * A Beginner’s Introduction to Privacy: https://www.amazon.com/Beginners-Introduction-Privacy-Naomi-Brockwell-ebook/dp/B0BQHS8MFS * Who can access your car remotely? https://www.youtube.com/watch?v=Ff9pmaSdZV8 * Naomi Brockwell on All Things Secured: https://www.youtube.com/watch?v=D0WjIWBQEBM * Michael Bazzell’s Extreme Privacy resources: https://inteltechniques.com/links.html * Try Proton! https://firewallsdontstopdragons.com/its-time-to-try-proton/ * Try Signal! https://firewallsdontstopdragons.com/how-to-switch-to-signal/
Further Info Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Security experts talk at length about how to choose a good password – but we don’t often talk about how to choose a good PIN code. A recent analysis by a researcher shows popular patterns humans use when choosing PIN codes, and therefore what you should avoid doing.
In the news: MediSecure e-Rx firm hit by data breach; CISA warns of active D-Link router exploit; a couple cases of insecure APIs being abused; 53k Nissan employees’ SSN’s leaked; new macOS malware called Cuckoo; Ascension Healthcare suffers cyberattack; Proton user’s poor OpSec gives him away; TunnelVision VPN attack exploits DHCP feature; Maryland & Vermont pass data privacy laws; tracker detection feature debuts on iPhone & Android.
Article Links1. [BleepingComputer] MediSecure e-script firm hit by ‘large-scale’ data breach https://www.bleepingcomputer.com/news/security/medisecure-e-script-firm-hit-by-large-scale-ransomware-data-breach/ 2. [The Hacker News] CISA Warns of Actively Exploited D-Link Router Vulnerabilities https://thehackernews.com/2024/05/cisa-warns-of-actively-exploited-d-link.html 3. [Ars Technica] How I upgraded my water heater and discovered how bad smart home security can be https://arstechnica.com/gadgets/2024/05/how-i-upgraded-my-water-heater-and-discovered-how-bad-smart-home-security-can-be/ 4. [BleepingComputer] Dell API abused to steal 49 million customer records in data breach https://www.bleepingcomputer.com/news/security/dell-api-abused-to-steal-49-million-customer-records-in-data-breach/ 5. [infosecurity-magazine.com] 53,000 Nissan Employees’ Social Security Numbers Exposed https://www.infosecurity-magazine.com/news/employees-social-security-nissan/ 6. [Tom’s Guide] New Cuckoo macOS malware can take over all Macs and steal your passwords https://www.tomsguide.com/computing/malware-adware/new-cuckoo-macos-malware-can-take-over-all-macs-and-steals-your-passwords-too-dont-fall-for-this 7. [Dark Reading] Ascension Healthcare Suffers Major Cyberattack https://www.darkreading.com/cyberattacks-data-breaches/ascension-healthcare-hit-by-cyberattack 8. [restoreprivacy.com] Proton Mail Discloses User Data Leading to Arrest in Spain https://restoreprivacy.com/protonmail-discloses-user-data-leading-to-arrest-in-spain/ 9. [Ars Technica] Novel attack against virtually all VPN apps neuters their entire purpose https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/ 10. [mullvad.net] Evaluating the impact of TunnelVision https://mullvad.net/en/blog/evaluating-the-impact-of-tunnelvision 11. [epic.org] Vermont Passes Landmark Data Privacy Bill https://epic.org/vermont-passes-landmark-data-privacy-bill/ 12. [epic.org] Governor Moore Signs Maryland Online Data Privacy Act https://epic.org/governor-moore-signs-maryland-online-data-privacy-act/ 13. [9to5Mac] Here’s how the new Cross-Platform Tracking Detection works https://9to5mac.com/2024/05/13/cross-platform-tracking-detection-ios-17-5/ 14. Tip of the Week: How to Choose a PIN https://firewallsdontstopdragons.com/how-to-choose-a-pin/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Russia has been hacking Ukraine for at least a decade now, but since the invasion of Ukraine in February of 2022, the cyber war has changed. Instead of being a tactical element, cyber war is now a full-fledged strategic aspect of the conflict, on both sides. At the outset, Ukraine put out an official call to enlist cyber warriors from around the globe to their cause in what’s been called the IT Army of Ukraine. Today we’ll look at how this group was formed, how it operates, and what we should all be learning from what’s happening there. My guest is Dina Temple-Raston The Record and the Click Here Podcast, and formerly from NPR.
Interview Notes* Dina Temple-Raston at The Record: https://therecord.media/author/dina-temple-raston * Click Here podcast: https://therecord.media/podcast * Click Here, Episode 98: “Lessons from the world’s first hybrid war”: https://podcasts.apple.com/us/podcast/click-here/id1225077306?i=1000639045741 * NPR’s I’ll Be Seeing You: https://www.npr.org/series/760566025/ill-be-seeing-you * Operation Glowing Symphony: https://www.npr.org/2019/09/26/763545811/how-the-u-s-hacked-isis
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Google’s Chrome browser has dominated the planet – both on desktop computers and mobile devices. Furthermore, many other popular web browsers are actually based on the same Google-made Chromium browser engine, including Microsoft Edge and Brave Browser. This gives Google an inordinate amount of influence on web standards, in particular preventing better privacy protections. We need to support privacy-forward alternatives lest they disappear.
In other news: US passes expanded mass surveillance policies instead of curbing them; TikTok ban bill becomes law giving Bytedance a year to sell it; UK’s Investigatory Powers Bill amendment passes; photo-sharing app will use users’ uploaded images to train AI; Health insurers Kaiser and Change Healthcare are hacked; antivirus software service installs malware on user’s systems; FCC fines telecom’s $200M; CISA director pushes for vendor accountability; CISA’s proactive protection programs are making positive impacts; UK becomes first country to enforce strong and strict IoT security requirements; net neutrality is back; Google again delays killing third party cookies.
Article Links1. [Electronic Frontier Foundation] U.S. Senate and Biden Administration Shamefully Renew and Expand FISA Section 702, Ushering in a Two Year Expansion of Unconstitutional Mass Surveillance https://www.eff.org/deeplinks/2024/04/us-senate-and-biden-administration-shamefully-renew-and-expand-fisa-section-702-0 2. [TechCrunch] Biden signs bill that would ban TikTok if ByteDance fails to sell the app https://techcrunch.com/2024/04/24/biden-signs-bill-that-would-ban-tiktok-if-bytedance-fails-to-sell-the-app/ 3. [theregister.com] UK’s Investigatory Powers Bill to become law despite tech world opposition https://www.theregister.com/2024/04/26/investigatory_powers_bill/ 4. [TechCrunch] Photo-sharing community EyeEm will license users photos to train AI if they don’t delete them https://techcrunch.com/2024/04/26/photo-sharing-community-eyeem-will-license-users-photos-to-train-ai-if-they-dont-delete-them/ 5. [TechCrunch] Health insurance giant Kaiser notifies millions of a data breach https://techcrunch.com/2024/04/25/kaiser-permanente-health-plan-millions-data-breach/ 6. [TechCrunch] Change Healthcare hackers broke in using stolen credentials — and no MFA, says UHG CEO https://techcrunch.com/2024/04/30/uhg-change-healthcare-ransomware-compromised-credentials-mfa/ 7. [Ars Technica] Hackers infect users of antivirus service that delivered updates over HTTP https://arstechnica.com/security/2024/04/hackers-infect-users-of-antivirus-service-that-delivered-updates-over-http/ 8. [BleepingComputer] FCC fines carriers $200 million for illegally sharing user location https://www.bleepingcomputer.com/news/technology/fcc-fines-carriers-200-million-for-illegally-sharing-user-location/ 9. [cybersecuritydive.com] CISA director pushes for vendor accountability and less emphasis on victims’ errors https://www.cybersecuritydive.com/news/cisa-highlights-vendors-errors/714300/ 10. [therecord.media] More than 800 vulnerabilities resolved through CISA ransomware notification pilot https://therecord.media/vulnerabilities-resolved-through-cisa-pilot 11. [therecord.media] UK becomes first country to ban default bad passwords on IoT devices https://therecord.media/united-kingdom-bans-defalt-passwords-iot-devices 12. [WIRED] Net Neutrality Returns to a Very Different Internet https://www.wired.com/story/fcc-net-neutrality-rules-vote/ 13. [Ars Technica] Google delays third-party cookie death again: Now scheduled for 2025 https://arstechnica.com/gadgets/2024/04/google-delays-third-party-cookie-death-again-now-scheduled-for-2025/ 14. Tip of the Week: https://firewallsdontstopdragons.com/its-time-to-quit-chrome/
Further Info Under New Management plugin: https://github.com/classvsoftware/under-new-management * Donate to Mozilla (Firefox): https://foundation.mozilla.org/en/donate/ * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
AI has been grabbing all the tech headlines, but cryptocurrency is still innovating and changing. One of the primary goals of cryptocurrency was to be decentralized and therefore not controlled by governments like fiat currency. That is about to change. Central Bank Digital Currency (CBDC) is a new type of cryptocurrency that is created and governed by nation states, which comes with serious implications for privacy and global economics. Thankfully I’ve got cryptocurrency expert Seth for Privacy on the show to explain how CBDC works and how it will affect us.
Interview Notes* Opt Out Podcast: https://optoutpod.com/ * Freedom.Tech: https://freedom.tech/ * Foundation.xyz: https://foundation.xyz/ * CBDC tracker: https://cbdctracker.hrf.org/home * Samourai Wallet 1: https://freedom.tech/how-samourai-worked/ * Samourai Wallet 2: https://freedom.tech/samourai-to-sparrow/ * Cryptocurrency 101 interview: https://podcast.firewallsdontstopdragons.com/2022/06/06/cryptocurrency-101/
Further Info Treasure & Coin Promo: https://fdsd.me/promo424 * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
You’ve heard people like me recommend this for years. It’s time to just do it: freeze your credit report. There are really no downsides at this point. For example, it’s now free everywhere in the US, by law. It’s also free to temporarily “thaw” your credit. And it’s gotten a lot easier to do, too. Freezing your credit is your main defense against financial identity theft. And with the sheer number of data breaches (like the recent massive AT&T leak), the personal information needed to commit identity theft is out there already.
In other news: AT&T now says 51 million past and current customers’ data were leaked; beware of a new password reset ‘bomb’ campaign; Microsoft is using Outlook to harvest and share your data; a new email scam alters their content after forwarding; a devious and devastating supply chain attack was thwarted in the nick of time; AI organizations are using sneaky techniques to train their models on your data; Meta is lacing its apps with AI, and there’s not much you can do about it; LG TVs are hacked; Roku is breached again, this time affecting over 500,000 accounts; Twitter/X looking to charge new users a small fee to try to curb bot accounts; DuckDuckGo unveils trio of new for-pay privacy services; Google launches their own Find My network; and various US government agencies, lacking a real privacy law, attempt to curb privacy abuses using existing powers.
Article Links1. [BleepingComputer] AT&T now says data breach impacted 51 million customers https://www.bleepingcomputer.com/news/security/att-now-says-data-breach-impacted-51-million-customers/ 2. [AppleInsider] If you’re getting dozens of password reset notifications, you’re being attacked https://appleinsider.com/articles/24/03/27/if-youre-getting-dozens-of-password-reset-notifications-youre-being-attacked 3. [proton.me] Outlook is Microsoft’s new data collection service https://proton.me/blog/outlook-is-microsofts-new-data-collection-service 4. [Lutra Security] Kobold letters https://lutrasecurity.com/en/articles/kobold-letters/ 5. [Schneier Blog] Backdoor in XZ Utils That Almost Happened https://www.schneier.com/blog/archives/2024/04/backdoor-in-xz-utils-that-almost-happened.html 6. [Engadget] OpenAI and Google reportedly used transcriptions of YouTube videos to train their AI models https://www.engadget.com/openai-and-google-reportedly-used-transcriptions-of-youtube-videos-to-train-their-ai-models-163531073.html 7. [Lifehacker] How to Turn Off Meta AI on Facebook, Instagram, Messenger, and WhatsApp https://lifehacker.com/tech/how-to-turn-off-meta-ai-on-facebook-instagram-messenger-whatsapp 8. [bitdefender.com] Vulnerabilities Identified in LG WebOS https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/ 9. [Lifehacker] Roku Says More Than 500,000 Accounts Were Compromised in a Cyberattack https://lifehacker.com/tech/roku-cyberattack-compromises-accounts 10. [MacRumors] X May Charge New Users a ‘Small Fee’ to Post, Like and Reply https://www.macrumors.com/2024/04/15/x-small-fee-new-users/ 11. [WIRED] DuckDuckGo Is Taking Its Privacy Fight to Data Brokers https://www.wired.com/story/duckduckgo-vpn-data-removal-tool-privacy-pro/ 12. [MacRumors] Google Launches Android Find My Device Network https://www.macrumors.com/2024/04/08/google-android-find-my-device-network-2/ 13. [ftc.gov] Proposed FTC Order will Prohibit Telehealth Firm from Using or Disclosing Sensitive Data for Advertising Purposes https://www.ftc.gov/news-events/news/press-releases/2024/04/proposed-ftc-order-will-prohibit-telehealth-firm-cerebral-using-or-disclosing-sensitive-data 14. [The Verge] The CFPB wants to rein in data brokers https://www.theverge.com/2024/4/15/24131354/cfpb-data-brokers-fair-credit-reporting-act 15. [therecord.media] Automakers and FCC square off over potential regulations for connected cars https://therecord.media/fcc-automakers-connected-cars-regulation-mvnos 16. Tip of the Week: https://firewallsdontstopdragons.com/credit-freeze-now-is-the-time/
Further Info Treasure & Coin Promo: https://fdsd.me/promo424 * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
There’s a lot of nasty stuff online – things we would prefer our kids not see, at least not until they’re mature enough to handle it. Our elected representatives have proposed various regulations to try to protect kids online, and while this is obviously a laudable goal, the devil is always in the details. Many of the proposed solutions have serious negative consequences for both kids and adults, chilling free speech and blocking useful content. I’ll discuss the latest iteration of these proposed solutions in the US called the Kids Online Safety Act (KOSA) as well as the similar Online Safety Act in the UK. With me is Joe Mullin, senior policy analyst at the Electronic Frontier Foundation (EFF).
Interview Notes* Joe Mullin (EFF): https://www.eff.org/about/staff/joe-mullin * EFF on KOSA: https://www.eff.org/deeplinks/2024/02/dont-fall-latest-changes-dangerous-kids-online-safety-act * EFF on KOSA in depth: https://www.eff.org/deeplinks/2024/03/analyzing-kosas-constitutional-problems-depth * Contact Congress: https://www.eff.org/congress * EFF on CA ballot initiative: https://www.eff.org/deeplinks/2024/02/eff-opposes-california-initiative-would-cause-mass-censorship * EFF submission to Ofcom: https://www.eff.org/deeplinks/2024/03/effs-submission-ofcoms-consultation-illegal-harms * Santa Clara Principles for online content moderation: https://santaclaraprinciples.org/
Further Info Treasure & Coin Promo: https://fdsd.me/promo424 * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Today I answer some of the most interesting listener questions from the past several months, including: how to do you get SMS 2FA codes while traveling abroad; should I periodically change all my passwords; how do hackers attack IoT devices inside my home network; can a website fingerprint me based on a hardware security key; can you recommend an email client that protects your privacy; if I give my IoT device permission to see my local network, does that include the guest network; how to hackers find vulnerabilities and figure out how to attack them; why can’t I use my VPN on an airplane to stream Netflix; how can I protect my cryptocurrency and smartphone. Also, I give my take on the crazy TikTok ban legislation.
Links1. New Year’s Resolutions for 2024: https://firewallsdontstopdragons.com/new-years-resolutions-for-2024/ 2. GRC’s Shields Up! Tool: https://www.grc.com/shieldsup 3. Secure your home network: https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/ 4. My Take on TikTok Ban: https://firewallsdontstopdragons.com/my-take-on-tiktok-ban/ 5. The TikTok Situation is a Mess: https://lifehacker.com/tech/the-tiktok-situation-is-a-mess 6. EFF on TikTok: https://www.eff.org/deeplinks/2024/03/5-big-unanswered-questions-about-tiktok-bill 7. The US Wants to Ban TikTok: https://www.404media.co/the-u-s-wants-to-ban-tiktok-for-the-sins-of-every-social-media-company/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Today I talk with Justin and Jodi Daniels about that state of privacy today, how we can help consumers and companies better understand the importance of privacy and security, and how companies are dealing with these aspects internally. We talk about the state of privacy regulations (or the lack thereof), why companies are failing to protect their customers, and what we can do about that.
Justin and Jodi host a podcast together called She Said Privacy, He Said Security. They’ve also co-written a book called “Data Reimagined: Building trust one byte at a time”.
Interview Notes* Justin & Jodi Daniels’ podcast: https://redcloveradvisors.com/podcasts/ * Justin Daniels: https://www.linkedin.com/in/justinsdaniels/ * Jodi Daniels: https://www.linkedin.com/in/jodihoffmandaniels/ * Red Clover Advisors: https://redcloveradvisors.com/ * Baker Donelson: https://www.bakerdonelson.com/ * Data Reimagined book: https://redcloveradvisors.com/book-sales/ * International Association of Privacy Professionals (IAPP): https://iapp.org/ * Information Commissioner’s Office (ICO): https://ico.org.uk/ * YourAdChoices (AboutAds.info): https://youradchoices.com/ * How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ * Jeff Jockisch top 10: https://www.linkedin.com/posts/jozian_privacypodcast-peopleschoice-privacyawards-activity-7155591864593637376-Q3bi/
Further Info Coin & Treasure Promo: https://fdsd.me/promo424 * Send me your questions: https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Passwords, two-factor authentication and even passkeys don’t matter if you can access someone’s account by answering three simple account recovery questions. Also, just about every account today has a way to reset your password, no matter how strong it is, if you can gain access to someone’s email account. Until we can remove these weak links, it doesn’t matter how secure our regular authentication schemes are.
In the news: old A&T breach data is making the rounds; Apple Silicon chips have a security flaw baked into the hardware; two very popular digital safe locks come with backdoor codes; Twitter/X is failing to properly check posted links that redirect to scam sites; a court rules that external continuous camera surveillance of your house doesn’t require a warrant; searches for VPNs spike after PornHub pulls out of Texas; a blockbuster NY Times article brings much needed attention to data collection in cars; AirBnB implements a blanket camera ban.
And I announce a killer new patron promotion! Click this link! https://fdsd.me/promo424
Article Links1. [restoreprivacy.com] AT&T Investigating Potential Breach Following Leak of 73.4 Million Records https://restoreprivacy.com/att-investigating-breach-following-leak-of-73-4-million-records/ 1. HaveIBeenPwned.com: https://haveibeenpwned.com/ 2. [9to5Mac] Unpatchable security flaw in Apple Silicon Macs breaks encryption https://9to5mac.com/2024/03/22/unpatchable-security-flaw-mac/ 3. [404media.co] Massively Popular Safe Locks Have Secret Backdoor Codes https://www.404media.co/massively-popular-safe-locks-have-secret-backdoor-codes/ 4. [Lifehacker] It’s Not Safe to Click Links on X https://lifehacker.com/tech/its-not-safe-to-click-links-on-x 5. [Gizmodo] The Feds Can Film Your Front Porch for 68 Days Without a Warrant, Says Court https://gizmodo.com/feds-can-film-your-front-porch-without-warrant-1851352414 6. [CNN] Searches for VPNs spike in Texas after Pornhub pulls out of the state https://www.cnn.com/2024/03/15/tech/vpn-searches-spike-texas-pornhub 7. [The New York Times] Automakers Are Sharing Consumers’ Driving Behavior With Insurance Companies https://www.nytimes.com/2024/03/11/technology/carmakers-driver-tracking-insurance.html 8. [Lifehacker] Airbnb’s New Security Camera Ban Is a Big Deal https://lifehacker.com/tech/airbnbs-new-security-camera-ban 9. Tip of the Week: https://firewallsdontstopdragons.com/account-security-is-broken/
Further Info Become a Patron! (promo): https://fdsd.me/promo424 * Lock & Code Podcast: https://www.malwarebytes.com/blog/podcast/2024/03/securing-your-home-network-is-long-tiresome-and-entirely-worth-it-with-carey-parker-lock-and-code-s05e07 * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
The United States has no general data privacy laws. However, we do have some sector-specific regulations, including HIPAA for health data. But there are many misconceptions about HIPAA. For example, the “P” in HIPAA does not stand for Privacy – it stands for Portability. So, what information does HIPAA cover? Which healthcare and related service providers are governed by HIPAA? And most importantly, what can you do to protect your medical and health data? Today we’ll dive deep into this subject with Kate Black, a data, privacy & health lawyer and a strategic advisor in the health data field.
Interview Notes* Kate Black: https://www.linkedin.com/in/kate-black-sfo/ * Washington’s My Health, My Data law: https://hintzelaw.com/blog/2023/4/9/wa-my-health-my-data-act-pt1-overview * HIPAA rights: https://www.hhs.gov/hipaa/for-individuals/guidance-materials-for-consumers/index.html * STAT medical news: https://www.statnews.com/
Further Info Check out my dragon challenge coins! https://fdsd.me/coin2 * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Two-factor authentication (2FA) is a fantastic way to improve the security of your online accounts. However, if you lose access to the device containing your authenticator app, you may lose access to your 2FA-protected accounts. You need to backup the seed codes used to set up each account. I’ll give you several methods for doing this.
In the news: FBI uses smartphone push notifications to track down criminals; Roku TVs block all access until users consent to force arbitration; cheap video doorbells have horrible security; AI can be used to determine where photos were taken; vending machine caught using facial recognition; what happens to your data when a data broker goes bankrupt; your personal information that is publicly available; New Jersey passes motor vehicle data deletion law; Proton Mail’s new email aliasing feature; in Canada, police now need warrant to get a person’s IP address; US cracks down on commercial spyware firm; NSO Group forced to hand over source code to Meta in legal case; Authy is shutting down its desktop app.
Article Links1. [The Washington Post] The FBI’s new tactic: Catching suspects with push alerts https://www.washingtonpost.com/technology/2024/02/29/push-notification-surveillance-fbi/ 2. [TechCrunch] Roku disables TVs and streaming devices until users consent to forced arbitration https://techcrunch.com/2024/03/05/roku-disables-tvs-and-streaming-devices-until-users-consent-to-forced-arbitration/ 3. [Consumer Reports] These Video Doorbells Have Terrible Security https://www.consumerreports.org/home-garden/home-security-cameras/video-doorbells-sold-by-major-retailers-have-security-flaws-a2579288796/ 4. [NPR] Artificial intelligence can find your location in photos, worrying privacy experts https://www.npr.org/2023/12/19/1219984002/artificial-intelligence-can-find-your-location-in-photos-worrying-privacy-expert 5. [Ars Technica] Vending machine error reveals secret face image database of college students https://arstechnica.com/tech-policy/2024/02/vending-machine-error-reveals-secret-face-image-database-of-college-students/ 6. [The Markup] What Happens to Your Sensitive Data When a Data Broker Goes Bankrupt? – The Markup https://themarkup.org/privacy/2024/02/23/what-happens-to-your-sensitive-data-when-a-data-broker-goes-bankrupt 7. [Lifehacker] All of Your Information That’s Publicly Available (and What You Can Do About It) https://lifehacker.com/tech/all-your-information-thats-publicly-available-what-to-do-about-it 8. [privacy4cars.com] “Motor Vehicle Data Deletion Act” of New Jersey https://privacy4cars.com/nj-law/ 9. [Lifehacker] Proton Mail Now Lets You Hide Your Real Email Address https://lifehacker.com/tech/how-to-set-up-email-aliases-proton-mail 10. [CBC] Police now need a warrant to get a person’s IP address, Supreme Court rules https://www.cbc.ca/news/politics/supreme-court-privacy-ipaddress-1.7130727 11. [The Hacker News] U.S. Cracks Down on Predatory Spyware Firm for Targeting Officials and Journalists https://thehackernews.com/2024/03/us-cracks-down-on-predatory-spyware.html 12. [9to5Mac] iPhone spyware company NSO suffers major defeat in US court, in Meta lawsuit https://9to5mac.com/2024/03/01/iphone-spyware-company-nso-must-reveal-code/ 13. [The Verge] Authy is shutting down its desktop app https://www.theverge.com/2024/1/8/24030477/authy-desktop-app-shutting-down 14. Tip of the Week: Backing Up Your 2FA Seed Codes https://firewallsdontstopdragons.com/how-to-backup-2fa-seed-codes/ 15. Command line tool to extract codes from Authy: https://gist.github.com/gboudreau/94bb0c11a6209c82418d01a59d958c93
Further Info Check out my dragon challenge coins! https://fdsd.me/coin2 * Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support
Table of ContentsUse these timestamps to jump to a particular section of the show.
With the rise of IoT and tracking technologies (both online and in the real word), we are generating staggering amounts of highly personal information. This massive trove of juicy data has drawn the attention of several interested parties outside the realm of consumer marketing. Like chum in the water, it’s created a feeding frenzy from data aggregators as well as from law enforcement and intelligence agencies, both foreign and domestic. The journalists at 404 Media have published several blockbuster articles on this data ecosystem which have triggered backlashes from lawmakers and consumers alike. Today I’ll speak with two of the founders: Joseph Cox and Jason Koebler.
Interview Notes* 404 Media: https://www.404media.co/ * 404 Media podcast: https://www.404media.co/the-404-media-podcast/ * 404 Media support: https://www.404media.co/faq/ * Formation of 404 Media: https://www.nytimes.com/2023/08/22/business/media/404-media-vice-motherboard.html
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support
Table of ContentsUse these timestamps to jump to a particular section of the show.
Artificial Intelligence is the buzzword of the day. Since the launch of ChatGPT in November 2022, there has been a flood of AI-based tools and services. Many tech firms are racing to build AI into their products without considering the consequences, let alone taking the time to build in guardrails for privacy and security. Today, I’ll tell you about some of the risks, how to mitigate them and explain why you should spend some time playing with AI tools so we can understand how they do (and don’t) work.
In other news: Wyze home webcams had yet another security breach; Poland’s PM calls out illegal use of Pegasus spyware by opposition party; US military finally notifies 20,000 of email data breach; Skiff was bought by Notion and will shut down services; FTC fines Avast antivirus $16.5M for mining user data; Backdoors in encryption violate human rights according to EU court; LockBit ransomware servers were taken over by multinational law enforcement efforts; Apple’s iMessage gaining quantum computer resistant encryption; Signal finally allows users to hide cell phone numbers via usernames; new Android secure browsing features announced.
Article Links1. [Lifehacker] Wyze Had a Security Breach (Again) https://lifehacker.com/tech/wyze-security-breach-again 2. [The Associated Press] Poland’s prime minister says authorities widely used spyware under the previous government https://apnews.com/article/poland-government-pegasus-spyware-tusk-duda-78420fc7099401926d28b5be98669192 3. [TechCrunch] US military notifies 20,000 of data breach after cloud email leak https://techcrunch.com/2024/02/14/department-defense-data-breach-microsoft-cloud-email/ 4. [The Cut] The Day I Put $50,000 in a Shoe Box and Handed It to a Stranger https://www.thecut.com/article/amazon-scam-call-ftc-arrest-warrants.html 1. https://pluralistic.net/2024/02/05/cyber-dunning-kruger/ 5. [restoreprivacy.com] Skiff Mail Shutting Down in 6 Months (Try These Alternatives) https://restoreprivacy.com/skiff-shutting-down-alternatives-to-skiff-mail/ 6. [404media.co] FTC Fines Avast $16.5 Million For Selling Browsing Data Harvested by Antivirus https://www.404media.co/impact-ftc-fines-avast-16-5-million-for-selling-browsing-data-harvested-by-antivirus/ 7. [Ars Technica] Backdoors that let cops decrypt messages violate human rights, EU court says https://arstechnica.com/tech-policy/2024/02/human-rights-court-takes-stand-against-weakening-of-end-to-end-encryption/ 8. [Ars Technica] LockBit ransomware group taken down in multinational operation https://arstechnica.com/information-technology/2024/02/lockbit-ransomware-group-taken-down-in-multinational-operation/ 9. [WIRED] Apple’s iMessage Is Getting Post-Quantum Encryption https://www.wired.com/story/apple-pq3-post-quantum-encryption/ 10. [signal.org] Keep your phone number private with Signal usernames https://signal.org/blog/phone-number-privacy-usernames/ 11. [Lifehacker] These New Android Features Will Keep You Safer Online https://lifehacker.com/tech/android-safer-browsing-and-live-threat-detection-rolling-out 12. Tip of the Week: Mitigating AI Risks https://firewallsdontstopdragons.com/how-to-mitigate-the-risks-of-ai/
Further Info Send me your questions! https://fdsd.me/qna * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Subscribe to the newsletter: https://fdsd.me/newsletter * Become a patron! https://www.patreon.com/FirewallsDontStopDragons * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Support our mission! https://fdsd.me/support * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Modern cars are chock full of sensors and connected to the internet via built-in cellular modems. That’s a recipe for massive data collection. Last September, Mozilla’s Privacy Not Included team released a blockbuster report how much data our cars were gathering and it was absolutely staggering. According to the hard-to-find privacy policies, your car can collect extremely personal information including precise location, contact lists from your phone, call and message data, and – believe it or not – even “sexual activity”. Today, I’ll walk through this report and its implications with the head of Mozilla’s Privacy Not Included project, Jen Caltrider.
Interview Notes* Mozilla’s Privacy Not Included: https://foundation.mozilla.org/en/privacynotincluded/ * Mozilla’s car report: https://foundation.mozilla.org/en/privacynotincluded/articles/its-official-cars-are-the-worst-product-category-we-have-ever-reviewed-for-privacy/ * Mozilla’s report on AI chatbots: https://foundation.mozilla.org/en/privacynotincluded/articles/happy-valentines-day-romantic-ai-chatbots-dont-have-your-privacy-at-heart/ * Donate to Mozilla Foundation: https://donate.mozilla.org/ * Mozilla layoffs: https://techcrunch.com/2024/02/13/mozilla-downsizes-as-it-refocuses-on-firefox-and-ai-read-the-memo/ * Sign the petition to stop car data gathering! https://foundation.mozilla.org/en/privacynotincluded/articles/car-companies-stop-your-huge-data-collection-programs-en/ * Bruce Schneier article in Slate: https://slate.com/technology/2023/12/ai-mass-spying-internet-surveillance.html
Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book
Table of ContentsUse these timestamps to jump to a particular section of the show.
It's tax time here again in the USA, and therefore it's also time for tax scams. I'll explain how to recognize common tax scams, how to respond to them, how to prevent scammers from taking over your IRS account and even filing fraudulent tax returns in your name.In other news: the Mother of All Breaches (MOAB) contains 26 billion records; 23andMe is in trouble after massive data breach and pending class action lawsuits; a viral story about a smart toothbrush botnet isn't true... but could have been; a clever hack of older computer TPM modules could expose encrypted hard drive data (but it's not easy to do); Malwarebytes has issued their 2024 malware report; the FBI and CISA are raising the alarm over Chinese hackers and key US infrastructure, as well as taking action to prevent it; you might want to consider creating a family password to defeat voice clone scams; Mozilla has released a new data deletion service; and Privacy4Cars has an interesting new mechanism for universally opting out of data collection.Article Links[cybernews] Mother of all breaches reveals 26 billion records https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/[Fast Company] 23andMe at risk of being delisted from the Nasdaq as lawsuits mount https://www.fastcompany.com/91020738/23andme-risk-delisted-nasdaq-class-action-lawsuits[404media.co] The Viral Smart Toothbrush Botnet Story Almost Certainly Isn't Real https://www.404media.co/the-viral-toothbrush-ddos-botnet-story-almost-certainly-isnt-real/[Tom's Hardware] YouTuber breaks BitLocker encryption in less than 43 seconds with sub-$10 Raspberry Pi Pico https://www.tomshardware.com/pc-components/cpus/youtuber-breaks-bitlocker-encryption-in-less-than-43-seconds-with-sub-dollar10-raspberry-pi-pico[9to5Mac] Report: Mac security threats on the rise, here’s what to watch out for https://9to5mac.com/2024/02/06/report-mac-security-threats-on-the-rise/[NBC News] FBI director to warn Chinese hackers aim to 'wreak havoc' on US critical infrastructure https://www.nbcnews.com/politics/national-security/fbi-director-warn-chinese-hackers-aim-wreak-havoc-us-critical-infrastr-rcna136524[Ars Technica] Chinese malware removed from SOHO routers after FBI issues covert commands https://arstechnica.com/security/2024/01/chinese-malware-removed-from-soho-routers-after-fbi-issues-covert-commands/[cisa.gov] CISA and FBI Release Secure by Design Alert Urging Manufacturers to Eliminate Defects in SOHO Routers https://www.cisa.gov/news-events/alerts/2024/01/31/cisa-and-fbi-release-secure-design-alert-urging-manufacturers-eliminate-defects-soho-routers[9to5Mac] FCC outlaws voice cloning robocalls after AI-generated voice claimed to be President Biden https://9to5mac.com/2024/02/08/voice-cloning-robocalls/[Electronic Frontier Foundation] Worried about AI voice clone scams? Create a family password https://www.eff.org/deeplinks/2024/01/worried-about-ai-voice-clone-scams-create-family-password [The Verge] Firefox maker Mozilla has a new subscription to keep your info out of data brokers’ clutches https://www.theverge.com/2024/2/6/24062765/mozilla-monitor-plus-firefox-paid-subscription-privacy-data-broker-removal-requests[optoutcode.com] A Privacy4Cars Universal Opt-Out Concept https://optoutcode.com/Tip of the Week: Avoiding Tax Scams https://firewallsdontstopdragons.com/how-to-avoid-tax-scams/Further InfoSecure Your Network: https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/ Davos speech, original: https://www.youtube.com/watch?v=fJoEPRQMBuY Davos speech, translated: https://www.youtube.com/live/6Fwv9Cek2F4?feature=shared&t=98How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ How to send files securely: https://firewallsdontstopdragons.com/how-to-send-files-securely-like-tax-info/ Send me your questions! https://fdsd.
Are Macs really safer than PCs? What should you do to make your Mac more secure? How do you know if your Mac has a virus? And how do you know which security apps you can trust? I'll dig into all of these questions and more today with Mac security guru Patrick Wardle.Patrick Wardle is the founder of the Objective-See Foundation. Having worked at NASA and the NSA, as well as presented at countless security conferences Patrick is passionate about all things related to macOS security, writing books on macOS malware, and releasing free open-source security tools to protect Mac users.Interview NotesObjective See (free Mac tools): https://objective-see.org/ The Art of Mac Malware (book): https://taomm.org/ Objective by the Sea conference: https://objectivebythesea.org/ Apple’s Malware protections: https://support.apple.com/guide/security/protecting-against-malware-sec469d47bd8/1/web/1 Reinstall macOS in Recovery Mode: https://support.apple.com/en-us/HT204904 Jamf presentation on Apple anti-malware tools: https://www.jamf.com/resources/videos/a-closer-look-at-macos-built-in-security-tools/ Further InfoGet your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:01:45: Interview setup0:04:06: What have you been up to since we last had you on the show?0:13:40: Are Macs safer than PCs?0:17:34: How effective are modern antivirus programs?0:22:25: Which are the better AV software programs?0:24:45: Tell us about the Mac security apps that you created0:27:53: How does Lulu differ from a regular firewall?0:32:00: How do you know which security software you can trust?0:38:00: How do we combat security fatigue?0:43:22: Does the Apple App Store protect me from bad apps?0:52:09: What's your take on Apple's new Lockdown Mode?0:53:34: How do I know if my computer is infected with malware?0:58:03: What should I do to protect my brand new Mac?1:01:23: What worries you most right now? What gives you hope?1:04:43: What's next for you?1:10:31: Wrap-up
While every week is Data Privacy Week here at Firewalls Don't Stop Dragons, the rest of the world stops to join us in focusing on how and why to protect your personal data. I'll give you some of my top privacy tips and refer you to a lot of top privacy resources.In the news: Microsoft executives' emails are hacked by a nation-state actor; Facebook is gathering even more data with the help of other companies; a company is using real-time bidding to track us and sell to intelligence agencies; Mozilla outlines how incumbent browser owners tilt the playing field in favor of the owner; the EU is driving major changes to how iOS will work (but only in the EU); Brave browser simplifies its anti-fingerprinting options; Facebook limits how adult strangers can DM minors; FTC brings actions against GoodRx and Intuit; Samsung matches Google's 7-year OS update update promise; and Apple rolls out Stolen Device Protection feature. Article Links[msrc.microsoft.com] Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/[Consumer Reports] Each Facebook User Is Monitored by Thousands of Companies https://www.consumerreports.org/electronics/privacy/each-facebook-user-is-monitored-by-thousands-of-companies-a5824207467/[404media.co] Inside a Global Phone Spy Tool Monitoring Billions https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/[Mozilla] Platform Tilt: Documenting the Uneven Playing Field for an Independent Browser Like Firefox https://blog.mozilla.org/netpolicy/2024/01/19/platform-tilt[MacRumors] Here Are All the iPhone Changes Coming to EU Users by March 6 https://www.macrumors.com/2024/01/26/iphone-changes-coming-to-eu-users/[brave.com] Brave browser simplifies its fingerprinting protections https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/[9to5Mac] Adult strangers won’t be able to send DMs to teens on Instagram or Facebook https://9to5mac.com/2024/01/25/teens-on-instagram-safeguards/[ftc.gov] FTC Statement on Intuit TurboTax Case https://www.ftc.gov/news-events/news/press-releases/2024/01/statement-samuel-levine-director-ftc-bureau-consumer-protection-regarding-commissions-order-opinion[ftc.gov] FTC Enforcement Action to Bar GoodRx from Sharing Consumers’ Sensitive Health Info for Advertising https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising[9to5Google] Samsung Galaxy S24 follows Google Pixel 8’s lead with 7 years of Android updates https://9to5google.com/2024/01/17/samsung-galaxy-s24-android-updates-policy/[AppleInsider] How to use Stolen Device Protection https://appleinsider.com/articles/24/01/23/how-to-use-stolen-device-protectionTip of the Week: Data Privacy Checklist https://fdsd.me/dpc Further InfoCarey’s Data Privacy Checklist (just updated!): https://fdsd.me/dpc Proton’s mention: https://www.linkedin.com/posts/protonprivacy_protonprivacyreadinglist-activity-7155246272273170432-XlM0Jeff Jockisch’s Best Privacy Podcast results: https://www.linkedin.com/posts/jozian_privacypodcast-peopleschoice-privacyawards-activity-7146196804940820481-yB-PSend me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:29: Recent accolades
Drones are everywhere today. Cheap and tiny accelerometers, gyroscopes and processors have allowed us to create drones that anyone can afford and everyone can fly. Drones have been used by law enforcement and military forces, as well - for surveillance but also for killing. With the rapid development of AI technologies, what happens when we make these drones autonomous? What are the implications for privacy and security? I'll discuss this and more with Nick Weaver, computer and cybersecurity expert, and chief mad scientist at Skerry Technologies.Interview NotesNick Weaver: https://www1.icsi.berkeley.edu/~nweaver/ NYPD drone use: https://www.washingtonpost.com/nation/2023/09/01/drones-labor-day-parties-new-york/ AI drone “kills” its operator: https://www.reuters.com/article/factcheck-ai-drone-kills/fact-check-simulation-of-ai-drone-killing-its-human-operator-was-hypothetical-air-force-says-idUSL1N38023R/ The Future of Drone Warfare: https://www.schneier.com/blog/archives/2023/10/the-future-of-drone-warfare.htmlBetaflight: https://github.com/betaflight/betaflightArdupilot: https://github.com/ArduPilot/ardupilotPX4: https://github.com/PX4/PX4-Autopilot Small Business Innovation Research: https://www.sbir.gov/ Further InfoData Privacy Week: https://staysafeonline.org/programs/data-privacy-week/ Carey’s Data Privacy Checklist (just updated!): https://fdsd.me/dpc Nominate someone for a challenge coin: https://fdsd.me/quest Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:21: Data Privacy Week teaser0:01:11: Apple backdoor clarification0:03:14: Interview setup0:07:15: What first got you interested in autonomous drone technology?0:10:27: What technologies have enabled the explosion of cheap drones?0:15:22: What are the capabilities of modern consumer drones?0:17:54: Are there any legal restrictions on flying drones?0:20:44: Are there privacy laws around drone surveillance?0:22:24: How are drones used by law enforcement?0:25:14: How are drones being used for criminal purposes?0:27:12: What level of autonomy or AI can be found in consumer drones today?0:29:41: How hard is it to turn a DJI drone into an autonomous killbot?0:35:49: What sorts of countermeasures have we developed against drones?0:45:11: What roles have drones played in modern warfare?0:48:40: Can you detect drones on radar?0:50:22: Have drones influenced modern military tactics?0:52:33: Are there treaties restricting automomous killing machines?0:55:51: What's the future of automonous drone tech?0:58:46: Is it difficult today to make your own drone?1:06:24: Interview wrap-up1:09:08: Annual listener survey update
The new year is here! And I've got a handful of solid tips for you that you should absolutely plan to accomplish in 2024! I also have a lot of news to catch you up on:23andMe blames its customers for their data breach; Burger King in Brazil using facial recognition to offer discounts based on how hungover you look; Russian agents hack live webcams to hone in on targets in Ukraine; fake celebrity ads for medicare scam on YouTube; Facebook's Link History is a confusing new tracking feature; FTC orders location data broker to stop selling your info; Google new location history changes may spell the end for geofence warrants; AirDrop anonymity cracked by China; well-hidden iPhone backdoor discovered by Kaspersky; UK tries to further expand surveillance capabilities; the Beeper Mini messaging saga is over; and a marketing company is offering to listen in on real time conversations to target ads.Article Links[TechCrunch] 23andMe tells victims it’s their fault that their data was breached https://techcrunch.com/2024/01/03/23andme-tells-victims-its-their-fault-that-their-data-was-breached/[Dark Reading] Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv https://www.darkreading.com/ics-ot-security/russian-agents-use-residential-webcams-to-gather-info-for-missile-attack-on-kyiv[404media.co] Deepfaked Celebrity Ads Promoting Medicare Scams Run Rampant on YouTube https://www.404media.co/joe-rogan-taylor-swift-andrew-tate-ai-deepfake-youtube-medicare-ads/[Gizmodo] Meet ‘Link History,’ Facebook’s New Way to Track the Websites You Visit https://gizmodo.com/meet-link-history-facebook-s-new-way-to-track-the-we-1851134018[ftc.gov] FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data[Electronic Frontier Foundation] Is This the End of Geofence Warrants? https://www.eff.org/deeplinks/2023/12/end-geofence-warrants[9to5Mac] AirDrop cracked by China, revealing phone number and email address of sender https://9to5mac.com/2024/01/09/airdrop-cracked-by-china/[Schneier Blog] New iPhone Exploit Uses Four Zero-Days https://www.schneier.com/blog/archives/2024/01/new-iphone-exploit-uses-four-zero-days.htmlSecurity Now, Ep955: https://youtu.be/fJHzq4YOv68?si=WTdyr5LCXV4xJh-k&t=2105 [POLITICO Europe] Britain’s got some of Europe’s toughest surveillance laws. Now it wants more https://www.politico.eu/article/uk-bulking-up-spying-regime-breakneck-speed/[MacRumors] Beeper Mini Resorts to Jailbreaking iPhones to Rescue Blue Bubbles https://www.macrumors.com/2023/12/21/beeper-mini-jailbroken-iphones-rescue-imessage/[404media.co] Marketing Company Claims That It Actually Is Listening to Your Phone and Smart Speakers to Target Ads https://www.404media.co/cmg-cox-media-actually-listening-to-phones-smartspeakers-for-ads-marketing/Tip of the Week: https://firewallsdontstopdragons.com/new-years-resolutions-for-2024/ Further InfoTake the annual listener survey! https://fdsd.me/survey2024 Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:38: Listener survey0:01:57: News rundown0:04:35: 23andMe blames victims for their data breach0:09:39: Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv0:15:19: Deepfaked Celebrity Ads Promoting Medicare Scams ...
Data breaches are usually produced by hackers looking for financial gain. Data leaks, on the other hand, are usually published by whistleblowers or perhaps accidentally disclosed via negligence. Journalists today are inundated by such data leaks - to the point where specialized tools and techniques are required to parse through the piles of digital detritus to ascertain the value and import that they may represent. Micah Lee has been performing this function for The Intercept for many years, including analyzing the Snowden documents. And he has just released a book that outlines the tools, techniques and procedures he uses for this arduous process. Today we discuss the importance and impact of whistleblowers, the state of data leaks today, and how it has impacted modern journalism.Interview NotesMicah’s book: https://hacksandleaks.com/ Excerpt article: https://theintercept.com/2023/12/16/hacked-datasets-verification/ Micah’s GIthub project: https://github.com/micahflee/hacks-leaks-and-revelations COINTELPRO documentary: https://en.wikipedia.org/wiki/1971_(2014_film) “The Burglary” book: https://www.amazon.com/Burglary-Discovery-Edgar-Hoovers-Secret/dp/0307962954 EFF’s Surveillance Self-Defense Guide: https://ssd.eff.org/ Further InfoTake the annual listener survey! https://fdsd.me/survey2024 Vote for my show as the best privacy podcast! http://tinyurl.com/PPPCAwards2024 Send me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Become a patron! https://www.patreon.com/FirewallsDontStopDragons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:01:29: Pre-show notes0:03:32: Interview prep0:05:57: Tell us more about the book and why you wrote it.0:08:11: What's the difference between a data breach and a data leak?0:10:02: What are some of history's most importank leaks?0:16:14: How do journalists typically obtain leaked data?0:22:04: You've just obtained a massive blob of data. How do you analyze it?0:27:05: How do you handle leaked data ethnically?0:30:14: Do you warn the owners of leaked data before you reveal it?0:32:23: I want to blow the whistle? What should I do? What shoudn't I do?0:36:28: I've extracted my data. How do I securely share it with a journalist?0:38:57: What are the legal ramifications of whistleblowing?0:41:57: How hard is it to analyze digital data? What tools do you use?0:44:39: Are there dangers to analyzing leaked data?0:46:43: How do organizations try to identify data leakers?0:49:42: Will AI tools like ChatGPT help to analyze data leaks?0:52:19: What can the average person take away from all of this?0:54:15: How do you know which news sources you can trust today?0:56:08: Interview wrap-up0:57:10: Micah blocked on Twitter?0:57:55: Text parsing tools0:58:30: Show links0:58:53: Bonus podcast preview0:59:42: Annual listener survey raffle info
Every week, I record a special, private bonus podcast for my patrons. Until today, all of that content was restricted to my supporters. But today I've got a sampler platter of some of the best snippets from my bonus Q&A with my interview guests, along with an episode of my more-technical bonus series I call Merlin's Musings. You'll hear from Josh Corman (CISA and I Am the Cavalry), Ernesto Falcon (EFF and CA Senate candidate), Omega and Deth Veggie (Cult of the Dead Cow), Michael Littman (AI expert from Brown Univ) and Cory Doctorow (author and activist), plus the strange story of the ProxyHam.Podcast LinksThese are links to the public podcasts associated with the bonus clips I played today along with some related links.Ep332, Josh Corman: https://podcast.firewallsdontstopdragons.com/2023/07/10/national-cyber-strategy/ Cyberattacks on hospitals are growing threats to patient safety, experts say : https://abcnews.go.com/Health/cyberattacks-hospitals-growing-threats-patient-safety-experts/story?id=99115898Ep334, Ernesto Falcon: https://podcast.firewallsdontstopdragons.com/2023/07/24/the-politics-of-privacy/ Ep336, Cult of the Dead Cow: https://podcast.firewallsdontstopdragons.com/2023/08/07/cult-of-the-dead-cow/ Ep338, Michael Littman: https://podcast.firewallsdontstopdragons.com/2023/08/21/demystifying-ai/ Ep348, Cory Doctorow: https://podcast.firewallsdontstopdragons.com/2023/10/30/reclaiming-the-internet/ Wired article on ProxyHam: https://www.wired.com/2015/07/online-anonymity-project-proxyham-mysteriously-vanishes/ Hackaday ProxyHam: https://hackaday.com/tag/proxyham/ ProxyGambit: https://github.com/samyk/proxygambit Further InfoBecome a patron! https://www.patreon.com/FirewallsDontStopDragonsSend me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:02:41: Josh Corman: analog back and sci-fi table top exercises0:12:51: Ernesto Falcon: raising money and CA influence0:19:19: Cult of the Dead Cow: Agent Steal0:23:44: Michael Littman: Superintelligent AI risks vs reality0:33:03: Cory Doctorow: Burning Man0:41:00: Merlin's Musings: ProxyHam0:53:37: Wrapup & patron perks
Today, I dip back into the archives to bring you a classic interview from the first year of this podcast. In Episode 21 (Aug 2017) I interviewed Ladar Levison, the founder of the secure email service Lavabit. He started Lavabit in 2004 as one of the first truly secure, end-to-end encrypted email services focused on the privacy of users, almost ten years before Proton Mail launched. But when the FBI came (literally) knocking in 2013 asking him to subvert the encryption so that they could monitor his users (in particular a guy named Edward Snowden), Ladar decided to shut down Lavabit instead of complying. Ladar relaunched Lavabit in 2021 and I interviewed him that summer about his company, the right to privacy, the story of the shutdown, and much more. It's as relevant today as it was then.Interview NotesLavabit: https://lavabit.com/ Lavabit history: https://en.wikipedia.org/wiki/Lavabit Mr Peaboy and the Wayback Machine: https://en.wikipedia.org/wiki/Mister_Peabody Further InfoSend me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:29: Set the Wayback Machine for 2017!0:04:10: Episode 1 intro0:06:47: Ladar Levison episode intro0:09:43: How and why did you start Lavabit?0:13:24: Why did you shut Lavabit down in 2013?0:18:36: How did the Snowden FBI request differ from the previous ones?0:22:56: Why is privacy important for democracy?0:26:56: Why don't people seem to believe privacy is important?0:28:32: Why should we fight for our right to privacy?0:30:51: What is the legal basis for email searches?0:35:12: How should we allow law enforcement access to private data?0:39:29: Do you worry about losing access to encryption technology?0:51:25: Is secure email an oxymoron?0:53:30: How do we protect users from themselves?0:55:30: Who should be using encrypted email?0:59:35: What is the new Lavabit service like?1:01:33: How does Lavabit work with non-Lavabit recipients?1:02:25: Is the new Lavavit service available now?1:04:08: Does using E2EE services get you on some watch list?1:05:56: How can people best support the right to privacy?1:07:56: Wrap-up and look ahead
I've culled through the podcasts from the last year and put together an hour's worth of the best content! Here's a nice little charcuterie sampler of the top interview segments from 2023.Episode LinksEp347 (Oct 16) What’s Your Threat Model? https://podcast.firewallsdontstopdragons.com/2023/10/16/whats-your-threat-model/ Ep342 (Sep 18) Your Face Belongs to Us https://podcast.firewallsdontstopdragons.com/2023/09/18/your-face-belongs-to-us/ Ep336 (Aug 7) Cult of the Dead Cow https://podcast.firewallsdontstopdragons.com/2023/08/07/cult-of-the-dead-cow/ Ep348 (Oct 30) Reclaiming the Internet https://podcast.firewallsdontstopdragons.com/2023/10/30/reclaiming-the-internet/ Ep324 (May 15) - Probing the Ministry of Truth https://podcast.firewallsdontstopdragons.com/2023/05/15/probing-the-ministry-of-truth/ Ep338 (Aug 21) Demystifying AI https://podcast.firewallsdontstopdragons.com/2023/08/21/demystifying-ai/ Further InfoSend me your questions! https://fdsd.me/qna Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Subscribe to the newsletter: https://fdsd.me/newsletter Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Support our mission! https://fdsd.me/support Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:02:09: Andy Yen, CEO Proton: LastPass breach0:07:22: Kashmir Hill, NY Times: Clearview Ai0:17:25: Omega and Deth Veggie, Cult of the Dead Cow: being a hacker0:39:43: Cory Doctorow, author/activist: ensh*tification0:49:42: Vincent Hendricks, author: social media0:58:32: Michael Littman, Brown Univ: Dangers of AI1:04:46: Wrap-up and look ahead
We here in the US like to believe that we're the gold standard for democracy. And yet, in recent years, much of the electorate has lost faith in the outcome of our elections. Many security researchers have found concerning vulnerabilities in our voting systems, and yet we have no evidence that those vulnerabilities have actually been exploited. Many people believe that people are voting multiple times or that ineligible people are voting, and yet study after study shows that voter fraud is nearly non-existent. How can we restore trust in our election results? What changes must we make to our election systems and processes to promote complete transparency and remove doubt? Today I'll dig deep into this complicated topic with Ben Adida, founder and Executive Director of VotingWorks.Interview NotesVotingWorks: https://www.voting.works/Risk Limiting Audits with ARLO: https://www.voting.works/risk-limiting-audits Verified Voting, Verifier tool: https://verifiedvoting.org/verifier/ Ben’s PhD thesis defense (Verifying a Secret-Ballot Election with Cryptography) and much more: https://ben.adida.net/presentations/ Voluntary Voting System Guidelines (VVSG) 2.0: https://www.eac.gov/sites/default/files/TestingCertification/Voluntary_Voting_System_Guidelines_Version_2_0.pdf Harri Hursti interview: https://podcast.firewallsdontstopdragons.com/2021/11/08/restoring-trust-in-our-elections/ ElectionGuard interview: https://podcast.firewallsdontstopdragons.com/2021/12/06/defending-democracy-with-technology/ DEF CON Voting Village videos: https://www.youtube.com/@defconvotingvillage/videos Further InfoGive the gift of privacy and security: https://fdsd.me/coupons Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:03:28: What is the mission of VotingWorks and what drove you to found it?0:04:39: How do election work, exactly, here in the US?0:12:26: How are all the votes tabulated and reported?0:14:11: Where are US elections most vulnerable to influence?0:19:52: How does accessibility impact security in elections?0:24:27: How can we harden the election systems and processes?0:31:16: How to risk-limiting audits work?0:33:11: How vulnerable are election computers to hacking?0:36:37: If our systems are vulnerable, why haven't they been hacked?0:43:37: How can we best convince people that our election outcomes are valid?0:51:30: How prevelent is voter fraud in the US?0:53:56: Do we have federal minimum guidelines for election security?0:56:52: Why aren't election systems open for third party review?0:58:25: How do I learn about my local election systems and processes?1:04:22: Wrap-up1:07:34: Looking ahead
Your online account credentials have two parts: a user name and a password. Today, most online providers force you to use your email address for your user name. This gives the service provider a guaranteed way to contact (and spam) their users, but it also means that bad guys know half of all your credentials and data brokers have a unique ID to track you across all your accounts. Today I'll explain the value of using email aliases for your online user names.In other news: Iranian hackers attack US water plant; CISA launches program to address critical infrastructure threats; Google Drive users report missing data; Plex users fear new feature will leak p0rn watching habits; several articles on the ease of using data broker tools to spy on just about anyone, creating privacy and national security problems; smart mattress company CEO inadvertently reveals extent of data collection; concerns about IoT device sold with a home; overblown fears over Apple's new NameDrop feature; Zelle offering refunds to some scam victims; and Malwarebyte's survey of people's security practices (spoiler: it's bad).Article Links[The Hacker News] Iranian Hackers Exploit PLCs in Attack on Water Authority in U.S. https://thehackernews.com/2023/11/iranian-hackers-exploit-plcs-in-attack.html[Dark Reading] CISA Launches Pilot Program to Address Critical Infrastructure Threats https://www.darkreading.com/ics-ot/cisa-launches-pilot-program-critical-infrastructure-threats[AppleInsider] Google Drive users complain of missing files, months of data disappearing https://appleinsider.com/articles/23/11/27/google-drive-users-complain-of-missing-files-months-of-data-disappearing[404media.co] Plex Users Fear New Feature Will Leak Porn Habits to Their Friends and Family https://www.404media.co/plex-users-fear-discover-together-week-in-review-feature-will-leak-porn-habits-to-their-friends-and-family/[Rolling Stone] We Spied on Trump’s ‘Southern White House’ From Our Couches https://www.rollingstone.com/culture/culture-features/data-brokers-trump-tech-spying-privacy-threat-1234897098/[9to5mac.com] Data brokers selling even more sensitive info; national security risk, says report https://9to5mac.com/2023/11/14/data-brokers-sensitive-info/[MIT Technology Review] The US military’s privacy problem in three charts https://www.technologyreview.com/2023/11/13/1083262/the-us-militarys-privacy-problem-in-three-charts/[therecord.media] Court rules automakers can record and intercept owner text messages https://therecord.media/class-action-lawsuit-cars-text-messages-privacy[404media.co] CEO Reminds Everyone His Company Collects Customers' Sleep Data to Make Zeitgeisty Point About OpenAI Drama https://www.404media.co/ceo-reminds-everyone-eightsleep-pod-collects-sleep-data-to-make-zeitgeisty-point-about-openai-drama/[sdmmag.com] Who Is Gonna “Own” the IoT? https://www.sdmmag.com/articles/93730-who-is-gonna-own-the-iot[TechRadar] NameDrop in iOS 17 doesn’t have to be a privacy nightmare – here’s how to control it https://www.techradar.com/phones/ios/namedrop-in-ios-17-doesnt-have-to-be-a-privacy-nightmare-heres-how-to-control-it[9to5mac.com] Zelle scams: App now starting limited refunds, under pressure from lawmakers https://9to5mac.com/2023/11/13/zelle-scams/[malwarebytes.com] 3 crucial security steps people should do, but don't https://www.malwarebytes.com/blog/news/2023/10/the-3-crucial-security-steps-people-should-do-but-dontOwnCloud hack: https://www.helpnetsecurity.com/2023/11/28/cve-2023-49103/ Pros & Cons of Antivirus Software: https://firewallsdontstopdragons.com/the-pros-and-cons-of-anti-virus-software/ Tip of the Week: https://firewallsdontstopdragons.com/how-to-use-email-aliases-part-1/Further InfoGive the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support
City governments are relying more and more on a vast network of sensors to tell them what's going on: stop light cameras, gunshot detectors, air quality sensors, license plate readers, automated toll booths, and much more. While these technologies can help the powers that be allocate precious resources and gain helpful insights, they can also lead to over-policing, chilling of free speech and mass warrantless surveillance. Today I'll discuss the dangers of smart cities with Eleni Manis from the Surveillance Technology Oversight Project (STOP).Interview NotesSurveillance Technology Oversight Project: https://www.stopspying.org/ S.T.O.P.'s Beginner’s Guide to the All-Too-Dumb World of Smart Cities: www.justcities.tech CCOPS laws: https://www.eff.org/issues/community-control-police-surveillance-ccops Further InfoBest & Worst Gifts for 2023: https://firewallsdontstopdragons.com/best-worst-gifts-2023/ Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:04:38: What got you into researching smart cities?0:09:03: What are the positive aspects of smart cities?0:13:06: How ubiquitous are these smart city technologies?0:15:32: What are some of the most concerning smart city technologies?0:16:45: is this data being shared between local and federal agencies?0:19:14: Can students opt out of school surveillance?0:20:48: How can the police access footage from video doorbells?0:24:20: How is this tech used for predictive policing?0:26:31: Do these predictive policing systems actually work?0:27:29: How does this mass surveillance affect people?0:28:58: What about use of surveillance tech in neighborhoods?0:33:56: Who operates these sensor networks? Who can access the data?0:37:49: Is it possible to anonymize this data properly?0:42:06: Can government agencies access our cellular data?0:45:22: Can you refuse to hand your cell phone over to authorities?0:48:04: Can we find ways to collect this data without ruining privacy?0:49:42: How do I find out what smart city tech is being used in my area?0:53:29: Wrap-up0:54:57: Preview of upcoming shows
The holiday gift-giving season is upon us - and therefore it's time for my annual guide on the best and worst gifts for your loved ones, at least in terms of security and privacy. There are some perennial favs on the nice and naughty lists, but there are some newcomers, as well. And I've got some top tips for how to shop for privacy-respecting, security-protecting products! I've even got some ideas for free and helpful stocking stuffers.In the news: FCC tried to protect consumers from SIM-swap attacks; cheap children's tablet came with malware and data mining software; medical transcription service has data of 9M patients exposed; hackers hold data from plastic surgeon patients for ransom, including nude photos; FTC filing in Kochava case unsealed showing 'staggering' amount of data for sale; Bitwarden announces support for passkeys; Article 45 of eIDAS 2.0 bill will completely undermine internet security in the EU.Article Links[The Hacker News] FCC Enforces Stronger Rules to Protect Customers Against SIM Swapping Attacks https://thehackernews.com/2023/11/fcc-enforces-stronger-rules-to-protect.html[TechCrunch] Children’s tablet has malware and exposes kid’s data, researcher finds https://techcrunch.com/2023/11/16/childrens-tablet-has-malware-and-exposes-kids-data-researcher-finds/[BleepingComputer] PJ&A says cyberattack exposed data of nearly 9 million patients https://www.bleepingcomputer.com/news/security/pj-and-a-says-cyberattack-exposed-data-of-nearly-9-million-patients/[8newsnow.com] Hackers target Las Vegas plastic surgeons, post patient information, naked photos online https://www.8newsnow.com/investigators/hackers-target-las-vegas-plastic-surgeons-post-patient-information-naked-photos-online/[Ars Technica] Data broker’s “staggering” sale of sensitive info exposed in unsealed FTC filing https://arstechnica.com/tech-policy/2023/11/data-brokers-staggering-sale-of-sensitive-info-exposed-in-unsealed-ftc-filing/[bitwarden.com] Bitwarden launches passkey management https://bitwarden.com/blog/bitwarden-launches-passkey-management/[Electronic Frontier Foundation] Article 45 Will Roll Back Web Security by 12 Years https://www.eff.org/deeplinks/2023/11/article-45-will-roll-back-web-security-12-yearsBest & Worst Gifts for 2023: https://firewallsdontstopdragons.com/best-worst-gifts-2023/ Further InfoGive Thanks!: https://firewallsdontstopdragons.com/give-thanks-donate/ Consumer Reports Naughty List: https://foundation.mozilla.org/en/privacynotincluded/articles/our-longest-naughty-list-ever-the-2023-holiday-buyers-guide-is-here/ Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Table of ContentsUse these timestamps to jump to a particular section of the show.0:01:37: News run-down0:03:18: FCC Enforces Stronger Rules to Protect Against SIM Swapping0:06:39: Children’s tablet has malware and exposes kid’s data0:11:22: Cyberattack exposed data of nearly 9 million patients0:15:16: Hackers target plastic surgeons, post patient info, naked photos online0:22:37: Data broker’s “staggering” sale of sensitive info exposed in unsealed FTC filing0:27:10: Bitwarden launches passkey management0:30:45: Article 45 Will Roll Back Web Security by 12 Years0:39:00: Best & Worst Gifts for 20230:42:38: The Naughty List0:47:50: The Nice List0:59:14: Give thanks!1:00:03: FDSD Merch sale!1:00:25: Upcoming shows & promotion
Today there is a thriving market for legal, for-profit smartphone spyware (aka mercenary spyware). Companies like the NSO Group are free to create and sell highly sophisticated, zero-click malware such as Pegasus which has been used to spy on dissidents, politicians, activists and journalists around the world. There are also several apps available to parents to track their children, but are often used to abuse or stalk adult partners or ex-lovers. Today I'll discuss the state of these malicious apps, ways to protect our smartphones and even detect such spyware after the fact with the co-founders of iVerify, Danny Rogers and Rocky Cole.Interview NotesiVerify app: https://www.iverify.io/consumerxkcd “Security” cartoon: https://xkcd.com/538/ Moxie Marlinspike (Signal) on Cellebrite tool: https://signal.org/blog/cellebrite-vulnerabilities/ Further InfoNominate someone for a challenge coin: https://fdsd.me/quest Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:01:38: Interview setup0:03:08: How does iVerify work and why did you create it?0:07:10: What sort of people need protection like iVerify?0:11:07: How do you know that you can trust a security app?0:14:54: What do MDM profiles do to my phone? Is it reversible?0:20:37: How dangerous are third-party app stores, compared to Apple/Google?0:27:37: If an app I've installed is pulled from the app store, will I be notified?0:28:50: How hard is it today to jailbreak a phone?0:31:49: How do you tell if a phone has been hacked?0:33:21: Can you detect if an app has escaped its sandbox?0:38:09: What is the marketplace like for spyware?0:41:36: Are phones getting harder to hack?0:44:16: Is it possible to detect or prevent hacking via physical access?0:49:11: How do Apple and Google phones compare on security?0:52:08: How does Apple's Lockdown Mode work?0:54:47: Should governments outlaw the sale of mercenary spyware?1:01:10: Should governments hoard 0-days or disclose them?1:03:31: What are your top security tips for regular users?1:05:44: What's next for iVerify?1:07:28: Wrap-up
Connecting all our stuff to the internet – making devices “smart” – brings with it a lot of risks. Besides the more obvious cybersecurity vulnerabilities, these devices are also collecting a lot of personal data, offsetting razor thin profit margins by monetizing our data. In most cases, we can limit this data exfiltration using outbound firewalls and DNS services, or just by disconnecting the devices from the internet altogether. But lately I've been seeing devices coming configured with cellular data connections, which would effectively bypass your home network entirely - and therefore your ability to block or control the data flow.In other news: 1Passwords discloses security breach; Drug makers to pay 23andMe for access to your DNA; EFF publishes guidance for 23andMe customers after further data breach; Apple's private Wi-Fi MAC address feature has never worked right, until now; Hackers find side-channel attack on Apple Silicon to pull private data from Safari browsers; Windows PCs targeted with new malware; YouTube is waging a new way on ad blockers; Apple's iMessage has new method to thwart 'ghost' listeners; the White House releases sweeping executive order on AI; Pew publishes new study on data privacy views. Article Links[BleepingComputer] 1Password discloses security incident linked to Okta breach https://www.bleepingcomputer.com/news/security/1password-discloses-security-incident-linked-to-okta-breach/[Bloomberg] Drugmakers Are Set to Pay 23andMe Millions to Access Consumer DNA https://www.bloomberg.com/news/articles/2023-10-30/23andme-will-give-gsk-access-to-consumer-dna-data[Electronic Frontier Foundation] What to Do If You're Concerned About the 23andMe Breach https://www.eff.org/deeplinks/2023/10/what-do-if-youre-concerned-about-23andme-breach[AppleInsider] Apple's private Wi-Fi MAC addresses were security theater until iOS 17.1 https://appleinsider.com/articles/23/10/27/apples-private-wi-fi-mac-addresses-were-security-theater-until-ios-171[Ars Technica] Hackers can force iOS and macOS browsers to divulge passwords and much more https://arstechnica.com/security/2023/10/hackers-can-force-ios-and-macos-browsers-to-divulge-passwords-and-a-whole-lot-more/[TechRadar] Windows PCs are being targeted with a nasty new malware - here's what you need to know https://www.techradar.com/pro/security/windows-pcs-are-being-targeted-with-a-nasty-new-malware-heres-what-you-need-to-know[404media.co] YouTube's 'War' on Adblockers Shows How Google Controls the Internet https://www.404media.co/youtubes-war-on-adblockers-shows-how-google-controls-the-internet/[9to5mac.com] iMessage Contact Key Verification blocks the ‘ghost proposal’ plan by government spy agency https://9to5mac.com/2023/10/30/imessage-contact-key-verification-reason/[Mashable] White House drops an AI regulation bombshell: 10 new mandates that'll shake up the industry https://mashable.com/article/white-house-drops-ai-regulation-bombshell[pewresearch.org] How Americans View Data Privacy https://www.pewresearch.org/internet/2023/10/18/how-americans-view-data-privacy/Tip of the Week: The Rise of Cellular IoT https://firewallsdontstopdragons.com/the-rise-of-cellular-iot/ Further InfoGet your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:56: News rundown0:03:11: 1Password discloses security incident linked to Okta breach0:06:09: Drugmakers Are Set to Pay 23andMe Millions to Access Consumer DNA0:10:08: What to Do If You're Concerned About t...
What happened to the internet? It had so much promise. Social media and search results are full of stuff we never wanted to see. Surveillance capitalism is monetizing our most private information to serve us so many ads that we can never seem to consume the actual content. And if we're all so unhappy with the incumbents, where are the competitors offering better service? Cory Doctorow helps us understand how the internet got so crappy and what we can do to fix it.Cory Doctorow is a science fiction author, activist, journalist and blogger at the site Pluralistic. He has written a bunch of great books, both fiction and non, including Little Brother, Red Team Blues and Chokepoint Capitalism.Interview NotesTikTok’s Enshtification: https://pluralistic.net/2023/01/21/potemkin-ai/#hey-guys Cory’s blog: https://pluralistic.net/Cory at DEF CON 31: https://www.youtube.com/watch?v=rimtaSgGz_4 The Internet Con: https://craphound.com/category/internetcon/ Chokepoint Capitalism: https://chokepointcapitalism.com/ Red Team Blues: https://craphound.com/category/novels/redteamblues/ Saving the News from Big Tech: https://www.eff.org/deeplinks/2023/04/saving-news-big-tech Tracking Exposed: https://tracking.exposed/ Further InfoNominate someone for a challenge coin: https://fdsd.me/quest Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:55: Defining some terms0:03:57: Swear warning0:04:25: What have you been up to since we last had you on the show?0:07:58: What is enshtification? How does it work?0:18:26: Have any companies actually completed the enshtification cycle?0:22:36: Do we have concrete examples of interoperability breaking this cycle?0:29:07: What percentage of oday are not what we asked for?0:37:04: What happens to DRM'd content when the licencing company goes away?0:39:19: How can we reverse engineer these algorithms?0:41:04: How is social media promotion like a big carnival teddy bear?0:44:28: Whatever happened to the Amazon Smile program?0:45:58: What do you mean by the End-to-End Principle?0:51:53: Isn't enshtification just a natural result of modern capitalism?0:54:02: Doesn't capitalism require rules (aka regulations)?0:57:18: So what are the solutions? How do we fix the internet?1:02:46: Did we undermine antitrust by lowering the bar of consumer harm?1:04:25: What can we do to help, as consumers and citizens?1:07:06: Wrap-up1:07:50: Looking ahead
Email is old and was never built for security and privacy. Thankfully there are several modern secure email services. My personal favorite is Proton Mail and I'll explain to you today why you should really give it a try. I will also (finally) answer several interesting "Dear Carey" questions from listeners.In other news: If you use WinRAR, you need to update right away; hackers are targeting a company that brokers Emergency Data Requests between law enforcement and Big Tech companies; Google is forced to reveal user search history in a CO court case; Google is making passkeys the default, but you may want to wait; EFF asks MasterCard to stop selling our data; and Bruce Schneier has an insightful article around the rather heated discussions over the benefits and dangers of artificial intelligence.Article Links[Gizmodo] You Need to Update WinRAR, Right Now https://gizmodo.com/you-need-to-update-winrar-right-now-1850939201[404media.co] Hackers Target Company That Vets Police Data Requests for Tech Giants https://www.404media.co/hackers-target-kodex-accounts-edrs/[TechSpot] Google forced to reveal user search history in Colorado court ruling https://www.techspot.com/news/100529-google-forced-reveal-users-search-queries-colorado-court.html[blog.google] Passwordless by default: Make the switch to passkeys https://blog.google/technology/safety-security/passkeys-default-google-accounts/[Electronic Frontier Foundation] Mastercard Should Stop Selling Our Data https://www.eff.org/deeplinks/2023/10/mastercard-should-stop-selling-our-data[Schneier Blog] AI Risks https://www.schneier.com/blog/archives/2023/10/ai-risks.htmlTip of the Week: Try Proton https://firewallsdontstopdragons.com/its-time-to-try-proton/ Further InfoDe-Googling Your Life: https://firewallsdontstopdragons.com/reducing-my-google-footprint/ Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:01:12: News rundown0:02:38: You Need to Update WinRAR, Right Now0:05:10: Hackers Target Company That Vets Police Data Requests for Tech Giants0:11:22: Google forced to reveal user search history in Colorado court ruling0:15:59: Google: Passwordless by default0:21:48: EFF: Mastercard Should Stop Selling Our Data0:25:59: Bruce Schneier: AI Risks0:33:12: Mailbag!!0:42:28: Tip of the Week: Try Proton0:54:25: Wrap up, look ahead
There are several privacy-focused services available today. And the products we use have a dizzying array of privacy and security settings. How do you know which products you need and which vendors you can trust? How do you know which protections you need and which ones you don't? It comes down to understanding your personal threat model. We each have different things to protect and different consequences for failure. Today I'll speak with Andy Yen, CEO and founder of Proton, to help us figure out what we need.Interview NotesProton Sentinel: https://proton.me/blog/sentinel-high-security-program Privacy Decrypted #1: https://proton.me/blog/what-is-a-threat-model?ref=instantsearch Private from Everyone (But Us): https://podcast.firewallsdontstopdragons.com/2022/04/25/private-from-everyone-but-us/Security Planner (threat model tool): https://innovation.consumerreports.org/initiatives/security-planner/ Ars Technica threat model series: https://arstechnica.com/features/2021/10/securing-your-digital-life-part-1/ Further InfoGet your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Table of ContentsUse these timestamps to jump to a particular section of the show.0:01:03: Show preview0:01:44: Delete Act passes0:02:36: What new at Proton since we last spoke?0:07:00: How do you determine your personal threat model?0:09:21: How does Proton decide which threat models to address?0:13:40: How do you learn about all the possible security settings?0:15:37: How do you know which companies and products you can trust?0:18:11: How should VC money and buyouts affect our trust?0:22:30: What should tech reviewers be focusing on with privacy products?0:26:24: How important is a company's location for privacy?0:28:47: Are technological solutions sufficient to protect our data?0:30:22: Has Proton received any pressure from governments to weaken privacy?0:33:27: Does Proton actively market to government officials?0:34:43: How can larger companies protect against insider threats?0:37:05: What's your take on the LastPass breach?0:41:32: What is Proton Sentinel and who is it for?0:46:09: Will Sentinel be able to scale?0:47:31: Proton asks Sentinel users for personal information - is that safe?0:51:04: Can you share any specific Sentinel success stories?0:53:39: What other features would you like to add to Proton?0:58:30: Wrap-up1:00:11: Look ahead
October is national Cybersecurity Awareness Month here in the US. One of the four key themes this year is Recognizing and Reporting Phishing. We just discussed this at length with Nick Oles, but I wanted to give my perspective and tell you how to report phishing emails to the proper authorities.In other news: cheap Android TV boxes come laced with malware and fraud software; 23andMe investigating massive data breach; US agencies caught using location data illegally; Meta proposes subscription plans in Europe for Facebook and Instagram; FBI warns of 'phantom hacker' scams targeting elderly; new Microsoft AI tool can simulate any voice with just 3 seconds of audio; attackers don't bother brute-forcing long passwords; free upgrade from Windows 7/8 to 10 is going away soon; FCC details plans to reinstate net neutrality; how to turn off Google's new Topics tracking system; new app from Consumer Reports to delete personal data; new privacy-respecting URL shortening tool from Panquake.Article Links[WIRED] Your Cheap Android TV Streaming Box May Have a Dangerous Backdoor https://www.wired.com/story/android-tv-streaming-boxes-china-backdoor/[cyberscoop.com] DNA testing service 23andMe investigating theft of user data https://cyberscoop.com/23andme-user-data-theft/[404media.co] ICE, CBP, Secret Service All Illegally Used Smartphone Location Data https://www.404media.co/ice-cbp-secret-service-all-broke-law-with-smartphone-location-data/[9to5mac.com] Meta proposing ad-free Facebook and Instagram plans for up to $17/month https://9to5mac.com/2023/10/03/facebook-instagram-no-ads-plan/[BleepingComputer] FBI warns of surge in 'phantom hacker' scams impacting elderly https://www.bleepingcomputer.com/news/security/fbi-warns-of-surge-in-phantom-hacker-scams-impacting-elderly/[futurism.com] New Microsoft AI Can Clone Your Voice From Three Seconds of Audio https://futurism.com/the-byte/new-microsoft-ai-clone-your-voice[therecord.media] Attackers don’t bother brute-forcing long passwords, Microsoft engineer says https://therecord.media/attackers-dont-bother-brute-forcing-long-passwords-microsoft-engineer-says/[TechRadar] Been putting off that free Windows 11 or 10 upgrade? Windows 7 and 8 diehards need to move fast https://www.techradar.com/computing/windows/been-putting-off-that-free-windows-11-or-10-upgrade-windows-7-and-8-diehards-need-to-move-fast[Ars Technica] FCC details plan to restore the net neutrality rules repealed by Ajit Pai https://arstechnica.com/tech-policy/2023/09/fcc-details-plan-to-restore-the-net-neutrality-rules-repealed-by-ajit-pai/[Electronic Frontier Foundation] How To Turn Off Google’s “Privacy Sandbox” Ad Tracking—and Why You Should https://www.eff.org/deeplinks/2023/09/how-turn-googles-privacy-sandbox-ad-tracking-and-why-you-should[CNET] This App Can Delete Your Personal History from Websites. And It's Simple https://www.cnet.com/tech/services-and-software/this-app-can-delete-your-personal-history-from-websites-and-its-simple-heres-how-to-use/[talkliberation.substack.com] NOW SERVING: An early release of the Panquake Pie! https://talkliberation.substack.com/p/panquake-early-release-pnqk-now-availableTip of the Week: Catching Phish: https://firewallsdontstopdragons.com/how-to-catch-a-phish/ Further InfoWin a copy of “How to Catch a Phish”! https://fdsd.me/catchaphish National Cybersecurity Awareness Month: https://www.cisa.gov/cybersecurity-awareness-month Microsoft’s VALL-E voice-gen tool: https://www.microsoft.com/en-us/research/project/vall-e-x/ Panquake URL shortener: https://pnqk.me/ Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Generate secure passphrases! https://d20key.
The weakest link in most cybersecurity systems is you - that is, human beings. And one of the primary ways that people are tricked into infecting their devices (and potentially then threatening other devices on the network) is through phishing. We've all seen the Nigerian Prince scams, but with AI tools like ChatGPT, scam emails are going to get a lot harder to spot. On today's show, author and cybersecurity expert Nick Oles will teach us how to recognize phishing emails, introduce us to tools for detecting and protecting against phishing, and detail other techniques for defending against these sorts of attacks. All of this is just a taste of the top notch advice contained in his new book, "How to Catch a Phish".Interview NotesHow to Catch a Phish: https://www.amazon.com/How-Catch-Phish-Practical-Detecting/dp/1484293606 Win a free copy!! https://fdsd.me/catchaphish Nick Oles on LinkedIn: https://www.linkedin.com/in/nick-o-8b5b6349/ National Cybersecurity Awareness Month: https://www.cisa.gov/cybersecurity-awareness-month Virustotal URL scanner: https://www.virustotal.com/gui/home/url URLscan.io: https://urlscan.io/SANS PICERL Incident Response model (PDF): https://www.sans.org/media/score/504-incident-response-cycle.pdf Malwarebytes personal: https://www.malwarebytes.com/getprotection Further InfoNominate someone for a challenge coin: https://fdsd.me/quest Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:45: Patron book club update0:02:11: Nat'l Cybersecurity Awareness Month0:02:48: What drove you to write the book?0:06:57: What really happens behind the scenes when I send an email?0:13:37: What are email headers and why would I want to look at them?0:17:13: How are email senders spoofed and can we prevent this?0:23:35: Do email clients have indicators for vetted senders?0:25:40: What is phishing and how can we recognize it?0:32:06: How has phishing evolved over the years?0:37:01: What are spearphishing and business email compromise?0:40:24: Do spam filters help at all with phishing emails?0:42:50: How do I know if I can trust any link or URL in an email?0:48:34: Are web email clients safer than dedicated email apps?0:51:35: How can we know which email attachments are safe to open?0:54:48: If I accidentally click a bad link or attachment, what then?0:59:11: How will AI impact phishing campaigns?1:01:13: Are things getting better or getting worse?1:04:08: Interview wrap-up1:07:44: Book giveaway details
Apple has just released a major update to its mobile operating system: iOS 17. There are tons of fun new features, but today I'll walk you through some of the security and privacy enhancements. These include new protections in Lockdown Mode, the Check In feature which can alert loves ones if you fail to arrive at your destination, some privacy-enhancing web browser features, and support for securely sharing passwords and passkeys with others.In other news: a critical WebP vulnerability means we have to update most of our apps and devices; credit bureaus in the US now allow free weekly access to your credit reports; Proton announces a new, privacy-focused CAPTCHA service; the FTC puts data brokers on notice; LastPass is requiring their users to make their master passwords longer; password managers are still your best bet for web security, despite the LastPass debacle; Hyundai Pay seeks to make in-car payments a thing; and an interesting article from a privacy advocate claiming that privacy tools are too difficult to use.Article Links[MakeUseOf] Update Everything: This Critical WebP Vulnerability Affects Major Browsers and Apps https://www.makeuseof.com/critical-webp-vulnerability-affects-major-browsers-apps/[Consumer Reports] Credit Bureaus Equifax, Experian, and TransUnion Announce Permanent, Free Weekly Access to Credit Reports https://www.consumerreports.org/money/credit-scores-reports/credit-bureaus-permanent-free-weekly-credit-report-access-a2226546788/[proton.me] Introducing Proton CAPTCHA https://proton.me/blog/proton-captcha[The Washington Post] FTC consumer protection chief puts data brokers on notice https://www.washingtonpost.com/politics/2023/09/21/ftc-consumer-protection-chief-puts-data-brokers-notice/[briankrebs] LastPass: ‘Horse Gone Barn Bolted’ is Strong Password https://krebsonsecurity.com/2023/09/lastpass-horse-gone-barn-bolted-is-strong-password/[ZDNet] Why you can still trust (other) password managers, even after that LastPass mess https://www.zdnet.com/article/why-you-can-still-trust-other-password-managers-even-after-that-lastpass-mess/[The Verge] ‘Hyundai Pay’ is the latest effort by car companies to make in-car payments a thing https://www.theverge.com/2023/9/6/23861412/hyundai-pay-parkopedia-in-car-payment[theprivacydad.com] Privacy Tools Are Not Worth the Hassle https://theprivacydad.com/privacy-tools-are-not-worth-the-hassle/[TechCrunch] iOS 17 includes these new security and privacy features https://techcrunch.com/2023/09/18/ios-17-includes-these-new-security-and-privacy-features/Tip of the Week: iOS 17 Security & Privacy: https://firewallsdontstopdragons.com/ios-17-security-privacy/Further InfoSecure Your Home Network article series: https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/ Nominate someone for a challenge coin: https://fdsd.me/quest Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:27: Delete Act update0:00:59: BSides RDU0:01:54: News rundown0:04:20: Critical WebP Vulnerability Affects Major Browsers and Apps0:12:22: Credit Bureaus Announce Permanent, Free Weekly Access to Credit Reports0:17:24: Introducing Proton CAPTCHA0:22:07: FTC consumer protection chief puts data brokers on notice0:26:19: LastPass requiring users to create longer passwords0:32:58: Why you can still trust (non-LastPass) password managers0:43:01: ‘Hyundai Pay’ in-car payments coming0:45:38: "Privacy Tools Are Not Worth the Hassle"0:54:57: Tip of the Week: iOS 17 security & priv...
When the New York Times broke the Clearview AI story in 2020, we suddenly had to face the reality that no one could truly be anonymous in public any more. This powerful app could take a picture of any face and find dozens of public images on the internet that they were in - even just in the background. And if those pictures were associated with a social media profile, we could identify the owner of the face along with their friends and family - all in an instant. Today I speak with Kashmir Hill about her investigation of this company and the sobering impacts of facial recognition technology in a world full of cameras, chronicled in her new book "Your Face Belongs to Us".Interview NotesYour Face Belongs to Us: https://www.kashmirhill.com/book Kashmir Hill facial recognition stories: https://www.kashmirhill.com/stories/face-recognition Clearview AI, delete dead links: https://www.clearview.ai/privacy-and-requests FRT used to track activity in coffee shop: https://www.linkedin.com/posts/endritrestelica_ai-tech-activity-7098293527951851520-Mejy/PimEyes: https://pimeyes.com/ Fawkes masking tool: https://sandlab.cs.uchicago.edu/fawkes/ Further InfoNominate someone for a challenge coin: https://fdsd.me/quest Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:01:37: Tell us about your beat at the New York Times0:02:17: What is the Clearview app and what does it do?0:05:12: How did you come to write about Clearview AI?0:07:40: What happened when you first investigated this company?0:11:46: How did Clearview AI obtain all these images of our faces?0:14:24: Why are privacy advocates calling for a ban on this technology?0:16:36: Do the makers of Clearview appreciate the privacy implications of their tool?0:18:56: How did 9/11 influence our views on surveillance technology?0:22:33: Who has access to the Clearview app?0:24:14: How do we know who is using this tool?0:25:22: How has Clearview tried to win approval for this tool?0:27:37: What's to stop others from copying this technology?0:31:05: Wasn't Clearview used to ban lawyers from venues in NYC?0:33:13: Didn't Illinois sue Clearview AI and win?0:34:09: Where else is facial recognition being used today?0:38:05: How often is FRT used in solving crimes in the US?0:41:26: What about cases where FRT identifies the wrong person?0:43:23: How accurate are these tools? What causes them to fail?0:45:59: How accurate is Clearview compared to other tools?0:47:02: How well does Clearview deal with facial hair, masks, etc?0:50:01: What can we do to protect our faces online?0:52:33: How well can Clearview pick out faces in the background?0:54:41: What's the future of privacy in a world full of cameras?0:56:24: What can we do to rein in abuse of FRT?0:58:00: Wrap up and a look ahead
Today I wrap up my four-part series on how to secure your home network. We've enumerated our devices, gotten rid of stuff we don't need, assessed the state of our devices and now it's time to actually remediate any vulnerabilities we found. I'll walk you through everything you need to do.In other news: Chrome's Topics API has rolled out (and I'll tell you how to shut it off); Apple fixes two zero-day, zero-click exploits; FBI dismantles and even fixes the Qakbot malware network; the UK backs down on requirements to undermine end-to-end encryption; Macs are being targeted with a malvertising campaign; LastPass breach seems to be behind crypto wallet stealing; Apple reveals why it abandoned its CSAM scanning feature; Kias and Hyundais are being stolen left and right and are being sued; new cars are a privacy nightmare; Chrome extensions are able to steal private data from web pages.Article Links[The Verge] How to disable Chrome’s new targeted ad tracking https://www.theverge.com/23860050/chrome-ads-topics-sandbox[citizenlab.ca] NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/[TechCrunch] FBI operation tricked thousands of computers infected by Qakbot into uninstalling the malware https://techcrunch.com/2023/08/29/fbi-operation-qakbot-uninstall/[AppleInsider] UK backs down from nonsensical law after threats from Apple, WhatsApp https://appleinsider.com/articles/23/09/06/uk-backs-down-from-nonsensical-law-after-threats-from-apple-whatsapp[Tom's Guide] Macs under threat from malicious ads spreading malware — don’t fall for this https://www.tomsguide.com/news/macs-under-threat-from-malicious-ads-spreading-malware-dont-fall-for-this[briankrebs] Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach https://krebsonsecurity.com/2023/09/experts-fear-crooks-are-cracking-keys-stolen-in-lastpass-breach/[WIRED] Apple’s Decision to Kill Its CSAM Photo-Scanning Tool Sparks Fresh Controversy https://www.wired.com/story/apple-csam-scanning-heat-initiative-letter/[VICE] Kias and Hyundais Keep Getting Stolen by the Thousands and Cities Are Suing https://www.vice.com/en/article/93kdmp/kias-and-hyundais-keep-getting-stolen-by-the-thousands-and-cities-are-suing[Gizmodo] If You’ve Got a New Car, It’s a Data Privacy Nightmare https://gizmodo.com/mozilla-new-cars-data-privacy-report-1850805416[techxplore.com] Researchers issue warning over Chrome extensions that access private data https://techxplore.com/news/2023-09-issue-chrome-extensions-access-private.htmlTip of the Week: Remediate Your Network: https://firewallsdontstopdragons.com/secure-your-network-4-remediate/Further InfoNominate someone for a challenge coin: https://fdsd.me/quest Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch Give the gift of privacy and security: https://fdsd.me/coupons Send me your questions! https://fdsd.me/qna Support our mission! https://fdsd.me/support Subscribe to the newsletter: https://fdsd.me/newsletter Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/ Table of ContentsUse these timestamps to jump to a particular section of the show.0:00:29: Kashmir Hill interview coming0:01:40: News rundown0:04:32: How to disable Chrome’s new targeted ad tracking0:07:12: NSO Group iPhone Zero-Click, Zero-Day Exploit Captured in the Wild0:10:36: FBI operation dismantles Qakbot botnet0:13:51: UK backs down from nonsensical law after threats from Apple, WhatsApp0:17:10: Macs under threat from malicious ads spreading malware0:23:03: Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach
In the US today we’re dealing with a completely unfettered free-for-all of data harvesting. Without meaningful privacy regulations like the EU’s GDPR, our private information is being collected, collated, packaged and sold by data brokers to all comers. Ad companies like Google and Facebook collect and hoard our data to sell targeted ads for high profits without commensurate benefits to the people placing the ads. How does it all work? What’s our data worth? And how can we protect it? I’ll discuss all of this and more with my guest, Tom Kemp.
Tom Kemp is a Silicon Valley-based entrepreneur, investor, and policy advisor. Tom is also the author of Containing Big Tech: How to Protect Our Civil Rights, Economy, and Democracy.
Interview Notes* Containing Big Tech:: https://www.tomkemp.ai/containing-big-tech * Let’s Make Privacy Easy: https://techpolicy.press/lets-make-privacy-easy/ * LinkedIn panel discussion on AI and privacy regulation in the US: https://www.linkedin.com/events/thestateofusprivacy-airegulatio7087548531820941312/ * SB362 (Delete Act): https://www.darkreading.com/endpoint/why-the-california-delete-act-matters * Tom’s post on SB362: https://www.linkedin.com/posts/tomkemp_sb362-databrokers-privacy-activity-7103448636260302848-Qg6p * Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/
Further Info Nominate someone for a challenge coin: https://fdsd.me/quest * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
In the third part of my series on securing your home network, we’ll assess your security and privacy vulnerabilities. In prior weeks, we’ve exhaustively listed our network devices (Scan) and removed any devices that we no longer need or don’t need to be “smart” (Simplify). Now it’s time to investigate the remaining devices and think about what we need to do to secure them.
In other news: an old Mac malware info stealer is back; thousands of Android apps are evading detection using an interesting technique; Illinois just passed a law allowing doxing victims to sue perpetrators for damages; Meta plans to roll out end-to-end encryption for Messenger by year’s end; LinkedIn accounts are being targeted for takeover; Intel’s GPU driver collects personal info by default; Tesla suffers data breach of 75,000 current and former employees; police are accessing DNA databases even for people who opted out of this access; Pennsylvania court says police been to be transparent about social media monitoring; Kansas newspaper raid by police teaches us how better to encrypt our data; hackers are selling credit report info on just about any American; NSA director tells employees to spy “with dignity and respect”.
Article Links1. [TechRadar] One of the worst Mac malware strains is back and hiding as a productivity app – so beware https://www.techradar.com/pro/security/one-of-the-worst-mac-malware-strains-is-back-and-hiding-as-a-productivity-app-so-beware 2. [Tom’s Guide] Thousands of Android malware apps use stealthy APKs to bypass security, study finds https://www.tomsguide.com/news/thousands-of-android-malware-apps-use-stealthy-apks-to-bypass-security-study-finds 3. [Ars Technica] Illinois just made it possible to sue people for doxxing attacks https://arstechnica.com/tech-policy/2023/08/illinois-just-made-it-possible-to-sue-people-for-doxxing-attacks/ 4. [TechCrunch] Meta plans to roll out default end-to-end encryption for Messenger by the end of the year https://techcrunch.com/2023/08/22/meta-plans-to-roll-out-default-end-to-end-encryption-for-messenger-by-the-end-of-the-year/ 5. [TechRadar] LinkedIn user accounts have been taken over in huge hacking campaign https://www.techradar.com/pro/security/linkedin-user-accounts-have-been-taken-over-in-huge-hacking-campaign 6. [extremetech.com] Intel’s GPU Drivers Now Collect Telemetry https://www.extremetech.com/gaming/intels-gpu-drivers-now-collect-telemetry-including-how-you-use-your-computer 7. [TechCrunch] Tesla says data breach impacting 75,000 employees was an insider job https://techcrunch.com/2023/08/21/tesla-breach-employee-insider/ 8. [BBC] Why US tech giants are threatening to quit the UK https://www.bbc.com/news/technology-66304002 9. [The Intercept] Police Are Getting DNA Data From People Who Think They Opted Out https://theintercept.com/2023/08/18/gedmatch-dna-police-forensic-genetic-genealogy/ 10. [The Associated Press] A Pennsylvania court says state police can’t hide how it monitors social media https://apnews.com/article/pennsylvania-police-aclu-social-media-monitoring-1508189aba86cc776e19892b4a2b358a 11. [freedom.press] What a newsroom police raid teaches us about encrypting our devices https://freedom.press/training/blog/marion-record-police-raid/ 12. [404media.co] The Secret Weapon Hackers Can Use to Dox Nearly Anyone in America for $15 https://www.404media.co/the-secret-weapon-hackers-can-use-to-dox-nearly-anyone-in-america-for-15-tlo-usinfosearch-transunion/ 13. [The Intercept] NSA Orders Employees to Spy on the World “With Dignity and Respect” https://theintercept.com/2023/08/25/nsa-spy-dignity-respect/ 14. Tip of the Week: Securing Your Network 3: Assess: https://firewallsdontstopdragons.com/secure-your-network-3-assess/
Further Info Dragon Challenge Coin promotion: https://fdsd.me/promo823 * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Unless you've been living under a rock, you've seen several news stories about AI, machine learning and so-called Large Language Models. While tools like ChatGPT hold a lot of promise, many are deeply concerned about AI replacing jobs, generating potent malware, and being used in phishing and disinformation campaigns. Today I will ask AI expert Michael Littman to explain clearly what AI is and what it isn't, how the technology actually works, and what we should and maybe shouldn't be worried about.
Michael Littman is a computer science professor at Brown University who has won several prestigious teaching awards while studying machine learning and the implications of artificial intelligence. He serves as division director for Information and Intelligent Systems at the National Science Foundation and is also a Fellow of the Association for the Advancement of Artificial Intelligence and the Association for Computing Machinery.
Interview Notes
Gathering Strength, Gathering Storms: The One Hundred Year Study on Artificial Intelligence https://ai100.stanford.edu/gathering-strength-gathering-storms-one-hundred-year-study-artificial-intelligence-ai100-2021-study
Code to Joy book preorder: https://www.amazon.com/Code-Joy-Everyone-Should-Programming/dp/0262546396/
Michael Littman’s website: https://www.littmania.com/
Gandalf AI challenge: https://gandalf.lakera.ai/
ChatGPT: https://openai.com/blog/chatgpt
Stable Diffusion: https://stability.ai/stablediffusion
Canva Image Generator online: https://www.canva.com/ai-image-generator/
Paperclip Maximizer: https://en.wikipedia.org/wiki/Instrumental_convergence#Paperclip_maximizer
Further Info
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:56: Dragon coin promo update
0:01:51: Interview preview
0:03:15: What is Artificial Intelligence, really?
0:05:36: Is it a mistake to anthropomorphize AI?
0:08:50: What is AI versus machine learning?
0:11:59: How does AI differ from normal computer code?
0:14:49: What is a large language model or LLM?
0:18:45: What does it take to create an LLM?
0:22:04: Why are these AI models limited to certain points in time?
0:26:46: How are these chat bots leading people to believe they're sentient?
0:28:54: What was behind the AI explosion in late 2022?
0:32:29: How to AI systems generate images from text prompts?
0:35:36: How are AI systems affected by their training data?
0:40:24: Which concerns about AI are justified and which are overblown?
0:44:55: What sorts of jobs may be impacted by AI?
0:47:15: Is there an art to creating AI prompts?
0:48:43: Can you trick AI systems?
0:51:42: How do we detect AI output? How should we restrict this technology?
0:56:19: How can we try out these AI systems to learn more?
0:59:26: What's the next big thing in AI?
1:02:12: Why should people learn to do a little coding?
1:05:27: Wrap-up
1:07:01: Gandalf AI game
1:08:19: Upcoming interviews
Every summer, hackers from around the US and around the globe descend on Las Vegas, Nevada, for a series of computer security conferences which are lovingly referred to as hacker summer camp. These conferences - BSides Las Vegas, BlackHat and DEF CON - run for over a week, each overlapping the other. They bring top tier security researchers, government and industry leaders, and eager hackers to learn about new vulnerabilities, new defense mechanisms, and everything in between. There are contests and parties galore, allowing hackers to test their skills and network with others. Today I'll tell you about my trip to BSides and DEF CON in 2023.
Article Links
[securityweek.com] Downfall: New Intel CPU Attack Exposing Sensitive Information https://www.securityweek.com/downfall-new-intel-cpu-attack-exposing-sensitive-information/
[9to5mac.com] Mac malware can easily bypass Apple’s Background Task Manager, says security researcher https://9to5mac.com/2023/08/14/mac-malware-background-task-manager/
[whitehouse.gov] Biden-Harris Administration Launches Artificial Intelligence Cyber Challenge to Protect America’s Critical Software https://www.whitehouse.gov/briefing-room/statements-releases/2023/08/09/biden-harris-administration-launches-artificial-intelligence-cyber-challenge-to-protect-americas-critical-software/
Donate to Maui wildfire relief fund: https://www.gofundme.com/f/5auw5q-maui-wildfire-relief-fund
Veilid project (cDc): https://veilid.com/
Back Orifice: https://en.wikipedia.org/wiki/Back_Orifice
Namecheck from Steve Gibson: https://youtu.be/hGyVuszu0F8?t=6240
CalyxOS mention: https://en.wikipedia.org/wiki/CalyxOS
Tom Kemp on LinkedIn Live: https://www.tomkemp.ai/blog/2023/7/19/live-event-the-state-of-us-privacy-and-ai-regulation
Further Info
Dragon Challenge Coin promotion: https://fdsd.me/promo823
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:04: Preview
0:01:27: Look ma, I'm on Wikipedia!
0:02:16: Steve Gibson reads FDSD
0:03:16: Show overview
0:04:29: What is Hacker Summer Camp?
0:06:21: Using Lockdown Mode on Apple
0:07:20: BSides Las Vegas 2023, Josh Corman, et al
0:08:28: BSides pool party
0:09:44: I skipped out on linecon
0:11:36: I skipped the merch line, too
0:12:36: Darknet Diaries meets FDSD
0:13:13: r00t party!
0:15:14: cDc announces Veilid platform
0:18:48: Voting Village, brush with Chris Krebs
0:20:34: Interview with Nick Oles
0:22:49: Meet Joe Gray ("Practical Social Engineering" author)
0:23:22: cDc Veilid launch party
0:24:19: Checking in the the Hack-a-Sat team
0:38:00: EFF Tech Trivia
0:38:37: Hacker Jeopardy
0:40:11: Evacuation of Caesar's Forum
0:41:50: Closing ceremonies
0:42:48: No swag or amulet sightings
0:43:31: Downfall: New Intel CPU Attack Exposing Sensitive Information
0:47:24: Mac malware can easily bypass Apple’s Background Task Manager
0:52:22: Maui wildfire relief fund
0:53:01: DARPA Launches AI Cyber Challenge
0:54:07: Looking ahead
0:55:28: Dragon coin promotion is ending soon
In the early 1980s, personal computers started entering our homes. Prior to the internet and services like America On Line (AOL), there were online bulletin board systems (BBS) where people could share text files via phone modem connections. Of course, if you wanted to connect to a BBS outside your home area code, you would have to dial long distance - which at the time could be prohibitively expensive. Necessity is the mother of invention and it's no coincidence that some of the earliest hacking was of the phone system to get free long distance calls. One of the first named groups of hackers was The Cult of the Dead Cow (aka, cDc). Today I'll reminisce about the old days with two prominent members of cDc: Deth Veggie and Omega. We'll talk about what it was like in the days prior to the internet, how hackers think, and how hacking has evolved over the years. We'll talk about how cDc pioneered the hactivist movement and how their group overlapped and interacted with other famous groups like L0pht Heavy Industries, Masters of Deception (MOD), Legion of Doom (LOD) and much, much more.
Interview Notes
The Cult of the Dead Cow: https://cultdeadcow.com/
"The Cult of the Dead Cow" book: https://www.hachettebookgroup.com/titles/joseph-menn/cult-of-the-dead-cow/9781549169991/
cDc text files: http://textfiles.com/groups/CDC/
The Hacker’s Manifesto: http://phrack.org/issues/7/3.html
Hactivismo Declaration: https://web.archive.org/web/20090502054355/http://www.cultdeadcow.com/cDc_files/declaration.html
cDc’s unofficial suggested reading/viewing list: https://fdsd.me/cdclist
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:43: Interview prep
0:03:51: How did cDc start and where did it get its name?
0:08:11: How did you get involved with cDc?
0:11:15: What is a BBS? What are textfiles?
0:15:36: What sort of information did these textfiles contain?
0:23:46: What really happened in the Hacker Wars?
0:25:28: How did phone phreaking work?
0:29:43: How did you choose your handle? When did you first use it in public?
0:37:47: Two things War Games got right
0:38:38: Blue boxes and red boxes
0:40:26: What did your friends & family think? How have perceptions of hackers changed?
0:45:16: What is hacktivism? What sort of hactivist behavior is acceptable?
0:51:58: What are some examples of hactivism?
0:55:19: What are some signs that I might enjoy hacking?
1:01:49: Hacking in the real world, questioning everything.
1:04:38: Books and movies with accurate portrayals of hackers & hacking?
1:11:14: Interview wrap-up
1:12:46: Patron bonus material & promo
1:16:04: Next week's show may be delayed
Last time, I told you how to enumerate all the devices on your home network. Before we go to the trouble of analyzing and mitigating their vulnerabilities, we should take the opportunity to cull the inventory. Do you really need all of these devices? Or could you forego the "smart" features that require them to be connected to your network? Today we'll talk about reducing your attack surface before we bother trying to secure it.
In other news: the White House announces new cybersecurity labeling program; the SEC mandates a 4-day reporting window for cyber attacks; EFF opposes a bill that threatens our privacy; stolen Microsoft signing keys behind a set of targeted US government email hacks; more details emerge about Facebook mining Onano VPN for user data; TETRA radios used for decades revealed to have deliberately weakened encryption; ALPR data now being used with AI algorithms to guess which cars might contain criminals; Apple threatens to pull Facetime, Messages from UK over proposed surveillance law changes; Google's Web Integrity API causes a stir; Apple to require justification for use of some APIs that might compromise user privacy.
Article Links
[whitehouse.gov] Biden-Harris Administration Announces Cybersecurity Labeling Program for Smart Devices to Protect American Consumers https://www.whitehouse.gov/briefing-room/statements-releases/2023/07/18/biden-harris-administration-announces-cybersecurity-labeling-program-for-smart-devices-to-protect-american-consumers/
[The Hacker News] New SEC Rules Require U.S. Companies to Reveal Cyber Attacks Within 4 Days https://thehackernews.com/2023/07/new-sec-rules-require-us-companies-to.html
[Electronic Frontier Foundation] Amended Cooper Davis Act Is a Direct Threat to Encryption https://www.eff.org/deeplinks/2023/07/amended-cooper-davis-act-direct-threat-encryption
[TechCrunch] Microsoft lost its keys, and the government got hacked https://techcrunch.com/2023/07/17/microsoft-lost-keys-government-hacked/
[Financial Review] Facebook admits it used app to ‘know nearly everything’ about users https://www.afr.com/companies/media-and-marketing/facebook-admits-it-used-app-to-know-nearly-everything-about-users-20230713-p5do2a
[WIRED] Code Kept Secret for Years Reveals Its Flaw—a Backdoor https://www.wired.com/story/tetra-radio-encryption-backdoor/
[Forbes] This AI Watches Millions Of Cars Daily And Tells Cops If You’re Driving Like A Criminal https://www.forbes.com/sites/thomasbrewster/2023/07/17/license-plate-reader-ai-criminal/
[MacRumors] Apple Threatens to Pull FaceTime and iMessage in the UK Over Proposed Surveillance Law Changes https://www.macrumors.com/2023/07/20/apple-threatens-to-pull-facetime-and-imessage-uk/
[Ars Technica] Google’s nightmare “Web Integrity API” wants a DRM gatekeeper for the web https://arstechnica.com/gadgets/2023/07/googles-web-integrity-api-sounds-like-drm-for-the-web/
[MacRumors] Apple Developers Required to Justify Use of Some APIs in Latest Move to Boost Privacy https://www.macrumors.com/2023/07/28/developers-required-to-justify-api-use/
Tip of the Week: Less is More: https://firewallsdontstopdragons.com/secure-your-network-2-simplify/
Further Info
Stop the bad bills: https://www.eff.org/deeplinks/2023/07/you-can-help-stop-these-bad-internet-bills
Dragon Challenge Coin Promo! https://fdsd.me/promo823
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Table of Contents
Add time-based list of markers.
Despite growing demand from US citizens for privacy protections, the federal government has failed repeatedly to enact basic privacy laws. However, one US state - California - has led the charge on privacy and passed regulations that have benefited people outside the state. Today I'll speak with Ernesto Falcon who is currently running for California State Senate in District 7. He has decades of experience in public policy, particularly in the realm of privacy rights, both in politics and with the Electronic Frontier Foundation. We'll talk about how the legislative sausage is made, why we can't seem to pass privacy regulations, how lobbyists influence policy, and much more.
Disclaimer: Views, opinions, or statements expressed are solely those of the candidate and not of his employer at the Electronic Frontier Foundation.
Interview Notes
Ernesto Falcon’s campaign website: https://www.ernestofalcon.com/
California Consumer Privacy Act: https://en.wikipedia.org/wiki/California_Consumer_Privacy_Act
California Privacy Rights Act: https://en.wikipedia.org/wiki/California_Privacy_Rights_Act
Further Info
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:16: Interview prep
0:02:40: Tell us about your CA Senate campaign
0:10:56: How have CA privacy laws impacted the greater US?
0:15:45: How do we regain control over our data?
0:17:59: What is preventing a good federal privacy law?
0:24:36: What are the dangers of all this personal data being hoarded?
0:31:01: How does HIPAA actually work? What doesn't it cover?
0:33:01: What is the EARN IT Act and why does EFF oppose it?
0:37:58: How do child safety laws undermine privacy?
0:40:41: How are legal wire taps different from backdoors in encryption?
0:43:10: Won't repressive regimes abuse encryption backdoors?
0:44:45: Is on-device scanning a valid compromise solution?
0:47:07: Will we ever win the Crypto Wars?
0:48:59: How can we best support the privacy cause?
0:52:00: Would more privacy transparency be a good first step?
0:54:35: Are monopolies part of the problem here?
0:58:53: What's next for you and your senate campaign?
1:00:42: Post interview wrap-up
1:01:46: Go talk to your representative!
1:02:55: Dragon Challenge Coin Promotion!
The Internet of Things (IoT) has added internet connections to lots of home devices. Each and every one of those devices runs software on a computer chip. Almost all software has bugs and those bugs may be exploitable by bad guys. We're going to take another look at protecting our home networks using a simple, logical methodology. Step one: SCAN. That is, first of all, we need to understand the scope of the problem by enumerating all of the devices on your home network. I'll explain how to do that.
In other news: Apple re-releases security update after web glitch; EV chargers are vulnerable to hacking which could have significant impacts; tax prep firms shared 'extraordinarily sensitive' data with Meta; Meta's new Threads service collects tons of personal info and employs dark patterns to hook you in; France passes law giving law enforcement access to private device cameras, mics and locations; police are collecting and selling personal info, bypassing the 4th Amendment and sharing across state lines; Massachusetts weighs outright ban on selling user location data; printers and printing services may be mining your documents for data.
Article Links
[MacRumors] Apple Releases Revised iOS and macOS Security Updates to Fix Actively Exploited Vulnerability and Safari Bug https://www.macrumors.com/2023/07/12/apple-releases-revised-security-updates/
[WIRED] EV Charger Hacking Poses a ‘Catastrophic’ Risk https://www.wired.com/story/electric-vehicle-charging-station-hacks/
[The Associated Press] 3 tax prep firms shared ‘extraordinarily sensitive’ data about taxpayers with Meta, lawmakers say https://apnews.com/article/irs-taxpayer-tax-preparation-meta-congress-9315cfca7a0942ab89f765d183fbf822
[Ars Technica] How Threads’ privacy policy compares to Twitter’s (and its rivals’) https://arstechnica.com/security/2023/07/how-threads-privacy-policy-compares-to-twitters-and-its-rivals/
[Yanko Design] The ‘Threads’ App is FILLED With Deceptive Dark Design Patterns – We Spotted More Than TEN https://www.yankodesign.com/2023/07/07/the-threads-app-is-filled-with-deceptive-dark-design-patterns-we-spotted-more-than-ten/
[Gizmodo] France Passes New Bill Allowing Police to Remotely Activate Cameras on Citizens' Phones https://gizmodo.com/france-bill-allows-police-access-phones-camera-gps-1850609772
[Tampa Bay Times] Hillsborough, Clearwater police monitoring private security cameras https://www.tampabay.com/news/hillsborough/2023/07/10/hillsborough-clearwater-police-monitoring-private-security-cameras/
[New York Daily News] NYPD seeks to grab cell phone IDs from people under arrest or in custody; push for IMEI numbers raises concerns https://www.nydailynews.com/new-york/nyc-crime/ny-nypd-campaign-cellphone-idenfiication-numbers-controversy-20230708-yltabdlozfbppeoodxymyub3zq-story.html
[The Sacramento Bee] California cops illegally share data with anti-abortion states https://www.sacbee.com/news/politics-government/capitol-alert/article275795726.html
[Engadget] Massachusetts weighs outright ban on selling user location data https://www.engadget.com/massachusetts-weighs-outright-ban-on-selling-user-location-data-191637974.html
[The Washington Post] Your printing service might read your documents. Here’s what to know. https://www.washingtonpost.com/technology/2023/07/10/printing-privacy-security-printed-documents/
Tip of the Week: IoT Inventory https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/
Further Info
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about sec...
After lengthy negotiations and revisions, the White House has finally released its National Cybersecurity Strategy document, outlining it's priorities and goals. It's a wide-ranging and ambitious document consisting of five major areas of focus, or "pillars". What's new here? What will it mean for businesses and critical infrastructure? And what does this mean for you and I? Today I'll cover all of that and more with Josh Corman from I Am the Cavalry and formerly with the US Cybersecurity and Infrastructure Security Agency (CISA).
Interview Notes
National Security Strategy doc: https://www.whitehouse.gov/wp-content/uploads/2023/03/National-Cybersecurity-Strategy-2023.pdf
Consequential Cybersecurity: https://claroty.com/blog/consequential-cybersecurity-brace-yourself-for-the-white-house-national-cybersecurity-strategy
PPD-21: https://obamawhitehouse.archives.gov/the-press-office/2013/02/12/presidential-policy-directive-critical-infrastructure-security-and-resil
Known Exploited Vulnerabilities catalog : https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Swimming with Sharks TED talk: https://www.youtube.com/watch?v=rZ6xoAtdF3o
I Am the Cavalry: https://iamthecavalry.org/
CISA Secure by Design: https://www.cisa.gov/securebydesign
Further Info
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:55: Interview setup
0:04:00: What is this strategy document, at a high level?
0:14:02: What are some of the more important or novels aspects?
0:18:05: Do agencies have the budget and authority to implement these strategies?
0:22:11: Will having a gov't backstop actually encourage attacks or discourage preparation?
0:30:40: Should the gov't actively scan US firms/orgs for vulnerabilities?
0:36:56: What should we do about the marketplace for zero-day hacks?
0:39:52: How aggressive should the US be against hackers?
0:41:03: What is NOT addressed by this strategy?
0:45:55: How should be manage our dependencies on foreign software and hardware?
0:52:59: What can everyday people take away from these strategies?
0:59:50: Has this document already had impacts? How do we monitor progress?
1:03:56: Interview wrap-up
1:07:40: Looking ahead
You're using a password manager. You're even using two-factor authentication. Great! When done properly, this will keep the bad guys out. Unfortunately, if you're not careful, it may also keep you out. If you forget your master password or lose access to your 2FA device, you'll be in real trouble... unless you have an access backup plan. This same plan can also help your spouse or next of kin to access your accounts should you die or become incapacitated.
In the news: CISA issues a DDoS warning after multiple attacks; LetMeSpy stalkerware maker suffers a data breach of collected data; researchers use LED power light flicker to break cryptographic keys; Australian PM recommends citizens to power cycle their phones once a day; several artists boycott venues that use facial recognition; Brave browser introduces new localhost access permission; Proton unveils new password manager; Dear Carey questioner asks about PDF readers.
Article Links
[BleepingComputer] CISA issues DDoS warning after attacks hit multiple US orgs https://www.bleepingcomputer.com/news/security/cisa-issues-ddos-warning-after-attacks-hit-multiple-us-orgs/
[TechCrunch] LetMeSpy, a phone tracking app spying on thousands, says it was hacked https://techcrunch.com/2023/06/27/letmespy-hacked-spyware-thousands/
[The Hacker News] Researchers Find Way to Recover Cryptographic Keys by Analyzing LED Flickers https://thehackernews.com/2023/06/researchers-find-way-to-recover.html
[9to5mac.com] Why tips like ‘turn off your iPhone for five minutes’ don’t actually help users https://9to5mac.com/2023/06/26/turn-off-your-iphone-for-5-minutes-advice/
[Rolling Stone] Tom Morello, Zack de la Rocha, and Boots Riley Boycotting Venues That Use Face-Scanning Technology https://www.rollingstone.com/music/music-features/tom-morello-zack-de-la-rocha-facial-recognition-concerts-boycott-1234775909/
[BleepingComputer] Brave Browser boosts privacy with new local resources restrictions https://www.bleepingcomputer.com/news/security/brave-browser-boosts-privacy-with-new-local-resources-restrictions/
[9to5mac.com] Proton Pass end-to-end encrypted password manager is here and free for everyone https://9to5mac.com/2023/06/28/proton-pass-encrypted-password-manager-free/
Tip of the Week - Access Backup Plan: https://firewallsdontstopdragons.com/craft-your-access-backup-plan/
Further Info
Saving your Apple Photo Stream pics: https://support.apple.com/en-us/HT210705
Securityzed podcast: https://www.securityzed.com/podcast-test/securityzed-ltfyn-7xm5l-b8c8s-km25d-jbagp-6k9d4-39cr9-z5nhw-w4jwm
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:00: Photo Stream, Securityzed podcast
0:03:21: News rundown
0:05:10: CISA issues DDoS warning after attacks hit multiple US orgs
0:09:29: LetMeSpy stalkerware maker says it was hacked
0:16:43: Researchers Recover Crypto Keys from LED Flickers
0:24:07: Turn your iPhone off every day for 5 mins?
0:29:39: Artists boycotting venues that Use Face-Scanning Technology
0:34:02: Brave Browser boosts privacy with localhost restrictions
0:41:28: Proton debuts new password manager
0:45:56: Dear Carey question
0:50:05: Tip of the Week
1:00:32: Wrap-up
Right now there are thousands of satellites orbiting above our heads performing crucial tasks. At the end of the day, they're just computers running software - albeit at thousands of miles up and thousands of miles per hour. Can they be hacked? What are the dangers? Aaron Myrick and the Hack-A-Sat team are trying to answer those questions. And they're doing it by launching an actual satellite into low earth orbit for this year's DEF CON hacking contest and asking talented hackers from around the world to take their best shot.
Interview Notes
Moonlighter Fact Sheet: https://aerospace.org/fact-sheet/moonlighter-fact-sheet
Hack-A-Sat 4: https://hackasat.com/moonlighter/
Hack-A-Sat GitHub resources: https://github.com/deptofdefense/hack-a-sat-library
Space-Track.org: https://www.space-track.org/
Moonlighter launch: https://vimeo.com/833432259/4ba9b0927b
Further Info
Amulet of Entropy (DEF CON badge): https://amuletofentropy.com/
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:36: Update Apple devices, ASUS routers
0:01:03: Misc updates
0:03:08: Interview setup
0:04:19: What is Aerospace Corp and what do you do there?
0:08:25: What are things satellites do that we might not think about?
0:13:42: Break down some key stats on satellites for us.
0:17:27: How might we be affected by loss of satellites?
0:21:31: How do you hack an orbiting satellite, logistically?
0:24:38: What sorts of attacks are we worried about?
0:26:58: How do we debug problems in orbiting satellites?
0:30:55: How is hacking a satellite different from a computer?
0:35:23: What happens to old satellites?
0:41:26: What is the Hack-A-Sat program about?
0:43:35: How did the target systems work, prior to this year?
0:46:39: What have we learned so far from past contests?
0:51:24: What's new with Hack-a-Sat 4?
0:52:43: When and how will Moonlighter launch?
0:58:30: What kinds of things can I hack on Moonlighter?
1:00:43: What's the future for Hack-a-Sat?
1:03:26: Wrap-up
I launched my mission to improve people’s privacy and security almost ten years ago now. It’s been quite a journey and I’ve learned a lot in that time. One thing I’ve realized is that there’s only so much I can do on my own. And so I’ve encouraged the more technically savvy members of my audience to help others where they can. One downside to being a podcaster is that I don’t have much insight into the effectiveness of my exhortations. I have no idea how many people are going forth to do good deeds nor what those deeds are. So today I'm launching a new campaign to solicit stirring stories of good deeds and every quarter or so I will select the most inspiring deed-doers and reward them with one of my dragon challenge coins!
In the news: Clop ransomware gang lists first victims of MOVEit supply chain hacks; firmware bug in Gigabyte motherboards has a fix now; US Congress and intelligence agencies debate reform for mass surveillance program; tissue and fluid samples are being abused by law enforcement for DNA scans; check washing scams are on the rise; how to avoid being scammed by virtual kidnapping schemes; 1Password announces beta support for browser passkey extension; bold new plan for 311 cyber support line.
Article Links
[TechCrunch] Ransomware gang lists first victims of MOVEit mass-hacks, including US banks and universities https://techcrunch.com/2023/06/15/moveit-clop-mass-hacks-banks-universities/
[restoreprivacy.com] Hackers Stole Millions of Driver’s Licenses and IDs from U.S. States https://restoreprivacy.com/hackers-stole-millions-of-drivers-licenses-and-ids-from-u-s-states/
[Tom's Hardware] Firmware Backdoor Discovered in Gigabyte Motherboards, 250+ Models Affected https://www.tomshardware.com/news/gigabyte-motherboards-come-with-a-firmware-backdoor
[cyberscoop.com] Congress and intelligence officials spar over surveillance reforms https://cyberscoop.com/congress-fbi-section-702/
Senate hearing: https://www.judiciary.senate.gov/oversight-of-section-702-of-the-foreign-intelligence-surveillance-act-and-related-surveillance-authorities
[aclu.org] Donated Blood or an Organ? Police Shouldn’t Have Easy Access to Your DNA https://www.aclu.org/news/privacy-technology/donated-blood-or-an-organ-police-shouldnt-have-easy-access-to-your-dna
[Lifehacker] Why You Should Stop Sending Checks in the Mail, Especially Now https://lifehacker.com/why-you-should-stop-sending-checks-in-the-mail-especia-1850543113
[connectsafely.org] Quick-Guide to Virtual Kidnapping Scams https://connectsafely.org/virtualkidnapping/
[9to5mac.com] 1Password passkey support for the web launches in public beta on the Mac https://9to5mac.com/2023/06/06/1password-passkey-browser-extension/
[WIRED] The Bold Plan to Create Cyber 311 Hotlines https://www.wired.com/story/ut-austin-cybersecurity-clinic-311/
Tip of the Week: Go Forth, Do Good Deeds: https://fdsd.me/quest
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:47: News preview
0:03:01: Clop Ransomware hits several public and privacy organizations
0:11:32: Firmware Backdoor Discovered in Gigabyte Motherboards
0:17:04: Congress and intelligence officials spar over surveillance reforms
0:24:13: Police Shouldn’t Have Easy Access to Your DNA
0:28:03: Why You Should Stop Sending Checks in the Mail
0:31:43: Quick-Guide to Virtual Kidnapping Scams
At some point, when you care enough about a particular cause, you shift from following the issue to actually trying to advance the issue - to make a difference. The easiest way to do this is to find groups that are already working for this cause and supporting them with donations of your time and/or money. But what do you do if you can't find such a group, or maybe there's no local chapter? Well, you can start your own! It's not as hard as it sounds - and in fact, there exist organizations that can help you. Today I'll speak with Rory Mir from the Electronic Frontier Alliance along with leaders from two successful EFA-affiliated groups: Freddy Martinez from Lucy Parsons Labs and Chris Bushick from PDX Privacy.
Interview Notes
Reach out to EFF organizing team: organizing@eff.org
Electronic Frontier Alliance (EFA): https://www.eff.org/efa
Meetup groups: https://meetup.com
Lucy Parsons Labs: https://lucyparsonslabs.com/
PDX Privacy: https://www.pdxprivacy.org/
EFF on the EARN IT Act: https://www.eff.org/deeplinks/2023/05/dangerous-earn-it-bill-advances-out-committee-several-senators-offer-objections
Further Info
Dragon Coins! https://fdsd.me/coin2
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
0:00:25: Interview setup
0:04:32: Introductions and overview of EFA
0:09:12: Lucy Parsons Project overview
0:10:52: PDX Privacy overview
0:12:28: How has the EFA helped you with your projects?
0:15:33: What other types of groups work with the EFA?
0:17:49: What did you do before? What was it like starting your group?
0:23:02: How can you go about finding sources of funding?
0:25:25: What sorts of grants are available?
0:30:09: What accomplishments are you most proud of?
0:34:48: What were some of your biggest challenges?
0:38:51: Do you ever feel like you're David versus Goliath?
0:42:26: How can I find existing groups that I can support or join?
0:45:58: What's the first step in starting my own group?
0:49:31: If you were starting over again, what would you have done differently?
0:49:56: Do I need to incorporate or create a legal entity?
0:53:02: Can a non-profit organization make money?
0:57:32: Any parting thoughts you'd like to share?
1:00:32: Wrap-up
1:03:11: Looking ahead
1:04:09: Upcoming challenge coin campaign
Two weeks ago, I told you about the availability of two new top-level domains that also happen to be popular file name extensions: .zip and .mov. The ambiguity will undoubtedly be exploited by ne'er-do-wells to trick people into doing something they shouldn't do. There are clever ways to manipulate website addresses that would trick even tech-savvy people into clicking malicious links. Today I'll tell you how these tricks work and explain you can avoid all of these issues by simply blocking these new domains.
In other news: iTunes for Windows patches a nasty bug; Android malware downloaded over 420 million times; Android phones vulnerable to fingerprint brute-force attacks; Luxottica exposes 300 million customer records; free VPN service SuperVPN exposes 360 million user records; Amazon gets slap on the wrist for Ring video doorbell private data access; KeePass "master password crack" not as bad as it sounds; Twitter adding Content Notes 'fact checks' to images; Microsoft now scanning inside password-protected zip files; drone pilot is NOT killed by drone; AI is NOT likely to cause human extinction; and Brave introduces new Off The Record browsing mode. Plus my Dear Carey question: recommended cheat sheet for computer safety.
Article Links
[MacRumors] PSA: If You Run Windows, Make Sure to Update iTunes to Fix Security Vulnerability https://www.macrumors.com/2023/06/01/itunes-windows-vulnerability/
[Lifehacker] This Android Malware Was Downloaded Over 420 Million Times https://lifehacker.com/this-android-malware-was-downloaded-over-420-million-ti-1850492306
[BleepingComputer] Android phones are vulnerable to fingerprint brute-force attacks https://www.bleepingcomputer.com/news/security/android-phones-are-vulnerable-to-fingerprint-brute-force-attacks/
[bitdefender.com] Luxottica 2021 breach: 300 million customer records up for grabs online https://www.bitdefender.com/blog/hotforsecurity/luxottica-2021-breach-300-million-customer-records-up-for-grabs-online/
[hackread.com] Free VPN Service SuperVPN Exposes 360 Million User Records https://www.hackread.com/free-vpn-service-supervpn-leaks-user-records/
[AppleInsider] Amazon gets slap on the wrist over privacy violations with Ring cameras https://appleinsider.com/articles/23/05/31/amazon-gets-slap-on-the-wrist-over-privacy-violations-with-ring-cameras
[Naked Security] Serious Security: That KeePass “master password crack”, and what we can learn from it https://nakedsecurity.sophos.com/2023/05/31/serious-security-that-keepass-master-password-crack-and-what-we-can-learn-from-it/
[Mashable] Twitter will now put Community Notes 'fact checks' on images https://mashable.com/article/twitter-notes-on-media-images
[Ars Technica] Microsoft is scanning the inside of password-protected zip files for malware https://arstechnica.com/information-technology/2023/05/microsoft-is-scanning-the-inside-of-password-protected-zip-files-for-malware/
[VICE] USAF Official Says He ‘Misspoke’ About AI Drone Killing Human Operator in Simulated Test https://www.vice.com/en/article/4a33gj/ai-controlled-drone-goes-rogue-kills-human-operator-in-usaf-simulated-test
[Schneier Blog] On the Catastrophic Risk of AI https://www.schneier.com/blog/archives/2023/06/on-the-catastrophic-risk-of-ai.html
[brave.com] Request "Off the Record" https://brave.com/privacy-updates/26-request-off-the-record/
Tip of the Week: Blocking .zip Domains: https://firewallsdontstopdragons.com/how-to-block-the-new-zip-domain/
Further Info
How to send files securely: https://firewallsdontstopdragons.com/how-to-send-files-securely-like-tax-info/
Checklist of Tips for my book: https://firewallsdontstopdragons.com/wp-content/uploads/2023/02/FDSDv5-workbook-v1.pdf
10 Years After Snowden: https://www.eff.org/deeplinks/2023/05/10-years-after-snowden-some-things-are-better-some-were-still-fighting
The Wayback Machine: https://web.archive.org/
Modern cars are more like smartphones on wheels. Like our cell phones, they are chock full of sensors, computer chips and software, and they're connected to the internet 24/7 via cellular modems. What data is being collected? Who owns this data? How secure is your data? Who is it being shared with? And most importantly, what - if anything - can you do about it? Since we last spoke with Privacy4Car's Andrea Amico, his company has released a powerful new Vehicle Privacy Report tool that aims to answer at least some of these questions and help you to be a more informed car buyer. Today we'll delve into the murky world of car data collection and privacy.
Andrea Amico is one of the nation’s leading authorities on vehicle privacy and cybersecurity. He is also the founder of Privacy4Cars, the first and only privacy-tech company focused on identifying the challenges posed by vehicle data.
Interview Notes
Privacy4Cars: https://privacy4cars.com/
Vehicle Privacy Report tool: https://vehicleprivacyreport.com/
Assert your data rights: https://privacy4cars.com/personal-use/assert-your-data-rights/
Previous interview: Driving Data Privacy for Cars https://podcast.firewallsdontstopdragons.com/2021/09/13/driving-data-privacy-for-cars/
New privacy rules will impact your shop: https://www.autoserviceworld.com/new-privacy-rules-will-impact-your-shop/
Who Is Collecting Data From Your Car? https://themarkup.org/the-breakdown/2022/07/27/who-is-collecting-data-from-your-car
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:04:38: What has happened with Privacy4Cars since we last spoke?
0:06:17: Why are cars collecting so much data? How private is this data?
0:09:31: You say cars are "cell phones on wheels" - what does that mean?
0:10:24: Are cars connected even when turned off?
0:11:55: What types of data is my car collecting?
0:14:16: Do electric cars gather more data than regular cars?
0:16:54: Do cameras built into your car represent a privacy risk?
0:21:51: Who can access my car's data? Can I access it myself?
0:27:25: Who owns the data in rental or fleet cars? What about wrecked cars?
0:32:24: Cars now have smartphone apps - what data are they collecting?
0:37:18: How do I know if I've opted in to data collection?
0:40:42: Can I opt of of data collection? If so, how?
0:44:20: What about Apple's CarPlay or Google's Android Auto?
0:49:37: How do I know which cars best respect my privacy?
0:55:08: How does the Vehicle Privacy Report tool work?
0:57:14: What does this tool tell me about a car?
1:00:43: What's the value of this tool for car makers and dealerships?
1:06:09: What's next for your company and the reporting tool?
1:09:49: Interview follow-up notes
Everyone hates dealing with passwords. This has led to a mad search for 'password-killer' technology. After several failed attempts, there's finally a worthy contender: passkeys. The technology has been around for years - it's the basis for hardware keys like YubiKey. But no one wanted to have to carry the little things all the time. With passkeys, you get the same phishing-proof, passwordless goodness but tied to a device you always have: your smartphone. Websites are slowly rolling out the ability to secure your accounts with passkeys, and Apple, Google and Microsoft are building support for passkeys into their operating systems. But I would caution you to wait a bit before jumping on the bandwagon - I'll explain why in today's show.
In other news: update all your Apple devices; FBI and NSA break the notorious Snake malware; Intel deploys microcode security update; location data on 2M Toyoya customers exposed for years; new .zip and .mov domains are dangerously ambiguous; new crafty Chinese router malware; online age verification will cause serious problems; Apple will allow you to 'bank' your voice soon.
Article Links
[Tom's Guide] Apple issues urgent fix to block zero-day attacks — update your iPhone and Mac now https://www.tomsguide.com/news/apple-issues-urgent-fix-to-block-zero-day-attacks-update-your-iphone-and-mac-now
[tech.co] FBI & NSA Cut the Head Off Notorious Russian Snake Malware https://tech.co/news/nsa-fbi-russian-snake-malware
[Tom's Hardware] Intel Deploys Undisclosed Microcode Security Update For CPUs Going Back To Coffee Lake https://www.tomshardware.com/news/intel-microcode-security-update
[BleepingComputer] Toyota: Car location data of 2 million customers exposed for ten years https://www.bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/
[Digital Trends] Hackers are using a devious new trick to infect your devices https://www.digitaltrends.com/computing/hackers-are-abusing-zip-mov-domain-names/
[9to5mac.com] Researchers find security flaw in Wemo Smart Plug, Belkin says it won’t release a patch https://9to5mac.com/2023/05/16/wemo-smart-plug-security-flaw-no-patch-coming/
[Ars Technica] Malware turns home routers into proxies for Chinese state-sponsored hackers https://arstechnica.com/information-technology/2023/05/malware-turns-home-routers-into-proxies-for-chinese-state-sponsored-hackers/
[Electronic Frontier Foundation] Age Verification Mandates Would Undermine Anonymity Online https://www.eff.org/deeplinks/2023/03/age-verification-mandates-would-undermine-anonymity-online
[9to5mac.com] Everyone should use Personal Voice; it does in 15 minutes what currently takes several weeks https://9to5mac.com/2023/05/19/everyone-should-use-personal-voice/
Tip of the Week: The Pros & Cons of Passkeys https://firewallsdontstopdragons.com/the-pros-and-cons-of-passkeys/
Further Info
Meross MSS115 Matter-enabled smart plug: https://shop.meross.com/products/meross-matter-smart-wi-fi-plug-mini-mss115
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:10: Update on new location tracker spec
0:02:52: News preview
0:05:30: FBI & NSA Cut the Head Off Notorious Russian Snake Malware
0:07:27: Intel Deploys Undisclosed Microcode Security Update
0:11:12: Toyota location data of 2M customers exposed for years
In the book "1984" (published in 1949), George Orwell envisioned a Big Brother that would control the media and dictate what was "truth". But Orwell didn't predict that "telescreens" would fit in our pockets or that we would willingly carry them with us 24/7, even to the bathroom. He also didn't foresee that we would willingly subscribe to sources of mis- and disinformation in the form of social media. Today I speak with the co-author of the book "Ministry of Truth", Vincent Hendricks, about the current state of social media and its influence on democracy and society.
Vincent F. Hendricks, author of THE MINISTRY OF TRUTH: BigTech's Influence On Facts, Feelings And Fictions, is Professor of Formal Philosophy at the University of Copenhagen. He is the Director of the Center for Information and Bubble Studies (CIBS) funded by the Carlsberg Foundation.
Interview Notes
“Ministry of Truth” book: https://www.vince-inc.com/vincent/?p=7625
“1984” by George Orwell: https://en.wikipedia.org/wiki/Nineteen_Eighty-Four
"Reality Lost" (free PDF book): https://link.springer.com/book/10.1007/978-3-030-00813-0
Vincent Hendricks website: https://www.vince-inc.com/vincent/
More from Vincent: https://www.oecd-forum.org/users/vincent-f-hendricks
Blocking Google popups (and other annoyances): https://firewallsdontstopdragons.com/how-to-block-google-popups/
Further Info
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/
Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:02:23: Pre-inteview notes
0:03:51: Why did you write this book?
0:06:06: What is the current state of social media content moderation?
0:10:41: How equally are moderation rules applied to all users?
0:12:44: Do algorithms just feed our desire for stuff that's not good for us?
0:16:39: Are things really worse today or just different?
0:21:21: Do private companies have a moral duty to support a "public square"?
0:26:23: Are social media companies warping the public discourse?
0:28:58: Is TikTok really more of a threat than Facebook or Twitter?
0:31:15: Are any of the proposed TikTok solutions viable?
0:35:41: Why can't the US Congress pass a real privacy law?
0:38:00: Can we fix some key social media ills by adding some friction?
0:41:10: How will AI systems like ChatGPT impact disinformation?
0:44:15: Can AI also have positive impacts on social media?
0:48:10: How are social media platforms like casinos?
0:50:28: How are social media platforms like Orwell's Ministry of Truth?
0:51:34: How much responsibility do we have here?
0:57:42: What tips do you have for using social media today?
1:02:59: Interview wrap-up
1:03:28: Privacy and security book club
1:04:37: Patron perks
1:05:02: Preview of upcoming shows
Have you noticed Google getting really pushy lately with offers to “sign in with Google”? You’re not alone. Many websites offer the ability to create a free account so that you can “personalize your experience”, but lately Google has been popping up an very annoying window to prompt you to create this account by signing in with your Google account. First of all, you almost never need to create an account to view the site. But second, even if you do want to create an account, you shouldn’t be linking that account with Google. You’re creating a data sharing arrangement that is completely unnecessary and not in your best interests. I’ll explain how to block these irritating popups (and many like them) for good.
In other news: 1Password was not hacked, but recent messages might have worried you; new macOS malware stealer app; five things scammers hope you search for; Microsoft Edge is recording your web surfing data; Windows 10 will never receive another feature update; Microsoft is rewriting core Windows software in a memory-safe language; study claims 83% of passwords can be hacked in one second; Google adds support for passkeys; Apple issues first Rapid Security Response with confusing messages; NYPD hands out 500 free AirTags to combat auto thefts; Apple and Google partner on industry spec to thwart unwanted tracking devices; Google adds cloud backup for 2FA without end-to-end encryption; Amazon Clinic requires you to sign away privacy rights; Washington State pass health data privacy law; my take on recent efforts to undermine encryption and restrict access to social media.
Article Links1. [Digital Trends] No, 1Password wasn’t hacked – here’s what really happened https://www.digitaltrends.com/computing/1password-secret-keys-not-hacked/ 2. [9to5mac.com] PSA: ‘Atomic macOS Stealer’ malware can compromise iCloud Keychain passwords, credit cards, crypto wallets https://9to5mac.com/2023/04/28/atomic-macos-stealer-malware-steal-passwords/ 3. [Lifehacker] Five Things Scammers Are Hoping You Google https://lifehacker.com/five-things-scammers-are-hoping-you-google-1850405964 4. [The Verge] Microsoft Edge is leaking the sites you visit to Bing https://www.theverge.com/2023/4/25/23697532/microsoft-edge-browser-url-leak-bing-privacy 5. [Lifehacker] Microsoft Will Never Update Windows 10 Again (But You Can Keep Using It) https://lifehacker.com/microsoft-will-never-update-windows-10-again-but-you-c-1850386188 6. [theregister.com] Microsoft is busy rewriting core Windows code in memory-safe Rust https://www.theregister.com/2023/04/27/microsoft_windows_rust/ 7. [9to5mac.com] Study reveals top 20 most used passwords; 83% can be cracked in a second https://9to5mac.com/2023/05/02/most-used-passwords-report/ 8. [The Hacker News] Google Introduces Passwordless Secure Sign-In with Passkeys for Google Accounts https://thehackernews.com/2023/05/google-introduces-passwordless-secure.html 9. [AppleInsider] Apple issues Rapid Security Response update for iOS 16.4.1, macOS 13.3.1 https://appleinsider.com/articles/23/05/01/apple-issues-rapid-security-response-update-for-ios-1641-macos-1331 10. [AppleInsider] New York hands out 500 AirTags in car theft crackdown https://appleinsider.com/articles/23/05/01/new-york-hands-out-500-airtags-in-car-theft-crackdown 11. [Apple] Apple, Google partner on an industry specification to address unwanted tracking https://www.apple.com/newsroom/2023/05/apple-google-partner-on-an-industry-specification-to-address-unwanted-tracking/ 12. [Gizmodo] Google’s New Two-Factor Authentication Isn’t End-to-End Encrypted, Tests Show https://gizmodo.com/google-authenticator-two-factor-not-end-encrypted-1850377102 13. [The Washington Post] To become an Amazon Clinic patient, first you sign away some privacy https://www.washingtonpost.com/technology/2023/05/01/amazon-clinic-hipaa-privacy/ 14. [The Verge] Washington passes law requiring consent before companies collect health data https://www.theverge.com/2023/4/28/23702246/washington-health-data-law-consent-collect-sell 15. [Yahoo] India has blocked 14 mobile messenger apps on security fears https://www.yahoo.com/lifestyle/india-blocked-14-mobile-messenger-074000711.html 16. [CNN] Arkansas governor signs sweeping bill imposing a minimum age limit for social media usage https://www.cnn.com/2023/04/12/tech/arkansas-social-media-age-limit/index.html 17. [act.eff.org] The “Earn It” Act is Back, Seeking To Scan Us All https://act.eff.org/action/the-earn-it-act-is-back-seeking-to-scan-us-all 18. Tip of the Week: Block Google Sign-In Popups: https://firewallsdontstopdragons.com/how-to-block-google-popups/
Further Info TP-Link software update: https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware * Install uBlock Origin: https://ublockorigin.com/ * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
There’s a big difference between mass surveillance and targeted surveillance based on a court-approved, limited-scope search warrant. But advances in technology have made warrant-less, dragnet surveillance exceptionally easy and stunningly effective. Local law enforcement agencies have deployed several types of surveillance systems in our communities, but have strongly resisted calls for transparency and oversight. Furthermore, police have simply bypassed the need for a warrant and pesky Fourth Amendment rights by just buying surveillance data from private companies. My guests today – Albert Fox Cahn and Evan Enzer, from the Surveillance Technology Oversight Project (S.T.O.P.) – will explain what’s going on, why it’s a danger to our privacy rights and democratic principles, and what we can do to fix it.
Interview Notes* Surveillance Technology Oversight Project: https://www.stopspying.org/ * STOP on Twitter & TikTok: @STOPSpyingNY * Donate to S.T.O.P. https://www.stopspying.org/donate * STOP Trojan House report: https://www.stopspying.org/the-trojan-house * Public Oversight of Surveillance Technology (POST) Act: https://www.nyc.gov/site/nypd/about/about-nypd/policy/post-act.page * Community Control of Police Surveillance (CCOPS): https://www.eff.org/issues/community-control-police-surveillance-ccops * Electronic Frontier Alliance: https://www.eff.org/fight * EFF’s Atlas of Surveillance: https://atlasofsurveillance.org/
Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Our smartphones have become indispensable tools for our daily lives – so seeing that dreaded red battery indicator can induce some serious anxiety. But before you jack your phone into some public USB charging port, think twice. Those USB connections can pass data as well as power, and it’s actually possible to hack your phone using those ubiquitous and innocent-looking ports. Is this common? Probably not. But it’s also very easy to avoid. I’ll give you several tips for staying safe, particularly while traveling.
In other news: Mullvad VPN was subjected to a search warrant (but had no data to give up); Proton has announced that it has created a password manager; YubiCo is merging with another company and going public; Facebook probably owes you some money; Apple HomePods can tell you if your house is on fire; one of several Israeli spyware makers is shutting down; the US and several partner countries are urging device makers to adopt Security by Design principles; hackers use fake Chrome updates to install malware; the much-hyped Florida water treatment plant hack wasn’t really a hack; clever thieves are stealing modern cars through headlamp connectors; and health care portal check-in vendors are tricking patients into allowing them to monetize very sensitive health data.
Article Links1. [mullvad.net] Mullvad VPN was subject to a search warrant. Customer data not compromised https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised/ 2. [proton.me] Proton Pass is now in beta https://proton.me/blog/proton-pass-beta 3. [yubico.com] Yubico is merging with ACQ Bure: merged company intends to go public on Nasdaq First North Growth Market in Stockholm https://www.yubico.com/blog/yubico-is-merging-with-acq-bure/ 4. [Lifehacker] Facebook Probably Owes You Money https://lifehacker.com/facebook-probably-owes-you-money-1850350640 5. [MacRumors] HomePod Can Now Alert You If Your Smoke Alarm Goes Off https://www.macrumors.com/2023/04/18/homepod-alert-smoke-alarm/ 6. [The Hacker News] Israeli Spyware Vendor QuaDream to Shut Down Following Citizen Lab and Microsoft Expose https://thehackernews.com/2023/04/israeli-spyware-vendor-quadream-to-shut.html 7. [cisa.gov] U.S. and International Partners Publish Secure-by-Design and -Default Principles and Approaches https://www.cisa.gov/news-events/news/us-and-international-partners-publish-secure-design-and-default-principles-and-approaches 8. [Tom’s Guide] Hackers are using fake Chrome updates to spread malware — don’t fall for this https://www.tomsguide.com/news/hackers-are-using-fake-chrome-updates-to-spread-malware-dont-fall-for-this 9. [VICE] Much-Hyped Water Plant Hack Wasn’t a Hack, Was Actually User Error, Official Says https://www.vice.com/en/article/y3wddv/much-hyped-water-plant-hack-wasnt-a-hack-was-actually-user-error-official-says 10. [theregister.com] CAN do attitude: How thieves steal cars using network bus https://www.theregister.com/2023/04/06/can_injection_attack_car_theft/ 11. [statnews.com] I declined to share my medical data with advertisers at my doctor’s office. One company claimed otherwise https://www.statnews.com/2023/04/07/medical-data-privacy-phreesia/ 12. Tip of the Week: How to Avoid Juice Jacking https://firewallsdontstopdragons.com/how-to-avoid-juice-jacking/
Further Info Facebook settlement form: https://www.facebookuserprivacysettlement.com/#submit-claim * CISA Secure by Design, Secure by Default: https://www.cisa.gov/securebydesign * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
As cybersecurity experts love to say, the “S” in “IoT” stands for security… meaning there is none. I’ve seen estimates that say there were almost 30 billion IoT devices on the internet in 2022. I have dozens of them on my home network alone. Each of these devices contains at least one computer, which is running potentially hackable software. And because these devices have internet connections, they are vulnerable to cyber attacks from anywhere on the planet. Today I’ll ask Bill Niefert from Corellium how IoT devices differ from regular computers, how secure they are, what the risks are of insecure smart devices, and how we can make them better.
Interview Notes* Corellium: https://www.corellium.com/ * Interesting IoT statistics: https://techjury.net/blog/internet-of-things-statistics/ * Raspberry Pi: https://www.raspberrypi.org/ * Fun RPi projects: https://www.pcworld.com/article/420028/10-practical-raspberry-pi-projects-anyone-can-do.html * Matter IoT standard: https://en.wikipedia.org/wiki/Matter_(standard)
Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Right after releasing my episode on web fingerprinting, highly-respected VPN provider Mullvad teamed up with Tor to release a new web browser, specifically designed to protect your privacy – including attempting to block fingerprinting! Great timing, so I thought I’d give you my review of the Mullvad Browser – the good, the bad, and (yes) the ugly.
In other news: Timely tips on spotting IRS phone scams; ultrasound attacks can hijack your smart speakers; brace yourself for a wave of more sophisticated AI-based scams; alcohol recover startups shared patients’ data with advertisers; Google to require app developers to let you delete your account data; FBI’s Operation Cookie Monster shuts down popular cybercrime forum; Facebook will grudgingly offer users in Europe to opt out of all tracking; the FDA is requiring medical device manufacturers to improve cybersecurity and support; and I answer a Dear Carey question about how to use a Mac mini as a server to host private versions of cloud apps.
Article Links1. [NPR] No, the IRS isn’t calling you. It isn’t texting or emailing you, either https://www.npr.org/2023/04/07/1168353969/irs-scam-tax-day-imposter-how-to-avoid 2. [Gizmodo] Ultrasound Attack Can Secretly Hijack Phones and Smart Speakers, Researchers Find https://gizmodo.com/ultrasound-attack-hacks-phones-siri-alexa-usenix-1850273055 3. [WIRED] Brace Yourself for a Tidal Wave of ChatGPT Email Scams https://www.wired.com/story/large-language-model-phishing-scams/ 4. [TechCrunch] Alcohol recovery startups Monument and Tempest shared patients’ private data with advertisers https://techcrunch.com/2023/04/04/monument-tempest-alcohol-data-breach/ 5. [Engadget] Google will require that Android apps let you delete your account and data https://www.engadget.com/google-will-require-that-android-apps-let-you-delete-your-account-and-data-170618841.html 6. [CNN] ‘Operation Cookie Monster’: FBI seizes popular cybercrime forum used for large-scale identity theft https://www.cnn.com/2023/04/04/politics/genesis-market-fbi-seizure/index.html 7. [BGR] Facebook and Instagram users can now opt out of tracking, but only in Europe https://bgr.com/tech/facebook-and-instagrams-users-can-now-opt-out-of-tracking-but-only-in-europe/ 8. [scmagazine.com] FDA will refuse new medical devices for cybersecurity reasons on Oct. 1 https://www.scmagazine.com/news/device-security/fda-will-refuse-new-medical-devices-for-cybersecurity-reasons-on-oct-1 9. Tip of the Week: Mullvad Browser https://firewallsdontstopdragons.com/new-privacy-tool-mullvad-browser/
Further Info Watchman Privacy interview: https://www.youtube.com/watch?v=fByagxDetVI * Using ultrasound to drive away teens: https://www.today.com/news/controversial-mosquito-sonic-devices-deter-young-people-high-pitched-sounds-t157801 * Train Siri to recognize your voice: https://support.apple.com/en-us/HT204753 * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Give the gift of privacy and security: https://fdsd.me/coupons * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
On today’s show, I’ll take you behind the scenes of not one, not two, but three different privacy websites. I ask Nate from The New Oil and Niek from Privacy Guides how they deal with being a public figures advocating for privacy, how they set their personal standards for privacy products, and how they cope with people and product makers who complain about their recommendations (or lack thereof). I ask them about some favorite products that they’ve had to remove from their recommended lists and where they go to keep up to date on privacy topics and products. Finally, I ask them what gives them hope about the future of privacy and what keeps them up at night.
Interview Notes* The New Oil: https://thenewoil.org/ * Privacy Guides: https://www.privacyguides.org/ * Techlore: https://techlore.tech/ * Panopticon: https://en.wikipedia.org/wiki/Panopticon * Naomi Brockwell on VPNs: https://www.youtube.com/watch?v=8MHBMdTBlok
Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Marketers are desperately trying to follow us as we traverse the web. Tracking where we go and what we do allows them to better target us with ads. Browsers have built in protections to block older tracking techniques like cookies and tracking pixels, and so ad companies have had find new methods for identifying us across websites. Unfortunately, they’ve settled on a technique that is extremely difficult to defeat: fingerprinting. I’ll explain what is, how it works, and what you can do to mitigate it.
In other news: Google is warning Android users to update their devices right away in order to fix some truly nasty bugs; hackers are using malicious Chrome extensions to read your Gmail and potentially hack your Android device; popular fertility apps are collecting ridiculous amounts of highly personal data and sharing it with partners; scammers are using AI to simulate voices of people you know to steal your money; CISA has launched a great new ransomware vulnerability pilot program; I’ll tell you why you should opt out of sharing your data with your mobile service provider; America’s threatening to ban TikTok but this won’t fix the real problem; the IRS is supposed to be moving away from ID.me authentication.
Article Links1. [Naked Security] Dangerous Android phone 0-day bugs revealed – patch or work around them now! https://nakedsecurity.sophos.com/2023/03/17/dangerous-android-phone-0-day-bugs-revealed-patch-or-work-around-them-now/ 2. [Tom’s Guide] Hackers are stealing Gmail messages — delete this extension right now https://www.tomsguide.com/news/hackers-are-stealing-gmail-messages-delete-this-extension-right-now 3. [The Conversation] Popular fertility apps are engaging in widespread misuse of data, including on sex, periods and pregnancy https://theconversation.com/popular-fertility-apps-are-engaging-in-widespread-misuse-of-data-including-on-sex-periods-and-pregnancy-202127 4. [consumer.ftc.gov] Scammers use AI to enhance their family emergency schemes https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes 5. [cisa.gov] CISA Establishes Ransomware Vulnerability Warning Pilot Program https://www.cisa.gov/news-events/news/cisa-establishes-ransomware-vulnerability-warning-pilot-program 6. [briankrebs] Why You Should Opt Out of Sharing Data With Your Mobile Provider https://krebsonsecurity.com/2023/03/why-you-should-opt-out-of-sharing-data-with-your-mobile-provider/ 7. [The Washington Post] America’s online privacy problems are much bigger than TikTok https://www.washingtonpost.com/technology/2023/03/24/tiktok-online-privacy-laws/ 8. Dear Carey: IRS plans to approve use of Login-dot-gov as Tax Day nears https://www.fcw.com/it-modernization/2023/03/plans-approve-use-login-dot-gov-tax-day-nears/383934/ 9. Tip of the Week: https://firewallsdontstopdragons.com/how-to-block-web-fingerprinting/
Further Info Syncthing: https://syncthing.net/ * KeePassXC: https://keepassxc.org/ * IP address black list check: https://whatismyipaddress.com/blacklist-check * EFF on TikTok: https://www.eff.org/deeplinks/2023/03/government-hasnt-justified-tiktok-ban * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
If for some reason you haven’t started using a password manager yet, it’s time to make the move. But how can you trust all these important secrets to some unknown company? How can you be sure that your password vault will be safe in a cloud-based service? And finally, how do you figure out which service is best for you? Today I’ll ask Kasey Babcock from Bitwarden all those questions. We’ll also talk about two-factor authentication and newer “passkeys” technology, Argon2 vs PBKDF2, and even how you might self-host a solution like Bitwarden if you want to have full control.
Kasey Babcock is a Product Marketing Manager at Bitwarden, and she has many years of experience working at software start-ups in the cybersecurity and project portfolio management industries, working with product and engineering teams to communicate meaningful cybersecurity information and product updates.
Interview Notes* Bitwarden Personal: https://bitwarden.com/products/personal/ * Bitwarden Secrets Manager: https://bitwarden.com/products/secrets-manager/ * Bitwarden blog article: https://bitwarden.com/blog/accelerating-value-for-bitwarden-users-bitwarden-raises-usd100-million/
Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Our devices are connected to the Internet 24/7 and the only thing separating them from the bad guys is usually your home router. In the era of smart devices and the Internet of Things (IoT), we also now have many more doohickeys connected to the Internet – most of them with crappy security. If one of those devices is compromised, the bad guys now have a beachhead from which to probe and attack all your other devices. In today’s show, we’ll review some important cybersecurity tips for our home network and connected devices.
In other news: police raid homes of alleged ransomware gang; locally exploitable TPM 2.0 security flaws found; White House unveils comprehensive cybersecurity strategy; new LastPass breach details show specific employee was targeted at home; browser synchronization features may compromise employer systems; Catholic group buys data to target gay priests; private home webcams are a goldmine for police evidence gathering; telehealth companies leak sensitive patient data; ICE and Secret Service admit to using cell-site simulators to collect mass surveillance data.
Article Links1. [The Verge] Police raid homes of alleged hackers who attacked hospital systems https://www.theverge.com/2023/3/6/23627238/hackers-ransomware-raid-german-ukrainian-police 2. [TechSpot] Two security flaws in the TPM 2.0 specs put cryptographic keys at risk https://www.techspot.com/news/97824-two-security-flaws-tpm-20-specs-put-cryptographic.html 3. [The Washington Post] Biden unveils cyber strategy that takes more aggressive regulatory approach https://www.washingtonpost.com/national-security/2023/03/02/cybersecurity-biden/ 4. [Ars Technica] LastPass says employee’s home computer was hacked and corporate vault taken https://arstechnica.com/information-technology/2023/02/lastpass-hackers-infected-employees-home-computer-and-stole-corporate-vault/ 5. [Kaspersky] Disable browser synchronization in the office https://www.kaspersky.com/blog/disable-browser-sync-enterprise/47460/ 6. [The Washington Post] Catholic group spent millions on app data that tracked gay priests https://www.washingtonpost.com/dc-md-va/2023/03/09/catholics-gay-priests-grindr-data-bishops/ 7. [Electronic Frontier Foundation] Report: ICE and the Secret Service Conducted Illegal Surveillance of Cell Phones https://www.eff.org/deeplinks/2023/03/report-ice-and-secret-service-conducted-illegal-surveillance-cell-phones 8. [POLITICO] The privacy loophole in your doorbell https://www.politico.com/news/2023/03/07/privacy-loophole-ring-doorbell-00084979 9. [TechCrunch] Telehealth startup Cerebral shared millions of patients’ data with advertisers https://techcrunch.com/2023/03/10/cerebral-shared-millions-patient-data-advertisers/ 10. [NPR] Personal information of members of Congress exposed in health data breach https://www.npr.org/2023/03/09/1162191035/personal-information-of-u-s-house-members-exposed-in-health-data-breach 11. Securing Your Home Network: https://firewallsdontstopdragons.com/how-to-secure-your-home-network/
Further Info Apple’s HomeKit Secure Video: https://support.apple.com/en-us/HT210538 * Shodan: https://www.shodan.io/ * What’s My IP? https://www.whatismyip.com/ * NSA home network security (PDF): https://media.defense.gov/2023/Feb/22/2003165170/-1/-1/0/CSI_BEST_PRACTICES_FOR_SECURING_YOUR_HOME_NETWORK.PDF * What a VPN Is (and Isn’t): https://firewallsdontstopdragons.com/what-a-vpn-is-and-isnt/ * Get your Dragon Swag! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Privacy advocates like me implore people to use secure apps that protect their data. But how difficult is it to actually create those apps? How do you balance security and privacy against sharing features and ease of use? How do you earn the trust of your users and how do you keep that trust? When does being private begin to negatively impact your ability to participate in society? Today I’ll ask Mo, the creator of the secure note-taking app Standard Notes, all of these questions and more – including his personal thoughts for how best to organize and back up your notes and other data.
Interview Notes* Standard Notes: https://standardnotes.com/ * Write Fearlessly (blog article): https://standardnotes.com/why-encrypted * Standard Notes YouTube channel: https://www.youtube.com/@standardnotes * Second Brain note taking styles: https://fortelabs.com/blog/the-4-notetaking-styles-how-to-choose-a-digital-notes-app-as-your-second-brain/ * Tresosit secure cloud storage: https://tresorit.com/individuals * Sync.com secure cloud storage: https://sync.com/
Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support our mission! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Web links are great, when you’re on the web. But if you need to read off or write down a web address, or URL, to someone else, anything beyond a simple domain name is going to be way too complicated. Ideally, you want something short and memorable. Enter link-shortening services like Bitly, Owly and others. These services convert long, ugly URLs to short, simple, memorable links. Unfortunately, this also obscures the actual link. When you click a shortened link, you have no idea where it will take you. Today, I’ll give you some tools that will allow you to determine the final destination and even see an image of the site without actually going there.
In other news: TikTok group teaches people how to hot-wire Kia and Hyundai cars; Twitter charges users for the least-secure two-factor authentication method; scam authenticator apps proliferation on the app store; Apple devices are being stolen after surreptitiously learning the lock codes; Google to launch Android Privacy Sandbox beta; Mozilla discovers huge discrepancies between actual privacy policies and the ‘nutrition label’ summaries on top Android apps; supermarkets track tons of user data via loyalty cards and apps; we need to create a much more robust and resilient internet; and the CEO of Safing answers a user question about Portmaster and SPN.
Article Links1. [Lifehacker] TikTokers Are Hot-Wiring These Hyundai and Kia Cars https://lifehacker.com/tiktokers-are-hot-wiring-these-hyundai-and-kia-cars-1850113943 2. [Mashable] Twitter to charge users for SMS two-factor authentication https://mashable.com/article/twitter-removes-sms-2fa 3. [9to5mac.com] Scam authenticator app advertising on App Store: Sends all your QR codes to the developer https://9to5mac.com/2023/02/21/scam-authenticator-app/ 4. [MacRumors] Apple Responds to Report About Thieves Spying on iPhone Passcodes to ‘Steal Your Entire Digital Life’ https://www.macrumors.com/2023/02/24/iphone-stolen-passcodes-report/ 5. [The Verge] Google launches first Android beta for ad-tracking overhaul https://www.theverge.com/2023/2/14/23599027/google-android-privacy-sandbox-beta-advertising-tracking 6. [foundation.mozilla.org] Mozilla Study: Data Privacy Labels for Most Top Apps in Google Play Store are False or Misleading 7. [The Markup] Forget Milk and Eggs: Supermarkets Are Having a Fire Sale on Data About You https://themarkup.org/privacy/2023/02/16/forget-milk-and-eggs-supermarkets-are-having-a-fire-sale-on-data-about-you 8. [Schneier Blog] What Will It Take? https://www.schneier.com/blog/archives/2023/02/what-will-it-take.html 9. How to Reveal Shortened URLs: https://firewallsdontstopdragons.com/how-to-reveal-shortened-urls/
Further Info 2FA apps: https://lifehacker.com/the-best-authenticator-apps-for-iphone-and-android-1850140802 * Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Social media wasn’t always so bad. It didn’t use to collect so much information. It didn’t use to feed us content we didn’t ask for in an attempt to maintain our attention. Doom scrolling, virtue signaling, algorithmic feeds and misinformation bots are not natural extensions of social media. So what went wrong? And better yet, how can we fix it? Today I’ll discuss all of these topics and more with Suzie Dawson, the founder of Panquake.com. She’s on a mission to solve all of these problems and restore the promise of social media to be a positive force for society and serve the users, not corporations or governments.
Interview Notes* Panquake: https://panquake.com/ * A Personal Message from our Founder (Suzie): https://vimeo.com/770524936 * What is Panquake? https://vimeo.com/503223746 * The Social Dilemma (documentary): https://www.thesocialdilemma.com/ * Mastodon: https://joinmastodon.org/ * Fediverse: https://www.eff.org/deeplinks/2022/11/fediverse-could-be-awesome-if-we-dont-screw-it * Microsoft’s Decentralized Identity: https://learn.microsoft.com/en-us/azure/active-directory/verifiable-credentials/decentralized-identifier-overview
Further Info Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
As a general rule, I would normally advise people to minimize the number of online accounts they have, including avoiding creating unnecessary accounts and closing accounts they no longer need. However, as a regular citizen, there are a handful of governmental accounts that exist for you already, whether you use them or not. And you should claim those accounts for yourself before bad guys do this on your behalf. Furthermore, as a home owner or modern consumer, you probably have several other accounts that you may never have claimed: utilities, financial institutions, medical portals, and more. Today I’ll tell you where and why to plant your flag.
In other news: Booking.com reservation data being used to scam customers; top background check service customers’ data leaked; Finnish psychotherapy extortion suspect arrested; FTC takes on telehealth data sharing; the ACLU lobbies court to restrict Google geofence warrant data; Anker admits to Eufy camera security bugs; fake, malicious Bitwarden ads deliver malware; maker of stalkerware fined and forced to notify victims; NIST proposes security protocols for low-power IoT devices. I also answer a listener question about IPv4 vs IPv6.
Article Links1. [Ars Technica] Mysterious leak of Booking.com reservation data is being used to scam customers https://arstechnica.com/information-technology/2023/02/mysterious-leak-of-booking-com-reservation-data-is-being-used-to-scam-customers/ 2. [TechRadar] Top background check services hit by data breach https://www.techradar.com/news/top-background-check-services-hit-by-data-breach 3. [Naked Security] Finnish psychotherapy extortion suspect arrested in France https://nakedsecurity.sophos.com/2023/02/06/finnish-psychotherapy-extortion-suspect-arrested-in-france/ 4. [The Markup] The FTC Is Taking on Telehealth’s Data Sharing Problem—Starting with GoodRx – The Markup https://themarkup.org/pixel-hunt/2023/02/01/the-ftc-is-taking-on-telehealths-data-sharing-problem-starting-with-goodrx 5. [Computerworld] ACLU, public defenders push back against Google giving police your mobile data https://www.computerworld.com/article/3686535/aclu-public-defenders-push-back-against-google-giving-police-your-mobile-data.html 6. [9to5mac.com] Anker admits to lying about Eufy security camera encryption; describes future plans https://9to5mac.com/2023/02/01/eufy-security-camera-encryption/ 7. [PCWorld] Phony, malicious Bitwarden ads slip past Google’s watch https://www.pcworld.com/article/1487690/phony-bitwarden-ads-are-the-latest-to-slip-through-on-googles-watch.html 8. [Electronic Frontier Foundation] Stalkerware Maker Fined $410k and Compelled to Notify Victims https://www.eff.org/deeplinks/2023/02/stalkerware-maker-fined-410k-and-compelled-notify-victims 9. [ZDNet] Tiny IoT devices are getting their own special encryption algorithms https://www.zdnet.com/article/tiny-iot-devices-are-getting-their-own-special-encryption-algorithms/
Further Info Order the new 5th edition of my book! https://fdsd.me/book* * OSINT Tools: https://inteltechniques.com/tools/index.html * WireGuard IPv6 help: https://stanislas.blog/2019/01/how-to-setup-vpn-server-wireguard-nat-ipv6/ * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
The business of data mining and behavioral advertising has never been stronger or more ubiquitous. And yet, cracks are beginning to appear in the foundations of surveillance capitalism. Nowhere is this more evident than in the European Union where advertising behemoths like Google and Meta (parent company of Facebook) have suffered a series of legal defeats at the hands of aggressive privacy regulators. The GDPR has provided a framework for curtailing rampant abuses of the advertising industry and its promise is finally coming to fruition. Today I’ll speak with Johnny Ryan from the Irish Council for Civil Liberties, who is fighting for all of us on the front lines of the war for privacy.
Johnny Ryan works at the Irish Council for Civil Liberties and he was previously Chief Policy Officer at Brave. He has testified and spoken at the US Senate, the European Commission, and the European Parliament.
Interview Notes* Irish Regulators Fine Facebook $414 Million https://thehackernews.com/2023/01/irish-regulators-fine-facebook-414.html * Irish Council for Civil Liberties: https://www.iccl.ie/ * Ep231: Selling You Out to the Highest Bidder https://podcast.firewallsdontstopdragons.com/2021/08/02/selling-you-out-to-the-highest-bidder/ * Fair Information Practice Principles (FIPPs): https://en.wikipedia.org/wiki/FTC_fair_information_practice * Diesel-Gate: https://en.wikipedia.org/wiki/Volkswagen_emissions_scandal
Further Info Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Every January, we celebrate privacy with Data Privacy Week. It has rightly expanded from Data Privacy Day. And of course every day should be data privacy day.
In the news: The FBI shuts down a major ransomware group; new Windows malware steals passwords and other data; new Android malware can completely take over your device; a dangerous “malvertising” campaign mimics popular software to steal info; the previously-secret “no fly” list was leaked online; tens of thousands of PayPal accounts hacked via credential stuffing; T-Mobile admits to over 37M customer records stolen; and Twitter GodMode is back (or rather never really went away). I’ll answer a Dear Carey question about Plain, the service that allows financial tech aggregators to access your account information and my Tip of the Week will explain Apple’s new Advanced Data Protection feature.
Article Links1. [NPR] FBI says it ‘hacked the hackers’ to shut down major ransomware group https://www.npr.org/2023/01/26/1151696092/fbi-says-it-hacked-the-hackers-to-shut-down-major-ransomware-group 2. [Tom’s Guide] This Windows malware is stealing passwords and other data — how to stay safe https://www.tomsguide.com/news/this-windows-malware-is-stealing-passwords-and-other-data-how-to-stay-safe 3. [TechSpot] New malware dubbed “Hook” allows hijacking and real-time spying on Android devices https://www.techspot.com/news/97356-new-malware-dubbed-hook-allows-hijacking-real-time.html 4. [TechRadar] This dangerous malvertising campaign mimicks popular software to steal victim info https://www.techradar.com/news/this-dangerous-malvertising-campaign-mimicks-popular-software-to-steal-victim-info 5. [BleepingComputer] Secret terrorist watchlist with 2 million records exposed online https://www.bleepingcomputer.com/news/security/secret-terrorist-watchlist-with-2-million-records-exposed-online/ 6. [BleepingComputer] PayPal accounts breached in large-scale credential stuffing attack https://www.bleepingcomputer.com/news/security/paypal-accounts-breached-in-large-scale-credential-stuffing-attack/ 7. [Naked Security] T-Mobile admits to 37,000,000 customer records stolen by “bad actor” https://nakedsecurity.sophos.com/2023/01/20/t-mobile-admits-to-37000000-customer-records-stolen-by-bad-actor/ 8. [9to5mac.com] Twitter GodMode still available to all engineers, following hack of Apple and other accounts https://9to5mac.com/2023/01/24/twitter-godmode/ 9. Dear Carey: Is Plaid Safe? https://www.allthingssecured.com/reviews/security/is-plaid-safe-to-use/ 10. Apple’s Advanced Data Protection: https://support.apple.com/guide/security/advanced-data-protection-for-icloud-sec973254c5f/web 11. Apple recovery contact: https://support.apple.com/en-us/HT212513
Further Info ANNUAL LISTENER SURVEY!! https://fdsd.me/survey2023 * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Our email addresses and cell phone numbers have become highly valuable identifiers for marketers. Like government-issued IDs, your email address and phone number are directly associated with your identity and you will probably have them for life. This makes them ideal for tracking you across websites and accounts. It’s no wonder that you are asked to provide this information all the time, for the simplest things. So why not throw them off your trail by having multiple email addresses and phone numbers? It’s not as hard as you think, and it’s getting easier all the time. This is a privacy concept called aliasing and we’ll delve into all the details with the CEO and founder of SimpleLogin, Son Nguyen Kim.
Interview Notes* SimpleLogin: https://simplelogin.io/ * Proton & SimpleLogin: https://proton.me/support/create-simplelogin-account-proton-account * Data Privacy Week: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ * Fastmail Masked Email: https://www.fastmail.help/hc/en-us/articles/4406536368911-Masked-Email * Apply Private Relay: https://support.apple.com/en-us/HT212614 * DuckDuckGo Private Email: https://spreadprivacy.com/introducing-email-protection-beta/ * MySudo: https://mysudo.com/ * Hushed: https://hushed.com/ * Privacy.com: https://privacy.com/
Further Info ANNUAL LISTENER SURVEY!! https://fdsd.me/survey2023 * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
It’s that time of year again! Time to put the past behind us and look forward to a brand new year, full of possibilities and hope! In today’s show I’ll throw out several tips for improving your privacy and security that you might want to put on your to-do list for 2023. I’ve also got a minor LastPass update and some thoughts on how we might make managing passwords easier and more robust. I’ll answer a listener question on tracking in beta software.
And then I’ll cover several news stores: A government watchdog cracks many accounts in a federal agency with a cheap password cracking rig; NortonLifeLock is warning several users that hackers may have breached their accounts; Russian hackers suspected in Royal Mail attack; Iran’s citizens being targeted with spyware in VPN apps; Windows 7 is finally totally dead; identity thieves find authentication bypass to access Experian credit reports; robot vacuum cleaner captured compromising pictures that ended up on social media; even the FBI is recommending ad blockers; dozens of telehealth companies sharing sensitive health information with Big Tech companies.
Article Links1. [TechCrunch] A government watchdog spent $15,000 to crack a federal agency’s passwords in minutes https://techcrunch.com/2023/01/10/interior-department-watchdog-passwords/ 2. [BleepingComputer] NortonLifeLock warns that hackers breached Password Manager accounts https://www.bleepingcomputer.com/news/security/nortonlifelock-warns-that-hackers-breached-password-manager-accounts/ 3. [Metro] Russian hackers suspected to be behind Royal Mail cyber attack https://metro.co.uk/2023/01/13/russian-hackers-suspected-to-be-behind-royal-mail-cyber-attack-18093326/ 4. [techmonitor.ai] Iran’s citizens targeted by EyeSpy spyware hidden in VPNs https://techmonitor.ai/technology/cybersecurity/eyespy-spyware-iran-vpn 5. [Lifehacker] Windows 7 Is Officially Dead https://lifehacker.com/windows-7-is-officially-dead-1849966248 6. [briankrebs] Identity Thieves Bypassed Experian Security to View Credit Reports https://krebsonsecurity.com/2023/01/identity-thieves-bypassed-experian-security-to-view-credit-reports/ 7. [Kaspersky] Rise of the robot vacuum cleaners https://www.kaspersky.co.uk/blog/robot-vacuum-privacy/25348/ 1. Bonus: https://www.technologyreview.com/2023/01/10/1066500/roomba-irobot-robot-vacuum-beta-product-testers-consent-agreement-misled/ 8. [TechCrunch] Even the FBI says you should use an ad blocker https://techcrunch.com/2022/12/22/fbi-ad-blocker/ 9. [The Markup] “Out Of Control”: Dozens of Telehealth Startups Sent Sensitive Health Information to Big Tech Companies https://themarkup.org/privacy/2022/12/13/out-of-control-dozens-of-telehealth-startups-sent-sensitive-health-information-to-big-tech-companies
Further Info ANNUAL LISTENER SURVEY!! https://fdsd.me/survey2023 * Data Privacy Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ * BitWarden vault backup: https://community.bitwarden.com/t/how-to-a-users-guide-to-backing-up-your-bitwarden-vault/44083 * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Facebook stock is down 65%, they just paid $725M to settle the Cambridge Analytica lawsuit, and they’ve just been fined over $400M by the EU. But that’s not the worst part (for Meta). The EU and its General Data Protection Regulation (GDPR) is basically saying that its entire business model – surveillance capitalism – is wrong and must stop. That’s the same business model used by Google, too. It really seems that the tide is finally turning in favor of user privacy as more nails are hammered into the coffin of behavior-based advertising.
In other news: the first LastPass class actions lawsuit has been filed over the recently announced data breach; WhatsApp adds a feature to bypass internet censorship by repressive regimes; Pornhub is now requiring viewers from Louisiana to verifying the age via ID; data from up to 400M Twitter accounts is up for sale; a military device containing information including biometric scans of over 2000 people was bought on eBay for $68; Mom and daughter kicked out of Rockettes show in Radio City Music Hall. Plus, a Dear Carey question and my Tip of the Week.
Article Links1. [TechRadar] LastPass is being sued following major cyberattack https://www.techradar.com/news/lastpass-is-being-sued-following-cyberattack 2. [The Washington Post] WhatsApp adds feature to bypass internet censors in repressive regimes https://www.washingtonpost.com/technology/2023/01/06/whatsapp-proxy-server-address/ 3. [The Verge] Meta agrees to pay $725 million to settle Cambridge Analytica class action lawsuit https://www.theverge.com/2022/12/23/23523862/meta-cambridge-analytica-class-action-lawsuit-settlement-725-million 4. [The Hacker News] Irish Regulators Fine Facebook $414 Million for Forcing Users to Accept Targeted Ads https://thehackernews.com/2023/01/irish-regulators-fine-facebook-414.html 5. [Ars Technica] Pornhub requires ID from Louisiana users to comply with state’s new porn law https://arstechnica.com/tech-policy/2023/01/no-porn-without-id-louisiana-law-forces-porn-sites-to-verify-users-ages/ 6. [Naked Security] Twitter data of “+400 million unique users” up for sale – what to do? https://nakedsecurity.sophos.com/2022/12/28/twitter-data-of-400-million-unique-users-up-for-sale-what-to-do/ 7. [The New York Times] For Sale on eBay: A Military Database of Fingerprints and Iris Scans https://www.nytimes.com/2022/12/27/technology/for-sale-on-ebay-a-military-database-of-fingerprints-and-iris-scans.html 8. [Ars Technica] MSG defends using facial recognition to kick lawyer out of Rockettes show https://arstechnica.com/tech-policy/2022/12/facial-recognition-flags-girl-scout-mom-as-security-risk-at-rockettes-show/ 9. [Lifehacker] You Can Disable Google Sign-in Pop-ups on All Websites https://lifehacker.com/you-can-disable-google-sign-in-pop-ups-on-all-websites-1849913714
Further Info ANNUAL LISTENER SURVEY!! https://fdsd.me/survey2023 * LastPass breach info: https://firewallsdontstopdragons.com/special-lastpass-breach/ * Peppering Your Passwords: https://firewallsdontstopdragons.com/password-manager-paranoia/ * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Right before Christmas, LastPass dropped a bombshell report explaining that bad actors appeared to have made copies of LastPass users’ encrypted password vaults. The information was a little short on key details, probably indicating that the investigation is ongoing and we will learn more in the coming weeks. However, we have already learned enough to know that the data breach did leak some important metadata contained in people’s password vaults and that any users who had less-than-secure master passwords should be worried that the encrypted contents may now be vulnerable to disclosure. That is about as bad as it gets. Today I will speak with a cybersecurity and authentication expert from CISA about this breach: what we know, what we don’t know, what we should learn from the incident, and (most importantly) what LastPass users should do about this.
Bob Lord is a Senior Technical Advisor for the Cybersecurity and Infrastructure Security Agency (CISA) and former Chief Information Security Officer (CISO) for Yahoo.
Interview Notes* SPECIAL REPORT: LastPass Breach: https://firewallsdontstopdragons.com/special-lastpass-breach/ * Twitter thread investigating what’s encrypted and what’s not: https://twitter.com/UK_Daniel_Card/status/1606012536582656000 * Write-up by a security researcher: https://www.pwndefend.com/2022/12/24/lastpass-breach-the-danger-of-metadata/ * Mastodon technical thread #1: https://mastodon.social/@epixoip@infosec.exchange/109585049690097599 * Mastodon technical thread #2: https://infosec.exchange/@WPalant/109590750504031700 * My “diceware” passphrase generator: https://d20key.com/ * My blog on creating strong passphrase: https://firewallsdontstopdragons.com/how-when-to-use-a-passphrase/ * How to make stronger passwords: https://firewallsdontstopdragons.com/need-a-bigger-password-haystack/ * Classic XKCD cartoons on passphrases: https://xkcd.com/936/ * Consumer Reports Security Planner: https://securityplanner.consumerreports.org/
Further Info Follow me on social media: https://firewallsdontstopdragons.com/contact/ * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book
Table of ContentsUse these timestamps to jump to a particular section of the show.
All our devices and apps use the internet these days. But what are they doing on the internet, exactly? Who are they talking to? You’d be surprised. But there are tools which will not only let you see what they’re up to, but also let you have fine-grain control over what communications you want to allow. But just the mere fact that they’re sending and receiving data to and from multiple sources can be revealing, too. While VPN’s are good for adding a layer of security, they’re really not great at adding privacy – despite having “private” in the name. Thankfully, there’s a new service that can help there, too. We’ll be discussing network privacy and how we can improve it with the CEO of Safing, Raphael Fiedler.
Raphael Fiedler is the CEO of Safing, a speaker on topics about privacy, and a regular co-host on an InfoSec podcast.
Interview Notes* Safing.io, Portmaster, Safing Privacy Network (SPN): https://safing.io/ * Securitized podcast: https://www.securityzed.com/ * The Hut Six Story: Breaking the Enigma Codes https://www.amazon.com/Hut-Six-Story-Breaking-Enigma/dp/0947712348 * Naomi Brockwell, The Dark Side of VPNs: https://www.youtube.com/watch?v=8MHBMdTBlok * OSI Layer Model: https://en.wikipedia.org/wiki/OSI_model * Nym network: https://nymtech.net/ * SPN white paper: https://safing.io/files/whitepaper/Gate17.pdf
Further Info 300th episode promotion: https://fdsd.me/ep300 * Patron promotion: https://fdsd.me/coinpromo * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of Contents* 0:00:35: Promotions update – last call! * 0:02:11: Interview preview * 0:04:41: How did Safing start? What problems are you trying to solve? * 0:07:57: What are the most likely threats to our home network? * 0:10:12: Are our devices and apps tattling on us? * 0:14:14: What can an application firewall do for us? * 0:17:04: Given broad use of HTTPS, do we need VPNs like we used to? * 0:19:30: Can we collect useful analytics and still preserve privacy? * 0:23:46: Which VPN marketing claims are bogus or misleading? * 0:29:31: How does a decentralized VPN work? * 0:33:10: What is the value of a decentalized VPN? * 0:35:13: How is your SPN different from a VPN? * 0:41:10: Who owns the SPN exit nodes? * 0:43:27: Can your SPN mix traffic amongst backbone providers? * 0:48:18: Can an SPN do anything to prevent fingerprinting? * 0:51:14: Does a multi-connection SPN confuse some websites or apps? * 0:54:28: How does the SPN compare to Tor or Apply Private Relay? * 1:00:22: What’s the roadmap look like for Portmaster and SPN? * 1:03:30: Wrap-up
The year is almost over and as we head into the holiday season I wanted to reminisce with some of my favorite snippets from the last year! Unlike in previous ‘best of’ shows, I’ve actually included some new snippets from my private podcast, to give you a little taste of the bonus content that I create for my patrons! The links in the show notes will take you to the full episodes, including all the relevant ‘further information’ links associated with them.
Happy holidays, everyone!!
Article Links1. Ep267: Luck Favors the Prepared https://podcast.firewallsdontstopdragons.com/2022/04/11/luck-favors-the-prepared/ 2. Ep279: Necessary Chaos: https://podcast.firewallsdontstopdragons.com/2022/07/04/necessary-chaos/ 3. Ep272: Tomatoes & Telegraphs: https://podcast.firewallsdontstopdragons.com/2022/05/23/tomatoes-telegraphs/ 4. Ep275: Cryptocurrency 101: https://podcast.firewallsdontstopdragons.com/2022/06/06/cryptocurrency-101/ 5. Ep283: How to Stop Tracking & Stalking: https://podcast.firewallsdontstopdragons.com/2022/05/09/how-to-stop-tracking-stalking/ 6. Ep287: The Night the Lights Went Out in Vegas: https://podcast.firewallsdontstopdragons.com/2022/08/29/the-night-the-lights-went-out-in-vegas/ 7. Ep289: Decoding Computers & Software: https://podcast.firewallsdontstopdragons.com/2022/09/12/decoding-computers-software/ 8. Ep292: Capture the Flag for Fun & Profit: https://podcast.firewallsdontstopdragons.com/2022/10/03/capture-the-flag-for-fun-profit/ 9. Steganography: https://en.wikipedia.org/wiki/Steganography
Further Info Give the gift of security and privacy! https://fdsd.me/coupons * 300th episode promotion: https://fdsd.me/ep300 * Patron promotion: https://fdsd.me/coinpromo * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Today when computer systems fail, they can cause real, physical harm. In just the last few years, we’ve seen cyber attacks interfere with our food supply, tamper with city water supplies, and disrupt gas pipelines. While cheap consumer electronics often have poor security, medical devices like insulin pumps and pacemakers are also vulnerable to attack – and the consequences of failure can be lethal. The free market doesn’t reward better security. Regulations are weak or nonexistent, regulators are understaffed and underfunded. Targeted organizations lack sufficient funding, training and personnel to prepare and respond. They need help. I Am the Cavalry aims to engage technologists and hackers to ride to the rescue.
Joshua Corman is VP of Cyber Safety Strategy at Claroty, Founder of I am The Cavalry, and formerly served as Chief Strategist for CISA regarding COVID, healthcare, and public safety.
Interview Links* I Am The Cavalry: https://iamthecavalry.org/ * BSides 2022 Cavalry presentation: https://www.youtube.com/watch?v=aw3egJej7so * The Cavalry Isn’t Coming (DEF CON 21 talk): https://www.youtube.com/watch?v=2kMGdkOMSK0 * Rugged Software Manifesto: https://github.com/rugged-software/rugged-software.github.io * CISA Bad Practices: https://www.cisa.gov/BadPractices * CISA Information Sharing and Awareness: https://www.cisa.gov/information-sharing-and-awareness * Maslow’s Hierarchy of Needs: https://www.simplypsychology.org/maslow.html * Click Here to Kill Everyone: https://www.schneier.com/books/click-here/ * SBOM interview: https://podcast.firewallsdontstopdragons.com/2021/07/19/its-time-to-drop-the-sbom/ * My Jeff Moss interview: https://podcast.firewallsdontstopdragons.com/2022/08/29/the-night-the-lights-went-out-in-vegas/
Further Info 300th episode promotion: https://fdsd.me/ep300 * Patron promotion: https://fdsd.me/coinpromo * Send me your questions! https://fdsd.me/qna * Subscribe to the newsletter:https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Become a Patron! https://www.patreon.com/FirewallsDontStopDragons * Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ * Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Tis the season for giving… and unfortunately, also for taking. Scammers tend to be extremely active during the holiday season. We’re buying lots of stuff online, having lots of packages delivered. We’re away from our homes for extended periods of time. We’re giving money to charities. We’re firing up new tech toys. The bad guys know this and are happy to take advantage of our chaotic holiday schedule and unusual levels of spending and giving. I’ll give you some top tips to avoid being a victim this holiday season.
In other news: the SFPD wants to arm its law enforcement robots; the TSA is expanding the use of facial recognition at airports; Microsoft warns of malware coming from Google Ads; a new study shows that computer repair shops may be accessing your personal data; WhatsApp data breach affects nearly 500M users; Twitter data breach was far worse than reported; Meta shuts down covert US propaganda operation; US watchdog raises warning for offshore oil and gas rig security; a new malware campaign bypasses Windows protections; LastPass admits to customer data breach caused by previous breach; and Anker’s Eufy cameras caught sending data to cloud without user consent.
Article Links1. [Electronic Frontier Foundation] Red Alert: The SFPD want the power to kill with robots https://www.eff.org/deeplinks/2022/11/red-alert-sfpd-want-power-kill-robots 2. [The Washington Post] TSA now wants to scan your face at security. Here are your rights. https://www.washingtonpost.com/technology/2022/12/02/tsa-security-face-recognition/ 3. [BleepingComputer] Brave starts showing “privacy-preserving” ads in search results https://www.bleepingcomputer.com/news/technology/brave-starts-showing-privacy-preserving-ads-in-search-results/ 4. [Tech.co] Microsoft Warns Hackers Use Google Ads to Deliver Ransomware https://tech.co/news/microsoft-warns-hackers-google-ads-ransomware 5. [Ars Technica] Thinking about taking your computer to the repair shop? Be very afraid https://arstechnica.com/information-technology/2022/11/half-of-computer-repairs-result-in-snooping-of-sensitive-data-study-finds/ 6. [TechRadar] WhatsApp data breach sees nearly 500 million user records up for sale https://www.techradar.com/news/whatsapp-data-breach-sees-nearly-500-million-user-records-up-for-sale 7. [9to5mac.com] Massive Twitter data breach was far worse than reported, reveal security researchers https://9to5mac.com/2022/11/25/massive-twitter-data-breach/ 8. [BleepingComputer] Meta links U.S. military with covert Facebook influence operation https://www.bleepingcomputer.com/news/security/meta-links-us-military-with-covert-facebook-influence-operation/ 9. [TechCrunch] US offshore oil and gas rigs at ‘significant’ risk of cyberattacks, warns watchdog https://techcrunch.com/2022/11/22/offshore-oil-gas-cyberattacks-watchdog/ 10. [TechRadar] This new malware is able to bypass all of Microsoft’s security warnings https://www.techradar.com/news/this-new-malware-is-able-to-bypass-all-of-microsofts-security-warnings 11. [Naked Security] LastPass admits to customer data breach caused by previous breach https://nakedsecurity.sophos.com/2022/12/02/lastpass-admits-to-customer-data-breach-caused-by-previous-breach/ 12. [MacRumors] Anker’s Eufy Cameras Caught Uploading Content to the Cloud Without User Consent https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/ 13. Tip of the Week: Tis the Season for Scams: https://firewallsdontstopdragons.com/how-to-avoid-holiday-scams/
Further Info Boston Dynamics robodog: https://www.youtube.com/watch?v=6Zbhvaac68Y * This Person Doesn’t Exist: https://thispersondoesnotexist.com/ * 300th episode promotion: https://fdsd.me/ep300 * Patron promotion: https://fdsd.me/coinpromo * Send me your questions! https://fdsd.me/qna * Support me! https://fdsd.me/support * Subscribe to the newsletter: https://fdsd.me/newsletter * Check out my book, Firewalls Don’t Stop Dragons*: https://fdsd.me/book * Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
I can’t believe I’ve been doing this for 300 weeks – almost 6 years now! And returning for his 3rd “podcentennial” episode is world-renowned security guru Bruce Schneier! Today we’ll discuss hacking – not just in the realm of computers, but in legal, political, social and economic spaces. And then we’ll talk about how artificial intelligence and computer automation are starting to play a significant role in hacking all of these realms. Computers and AI expand the scope, scale and speed of hacking and we’re honestly not prepared for it.
To celebrate the 300th episode and the coming release of the 5th edition of my book, today I’m kicking off a big giveaway with lots of prizes and a killer promotion for patrons on Patreon! (See below for links.)
Bruce Schneier is an internationally renowned technologist and security guru. He is the author of over one dozen books, including his latest, A Hacker’s Mind, due out in February, I believe. He has testified before Congress and has served on several government committees and corporate boards, written many seminal papers, has a very popular blog called Crypto-Gram, and last but not least, Bruce is the Chief of Security Architecture at Inrupt.
Further Info 300th episode promotion: https://firewallsdontstopdragons.com/enter-to-win-300th-podcast-giveaway/ * Patron promotion: https://www.patreon.com/posts/december-patron-75151773 * The Coming AI Hackers: https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html * A Hacker’s Mind book: https://www.schneier.com/books/a-hackers-mind/ * Give the gift of security & privacy: https://firewallsdontstopdragons.com/give-the-gift-of-security-and-privacy/ * Check out my Best & Worst Gifts Guide for 2022: https://firewallsdontstopdragons.com/best-worst-gifts-2022/ * The Coming AI Hackers: https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html * A Hacker’s Mind book: https://www.schneier.com/books/a-hackers-mind/ * The Trolley Problem: https://en.wikipedia.org/wiki/Trolley_problem * Gödel’s incompleteness theorems: https://en.wikipedia.org/wiki/G%C3%B6del’s_incompleteness_theorems * Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/ * Check out my book, Firewalls Don’t Stop Dragons*: https://www.amazon.com/gp/product/1484261887 * Become a Patron! https://www.patreon.com/FirewallsDontStopDragons * Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ * Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker * Generate secure passphrases! https://d20key.com/#/
Table of ContentsUse these timestamps to jump to a particular section of the show.
Black Friday is just around the corner, which marks the unofficial launch of the holiday shopping season. As you're considering what gifts to give to your loved ones this year, I want to make sure you're thinking about the privacy and security aspects. To that end, I have updated my annual Best and Worst Gift Guide and I will go over the highlights in this episode for my Tip of the Week. But I also have a special new gift idea this year: security and privacy coupons that you can download and give to your loved ones!
In the news: USPS tells customers to avoid using the big blue mailboxes for gifts and important letters during the holiday season; Google pays nearly $400M fine to 40 states who sued over location tracking; Medibank refuses to pay ransom for data and criminals are starting to leak sensitive medical records online; TransUnion reports a data breach; FBI director warns that TikTok is a national security risk; Lenovo laptops are exposed to UEFI malware risks (update now); a mysterious company with government ties and a history of spying has become a root certificate authority; the British government is scanning its citizens devices looking for vulnerabilities in hopes of fixing them; almost 50% of all Mac malware can be traced to a single, security application; Apple apps are sending tons of analytics data to Apple even when analytics are disabled; I answer a listener question (Dear Carey) about the best Mastodon clients, in the wake of the Twitter collapse.
Article Links
[Lifehacker] Avoid Using Blue Mailboxes During the Holidays, USPS Warns https://lifehacker.com/avoid-using-blue-mailboxes-during-the-holidays-usps-wa-1849773201
[The Hacker News] Google to Pay $391 Million Privacy Fine for Secretly Tracking Users' Location https://thehackernews.com/2022/11/google-to-pays-391-million-privacy-fine.html
[CPO Magazine] Medibank Refuses Ransom Payments, Hackers Leak Stolen Health Data to Dark Web https://www.cpomagazine.com/cyber-security/medibank-refuses-ransom-payments-hackers-leak-stolen-health-data-to-dark-web/
[BGR] TransUnion data breach compromises financial information of consumers https://bgr.com/tech/transunion-data-breach-compromises-financial-information-of-consumers/
[USA TODAY] FBI director says TikTok poses national security threat, and he's 'extremely concerned' https://www.usatoday.com/story/tech/2022/11/16/tiktok-poses-national-security-threat-fbi/10709987002/
[Ars Technica] Lenovo driver goof poses security risk for users of 25 notebook models https://arstechnica.com/information-technology/2022/11/lenovo-patches-secure-boot-vulnerabilities-that-imperil-25-notebook-models/
[The Washington Post] Mysterious company with government ties plays key internet role https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/
[Bleeping Computer] British govt is scanning all Internet devices hosted in UK https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/british-govt-is-scanning-all-internet-devices-hosted-in-uk/amp/
[Tom's Guide] Almost 50% of macOS malware reportedly comes from single app — delete it now https://www.tomsguide.com/news/new-report-says-nearly-half-of-macos-malware-comes-from-single-app-delete-it-now
[Gizmodo] Apple Is Tracking You Even When Its Own Privacy Settings Say It’s Not, New Research Says https://gizmodo.com/apple-iphone-analytics-tracking-even-when-off-app-store-1849757558
Dear Carey: Mastodon clients.
https://joinmastodon.org/apps
https://bilge.world/mastodon-ios-apps
Further Info
Best & Worst Gifts for 2022: https://firewallsdontstopdragons.com/best--worst-gifts-2022/
Privacy & Security Coupons: https://fdsd.me/coupons
Give thanks and donate! https://firewallsdontstopdragons.com/give-thanks-donate/
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://firewallsdo...
Connected computers have changed the world perhaps more than any other single invention. The impacts of nearly instant global communication and effectively infinite, perfect storage of information are at once undeniable and difficult to fully comprehend. And yet, technologists, bureaucrats and corporate leaders make decisions on a daily basis that should be considering the repercussions. Just because you can do something doesn't mean you should. Today, we'll discuss the digitization of the world and some of the more important impacts it has had and is having on society with the authors of the book Blown to Bits: Your Life, Liberty, and Happiness After the Digital Explosion.
Harry Lewis, former Dean of Harvard College, is Gordon McKay Professor of Computer Science at Harvard. Ken Ledeen is the Chairman and Chief Executive Officer at Nevo Technologies, Inc., a software development and information technology consulting firm located in Cambridge, Massachusetts. Wendy Seltzer is Strategy Lead and Counsel to the World Wide Web Consortium (W3C) at MIT, improving the Web’s security, availability, and interoperability through standards.
Further Info
Buy or download Blown to Bits: https://www.bitsbook.com/thebook/
Weird Marketing Tales interviewed me: https://weirdmarketingtales.com/why-firewalls-dont-stop-dragons-carey-parker-privacy-security/
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/
Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons
Donate directly with Monero! https://firewallsdontstopdragons.com/contact/
Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:03:16: interview start
0:04:03: What brought you all together to write this book?
0:05:28: What are the biggest changes since the first edition?
0:10:04: What were the impacts of the Edward Snowden revelations?
0:12:44: How do we resolve the tension between privacy and law enforcement?
0:16:43: Are computer systems free from bias?
0:19:22: How do algorithms impact judicial decisions?
0:20:45: Why is it hard to explain how AI systems make decisions?
0:28:33: What is net neutrality and who are the gatekeepers today on the internet?
0:31:59: Have we lost the original Utopian ideal of the internet?
0:35:41: How have content moderation and personalization affected our experience?
0:40:48: How do these companies hyper-personalize the web?
0:45:44: Are we changing our own behaviors to game the algorithms?
0:47:35: Are bits more fragile than parchment and cave paintings?
0:53:29: What gives you hope? What keeps you up at night?
0:58:12: Interview wrap-up
0:59:34: Upcoming shows, promotions, interviews
QR codes are not inherently dangerous. They're effectively links we can click in the real world using the camera app on our phone. Like hyperlinks on a web page, QR code "links" can take you to good websites or bad websites. They can also disguise their ultimate destination by using URL shortening services like bitly or owly. But now "free" QR code generator websites - that is, sites that will let you create one of these QR codes by entering the HTTP link you want it to take people to - are using these redirects to basically hold your QR code for ransom. The QR codes they give you use the redirect links to insert themselves into the middle - and after some time, they will stop working until you subscribe and pay them money. If you've already printed these codes on hundreds of business cards or dozens of plaques for your restaurant, they they've really got you over a barrel. I'll help you avoid these scams.
In other news: Microsort warns that attackers are quickly leveraging newly reported zero-days; some Chrome extensions are making money by inserting affiliate links for thousands of websites; Microsoft appears to be readying a useful PC cleanup tool for release; Apple clarifies its policy on security updates for older OS releases; a report details how hidden AI algorithms are affecting the lives of DC residents; facial recognition systems are being installed in many soccer stadiums; Uber is planning to bombard their users with ads; Clearview AI has been fined 30M euros by France; Apple is ramping up its own ads on its various apps and devices; and I answer another Dear Carey question, this one on the case that is bringing Section 230 in front of the Supreme Court.
Article Links
[Hacker News] Microsoft Warns of Uptick in Hackers Leveraging Publicly-Disclosed 0-Day Vulnerabilities https://thehackernews.com/2022/11/microsoft-warns-of-uptick-in-hackers.html
[BleepingComputer] Chrome extensions with 1 million installs hijack targets’ browsers https://www.bleepingcomputer.com/news/security/chrome-extensions-with-1-million-installs-hijack-targets-browsers/
[PCWorld] Microsoft’s surprise PC Manager system optimizer takes aim at CCleaner https://www.pcworld.com/a rticle/1360140/microsoft-releases-beta-of-a-ccleaner-style-pc-manager-tool.html
[Ars Technica] Apple clarifies security update policy: Only the latest OSes are fully patched https://arstechnica.com/gadgets/2022/10/apple-clarifies-security-update-policy-only-the-latest-oses-are-fully-patched/
[WIRED] Algorithms Quietly Run the City of DC—and Maybe Your Hometown https://www.wired.com/story/algorithms-quietly-run-the-city-of-dc-and-maybe-your-hometown/
[WIRED] Soccer Fans, You’re Being Watched https://www.wired.com/story/soccer-world-cup-biometric-surveillance/
[Gizmodo] Uber Plans to Advertise to You At Every Stage of Your Ride, Using Your Own Data https://gizmodo.com/uber-ads-ride-share-uber-eats-1849678092
[Naked Security] Clearview AI image-scraping face recognition service hit with €20m fine in France https://nakedsecurity.sophos.com/2022/10/26/clearview-ai-image-scraping-face-recognition-service-hit-with-e20m-fine-in-france/
[Lifehacker] How to Block Apple’s Own Ads on Your iPhone https://lifehacker.com/how-to-block-apple-s-own-ads-on-your-iphone-1849703889
Tip of the Week: https://firewallsdontstopdragons.com/qr-code-scams-revisited/
Further Info
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/
Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:42: Countdown to 300
It's easy to tell people to use this or that privacy tool, but this always assumes that you trust the service that is providing that tool. How can mere mortals ever hope to obtain sufficient knowledge of the inner workings of these products and service providers that would allow them to make an informed decision? Today, I'll ask Adrianus Warmenhoven from Nord VPN that question, along with questions about normalizing surveillance and what privacy really means in our digital internet society.
Adrianus Warmenhoven is a Defensive Strategist and Threat Intelligence Manager at NordVPN. He is responsible for getting the most relevant IOCs (Indicators of Compromise), malware samples and their indicators and generally mapping out the threat landscape for the company’s customers.
Interview Links
Nord VPN: https://nordvpn.com/The Follower: https://driesdepoorter.be/thefollower/ Five-Eyes Countries: https://en.wikipedia.org/wiki/Five_Eyes Electronic Frontier Foundation: https://www.eff.org/ Mozilla Foundation: https://foundation.mozilla.org/en/ Give thanks and donate: https://firewallsdontstopdragons.com/give-thanks-donate/
Further Info
Send me your questions! https://fdsd.me/qna Support me! https://fdsd.me/support Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:26: Elon Musk buys Twitter0:01:31: What is Mastodon?0:02:36: Interview preview0:04:13: Tell us about Nord and what you do there0:05:25: What is most misunderstood about privacy?0:07:53: How does my privacy overlap your privacy?0:10:08: What threats to privacy aren't getting enough attention?0:13:02: Doesn't capitalism require companies to monetize our data?0:16:26: Is it possible compartmentalize our lives today?0:18:32: Why can't we learn that just because we can doesn't mean we should?0:22:09: How does privacy in the physical world differ from online?0:24:21: Have we normalized surveillance for the younger generation?0:30:22: How do we know which companies to trust with our privacy?0:38:11: How can companies avoid gathering user data?0:42:47: How important is transparency for consumers?0:45:48: How do VPNs work and how do they fail?0:48:46: How important is it for privacy companies to be in favorable jurisdictions?0:52:19: How can I get more involved with privacy rights?0:56:03: What gives you hope?0:57:59: Bonus content0:58:54: Interview wrapup1:01:51: Give thanks and donate1:03:17: Dear Carey - ask me a question1:04:13: Upcoming stuff
This is going to sound bonkers, even though you're used to so many things tracking you... web pages, emails, and apps... but I'm here to tell you that while you're watching your TV, your TV is also watching you. Or I guess more accurately, your TV is watching what you're watching. Even if you're not using the built-in smart apps, if you're just piping pixels in from an external box, your TV can recognize the movies and shows being displayed. And it's taking meticulous taking notes and selling that data. It's called Automatic Content Recognition and "post-purchase monetization". It's sorta like the Shazam music recognition app, but for TV shows and movies. I'll tell you what you can do to stop it.
In other news: a tricky new ransomware campaign is targeting home Windows users; Signal is removing support for SMS text messaging; Toyota user app data was exposed for years; the White House unveiled a new cybersecurity rating system for consumer products; Apple privacy is better than most, but still falls short; a privacy researcher tries and fails to keep her pregnancy secret from marketers; companies in the UK are tailoring real-life billboards using cameras and AI; relief funds were sent to people impacted by Hurricane Ian using AI algorithms; Facebook's new VR headset will mine your facial expressions for marketing; Wired article gives tips for avoiding student surveillance tools.
Article Links
[ZDNet] This unusual ransomware attack targets home PCs, so beware https://www.zdnet.com/article/this-unusual-ransomware-attack-targets-home-pcs-so-beware/[Signal] Removing SMS support from Signal Android (soon) https://signal.org/blog/sms-removal-android/[BleepingComputer] Toyota discloses data leak after access key exposed on GitHub https://www.bleepingcomputer.com/news/security/toyota-discloses-data-leak-after-access-key-exposed-on-github/[CyberScoop] White House to unveil ambitious cybersecurity labeling effort modeled after Energy Star https://www.cyberscoop.com/white-house-to-unveil-internet-of-things-labeling/[The Atlantic] I Tried to Keep My Pregnancy Secret https://www.theatlantic.com/ideas/archive/2022/10/can-you-hide-your-pregnancy-era-big-data/671692/[The Guardian] Apple says it prioritizes privacy. Experts say gaps remain https://www.theguardian.com/technology/2022/sep/23/apple-user-data-law-enforcement-falling-short[VICE] Companies in the UK Are Mining Users’ Personal Data to Place Billboard Ads https://www.vice.com/en/article/n7zqmb/companies-in-the-uk-are-mining-users-personal-data-to-place-billboard-ads[WIRED UK] Hurricane Ian Destroyed Their Homes. Algorithms Sent Them Money https://www.wired.co.uk/article/hurricane-ian-destroyed-homes-google-algorithms-sent-money[Gizmodo] Meta’s New Headset Will Track Your Eyes for Targeted Ads https://gizmodo.com/meta-quest-pro-vr-headset-track-eyes-ads-facebook-1849654424[WIRED] How to Protect Yourself If Your School Uses Surveillance Tech https://www.wired.com/story/how-to-protect-yourself-school-surveillance-tech-privacy/Tip of the Week: https://firewallsdontstopdragons.com/your-tv-is-watching-you/
Further Info
Send me your questions! https://fdsd.me/qna Support me! https://fdsd.me/support Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:27: News rundown0:03:40: Sneaky new Windows ransomware targets home users0:07:20: Signal drops support for SMS on Android0:14:53: Toyota leak exposed car app data for 5 years0:18:27: White House cybersecurity product labeling initiative0:21:54: Privacy scholar tries and fails to keep pregnancy secret0:28:28: Apple still had glaring privacy holes0:33:...
We talk a lot about security and privacy on my show, but we don't talk enough about these subjects in relation to students and schools. Schools are tragically underfunded and can't afford to hire cybersecurity experts, let alone privacy experts. Students are minors who lack the legal rights and life experience to push back against horrific privacy invasions brought on by remote learning and in-home test proctoring. The laws in the US are woefully outdated and we too often assume that what is legal is the same as what is right and just. Today, I'll discuss these challenges and ethical dilemmas with Doug Levin.
Doug Levin is co-founder and national director of the K12 Security Information eXchange (K12 SIX), a national non-profit dedicated solely to helping schools protect themselves from emerging cybersecurity threats.
Interview Links:
K12 SIX: https://www.k12six.org/Annual “State of K-12 Cybersecurity Report’: https://www.k12six.org/the-report K-12 Essentials Series: https://www.k12six.org/essentials-series Public event calendar: https://www.k12six.org/events US Department of Education, Privacy Technical Assistance Center: https://studentprivacy.ed.gov/ CISA K-12 Cybersecurity Resources: https://www.cisa.gov/stopransomware/k-12-resources CISA Back to School Campaign: https://www.cisa.gov/r8-virtual-back-school-campaign-2022 US GAO: “Critical Infrastructure Protection: Education Should Take Additional Steps to Help Protect K-12 Schools from Cyber Threats” https://www.gao.gov/products/gao-22-105024 EFF: Student Privacy Resources https://www.eff.org/issues/student-privacy CDT: Student Privacy Resources https://cdt.org/area-of-focus/privacy-data/student-privacy/ EPIC: Student Privacy https://epic.org/issues/data-protection/student-privacy /Algorithmic Justice League: https://www.ajl.org/ The Markup: https://themarkup.org/machine-learning/2022/01/19/help-us-investigate-the-ed-tech-industry Fight for the Future, which e.g., runs this campaign: https://www.baneproctoring.com/ ACLU: https://www.nyclu.org/en/issues/education-policy-center/technology-schools
Further Info
Send me your questions! https://fdsd.me/qna Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:03:24: Pre-interview definition of terms0:05:07: What is K12SIX about?0:10:52: What are the biggest security threats for schools?0:17:15: What about security threats for teachers and students?0:21:58: What are your top security recommendations for schools?0:30:01: What are the major impediments for schools improving cybersecurity?0:33:20: How can schools systems best share info and help one another?0:37:41: What are the main privacy threats for students?0:46:25: How is student data being used (or abused)?0:48:36: How do AI systems fail when it comes to minority populations?0:51:32: How can students and parents assert their privacy rights?0:56:03: What resources can you recomment for schools and students?0:59:39: Interview wrap-up1:00:40: Not reusing user names and passwords1:02:20: Preview of upcoming shows, promotions
Cold hard cash is becoming more and more rare these days. People just don't carry it around much any more. So how do you split a bill at a restaurant or buy from a street vendor? Many people today use mobile payment apps like Venmo, Apple Pay, PayPal, the Cash App, or a service promoted by many US banks called Zelle. While convenient, are these payment systems safe? Most of them actually are pretty secure (though some of them are not very private, like Venmo). But because most of these apps draw directly from your bank account, if you send money to the wrong person, either by mistake or because you were scammed, that money is pretty much gone. Ironically, this is very much like physical cash. Specifically, protections many people assume they have against fraudulent bank transactions don't really apply. You explicitly made the transfer and therefore many banks will not reimburse you for the loss.
In other news: Optus confirms massive data breach; Optus breach triggers privacy regulation review in Australia; Facebook shuts down propaganda campaigns from Russia and China; Facebook warns 1M users of potential credential theft; Google will be migrating Fitbit customers to Google accounts; Microsoft adds new protections to warn you of PC password reuse and insecure storage; the FTC is pushing for new rules around location data collection and sharing; Google releases new tool to help purge personal information from its search results.
Article Links
[BleepingComputer] Optus confirms 2.1 million ID numbers exposed in data breach https://www.bleepingcomputer.com/news/security/optus-confirms-21-million-id-numbers-exposed-in-data-breach/[The Verge] Australia to overhaul privacy laws after massive data breach https://www.theverge.com/2022/9/26/23372868/australian-hack-disclosure-privacy-laws-optus-data-breach[Hacker News] Facebook Shuts Down Covert Political 'Influence Operations' from Russia and China https://thehackernews.com/2022/09/facebook-shuts-down-covert-political.html[9to5mac.com] Facebook security warning for 1M users: Scam apps stole login credentials https://9to5mac.com/2022/10/07/facebook-security-warning/[Hacker News] Google to Make Account Login Mandatory for New Fitbit Users in 2023 https://thehackernews.com/2022/09/google-to-make-account-login-mandatory.html[Lifehacker] Microsoft Has a New Trick for Keeping Your Password Safe https://lifehacker.com/microsoft-has-a-new-trick-for-keeping-your-password-saf-1849580498[Bloomberg] FTC Joins Push for Rules on Trade of Smartphone Location Data https://www.bloomberg.com/news/articles/2022-09-16/location-data-rules-draw-ftc-s-attention-post-roe[The Verge] In 2023, Google can notify you if personal info pops up in search https://www.theverge.com/2022/9/28/23377208/google-results-about-you-notifications-personal-info[briankrebs] Report: Big U.S. Banks Are Stiffing Account Takeover Victims https://krebsonsecurity.com/2022/10/report-big-u-s-banks-are-stiffing-account-takeover-victims/
Further Info
National Cybersecurity Awareness Month: https://www.cisa.gov/cybersecurity-awareness-monthConsumer Reports: payment apps: https://www.consumerreports.org/digital-payments/how-to-safely-pay-for-goods-and-services-with-someone-you-dont-know/ Send me your questions! https://fdsd.me/qna Support me! https://fdsd.me/support Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:42: News rundown0:02:49: 10 Million Optus users affected by breach0:06:04: Optus breached via open web interface0:10:28: Facebook shuts down political influence campaigns0:13:38: Facebook warns 1M users of potential credential the...
Cybersecurity is the only technical, professional occupation I know of where practitioners routinely sharpen their skills through open competitions. The contests are based on the classic capture the flag game - except the flags are all virtual and capturing them involves hacking computers. Also unlike most other technical careers, cybersecurity is a high-paying profession that doesn't require a university degree or formal training. There are literally hundreds of thousands of unfilled cybersecurity jobs right now. You can also just dabble in cybersecurity, making money from bug bounty programs. Or you can just hack for the fun of it - in a completely safe and legal environment. Jordan will tell you all about it in today's show!
Jordan Wiens has been a reverse engineer, vulnerability researcher, network security engineer, three-time DEF CON CTF winner, even a technical magazine writer but now he's mostly a has-been CTF player who loves to talk about them. He has been the CTF expert for the first three years of HackASat and he was one of the founders of Vector 35, the company that makes Binary Ninja.
Interview Links
Hack-A-Sat 3: https://hackasat.com/ Satellite hacked using $25 hardware: https://threatpost.com/starlink-hack/180389/ Decommissioned satellite hacked to broadcast movie: https://www.independent.co.uk/tech/hack-satellite-hijack-def-con-b2147595.html Student Rick-Rolls school: https://www.malwarebytes.com/blog/news/2021/10/high-school-student-rickrolls-entire-school-district-and-gets-praised Hack-A-Sat 2 interview: https://podcast.firewallsdontstopdragons.com/2021/06/21/hacking-satellites-for-fun-profit/ Plaid CTF: https://plaidctf.com/ CTFTime.org: https://ctftime.org/ Pwnable.kr: https://pwnable.kr/ Pwnable.tw: https://pwnable.tw/ Reversing.kr: http://reversing.kr/ Shodan: https://www.shodan.io/Burp Suite: https://portswigger.net/burp Wireshark: https://www.wireshark.org/ Binary Ninja: https://binary.ninja/ Metasploit: https://www.metasploit.com/ Nmap: https://nmap.org/ Live Overflow: https://liveoverflow.com/ TryHackMe: https://tryhackme.com/
Further Info
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Support my work! https://firewallsdontstopdragons.com/support/ Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequestGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:03: Interview setup0:04:25: What is Hack-A-Sat?0:08:44: How has the Hack-A-Sat program evolved?0:12:58: How did CTF's start out and when did they become popular?0:17:37: Why do we have so many unfilled cybersecurity jobs?0:21:15: Do you need a college degree to work in cybersecurity?0:29:39: What's a black hat hacker vs white hat? What's a red team or blue team?0:32:15: How do CTF's actually work? What is a flag and how do I capture it?0:38:05: Are they beginner CTFs that are free to try?0:44:38: What sorts of tools do hackers use in CTFs and in real hacking?0:51:57: How do hackers chain together multiple exploits?0:56:26: What's your advice to someone who would like to try a CTF?1:00:36: What's next for Hack-A-Sat?1:02:25: interview wrapup1:04:07: What is Rick-Rolling?1:05:23: Try a CTF, go to a hacker con!
Apple just released a major update to its iPhone operating system, iOS 16. This release has some really important security and privacy features, including Passkeys, Lockdown Mode and Safety Check. I’ll give you an overview of these features.
In other news: D-Link routers have a major vulnerability that’s being actively exploited; Uber was completely pwned by a cocky 18-year old hacker; Morgan Stanley was fined $35 million for failing to delete user data from hundreds of hard drives before reselling them; Chrome and Edge may be sending your form data back to Google and Microsoft; a new voice AI tool lets you change your voice to sound like someone else; health apps are sharing your personal data and HIPAA isn’t helping; the US military is using yet another data broker to buy incredibly detailed information on almost all internet users; US border agents can search your phone and even copy your phone’s data, and may save that info for 15 years; your car is coughing up tons of personal and auto data to dozens of data companies; Intel’s new AI will be used to find students who are confused or even emotionally distressed.
Article Links
[BleepingComputer] Moobot botnet is coming for your unpatched D-Link router https://www.bleepingcomputer.com/news/security/moobot-botnet-is-coming-for-your-unpatched-d-link-router/[WIRED] The Uber Hack’s Devastation Is Just Starting to Reveal Itself https://www.wired.com/story/uber-hack-mfa-phishing/[Ars Technica] $35M fine for Morgan Stanley after unencrypted, unwiped hard drives are auctioned https://arstechnica.com/information-technology/2022/09/morgan-stanley-pays-35m-penalty-for-extensive-failure-to-safeguard-customer-data/[BleepingComputer] Google, Microsoft can get your passwords via web browser’s spellcheck https://www.bleepingcomputer.com/news/security/google-microsoft-can-get-your-passwords-via-web-browsers-spellcheck/[Ars Technica] With Koe Recast, you can change your voice as easily as your clothing https://arstechnica.com/information-technology/2022/09/with-koe-recast-you-can-change-your-voice-as-easily-as-your-clothing/[The Washington Post] Health apps share your concerns with advertisers. HIPAA can’t stop it. https://www.washingtonpost.com/technology/2022/09/22/health-apps-privacy/[VICE] Revealed: U.S. Military Bought Mass Monitoring Tool That Includes Internet Browsing, Email Data https://www.vice.com/en/article/y3pnkw/us-military-bought-mass-monitoring-augury-team-cymru-browsing-email-data[Engadget] US border forces are seizing Americans’ phone data and storing it for 15 years https://www.engadget.com/us-border-forces-traveler-data-15-years-085106938.html[The Washington Post] How to prevent customs agents from copying your phone’s content https://www.washingtonpost.com/technology/2022/09/18/phone-data-privacy-customs/[The Markup] Who Is Collecting Data from Your Car? – The Markup https://themarkup.org/the-breakdown/2022/07/27/who-is-collecting-data-from-your-car[Protocol] Intel thinks its AI knows what students think and feel in class https://www.protocol.com/enterprise/emotion-ai-school-intel-edutechTip of the Week: https://firewallsdontstopdragons.com/ios-16-privacy-security/
Further Info
Koe Recast web demo: https://koe.ai/recast/ 100-mile US border zone: https://www.aclu.org/other/constitution-100-mile-border-zone Tech Model Railroad Club: https://en.wikipedia.org/wiki/Tech_Model_Railroad_Club Send me your questions! https://firewallsdontstopdragons.com/dear-carey-podcast-qa/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
You may not be into cryptocurrency, but a recent incident involving a so-called "cryptocurrency mixer" has some important implications for privacy and free speech. Today we'll examine the relative anonymity of cryptocurrency transactions, tools that can be used to enhance that anonymity, and why the code that created these tools - and the services that might host them - must be protected under the First Amendment. Along the way, we'll explore the limits of free speech in the US and some interesting attempts to capture those rights.
Kurt Opsahl is the Deputy Executive Director and General Counsel of the Electronic Frontier Foundation, the leading nonprofit defending digital privacy, free speech, and innovation.
Interview Links
Coin Center article on Tornado Cash: https://www.coincenter.org/analysis-what-is-and-what-is-not-a-sanctionable-entity-in-the-tornado-cash-case/ Electronic Frontier Foundation: https://www.eff.org/ Code, Speech, and the Tornado Cash Mixer https://www.eff.org/deeplinks/2022/08/code-speech-and-tornado-cash-mixer Treasury Dept sued over Tornado Cash sanctions: https://fortune.com/2022/09/08/coinbase-employees-and-ethereum-backers-sue-u-s-treasury-over-tornado-cash-sanctions/
Further Info
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:42: Interview setup0:02:43: How anonymous are cryptocurrency transactions?0:07:30: What is a cryptocurrency mixer and why would I use one?0:10:34: Kurt's thoughts on "going dark"0:12:45: Physical currency is not technically anonymous, either0:14:07: How did the White House try to fix this problem?0:15:27: Who is OFAC and what is the SDN list?0:16:57: Who or what is Tornado Cash?0:20:23: What about Tornado Cash drew scrunity from the US Gov't?0:22:08: How does all of this relate to free speech?0:26:22: One of the developers was arrested - what's the EFF's take on this?0:29:14: Is a platform responsible for illegal activities related to content they host?0:31:18: What's the limit of free speech when it comes to software code?0:41:00: What free speech rights to platforms themselves have?0:44:42: What about attempts to turn code into books or T-shirts to gain protection?0:48:04: What's next for the Tornado Cash case?0:55:12: Interview wrap-up0:55:46: Looking ahead
A little over 20 years ago, Charles Petzold wrote what would become a classic book on understanding modern computers and the software that drives them. Computers have become essential to daily life and inhabit more and more of the devices we use every day. Every "smart" device you own contains a computer running software. While these little silicon chips and the binary code running them seem like magic, they're really just a series of simple building blocks chained together to accomplish a task. Having a basic understanding of these concepts can give us a lot more perspective on how computers can be used and abused, programmed and subverted.
When I learned that Charles was releasing a fully updated 2nd edition of Code, I asked him to come on the show to give us all a historical overview of computers and software. He graciously agreed. The concepts of computing and programming go back a lot further than you might think. Today we'll learn about this and much more.
Charles Petzold is the author of the books Code, The Annotated Turing, and numerous programming tutorials involving Microsoft Windows.
Interview Notes
Code: The Hidden Language of Computer Hardware and Software: https://www.charlespetzold.com/books/ Companion website: https://codehiddenlanguage.com/ The Annotated Turing: https://www.charlespetzold.com/AnnotatedTuring/ Alan Turing: https://en.wikipedia.org/wiki/Alan_Turing Ada Lovelace: https://en.wikipedia.org/wiki/Ada_Lovelace Delay Line Mercury Storage: https://en.wikipedia.org/wiki/Delay-line_memory#Mercury_delay_lines Steganography: https://en.wikipedia.org/wiki/Steganography
Further Info
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:08: Hold off on iOS 16 update0:02:47: Preview of today's interview0:05:49: Why did you write this book and who was your target audience?0:11:03: Why should we understand the basics of computing?0:12:39: What IS a "computer", fundamentally?0:16:35: Where did computers start, historically?0:19:21: What's the origin of software and programming computers?0:22:14: How did we store computer programs before hard drives?0:25:30: How did encoding enable us to communicate over large distances?0:30:00: How do we measure progress in computing?0:34:24: How did you decide how to lay out the concepts in the book?0:39:29: How can understanding computers help us be more secure?0:43:17: What does the future of computing look like?0:49:58: What will your next book be about?0:53:55: Interview wrap-up0:54:53: My Google rant0:58:03: A bit on steganography and codes0:59:41: Upcoming shows, schedule change
Password manager software maker LastPass suffered a data breach last week, which understandably made their customers very nervous - and caused some people to question the decision to put all their passwords in one digital basket. In today's show, I'll explain why this particular breach was not a threat to anyone's passwords and why you should still use a high quality password manager.
In other news: Former security chief blows the whistle on Twitter; major VPN providers are pulling out of India over surveillance law issues; a set of popular Chrome extensions caught committing click fraud; Google's new Chrome extension restrictions threaten to hobble ad blockers; a father's Google accounts are deleted over false AI-flagged CSAM; US Federal Trade Commission sues a data broker over lax protection of location data; EFF finds another data broker selling location data to law enforcement; Google launches bug bounty program for open source software projects; DuckDuckGo's email privacy protection feature now available to all; Ohio judge rules that scanning students' rooms before tests is illegal; a flight to Cabo is nearly grounded thanks to a passenger sending dick pics to other passengers, including one of the pilots.
Article Links
[The Washington Post] Former security chief claims Twitter buried ‘egregious deficiencies’ https://www.washingtonpost.com/technology/interactive/2022/twitter-whistleblower-sec-spam/[9to5mac.com] Major VPN services shut down in India over anti-privacy law; Apple hasn’t yet commented https://9to5mac.com/2022/09/01/major-vpn-services/[BleepingComputer] Chrome extensions with 1.4 million installs steal browsing data https://www.bleepingcomputer.com/news/security/chrome-extensions-with-14-million-installs-steal-browsing-data/[BleepingComputer] AdGuard’s new ad blocker struggles with Google’s Manifest v3 rules https://www.bleepingcomputer.com/news/security/adguard-s-new-ad-blocker-struggles-with-google-s-manifest-v3-rules/[The New York Times] A Dad Took Photos of His Naked Toddler for the Doctor. Google Flagged Him as a Criminal. https://www.nytimes.com/2022/08/21/technology/google-surveillance-toddler-photo.html[Reuters] U.S. FTC sues data broker Kochava for alleged sale of sensitive data https://www.reuters.com/legal/us-ftc-sues-data-broker-kochava-alleged-sale-sensitive-data-2022-08-29/[Electronic Frontier Foundation] Data Broker Helps Police See Everywhere You’ve Been with the Click of a Mouse: EFF Investigation https://www.eff.org/press/releases/data-broker-helps-police-see-everywhere-youve-been-click-mouse-eff-investigation[Naked Security] LastPass source code breach – do we still recommend password managers? https://nakedsecurity.sophos.com/2022/08/29/lastpass-source-code-breach-do-we-still-recommend-password-managers/[Decipher] Google Launches Bug Bounty Program For Open Source Projects https://duo.com/decipher/google-launches-bug-bounty-program-for-its-open-source-projects[Spread Privacy] Protect Your Inbox: DuckDuckGo Email Protection Beta Now Open to All! https://spreadprivacy.com/protect-your-inbox-with-duckduckgo-email-protection/[The Verge] University can’t scan students’ rooms during remote tests, judge rules https://www.theverge.com/2022/8/23/23318067/cleveland-state-university-online-proctoring-decision-room-scan[VICE] Creeps Airdropping Dick Pics Just Made Flying Even Worse https://www.vice.com/en/article/3adag9/southwest-tiktok-video-pilot-airdropped-nudesTip of the Week: How to Prevent Cyberflashing https://firewallsdontstopdragons.com/how-to-prevent-cyberflashing/
Further Info
Peppering Your Passwords: https://firewallsdontstopdragons.com/password-manager-paranoia/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero!
Thirty years ago, a young hacker named Jeff Moss (aka The Dark Tangent) threw a party in the desert of Nevada to commemorate the demise of a bulletin board system called PlatinumNet. Unlike the other handful of hacker conferences in that time, this one would be on the West Coast and open to everyone. Over the next three decades, DEF CON would become the preeminent hacker convention for the US (possibly the world), drawing upwards of 30,000 attendees. Along with its more-corporate spinoff Black Hat and related BSides conference, the back-to-back conferences are affectionately referred to as Hacker Summer Camp. In today's show, I'll walk down memory lane with Jeff, discussing the ups and downs he's experienced and delve into what this has all meant to him, personally. Oh yeah... and also the incident involving strippers and hacking the power grid.
Further Info
Amulet of Entropy badge: https://amuletofentropy.com/ DEF CON documentary: https://www.youtube.com/watch?v=SUhyeY0FsvwMy first trip to DEF CON: https://podcast.firewallsdontstopdragons.com/2021/08/11/understanding-hackers-hacking/ Last year’s interview with Jeff Moss: https://podcast.firewallsdontstopdragons.com/2021/08/16/on-a-dark-tangent/ Hackers, book by Steven Levy: https://www.amazon.com/Hackers-Computer-Revolution-Steven-Levy/dp/1449388396Legion of Doom (LOD) vs Masters of Deception (MOD): https://en.wikipedia.org/wiki/Great_Hacker_War SATAN tool: https://en.wikipedia.org/wiki/Security_Administrator_Tool_for_Analyzing_NetworksA brief history of hacking: https://encyclopedia.kaspersky.com/knowledge/a-brief-history-of-hacking/ Cap’N Crunch whistle: https://www.thingiverse.com/thing:2630646 Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:31: Hacker Summer Camp0:03:30: pre-interview things of note0:05:31: DEF CON, the early years0:12:02: How had DEF CON changed since the beginning?0:16:08: What's the closest DEF CON ever came to ending?0:24:44: Why is DEF CON so full of shennanigans?0:26:49: What has DEF CON meant to you, personally?0:32:02: Thoughts on the DEF CON culture0:37:13: What's your "Jeff sense" on choosing the best people?0:39:50: What's in the future for DEF CON?0:46:13: What speakers have you always wanted but couldn't get?0:51:04: learning more about hackers and hacking0:53:50: Where does "2600" come from?0:57:18: Important notes for new listeners
If it's August in Las Vegas, it's time for Hacker Summer Camp. There are three hacker conferences that coordinate to happen next to each other every year: BSides Las Vegas, Black Hat and DEF CON. My first trip to DEF CON was last year and I was hooked - I hope to go back every year. This was the big 30th anniversary of DEF CON and several of the news stories this week came from one of these hacker conferences. And next week I'll air my wonderful interview with DEF CON's CEO and Founder, Jeff Moss (aka The Dark Tangent).
In the news this week: Several malicious Mac apps have slipped through Apple's App Store security checks and contain malware - you should delete them ASAP; iOS VPN apps aren't properly securing connections made before activating the VPN; TikTok's in-app browser injects JavaScript code that could enable it to snoop on your session, including capturing keystrokes; Cisco's network breach has lessons for all of us; Signal's use of phone numbers as identifiers highlighted due to breach at Twilio; a new jailbreak has been found on John Deere tractors that might allow farmers to service their own equipment; Amazon is planning to release a reality TV show based on Ring doorbell footage; a digital hallway pass allows schools to intrusively monitor its students; and law enforcement is tapping into DNA databases of the blood samples taken at birth by hospitals to solve crimes.
Article Links
[Tom's Guide] These Mac apps are secretly spreading malware — delete them now https://www.tomsguide.com/news/these-mac-apps-are-secretly-spreading-malware-delete-them-now[Ars Technica] iOS VPNs have leaked traffic for years, researcher claims [Updated] https://arstechnica.com/information-technology/2022/08/ios-vpns-still-leak-traffic-more-than-2-years-later-researcher-claims/[Forbes] TikTok’s In-App Browser Includes Code That Can Monitor Your Keystrokes, Researcher Says https://www.forbes.com/sites/richardnieva/2022/08/18/tiktok-in-app-browser-research/[None] Cisco Confirms Network Breach Via Hacked Employee Google Account https://threatpost.com/cisco-network-breach-google/180385/[TechCrunch] Signal says 1,900 users’ phone numbers exposed by Twilio breach https://techcrunch.com/2022/08/15/signal-phone-number-exposed-twilio/[Ars Technica] A new jailbreak for John Deere tractors rides the right-to-repair wave https://arstechnica.com/information-technology/2022/08/a-new-jailbreak-for-john-deere-tractors-rides-the-right-to-repair-wave/[VICE] 'Ring Nation' Is Amazon's Reality Show for Our Surveillance Dystopia https://www.vice.com/en/article/7k8x49/ring-nation-is-amazons-reality-show-for-our-surveillance-dystopia[VICE] A Tool That Monitors How Long Kids Are in the Bathroom Is Now in 1,000 American Schools https://www.vice.com/en/article/dy73n7/ehallpass-1000-thousand-schools-monitor-bathroom[WIRED] Police Used a Baby’s DNA to Investigate Its Father for a Crime https://www.wired.com/story/police-used-a-babys-dna-to-investigate-its-father-for-a-crime/Tip of the Week: https://firewallsdontstopdragons.com/be-my-guest-no-i-insist/
Further Info
A few Amulets of Entropy are still left: https://hackerboxes.com/collections/past-hackerboxes/products/hackerbox-0080-entropySubscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:17: DEFCON 30 notes0:03:00: Quick security notes0:03:46: News run down0:06:50: Delete these Apple apps immediately0:10:44: iOS VPN apps fail to secure old connections0:15:00: TikTok's in-app browser a...
There's no doubt that the internet has enabled criminals to share illicit and vile content with ease. The advent of high-quality end-to-end encrypted communications has made sharing this material harder for law enforcement to police. But the solution is not to cripple this technology, which is essential for security, privacy and even democracy. Today I'll discuss this thorny issue with Dhanaraj Thakur from the Center for Democracy and Technology. We'll talk about several dangerous proposals currently being considered in the US and Europe, and some potential solutions that can limit criminal behavior while preserving security and our right to privacy.
Dhanaraj Thakur is Research Director at the Center for Democracy & Technology, where he leads research that advances human rights and civil liberties online.
Further Info
Outside Looking In: Approaches to Content Moderation in End-to-End Encrypted Systems: https://cdt.org/insights/outside-looking-in-approaches-to-content-moderation-in-end-to-end-encrypted-systems/ End Run Around Your Rights: https://podcast.firewallsdontstopdragons.com/2021/12/13/end-run-around-your-rights/ Center for Democracy & Technology: https://cdt.org/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:19: Rebranding rolling out0:02:11: Why is content moderation coming to the fore?0:05:11: What are the types of content we're trying to control?0:08:30: How is automated copyright detection being abused by police?0:09:49: What are the phases of content moderation?0:12:01: How can content moderation scale on huge platforms?0:15:14: How does moderation differ inside vs outside the US?0:18:12: What is the platform liability for content?0:21:33: How good is automated content filtering?0:25:01: When does moderation become censorship?0:27:52: Can social media companies block or allow whatever they want?0:30:53: What does end-to-end encryption really mean?0:34:42: How important is metadata for identifying illicit content?0:37:26: What are the current legislative proposals around content moderation?0:41:13: How can we comply with these orders without losing privacy?0:46:09: So where do we draw the line?0:48:44: How did we police this before the internet?0:49:34: How can I learn more and get involved?0:51:57: Listener mailbag coming soon!0:52:49: Preview of coming shows
All software has bugs, so the more software you have installed, the more bugs you have. It's not just the bugs in any individual application, but it's also magnified by interactions between some applications. Thankfully, the converse is also true: the less software you have installed, the fewer bugs you have (statistically, anyway). How many apps have you installed because they were free? How many apps came installed with your PC that you never use? How about companion apps for products you no longer own? Or maybe apps you installed years ago that you've forgotten about. You need to review all of your apps and get rid of anything you aren't using. You can always reinstall them later, if necessary. But removing unused apps will also remove any software bugs and vulnerabilities that inevitably come with them. (It's also one less app to gather and sell personal data.)
In other news: Amazon is looking to buy the maker of Roomba robotic vacuums that know the map of your home; Amazon is also hoping to buy a medical company to start directly providing healthcare; Google once again delays removing support for 3rd party cookies in Chrome; a candidate post-quantum computing encryption algorithm was defeated in an hour with a regular PC; open source software is used everywhere, but is getting very little security support; hackers act on patched bugs within minutes; our cars are collecting and sharing tons of detailed information about us and our driving habits; Samsung has implemented a "repair mode" to protect your data while your phone is in the shop; and a new Android malware is contained in several "cleaner" apps.
Article Links
[Mashable] Amazon vacuums up Roomba maker iRobot, sparking immediate privacy concerns https://mashable.com/article/amazon-irobot-acquisition-roomba-privacy[Time] Amazon's Dangerous Ambition to Dominate Healthcare https://time.com/6201575/amazons-dangerous-ambition-to-dominate-healthcare/[HackerNews] Google Delays Blocking 3rd-Party Cookies in Chrome Browser Until 2024 https://thehackernews.com/2022/07/google-delays-blocking-3rd-party.html[Ars Technica] Post-quantum encryption contender is taken out by single-core PC and 1 hour https://arstechnica.com/information-technology/2022/08/sike-once-a-post-quantum-encryption-contender-is-koed-in-nist-smackdown/[Ars Technica] Samsung’s “repair mode” lets technicians look at your phone, not your data https://arstechnica.com/gadgets/2022/07/samsungs-repair-mode-lets-technicians-look-at-your-phone-not-your-data/[Lawfare] Open-Source Security: How Digital Infrastructure Is Built on a House of Cards https://www.lawfareblog.com/open-source-security-how-digital-infrastructure-built-house-cards[ZDNet] Race against time: Hackers start hunting for victims just 15 minutes after a bug is disclosed https://www.zdnet.com/article/race-against-time-hackers-start-hunting-for-victims-just-15-minutes-after-a-bug-is-disclosed/[The Markup] Who Is Collecting Data from Your Car? – The Markup https://themarkup.org/the-breakdown/2022/07/27/who-is-collecting-data-from-your-car[Ars Technica] T-Mobile to pay $500M for one of the largest data breaches in US history https://arstechnica.com/tech-policy/2022/07/t-mobile-to-pay-500m-for-one-of-the-largest-data-breaches-in-us-history/[Tom's Guide] Millions infected by 'auto-starting' Android malware — delete these apps now https://www.tomsguide.com/news/millions-infected-by-auto-starting-android-malware-delete-these-apps-nowTip of the Week: https://firewallsdontstopdragons.com/deleting-your-way-to-better-security/
Further Info
Mac AppCleaner: https://freemacsoft.net/appcleaner/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Would you like me to speak to your g...
Cameras are everywhere. Every person you pass on the street has a camera on their phone and security cameras are everywhere. They're so cheap and small now, and most of them are connected to the cloud. Not only does that mean they basically have unlimited storage, but it also opens the door for computers to process those images and footage looking for faces. Today, I'll speak with Nate Wessler from the ACLU about the implications of this technological perfect storm on our privacy and what rights we actually have today with regard to facial recognition and use of these systems by law enforcement.
Nate Wessler is a deputy director with the ACLU’s Speech, Privacy, and Technology Project, where he focuses on litigation and advocacy around surveillance and privacy issues, including government searches of electronic devices, requests for sensitive data held by third parties, and use of surveillance technologies.
Further Info
ACLU suit against Clearview AI: https://iapp.org/news/a/aclu-files-class-action-vs-clearview-ai-under-biometric-privacy-law/Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:41: DEF CON updates0:03:18: Interview start0:05:46: Carpenter v. US case0:10:13: What's my expectation of privacy in public spaces?0:17:30: Private right of action0:18:58: What rights do I have for online photos of me?0:21:54: Aren't we enabling facial recognition by tagging people?0:23:47: Is there any solution beyond regulation?0:27:16: Who is Clearview AI and what are they doing?0:32:24: ACLU's lawsuit win against Clearview AI0:38:57: Is it possible to limit this tech to just "the good guys"?0:43:00: This guy looks like Woody Harrelson!0:47:07: What about the good uses for this tech?0:53:09: What about 1-to-1 facial matching services?0:56:20: So what can we, as citizens, do about all of this?0:58:22: When should we reach out to the ACLU?1:00:26: Wrap up
The "rolling code" technology used to remotely open and lock your car is supposed to prevent hacking. Unfortunately, Honda has a pretty serious vulnerability in their cars that apparently allows anyone with a little talent and cheap hacking tools to get into your car - and maybe even start it (though not actually drive it away). If correct, this vulnerability affects probably all Hondas made over the last 10 years. So far, Honda has denied that this is a problem, but many researchers have reproduced the hack.
In other news: cheap, Chinese-made GPS vehicle trackers are vulnerable to remote hacking; Chrome, Edge and Safari browsers fix serious 0-day bugs; Twitter data breach info on 5.4M users is up for sale on the dark web; Windows getting a crucial security update to make important security feature on by default; the Conti ransomware gang is attacking the entire country of Costa Rica; Facebook quickly bypasses Firefox's URL tracking removal feature; Tor Browser adds a useful feature that will help people in repressive countries; Google appears ready to stop blocking political spam emails; Amazon admits to giving Ring video to law enforcement without consent or a warrant; a complicated, targeted web browser trick can be used to identify website visitors.
Article Links
[U.S. News & World Report] Researchers: Chinese-Made GPS Tracker Highly Vulnerable https://www.usnews.com/news/business/articles/2022-07-19/researchers-chinese-made-gps-tracker-highly-vulnerable[Ars Technica] 0-day used to infect Chrome users could pose threat to Edge and Safari users, too https://arstechnica.com/information-technology/2022/07/exploit-seller-used-chrome-exploit-and-2-other-0-days-to-infect-journalists/[9to5mac.com] Twitter data breach exposes contact details for 5.4M accounts; on sale for $30k https://9to5mac.com/2022/07/22/twitter-data-breach/[ZDNet] Windows 11 is getting a new security setting to block ransomware attacks https://www.zdnet.com/article/windows-11-is-getting-a-new-security-setting-to-block-ransomware-attacks/[ThreatPost] Conti’s Reign of Chaos: Costa Rica in the Crosshairs https://threatpost.com/contis-costa-rica/180258/[Schneier Blog] Facebook Is Now Encrypting Links to Prevent URL Stripping https://www.schneier.com/blog/archives/2022/07/facebook-is-now-encrypting-links-to-prevent-url-stripping.html[None] Tor Browser Adds Automatic Censorship Circumvention https://www.infosecurity-magazine.com/news/tor-browser-automatic-censorship/[Inc. Magazine] Google Revealed Plans for a Big Change to Gmail That Almost Nobody Wants. You Have 19 Days to Object https://www.inc.com/bill-murphy-jr/google-revealed-plans-for-a-big-change-to-gmail-that-almost-nobody-wants-you-have-19-days-to-object.html[The Intercept] Amazon Admits Giving Ring Camera Footage to Police Without a Warrant or Consent https://theintercept.com/2022/07/13/amazon-ring-camera-footage-police-ed-markey/[The Drive] I Tried the Honda Keyfob Hack on My Own Car. It Totally Worked https://www.thedrive.com/news/i-tried-the-honda-keyfob-hack-on-my-own-car-it-totally-worked[WIRED] A New Attack Can Unmask Anonymous Users on Any Major Browser https://www.wired.com/story/web-deanonymization-side-channel-attack-njit/Tip of the Week: More Uses for Password Vaults: https://firewallsdontstopdragons.com/more-uses-for-password-vaults/
Further Info
Amulet of Entropy!!: https://amuletofentropy.com/ Peppering your passwords: https://firewallsdontstopdragons.com/password-manager-paranoia/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Donate directly with Monero! https://firewallsdontstopdragons.com/contact/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:02:02: Bad Bugs in GPS Vehicle Trackers0:07:16: Zero-Day Bugs in Chrome, Edge,
We take that little box that connects our home to the internet for granted. But in reality, it's often the only thing hiding our computers and vulnerable IoT devices from automated, remote attacks. This "internet background radiation" is ever present - a massive network of malicious or compromised devices, constantly scanning the internet for exposed and ill-protected systems. Today, we'll discuss routers, firewalls and other common aspects of home network security with the CEO of CrowdSec. He'll also explain how we can enable these devices to share information in a sort of global neighborhood watch program, distributing information about bad actors to better protect us all.
Philippe Humeau graduated as an IT security engineer in 1999 in Cyber security. He then created his first company, dedicated to red team penetration testing and high-security hosting. After selling his first company, his eternal crushes for Cybersecurity led him to create CrowdSec in 2020. This open-source editor creates a participative IPS which generates a global, crowd-powered CTI.
Further Info
CrowdSec: https://crowdsec.net/ CrowdSec code repository: https://github.com/crowdsecurity/crowdsec Lulu reverse firewall: https://objective-see.org/products/lulu.html Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Amulet of Entropy!!:https://amuletofentropy.com/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:02:46: Update on Firefox Total Cookie Protection0:03:50: DEF CON coming soon0:04:47: Interview start0:06:49: What does a firewall do?0:10:18: Should I enable the firewall on my computer, too?0:14:18: What is Universal Plug and Play (uPnP?)0:16:04: What is Network Address Translation (NAT)?0:20:16: Hacker vs Cybercriminal?0:21:17: Internet Background Radiation0:26:19: Creating network silos0:29:28: Attacks from within0:32:15: Botnets and DDoS attacks0:35:37: What are the biggest network threats today?0:40:16: Who are the main threat actors?0:45:09: How does Crowdsec work?0:49:36: How quickly do agents share info?0:51:37: How does Crowdsec make money?0:53:03: Can you use Crowdsec on home routers?0:55:28: Are things getting better or worse?0:57:43: Top security tips?1:01:45: How do you poke a hole in a firewall?1:04:01: Setting up guest network1:07:48: Reverse firewalls1:09:07: Final word
This week we'll talk about three significant new data breaches. Each of these data leaks are important in different ways, but the trend is clear: data wants to be free. First of all, we need to stop collecting so damn much of it. But second, we need to make it more expensive for data-collectors who are criminally negligent with the protection of our data. Right now, it's cheaper to let it escape than to spend time, effort and money to protect it. (In my Tip of the Week, I'll tell you about a great free tool that will let you protect your own data.)
In other news: Google patches some serious zero-day Chrome bugs and I'll explain how they work; personal data for many California gun owners was leaked; Marriott suffered yet another customer data breach; personal data on over 1 billion people in China is up for sale; Crypto exchange Coinbase is sharing info with US immigration enforcers; a sophisticated malware named ZouRAT is infecting SOHO routers; a new Windows worm appears to be coming from infected USB devices; a free decryptor has been released for AstraLocker and Yashma ransomware; Apple's new Lockdown mode shows real promise; and the US Immigration and Customs Enforcement agency has become a full-tilt mass surveillance organization.
Article Links
[Naked Security] Google patches “in-the-wild” Chrome zero-day – update now! https://nakedsecurity.sophos.com/2022/07/05/google-patches-in-the-wild-chrome-zero-day-update-now/[Gizmodo] California Gun Owners Had Lots of Their Data Exposed by the State Government https://gizmodo.com/california-gun-owners-data-exposed-state-justice-dept-1849124116[TechCrunch] Hotel giant Marriott confirms yet another data breach https://techcrunch.com/2022/07/06/marriott-breach-again/[ZDNet] Giant data breach? Leaked personal data of one billion people has been spotted for sale on the dark web https://www.zdnet.com/article/giant-data-breach-leaked-personal-data-of-one-billion-people-has-been-spotted-for-sale-on-the-dark-web/[The Intercept] Cryptocurrency Titan Coinbase Providing “Geo Tracking Data” to ICE https://theintercept.com/2022/06/29/crypto-coinbase-tracer-ice/[Ars Technica] A wide range of routers are under attack by new, unusually sophisticated malware https://arstechnica.com/information-technology/2022/06/a-wide-range-of-routers-are-under-attack-by-new-unusually-sophisticated-malware/[PCM] Hundreds of Windows Networks Are Infected With Raspberry Robin Worm https://www.pcmag.com/news/hundreds-of-windows-networks-are-infected-with-raspberry-robin-worm[BleepingComputer] Free decryptor released for AstraLocker, Yashma ransomware victims https://www.bleepingcomputer.com/news/security/free-decryptor-released-for-astralocker-yashma-ransomware-victims/[9to5mac.com] Firefox now lets users remove tracking parameters from URLs to enhance privacy https://9to5mac.com/2022/06/29/tracking-parameters-urls-firefox/[Ars Technica] Why Lockdown mode from Apple is one of the coolest security ideas ever https://arstechnica.com/information-technology/2022/07/introducing-lockdown-from-apple-the-coolest-defense-youll-probably-never-use/Data-Driven Deportation in the 21st Century https://americandragnet.org/Tip of the Week: https://firewallsdontstopdragons.com/creating-a-file-vault-with-cryptomator/
Further Info
Cryptomator: https://cryptomator.org/ Donate directly with Monero! https://firewallsdontstopdragons.com/contact/ Seth interview on cryptocurrency: https://podcast.firewallsdontstopdragons.com/2022/06/06/cryptocurrency-101/ Amulet of Entropy!!:https://amuletofentropy.com/ No More Ransom. A non-profit devoted to helping break ransomware crypto so that victims don’t have to pay.ID Ransomware. A tool for identifying which ransomware you’ve been infected with and then guiding you to other resources for help.Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your...
While many of us prefer order in our lives, at least most of the time, we sometimes need a little chaos. Specifically, we need a source of true randomness in order to properly drive many of our cryptographic systems - to secure our digital communications, for example. And while computers are very good at doing what we tell them to do, they suck at being unpredictable. Therefore we have to find other ways to inject a little chaos. Today I will discuss these concepts with Joe Long, founder and CEO of HackerBoxes.com. Along the way, we'll share stories of hardware hacking and our love of electronics tinkering. And then we'll reveal a totally geeky project we've been working on together for many months now that we dubbed the Amulet of Entropy!
Joe Long is a professional engineer, patent attorney, and hardware hacker. He has decades of expertise in electronics which he has taught to over a million students around the world. Joe is the founder of HackerBoxes - a company that provides kits, workshops, and monthly subscription boxes for building and learning electronics.
Further Info
Amulet of Entropy!!: https://amuletofentropy.com/HackerBox #0080: https://hackerboxes.com/products/hackerbox-0080-entropy Amulet GitHub repo: https://github.com/FirewallDragon/amulet-of-entropyHackerBoxes: https://hackerboxes.com/ Forrest Mims electronics books: https://www.forrestmims.com/ Humble Bundle electronics books: https://www.humblebundle.com/books/boards-coding-make-co-books HackADay: https://hackaday.com/DEF CON 30: https://defcon.org/html/defcon-30/dc-30-index.html Firewalls Don’t Stop Dragons book: https://www.amazon.com/gp/product/1484261887 Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:04:23: Start of interview0:05:42: What is a hardware hacker?0:09:09: What got you into electronics?0:14:49: What do you need to get into electronics?0:21:46: What is entropy?0:24:36: Where do we find entropy in everyday life?0:28:18: Why is entropy important for cryptography?0:30:58: Why do computers suck at randomness?0:35:18: So how do we find true random values?0:38:42: What happens randomness fails?0:41:17: How we use patterns to efficiently encode things0:46:44: The Amulet of Entropy!0:51:53: Designing the project0:55:33: Fun uses of entropy0:56:41: How do I get one??0:57:53: Outro1:01:06: DEF CON 30 talk1:01:45: Electronics resources for newbies
Firefox officially rolled out its Total Cookie Protection feature last week, which is a clever and elegant solution for blocking tracking using third party cookies. Unfortunately... it doesn't seem to be working for me when I tested it. There are at least a couple reasons for why this might be, and a workaround, both of which I will discuss in today's Tip of the Week.
Also: A drunk employee lost a flash drive with half a million customer's data in Japan; a TikTok leak appears to show that even with US user data being "moved" to US soil, engineers in China can still access it; a new voicemail scam tries to trick you into giving up your Microsoft account credentials; MEGA fixes several flaws which might allow a rogue employee to view your data; 56 security flaws in industrial systems could impact thousands of devices around the world; Google Password Manager now allows for client-side encryption; Microsoft's Defender is now available for non-Windows devices (for a fee); T-Mobile is the latest to use its privileged position to hoover up and sell customer data; spyware companies are proliferating; Facebook is receiving sensitive medical info from it's Meta Pixel; and vacation rentals are sadly great places for spycams, and I'll help you try to spot them.
Article Links
[The Guardian] Japanese city worker loses USB containing personal details of every resident https://www.theguardian.com/world/2022/jun/24/japanese-city-worker-loses-usb-containing-personal-details-of-every-resident[Gizmodo] TikTok Leak Alleges User Data Isn't Private: ‘Everything Is Seen in China’ https://gizmodo.com/tiktok-china-oracle-bytedance-1849078477[Threatpost] Voicemail Scam Steals Microsoft Credentials https://threatpost.com/voicemail-phishing-scam-steals-microsoft-credentials/180005/[BleepingComputer] MEGA fixes critical flaws that allowed the decryption of user data https://www.bleepingcomputer.com/news/security/mega-fixes-critical-flaws-that-allowed-the-decryption-of-user-data/[BleepingComputer] Icefall: 56 flaws impact thousands of exposed industrial devices https://www.bleepingcomputer.com/news/security/icefall-56-flaws-impact-thousands-of-exposed-industrial-devices/[9to5Google] Google Password Manager starts offering on-device encryption on Android, iOS, and Chrome https://9to5google.com/2022/06/21/google-password-on-device-encryption/[PCM] WTF? Do I Have to Pay for Microsoft's Defender Antivirus Now? https://www.pcmag.com/news/wtf-do-i-have-to-pay-for-microsofts-defender-antivirus-now[The Verge] T-Mobile is selling your app usage data to advertisers — here’s how to opt out https://www.theverge.com/2022/6/24/23181851/t-mobile-browsing-data-app-insights-marketing-opt-out[WIRED] Google Warns of New Spyware Targeting iOS and Android Users https://www.wired.com/story/hermit-spyware-rcs-labs/[The Markup] Facebook Is Receiving Sensitive Medical Information from Hospital Websites – The Markup https://themarkup.org/pixel-hunt/2022/06/16/facebook-is-receiving-sensitive-medical-information-from-hospital-websites[USA TODAY] How to spot hidden surveillance cameras in your Airbnb, VRBO, or vacation rentals https://www.usatoday.com/story/tech/columnist/komando/2022/06/23/how-check-hidden-cameras-airbnb-vrbo-vacation-rentals/7652726001/
Further Info
Tip of the Week: Total Cookie Protection? https://firewallsdontstopdragons.com/total-cookie-protection/Cookie Forensics Test: https://www.grc.com/cookies/forensics.htm Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:02:17: News topic summary0:04:47: Drunk worker loses customer data0:08:00: TikTok phone call leak0:12:04: Microsoft voicemail scam0:16:23: ...
Everyone hates dealing with passwords, and yet they've been the de facto standard of computer authentication for decades. But there's light at the end of this long tunnel. There is a passwordless future where we can log in to our accounts using just our smartphones. In this future, it won't matter if websites are breached because there will be no password databases to steal. Even phishing will be a thing of the past. And thankfully, that future isn't far away. Today I'll discuss where we are, how we got here, and where we're going with YubiCo's Derek Hanson.
Derek Hanson has been involved in the identity and security industry for over ten years. He has been building networks and deploying computer systems since the mid-90s and now is an advocate for how you can best protect them. And he is now the VP of Solutions Architecture and Alliances at YubiCo.
Further Info
YubiCo/YubiKey: https://www.yubico.com/ NIST password guidelines: https://www.infosecurity-magazine.com/blogs/nist-password-guidelines/ OPM fingerprint database hack: https://www.wired.com/2015/09/opm-now-admits-5-6m-feds-fingerprints-stolen-hackers/ WebAuthn: https://webauthn.guide/ FIDO: https://fidoalliance.org/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Table of Contents (new!)
Use these timestamps to jump to a particular section of the show.
0:01:01: Welcome new patrons!0:01:41: New table of contents0:03:40: Update Windows ASAP0:04:03: Pre-interview notes0:04:34: Interview start0:06:21: Why do we still use passwords?0:11:26: Why don't more people use password managers?0:15:25: NIST updates password recommendations0:17:50: Should we use biometrics for authentication?0:23:40: How do passwordless systems compare to what we have now?0:29:00: How does authentication work in a passwordless system?0:32:50: Have we settled on a single passwordless standard?0:37:24: How well is this new standard supported?0:40:41: How do I use this passwordless technology?0:43:00: How soon will we see passwordless logins?0:46:22: Which 2FA system is best and will we still need this going forward?0:51:33: What current technologies are best for securing our accounts?0:55:18: How do hardware keys work?1:00:42: OPM fingerprint hack1:01:48: Bonus content preview1:02:02: Upcoming shows
I preach about using password managers constantly - because they really are a fantastic tool for increasing your security. Humans suck at creating memorable passwords that are not also easy to guess. But the idea of putting all your juicy secrets into a digital vault that is controlled by a third party and synchronizing through the cloud may not sit well with you. And I totally get that. It's a very valid concern. But what if there were a way to have your cake and eat it, too? (I never understood that expression... what good is having cake if you can't eat it, right?) I'll explain a simple technique using cryptographic "pepper" that will allow you to use a password manager, even if you don't trust it.
In other news: US water utilities are woefully unprepared for cyberattacks; paper ballots are essential for secure elections, but not sufficient; PDFs are being used to cleverly hide keylogging malware; Chinese hackers have infiltrated many global telecom companies for years; Australia's new "secure" digital driver's license is anything but; the FBI manages to recover half of the Colonial Pipeline ransom; a new facial search engine is on the scene, with even less protections than Clearview AI; and the Tim Horton's app stole a heck of a lot of user location data from its customers.
Article Links
U.S. Water Utilities Prime Cyberattack Target, Experts | Threatpost https://threatpost.com/water-cyberattack-target/179935/Do Ballot Barcodes Threaten Election Security? https://cdt.org/insights/do-ballot-barcodes-threaten-election-security/[BleepingComputer] PDF smuggles Microsoft Word doc to drop Snake Keylogger malware https://www.bleepingcomputer.com/news/security/pdf-smuggles-microsoft-word-doc-to-drop-snake-keylogger-malware/[MIT Technology Review] Chinese hackers exploited years-old software flaws to break into telecom giants https://www.technologyreview.com/2022/06/08/1053375/chinese-hackers-exploited-years-old-software-flaws-to-break-into-telecom-giants/[Ars Technica] “Tough to forge” digital driver’s license is… easy to forge https://arstechnica.com/information-technology/2022/05/digital-drivers-license-used-by-4m-australians-is-a-snap-to-forge/FBI Recovers $2.3 Million of Colonial Pipeline Ransomware Payment; Some Que https://www.cpomagazine.com/cyber-security/fbi-recovers-2-3-million-of-colonial-pipeline-ransomware-payment-some-questions-about-the-attack-answered/[The Mercury News] A face search engine anyone can use is alarmingly accurate https://www.mercurynews.com/2022/05/28/a-face-search-engine-anyone-can-use-is-alarmingly-accurate-2[CTV News] Tim Hortons app collected vast amounts of sensitive data: privacy watchdogs https://www.ctvnews.ca/business/tim-hortons-app-collected-vast-amounts-of-sensitive-data-privacy-watchdogs-1.5927716Pepper Your Passwords: https://firewallsdontstopdragons.com/password-manager-paranoia/
Further Info
Only FIVE DAY LEFTS to get your dragon coin! https://firewallsdontstopdragons.com/return-of-the-dragon-coins/ Techlore interview: https://youtu.be/-GubGbuWBfk Exploits of a Mom (XKCD “Bobby Tables” cartoon): https://xkcd.com/327/Bobby Tables explanation: https://www.explainxkcd.com/wiki/index.php/Little_Bobby_Tables Generate secure passphrases! https://d20key.com/#/Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Everyone has heard of Bitcoin, but almost no one understands what the heck is actually is. Today I'm interviewing Seth from Seth for Privacy who knows cryptocurrency backwards and forwards. Seth is also a privacy advocate who understands the broader implications of digital currency. I'll ask him to explain how cryptocurrency works, what the blockchain is, how crypto mining affects our environment, whether cryptocurrency is truly anonymous, and how cryptocurrency has any value whatsoever - and much more!
Seth is a privacy educator, Monero contributor, and host of the Opt Out podcast.
Further Info
Opt Out podcast, https://optoutpod.comSeth’s bio: https://sethforprivacy.com/about/ Seth’s Twitter feed: https://twitter.com/sethforprivacy Why Cryptocurrencies? https://whycryptocurrencies.com/toc.html Local Monero: https://localmonero.co/ Cryptocurrency ATMs: https://coinatmradar.com/ Bitcoin energy consumption: https://niccarter.info/topics/#energy Was Bitcoin Created by This International Drug Dealer? https://www.wired.com/story/was-bitcoin-created-by-this-international-drug-dealer-maybe/ XKCD comic - $5 wrench: https://xkcd.com/538/ Byzantine Generals Problem: https://en.wikipedia.org/wiki/Byzantine_fault Inside the Bitcoin Bust That Took Down the Web’s Biggest Child Abuse Site https://www.wired.com/story/tracers-in-the-dark-welcome-to-video-crypto-anonymity-myth/ Hot Wallets vs Cold Wallets: https://appleinsider.com/articles/22/06/04/crypto-101-the-difference-between-hot-and-cold-wallets Microsoft unpatched vulnerability: https://www.kaspersky.com/blog/follina-cve-2022-30190-msdt/44461/
Dragon Coins & Passphrases
Get your Dragon Challenge Coin!! https://firewallsdontstopdragons.com/return-of-the-dragon-coins/ Generate secure passphrases! https://d20key.com/#/
Modern smartphones have a potentially life-saving feature called "SOS" or "Emergency" mode that can give first responders critical medical information and automatically dial your country's emergency phone number. It can report your location and even notify selected contacts. In today's show, I'll share a story from one woman who believes this mode saved her life. It's easy to use and set up, but it won't do you any good if you don't know about it. I'll tell you everything you need to know.
In other news: Clearview AI is looking to expand its services to schools, banks and other institutions that wish to authenticate people; MasterCard is launching a new facial recognition system that will allow users to pay "with a smile"; the US Department of Justice has finally issued long-overdue guidance on common sense limitations for prosecuting security researchers and regular people who might run afoul of the tragically over-broad Computer Fraud and Abuse Act (CFAA); Twitter has been fined and Google has been sued for abusing customer data; local governments forced children to use EdTech software that surreptitiously harvested their data and fed them behavior-based ads; DuckDuckGo is in damage control over reports that it isn't blocking some Microsoft web tracking due to an agreement which they legally can't discuss; there's a new Wells Fargo phishing campaign going around which seeks to gather tons of data that would easily enable identity thefts; and a security researcher has found a bug with the OAuth single-sign on functionality used by Facebook.
Article Links
[Gizmodo] Clearview AI Says It's Bringing Facial Recognition to Schools https://gizmodo.com/clearview-ai-facial-recognition-privacy-1848975528[The Guardian] Mastercard launches ‘smile to pay’ system amid privacy concerns https://www.theguardian.com/technology/2022/may/17/mastercard-launches-smile-to-pay-amid-privacy-concerns[The Verge] Justice Department pledges not to charge security researchers with hacking crimes https://www.theverge.com/2022/5/19/23130910/justice-department-cfaa-hacking-law-guideline-limits-security-research[NPR] Twitter agrees to pay $150 million after FTC, DOJ accuse company of mishandling data https://www.npr.org/2022/05/25/1101275323/twitter-privacy-settlement-doj-ftc[None] Governments Harm Children’s Rights in Online Learning https://www.hrw.org/news/2022/05/25/governments-harm-childrens-rights-online-learning[Review Geek] DuckDuckGo Isn’t as Private as You Thought https://www.reviewgeek.com/118915/duckduckgo-isnt-as-private-as-you-thought/[Sky] Google sued for using the NHS data of 1.6 million Brits 'without their knowledge or consent' https://news.sky.com/story/google-sued-for-using-the-nhs-data-of-1-6-million-brits-without-their-knowledge-or-consent-12614525[None] Bank phishing and identity theft https://usa.kaspersky.com/blog/wells-fargo-phishing-identity-theft/26473/[Forbes] Security Warning For Facebook Users Who Login With Gmail OAuth Code https://www.forbes.com/sites/gordonkelly/2022/05/21/google-gmail-security-facebook-oauth-login-warning/[9to5mac.com] iPhone SOS credited with saving woman during assault attempt – Here’s how to set it up https://9to5mac.com/2022/05/24/iphone-sos-how-to-set-it-up/Set up Emergency mode, Apple iPhone: https://support.apple.com/en-us/HT208076Set up Emergency mode, Google Pixel: https://support.google.com/pixelphone/answer/7055029Set up Emergency mode, Samsung Galaxy: https://www.samsung.com/us/support/answer/ANS00050849/
Further Info
Get your Dragon Challenge Coin!! https://firewallsdontstopdragons.com/return-of-the-dragon-coins/ Generate secure passphrases! https://d20key.com/#/Amulet of Entropy teaser #2: https://twitter.com/HackerBoxes/status/1530341605567242240?s=20&t=OWW931j-mZk8cMRc6yp9bA Stop Using “Sign in with”: https://firewallsdontstopdragons.com/stop-using-sign-in-with/ EFF on facial recognition technology: https://www.eff.org/deeplinks/2021/10/face-recognition-isnt-just-face-ide...
There's a lot we can glean from history but sometimes it's not as obvious as you might think. For example, did you know that until the mid-1800's, most of Americans hated tomatoes and that ketchup was originally made from mushrooms? The story behind how Americans came to love tomatoes is quite fascinating, but what is perhaps most interesting is the way our guest applies this knowledge to the realm of cybersecurity. Today we will also learn how one of the most powerful cryptographic techniques to this day originated in the time of the telegraph. Along the way, we'll discuss how humans choose their passwords, how they should be creating passwords, and how often we should be changing our passwords.
Anthony Collette is a Senior Consent Form Editor at the largest Institutional Review Board (IRB) in the United States. This regulatory agency has reviewed over 1,000 COVID-19 research studies, conducted at more than 12,000 locations. Mr. Collette analyzes complex medical documents, synthesizes the central concepts, and translates technical jargon into relatable language directed to the non-technical research participant. These skills transfer perfectly to the task of analyzing and understanding the conflicting and often outdated advice given about passwords, stripping away what’s unnecessary, and getting down to the actionable core of the issues.
Interview Links
Anthony Collette: https://www.linkedin.com/in/tonycollette/ Loistava Information Security website: www.LositavaInfoSecurity.comCASTALOT™ Dice Landing Page: https://www.castalotdice.com?utm_source=dragons1 CASTALOT™ Dice Facebook VIP Group: https://www.facebook.com/groups/1317312032055849The History of Tomatoes in America: https://www.amazon.com/Tomato-America-History-Culture-Cookery/dp/1570030006/ NY Times, Secret Life of Passwords: https://www.nytimes.com/2014/11/19/magazine/the-secret-life-of-passwords.html A Look at Telegraph Codes (Steven Bellovin): https://www.cs.columbia.edu/~smb/papers/codebooks.pdf DFLEKT Keyless Entry Protection: https://www.duku.co.uk/dflekt
Further Info
Get your Dragon Challenge Coin!! https://firewallsdontstopdragons.com/return-of-the-dragon-coins/ Generate secure passphrases! https://d20key.com/#/ Amulet of Entropy teaser: https://twitter.com/HackerBoxes/status/1523318662807298051?s=20&t=dwQFy7ieRMGjRCqgAR7btQ
When we surf the web today - on our computers or smartphones - we are mercilessly tracked. Marketing firms and data brokers are hoovering up ungodly amounts of our personal data, selling it, trading it and mining it to derive even more about us. Many offer some way to limit or stop this wanton data collection, but good luck figuring out how - let alone even knowing who to ask. Wouldn't it be nice if you could just click one button and tell everyone to leave you alone? Of course, we tried this a decade ago with Do Not Track, but there were no regulations in place to require companies to respect it. While we have a long way to go, some regions do now have privacy laws - and now we have a new way to invoke our privacy rights: Global Privacy Control. Today, I'll tell you how to enable this on your devices and tell data miners to get lost.
In other news: Clearview AI has been forced to cut back on its creepy facial recognition software; the EU is proposing dangerous new surveillance requirements in the name of child safety; if you have an HP computer, you need to check for BIOS software updates ASAP; automated vehicles are outfitted with tons of video cameras, and law enforcement have been using this data for investigations; thousands of popular websites are saving data from online forms even if you don't click 'submit'; the CDC has been buying cell phone location data to track compliance with covid curfews and more; data from period-tracking apps may soon be used against people seeking abortions if Roe v. Wade is struck down in the US; Facebook is ending some location-based services (though still collecting your location data); Chinese hackers have stolen hundreds of billions of dollars in intellectual property, including military, manufacturing and pharmaceutical info; and mental health apps aren't taking proper care of your very personal data.
Article Links
[Engadget] Clearview AI agrees to limit sales of facial recognition data in the US https://www.engadget.com/clearview-ai-agrees-to-limit-sales-of-facial-recognition-data-in-the-us-173357030.html[Electronic Frontier Foundation] The EU Commission’s New Proposal Would Undermine Encryption And Scan Our Messages https://www.eff.org/deeplinks/2022/05/eu-commissions-new-proposal-would-undermine-encryption-and-scan-our-messages[TechSpot] HP pushes out BIOS update addressing high-severity vulnerabilities affecting 200+ models https://www.techspot.com/news/94561-hp-pushes-out-bios-update-addressing-high-severity.html[VICE] San Francisco Police Are Using Driverless Cars As Mobile Surveillance Cameras https://www.vice.com/en/article/v7dw8x/san-francisco-police-are-using-driverless-cars-as-mobile-surveillance-cameras[WIRED] Thousands of Popular Websites See What You Type—Before You Hit Submit https://www.wired.com/story/leaky-forms-keyloggers-meta-tiktok-pixel-study/[None] CDC tracked Americans’ phones to see if they followed COVID-19 lockdowns https://www.mlive.com/news/2022/05/cdc-tracked-americans-phones-to-see-if-they-followed-covid-19-lockdowns.html[VICE] Data Broker SafeGraph Stops Selling Location Data of People Who Visit Planned Parenthood https://www.vice.com/en/article/88gyn5/data-broker-safegraph-stops-selling-location-data-of-people-who-visit-planned-parenthood[NPR] How period tracking apps and data privacy fit into a post-Roe v. Wade climate https://www.npr.org/2022/05/10/1097482967/roe-v-wade-supreme-court-abortion-period-apps[9to5mac.com] Facebook to discontinue Nearby Friends and other location-based features https://9to5mac.com/2022/05/05/facebook-to-discontinue-nearby-friends-and-other-location-based-features/[CBS News] Chinese hackers took trillions in intellectual property from about 30 multinational companies https://www.cbsnews.com/news/chinese-hackers-took-trillions-in-intellectual-property-from-about-30-multinational-companies/[The Verge] Mental health apps have terrible privacy protections, report finds https://www.theverge.
We are being tracked constantly by our cell phones. We willingly carry supercomputers in our pockets 24/7, and these devices are chock full of sensors and radios that are tattling on us. Sometimes on purpose, sometimes incidentally, and sometimes maliciously. Apps for brick and mortar stores are tracking you within their stores, noting where you go, how long you stay in some locations, and where you don't go. Other apps track your global location and sell it to third parties. Apps to keep tabs on kids can also be used to stalk significant others. And spyware is used to track journalists, dissidents and "people of interest" by authoritarian governments. If all of that weren't bad enough, there are several cheap electronic devices that anyone can buy and hide on you to track your movements. Today I'll talk about all of this tracking and stalking with David Ruiz from Malwarebytes, and we'll give you some tips on how to avoid it.
David Ruiz is an online privacy advocate for Malwarebytes, where he writes about online privacy, cybersecurity, and the laws and proposed legislation that regulate how data is stored, shared, and accessed.
Further Info
Malwarebytes blog: https://blog.malwarebytes.com/Malwarebytes podcast: https://blog.malwarebytes.com/category/podcast/ David Ruiz interviews me: https://blog.malwarebytes.com/podcast/2022/03/de-googling-carey-parkers-and-your-life-lock-and-code-s03e06/ Coalition Against Stalkerware: https://stopstalkerware.org/ Malwarebytes detection software: https://www.malwarebytes.com/mwb-download Stalkerware-type detections hit record high in 2021, but fell in second half https://blog.malwarebytes.com/stalkerware/2022/04/stalkerware-type-detections-hit-record-high-in-2021-but-fell-in-second-half/ Kashmir Hill article: https://www.nytimes.com/2022/02/11/technology/airtags-gps-surveillance.html Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/or privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Security isn't a big differentiator today when choosing a web browser. First of all, 3 of the top 5 browsers all use the same engine - Chrome, Edge and Opera are all based on Chromium. Second, there's no real conflict of interest between browser makers and browser users when it comes to security - it's a win-win situation. Also, most browsers today are plenty fast enough and come with similar user features. So to me, the real differentiator when choosing a web browser is privacy. Today I'll give you my top choices for the most privacy-respecting web browser. (Spoiler alert: Chrome didn't make the list.)
NOTE: I'm giving away TEN free subscriptions to ProtonMail plus! All you have to do to enter is sign up for a free ProtonMail account here and then shoot me an email from your new account (send it to proton at firewallsdontstopdragons.com)! That's it! Do it by 11:59AM Eastern Time on May 6th.
In other news: The US and 60 other countries have signed an aspiration Declaration for the Future of the Internet; in a twist of fate, Russia is now the target of global hacking; another nasty Java zero-day bug has been found; leaked Cellebrite documents detail which iPhones they can hack into; Amazon and third parties are mining your Alexa requests for personal data; Microsoft is going to add a free VPN to its Edge browser; Facebook is pulling detailed user data from the US college financial aid site FAFSA; and apparently Facebook has no clue how to tell the source of all the data it collects (making it impossible to comply with privacy regulations); Google is now giving you a way to remove some person info from its searches; and Brave and DuckDuckGo are both blocking Google "AMP" links which collect data about the sites you visit.
Article Links
EFF Statement on the Declaration for the Future of the Internet https://www.eff.org/deeplinks/2022/04/eff-statement-declaration-future-internet Declaration for the Future of the Internet: https://www.whitehouse.gov/wp-content/uploads/2022/04/Declaration-for-the-Future-for-the-Internet_Launch-Event-Signing-Version_FINAL.pdf Russia Is Being Hacked at an Unprecedented Scale https://www.wired.co.uk/article/russia-hacked-attacks Java Cryptography Implementation Mistake Allows Digital-Signature Forgeries https://www.schneier.com/blog/archives/2022/04/java-cryptography-implementation-mistake-allows-digital-signature-forgeries.html Cellebrite iPhone cracking: Here’s which models the kit can unlock and access, and how to protect your data https://9to5mac.com/2022/04/29/cellebrite-iphone-cracking/ Report: Amazon and third parties use Alexa voice data for ads while Siri respects privacy https://9to5mac.com/2022/04/29/amazon-alexa-voice-data-used-for-ads/ Microsoft Is Adding a Free VPN to the Edge Browser https://www.pcmag.com/news/microsoft-is-adding-a-free-vpn-to-the-edge-browser Go read this exposé on how FAFSA got caught sending personal info to Facebook https://www.theverge.com/2022/4/29/23048305/fafsa-facebook-department-of-education-us-student-financial-aid-meta-tracking-pixel Applied for Student Aid Online? Facebook Saw You https://themarkup.org/pixel-hunt/2022/04/28/applied-for-student-aid-online-facebook-saw-you Facebook doesn't know what most of its user data is used for https://appleinsider.com/articles/22/04/27/facebook-doesnt-know-what-most-of-its-user-data-is-used-for You can now ask Google to remove your phone number from search https://www.androidauthority.com/google-search-remove-phone-number-3158456/ Google request site: https://support.google.com/websearch/answer/9673730 Brave, DuckDuckGo updates target Google AMP sites in privacy push https://www.macworld.com/article/633804/brave-duckduckgo-updates-target-google-amp-sites-in-privacy-push.html Which Is the Most Private Browser? https://firewallsdontstopdragons.com/which-is-the-most-private-browser/
Further Info
Subscribe to the newsletter: https://firewallsdontstopdragons.
Google and Facebook will swear up and down that they do not sell your data. While technically true, they do sell access to your data. Basically, your data is private from everyone - but them. And that's a crucial caveat. To have true privacy, you want to work with a company who has absolutely minimal access to your data. You want privacy by design. And this is not easy to do with a very old internet standard like email. Proton has been offering truly private email for almost a decade (ProtonMail) and over the years has added many other features like a VPN and calendar, making them a true privacy-respecting alternative to the likes of Google. Today I'll speak with Proton's founder and CEO, Dr. Andy Yen, about the importance of privacy as a human right and the delicate balance between privacy and the needs of law enforcement. I'll ask him how to evaluate products for privacy and what can we can all do to bring about a better future where we can express ourselves freely.
Dr. Andy Yen is the founder and CEO of Proton. He was a scientist at CERN, has a PhD in physics from Harvard University, and he has long worked to advance privacy and freedom online.
Further Info
ProtonMail: https://protonmail.com/ Proton & SimpleLogin join forces: https://protonmail.com/blog/proton-and-simplelogin-join-forces/ Check out my security-enhancing challenge coins! https://d20key.com/#/Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
When people don't understand how something works, it can be easy to be afraid of the consequences of that thing not working right. And this also makes them ripe targets for being frightened by hucksters who will then happily sell them a solution for the problem. This was the trade of snake oil salesmen back in the day - selling cures for ailments that didn't exist or that didn't actually improve the consumer's health. The realm of computers is rife with cybersecurity snake oil, as well, and one of the most lucrative products is a virtual private network (VPN) service. Today I'm going to help you understand just what a VPN is and (perhaps more importantly) what it is not.
In other news: T-Mobile tried to buy their hacked customer data back (and failed); the feds have discovered a troubling and powerful new hacking toolkit for industrial control systems; 8 million Cash App users may have had their data exposed; Pegasus spyware was discovered on the devices of EU officials; a company is offering to install chips under your skin that will allow you to pay for stuff with your hand; a scathing article about a security failure by Wyze web cams; and hackers are using fake Emergency Data Requests to get your data from tech companies.
Article Links
T-Mobile Secretly Bought Its Customer Data from Hackers to Stop Leak. It Failed. https://www.vice.com/en/article/k7w9mv/tmobile-hacked-bought-data-mandiant Feds Uncover a ‘Swiss Army Knife’ for Hacking Industrial Control Systems https://www.wired.com/story/pipedream-ics-malware/ Over 8 Million Cash App Users Potentially Exposed in a Data Breach After a Former Employee Downloaded Customer Information https://www.cpomagazine.com/cyber-security/over-8-million-cash-app-users-potentially-exposed-in-a-data-breach-after-a-former-employee-downloaded-customer-information/ Pegasus spyware hacked iPhones of senior EU officials, who were alerted by Apple https://9to5mac.com/2022/04/11/pegasus-spyware-hacked-iphones-of-senior-eu-officials/ The microchip implants that let you pay with your hand https://www.bbc.com/news/business-61008730 I’m done with Wyze https://www.theverge.com/23003418/wyze-cam-v1-vulnerability-no-patch-bitdefender-responsible-disclosure Hackers Using Fake Police Data Requests against Tech Companies https://www.schneier.com/blog/archives/2022/04/hackers-using-fake-police-data-requests-against-tech-companies.html VPNs are digital 'snake oil,' expert claims — here's why https://www.tomsguide.com/news/vpn-big-claims-truth-shmoocon22 What a VPN Is (and Isn’t): https://firewallsdontstopdragons.com/what-a-vpn-is-and-isnt/
Further Info
John Oliver on data brokers: https://www.youtube.com/watch?v=wqn3gR1WTcA Mullvad VPN: https://mullvad.net/IVPN: https://www.ivpn.net/ProtonVPN: https://protonvpn.com/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Today, most of us take the internet - and access to the internet - for granted. It's ubiquitous. However, the current war in Ukraine has (hopefully) made us realize that things can change dramatically overnight. While we can always hope for the best, we should be at least minimally prepared for the worst. I'm not suggesting we all prepare for military invasion, but there are much more likely scenarios that might lead to power and communications infrastructure problems like bad storms, natural disasters, and even radical political shifts in democratic countries. Understanding the fundamentals of how our digital world works can help us be more resilient in the face of emergencies. Today I'll be speaking with a lead cybersecurity instructor from the Tech Learning Collective about some lessons we can learn from the current Russia-Ukraine conflict and be better prepared for digital disruption.
Further Info
Tech Learning Collective: https://techlearningcollective.com/ How to Prepare for a Power Outage: https://firewallsdontstopdragons.com/how-to-prepare-for-power-outage/ Download Wikipedia: https://wiki.kiwix.org/wiki/Content_in_all_languages VulnHub downloadable, free CTFs: https://www.vulnhub.com/ Black Hills Infosec: https://www.blackhillsinfosec.com/ Crypto-Gram by Bruce Schneier: https://www.schneier.com/crypto-gram/ Code: The Hidden Language of Computer Hardware and Software: https://www.amazon.com/Code-Language-Computer-Hardware-Software/dp/0735611319 The Art of Exploitation: https://www.amazon.com/Hacking-Art-Exploitation-Jon-Erickson/dp/1593271441 Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
I wrap up my de-Google project this week with two biggies: Google Drive and Google Docs. I decided to reduce my Google data footprint as one of my 2022 New Year's resolutions, so I've done a ton of research to replace all the major Google services with privacy-respecting alternatives. My hope is that you can use this information to reduce your own Google data exposure (and help your friends and family, while you're at it).
In other news: UK police arrested seven people that may be tied to the Lapsus$ hacking group; the FCC has flagged Kaspersky software as a risk to national security; a very tricky new phishing technique tricks you into giving up your Facebook, Apple and Google credentials; an open-source software developer makes the dubious decision to target Russian users with "protestware"; the US passes a much-needed cybersecurity regulation (that takes way too long to come into effect); the Russia-based Yandex search engine is harvesting user details from many people, even those not using its search engine; app developers and cloud service providers are leaving your data lying around for anyone to find; and Google is testing its new tracking platform called Topics, which they will use to eventually replace third party cookies.
Article Links
UK police arrest 7 hacking suspects – have they bust the LAPSUS$ gang? https://nakedsecurity.sophos.com/2022/03/25/uk-police-arrest-7-hacking-suspects-have-they-bust-the-lapsus-gang/ FCC flags Russian cybersecurity firm Kaspersky as risk to national security https://mashable.com/article/fcc-bans-kaspersky-antivirus This 'browser in browser' attack will steal your passwords — here's how to avoid it https://www.tomsguide.com/news/bitb-phishing-attackDeveloper Sabotages Open-Source Software Package https://www.schneier.com/blog/archives/2022/03/developer-sabotages-open-source-software-package.htmlUS Passes "Game-Changing" Cyber Incident Reporting Legislation https://www.infosecurity-magazine.com/news/us-cyber-incident-reporting/ Yandex is sending data harvested from millions of iOS users to Russia https://9to5mac.com/2022/03/29/yandex-is-sending-data-from-ios-users/ Your personal data is exposed to hackers — alarming report reveals mobile apps are not protecting your info https://www.laptopmag.com/news/your-personal-data-is-exposed-to-hackers-alarming-report-reveals-mobile-apps-are-not-protecting-your-info Chrome’s “Topics” advertising system is here, whether you want it or not https://arstechnica.com/gadgets/2022/03/googles-topics-advertising-system-starts-rolling-out-to-chrome-canary/ De-Google My Life, Part 4: https://firewallsdontstopdragons.com/de-google-my-life-part-4
Further Info
Crypotmator: https://cryptomator.org/Sync.com: https://www.sync.com/ ONLYOFFICE: https://www.onlyoffice.com/ NextCloud: https://nextcloud.com/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Today I'm speaking with a fellow privacy evangelist: Henry from Techlore. Like me, Henry and his team are on a mission to teach regular, everyday people how to secure their data and improve their privacy. Henry and I have a frank discussion about the importance of privacy today and the struggles we have when deciding which privacy-oriented products to recommend. First of all, everyone's privacy "threat model" is different. Second, many people still don't understand the true impacts of privacy failures - to themselves and to society in general. Privacy isn't just a "me" thing - it's also very much a "we" thing. And if all of that weren't enough, privacy advocates argue constantly (and often heatedly) about the proper litmus tests to use when evaluating privacy-oriented products. Today, Henry and I will discuss what frustrates us and what gives us hope in the highly nuanced realm of privacy.
Further Info
Podcast 5th Anniversary Giveaway! https://firewallsdontstopdragons.com/5th-anniversary-giveaway/ Techlore: https://techlore.tech/ Support Techlore! https://www.patreon.com/techlore Simple Login: https://simplelogin.io/MySudo: https://mysudo.com/ Privacy.com: https://privacy.com/ Malwarebytes Lock & Code podcast: https://blog.malwarebytes.com/category/podcast/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
One of my New Year's resolutions for 2022 is to reduce my Google footprint - to try to de-Google my life as best I can - and hopefully inspire you to do the same. In today's show, I'll talk about replacing Google's many communications apps (Meet, Hangouts, Chat, Talk), Google Authenticator (the Kleenex of 2FA apps), Google Maps and Waze, and YouTube.
In security and privacy news: ISPs in the UK are complaining about Apple's Private Relay feature; the Federal Trade Commission has a new weapon to fight algorithmic data mining; if someone tricks you into sending them money via Zelle, your bank probably won't give it back; Russia has issued a state-sponsored "trusted root CA" that could undermine privacy in Russia for a decade; the EFF weighs in on attempts to cut off Russia (and its citizens) from the internet; DuckDuckGo took a controversial step to down-rate Russian mis/disinformation in its search results; Google is mining info from receipts and invoices in your email; and Google is also mining data from your dialer and messaging apps on Android.
Article Links
UK Network Operators Target iCloud Private Relay in Complaint to Regulator https://www.macrumors.com/2022/03/13/uk-network-operators-target-icloud-private-relay/ The FTC’s new enforcement weapon spells death for algorithms https://www.protocol.com/policy/ftc-algorithm-destroy-data-privacy Fraud is flourishing on Zelle. The banks say it’s not their problem. https://www.seattletimes.com/business/fraud-is-flourishing-on-zelle-the-banks-say-its-not-their-problem/ You Should Not Trust Russia’s New “Trusted Root CA” https://www.eff.org/deeplinks/2022/03/you-should-not-trust-russias-new-trusted-root-ca Wartime Is a Bad Time To Mess With the Internet https://www.eff.org/deeplinks/2022/03/wartime-bad-time-mess-internet DuckDuckGo down-ranks sites spreading Russian propaganda https://www.bleepingcomputer.com/news/technology/duckduckgo-down-ranks-sites-spreading-russian-propaganda/ Gmail tracking: Google keeps records of everything you buy. Here is how to delete this information. https://tutanota.com/blog/posts/gmail-tracks-everything-you-buy/ Google to make changes to apps after TCD study finds privacy issues https://www.irishtimes.com/business/technology/google-to-make-changes-to-apps-after-tcd-study-finds-privacy-issues-1.4826225 De-Google My Life, Part 3: https://firewallsdontstopdragons.com/de-google-my-life-part-3/
Further Info
Podcast 5th Anniversary Giveaway! https://firewallsdontstopdragons.com/5th-anniversary-giveaway/ My Lock & Code podcast interview: https://blog.malwarebytes.com/podcast/2022/03/de-googling-carey-parkers-and-your-life-lock-and-code-s03e06/ Data Privacy for Cars: https://podcast.firewallsdontstopdragons.com/2021/09/13/driving-data-privacy-for-cars/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
We didn't use to think too much about physical computer security because most computers were safely stored in our homes or businesses. But many people today use laptops which can be lost or stolen while traveling or toting them back and forth to work. Having physical access to a computer makes it much easier for bad guys to hack into them and steal our data. By "sniffing" the data signals on the wires in computer motherboards, bad guys can actually pull out security keys that would allow them to bypass encrypted hard drives and account authentication. To combat this, Microsoft's Pluton project makes this data exfiltration much, much harder by embedding the security circuitry directly into the CPU chip where the "wires" are microscopic and embedded in plastic casings.
Tony Chen is a software engineer and security architect in the Microsoft core operating systems team. He's was the development lead responsible for Xbox One security that worked with the hardware team and AMD to successfully launch the Xbox One console in 2013 which has not been hacked for piracy or cheating for over 5 years.
Further Info
MIcrosoft's Pluton project: https://www.microsoft.com/security/blog/2020/11/17/meet-the-microsoft-pluton-processor-the-security-chip-designed-for-the-future-of-windows-pcs/ Podcast 5th Anniversary Giveaway! https://firewallsdontstopdragons.com/5th-anniversary-giveaway/Malwarebytes Lock & Code podcast: https://blog.malwarebytes.com/category/podcast/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
As my de-Google project progresses, I realized that I skipped the most important step: reconnaissance. Before you can de-Google your life, you need to first make a list of the Google products and services you interact with - and not all of them have "Google" in their names. Google also owns YouTube, Waze, Nest, Fitbit, Chromebooks, and much more. Furthermore, you need to know and understand what information Google already knows about you. And while you're doing that, you should delete all the existing data and prevent further collection. Thankfully, Google provides several tools to help you do this (most likely due to regulations like GDPR and CCPA). I'll help you create your personal de-Google to-do list.
In other news: today I'm launching a massive giveaway promotion to celebrate the 5th anniversary of the podcast!! Also, 100 million Samsung phones shipped with horrible security flaws; Nvidia hackers are pressuring the company to turn off cryptocurrency mining limitations; the (Russian) Conti and TrickBot ransomware operations have been hacked; details of 120,000 Russian soldiers in Ukraine have been leaked (on purpose); the US Senate has passed landmark cybersecurity legislation in light of the rising cyber warfare threat; and the ACLU has published a sobering report about a mass surveillance company called Flock (no relation to Google's FLoC).
Article Links
100 Million Samsung Phones Shipped With Flawed Encryption https://www.cpomagazine.com/cyber-security/100-million-samsung-phones-shipped-with-flawed-encryption-galaxy-s8-to-s21-series-cryptographic-keys-trivial-to-expose/ Nvidia Hackers Threaten to Release Mining-Limiter Killer https://www.tomshardware.com/news/nvidia-hackers-threaten-to-release-lhr-performance-limiter Conti Ransomware source code leaked by Ukrainian researcher https://www.bleepingcomputer.com/news/security/conti-ransomware-source-code-leaked-by-ukrainian-researcher/ Details of '120,000 Russian soldiers' leaked by Ukrainian media https://www.theregister.com/2022/03/02/russian_soldier_leaks/ Senate passes cybersecurity act forcing orgs to report cyberattacks, ransom payments https://www.zdnet.com/article/senate-passes-cybersecurity-act-forcing-critical-infrastructure-orgs-to-report-cyberattacks-ransom-payments/ Fast-Growing Company Flock is Building a New AI-Driven Mass-Surveillance System https://www.aclu.org/report/fast-growing-company-flock-building-new-ai-driven-mass-surveillance-system My De-Google Strategy: https://firewallsdontstopdragons.com/my-de-google-strategy/ Lawrence Lessig’s article: https://medium.lessig.org/crowdsourced-war-b5774c0ca7b5
Further Info
5th Anniversary Giveaway!! Details will be posted this week on my blog - keep your eye out on my main website! https://firewallsdontstopdragons.com/ Check out Techlore: https://techlore.tech/ Conti Ransomware report from Krebs On Security: https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-i-evasion/ https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-ii-the-office/ https://krebsonsecurity.com/2022/03/conti-ransomware-group-diaries-part-iii-weaponry/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Your cell phone is a super computer and phenomenally powerful tracking device. Even George Orwell wouldn't have dreamed that telescreens would be pocket sized and that citizens would willingly carry them 24/7. That one device knows all about you and has access to your most personal and critical information, including contacts, emails, social media, financial accounts, medical information, and much more. Furthermore, these devices are often used to secure our accounts through two-factor authentication. Stealing or cloning someone's mobile phone can have dire consequences. Therefore, it's crucial that we protect it. Today, I'll speak with Habeeb Awan whose company Efani is dedicated to providing secure phones and cell service to its VIP clientele, and we'll get his insights into the security risks and mitigation techniques of the mobile world.
Haseeb Awan built one of the first and largest bitcoin ATMs - Bitaccess - which has 8000+ locations in 15 countries. He is also the CEO of Efani, America's most secure and private cell phone service, which protects people against SIM Swaps, eavesdropping, and location tracking.
Further Info
Efani: https://www.efani.com/ My Startpage interview: https://www.startpage.com/privacy-please/privacy-advocate-articles/privacy-in-action-carey-parker-author-and-podcast-hostSubscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
One of my big goals for 2022 was to minimize my Google footprint. In the last news show, I covered Google Search, Chrome and Android. In today's show, I'll tackle two other big ones: Google's email (Gmail) and calendar (Gcal) services (and Google's contacts, for good measure). I actually replaced Gmail with two different services, because they each address two different needs I have.
In others news: Microsoft finally disables Word and Excel macros by default for any file downloaded from the internet; the IRS backs off it's requirement for using facial recognition to authenticate to the IRS website; Missouri's prosecutor declines to prosecute the reporter who pointed out a state website which gave away social security numbers for some state employees; Kashmir Hill compares the relative privacy and tracking capabilities of AirTags, Tile and a cheap GPS tracker; two US senators are decrying a newly declassified report of a CIA program that surveils American citizens in bulk; a remote test proctoring company sinks to new lows; hundreds of Android apps were found to be tracking you using ultrasonic signals; and Google will be implementing a new privacy feature in Android that it claims is just as private as Apple's App Tracking Transparency, but will somehow preserve the ad-based web economy.
Article Links
Microsoft's Small Step to Disable Macros Is a Huge Win for Security https://www.wired.com/story/microsoft-disables-macros-default-security-phishing/ IRS To Ditch Biometric Requirement for Online Access https://krebsonsecurity.com/2022/02/irs-to-ditch-biometric-requirement-for-online-access/ Missouri prosecutor won't press charges against reporter who found flaw in state website https://www.kcur.org/politics-elections-and-government/2022-02-14/missouri-prosecutor-wont-press-charges-against-reporter-who-found-flaw-in-state-website New test shows AirTag’s safety precautions are far better than Tile, other GPS trackers https://9to5mac.com/2022/02/11/airtag-safety-vs-tile/ T2 Mac security vulnerability means passwords can now be cracked https://9to5mac.com/2022/02/17/t2-mac-security-vulnerability-passware/ Senators say CIA has been collecting data in bulk in secret program https://thehill.com/homenews/administration/593833-senators-say-cia-has-been-collecting-american-data-in-bulk-in-secret A Network of Fake Test Answer Sites Is Trying to Incriminate Students https://themarkup.org/machine-learning/2022/02/15/a-network-of-fake-test-answer-sites-is-trying-to-incriminate-students Hundreds of apps spying on users with ultrasonic tracking technology https://www.komando.com/gadgets/hundreds-of-apps-spying-on-users-with-ultrasonic-tracking-technology/402030/ Google's New Plan for Android Privacy Doesn't Sound All That Private https://gizmodo.com/google-android-privacy-sandbox-apple-ios-meta-1848547922?rev=1645048008531 De-Google My LIfe (part 2): https://firewallsdontstopdragons.com/de-google-my-life-part-2/
Further Info
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
You may not know it, but our world has already been basically taken over by free and open source software, or FOSS - specifically, the Linux operating system. Just about every single electronic appliance or device today, from your smartphone to your smart toaster, is running some flavor of the Linux operating system. Furthermore, open source software projects are the bedrock of many for-profit software applications, operating systems, mobile apps and web apps. It's everywhere, and yet you probably know very little about it. Today, Sean O'Brien will give us a little FOSS history lesson, explain why supporting this movement is so important, and even tell us how we might replace some pricey and user-hostile popular software with top-notch free and open alternatives.
Sean O’Brien is a lecturer in Cybersecurity at Yale Law School and Chief Security Officer at Panquake.com He is a Visiting Fellow at the Information Society Project at Yale Law School, where he founded and leads the Privacy Lab initiative. He has been involved in Free and Open-Source Software (FOSS) for approximately two decades, including volunteer work for the Free Software Foundation and FreedomBox Foundation.
Show Links
Panquake: https://panquake.com/ Yale Privacy Lab: https://privacylab.yale.edu/ It’s FOSS website: https://itsfoss.com/ Free Software Foundation: https://www.fsf.org/ Intro to Linux classes: https://itsfoss.com/free-linux-training-courses/ Windows Subsystem for Linux: https://docs.microsoft.com/en-us/windows/wsl/about System 76: https://system76.com/Purism: https://puri.sm/ Lineage OS: https://lineageos.org/Graphene OS: https://grapheneos.org/ Calyx OS: https://calyxos.org/ F-Droid: https://f-droid.org/ LibreOffice: https://www.libreoffice.org/ VLC Media Player: https://www.videolan.org/vlc/ Audacity audio editor: https://www.audacityteam.org/GIMP photo editor: https://www.gimp.org/ Inkscape illustrator: https://inkscape.org/ CryptPad: https://cryptpad.fr/
Further Info
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
One of my New Year's Resolutions for 2022 is to minimize my Google footprint. In reality, it's very difficulty to completely avoid Google products, if you include things like Google Analytics, Google's cloud computing, and other services that we may not directly choose. But thankfully, there are many excellent, privacy-respecting alternatives to Google's more well-known products and services. In today's show, I'll start with some of the most basic ones: Google Search, Google Chrome browser, and Android.
In other news: Google beats Apple to offering a way to disable insecure 2G cellular connections; people are selling "silent" AirTags that won't beep to let you know they're near (which could be better for stalking people); Facebook reported its first ever loss in subscribers along with a $10 billion loss due to people opting out of ad tracking; privacy advocates scored a huge win in the European Union against advertisers collecting and sharing your data; the IRS may be rethinking its coming requirement for facial recognition-based authentication after pushback; the FBI admits to evaluating NSO Group's nasty Pegasus cell phone spyware; Kaspersky finds several serious vulnerabilities in wearable medical devices; and Google has abandoned its FLoC web tracking system for a much more privacy-respecting version called Topics.
Article Links
EFF praises Android’s new 2G kill switch, wants Apple to follow suit https://arstechnica.com/gadgets/2022/01/eff-praises-androids-new-2g-kill-switch-wants-apple-to-follow-suit/Sale of 'Silent AirTags' on eBay and Etsy Raises Privacy Concerns https://www.macrumors.com/2022/02/03/silent-airtags-privacy-concerns/Facebook lost daily users for the first time ever last quarter https://www.theverge.com/2022/2/2/22914970/facebook-app-loses-daily-users-first-time-earnings A Change by Apple Is Tormenting Internet Companies, Especially Meta https://www.nytimes.com/2022/02/03/technology/apple-privacy-changes-meta.html Regulators find Europe’s ad-tech industry acted unlawfully https://www.engadget.com/european-union-gdpr-ad-tech-unlawful-iccl-iab-europe-125735068.htmlTreasury Weighing Alternatives to ID.me Over Privacy Concerns https://www.bloomberg.com/news/articles/2022-01-28/treasury-weighing-id-me-alternatives-over-privacy-concerns FBI acknowledges it tested NSO Group’s spyware https://www.washingtonpost.com/technology/2022/02/02/pegasus-fbi-nso-test/ Unpatched Security Bugs in Medical Wearables Allow Patient Tracking, Data Theft https://threatpost.com/unpatched-security-bugs-medical-wearables-patient-tracking-data-theft/178150/ Google abandons FLoC, introduces Topics API to replace tracking cookies https://www.theverge.com/2022/1/25/22900567/google-floc-abandon-topics-api-cookies-tracking De-Google My Life, Part 1: https://firewallsdontstopdragons.com/de-google-my-life-part-1/Apple’s new Personal Safety User Guide: https://support.apple.com/guide/personal-safety/welcome/web
Further Info
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
We tell our search engines a lot of very personal things. They arguably know more about us than our best friends and significant others do. A history of your search terms can reveal so much about you, especially when viewed over the course of days, months and even years. And unfortunately, companies like Google use this privileged position to better target us with advertisements. This may seem innocuous, today's guest, Kelly Finnerty, will explain how this data collection can lead to some truly creepy outcomes and even emotional harm. But it doesn't have to be that way. There are search engines and other tools that don't track your history and sell you out. And there is hope for a brighter, privacy-respecting future.
Kelly Finnerty is the director of brand for Startpage, a global privacy technology company that provides search and browsing products that protect people's personal data. Kelly is a #techforgood advocate that believes privacy is a worldwide human right.
Episode Links
Startpage browser extension: https://add.startpage.com/protection/ What does your search engine know about you? https://www.startpage.com/privacy-please/startpage-articles/what-does-your-search-engine-know-about-you Startpage data flow: https://support.startpage.com/index.php?/en/Knowledgebase/Article/View/1276/0/how-startpage-processes-and-protects-your-dataInterview with System1 CEO: https://thinkprivacy.ch/system1-interview/ Terms of Service; Didn’t Read: https://tosdr.org/ EFF’s Surveillance Self Defense: https://ssd.eff.org/
Further Info
Annual listener survey: https://bit.ly/Firewalls-survey-2022Carey’s 2022 Privacy Blog: https://firewallsdontstopdragons.com/data-privacy-week-2022/ Carey’s Privacy Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ Data Privacy Week: https://staysafeonline.org/data-privacy-week/Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Personal data privacy isn't going to just happen on its own. We have to somehow collectively construct it. But how? Will it require regulation or can consumers drive change by consciously choosing privacy-respecting products and services? When it comes to regulations, why are things so different in the European Union versus the US and other global markets? What do privacy teams look like in modern corporations and how should they function? I'll pose these and many other questions to my guest, Whitney Merrill, who brings unique experience on privacy from both the private sector and the federal government.
Whitney Merrill is a data protection officer, privacy attorney, hacker, and the co-founder of the Crypto & Privacy Village. She loves privacy and is glad the world is getting excited about it, too.
Podcast Links
Carey’s 2022 Privacy Blog: https://firewallsdontstopdragons.com/data-privacy-week-2022/ Carey’s Privacy Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ Data Privacy Week: https://staysafeonline.org/data-privacy-week/FTC Privacy & Security: https://www.ftc.gov/tips-advice/business-center/privacy-and-security EFF Surveillance Self Defense Guide: https://ssd.eff.org/ACLU Privacy & Technology: https://www.aclu.org/issues/privacy-technology IAPP Resources: https://iapp.org/resources/ European Data Protection Board: https://edpb.europa.eu/edpb_en Data Protocol: https://dataprotocol.com/ The Gamification of Everything: https://lifehacker.com/how-gamification-of-everything-is-manipulating-you-and-1848352808
Further Info
Annual listener survey: https://bit.ly/Firewalls-survey-2022Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Of course, every week should be "data privacy week", but we do set aside a specific time each year to focus on privacy - particularly educating as many people as possible about it. Until this year, we only dedicated one day for this - but as of 2022, it's been promoted to an entire week! Data Privacy Week runs from January 24-28, so today I'm going to prep you for it with several of my top privacy protection tips!
In the news: the FBI uses foreign intelligence services to sidestep US surveillance restrictions; Russia takes down the REvil ransomware outfit as the United State's request; Google gives Android users the ability to disable insecure 2G cell connections; Subaru is sued in Illinois for capturing driver's biometric information with consent; lawmakers propose legislation to simplify and standardize terms of services agreements; and the Ponemon Institute releases the results of a recent poll on what people worry about with relation to privacy and what they feel should be done about it.
Article Links
Using Foreign Nationals to Bypass US Surveillance Restrictions https://www.schneier.com/blog/archives/2022/01/using-foreign-nationals-to-bypass-us-surveillance-restrictions.html Russia’s FSB says it has taken down REvil hacker group at US request https://www.theverge.com/2022/1/14/22883675/russia-fsb-revil-hacker-group-ransomware-us-request-fbi-doj VICTORY: Google Releases “disable 2g” Feature for New Android Smartphones https://www.eff.org/deeplinks/2022/01/victory-google-releases-disable-2g-feature-new-android-smartphones Class action: Subaru DriverFocus system improperly scans driver's faces, eyes https://cookcountyrecord.com/stories/613746211-class-action-subaru-driverfocus-system-improperly-scans-driver-s-faces-eyes Lawmakers Come After Companies’ Terms of Service With New TLDR Bill https://www.gizmodo.com.au/2022/01/lawmakers-come-after-companies-terms-of-service-with-new-tldr-bill/ New Ponemon Institute Report Indicates Major Consumer Privacy Gap https://www.cpomagazine.com/data-privacy/new-ponemon-institute-report-indicates-major-consumer-privacy-gap/
Further Info
Data Privacy Week: https://staysafeonline.org/data-privacy-week/about-dpw/ My Data Privacy checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ DNA service impacts: https://thenib.com/its-all-relatives/ Annual listener survey: https://bit.ly/Firewalls-survey-2022Hunting for Stingrays podcast: https://podcast.firewallsdontstopdragons.com/2021/04/19/hunting-for-stingrays-part-1/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
It's the start of a brand new calendar year! And therefore it's time to engage in that annual ritual of planning to do better this year by making our list of New Year's Resolutions. To help you with the cybersecurity and privacy items on your list (an area where we all need major improvement), I will share with you my personal list of cyber goals for 2022. Yes, even security advocates can suffer from the "do as I say, not as I do" syndrome. We're all human, and there are plenty of things that I still need to get done - things that you probably need to do, too.
I'll also catch you up on the latest security and privacy news: several articles popped up about a supposed data breach at LastPass that turned out to be incorrect; the US Federal Trade Commission is getting very serious about fining companies with lax cybersecurity practices in light of the Log4J/Log4Shell nightmare; clever scammers in Texas are tricking motorists into paying the wrong people for parking; Norton 360 and other antivirus software packages have started pre-installing cryptocurrency mining software on their customers' computers; TurboTax is the second major tax-filing software service to drop out of the federal Free File program; Google's adoption of the Manifest V3 specification gives users yet another reason not to use their Chrome browser; and a lawsuit in California alleges that Google's exclusive search engine deal with Apple is stifling competition and harming consumers.
Article Links
LastPass says there’s no data breach, so your passwords were not hacked https://bgr.com/tech/lastpass-says-theres-no-data-breach-so-your-passwords-were-not-hacked/?bgr-partner=flipboard FTC to Go After Companies that Ignore Log4j https://threatpost.com/ftc-pursue-companies-log4j/177368/ QR code scammers hitting on-street parking in Texas cities https://www.click2houston.com/news/local/2022/01/05/qr-code-scammers-hitting-on-street-parking-in-texas-cities-this-is-what-houston-officials-want-you-to-know/ Norton 360 Now Comes With a Cryptominer https://krebsonsecurity.com/2022/01/norton-360-now-comes-with-a-cryptominer/ 500M Avira Antivirus Users Introduced to Cryptomining https://krebsonsecurity.com/2022/01/500m-avira-antivirus-users-introduced-to-cryptomining/ Want to file your tax return for free? TurboTax opts out of major program https://www.freep.com/story/money/personal-finance/susan-tompor/2022/01/05/how-file-your-tax-return-free-turbotax/9077019002/ Podcast on Free File report from Pro Publica: https://podcast.firewallsdontstopdragons.com/2020/01/13/why-free-file-isnt-free/ Google makes the perfect case for why you shouldn't use Chrome https://www.techrepublic.com/article/google-makes-the-perfect-case-for-why-you-shouldnt-use-chrome/ Google Basically Pays Apple to Stay Out of the Search Engine Business, Class Action Lawsuit Alleges https://www.macrumors.com/2022/01/05/google-pays-apple-stay-out-of-search/ Betty White on MFA: https://www.youtube.com/watch?v=DmIDtDAYTPA
Further Info
Annual listener survey: https://bit.ly/Firewalls-survey-2022Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/or privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Navigating the online world today is hard enough as an adult. But it's way worse for kids. Not only are they short on life experiences that would give them the context they need, but as students during a pandemic, their privacy rights are being sorely tested by new "edtech" apps and services. Today I speak with Jill Bronfman from Common Sense Media about their new report on the state of privacy for kids. Their research is quite comprehensive - and (spoiler alert) the results aren't great. Obviously, this report is helpful for parents, educators and policy makers - but much of what's covered here is useful knowledge for anyone.
Jill Bronfman is Privacy Counsel at Common Sense Media, teaches Media Ethics and Privacy Law.
Further Info
2021 State of Kid’s Privacy: https://www.commonsensemedia.org/research/state-of-kids-privacy-2021 Common Sense Media: https://www.commonsensemedia.org/ Common Sense Privacy Program: https://privacy.commonsense.org/Boston COVID in the waste water: https://www.msn.com/en-us/weather/topstories/how-fast-is-covid-surging-in-boston-this-chart-shows-the-spike-after-christmas/ar-AAShL4P Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
We've come to the end of another year. As we take a breather and gather with family and friends for the holidays, it's a good time to look back over the year that just passed. I've collected a handful of snippets from some of my favorite shows from this year, along with some a little commentary.
If you're new to the show, you can catch up on some stuff you may have missed. Or if you'd like to introduce someone else to the podcast, this would be a great one to share.
You can find all the original, full-length episodes using the links below.
Best Of Episodes
Ep206, Feb 8 - Troy Hunt, De-Platforming: https://podcast.firewallsdontstopdragons.com/2021/02/08/free-speech-deplatforming/Ep214, Apr 5 - Phil Zimmerman, Social media is ruining society https://podcast.firewallsdontstopdragons.com/2021/04/05/social-media-is-ruining-societyEp219, May 10 - Alison Macrina, library freedom https://podcast.firewallsdontstopdragons.com/2021/05/10/protecting-intellectual-freedom-part-1/ Ep232, Aug 9 - DEFCON - understanding hackers https://podcast.firewallsdontstopdragons.com/2021/08/11/understanding-hackers-hacking/ Ep233, Aug 16 - DEFCON - Jeff Moss interview https://podcast.firewallsdontstopdragons.com/2021/08/16/on-a-dark-tangent/Ep235, Aug 30 - Morpheus - Todd Austin https://podcast.firewallsdontstopdragons.com/2021/08/30/morpheus-securing-cpus-with-entropy/Ep237, Sep 13 - Privacy for Cars - Andrea Amico https://podcast.firewallsdontstopdragons.com/2021/09/13/driving-data-privacy-for-cars/Ep245, Nov 8 - Harri Hursti https://podcast.firewallsdontstopdragons.com/2021/11/08/restoring-trust-in-our-elections/ Ep200, Dec 27, 2020 - Bruce Schneier https://podcast.firewallsdontstopdragons.com/2020/12/28/200th-podcast-new-years-2021/
Further Info
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
The internet is on fire this week. The worst cybersecurity vulnerability of the last ten years (and perhaps more) has kicked the internet ant hill. Companies around the globe - big and small - are scrambling to repair a gaping hole in a ridiculously mundane but widely popular open source tool called Log4J. What it is and what does it mean for you? I'll get into all of that today.
In other news: many popular wireless home routers are riddled with security bugs (update your firmware now); family "safety" app Life360 is selling your detailed location data; Consumer Reports released a comprehensive report on VPN security and privacy; Firefox just got a lot more secure; LastPass is once again an independent company; Apple released a lot of cool security and privacy features for iOS and macOS; and Verizon just opted you into a program for tracking you - and how you can opt out. (I'll touch on T-Mobile and AT&T tracking, too.)
Article Links
Op-Ed: What a house cat can teach us about cybersecurity https://www.latimes.com/opinion/story/2021-11-07/op-ed-what-a-house-cat-can-teach-us-about-cybersecurity Nine WiFi routers used by millions were vulnerable to 226 flaws https://www.bleepingcomputer.com/news/security/nine-wifi-routers-used-by-millions-were-vulnerable-to-226-flaws/ The Popular Family Safety App Life360 Is Selling Precise Location Data on Its Tens of Millions of Users https://themarkup.org/privacy/2021/12/06/the-popular-family-safety-app-life360-is-selling-precise-location-data-on-its-tens-of-millions-of-user Consumer Reports exhaustive report on VPNs https://www.consumerreports.org/vpn-services/mullvad-ivpn-mozilla-vpn-top-consumer-reports-vpn-testing-a9588707317/ The new Firefox 95 might be the most secure web browser on the market https://www.techrepublic.com/article/the-new-firefox-95-might-be-the-most-secure-web-browser-on-the-market/ The Log4Shell 0-day, four days on: What is it, and how bad is it really? https://arstechnica.com/information-technology/2021/12/the-log4shell-zeroday-4-days-on-what-is-it-and-how-bad-is-it-really/ Widely-Used Kronos Payroll Provider Down for “Weeks” Due to Ransomware Attack; Was Log4Shell Involved? https://www.cpomagazine.com/cyber-security/widely-used-kronos-payroll-provider-down-for-weeks-due-to-ransomware-attack-was-log4shell-involved/ LastPass is going to become an independent company https://www.theverge.com/2021/12/14/22833319/lastpass-independent-company-logmeinHow to Use App Privacy Report in the iOS 15.2 Beta https://www.macrumors.com/guide/app-privacy-report/iOS 15.2 Beta 2 Lets Your Family Access Your Data If You Pass Away https://www.macrumors.com/2021/11/09/ios-15-2-legacy-contact/ Hide My Email Available in Mail App With New iOS 15.2 and macOS Monterey 12.1 Betas https://www.macrumors.com/2021/11/09/macos-monterey-12-1-beta-2-hide-my-email/ iOS 15.2 Beta Adds Messages Communication Safety Feature for Kids https://www.macrumors.com/2021/11/09/apple-messages-communication-safety-ios-15-2/ Verizon May Have Just Enrolled You in a Data-Collection Scheme–Here's How to Get Out https://gizmodo.com/verizon-may-have-just-enrolled-you-in-a-data-collection-1848156157
Further Info
Still looking for holiday gifts? https://firewallsdontstopdragons.com/best-worst-gifts-2021/ Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
The rampant collection and sharing of personal data is not just a creepy nuisance. Surveillance capitalism has actually had seriously deleterious effects on society and democracy. In the United States, we have certain rights enshrined in the Constitution that are supposed to protect citizens against unreasonable search and seizure. Law enforcement and intelligence agencies are supposed to have to jump through some non-trivial legal hoops in order to access our personal data. But with a massive market for gathering and correlating your location, purchase history, web surfing habits, search history, and more, it's become trivial to circumvent these pesky road blocks by just buying the information from data brokers. In an important and landmark report from the Center for Democracy and Technology, the end run around our supposed rights has become frighteningly clear. Today I speak with Dhanaraj Thakur about this report and what it means for our democracy.
Dhanaraj Thakur is Research Director at the Center for Democracy & Technology, where he leads research that advances human rights and civil liberties online.
Further Info
CDT Report on Legal Loopholes: https://cdt.org/insights/report-legal-loopholes-and-data-for-dollars-how-law-enforcement-and-intelligence-agencies-are-buying-your-data-from-brokers/ Center for Democracy & Technology: https://cdt.org/ Patriot Act Turns 20 panel discussion: https://www.youtube.com/watch?v=xaUIvxLdGCQMy particular question at the panel: https://www.youtube.com/watch?v=xaUIvxLdGCQ&t=4783s Best & Worst Gifts Guide for 2021: https://firewallsdontstopdragons.com/best-worst-gifts-2021/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Transparency is critical when it comes to trust - and right now, particularly in the United States, we're having some real issues with trust in our elections. Most of our election systems today are completely opaque in terms of their hardware and software design because they're made by private companies who want to protect their intellectual property. But this secrecy also seriously impedes independent third parties from being able to test and verify these devices that are crucial to our democracy, and therefore contributes to the distrust in our election outcomes. Microsoft is working to change this with a program called ElectionGuard - a free and open source software framework that would allow any company (existing or new) to create robust and secure election systems. Not only can security researchers, journalists and democracy activists review and test the code, but the system actually provides technical capabilities that would allow voters and watchdog groups with a secure and private method for verifying that all votes were counted correctly. And that's just part of what Microsoft is doing to defend democratic processes as part of their Democracy Forward program.
Ethan Chumley is a Senior Security Strategist for Microsoft’s Democracy Forward Program, leading the team’s Critical Institution cybersecurity programs. He works at the intersection of cybersecurity, policy, and technology in support of open and secure elections by working with political campaigns, elections organizations, think tanks, NGOs, disinformation researchers, and tech industry partners.
Further Info
Microsoft ElectionGuard: https://www.electionguard.vote/ Microsoft's Democracy Forward program: https://news.microsoft.com/on-the-issues/topic/defending-democracy-program/ Contact Microsoft about ElectionGuard: electionguard@microsoft.com Contact Microsoft about protecting elections: protectelections@microsoft.com ElectionGuard code: https://github.com/microsoft/electionguard Harri Hursti interview: https://podcast.firewallsdontstopdragons.com/2021/11/08/restoring-trust-in-our-elections/ Article on brute forcing debit card numbers: https://www.techspot.com/news/92476-hackers-brute-force-guessing-payment-card-numbers-there.html Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Credit cards are more secure than debit cards. I've said this in my book, my podcast, my blog and my seminars. Credit card transactions are loans - you're not out any money if a fraudulent charge comes through (assuming you or the credit card company catches it first). With debit cards, any fraud activity will actually take your money from your account - it's gone and you have to convince your bank to give it back. And so, I almost never use my debit card. And yet, I was still hacked. My card wasn't stolen or cloned with a skimmer. The number wasn't leaked in a hack. The bad guys somehow managed to guess my card number. And then they got clever and drained my bank account. I'll give you the details today and give you some pointers for avoiding being bitten the same way I was.
In other news: bad guys have come up with some very clever ways to drain your bank accounts using Zelle and text messages; they've also used similar techniques to disable the Find My feature on stolen iPhones; Apple is suing Israeli hacking company NSO Group over their Pegasus spyware; attackers apparently don't try guessing passwords longer than about 10 characters; GoDaddy admits to a major breach, but in a dumb way; there's a nasty new Windows bug that was give up by an upset security researcher; there's a powerful IoT malware that appears to be lurking on the internet; Microsoft Windows is doing some shady stuff to force you to use Edge browser and give up your data; and Vizio makes more money off your TV data than off the TV itself.
Article Links
The ‘Zelle Fraud’ Scam: How it Works, How to Fight Back https://krebsonsecurity.com/2021/11/the-zelle-fraud-scam-how-it-works-how-to-fight-back/ iPhone thieves are using this trick to disable Find My on stolen devices https://www.imore.com/iphone-thieves-are-using-trick-disable-find-my-stolen-devices Apple sues NSO Group for attacking iPhones with Pegasus spyware https://www.theverge.com/2021/11/23/22798917/apple-nso-group-spyware-pegasus-cybersecurity-research Apple will alert users exposed to state-sponsored spyware attacks https://appleinsider.com/articles/21/11/25/apple-will-alert-users-exposed-to-state-sponsored-spyware-attacks Attackers don’t bother brute-forcing long passwords https://therecord.media/attackers-dont-bother-brute-forcing-long-passwords-microsoft-engineer-says/ GoDaddy admits to password breach: check your Managed WordPress site! https://nakedsecurity.sophos.com/2021/11/23/godaddy-admits-to-password-breach-check-your-managed-wordpress-site/ New Windows zero-day with public exploit lets you become an admin https://www.bleepingcomputer.com/news/microsoft/new-windows-zero-day-with-public-exploit-lets-you-become-an-admin/ This mysterious malware could threaten millions of routers and IoT devices https://www.zdnet.com/article/this-mysterious-malware-could-threaten-millions-of-routers-and-iot-devices/ Microsoft Enables Edge Sync By Default, Hoovering Up Your Data in the Process https://www.extremetech.com/computing/329162-microsoft-enables-edge-sync-by-default-hoovering-up-your-data-in-the-process?source=Computing Vizio is making more money selling your data than it is selling TVs https://knowtechie.com/vizio-is-making-more-money-selling-your-data-than-it-is-selling-tvs/ My Debit Card Was Hacked: https://firewallsdontstopdragons.com/my-debit-card-was-hacked/
Further Info
HUGE sale on my book! 9.99/6.99: https://link.springer.com/book/10.1007/978-1-4842-6189-7Give Thanks and Donate https://firewallsdontstopdragons.com/give-thanks-donate/ Best & WorstBecome a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
When you think about improving your privacy and protecting your personal information, it's important to realize that it will also improve your security. According to Craig Danuloff, CEO of The Privacy Co. and maker of the Priiv app, privacy harms fall into at least four different buckets: personal data leaks (embarrassment and reputation harm), online tracking (targeted ads and manipulation), financial accounts (including fraud and identity theft), and harassment (stalking, bullying, even physical threats). Today Craig will offer his opinions on the state of privacy today and provide several of his top tips for protecting your privacy and increasing your security.
Craig Danuloff is a technology entrepreneur who has founded a series of tech companies including desktop publishing, e-commerce, ad-tech, identity, and now consumer privacy. Craig is a graduate of the University of Colorado Leeds School of Business, and the author of over 20 computer books.
Further Info
Priiv app: https://www.theprivacy.co/priiv HUGE sale on my book! 9.99/6.99: https://link.springer.com/book/10.1007/978-1-4842-6189-7 Give Thanks and Donate https://firewallsdontstopdragons.com/give-thanks-donate/ Best & WorstGift Guide for 2021: https://firewallsdontstopdragons.com/best-worst-gifts-2021/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
The gift-giving season is officially upon us, and with covid supply chain issues, if you're going to order gifts, you need to get on it. And in today's show, I'll share the highlights of my annual Best & Worst Gift Guide where I focus on the privacy and security of popular gifts. You won't be surprised at a lot of the items on my naughty list, but I'll bet you'll find some interesting ideas from the nice list that you can give your loved ones this holiday season.
I will also cover several news items - many of them actually good news! A new bipartisan bill would allow people to disable news feeds based on algorithms; Apple has dialed back some of it's well-intentioned but poorly-implemented child safety features; Facebook will remove many sensitive categories for targeted ads and stop using facial recognition; several people associate with the Kaseya ransomware hack have been arrested; and 23andme's DNA database (your DNA) may be leveraged foro a lucrative pharmaceutical business.
Article Links
New bipartisan bill takes aim at algorithms https://www.axios.com/algorithm-bill-house-bipartisan-5293581e-430f-4ea1-8477-bd9adb63519c.html Apple Has Listened And Will Retract Some Harmful Phone-Scanning https://www.eff.org/deeplinks/2021/11/apple-has-listened-and-will-retract-some-harmful-phone-scanning Facebook-parent Meta will remove the ability to target ads based on sensitive categories https://www.cnn.com/2021/11/09/tech/meta-facebook-ad-targeting-change/index.html Facebook shutting down face recognition efforts & deleting data https://appleinsider.com/articles/21/11/02/facebook-shutting-down-face-recognition-efforts-deleting-data Meta to continue use of facial recognition technology: https://appleinsider.com/articles/21/11/04/meta-to-continue-use-of-facial-recognition-technology Kaseya ransomware suspect nabbed in Poland, $6m seized from absent colleague https://nakedsecurity.sophos.com/2021/11/08/kaseya-ransomware-suspect-nabbed-in-poland-6m-seized-from-absent-colleague/ All Those 23andMe Spit Tests Were Part of a Bigger Plan https://www.bloomberg.com/news/features/2021-11-04/23andme-to-use-dna-tests-to-make-cancer-drugs
Further Info
My annual Best & Worst Gift Guide is out for 2021! https://firewallsdontstopdragons.com/best-worst-gifts-2021/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Nothing is arguably more fundamental to a democracy than voting. But it's not enough to have a secure election. The electorate also needs to trust that the results are valid. In the United States today, that trust is in short supply - many people believe that the 2020 election was rigged. On one hand, many of our electronic voting systems are demonstrably insecure and trivially capable of being hacked. On the other, our cybersecurity experts, government agencies and election officials are telling us that the 2020 election was one of the most secure in US history and voter fraud almost never happens. So which is it? How do we reconcile these two seemingly incongruent positions?
Today I'll ask these questions and more of computer and election security guru Harri Hursti. Harri has investigated and hacked several popular election systems used in the US and runs the Voting Machine Hacking Village at the annual DEF CON hacking conference. He's also officially observed many elections around the world and participated in several high profile audits. As if that weren't enough, Harri's been featured in two separate HBO documentaries on election security and is co-founder of the Election Integrity Foundation. I met Harri at DEF CON 29 and I was thrilled when he agreed to come on the show.
Further Info
Harri Hursti: https://en.wikipedia.org/wiki/Harri_Hursti Election Integrity Foundation https://electionintegrityfoundation.org/ California voting system review (“top to bottom”): https://www.sos.ca.gov/elections/voting-systems/oversight/top-bottom-review Ohio voting system review (“Everest”): https://www.eac.gov/documents/2017/03/21/everest-report-state-voting-systems-voting-technology New Hampshire election audit: http://doj.nh.gov/sb43/documents/20210713-sb43-forensic-audit-report.pdf Kill Chain: The Cyber War on America's Elections (HBO documentary, 2020) https://www.hbo.com/documentaries/kill-chain-the-cyber-war-on-americas-elections Hacking Democracy (HBO documentary, 2006) https://www.youtube.com/watch?v=b_gb_w_L9NE Election Administration and Voting Survey 2020: https://www.eac.gov/research-and-data/studies-and-reports Voluntary Voting System Guidelines: https://www.eac.gov/voting-equipment/voluntary-voting-system-guidelines CISA, Election Security Rumor vs Reality: https://www.cisa.gov/rumorcontrol 2020 election security reports: https://www.brennancenter.org/our-work/research-reports/its-official-election-was-secure DEF CON 25 Voting Machine Hacking Village Report: https://archive.org/download/DEFCON25VotingVillageReport/DEF%20CON%2025%20voting%20village%20report.pdf Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
There were lots of scary computer security and privacy stories in the news this week, coinciding nicely with Halloween. We'll start off with an unfortunate new cybersecurity term: killware. This is software whose end result is actual physical harm to human beings, including death. Sadly, this is now a thing. And I don't know about you, but Mark Zuckerberg's vision of the future (the "metaverse") is pretty damn scary, too.
In other news: a hacker seems to have stolen the government identity information for every person in Argentina; a New York Times journalist explains how his iPhone has been hacked multiple times by the NSO Group and what he does to protect himself (and his sources); the FBI, the Secret Service and other "like-minded countries" seem to have finally taken down the REvil ransomware gang for good; Facebook has changed its name to "Meta"; link previews in chat apps can actually cause serious security and privacy problems; Delta Airlines and UK schools are normalizing the use of facial recognition for mundane purposes; your ISP is collecting tons of information about you in the US because we let them; and finally, I demystify and debunk the "dangers" of QR codes.
Article Links
Killware: What You Need to Know https://adamlevin.com/2021/10/15/killware-what-you-need-to-know/Hacker steals government ID database for Argentina’s entire population https://therecord.media/hacker-steals-government-id-database-for-argentinas-entire-population/ NYT journalist describes his iPhone being hacked, and the precautions he now takes https://9to5mac.com/2021/10/25/nyt-journalist-describes-his-iphone-being-hacked-and-the-precautions-he-now-takes/ FBI, others crush REvil using ransomware gang’s favorite tactic against it https://arstechnica.com/tech-policy/2021/10/fbi-others-crush-revil-using-ransomware-gangs-favorite-tactic-against-it/ Facebook changes its name to Meta: https://www.inc.com/jason-aten/5-things-mark-zuckerberg-said-about-his-plan-for-metaverse-that-should-make-you-very-worried.html Link Previews in Popular Messaging Apps May Lead to Security Vulnerabilities https://www.macrumors.com/2020/10/26/link-previews-may-lead-to-security-vulnerabilities/ Delta Air Lines partners with TSA PreCheck to launch biometrics-based bag drops https://finance.yahoo.com/news/delta-air-lines-partners-tsa-164655619.html UK schools are using facial recognition to take pupils’ lunch money https://www.theverge.com/2021/10/18/22732330/uk-schools-facial-recognition-lunch-payments-north-ayrshire Location Data Firm Got GPS Data From Apps Even When People Opted Out https://www.vice.com/en/article/5dgmqz/huq-location-data-opt-out-no-consent Internet service providers have so much data on you https://www.protocol.com/policy/isp-ftc-data Beware QR Code… Articles: https://firewallsdontstopdragons.com/beware-qr-code-articles/
Further Info
Only ONE DAY LEFT to snag your challenge coin!! The promotion ends at 11pm Eastern Time on Tuesday, November 2nd! https://firewallsdontstopdragons.com/my-challenge-coins-are-back/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Today, we're surrounded by strong encryption. Thanks to efforts like Let's Encrypt, almost all web communications today at encrypted. And thanks to wonderful privacy communications tools like Signal, we can share private thoughts instantly and securely with anyone on the planet. But this was not always the case. This secure, private, encryption-enabled future we're living now was far from certain 30 years ago when Phil Zimmermann created and freely released his email encryption tool Pretty Good Privacy (PGP). If not for Phil and a handful of others, we could very easily have lost the Crypto Wars of the 1990's and authoritarian mass surveillance could have been the norm.
In today's show, Phil and I walk through the creation of PGP, the technological and political climate of that day, and the nerve-racking few years where Phil faced potential jail time for releasing "munitions grade" encryption to the world. We'll also discuss the literally life-saving impacts PGP has had over these last 30 years and how global law enforcement agencies and liberal democratic governments have revived the Crypto Wars.
Phil Zimmermann is the creator of Pretty Good Privacy, which is still widely regarded as the gold standard for secure email communication. Phil went on to form Silent Circle and win several prestigious awards including US Privacy Champion and was inducted into the Cybersecurity Hall of Fame.
Further Info
Phil Zimmermann’s website: https://philzimmermann.com/ Phil’s announcement for the 30th anniversary of PGP: https://philzimmermann.com/EN/news/index.htmlPGP Web of Trust: https://en.wikipedia.org/wiki/Web_of_trust SNL Bass-o-matic skit: https://www.nbc.com/saturday-night-live/video/bassomatic/n8631 National Cybersecurity Awareness Month resources: https://www.cisa.gov/cybersecurity-awareness-month-resources Only ONE WEEK LEFT to snag your challenge coin!! https://firewallsdontstopdragons.com/my-challenge-coins-are-back/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Facebook had a horrible, no-good, very bad week. Not only did Facebook, Instagram and WhatsApp go completely offline for about six hours, a whistleblower came forward to show the world what most of us already knew: Facebook values money over its users' well being. And I have another story that backs that up, as well - one that you almost surely did not hear about.
In other news: the FTC tells app makers to fess up when users private data gets loose; the governor of Missouri wants to sue a newspaper for revealing a horrible security flaw that exposed teachers' social security numbers; Apple's attempts to prevent user tracking on iOS are being undermined by unscrupulous apps; a company that you've never heard of with access to almost all cellular text messages was hacked over the course of five years; the VPN maker and VPN review industries are awash in conflicts of interest; Windows 11 is finally out, but it's not clear if and whether you should upgrade to it; and Firefox is searching for more ways to make money and stay alive, including adding more sponsored search suggestions for you to consider.
Article Links
FTC says health apps must notify consumers about data breaches — or face fines https://techcrunch.com/2021/09/16/ftc-says-health-apps-must-notify-consumers-if-their-data-is-breached-or-face-fines/ Missouri Governor Vows to Prosecute St. Louis Post-Dispatch for Reporting Security Vulnerability https://krebsonsecurity.com/2021/10/missouri-governor-vows-to-prosecute-st-louis-post-dispatch-for-reporting-security-vulnerability/ Investigation Finds Apple App Tracking Rules May Be Ineffective; IDFA Blocked, but Apps Frequently Access Other Identifiers https://www.cpomagazine.com/data-privacy/investigation-finds-apple-app-tracking-rules-may-be-ineffective-idfa-blocked-but-apps-frequently-access-other-identifiers/ Company That Routes Billions of Text Messages Quietly Says It Was Hacked https://www.vice.com/en/article/z3xpm8/company-that-routes-billions-of-text-messages-quietly-says-it-was-hacked Consolidation of the VPN industry spells trouble for the consumer, https://blog.windscribe.com/consolidation-of-the-vpn-industry-spells-trouble-for-the-consumer-57e638634cf0/Facebook has finally given a reason for the six-hour outage Monday https://www.theverge.com/2021/10/4/22709806/facebook-says-the-six-hour-outage Understanding How Facebook Disappeared from the Internet: https://blog.cloudflare.com/october-2021-facebook-outage/ Facebook bans developer behind Unfollow Everything tool https://www.theverge.com/2021/10/8/22716044/facebook-unfollow-everything-tool-louis-barclay-banned-for-lifeFacebook whistleblower Frances Haugen tells lawmakers that meaningful reform is necessary ‘for our common good’ https://www.washingtonpost.com/technology/2021/10/05/facebook-senate-hearing-frances-haugen/ Windows 11 compatibility: Check if your PC meets Microsoft's requirements https://www.cnet.com/tech/computing/windows-11-compatibility-check-if-your-pc-meets-microsofts-requirements/ Firefox Now Sends Your Address Bar Keystrokes to Mozilla https://www.howtogeek.com/760425/firefox-now-sends-your-address-bar-keystrokes-to-mozilla/ BONUS: Trust, but verify: An in-depth analysis of ExpressVPN's terrible, horrible, no good, very bad week https://www.zdnet.com/article/trust-but-verify-an-in-depth-analysis-of-expressvpns-terrible-horrible-no-good-very-bad-week/
Further Info
National Cybersecurity Awareness Month resources: https://www.cisa.gov/cybersecurity-awareness-month-resources Only two weeks left to snag a challenge coin!! https://firewallsdontstopdragons.com/my-challenge-coins-are-back/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Today I have the great honor and pleasure of speaking with two luminaries in the field of privacy: Michelle Finneran Dennedy and Melanie Ensign. Between them, they have decades of experience managing privacy processes, policies, technology and communications within dozens of big name tech companies. I get their unique perspective on data privacy and the evolution of how these companies approach the problem of collecting and managing your data. Are things getting better or worse? How can companies earn the trust of their customers? Is data the new oil? And is it an asset or a liability? How can we have social media like Facebook and privacy at the same time?
NOTE: I captured WAY more content from these two than I could fit into this one podcast. To get the full interview, become a patron! (And nab yourself a kick-butt challenge coin, too!)
Michelle Dennedy was the first CPO for many global IT infrastructure companies including Oracle, McAfee, Intel & Cisco. Michelle is now a partner at Privatus.online and CEO at a Privacy Engineering startup in stealth mode. She is the co-author of The Privacy Engineer’s Manifesto and The Privacy Engineer’s Companion.
Melanie Ensign is the CEO of Discernible, helping cybersecurity & privacy teams better communicate with business leaders and consumers. She is also part of the DEF CON leadership team.
Further Info
Discernable: https://discernibleinc.com/ Privatus: https://privatus.online/ The Privacy Engineer’s Manifesto: https://www.amazon.com/Privacy-Engineers-Manifesto-Getting-Policy/dp/1430263555 The Rise of Privacy Tech (TROPT): https://www.riseofprivacytech.com/ Privacy is Power (book): https://firewallsdontstopdragons.com/privacy-is-power-review/ The Social Dilemma: https://www.thesocialdilemma.com/ The challenge coin promotion is BACK!! https://firewallsdontstopdragons.com/my-challenge-coins-are-back/Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
I admit it. I'm an Apple fan. Are they perfect? Definitely not. But in most cases, they're actually trying to be good. And at the end of the day, their business model doesn't rely on hoovering up your personal data. Apple just released a big update to its devices, iOS 15, and it's got some really cool security and privacy features. I'll tell you all about them in today's show.
In other news: thousands of Netgear routers can be hacked via a Disney parental control feature even if you didn't ask for it; yet another company is scraping social media and public info to sell it to law enforcement; the NSA and CIA are warning their employees to block ads for cybersecurity reasons; Microsoft has rolled out a "passwordless" login system; EFF is ending support for its wonderful browser plugin HTTPS Everywhere - because HTTPS is now already everywhere; Amazon's new house robot, Astro, is a privacy nightmare (shocker); and this is the first week of National Cybersecurity Awareness Month in the US.
Article Links
National Cybersecurity Awareness Month, Week #1: Own your role in cybersecurity https://staysafeonline.org/wp-content/uploads/2020/04/Own-Your-Role-in-Cybersecurity_-Start-with-the-Basics-.pdf Thousands of Netgear routers can be hacked — here's what to do https://www.tomsguide.com/news/netgear-router-circle-patches Researcher drops three iOS zero-days that Apple refused to fix https://www.bleepingcomputer.com/news/security/researcher-drops-three-ios-zero-days-that-apple-refused-to-fix/ ShadowDragon: Inside the Social Media Surveillance Software That Can Watch Your Every Move https://theintercept.com/2021/09/21/surveillance-social-media-police-microsoft-shadowdragon-kaseware/ The NSA and CIA Use Ad Blockers Because Online Advertising Is So Dangerous https://www.vice.com/en/article/93ypke/the-nsa-and-cia-use-ad-blockers-because-online-advertising-is-so-dangerous You Can Now Sign-in to Your Microsoft Accounts Without a Password https://thehackernews.com/2021/09/you-can-now-sign-in-to-you-microsoft.html HTTPS Is Actually Everywhere https://www.eff.org/deeplinks/2021/09/https-actually-everywhere Amazon Astro is ‘terrible’ and will ‘throw itself down’ stairs, developers reportedly claim https://www.theverge.com/2021/9/28/22699284/amazon-astro-real-world-stairs-fragile-developer-claims-documents-tracking National Cybersecurity Awareness Month https://www.cisa.gov/cybersecurity-awareness-monthApple’s iOS 15 Privacy and Security features: https://firewallsdontstopdragons.com/ios-15-security-privacy-features/
Further Info
The challenge coin promotion is BACK!! https://firewallsdontstopdragons.com/my-challenge-coins-are-back/ Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Apple was set to roll out controversial new on-device scanning technology in iOS 15 last week, but thanks to pushback from groups like the Electronic Frontier Foundation and people like you, Apple has since thought better of it and backed down. It's not clear when or if these "child safety" features will come to iPhones, but in the meantime we can hope that Apple will listen carefully to our concerns before proceeding. Today I'll speak with Jason Kelley from the EFF about Apple's proposed technology, the problem of child sexual abuse material (CSAM), and why Apple's proposed solution was so problematic.
Jason Kelley guides EFF’s social media tactics, develops EFF’s online digital advocacy, and writes about various forms of governmental and private surveillance and tracking.
Further Info
Donate to EFF! https://supporters.eff.org/donate/join-4 EFF's Perspectives event: https://www.eff.org/event/perspectives-encryption-and-child-safety Sign the petition to stop Apple’s poorly-designed child safety features: https://www.eff.org/deeplinks/2021/09/dont-stop-now-join-eff-fight-future-apple-protests-nationwide Fight for the Future’s #noSpyPhone coverage: https://www.fightforthefuture.org/news/2021-09-13-photos-video-protests-hit-apple-stores-across/ Child Rights International Network (CRIN): https://home.crin.org/ Detailed new review of my book: https://parmsam.medium.com/notes-from-reading-firewalls-dont-stop-dragons-f69ae0d4bf0a Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
It's really easy to complain about the sadly insecure state of many of our products and services, but the fact is that doing security right is hard - even when you're trying to get it right. Part of the problem is that there are just so many things to secure, even on a single product or service. Today we're going to discuss several recent security issues with popular products, and why getting it right can be such a daunting task.
In today's show: a universal decryption key for all REvil ransomware victims prior to July 13th is now available; Microsoft patched a nasty security bug in all of its Windows OS versions, but it's still being actively exploited (hint: patch now!); it was recently argued that WhatsApp's end-to-end encryption has a "backdoor", but I'll explain why that's not true; a home security system maker refuses to patch a bug that would allow an attacker to disable your system just by knowing (or guessing) your email address; ProtonMail is forced to alter its "no IP logging" marketing in the face of a recent incident involving a French activist's account; new Mac malware has emerged that uses poisoned search results to trick its victims; and for my tip of the week, I'll tell you about a new fourth credit bureau where you should freeze your credit report.
Article Links
Free REvil ransomware master decrypter released for past victims https://www.bleepingcomputer.com/news/security/free-revil-ransomware-master-decrypter-released-for-past-victims/ Recently reported Microsoft zero-day gaining popularity with attackers, Kaspersky says https://www.msn.com/en-us/news/technology/recently-reported-microsoft-zero-day-gaining-popularity-with-attackers-kaspersky-says/ar-AAOyUvR WhatsApp Fixes Its Biggest Encryption Loophole https://www.wired.com/story/whatsapp-end-to-end-encrypted-backups/ No, Facebook Isn't Reading Your Private WhatsApp Messages. The Problem Is Much Worse https://www.inc.com/jason-aten/no-facebook-isnt-reading-your-private-whatsapp-messages-problem-is-much-worse.html Pwned! The home security system that can be hacked with your email address https://nakedsecurity.sophos.com/2021/09/02/pwned-the-home-security-system-that-can-be-hacked-with-your-email-address/ ProtonMail Amends Its Policy After Giving Up an Activist’s Data https://www.wired.com/story/protonmail-amends-policy-after-giving-up-activists-data/ New Mac malware spreads via search results https://www.tomsguide.com/news/mac-malware-fake-iterm2Tip of the week: https://firewallsdontstopdragons.com/freeze-you-credit-at-innovis-too/
Further Info
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerStay tuned for a new challenge coin promotion! https://firewallsdontstopdragons.com/get-your-official-challenge-coin/ Generate secure passphrases! https://d20key.com/#/
Ever paired your phone to a rental car? Did you erase all the data from the last car you sold or turned in at the end of your lease? Do you know what data you car is sending to the cloud wireless right now? Cars have become a privacy nightmare. Andrea Amico is the founder of a company called Privacy 4 Cars and today he'll help us understand all the data you car is hoovering up - from your phone, your driving habits, your location, and even your facial expressions (no, really). And thankfully, his company also gives you a powerful tool to find and delete the data exhaust you've generated, probably without even realizing it.
Andrea Amico is one of the nation’s leading authorities on vehicle privacy and cybersecurity. He is also the founder of Privacy4Cars, the first and only privacy-tech company focused on identifying the challenges posed by vehicle data.
Further Info
Privacy4Cars: https://privacy4cars.com/Assert Your Data Rights! https://privacy4cars.com/personal-use/assert-your-data-rights/ Twitter: https://twitter.com/privacy4carsFree CCPA Agent: https://freeccpaagent.com/ Auto ISAC: https://automotiveisac.com/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
For many people, privacy is just a vague concept. But it can literally be a matter of life and death. It deserves your attention, your consideration and (crucially) your support. Technology has vastly improved our daily lives, but some of it also threatens to undermine our basic human rights and even our democracy/society. We need to understand the implications of the laws we pass - and the laws we aren't passing. Today, I'll talk about several stories with a common theme: privacy matters.
Of course, I'll also cover several security-related topics this week, as well: I'll tell you how to completely hack someone's Windows PC with a gaming mouse; Microsoft's Azure cloud service left thousands of customers' data completely exposed; new and disturbing details emerge about the role of NSA-pushed backdoors in the massive Juniper breach of 2015; Australia considers making state ID required for social media accounts; Google tries to cut off access to account data that endangers US helpers in Afghanistan; Apple partners with 8 US states to incorporate state IDs into Apple Wallet; Apple has thankfully delayed its rollout of on-device surveillance technology aimed at stemming child porn; the FTC comes down hard on a stalkerware company; and I take a moment to reflect on the 20th anniversary of 9/11. My Tip of the Week explains how to quickly disable biometric unlocking of your smartphone.
Article Links
Not just Razer: SteelSeries mice, keyboards hijack Windows 10 too — what you can do https://www.tomsguide.com/news/steelseries-windows-privilege-escalationMicrosoft Azure cloud vulnerability is the ‘worst you can imagine’ https://www.theverge.com/2021/8/27/22644161/microsoft-azure-database-vulnerabilty-chaosdbJuniper Breach Mystery Starts to Clear With New Details on Hackers and U.S. Role https://finance.yahoo.com/news/juniper-breach-mystery-starts-clear-130016591.html Australia Considers Social Media ID Requirement https://www.infosecurity-magazine.com/news/australia-considers-social-media Google locks Afghan government email accounts as concerns grow over the Taliban tracking down their enemies https://www.businessinsider.com/google-locks-afghan-government-email-accounts-to-block-taliban-report-2021-9Opinion: It’s dangerously stupid to put your state ID in your Apple Wallet https://thenextweb.com/news/dangerously-stupid-state-id-in-your-apple-walletMillions of smartphones, laptops, trucks, planes affected by new Bluetooth flaws — what you need to know https://www.tomsguide.com/news/braktooth-bluetooth-flawsApple cares about privacy, unless you work at Apple https://www.theverge.com/22648265/apple-employee-privacy-icloud-idApple backs down on CSAM features, postpones launch https://appleinsider.com/articles/21/09/03/apple-backs-dowVictory! Federal Trade Commission Bans Stalkerware Company from Conducting Business https://www.eff.org/deeplinks/2021/09/victory-federal-trade-commission-bans-stalkerware-company-conducting-business ‘Panic made us vulnerable’: how 9/11 made the US surveillance state – and the Americans who fought backhttps://www.theguardian.com/world/2021/sep/04/surveillance-state-september-11-panic-made-us-vulnerable
Further Info
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Computers are supposed to be completely predictable. When you tell it to do something, it should do exactly that - over and over again, if necessary - in the same way, with the same result. This is the nature of computer programming. But this predictability can allow computer criminals to interrupt a computer's processing and divert it to do nefarious things. If you know exactly where to poke the system, predicting where and how it does it's processing, you can effectively rewire it to do your bidding. This is the basic attack methodology that lets bad guys insert their malware into our systems. But what if we were able to randomly perturb a computer's processing on a periodic basis, making it effectively unpredictable? This is the essence of a new computer architecture called Morpheus that may one day make all of our computers and computerized devices much, much harder to hack. Today, Todd Austin will explain how this brilliant defense mechanism works and how it was inspired by the human body's immune system.
Todd Austin is a Professor of Electrical Engineering and Computer Science at the University of Michigan in Ann Arbor. His research interests include computer architecture, robust and secure system design, hardware and software verification, and performance analysis tools and techniques. Todd is also co-founder of Agita Labs, a startup developing privacy-enhanced computation technologies that help ease the tension between data discovery and personal privacy.
Further Info
Morpheus article: https://spectrum.ieee.org/morpheus-turns-a-cpu-into-a-rubiks-cube-to-defeat-hackers Morpheus video: https://www.youtube.com/watch?v=v2mLm2QqsVo DARPA SSITH program: https://www.darpa.mil/program/ssith Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
How far would you go to protect your children from sexual predators? How much privacy would you give up to try to prevent the sharing of child pornography? We are now faced squarely with those questions because Apple has just announced some new initiatives that it believes will curb the viewing and sharing of pornographic images. But we need to be extremely careful here. The Four Horsemen of the Infocalypse are pedophiles, terrorists, drug dealers and organized crime. When someone asks you what privacy and civil liberties you would be willing to give up to stop these undeniably bad things, you need to replace their bogeyman with other straw men and make sure your convictions still hold. Technologies that can be used to stop something you hate today can also be used to stop things you don't tomorrow. Today I'll discuss Apple's new "child safety" initiatives and explain why I think they're making the wrong tradeoffs. And also why they are actually not that effective and even potentially harmful to children.
In other news: Both T-Mobile and AT&T appear to have suffered massive data breaches of current and even prospective customers; Microsoft's PrintNightmare continues, despite several attempts to fix the issues; millions of home routers, web cams and baby monitors are vulnerable to a new attacks; Facebook is trying to help Afgans hide their friends lists in the face of Taliban reprisals; your IoT devices are horrible with random numbers, and that's a huge security risk; a secret terrorist watch list with almost 2 million people has leaked; and the OAuth web app authentication system is ripe for hacking, potentially putting several of your accounts at risk.
Article Links
Blocking the Exploitation of PrintNightmare https://securityboulevard.com/2021/08/blocking-the-exploitation-of-printnightmare/Disabling your Print Spooler (see “Workarounds”): https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527Millions of home Wi-Fi routers under attack by botnet malware https://www.tomsguide.com/news/arcadyan-router-malwareSEE ALSO: Router Security: https://routersecurity.org/ T-Mobile Data Breach: 100 Million Customer Data Records Compromised Including Social Security, Driver’s License & Unique Device Numbers https://www.cpomagazine.com/cyber-security/t-mobile-data-breach-100-million-customer-data-records-compromised-including-social-security-drivers-license-unique-device-numbers/Hacker Selling Private Data Allegedly from 70 Million AT&T Customers https://restoreprivacy.com/att-data-breach-70-million-customers/ Millions of Web Camera and Baby Monitor Feeds Are Exposed https://www.wired.com/story/kalay-iot-bug-video-feeds/ Secret terrorist watchlist with 2 million records exposed online https://www.bleepingcomputer.com/news/security/secret-terrorist-watchlist-with-2-million-records-exposed-online/ To protect users, Facebook says it’s hiding friends lists on accounts in Afghanistan https://www.nytimes.com/2021/08/20/world/asia/afghanistan-facebook.html Web apps have become so complex that they're unsafe to use, researchers say https://www.tomsguide.com/news/unsafe-web-apps-oauth DEFCON “You’re doing IoT RNG” paper: https://labs.bishopfox.com/tech-blog/youre-doing-iot-rng Apple’s New ‘Child Safety’ Initiatives, and the Slippery Slope https://daringfireball.net/2021/08/apple_child_safety_initiatives_slippery_slopeWe built a system like Apple’s to flag child sexual abuse material — and concluded the tech was dangerous https://www.washingtonpost.com/opinions/2021/08/19/apple-csam-abuse-encryption-security-privacy-dangerous/Open letter to Apple from 90+ world orgs https://cdt.org/insights/international-coalition-calls-on-apple-to-abandon-plan-to-build-surveillance-capabilities-into-iphones-ipads-and-other-products/ Tell Apple not to scan our phones: https://act.eff.org/action/tell-apple-don-t-scan-our-phones
Further Info
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to ...
Are hackers born or are they made? What is the essence of a true hacker? Today I explore these topics and more with the founder of both DEFCON and Black Hat, Jeff Moss - also known as The Dark Tangent. I also ask Jeff why we seem to suck at cybersecurity, what his top tips are for staying safe online, when DEFCON evolved to be bigger than its founder, how DEFCON has managed to stay focused on its attendees all these years, and how he plans to find a worthy successor to run the DEFCON conference when he inevitably steps aside.
Further Info
DEFCON documentary: https://www.youtube.com/watch?v=3ctQOmjQyYg Privacy is Power, book by Carissa Véliz : https://www.amazon.com/Privacy-Power-Should-Take-Control/dp/1612199151 My review of Privacy is Power: https://firewallsdontstopdragons.com/privacy-is-power-review/ The Value of Privacy, by Bruce Schneier: https://www.schneier.com/blog/archives/2006/05/the_value_of_pr.html TED Talk on Privacy by Glenn Greenwald: https://www.ted.com/talks/glenn_greenwald_why_privacy_matters Hackers, book by Steven Levy: https://www.amazon.com/Hackers-Computer-Revolution-Steven-Levy/dp/1449388396 Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
What is a hacker, exactly? What does it mean to hack something? With all the ransomware attacks and election meddling in the headlines, it's easy to paint all hackers with a broad brush as malicious, self-serving computer criminals. And to be clear, many computer criminals are definitely hackers (some aren't). But the real definition of hacker, the original notion of hacking itself, is something quite different. Nowhere is this more evident than at DEFCON, one of the world's largest hacking conferences. I've been wanting to go to DEFCON for many years, but finally made my pilgrimage to Las Vegas this year for DEFCON 29. My goal was to document first hand, not just the conference, but the culture and the hackers themselves. Because unlike most trade conferences, DEFCON is really about the attendees and the betterment of their craft. Today's show is a non-technical exploration of what it means to be a hacker and why you might aspire to be one yourself.
Further Info
DEFCON documentary: https://www.youtube.com/watch?v=3ctQOmjQyYg DEFCON 29: https://defcon.org/html/defcon-29/dc-29-index.html DEFCON 29 media: https://media.defcon.org/DEF%20CON%2029/ Making the DEF CON 29 Badge: https://www.youtube.com/watch?v=H3kdq40PY3s Soundtrack https://media.defcon.org/DEF%20CON%2029/DEF%20CON%2029%20music/ Preparing for Hacker Summer Camp: https://theplaceboeffects.wordpress.com/2019/07/13/preparing-for-hacker-summer-camp/ Hack-A-Day badge article: https://hackaday.com/2021/08/05/hands-on-def-con-29-badge-embraces-the-new-normal/ DC Tin Foil Hat: @DC_Tin_Foil_Hat (Twitter)Hackerboxes.com: https://hackerboxes.com/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Generate secure passphrases! https://d20key.com/#/Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Every time you load a web page, your personal data is being shared with thousands of companies. The ad spaces on the page are being auctioned off to the highest bidder in fractions of a second. The Irish Council for Civil Liberties calls this the biggest data breach in histor, and is suing the ad tech companies on your behalf to stop this needlessly invasive and dangerous practice. My guest Johnny Ryan will explain how this real-time bidding process works and has insider documentation on the types of extremely personal data that's being shared in order to target those ads to you.
Dr Johnny Ryan is a Senior Fellow at the Irish Council for Civil Liberties, and a Senior Fellow at the Open Markets Institute. He is focused on surveillance, data rights, competition/anti-trust, and privacy. He is former Chief Policy & Industry Relations Officer at Brave, the private web browser. Dr Ryan led Brave’s campaign for GDPR enforcement, and liaised with government and industry colleagues globally. Previously, Dr. Ryan worked in adtech, media, and policy. His previous roles included Chief Innovation Officer of The Irish Times and Senior Researcher at the Institute of International & European Affairs (IIEA).
Further Info:
Irish Council for Civil Liberties lawsuit: https://www.iccl.ie/rtb-june-2021/ Johnny Ryan: https://www.iccl.ie/staff/dr-johnny-ryan/ IAB Audience Taxonomy: https://www.iab.com/guidelines/audience-taxonomy/IAB Content Taxonomy: https://www.iab.com/guidelines/content-taxonomy/ OpenRTB 3.0 spec: https://github.com/InteractiveAdvertisingBureau/openrtb Browser plugin: https://chrome.google.com/webstore/detail/bidfilter-header-bidding/addamgcbhieigmdmmaooppajdocgggckFTC’s data broker report from 2014: Data Brokers: A Call for Transparency and AccountabilityBecome a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Your phone number is arguably as strong a personal identifier as your social security number, passport number or email address. These are things we almost never change any more - meaning that it's an identifier for life. Our cell phones contain a ton of personal information, including our locations (not just now, but over time). Today I'll help you understand why it's so important to protect your cell phone number and digital contact lists.
In other news: you need to update everything again... Apple, Microsoft, Google, Adobe; REvil ransomware gang has disappeared completely from the dark web - and possibly not coincidentally, Kaseya has obtained a universal decryption key for all of it's customers (REvil victims); the Pegasus Project appears to have unveiled serious abuses of the NSO Group's spyware; Venmo finally gets rid of the public transaction list; the FBI is using cell site simulators to track cars; and it turns out that it's easy and highly profitable to re-associate people with supposedly anonymous data sets.
Article Links
Apple fixes bug that breaks iPhone WiFi when joining rogue hotspots https://www.bleepingcomputer.com/news/security/apple-fixes-bug-that-breaks-iphone-wifi-when-joining-rogue-hotspots/ Revil Ransomware Group Missing From Dark Web; Temporary Vacation, or Permanently Out of Business? https://www.cpomagazine.com/cyber-security/revil-ransomware-group-missing-from-dark-web-temporary-vacation-or-permanently-out-of-business/ The Kaseya Ransomware Nightmare Is Almost Over https://www.wired.com/story/kaseya-ransomware-nightmare-is-almost-over/ Takeaways from the Pegasus Project https://www.washingtonpost.com/investigations/2021/07/18/takeaways-nso-pegasus-project/ How to Protect Yourself From the New Windows 10 and 11 Security Bug https://lifehacker.com/how-to-protect-yourself-from-the-new-windows-10-and-11-1847338342 Venmo removes its global, public feed as part of a major redesign https://techcrunch.com/2021/07/20/venmo-removes-its-global-public-feed-in-a-significant-app-redesign/ The FBI Is Locating Cars By Spying On Their WiFi https://www.forbes.com/sites/thomasbrewster/2021/07/22/the-fbi-is-using-stingray-smartphone-surveillance-to-locate-cars-and-spy-on-their-wifi/?sh=113ea16335c8 Inside the Industry That Unmasks People at Scale https://www.vice.com/en/article/epnmvz/industry-unmasks-at-scale-maid-to-pii A priest’s phone location data outed his private life. It could happen to anyone. https://www.washingtonpost.com/technology/2021/07/22/data-phones-leaks-church/ Connected cars: What happens to your data after you leave your rental car behind? https://www.zdnet.com/article/connected-cars-what-happens-to-your-data-after-you-leave-your-rental-car/ Privacy International 2017 study: http://privacyinternational.org/sites/default/files/2017-12/cars_briefing.pdf
Further Info
Who’s making money on ransomware? https://ransomwhe.re/ No More Ransom: https://www.nomoreransom.org/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
The first step to solving any problem is gathering as much information as you can. Unfortunately, today we're basically flying blind when it comes to identifying and resolving latent software bugs in our systems. Software today is made up of dozens if not hundreds of distinct components. Like automobiles, these piece parts can come from many different vendors. And even the parts from those vendors are likely themselves made up of many sub-components from yet other vendors. But you can bet that Ford and Toyota have a complete and accurate list of each and every one of the components in their vehicles - knowing who made them, which lot or batch they were from, which revision of the part they have, and so on. Because at the end of the day, the auto maker is responsible for knowing this in case there's a safety issue. This is not true for software makers... yet. Allan Friedman and his team at the National Telecommunications and Information Administration (NTIA, a part of the Dept. of Commerce) are trying to change that.
Allan Friedman is the Director of Cybersecurity Initiatives at the National Telecommunications and Information Administration, which is part of the US department of Commerce,. There he coordinates cross-sector efforts to address key challenges in the cybersecurity ecosystem.
Further Info
NTIA’s SBOM website: https://www.ntia.gov/sbom Twitter #SBOM: https://twitter.com/search?q=%23SBOM Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/or privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Just when you thought it couldn't get worse, the bad guys say "hold my beer". The REvil gang has managed to pull off what appears to be the biggest ransomware infection ever through a clever supply chain attack on a company you've never heard of called Kaseya. Kaseya is what we call a Managed Service Provider, or MSP. They manage software and IT functions for lots of small-to-medium sized businesses, so that those companies don't have to. But this also gives MSP's a very privileged security position, making it a prime target for bad guys wanting to infect a lot of companies with a single hack. Today I'll catch you up on this ongoing horror show and give you some tips on how to avoid becoming a ransomware victim yourself.
In other news: Kaspersky Password Manager (KPM) was found to have a bad bug making its generated passwords a lot easier to crack; I'll tell you about how some Brazilian iPhone thieves came up with a clever way to hack your accounts; Google has delayed FLoC and blocking of third-party cookies for at least two years; a Microsoft exec tells the US Congress about how law enforcement and intelligence agencies make thousands of gag-order-restricted demands for data every year; a research group discovers that an old cell phone encryption standard was intentionally weakened to allow easier cracking; Microsoft's PrintNightmare bug is still not fully patched and the back story is a comedy of errors; and with hurricane season upon us, I'll point you to some great tips on preparing for power outages.
Article Links
A popular password manager screwed up, but there's an easy fix https://mashable.com/article/kaspersky-password-manager-security-bug Brazilian iPhone thieves demonstrate importance of responsible password practices https://appleinsider.com/articles/21/07/07/brazilian-iphone-thieves-demonstrate-importance-of-responsible-password-practices Why Google Can't Bring Itself to Make the Internet Respect Your Privacy https://www.inc.com/jason-aten/why-google-cant-bring-itself-to-make-internet-respect-your-privacy.html Microsoft exec: Targeting of Americans’ records ‘routine’ https://apnews.com/article/government-and-politics-technology-business-ed50baf4ffb09ca50cda9b8a262c54ad Bombshell Report Finds Phone Network Encryption Was Deliberately Weakened https://www.vice.com/en/article/4avnan/bombshell-report-finds-phone-network-encryption-was-deliberately-weakened PrintNightmare official patch is out – update now? https://nakedsecurity.sophos.com/2021/07/07/printnightmare-official-patch-is-out-update-now/ Up to 1,500 businesses infected in one of the worst ransomware attacks ever https://arstechnica.com/gadgets/2021/07/up-to-1500-businesses-infected-in-one-of-the-worst-ransomware-attacks-ever/
Further Info
Microsoft PrintNightmare patch: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527 CISA, FBI share guidance for victims of Kaseya ransomware attack https://www.bleepingcomputer.com/news/security/cisa-fbi-share-guidance-for-victims-of-kaseya-ransomware-attack/ Ransomware Defense: Top 5 Things to Do Right Now https://threatpost.com/ransomware-defense-top-5-tips/167536/ How to prepare for a power outage: https://firewallsdontstopdragons.com/how-to-prepare-for-power-outage/ How to safely download software: https://firewallsdontstopdragons.com/how-to-safely-download-software/ Sign up for the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Robocalls are the bane of my existence. I get so many spam calls that I've just stopped answering my home phone altogether. I've given out my cell number to fewer people, so thankfully I get fewer junk calls there. But I still won't answer any calls unless I recognize the number. Why is it so easy to spoof caller ID? Well, starting July 1st in the US, mobile carriers are now required to implement a new(ish) set of technologies to make that more difficult: "Stir" ("secure telephone identity revisited") and "Shaken" ("signature-based handling of asserted information using tokens"). While not perfect, they should at least help identify shady callers. In today's Tip of the Week, I'll give you some other options for blocking spam calls, as well.
Lots of other (mostly bad) cybersecurity news to cover today: Someone scraped a ton of LinkedIn data from over 700M LinkedIn subscribers (about 92% of total users) and posted it for $5000; a very odd and specific WiFi SSID could break your iPhone; 30M Dell computers are vulnerable to a nasty BIOS attack; many users of the old WD My Book Live storage drives have had all their data erased; the REvil ransomware gang has attacked at least 200 companies with a new supply chain hack; Microsoft tries and fails miserably to fix a bad printer server bug ("PrintNightmare"), Russian hackers are constantly trying to brute force your bad passwords; and finally, the USA's CISA is warning manufacturers of ThroughTek devices about an exploitable vulnerability in several webcams and IoT devices.
Article Links
Data Scraping Yields 700 Million LinkedIn Profiles for Sale on Dark Web; About 92% Of Platform Users, but Mostly Public Information https://www.cpomagazine.com/cyber-security/data-scraping-yields-700-million-linkedinBeware! Connecting to This Wireless Network Can Break Your iPhone's Wi-Fi Feature https://thehackernews.com/2021/06/beware-connecting-to-this-wireless.html 30M Dell Devices at Risk for Remote BIOS Attacks, RCE https://threatpost.com/dell-bios-attacks-rce/167195/ Western Digital My Book Live devices being remotely wiped by attackers https://appleinsider.com/articles/21/06/25/western-digital-my-book-live-devices-being-remotely-wiped-by-attackers REvil ransomware hits 200 companies in MSP supply-chain attack https://www.bleepingcomputer.com/news/security/revil-ransomware-hits-200-companies-in-msp-supply-chain-attack/ How to Avoid Windows' 'PrintNightmare' Security Threat https://lifehacker.com/how-to-avoid-windows-printnightmare-security-threat-1847221653 Russian Hackers Are Trying to Brute-Force Hundreds of Networks https://www.wired.com/story/fancy-bear-russia-brute-force-hacking/ CISA warns manufacturers of ThroughTek vulnerability (webcams) https://www.zdnet.com/article/cisa-warns-manufacturers-of-throughtek-vulnerability/ Robocalls are out of control. But that could all change today https://www.cnet.com/news/robocalls-are-out-of-control-but-that-could-all-change-today/
Further Info
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Today's news headlines are littered with stories on massive cybersecurity failures: SolarWinds, Microsoft Exchange, Colonial Pipeline, data breaches, ransomware... Are the bad guys ramping up their game? Or are we just really bad at cybersecurity? (Or both?) How do we fix this? Who can lead the charge to improve our cyber defenses and fend off these attacks? Where do we learn best practices? Can new tools like Artificial Intelligence (AI) help us be more secure - or will these tools benefit the bad guys more? In today's show, I discuss the current sorry state of cybersecurity and it's foggy future with Josh Jackson from 6clicks!
Josh Jackson is an avid student of law, policy, and regulations. He is a speaker on Artificial Intelligence and Automation and a teacher on the Legal and Regulatory Environment of Business. He is passionate about ethics and agency law, and corporate and regulatory risk.
Further Info:
6clicks: https://www.6clicks.io/ Cybersecurity Maturity Model: https://www.acq.osd.mil/cmmc/draft.html Internet of Things Cybersecurity Improvement Act of 2020: https://www.congress.gov/bill/116th-congress/house-bill/1668/text Only three days to get your challenge coin!! https://firewallsdontstopdragons.com/get-your-official-challenge-coin/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Are satellites really just IoT devices in space? They're small computers and connected to the internet, not unlike Nest thermostats, baby video monitors, and smart toasters. You'd think that they'd be a lot more complex and secure... but are they really? My two guests today are running a program to test that very question, and in the process, try to make our military and commercial satellites more secure. We don't think about it, but satellites play a crucial role in our daily lives. GPS satellites are used by airplanes, ships and even agricultural machinery. Weather satellites allow us to predict the path of severe storms and save countless lives. We take them for granted, but these orbiting computers are critical in our modern lives. The Hack-A-Sat contest was created to help ensure the security of these systems. Anyone can enter - and time to register for this year's tournament is running out!
Carl Rodio Jr. is Principal Cyber Security Engineer for The MITRE Corporation, supporting the US Space Force Defensive Cyber Operations for Space Systems (DCO-S) program. MITRE operates Federally Funded Research and Development Centers (FFRDC's), which support the US government in a variety of capacities.
Jason Williams is a Security Researcher, Engineer, and CEO of Cromulence LLC and member of Legitimate Business Syndicate (organizers of DEF CON CTF 2012-2017). 15+ years experience in cybersecurity and vulnerability research.
Further Info
Hack-A-Sat 2: https://www.hackasat.com/ US Digital Service: https://www.usds.gov/Cromulence LLC: https://cromulence.com/MITRE Corp: https://www.mitre.org/HUGE sale on my book right now! Use code SUMMER2021: https://www.apress.com/us/book/9781484261880 Get your custom d20 challenge coin! https://firewallsdontstopdragons.com/get-your-official-challenge-coin/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGenerate secure passphrases! https://d20key.com/#/
Payment apps are fairly secure & very convenient, but NOT private. And Venmo is the worst. Venmo is the only payment app that is primarily a "social" app. That's shorthand for "share as much info as possible, with as many people as possible". If you weren't already aware, all Venmo transactions are public by default. (That might come as an unwelcome surprise to the third of millennials who have used Venmo to pay for drugs.) Your Venmo friends list is also public by default, as Joe Biden recently discovered. But perhaps due to that event, Venmo at least now gives you a way to make it private. I'll tell you how to change this and other Venmo privacy settings - and also which apps are better at privacy.
Lots of other news to cover today: Amazon Sidewalk has been activated for all new Echo and Ring devices (like it or not), but you can turn it off; Amazon Ring is offering more transparency on requests for video footage by law enforcement; Apple addresses some of the "stalker" privacy concerns with AirTags; apps are sidestepping Apple's new App Tracking Transparency (shocker); TikTok just changed its privacy policy to mention the collection of your biometric info, including "faceprints" and "voiceprints"; we found out how the hackers got into the Colonial Pipeline computers and (maybe) how the FBI managed to get back some of the ransom money; the FBI secretly ran an encrypted communication platform marketed to criminals called Anom; and a new facial recognition service allows you (or come creeper) to search the web for anyone's face for free.
Article Links
Amazon is about to share your Internet connection with neighbors. Here’s how to turn it off. https://www.washingtonpost.com/technology/2021/06/07/amazon-sidewalk-network/ Ring will require police & fire departments to make public requests for video footage https://appleinsider.com/articles/21/06/03/ring-will-require-police-fire-departments-to-make-public-requests-for-video-footage Apple announces AirTag privacy improvements, Android app coming this year https://9to5mac.com/2021/06/03/airtag-privacy-improvements-sound-android-app/ How to Check Your AirTags Firmware Version https://www.macrumors.com/how-to/check-airtags-firmware-version/ Apps Continuing to Track Users Despite Apple's Privacy Prompt https://www.macrumors.com/2021/06/07/apps-continuing-to-track-users/ WhatsApp is getting a crafty new way to verify your identity https://www.techradar.com/news/whatsapp-is-getting-a-crafty-new-way-to-verify-your-identity TikTok just gave itself permission to collect biometric data on U.S. users, including ‘faceprints and voiceprints’ https://techcrunch.com/2021/06/03/tiktok-just-gave-itself-permission-to-collect-biometric-data-on-u-s-users-including-faceprints-and-voiceprints/ Ransomware attackers used compromised password to access Colonial Pipeline network https://www.cnn.com/2021/06/04/politics/colonial-pipeline-ransomware-attack-password/index.html How could the FBI recover BTC from Colonial’s ransomware payment? https://nakedsecurity.sophos.com/2021/06/09/how-could-the-fbi-recover-btc-from-colonials-ransomware-payment/ The FBI's Anom Stunt Rattles the Encryption Debate https://www.wired.com/story/fbi-anom-phone-network-encryption-debate/ This facial recognition website can turn anyone into a cop - or a stalker https://news.yahoo.com/facial-recognition-website-turn-anyone-113646451.html VICTORY: You Can Now Make Your Venmo Friends List Private. Here’s How. https://www.eff.org/deeplinks/2021/06/victory-you-can-now-make-your-venmo-friends-list-private-heres-how
Further Info
HUGE sale on my book right now (55% off)! Use code SUMMER2021: https://www.apress.com/us/book/9781484261880 Get your custom d20 challenge coin! https://firewallsdontstopdragons.com/get-your-official-challenge-coin/ Become a Patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to speak to your group about security and/or privacy? http://bit.
Is it possible for you to view your FLoC ID right now? And if so, can you decode this ID to understand what Google is learning about you from it? Does FLoC require your consent or cooperation from the sites you're visiting? Are there tools to block this and, if so, how effective are they? In part 2 of my discussion with EFF's Bennett Cyphers, we'll answer these questions and many more.
Google's FLoC proposal depends on Google being a "benevolent and omniscient overseer", which is a bad bet. Even if Google manages to get the technology right and carefully avoids tracking "sensitive" info, there's nothing saying it won't change this later - on purpose or by accident or both. And given the rabid desire by data mining companies to monetize your information, FLoC may enable new forms of tracking and fingerprinting.
Bennett Cyphers is a staff technologist on the Tech Projects team. He works with a variety of teams across EFF, focusing on consumer privacy, competition, and state legislation. He also assists with development on Privacy Badger. Outside of work he has hobbies and likes fun.
Further Info:
Ditch Chrome, switch to Firefox: https://firewallsdontstopdragons.com/its-time-switch-to-firefox/ Donate to Mozilla (Firefox): https://donate.mozilla.org/en-US/Am I FLoC’d? https://amifloced.org/ Disable Amazon’s Sidewalk: https://www.amazon.com/gp/help/customer/display.html?nodeId=GZ4VSNFMBDHLRJUK HUGE sale on my book right now! Use code SUMMER2021: https://www.apress.com/us/book/9781484261880Would you like me to speak to your group about security and/or privacy? http://bit.ly/Firewalls-SpeakerGet your custom d20 challenge coin! https://firewallsdontstopdragons.com/get-your-official-challenge-coin/ Generate secure passphrases! https://d20key.com/#/Become a Patron! https://www.patreon.com/FirewallsDontStopDragons
The public has voted and the results are in: people do not want to be tracked. In response, like pop-up ads before them, third party cookies are now being blocked by default by just about every browser - except Chrome. Google (who owns Chrome) is an ad company who relies on web tracking to make 90% of their revenue. With the writing on the wall, they and other ad tech companies are scrambling to find other ways to track people. Google has proposed a new system they call Federated Learning of Cohorts, or FLoC, which they claim can replace most of the tracking capability of third party cookies while somehow managing to preserve users' privacy. Today, I will discuss this new proposal with Bennett Cyphers of the Electronic Frontier Foundation: how it works, how they are rolling it out, and why EFF believes that FLoC is not the way to go.
Bennett Cyphers is a staff technologist on the Tech Projects team. He works with a variety of teams across EFF, focusing on consumer privacy, competition, and state legislation. He also assists with development on Privacy Badger. Outside of work he has hobbies and likes fun.
Further Info:
Get your custom d20 challenge coin! https://firewallsdontstopdragons.com/get-your-official-challenge-coin/ Become a patron! https://www.patreon.com/FirewallsDontStopDragons Would you like me to come speak to your group about security and/privacy? http://bit.ly/Firewalls-SpeakerGoogle’s “Sensitivity of Cohorts” paper: https://docs.google.com/a/google.com/viewer?a=v&pid=sites&srcid=Y2hyb21pdW0ub3JnfGRldnxneDo1Mzg4MjYzOWI2MzU2NDgw Google’s FLoC API spec: https://github.com/WICG/floc Am I FLoC’d? https://amifloced.org/ Opt out of NHS data sharing: https://www.ft.com/content/9fee812f-6975-49ce-915c-aeb25d3dd748
Today is the day we've all been waiting for! The super-secret, highly-collectible, security-enhancing device is finally HERE!! For a short period of time, I will be offering a very limited edition challenge coins to my patrons. Not only is the coin itself amazingly cool, it can also help you generate secure passphrases using my brand new website d20key.com! Listen in today for all the details, as well as my tip of the week for how and when to use passphrases (instead of passwords)!
In other news: The Colonial Pipeline is open again after a nasty ransomware attack by the DarkSide group; President Biden signs a landmark executive order to strength cybersecurity for the US government and anyone who sells to them; the HSE in Ireland is hit with a ransomware attack, too; Microsoft warns of a fake ransomware infection that just steals data; apparently when give a real, clear choice, almost no one wants apps to track them (Apple's App Tracking Transparency update); Veritone launches a creepy new deep-fake voice service for celebrities; Eufy camera bug crosses wires and shows people the wrong camera feeds (as in, from cameras they don't own); and Amazon is enabling its Sidewalk mesh network by default - and I'll tell you how to disable it.
Further Info
Get your own Firewalls Don’t Stop Dragons Challenge Coin! https://www.patreon.com/FirewallsDontStopDragons How and When to Use a Passphrase: https://firewallsdontstopdragons.com/how-when-to-use-a-passphrase/ Generate a secure passphrase! https://d20key.com/ Check out my Malwarebytes interview! https://blog.malwarebytes.com/category/podcast/ Threat Technology’s list of 20 Best Security Podcasts: https://threat.technology/20-best-computer-security-podcasts-of-2021/ FAQ: DarkSide Ransomware Group and Colonial Pipeline https://www.eff.org/deeplinks/2021/05/faq-darkside-ransomware-group-and-colonial-pipeline DarkSide group that attacked Colonial Pipeline drops from sight online https://www.washingtonpost.com/technology/2021/05/14/darkside-ransomware-shutting-down/ Biden signs executive order to strengthen US cybersecurity https://arstechnica.com/information-technology/2021/05/biden-signs-executive-order-to-strengthen-us-cybersecurity/ Irish cyber-attack: Hackers bail out Irish health service for free https://www.bbc.com/news/world-europe-57197688 Microsoft Warns of Data Stealing Malware That Pretends to Be Ransomware https://thehackernews.com/2021/05/microsoft-warns-of-data-stealing.html Americans Actually Want Privacy. Shocking. https://www.nytimes.com/2021/05/20/opinion/apple-facebook-ios-privacy.html Coalition Launches ‘Dark Patterns’ Tip Line to Expose Deceptive Technology Design https://www.eff.org/press/releases/coalition-launches-dark-patterns-tip-line-expose-deceptive-technology-design Veritone launches new platform to let celebrities and influencers clone their voice with AI https://www.theverge.com/2021/5/14/22432180/voice-clone-deepfake-celebrities-influencers-veritone-ai-platform Eufy camera owners report video mixups https://nakedsecurity.sophos.com/2021/05/17/those-arent-my-kids-eufy-camera-owners-report-video-mixups/ Here’s Anker’s apology after 712 Eufy customers had camera feeds exposed to strangers https://www.theverge.com/2021/5/19/22444164/eufy-security-camera-glitch-privacy-feed-exposed-statement-detailsAmazon's Sidewalk Network Is Turned On by Default. Here's How to Turn It Off https://www.inc.com/jason-aten/amazons-sidewalk-network-is-turned-on-by-default-heres-how-to-turn-it-off.html
What is Tor, exactly? How and why would I use it? And what the heck is a Tor node? In part 2 of my talk with Alison from the Library Freedom Project, we'll discuss why libraries are so important in the fight for privacy and how they're using technologies like Tor to keep its patron's (and even other's) web browsing anonymous. We'll talk about why it's important to do a self-assessment of your particular "threat model" and Alison will provide some time-tested tips for improving your security and privacy. Oh, and we'll talk about what all of this has to do with the so-called Streisand Effect!
Alison Macrina is a librarian, internet activist, and founder and director of Library Freedom project. Alison is passionate about fighting surveillance and connecting privacy issues to other struggles for justice and an analysis of power.
Further Info
BECOME A PATRON! https://www.patreon.com/FirewallsDontStopDragonsLibrary Freedom project: https://libraryfreedom.org/ Library Freedom wiki: https://libraryfreedom.wiki/ Library Freedom Institute GitHub page: https://github.com/alisonLFP/libraryfreedominstitute Library Freedom Institute on Vimeo: https://vimeo.com/libraryfreedominstitute Discover your threat model: https://ssd.eff.org/en/module/your-security-plan Download Tor Browser: https://www.torproject.org/download/
Want to read a book without your reading history being tracked? Do you need to surf the web with complete anonymity? If so, then look no further than your local public library. You have the right to research and collaborate on politically or socially sensitive topics without fearing your government or even your local community - and your local public libraries are there to help. Today I'll discuss the topics of intellectual freedom, access to information, and the right to privacy with the founder of the Library Freedom Project. We'll discuss book banning, media consolidation, mass surveillance, access to your library records by law enforcement, and even the lethal dangers of furniture!
Alison Macrina is a librarian, internet activist, and founder and director of Library Freedom project. Alison is passionate about fighting surveillance and connecting privacy issues to other struggles for justice and an analysis of power.
Further Info
BECOME A PATRON! https://www.patreon.com/FirewallsDontStopDragonsLibrary Freedom project: https://libraryfreedom.org/ Library Freedom wiki: https://libraryfreedom.wiki/ Library Freedom Institute GitHub page: https://github.com/alisonLFP/libraryfreedominstitute Library Freedom Institute on Vimeo: https://vimeo.com/libraryfreedominstitute Noam Chomsky propaganda model: https://en.wikipedia.org/wiki/Propaganda_model Terrorism vs furniture-related deaths: https://www.washingtonpost.com/news/monkey-cage/wp/2015/11/23/youre-more-likely-to-be-fatally-crushed-by-furniture-than-killed-by-a-terrorist/
After what seemed like forever, Apple has finally released its App Tracking Transparency (ATT) feature which requires apps to get your permission to track you across other apps and websites. This was announced last year and delayed by several months to allow app makers to come into compliance (particularly Facebook). Today I'll tell you what this feature does and doesn't do, and of course, how to enable it.
Tons of other security and privacy news to cover today, as well: A nasty bug was just fixed in macOS (update now!!); Firefox fixes a bug that could allow fake HTTPS lock icons and therefore compromise security; Facebook Messenger users have been targeted with a major scam; Codecov hack is just the latest in software supply chain attacks that threaten hundreds of companies and their customers; bad guys hacked ad servers to serve up malware; the US Postal Service is running a 'covert operations program' that monitors social media accounts; more US federal agencies are turning to private companies to buy data on people and bypass the 4th Amendment; Emotet malware has been taken down; the FBI has been hacking company servers without their consent (but with a warrant) to try to fix Exchange server hacks; some promising new AI regulations have cropped up in Europe and the US; Signal expertly trolls and hamstrings Cellebrite; and finally, Apple's long-awaited AirTags have finally been released, but the anti-stalker protections seem to fall short, particularly for Android owners.
Further Info:
A macOS major security bug has just been fixed - UPDATE NOW! https://www.forbes.com/sites/thomasbrewster/2021/04/26/update-your-mac-now-the-worst-hack-in-years-hits-apple-computers/Mozilla Fixes Firefox Flaw That Allowed Spoofing of HTTPS Browser Padlock https://threatpost.com/mozilla-fixes-firefox-flaw/165501/Facebook Messenger users targeted by a large-scale scam https://www.helpnetsecurity.com/2021/04/20/facebook-messenger-scam/Codecov hackers breached hundreds of restricted customer sites https://www.reuters.com/technology/codecov-hackers-breached-hundreds-restricted-customer-sites-sources-2021-04-19/120 Compromised Ad Servers Target Millions of Internet Users https://thehackernews.com/2021/04/120-compromised-ad-servers-target.htmlThe Postal Service is running a 'covert operations program' that monitors Americans' social media posts https://news.yahoo.com/the-postal-service-is-running-a-running-a-covert-operations-program-that-monitors-americans-social-media-posts-160022919.htmlFederal Agencies Are Secretly Buying Consumer Data https://www.brennancenter.org/our-work/analysis-opinion/federal-agencies-are-secretly-buying-consumer-dataEmotet Malware Taken Down By Global Law Enforcement Effort https://www.cpomagazine.com/cyber-security/emotet-malware-taken-down-by-global-law-enforcement-effort-cleanup-patch-pushed-to-1-6-million-infected-devices/Are we safer with the FBI accessing our computers without consent? https://thenextweb.com/news/are-we-safer-with-the-fbi-accessing-our-computers-without-consent-syndicationThe sun is setting on A.I.’s Wild West https://fortune.com/2021/04/27/the-sun-is-setting-on-a-i-s-wild-west/Signal professionally trolls and screws Cellebrite: https://signal.org/blog/cellebrite-vulnerabilities/ AirTags are scarily good at tracking items and ... people. I know because I tried. https://mashable.com/review/apple-airtags-review/ Apple reveals more about AirTag stalking protections as domestic abuse concerns expressed https://9to5mac.com/2021/04/30/airtag-stalking-protections/
While law enforcement touts the benefits of cell site simulators, today we will talk about the negative impacts, as well. While the actual impacts are not documented due to secrecy, we have to wonder whether Stingrays could interfere with critical communications like 911 calls, for example. We also must understand that any tool can be used for good and for evil, by the "good guys" as well as the "bad guys". In an effort to bring more transparency, Cooper created Crocodile Hunter (a reference to Steve Irwin, who was tragically killed by a real-life stingray). Cooper explains how it works and how anyone can make one. And finally we'll talk about why it's so important to get out there and fight for more transparency. Cooper shows us what a difference this can make in your community with two very different situations in two US cities.
Cooper Quintin is a security researcher and Senior Staff Technologist with the EFF Threat Lab. He has worked on projects such as Privacy Badger, Canary Watch, and analysis of state sponsored malware campaigns such as Dark Caracal. He has also performed security trainings for activists, non profit workers and ordinary folks, and given talks about security research at security conferences around the world. He previously worked building websites for non-profits, such as Greenpeace, Adbusters, and the Chelsea Manning Support Network. Cooper was also an editor and contributor to the hacktivist journal, “Hack this Zine.” He has spoken at multiple black hat conferences about security issues ranging from IMSI Catchers to Malware attacks against journalists.
Further Info
BECOME A PATRON! https://www.patreon.com/FirewallsDontStopDragonsElectronic Frontier Foundation (EFF): https://www.eff.org/ EFF’s Electronic Frontier Alliance: https://www.eff.org/electronic-frontier-alliance Crocodile Hunter project: https://github.com/EFForg/crocodilehunterHow IMSI catchers work: https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networksEFF page on IMSI catchers: https://www.eff.org/pages/cell-site-simulatorsimsi-catchersWhy 5g won’t help: https://www.eff.org/deeplinks/2019/01/5g-protocol-may-still-be-vulnerable-imsi-catchersDIGITS documentary: https://curiositystream.com/video/1720My new Apress video: Maximum Privacy with End-to-End Encryption https://link.springer.com/video/10.1007/978-1-4842-7034-9
The single easiest way to track someone today is using their cell phone. We have them with us at all times and in order for them to work, they must be tracked by the cell phone network. When law enforcement wants to identify people at a protest or hanging around a particular area, they could take the time to get a warrant to present to multiple cell phone providers. Or they could simply bring in a portable, fake cell site. Any cell phones in the area will reveal their location to all nearby cell sites, and the owners of those phones will be none the wiser. The use of cell site simulators (often known by a particularly popular model called a "Stingray") is heavily shrouded in secrecy. Even their very existence was denied for years. Today, we'll talk with a man who has made it his mission to uncover the use of such devices. We'll talk about how they work, why they're so hard to detect, and the broader implications of their use by police and sheriff's departments with little to no oversight.
Cooper Quintin is a security researcher and Senior Staff Technologist with the EFF Threat Lab. He has worked on projects such as Privacy Badger, Canary Watch, and analysis of state sponsored malware campaigns such as Dark Caracal. He has also performed security trainings for activists, non profit workers and ordinary folks, and given talks about security research at security conferences around the world. He previously worked building websites for non-profits, such as Greenpeace, Adbusters, and the Chelsea Manning Support Network. Cooper was also an editor and contributor to the hacktivist journal, "Hack this Zine." He has spoken at multiple black hat conferences about security issues ranging from IMSI Catchers to Malware attacks against journalists.
Further Info
BECOME A PATRON! https://www.patreon.com/FirewallsDontStopDragonsElectronic Frontier Foundation (EFF): https://www.eff.org/ EFF’s Electronic Frontier Alliance: https://www.eff.org/electronic-frontier-alliance Crocodile Hunter project: https://github.com/EFForg/crocodilehunterHow IMSI catchers work: https://www.eff.org/wp/gotta-catch-em-all-understanding-how-imsi-catchers-exploit-cell-networksEFF page on IMSI catchers: https://www.eff.org/pages/cell-site-simulatorsimsi-catchersWhy 5g won't help: https://www.eff.org/deeplinks/2019/01/5g-protocol-may-still-be-vulnerable-imsi-catchersSea Glass project: https://seaglass.cs.washington.edu/ Sitch project: https://sensor.readthedocs.io/en/latest/ My new Apress video: Maximum Privacy with End-to-End Encryption https://link.springer.com/video/10.1007/978-1-4842-7034-9
Lots of news to cover today... and to me the common thread seems to be a lack of proper security and privacy. So the theme today is "trust no one". And the idea there isn't really personal trust, but computer trust, algorithm trust, procedural trust. We need to engineer our systems and processes around the idea that data is a toxic asset that loves to find ways to leak. Assume that you will be hacked. Assume an employee will do something stupid or go rogue. Assume the "bad guys" will find a way to bypass your main security barrier, so you need to have a second, and possible third barrier in place.
Today I'll tell you about yet another massive Facebook and LinkedIn data leak; a new vaccine survey scam to watch out for; some new and troubling ransomware tactics to force victims to pay even if they have good data backups; a hacker site that sold credit cards and social security numbers was itself hacked; LexisNexis and Clearview AI have been working very closely with law enforcement, including ICE; and the ACLU has been caught sharing their own user's data with (of all companies) Facebook. And finally, I review the fantastic new book, Privacy is Power by Carissa Véliz.
Further Info
BECOME A PATRON! https://www.patreon.com/FirewallsDontStopDragons Privacy is Power book review: https://firewallsdontstopdragons.com/privacy-is-power-review/ Were you part of a data breach? https://haveibeenpwned.com/ Articles quoted today:Don’t Fall for the 'Vaccine Survey' Scam https://twocents.lifehacker.com/don-t-fall-for-the-vaccine-survey-scam-1846620925 Ransomware gang leaks data from Stanford, Maryland universities https://www.bleepingcomputer.com/news/security/ransomware-gang-leaks-data-from-stanford-maryland-universities/ Ransom Gangs Emailing Victim Customers for Leverage https://krebsonsecurity.com/2021/04/ransom-gangs-emailing-victim-customers-for-leverage/ Facebook Says Leak of 533 Million Users’ Data Wasn’t a Hack. https://www.wsj.com/articles/facebook-says-leak-of-533-million-users-data-wasnt-a-hack-does-it-matter-11617910106 , https://www.bleepingcomputer.com/news/security/533-million-facebook-users-phone-numbers-leaked-on-hacker-forum/ Another 500 million accounts have leaked online, and LinkedIn’s in the hot seat https://www.theverge.com/2021/4/8/22374464/linkedin-data-leak-500-million-accounts-scraped-microsoft 70,000 SSNs, 600,000 Credit Card Records Leaked After Stolen-Data Hub Gets Hacked https://gizmodo.com/70-000-ssns-600-000-credit-card-records-leaked-after-s-1846638234 LexisNexis to Provide Giant Database of Personal Information to ICE https://theintercept.com/2021/04/02/ice-database-surveillance-lexisnexis/ Clearview AI used by police https://www.buzzfeednews.com/article/ryanmac/clearview-ai-local-police-facial-recognition ACLU, a defender of digital privacy, reveals that it shares user data with Facebook https://fortune.com/2021/04/02/aclu-shares-data-facebook-third-parties-digital-privacy/
There are many business models and businesses that we curtail because they can be dangerous to people or democracy or society. Even rights enshrined in the US Constitution have reasonable limits. Now that it's become evident how engagement-optimized and algorithm-driven social media is ripping at the very fabric of our democracy, it's time for an intervention. Today, Phil Zimmermann (creator of PGP) will explain why things have gotten so bad and what we need to do to fix it and save civil society.
Phil Zimmermann is the creator of Pretty Good Privacy. PGP is still widely regarded as the gold standard for secure email communication and caused quite a controversy when it was introduced in the early 1990s. Phil went on to form Silent Circle and win several prestigious awards including US Privacy Champion and was inducted into the Cybersecurity Hall of Fame.
Further Info
BECOME A PATRON! https://www.patreon.com/FirewallsDontStopDragons About Phil Zimmermann: https://www.philzimmermann.com/EN/background/index.htmlRead Crypto by Steven Levy: https://amzn.to/2PyAjKE Silent Circle: https://www.silentcircle.com/ Okuna update: https://medium.com/okuna/the-path-forward-8d56ccf37b5c Check out Somus.app: https://www.somus.app/ Watch The Social Dilemma: https://www.netflix.com/title/81254224 Watch The Great Hack: https://www.netflix.com/Title/80117542 Foundation for Individual Rights in Education (FIRE): https://www.thefire.org/
Passwords suck and humans aren't good at using them. Password managers can help a lot, but to truly improve your account security these days, you need to add defense in depth. The easiest way to do that today is to enable two-factor authentication, or 2FA. Many websites have supported 2FA for years, but as hacking has gotten more aggressive and password databases are being stolen more often, the popularity of 2FA has grown significantly in the last year or two. Unfortunately, many 2FA systems rely on the lowest common denominator for implementing the PIN code system: SMS or text messaging. SMS is very old, but also very widely used and supported. It's never been terribly secure, but recently some clever security researchers have discovered a simple and cheap way to steal your text messages. Like, for $16. I'll explain this hack and tell you how and why you should switch to the much more secure Time-based one-time-password (TOTP) system for 2FA.
In other news: I'll update you on the massive Microsoft Exchange hack; I'll cover a couple stories about Apple bowing to pressure from foreign powers; thousands of surveillance cameras hacked in major corporations, schools, hospitals and even jails; a clever technique to identify deepfake videos; two welcome new privacy features in Firefox; Amazon's take-it-or-leave-it driver surveillance demands; opting out of T-Mobile's new data grab; and Texas making hundreds of millions of dollars off their citizens' data.
Further Info
Amazing Tom Cruise deep fake videos: https://www.tiktok.com/@deeptomcruise Stop using SMS for 2FA: https://firewallsdontstopdragons.com/stop-using-text-messages-for-2fa/ First interview with PGP’s Phil Zimmermann: https://podcast.firewallsdontstopdragons.com/2018/05/07/we-now-live-in-the-golden-age-of-surveillance/ Microsoft: 92% of Exchange servers safe from ProxyLogon attacks https://www.bleepingcomputer.com/news/security/microsoft-92-percent-of-exchange-servers-safe-from-proxylogon-attacks/ Apple Provides Timeline for ProtonVPN App Update, Suggesting App Store Rejection Was Unrelated to Current Events in Myanmar https://www.macrumors.com/2021/03/25/apple-responds-protonvpn-app-update-rejection/ Apple Bent the Rules for Russia—and Other Countries Will Take Note https://www.wired.com/story/apple-russia-iphone-apps-law/ Hackers Breach Thousands of Security Cameras, Exposing Tesla, Jails, Hospitals https://www.bloomberg.com/news/articles/2021-03-09/hackers-expose-tesla-jails-in-breach-of-150-000-security-cams?sref=iKB6XOvfScientists developed a clever way to detect Deepfakes by analyzing light reflections in the eyes https://thenextweb.com/neural/2021/03/11/ai-detects-deepfakes-analyzing-light-reflections-in-the-cornea-eyes-gans-thispersondoesnotexist/ Firefox 87 introduces new SmartBlock tracker blocking mechanism https://appleinsider.com/articles/21/03/24/firefox-87-launches-introduces-new-smartblock-tracker-blocking-mechanism Mozilla Firefox tweaks Referrer Policy to shore up user privacy https://www.zdnet.com/article/mozilla-firefox-tweaks-referrer-policy-to-shore-up-user-privacy/ Amazon Delivery Drivers Forced to Sign ‘Biometric Consent’ Form or Lose Job https://www.vice.com/en/article/dy8n3j/amazon-delivery-drivers-forced-to-sign-biometric-consent-form-or-lose-job It’s mind-blowing how many millions of dollars Texas makes each year selling your personal data https://www.dallasnews.com/news/watchdog/2021/03/19/its-mind-blowing-how-many-millions-of-dollars-texas-makes-each-year-selling-your-personal-data/ U.S. Carriers Fix SMS Routing Vulnerability That Let Hackers Hijack Texts https://www.macrumors.com/2021/03/25/sms-routing-vulnerability-fix/
Given that we're using computer algorithms to evaluate humans, can these systems be gamed or fooled? And is it possible that computers are less biased that humans? On any given day, humans can be distracted, tired, sick or just flat out biased against people for any number of reasons. Should these systems be more transparent? How do we know if they're being fair? Do we need to regulate these services? Is there a happy medium here? And finally, if you feel that you've been unfairly discriminated against by these systems, is there anything you can do about it?
John Davisson is Senior Counsel at EPIC. John works on a variety of appellate litigation and Freedom of Information Act cases. John first came to EPIC in 2015 as a clerk in the Internet Public Interest Opportunities Program. He has previously clerked at Levine Sullivan Koch & Schulz, served as a student attorney in the Civil Rights Section of Georgetown’s Institute for Public Representation, and interned at the Appignani Humanist Legal Center. John is a 2016 magna cum laude graduate of Georgetown University Law Center, where he was managing editor of the Georgetown Journal on Poverty Law & Policy, a Georgetown Law Fellow, and an NGO observer to the 9/11 military commission at Naval Station Guantanamo Bay. He worked as a journalist before entering the law and earned his B.A. at Columbia University. John is a member of the New York and District of Columbia bars.
Further Info:
Electronic Privacy Information Center: https://epic.org/ Become a patron! https://www.patreon.com/FirewallsDontStopDragons Follow me!https://twitter.com/FirewallDragonshttps://www.facebook.com/FirewallsDontStopDragons https://bit.ly/Firewalls-YouTube
Convincing a human to hire you is hard enough. Can you imagine trying to convince a computer? Artificial intelligence is now being used to automate the screening of job candidates, evaluating cognitive ability, vocabulary, and even emotional intelligence. This new "hiretech" promises to weed out the bad applicants and flag the good ones by analyzing not just the substance of answers to interview questions, but also the manor in which you respond - your cadence, your word choices, your tone, your speech patterns, and perhaps even your facial expressions and body language. What could possibly go wrong? We'll discuss this and more today with John Davisson from the Electronic Privacy Information Center.
John Davisson is Senior Counsel at EPIC. John works on a variety of appellate litigation and Freedom of Information Act cases. John first came to EPIC in 2015 as a clerk in the Internet Public Interest Opportunities Program. He has previously clerked at Levine Sullivan Koch & Schulz, served as a student attorney in the Civil Rights Section of Georgetown's Institute for Public Representation, and interned at the Appignani Humanist Legal Center. John is a 2016 magna cum laude graduate of Georgetown University Law Center, where he was managing editor of the Georgetown Journal on Poverty Law & Policy, a Georgetown Law Fellow, and an NGO observer to the 9/11 military commission at Naval Station Guantanamo Bay. He worked as a journalist before entering the law and earned his B.A. at Columbia University. John is a member of the New York and District of Columbia bars.
Further Info:
Electronic Privacy Information Center: https://epic.org/ Become a patron! https://www.patreon.com/FirewallsDontStopDragons Weapons of Math Destruction: https://www.amazon.com/Weapons-Math-Destruction-Increases-Inequality/dp/0553418815
Ep210. I've recommended LastPass for years - since I wrote my book and every day since. Until now. There are several good (secure and private) password managers out there. But LastPass was the full package: a free tier that had all the functionality most people need and for-pay tiers that had very useful extras. But now they're hobbling the free version by only allowing you to use it on one type of device: either a mobile device or a computer, but not both. To me, that makes the free tier useless. LastPass's Android app was also found to contain seven different trackers. That was the last straw for me. In today's episode, I'll tell you my new recommendations and give you an important tip on making the switch.
In other news: a new law in Australia aims to force Google and Facebook to pay for news links; SolarWinds is blaming an intern for using a horrible password; SMS tax scams are picking up; Alexa Skills have serious privacy and security issues; adtech companies are scrambling to avoid telling you that you're being tracked on iOS; cops use copyright filters to prevent being recorded; a new company is creating a nationwide surveillance system; pharmacies are capitalizing on the COVID vaccine to get your data for marketing; Firefox 86 has a killer new system to prevent third party cookie tracking; however, adtech is exploiting a loophole in DNS to turn third party cookies into first party cookies.
Further Info:
Switching to Bitwarden: https://firewallsdontstopdragons.com/?p=2447Chat with me on Discord and get exclusive content! https://www.patreon.com/FirewallsDontStopDragons SMS tax scam unmasked: Bogus but believable – don’t fall for it! https://nakedsecurity.sophos.com/2021/02/12/sms-tax-scam-unmasked-bogus-but-believable-dont-fall-for-it/Alexa Skills: Security gaps and data protection problems https://www.helpnetsecurity.com/2021/03/02/alexa-skills-security/Ongoing & enormous Microsoft Exchange server hack hits 30,000 US groups https://appleinsider.com/articles/21/03/06/microsoft-exchange-server-hack-affects-over-30000-us-organizationsPost-IDFA Alliance will address concerns of mobile app and game marketers https://venturebeat.com/2021/02/17/post-idfa-alliance-will-address-concerns-of-mobile-app-and-game-marketers/Judge approves $650m settlement of privacy lawsuit against Facebook https://www.theguardian.com/technology/2021/feb/27/facebook-illinois-privacy-lawsuit-settlementCops Using Music to Try to Stop Being Filmed Is Just the Tip of the Iceberg https://www.eff.org/deeplinks/2021/02/cops-using-music-try-stop-being-filmed-just-tip-icebergInside ‘TALON,’ the Nationwide Network of AI-Enabled Surveillance Cameras https://www.vice.com/en/article/bvx4bq/talon-flock-safety-cameras-police-license-plate-readerYou got a vaccine. Walgreens got your data. (Recode) https://www.vox.com/recode/22310281/covid-vaccine-walgreens-cvs-rite-aid-walmart-dataFirefox's Total Cookie Protection aims to stop tracking between multiple sites https://www.engadget.com/firefox-total-cookie-protection-stop-tracking-websites-140044979.htmlOnline Trackers Increasingly Switching to Invasive CNAME Cloaking Technique https://thehackernews.com/2021/02/online-trackers-increasingly-switching.htmlChanges to LastPass Free https://blog.lastpass.com/2021/02/changes-to-lastpass-free/Security researcher raises questions about trackers in LastPass Android app https://appleinsider.com/articles/21/02/26/security-raises-questions-about-trackers-in-lastpass-android-app
In the second half of my interview with the Tech Learning Collective, we delve into their course curriculum a bit, and then discuss why they teach what they teach and how they approach these topics in a unique and meaningful way. We also examine the notion of "ethical hacking" and how this term can be used to whitewash some truly unethical and immoral products and services. Finally, we discuss why it's important to know how to perform cyber attacks in order to properly defend against them. These classes are truly like nothing else you'll find online. Check out one of their workshops for yourself (and support their important work in the process)!
Technology, taught collectively. Looking to get certified? Look elsewhere. Looking to spark a revolution? We’ll show you how to become more powerful than the most well-funded adversaries, including corporate- and government-backed opponents.
Further Info
Tech Learning Collective: https://techlearningcollective.com/ Support me on Patreon! https://www.patreon.com/FirewallsDontStopDragons The Privacy Issue’s Essential Privacy Podcasts: https://theprivacyissue.com/privacy-and-society/download-privacy-security-podcastsTranscript: https://techlearningcollective.com/2021/04/06/firewalls-dont-stop-dragons-interviews-tech-learning-collective-part-2.html
I first learned of the Tech Learning Collective at a privacy conference in late 2020. I struck up a conversation with one of its representatives and ended up taking one of their wonderful workshops in January. The TLC offers some top-notch courses on computers with a focus on cybersecurity. Unlike college courses or cybersecurity certification courses, TLC offers eminently practical and affordable content, focused squarely on doing. It's like the difference between taking a karate class to earn colored belts and taking a personal self defense class to actually protect yourself. But it's also much more than that, and hard to describe. You'll have to listen to this interview to truly understand! From their website...
Technology, taught collectively. Looking to get certified? Look elsewhere. Looking to spark a revolution? We’ll show you how to become more powerful than the most well-funded adversaries, including corporate- and government-backed opponents.
Further Info
Tech Learning Collective: https://techlearningcollective.com/ The Privacy Issue's Essential Privacy Podcasts: https://theprivacyissue.com/privacy-and-society/download-privacy-security-podcastsTranscript: https://techlearningcollective.com/2021/04/06/firewalls-dont-stop-dragons-interviews-tech-learning-collective-part-1.html
Ep207. Clearview AI - the company that has hoovered up every face it can find on the internet to create a creepy person identifying app - is back in the news. Canada and the EU have decided that Clearview has gone too far and needs to allow its users to opt out and even delete all the data they have, upon request. It's a welcome development, but unfortunately only available to California residents in the US (plus Canada and the EU). I'll tell you how to delete your data.
In other news: Google uncovers a killer security feature in iOS 14 called BlastDoor; Amazon is expanding its "surveillance empire" in a massive and creepy way; someone "hacked" a water treatment plant in Florida trying (and failing) to poison its citizens; a bad bug has been found in a popular Wi-Fi iOT chip; a new phishing attack uses Morse code to hide its malicious web links; Facebook's "Supreme Court" has rendered its first set of rulings; and Clubhouse, the latest social media craze, is using some intrusive techniques to find more members. Also, I've got several tips for tax time in the US, including avoiding scams and safely transferring your financial data.
Further Info
Opt out of Clearview AI and delete your data: https://clearview.ai/privacy/requests Avoid tax scams: https://firewallsdontstopdragons.com/its-tax-scam-time-again/ Send files securely: https://firewallsdontstopdragons.com/how-to-send-files-securely-like-tax-info/ Get your IRS IP PIN: https://www.irs.gov/identity-theft-fraud-scams/get-an-identity-protection-pin
Episode 206. The social media events around the January 6th storming of the US Capitol have sparked raging, divisive debates in the US. But the banning of individuals and the deplatforming of apps and groups are not new phenomenons. The Right of Free Speech that is enshrined in the First Amendment to the US Constitution is not limitless. It does have legal boundaries. And private companies, even monopolies, have the legal right to control access to their platforms. But does that make it right? Today, I will wade into this decidedly thorny issue with Troy Hunt, who brings a plethora of global technology and security experience to the debate.
Troy Hunt is an Australian Microsoft Regional Director and a Most Valuable Professional awardee for Developer Security. He’s a blogger, international speaker and author of several online courses, and he runs the very valuable internet security service HaveIBeenPwned.
Further Info
Troy Hunt’s blog on deplatforming: https://www.troyhunt.com/weekly-update-226/ EFF's take: https://www.eff.org/deeplinks/2019/05/censorship-cant-be-only-answer-disinformation-online Legal limits of free speech: https://en.wikipedia.org/wiki/United_States_free_speech_exceptions Listener survey: https://bit.ly/Firewalls-survey-2021 Patron survey: http://bit.ly/Firewalls-patron-survey-2021
Tracking and data mining has gotten way out of hand. We're not only being tracked online, we're now being tracked around the real world, too. We're truly living in a panopticon - and it's not good for us as individuals or as a democratic society. Today I'll cover several stories that make it clear that we've hit a tipping point. It has to stop. And it's going to require all of us putting pressure on our representatives to lay down some common sense rules to curb surveillance capitalism.
In today’s news: One week left to send in your podcast listener survey; update all your iOS devices ASAP; Apple walks back a controversial OS change that would have allowed some Apple apps to bypass firewalls and VPNs; Microsoft is touting a new Edge browser feature that notifies you when your passwords have been breached; an innocuous-looking police robot is actually paving the way towards chilling mass surveillance; another US intelligence agency has been caught buying the location data of US citizens from data brokers; Apple’s efforts at improving user privacy are ruffling more feathers at Google and Facebook.
Further Info
New Years Resolution ideas for 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/Data Privacy Day checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ Listener survey: https://bit.ly/Firewalls-survey-2021 Patron survey: http://bit.ly/Firewalls-patron-survey-2021
We all love to beat up on Facebook over user privacy, but the real granddaddy of them all is Google. Google is everywhere. And they almost surely know way more about you than any other company on the planet. In addition to all the "G" apps and services that you know about, Google also owns Android, Chrome browser, Waze, Nest and YouTube. It's extremely hard to avoid using Google. But there are alternatives that will respect your privacy - and today I'll give you a long list of viable options. And with international Data Privacy Day happening this week (Jan 28th), it's a great time to take back control of your data.
In other news: Some malicious Chrome extensions have been scraping Facebook data, a man working for ADT has been caught spying on women using the security cameras he helped to install, Google seems to be dragging their heels on updating their iOS app privacy labels, Malwarebytes says they've been hacked by the same group behind the SolarWinds hacks, WhatsApp has upset many of their users with a new privacy ultimatum, and I'll delve into the national security implications of the recent US Capitol breach.
Further Info
Listener survey: https://bit.ly/Firewalls-survey-2021 Patron survey: http://bit.ly/Firewalls-patron-survey-2021 My Data Privacy Day Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ Google Alternatives: https://restoreprivacy.com/google-alternatives/Restore Privacy tools: https://restoreprivacy.com/privacy-tools/ No More Google: https://nomoregoogle.com/ Just Get My Data: https://justgetmydata.com/Just Delete Me: https://justdeleteme.xyz/
So I want to switch to a new, privacy-respecting email service. How do I even do that? What happens to all the email I have now? What about my calendar and contacts? Am I going to have to change my email address every time I change email providers? In part 2 of my interview with Fastmail's COO Helen Horstmann-Allen, we'll answer these questions and also address the thorny issue of privileged access by law enforcement.
Helen Horstmann-Allen is the Chief Operating Officer at Fastmail where she provides overall business strategy and product direction for Fastmail and its suite of products. Before Fastmail, she ran her company, Pobox, an email forwarding service, for 20 years before Fastmail acquired it in 2015. Helen graduated from the Wharton School of Business and currently serves on several nonprofit boards in the Philadelphia area.
Further Info
2021 Listener Survey: http://bit.ly/Firewalls-survey-2021 New Year’s Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/ No More Google: https://nomoregoogle.com/ Sign up for Fastmail (referral link): https://ref.fm/u18721448
What could I learn about you if I read all your emails? Like, all of them. Since you started sending email. Beyond private conversations, I would also likely know every web site you have a relationship or account with, every online purchase you've made, every club or organization you've been a part of, and all the appointments you've made. I can also make a pretty comprehensive list of everyone you know. And that's just the tip of the iceberg. If I analyze the content of your emails, I could almost certainly determine your political leanings, sexual preferences, religion, income, location(s), and more. So why don't we put more thought into choosing our email provider? In part one of my interview with Fastmail's COO, Helen Horstmann-Allen, we'll discuss how email privacy really works and why it's so crucially important.
Helen Horstmann-Allen is the Chief Operating Officer at FastMail where she provides overall business strategy and product direction for Fastmail and its suite of products. Before Fastmail, she ran her company, Pobox, an email forwarding service, for 20 years before Fastmail acquired it in 2015. Helen graduated from the Wharton School of Business and currently serves on several nonprofit boards in the Philadelphia area.
Further Info
CONTEST LINK!! http://bit.ly/Firewalls-200 New Year's Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/ No More Google: https://nomoregoogle.com/Sign up for Fastmail (referral link): https://ref.fm/u18721448 Arnold’s take: https://www.youtube.com/watch?v=mz3zFsTp2Pk
The Russian SVR has had backdoor access to hundreds if not thousands of government and corporate networks for nearly nine months. And if not for private security firm FireEye, we might never have known. The SolarWinds supply chain hack may be the biggest, most consequential cybersecurity event ever. And it will literally be years before we understand the full impacts. However, from what we know so far, this was not an "attack" or "act of war" ... it was straight-up espionage, which is widely accepted as normal during peacetime. The US does this all the time, as do all modern nations. And yet, espionage and infiltration are the first steps in any actual attack. It's a fine line. We'll discuss it today.
In other news: Adobe Flash is finally dead - it's time to remove it; Facebook is being sued by almost all 50 states and the Federal Trade Commission; butt-flap pajamas flooded internet ads; GoDaddy plays a cruel Christmas prank on its employees; Microsoft, McAfee and many others have joined forces to fight ransomware; and Signal messenger was NOT hacked by Cellebrite.
Further Info
CONTEST LINK!! http://bit.ly/Firewalls-200 Follow me on Facebook!! https://bit.ly/Firewalls-FacebookFollow me on YouTube!! https://bit.ly/Firewalls-YouTubeNew Year's Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/ Uninstall Adobe Flash:Windows: https://helpx.adobe.com/flash-player/kb/uninstall-flash-player-windows.htmlMac: https://helpx.adobe.com/flash-player/kb/uninstall-flash-player-mac-os.html
The dumpster fire that was 2020 is almost behind us, and it's time to look forward to a brighter future in 2021! By a stroke of fortuitous coincidence, this is also my 200th podcast! To celebrate these two important milestones, we have a world-renowned security guru for our guest, Bruce Schneier, and I'll be giving away over $1800 worth of great stuff to help you improve your privacy and security in 2021! And if all of that weren't enough, I'll also be sharing with you several top-notch to-do list ideas for your 2021 New Year's resolutions - not just from myself, but from several top industry experts! It's an amazing star-studded, prize-riddled, info-packed podcast!
Special Guest Appearances By:
Bruce Schneier (Chief of Security Architecture at Inrupt)Dr Ann Cavoukian (Executive Director at Global Privacy & Security by Design Centre)Dr Andy Yen (CEO/Co-Founder ProtonMail)Cory Doctorow (author & activist)David Ruiz (Malwarebytes)Helen Horstmann-Allen (COO Fastmail)Beah Burger-Lenehan (Director, Product at DuckDuckGo)Marshall Erwin (Chief Security Officer, Mozilla)Todd Weaver (Founder/CEO Purism)Rich Stokes (Founder/CEO Winston Privacy)
Further Info:
CONTEST LINK!! http://bit.ly/Firewalls-200Contest info: https://firewallsdontstopdragons.com/new-years-2021-giveaway/New Year's Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/Inrupt: https://inrupt.com/solidSolid Project: https://solidproject.org/Follow me on Facebook!! https://bit.ly/Firewalls-FacebookFollow me on YouTube!! https://bit.ly/Firewalls-YouTube
I've painstakingly scoured the last 50 episodes to select the best of the best, the cream of the crop, the top tips for the year 2020! If you're already a subscriber, this will be a great refresher - and maybe give you a chance to do some of those things you had meant to do but somehow never got around to doing it! And if you're a new subscriber, then you can catch up on some of what you missed! This would also be a great episode to share with friends and family who you feel might also benefit from improving their cyber security and data privacy! Enjoy! And Happy Holidays!!
Further Info
Don't miss the HUGE 200th episode next week! https://firewallsdontstopdragons.com/200th-podcast-a-brighter-future/Follow me on Facebook!! https://bit.ly/Firewalls-Facebook Follow me on YouTube!! https://bit.ly/Firewalls-YouTube
One today's show, Ben Moskowitz from Consumer Reports will tell us about an extremely useful tool they've created to help you improve your personal security and privacy, customized to your particular needs, called the Security Scanner. Just answer a few simple questions and it will give you a checklist of specific ways to be more secure, ranked by time, effort and cost.
Consumer Reports is also pioneering a comprehensive, open-source program that will allow consumers, manufacturers, advocacy organizations, and more to formally evaluate the privacy and security aspects of products and services. This will allow buyers to compare products more accurately and give manufacturers incentives to make better products.
Benjamin Moskowitz is the Director of Consumer Reports’ Digital Lab, a major initiative to expand CR’s work on privacy, digital security, and emerging concerns in digital consumer protection. Previously, he served as Director of Development for Innovation for the International Rescue Committee, where he secured more than $29 million in funding as a founding member of the Airbel Center—a research and development unit that designs, tests, and scales life-changing solutions for refugees and people affected by conflict.
Further Info
Consumer Reports Security Planner: https://securityplanner.consumerreports.org/ The Digital Standard: https://thedigitalstandard.org/ Virtual screening of Coded Bias: https://action.consumerreports.org/coded_bias Contribute! https://digital-lab.consumerreports.org/ Become a CR Member: https://www.consumerreports.org/membership Privacy Front & Center study: https://thedigitalstandard.org/downloads/CR_PrivacyFrontAndCenter_102020_vf.pdf Best & Worst Gift Guide 2020: https://firewallsdontstopdragons.com/best-worst-gifts-2020/ Follow me on Facebook!! https://bit.ly/Firewalls-Facebook Follow me on YouTube!! https://bit.ly/Firewalls-YouTubeRequest book for review: https://form.jotform.com/203127587895064
Are consumers really concerned about security and privacy in the products they buy? And if so, how could manufacturers capitalize on these attributes to sell more of their products? Consumer Reports has recently published an important, comprehensive study of consumer attitudes towards privacy and security, including the historical evolution of these feelings. The result is a roadmap which companies can use to better serve this fast-growing market. Today we'll discuss this study and its implications with Ben Moskowitz from CR's Digital Lab.
Benjamin Moskowitz is the Director of Consumer Reports' Digital Lab, a major initiative to expand CR’s work on privacy, digital security, and emerging concerns in digital consumer protection. Previously, he served as Director of Development for Innovation for the International Rescue Committee, where he secured more than $29 million in funding as a founding member of the Airbel Center—a research and development unit that designs, tests, and scales life-changing solutions for refugees and people affected by conflict.
Further Info:
Privacy Front & Center study: https://thedigitalstandard.org/downloads/CR_PrivacyFrontAndCenter_102020_vf.pdfConsumer Reports Security Planner: https://securityplanner.consumerreports.org/The Digital Standard: https://thedigitalstandard.org/Virtual screening of Coded Bias: https://action.consumerreports.org/coded_biasContribute! https://digital-lab.consumerreports.org/Become a CR Member: https://www.consumerreports.org/membershipMy new YouTube Channel: https://www.youtube.com/channel/UC0aUElaV7hDubXSpDJkiSrARequest book for review: https://form.jotform.com/203127587895064
Looking for fun gifts that won't also be gifts to hackers and data miners? In today's show, I'll list off the top products and services from my annual Naughty & Nice gifts guide! Every year, I review several popular gifts and give you my recommendations on which ones to buy and which ones to avoid like the plague (or the pandemic?).
In other news: Spotify has been hacked and you should change your password; Google is looking to add end-to-end encryption to its new Android RCS messaging system; an important new IoT security bill is waiting for the President's signature; 27.7M Texans' driver's license info has been stolen; the IRS and the US military have been doing an end run around the US Constitution to obtain location information on thousands of people including US citizens without a warrant; Apple lowers its App Store commission to 15% for the vast majority of developers; Apple has responded to the blow back concerning its security validation on macOS Big Sur; and now is the time to download and enable your state's COVID-19 tracing app.
Further Info:
Best & Worst Gifts for 2020: https://firewallsdontstopdragons.com/best-worst-gifts-2020/ COVID-tracing app story, Washington Post: https://www.washingtonpost.com/technology/2020/11/18/coronavirus-app-exposure-alerts/Setting up a Pi-Hole server: https://www.smarthomebeginner.com/pi-hole-setup-guide/
So, what can we do about these dark patterns? Are there technical solutions to this problem? Or will this require regulations? Or perhaps we just need to train our engineers and consumers better? In part 2 of my interview with Dr. Colin Gray of Purdue University, we talk about some possible solutions to the dark patterns problem, as well as tips and tricks for avoiding them. Colin also shares several interesting resources for further study.
Colin M. Gray is an Assistant Professor at Purdue University in the Department of Computer Graphics Technology. He is program lead for an undergraduate major and graduate concentration in UX Design. He holds a PhD in Instructional Systems Technology from Indiana University Bloomington, a MEd in Educational Technology from University of South Carolina, and a MA in Graphic Design from Savannah College of Art & Design. He has worked as an art director, contract designer, and trainer, and his involvement in design work informs his research on design activity and how design capability is learned. His research focuses on the ways in which the pedagogy and practice of designers informs the development of design ability, particularly in relation to ethics, design knowledge, and professional identity formation.
Further Info:
Colin’s home page: https://colingray.me Dark Patterns: https://darkpatterns.uxp2.com Dark Patterns (Brignull): https://darkpatterns.org/ Give Thanks: https://firewallsdontstopdragons.com/give-thanks-donate/ Rachel Maddow’s plea: https://www.nbcnews.com/feature/nbc-out/rachel-maddow-says-her-partner-has-covid-19-one-point-n1248375COVID-19 risk assessment tool: https://covid19risk.biosci.gatech.edu/ Facebook’s Social Contagion experiment: https://www.forbes.com/sites/kashmirhill/2014/06/30/facebook-only-got-permission-to-do-research-on-users-after-emotion-manipulation-study/Evil By Design: https://www.amazon.com/Evil-Design-Interaction-Lead-Temptation/dp/1118422147 Design Justice: https://design-justice.pubpub.org/ Data Feminism: https://data-feminism.mitpress.mit.edu/ Michael Sandel’s Justice course: http://justiceharvard.org/justicecourse/
Are you tired of being pestered to allow notifications or access to your location? Do you wonder why you have to give your credit card number in order to sign up for "free" trials? Why weren't you told about the shipping costs until the very last screen in the purchase process? Are you sure that you didn't intend to sign up for all those newsletters? You're not alone, and you're not simply being subjected to clever marketing. You've been the victim of dark patterns: specific, scientifically-proven techniques designed to favor shareholder value over user value. In part 1 of my interview with Dr. Colin Gray, we'll discuss all the ways in which we're being manipulated and why, as mere humans, we're horribly outmatched.
Colin M. Gray is an Assistant Professor at Purdue University in the Department of Computer Graphics Technology. He is program lead for an undergraduate major and graduate concentration in UX Design. He holds a PhD in Instructional Systems Technology from Indiana University Bloomington, a MEd in Educational Technology from University of South Carolina, and a MA in Graphic Design from Savannah College of Art & Design. He has worked as an art director, contract designer, and trainer, and his involvement in design work informs his research on design activity and how design capability is learned. His research focuses on the ways in which the pedagogy and practice of designers informs the development of design ability, particularly in relation to ethics, design knowledge, and professional identity formation.
Further Info:
Dr. Colin Gray's home page: https://colingray.me Dark Patterns: https://darkpatterns.uxp2.com Dark Patterns (Brignull): https://darkpatterns.org/ Facebook’s Social Contagion experiment: https://www.forbes.com/sites/kashmirhill/2014/06/30/facebook-only-got-permission-to-do-research-on-users-after-emotion-manipulation-study/
Zoom went from an obscure teleconferencing company to a household word when the pandemic hit. Zoom wasn’t the best videoconferencing app by any means. But it was dead simple to use and kinda fun to say. For better or worse, it became the de facto tool for many of us to keep in touch. Over that time, Zoom has made many important improvements. This week it has finally rolled out what appears to be true end-to-end encryption (E2EE). Today I'll tell you how to enable this new feature.
In other news: Be sure to update your iPhones to iOS 14.2; also be sure to keep Google Chrome and Windows 10 up to date; Adobe Flash is finally almost gone; police in Jackson, Mississippi are trialing a program to directly tap into people's private security cameras like Ring video doorbells; the NSA and FBI have been burned by the very backdoors they added; and California's Prop 24 passes, beefing up privacy protections for its citizens (and probably for all of us).
Further Info (for podcast page)
How to enable Zoom end-to-end encryption: https://firewallsdontstopdragons.com/zoom-now-with-actual-privacy/ Best & Worst Gifts from last year: https://firewallsdontstopdragons.com/best-worst-gifts-2019/Please add a nice review on my new book!! https://www.amazon.com/gp/product/1484261887
For better or for worse, the internet today is funded by advertising. While ads can be annoying, the real issue isn't having to watch ads - it's when then ads watch us. AdTech today is premised on invasive personal data collection. Companies like Google and Facebook amass voluminous dossiers on each of us, and sell highly-targeted ads based on our income, gender, age, location, buying habits, personal interests, sexual orientation, and much, much more. But it doesn't have to be that way. And Cloudflare is going to show us how. Today, I'll talk again with the CTO, John Graham-Cumming, about Cloudflare Radar and much more.
John Graham-Cumming is a British software engineer and writer best known for starting a successful petition to the Government of the United Kingdom asking for an apology for its persecution of Alan Turing. As of 2020, he serves as Chief Technology Officer (CTO) at Cloudflare.
Further Info:
Cloudflare Radar: Election 2020 https://radar.cloudflare.com/election-2020Cloudflare 1.1.1.1 DNS and Warp VPN: https://1.1.1.1/ VOTE! https://www.vote.org/
In the second half of my interview with the EFF’s Lindsay Oliver and Jason Kelley, we talk about how these draconian surveillance systems put several students at a distinct disadvantage and how the teacher themselves feel about all of this. How might all of this normalize surveillance for young people? Can the invisible hand of the market resolve some of these issues? What should the policies be around proctoring and the use of these surveillance apps? How can we push back and demand change most effectively?
Lindsay Oliver is the Project Manager for EFF’s activism team, and works on the self-help resource Surveillance Self-Defense, Security Education Companion, and student privacy.
Jason Kelley guides EFF’s social media tactics and develops EFF’s online digital advocacy, and writes about various forms of governmental and private surveillance and tracking.
Further Info:
VOTE! https://www.vote.org/ Cybersecurity & Infrastructure Security Agency tip sheets: https://www.cisa.gov/national-cybersecurity-awareness-month-resources Surveillance Self Defense for students: https://ssd.eff.org/en/module/privacy-studentsElectronic Frontier Alliance: https://supporters.eff.org/join-efa This article has TONS of student privacy resources: https://www.eff.org/deeplinks/2020/09/students-are-pushing-back-against-proctoring-surveillance-apps
In this time of COVID19, we've all had to learn to work and learn from home. But how do our bosses know we're not screwing around instead of working? How do our teachers know we're not cheating? It turns out that they're both willing to go to extremely intrusive measures to try to figure that out. Home and mobile device surveillance technology is booming thanks to this global pandemic, as we will learn from talking to the EFF's Lindsay Oliver and Jason Kelley. They have been investigating the serious impacts these products and services are having on our privacy and overall fairness for students and employees.
Lindsay Oliver is the Project Manager for EFF's activism team, and works on the self-help resource Surveillance Self-Defense, Security Education Companion, and student privacy.
Jason Kelley guides EFF’s social media tactics and develops EFF’s online digital advocacy, and writes about various forms of governmental and private surveillance and tracking.
Further Info:
Surveillance Self Defense for students: https://ssd.eff.org/en/module/privacy-studentsElectronic Frontier Alliance: https://supporters.eff.org/join-efa This article has TONS of student privacy resources: https://www.eff.org/deeplinks/2020/09/students-are-pushing-back-against-proctoring-surveillance-apps National Cybersecurity Awareness Month: https://www.cisa.gov/national-cybersecurity-awareness-month-resources
October is National Cybersecurity Awareness Month! The theme this year is: if you connect it, protect it! And given how popular IoT devices are these days, and also how horrid their security usually is, this advice has never been more important. In today's show, I'll walk through some top cyber tips for protecting your devices and your home network.
And there's a TON of news, as well: I'll update you on the "App Fairness" campaign from Epic, Protonmail, Spotify and others; watch out for fake Android messaging apps made to look like Threema or Telegram; Google's Chrome browser gets slammed for its poor privacy protections; Google is now giving out lists of people who searched on particular terms to law enforcement; Amazon is adding some new privacy options to their Alexa products, while also introducing a super-creepy home spy drone; should you let your insurance company track you? (spoiler: no); and Apple's T2 chip is found to have a severe, unfixable security flaw.
Further Info:
Cybersecurity & Infrastructure Security Agency (CISA) tip sheets: https://www.cisa.gov/publication/national-cybersecurity-awareness-month-publications Get 20% off my new book at Apress using code Dragons2020. https://www.apress.com/us/book/9781484261880 Google Chrome: the Anti-Privacy Browser: https://theprivacy.com/2020/09/14/google-chrome-the-anti-privacy-browser/?hss_channel=tw-976856456740864004 Coalition for App Fairness’s 10 principles examined: https://appleinsider.com/articles/20/10/05/breaking-down-the-coalition-for-app-fairness-issues-with-apple
What do Apple, Tyson Foods and Worldwide Wrestling (WWE) all have in common? And what is "chickenization"? In part 2 of my interview with Cory Doctorow, he explains how some markets in the US economy are completely distorted by dominant sellers as well as dominant buyers. Seeing all of these specific markets as facets of a single economic problem, we can find common cause and perhaps a common solution.
Cory Doctorow (craphound.com) is a science fiction author, activist, and journalist. He is the author of RADICALIZED and WALKAWAY, science fiction for adults, a YA graphic novel called IN REAL LIFE, the nonfiction business book INFORMATION DOESN’T WANT TO BE FREE, and young adult novels like HOMELAND, PIRATE CINEMA and LITTLE BROTHER. His latest book is POESY THE MONSTER SLAYER, a picture book for young readers. His next book is ATTACK SURFACE, an adult sequel to LITTLE BROTHER. He maintains a daily blog at Pluralistic.net. He works for the Electronic Frontier Foundation, is a MIT Media Lab Research Affiliate, is a Visiting Professor of Computer Science at Open University, a Visiting Professor of Practice at the University of North Carolina’s School of Library and Information Science and co-founded the UK Open Rights Group. Born in Toronto, Canada, he now lives in Los Angeles.
Further Info:
Buy Attack Surface: https://us.macmillan.com/books/9781250757531 Back Attack Surface audio book: https://www.kickstarter.com/projects/doctorow/attack-surface-audiobook-for-the-third-little-brother-bookBuy Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Watch The Social Dilemma!: https://www.netflix.com/title/81254224 Donate to EFF: https://supporters.eff.org/donate/join-4 Be very wary of disinformation right now: https://firewallsdontstopdragons.com/fake-news-be-highly-wary-right-now/VOTE!! https://www.vote.org/
Apple and Epic Games are locked in an epic legal (and PR) battle that may determine the future of the App Store, the Google Play Store, and several other game distribution networks. At the heart of this debate is the disproportionate influence the app store owner has over the apps in their store, including demanding a hefty cut of the app maker's profits. How did we get to this place? How does this distort the market for software? When did "contempt of business model" become a felony? Today I'll discuss this and more with EFF's Cory Doctorow.
Cory Doctorow (craphound.com) is a science fiction author, activist, and journalist. He is the author of RADICALIZED and WALKAWAY, science fiction for adults, a YA graphic novel called IN REAL LIFE, the nonfiction business book INFORMATION DOESN’T WANT TO BE FREE, and young adult novels like HOMELAND, PIRATE CINEMA and LITTLE BROTHER. His latest book is POESY THE MONSTER SLAYER, a picture book for young readers. His next book is ATTACK SURFACE, an adult sequel to LITTLE BROTHER. He maintains a daily blog at Pluralistic.net. He works for the Electronic Frontier Foundation, is a MIT Media Lab Research Affiliate, is a Visiting Professor of Computer Science at Open University, a Visiting Professor of Practice at the University of North Carolina’s School of Library and Information Science and co-founded the UK Open Rights Group. Born in Toronto, Canada, he now lives in Los Angeles.
Further Info:
Buy Attack Surface: https://us.macmillan.com/books/9781250757531 Back Attack Surface audio book: https://www.kickstarter.com/projects/doctorow/attack-surface-audiobook-for-the-third-little-brother-bookEnter to win a free copy of my book: https://bit.ly/firewalls4 Buy Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887 Watch The Social Dilemma!: https://www.netflix.com/title/81254224 Donate to EFF: https://supporters.eff.org/donate/join-4 VOTE!! https://www.vote.org/
If you're a Windows PC user, you know the term "bloatware", or maybe "crapware". Every consumer PC comes chock full of it. Free trials of games, cloud storage services and antivirus software. Half a dozen "helper" apps from the PC manufacturer. Pre-installed calling, chat, and shopping services. It's a mess. But they're not just annoying. They can slow down your computer's startup and shutdown, and waste precious battery life on laptops. Today I'll share two ways to take out this trash.
In other news: Android 11 and iOS 14 are out, and have neat new security and privacy features; Google is blocking W3C efforts to improve your privacy while also blocking resource-hogging ads in Chrome and blocking stalkerware apps in the Google Play Store; the FBI is now worried that video doorbells may actually let people spy on them; Facebook will try to ban deepfake political videos; and the US House unanimously passes a much-needed IoT security bill.
Enterprising scammers have found some very clever ways to trick you into believing your computer needs fixing, when in reality it's just fine. Using various techniques, fake web pop-up alerts can cause your browser or computer to seem sluggish or malfunctioning. And then you get a helpful pop-up alerting you of a serious problem and offering to help you fix it - for a fee. I'll tell you how to spot these fakes and how to recover from the issues they've inflicted.
In other news: there's a new and nasty Bluetooth bug, Emotet malware infections are spiking, Apple accidentally notarized malware in its App Store, Apple chooses to delay it's key privacy feature on iOS 14 due to push back from marketing companies like Facebook, the Epic/Apple battle ratchets up yet again, a US circuit court rules that warrantless wiretapping is illegal, Portland enacts the country's strictest ban on facial recognition technology, and the secure messaging app Threema has decided to go open source.
Further Info:
Order the 4th edition of my book: https://www.apress.com/us/book/9781484261880Enter my book giveaway! http://bit.ly/firewalls4
Did you know that Google's search can track you on a non-Chrome browser, even if you block third party cookies? And did you also know that there's a gaping privacy hole in web surfing that even a VPN may not fix? Is it possible to defeat browser fingerprinting? In the second half of my interview with Mozilla's Chief Security Officer Marshall Erwin, we'll answer these questions and much more. Marshall will give us his personal privacy tips and tell us about some upcoming Firefox features. And perhaps most importantly, he'll tell us what we can do to support Mozilla and Firefox.
Marshall Erwin is the Chief Security Officer at the Mozilla Corporation, where he leads teams responsible for protecting Mozilla and its users. He also drives policy initiatives on encryption, government vulnerability disclosure, malicious online content, and online political advertising, as well as product initiatives to protect people from pervasive web tracking. Prior to joining Mozilla, Marshall worked in a variety of positions related to technology policy, cybersecurity, and national security more broadly. He began his career in national security, an analyst covering counterterrorism and cybersecurity. He also served as the counterterrorism and intelligence adviser on the Senate Homeland Security and Government Affairs Committee and as the intelligence specialist at the Congressional Research Service, focusing on National Security Agency surveillance programs and legislative changes to FISA statute. Marshall is a current Non-Residential Fellow at Stanford Law School’s Center for Internet & Society.
Further Info:
Download the Firefox browser: https://www.mozilla.org/en-US/firefox/new/Donate to Mozilla Foundation: https://donate.mozilla.org/en-US/Pre-order the 4th edition of my book: https://www.amazon.com/gp/product/148426188Enter my book giveaway! http://bit.ly/firewalls4
If you really care about online privacy, you can't use Google's Chrome browser. Google is an advertising company. Everything else they do is in support of that core business. If you want a secure, fast browser that is actually focused on protecting your privacy, you want to be using Mozilla's Firefox browser. Today I'll be speaking with Mozilla's Chief Security Officer, Marshall Erwin. We'll trace Firefox's heritage back to the stalwart Netscape Navigator and then dive into the ugly world of ubiquitous web tracking, by both governments and corporations. Are we really going dark? Why is privacy important? Are targeted ads really worth that much more than "dumb" ads?
Marshall Erwin is the Chief Security Officer at the Mozilla Corporation, where he leads teams responsible for protecting Mozilla and its users. He also drives policy initiatives on encryption, government vulnerability disclosure, malicious online content, and online political advertising, as well as product initiatives to protect people from pervasive web tracking. Prior to joining Mozilla, Marshall worked in a variety of positions related to technology policy, cybersecurity, and national security more broadly. He began his career in national security, an analyst covering counterterrorism and cybersecurity. He also served as the counterterrorism and intelligence adviser on the Senate Homeland Security and Government Affairs Committee and as the intelligence specialist at the Congressional Research Service, focusing on National Security Agency surveillance programs and legislative changes to FISA statute. Marshall is a current Non-Residential Fellow at Stanford Law School’s Center for Internet & Society.
Further Info:
Firefox browser: https://www.mozilla.org/en-US/firefox/new/Donate to Mozilla Foundation: https://donate.mozilla.org/en-US/Pre-order the 4th edition of my book: https://www.amazon.com/gp/product/1484261887
Epic - the maker of the massively popular game Fortnite - has thrown down the proverbial gauntlet. It has decided that it no longer wishes to cut Apple in for 30% of its profits... Which is exactly what all app developers do - and have explicitly and contractually agreed to do - in return for using Apple's platform, tools, software development kits, and security testing. Apple provides this and access to billions of users. Microsoft, Sony and Google charge the same 30% in their app stores. But Epic claims that Apple's cut is too much, and has deliberately picked a legal fight with Apple (and Google) to try to get more favorable terms or be allowed to run a private Epic store. It's complex and nuanced, but I'll wade into the muddy and turbulent waters on today's show.
In other news: There's a tricky new Outlook email phishing scam going around, Jack Daniels has been hacked and asked to pay millions in ransom, Google had a big outage, your location data is for sale to corporations as well as government agencies (bypassing the need for court orders and warrants), and I'll cover a couple interesting Android security stories from the recent DEFCON and BlackHat security conferences.
Further Info:
Scan suspicious files online: www.virustotal.com
Can Facebook or Google really promise to keep your data private in this era of mass surveillance by the likes of the NSA and GCHQ? Max Schrems doesn't think so, and he's convinced the EU Court of Justice of the same thing. There's no way to protect user data when intelligence agencies are hoovering up all our communications and storing them on massive server farms forever. In part 2 of my chat with EFF's Danny O'Brien, we'll talk about the two Shrems cases in the EU and what the recent ruling against Privacy Shield will mean for all of us.
Danny O'Brien has been an activist for online free speech and privacy for over 20 years. In his home country of the UK, he fought against repressive anti-encryption law, and helped found the Open Rights Group, Britain's own digital rights organization. He was EFF's activist from 2005 to 2007, its international outreach coordinator from 2007-2009, and international director from 2013-2019. He now supervises EFF's medium and long-term strategy, with an eye to maintaining the organization's global impact and reputation.
Further Info:
EU Court Again Rules That NSA Spying Makes U.S. Companies Inadequate for Privacy: https://www.eff.org/deeplinks/2020/07/eu-court-again-rules-nsa-spying-makes-us-companies-inadequate-privacyNone of Your Business: https://noyb.eu/en Donate to EFF: https://supporters.eff.org/donate/join-eff-today
What good are privacy laws when we all know that intelligence agencies don't play by the rules? How can any company promise to keep our data safe when we know that agencies like the NSA and GCHQ are hoovering it all up? That's the essential argument behind the Max Schrems cases at the European Court of Justice. And the EU court agrees. In part 1 of my interview with EFF's Danny O'Brien, we'll talk about how we got here and how the parallel development of data mining and mass surveillance led us to these (successful) court challenges.
Danny O'Brien has been an activist for online free speech and privacy for over 20 years. In his home country of the UK, he fought against repressive anti-encryption law, and helped found the Open Rights Group, Britain's own digital rights organization. He was EFF's activist from 2005 to 2007, its international outreach coordinator from 2007-2009, and international director from 2013-2019. He now supervises EFF's medium and long-term strategy, with an eye to maintaining the organization's global impact and reputation.
Further Info:
EU Court Again Rules That NSA Spying Makes U.S. Companies Inadequate for Privacy: https://www.eff.org/deeplinks/2020/07/eu-court-again-rules-nsa-spying-makes-us-companies-inadequate-privacyDonate to EFF: https://supporters.eff.org/donate/join-eff-today
When most people think of protecting their computers, they think of antivirus software. Viruses are a real problem, of course, but how well do antivirus (AV) apps protect you? And are there any downsides to using AV software? Turns out there are plenty - so many that the cons probably outweigh the pros for most people, on Apple Mac or on Windows PC. Don't believe me? Listen to this show and then decide.
In other news: Google is finally bringing its Google One storage app to iOS, but don't use it; Netgear has declared that at least 45 of their highly vulnerably routers will never be fixed; and if you've purchased anything from Amazon, you have a public profile - and you should review what others can see about you.
Further Info:
Cryptomator: https://cryptomator.org/Sync.com secure cloud storageNetgear routers you should get rid of: https://www.tomsguide.com/news/netgear-routers-no-fixesMy "pros & cons of AV" article: https://firewallsdontstopdragons.com/the-pros-and-cons-of-anti-virus-software/
Last week, Twitter was massively hacked - apparently just to launch a Bitcoin scam (though that story is still developing). Famous people's accounts were taken over, including Joe Biden, Barack Obama, Bill Gates, Elon Musk and several popular brand name accounts. (President Trump's account was not taken over due to enhanced security measures.) But beyond the details of the hack, we need to look at the bigger picture and what this hack should be telling us about these totally unregulated social media giants with zero accountability. We'll dig into that in today's show.
In other news: account credential dumps have significantly increased on the dark web, including over 140 million MGM Resort creds; Windows 10 suffers another maddening bug, but there's a workaround; Signal has stirred up a lot of controversy with a recent change; a massive wifi router study revealed widespread security problems; and I'll go over some of the cool new privacy features coming in iOS 14 and macOS Big Sur.
Further Info:
Windows 10 "No Internet Connection" workaround: https://lifehacker.com/how-to-fix-windows-10s-latest-no-internet-connection-bu-1844458254 Fraunhofer Institute router security report: https://github.com/fkie-cad/embedded-evaluation-corpus/blob/master/2020/FKIE-HRS-2020.md
In the second part of my interview with Renee Dudley from ProPublica, we delve into the cyber insurance and ransomware incident response industries, including how some of these companies are being less than forthcoming about their services. In fact, it appears that several "incident response" companies are simply paying the ransom and then charging companies a fee on top of that. We'll talk about how cyber insurance works and how to decide whether or not it's for you. And Renee will also give us some tips on choosing an incident response firm and what red flags to watch out for.
Renee Dudley is a tech reporter at ProPublica. Before joining ProPublica in 2018, she was a member of the enterprise team at Reuters, where she reported extensively on issues with college-entrance exams. Before joining Reuters in 2015, she worked as a reporter in New York for Bloomberg News and in South Carolina for The (Charleston) Post and Courier and The (Hilton Head) Island Packet. At Bloomberg, she uncovered questionable accounting and unauthorized sales practices at Walmart Inc. In Charleston, her reporting led to the indictment and resignation of South Carolina’s most powerful politician. She received the Society of Professional Journalists’ Pulliam Award in 2010 for her work upholding First Amendment rights while reporting for The Island Packet.
Further Information:
ProPublica on ransomware: https://www.propublica.org/article/the-extortion-economy-how-insurance-companies-are-fueling-a-rise-in-ransomware-attacksMike Gillespie to the rescue: https://www.propublica.org/article/the-ransomware-superhero-of-normal-illinoisID Ransomware: https://id-ransomware.malwarehunterteam.com/No More Ransom: https://www.nomoreransom.org/Bleeping Computer: https://www.bleepingcomputer.com/
Unless you've been living under a rock, you know that ransomware is one of the most common and most lucrative cybersecurity rackets today. But despite all the press, ransomware is massively under-reported because companies don't want bad press. And in most cases, unless it can be proven that data was actually stolen, companies are under no legal obligation to inform the data subjects (you) of these hacks. In part one of my interview with Renee Dudley from ProPublica, we'll discuss the current state of the ransomware problem and the emergence of cyber insurance and incident response companies to deal with the threat and recover from attacks. And we'll also see that not all players are above board about what they do.
Renee Dudley is a tech reporter at ProPublica. Before joining ProPublica in 2018, she was a member of the enterprise team at Reuters, where she reported extensively on issues with college-entrance exams. Before joining Reuters in 2015, she worked as a reporter in New York for Bloomberg News and in South Carolina for The (Charleston) Post and Courier and The (Hilton Head) Island Packet. At Bloomberg, she uncovered questionable accounting and unauthorized sales practices at Walmart Inc. In Charleston, her reporting led to the indictment and resignation of South Carolina’s most powerful politician. She received the Society of Professional Journalists’ Pulliam Award in 2010 for her work upholding First Amendment rights while reporting for The Island Packet.
Further Information:
ProPublica on ransomware: https://www.propublica.org/article/the-extortion-economy-how-insurance-companies-are-fueling-a-rise-in-ransomware-attacksMike Gillespie to the rescue: https://www.propublica.org/article/the-ransomware-superhero-of-normal-illinoisID Ransomware: https://id-ransomware.malwarehunterteam.com/No More Ransom: https://www.nomoreransom.org/Bleeping Computer: https://www.bleepingcomputer.com/
TikTok is the hot new social media service (Snapchat and Instragram are so last year), particularly in Asian countries like India. But India just banned this and several other apps from China over privacy concerns - and I have a feeling they won't be the last. The TikTok app was just revealed to be copying the user's clipboard contents every few seconds for some completely unknown reason (and TikTok's explanation was lame). While it has supposedly "fixed" this, another researcher claims to have reverse engineered the TikTok app and found that it's pulling all sorts of other user data - enough to put Facebook and Google to shame. Short answer? Delete this app.
And there's a ton of other news this week: Zoom changes course on end-to-end encryption for free users, with a couple catches; I have more info on the recent Netgear router vulnerability affecting dozens of their products; Adobe Flash will be erased from the Earth by year's end; Oracle's BlueKai data mining subsidiary left a ton of personal data exposed with no password; Sen. Sherrod Brown (D-Ohio) has a wonderful privacy proposal that will probably never pass Congress; new Mac malware uses a trick to get around Apple's app security; Microsoft shoves its new Edge browser down its users' virtual throats; and Comcast is the first ISP to qualify for Mozilla's Trusted Recursive Resolver program (DNS over HTTPS) and might switch out Cloudflare without asking you.
Further Info:
Netgear router fix info:https://bit.ly/netgear-fixhttps://bit.ly/netgear-passwords Humble Bundle - LAST CHANCE! https://www.humblebundle.com/books/protect-your-stuff-apress-books
In the second half of my interview with Eduard Goodman and Adam Levin from Cyberscout, we discuss the privacy aspects of our new work- and learn-from-home reality. How much privacy should you really expect? What are your legal rights? What should we beware of when using a single device for both work and personal things? How much should companies be willing to spend to make sure their employees and intellectual property are well protected while working from home? How do we avoid, as a democracy, giving up too much privacy with hopes it will make us more secure? Will we ever get that privacy back? We discuss all of this and much more!
Eduard Goodman is the Chief Legal Counsel and Global Privacy Officer for CyberScout, a global leader in identity theft resolution, data defense and employee benefits services. An internationally trained attorney and data protection expert, Goodman has more than twenty years of experience in global privacy law and cybersecurity.
Adam Levin is a consumer advocate with more than 30 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. He is also the author of the book Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves.
Further Info:
CyberScout: https://www.cyberscout.com/enMy Apress Humble Bundle: https://www.humblebundle.com/books/protect-your-stuff-apress-booksPatreon: https://www.patreon.com/FirewallsDontStopDragons
Today I speak with not one but two experts on security and privacy to get their insights, stories and tips on staying safe from scammers and hackers in our new COVID19 pandemic reality. These guys have dealing with cyber incidents every day and bring some unique perspectives. In some ways, it's same stuff, different day; but the pandemic, economy woes and general civil unrest have given the bad guys some fertile material for working their craft.
Eduard Goodman is the Chief Legal Counsel and Global Privacy Officer for CyberScout, a global leader in identity theft resolution, data defense and employee benefits services. An internationally trained attorney and data protection expert, Goodman has more than twenty years of experience in global privacy law and cybersecurity.
Adam Levin is a consumer advocate with more than 30 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. He is also the author of the book Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves.
Further Info:
CyberScout: https://www.cyberscout.com/enMy Apress Humble Bundle: https://www.humblebundle.com/books/protect-your-stuff-apress-booksPatreon: https://www.patreon.com/FirewallsDontStopDragons
With the US general election just over 20 weeks away and no vaccine in sight for the coronavirus, it's time to think very seriously about how you're going to vote. Even if you think you want to vote in person this November, you should have a backup plan: voting by mail. This means that you'll need to register for an absentee ballot - and the sooner you do so, the better prepared your state and county will be. I'll tell you everything you need to know to get your absentee ballot.
In other news: Microsoft, IBM and Amazon have taken very welcome steps to curbing the use of facial recognition for law enforcement purposes; the FBI is once again warning us about banking hacks, this time related to mobile apps; the Brave browser was busted "accidentally" trying to cash in on your browsing; Google is being sued for $5B over its Chrome browser tracking while in incognito mode; and Zoom is rolling out full end-to-end encryption on its video conferencing solution... if you're willing to pay.
Further Info:
Get your absentee ballot: https://www.vote.org/Support election reform: https://www.verifiedvoting.org/Support fair and open voting: https://fairfight.com/ Vote at home: https://www.voteathome.org/
We've established that we have a high speed internet access problem - now what can we do about it? In part 2 of my interview with the EFF's Ernesto Falcon, we'll talk about how broadband fiber-based internet is a critical piece of national infrastructure, not unlike the highway system. It enables and supports industry and innovation, and ubiquitous access would greatly increase our ability to learn and work remotely. We talk about the politics and economics behind all of this, including some interesting solutions involving both the government and private corporations.
Ernesto Falcon is Senior Legislative Counsel at the Electronic Frontier Foundation with a primary focus on intellectual property, open Internet issues, broadband access, and competition policy. He represents EFF’s advocacy, on behalf of its members and all consumers, for a free and open Internet before state legislatures and Congress. Ernesto’s work includes pushing the state of California to pass the strongest net neutrality law in the country in response to federal repeal efforts, as well as leading EFF's research and advocacy to promote universally available, affordable, and competitive fiber broadband networks.
Further Info:
Electronic Frontier Foundation: https://www.eff.org/Why cable companies hate California's SB1130 bill: https://www.eff.org/deeplinks/2020/05/why-cable-companies-oppose-californias-universal-fiber-effort-sb-1130
The COVID-19 era has exposed several weaknesses in American infrastructure and exacerbated the gulf between the haves and the have-nots. Perhaps nowhere is this more evident than the digital divide: access to high speed internet. While much of the country was able to work and learn from home, for too many communities this was simply not an option due to poor or non-existent broadband access. In today's show, Ernesto Omar Falcon from the EFF explains the political and economic reasons we got into this mess.
Ernesto Falcon is Senior Legislative Counsel at the Electronic Frontier Foundation with a primary focus on intellectual property, open Internet issues, broadband access, and competition policy. He represents EFF’s advocacy, on behalf of its members and all consumers, for a free and open Internet before state legislatures and Congress. Ernesto’s work includes pushing the state of California to pass the strongest net neutrality law in the country in response to federal repeal efforts, as well as leading EFF's research and advocacy to promote universally available, affordable, and competitive fiber broadband networks.
Further Info:
Electronic Frontier Foundation: https://www.eff.org/Why cable companies hate California's SB1130 bill: https://www.eff.org/deeplinks/2020/05/why-cable-companies-oppose-californias-universal-fiber-effort-sb-1130
The FBI is once again trash-talking Apple for not helping them in their investigation of a terrorist - this time, the alleged perpetrator of the Pensacola shooting. However, like the San Bernardino shooting a few years ago, Apple has actually done everything in its power to aid law enforcement. The issue is the "in its power" part. The FBI and DOJ would prefer that Apple (and therefore they) would have more power to unlock and decrypt iOS devices. We'll discuss this and a recent ruling against the FBI in another phone-related case.
In other news: the Senate narrowly defeated a bill amendment that would protect your web history from government surveillance; 83% of users store their passwords in their heads (meaning their passwords suck); Firefox will soon tell you when sign-up forms are truncating your long passwords; Microsoft warns of a nasty new COVID-19-related phishing scheme that can take over your entire computer; and secure messaging app Signal has added a new security PIN to protect your account and make transferring to a new device easier.
Intel created the Thunderbolt protocol to give us blazingly fast data transfer and other interesting features. Thunderbolt usually comes with the newer USB-C ports, common on laptops, especially Macbooks. Unfortunately, researchers have found a major flaw affecting all computers that will allow bad guys to gain access to your computer in just a few minutes with a few hundred dollars of common equipment. Most computers built in 2019 and later are capable of blocking this attack, but not many have implemented it. Apple computers are safe, unless they're in Bootcamp mode running Windows or Linux. I'll go over the details of this "evil maid" attack and provide several tips for securing your computers.
In other news: Mozilla is adding a couple cool new privacy features to Firefox; Microsoft is rolling out some security and privacy in its coming May release; Google Authenticator finally provides a way to transfer accounts (sorta); Clearview AI is quickly backpedaling is data collection on Illinois residents; and Bruce Schneier explains why the Apple/Google contact tracing app will be basically useless.
Further Info:
My Duke OLLI lecture on COVID19 scams and privacy: https://duke.zoom.us/rec/share/-pFnFpPwz31LZ9Lg72CPX58rIdTaX6a82ncZ_qAKnn7ycTkgCcknURAXsgLmOR0
In part two of my interview with Malwarebyte's David Ruiz, he tells us how to avoid the scams we discussed last week. And then we move on to discuss the potentially serious privacy issues that could come from the emerging surveillance regimes, designed to help us curb the spread of the coronavirus.
David Ruiz is a content writer for Malwarebytes, covering online privacy, cybersecurity, and the laws - and proposed legislation - that regulate how data is stored, shared and accessed. He previously worked for Electronic Frontier Foundation, where he wrote and analyzed policy about NSA surveillance, encryption, and cross-border data transfer.
Further Info:
Malwarebytes blog: https://blog.malwarebytes.com/author/davidruiz/Malwarebytes antivirus: https://www.malwarebytes.com/for-home/products/Malwarebytes "Lock and Code" podcast: https://podcasts.apple.com/us/podcast/lock-and-code/id1500049667
In times of great fear and anxiety, we need to be especially vigilant against snail oil salesmen. Never letting a good crisis go to waste, the bad guys are capitalizing on the chaos to lure us into downloading malware and buying fraudulent (or even harmful) advice and products. In part one of my interview with Malwarebyte's David Ruiz, we talk about the explosion of COVID-19-related phishing scams and malware campaigns, including tips on how to avoid being a victim.
David Ruiz is a content writer for Malwarebytes, covering online privacy, cybersecurity, and the laws - and proposed legislation - that regulate how data is stored, shared and accessed. He previously worked for Electronic Frontier Foundation, where he wrote and analyzed policy about NSA surveillance, encryption, and cross-border data transfer.
Further Info:
Malwarebytes blog: https://blog.malwarebytes.com/author/davidruiz/Malwarebytes antivirus: https://www.malwarebytes.com/for-home/products/
Every time there's a data breach at a company or service where you do business, there's a chance that the bad guys will reverse engineer your password. And once they do that, they will almost surely try to use that email and password combination to log into dozens of other sites - a hacking technique called credential stuffing. And why do they do this? Because they know most people reuse the same password over and over again. Troy Hunt has created a free service called "Have I Been Pwned" that collects information from all of these breaches so that we can find out whether our email address has been included in any of these hacks.
I originally interviewed Troy over a year ago on the topic of database breaches and how to protect yourself against them, and sadly this is just as relevant today as it was then. So I brought this back as an encore performance!
Troy Hunt is an Australian Microsoft Regional Director and Microsoft Most Valuable Professional for Developer Security. You'll regularly find Troy in the press talking about security and even testifying before US Congress on the impact of data breaches.
Further Info
HaveIBeenPwned.comEthics of running a data breach search service: https://www.troyhunt.com/the-ethics-of-running-a-data-breach-search-service/Authentication evolved: https://www.troyhunt.com/passwords-evolved-authentication-guidance-for-the-modern-era/
The bad guys are having a field day with all the coronavirus hubbub, using our fears and anxieties to trick us into clicking bad links, downloading infected files, or installing malware. While the topic is new, the techniques are the same: phishing. Using cleverly disguised emails and text messages, bad guys trick us into giving up credit card and social security numbers, login credentials, and other sensitive information. In today's show, I'll give you several ways to spot these scams.
In other news: a new massive data breach contains records on 1.2 billion people; Microsoft released a new version of Windows Defender which is broken for some people; there's been an attack on some Linksys routers; and as if regular ransomware wasn't bad enough, the bad guys are now using a new "double extortion" tactic that really puts you in a bind.
Further Info:
Flatten the Curve Summit: https://flattenthecurve.tech/
As health services and society in general struggle to cope with the coronavirus pandemic, people are desperately seeking new and inventive ways to curb the spread of the disease. A tried and true tool of epidemiologists is contact tracing: interviewing infected subjects in order to create lists of people they've had contact with in recent days and weeks. But people's memories are notoriously sketchy and they may not even know all the names, let alone contact information. Google and Apple have united to propose a technical solution. Android phones and iPhones will silently record anonymous identifiers of every other device they come near, in hopes of eventually notifying those device owners if a person later tests positive for COVID-19. But doing this in a way that preserves privacy and resists mass surveillance is difficult. I'll walk through the technical and social implications of their proposal.
In other news: Zoom is working hard to fix their privacy and security issues (and repair their reputation); bad guys are capitalizing on Zoom's popularity to trick users into installing malware along with the app; smart locks can actually be pretty stupid (and insecure); and now that we're all working from home, it's a good time to review standard security practices to keep your company's data and devices secure. (And by the way, this is good practice for your personal stuff, too.)
Further Info:
Remote working security checklist: https://doist.com/blog/security-checklist-remote-workers/ VeraCrypt hard drive encryption app: https://www.veracrypt.fr/
During our global COVID-19 self-quarantining, video conferencing usage has exploded. I've tried to find hard statistics, but they're rising so fast that anything I post now will be stale tomorrow. That said, I've seen usage growth figures as high as 400%. And since we're all staying home now (right?), video chatting is a great way to get some some social time with friends and family. But many of the most popular video chat services are lacking in security, privacy, or both (I'm looking at you, Zoom). I'll give you a handful of good options that are all end-to-end encrypted.
In other news: over 12,000 Android apps were found to have some sort of backdoor; Cloudflare introduces 1.1.1.1 for Families; Marriott announces yet another major data breach; Google is using its vast hoard of location data to track our social distancing success (or failure); EFF issues some timely warnings about guarding our civil liberties when responding to this crisis; and the FBI is warning us to watch out for coronavirus-related scams.
Further Info:
Zoom alternatives and online gaming: https://firewallsdontstopdragons.com/secure-private-zoom-alternatives/Flatten the Curve Summit: https://flattenthecurve.tech/1.1.1.1 for Families: https://blog.cloudflare.com/introducing-1-1-1-1-for-families/
Wouldn't it be nice if privacy wasn't an afterthought? What if user privacy was built in from the get go? What if the entire design assumed that you didn't want anyone selling your data - and respected those wishes? That's the world of Privacy by Design - a concept pioneered in the mid-1990's by Dr. Ann Cavoukian. This may seem like an unattainable Utopian future, but Ann's infectious optimism may just convince you otherwise. Adding privacy doesn't mean sacrificing security or functionality, if done properly. Today we discuss the concepts of Privacy by Design and how we can achieve it.
Dr. Ann Cavoukian is recognized as one of the world’s leading privacy experts. Dr. Cavoukian served an unprecedented three terms as the Information & Privacy Commissioner of Ontario, Canada. There she created Privacy by Design, a framework that seeks to proactively embed privacy into the design specifications of information technologies. In 2010, International Privacy Regulators unanimously passed a Resolution recognizing Privacy by Design as an International Standard. Since then, PbD has been translated into 40 languages! In 2018, PbD was included in a sweeping new law in the EU: the General Data Protection Regulation. Dr. Cavoukian is now the Executive Director of the Global Privacy & Security by Design Centre.
Further Info:
Global Privacy & Security: https://gpsbydesigncentre.com/about-us/Fight the EARN IT Act: https://act.eff.org/action/protect-our-speech-and-security-online-reject-the-graham-blumenthal-bill
Never let a good crisis go to waste. Though normally applied to politics, it can be equally applied to opportunistic cyber criminals. With the world transfixed by and anxious about this nasty virus, bad guys are seizing on our fears to make a quick buck. From ransomware-laden virus tracking apps to actually threatening to infect families directly with the actual virus, COVID-19 is becoming a gold mine for unscrupulous hackers. We need to be extra vigilant and warn our loved ones to do the same.
In other news... connected cars are tapping into your driving data to make more money; a $3 robot lawyer can help you exercises your CCPA rights; the Brave browser will be implementing some novel fingerprinting protections; Firefox had created a privacy container for Facebook; and not to miss a good crisis, the US government is looking to weaken our civil liberties in the name of virus tracking.
In part 1 of this interview, Hayley Tsukayama walked us through the details of the new California Consumer Privacy Act (CCPA). In part 2, we discuss how this law will affect many of us who are not California residents and how it's influencing potential legislation in other states and even at the federal level. We also discuss how CCPA can synergize with other state laws and be used as a tool for journalists to expose data brokers to the light of scrutiny.
Hayley Tsukayama is a legislative activist for the Electronic Frontier Foundation, focusing on state legislation. Prior to joining EFF, she spent nearly eight years as a consumer technology reporter at The Washington Post writing stories on the industry's largest companies. Hayley has an MA in journalism from the University of Missouri and a BA in history from Vassar College. She was a 2010 recipient of the White House Correspondents' Association scholarship.
Further Info
Donate to the EFF: https://supporters.eff.org/donate/ Robot Lawyer to sue data hoarders: https://fortune.com/2020/03/05/delete-location-data-privacy-personal-information-donotpay/ My book is on sale for $18: https://www.apress.com/us/book/9781484238516
On January 1st, 2020, the California Consumer Privacy Act (CCPA) went into effect. While not perfect, the CCPA is a landmark piece of legislation for the United States, even though legally it only protect California residents. I will dig into the details of this bill - both the good and the bad - in part one of my delightful interview with Hayley Tsukayama from the EFF.
Hayley Tsukayama is a legislative activist for the Electronic Frontier Foundation, focusing on state legislation. Prior to joining EFF, she spent nearly eight years as a consumer technology reporter at The Washington Post writing stories on the industry's largest companies. Hayley has an MA in journalism from the University of Missouri and a BA in history from Vassar College. She was a 2010 recipient of the White House Correspondents' Association scholarship.
Further Info
Donate to the EFF: https://supporters.eff.org/donate/ Robot Lawyer to sue data hoarders: https://fortune.com/2020/03/05/delete-location-data-privacy-personal-information-donotpay/
A few weeks ago, the New York Times published a bombshell article about a small startup called Clearview AI who was using a massive database of three billion faces scraped from several social media sites to offer a creepy facial recognition app. Just one snapshot of some stranger's face could immediately identify that person - not just name, but potential location, age, other images, social media pages, and even a list of friends and family. Clearview claimed to only sell this service to law enforcement agencies, mostly in the US and Canada. However, this week Buzzfeed News obtained the company's client list, and it contained several non-law enforcement agencies and dozens of clients outside of North America.
In other news: the latest Windows 10 update has caused many serious problems; leaked documents show how big companies are buying our credit card data; up to a billion WiFi devices have a critical security bug; the FCC says it will fine the four big US cellular carriers $200M for selling your location data; and several news bits about browsers: Brave, Chrome and Firefox.
Further Info:
Public DNS providers supporting DNS over HTTPS: https://github.com/curl/curl/wiki/DNS-over-HTTPS WaPo: The Intelligence Coup of the Century: https://www.washingtonpost.com/graphics/2020/world/national-security/cia-crypto-encryption-machines-espionage/ WNCU Livestream (Sun Mar 8, 6:30pm ET): http://www.wncu.org/listen-live/ The Measure of Everyday Life podcast: https://podcasts.apple.com/us/podcast/the-measure-of-everyday-life/id956844695
it's not cheap or easy to get your iPhone repaired - largely because there's not a lot of real competition in the iPhone repair market. That's no accident. Owners of modern John Deere tractors have really only one option: John Deere. Why? There's no good technical reason. There's really no good legal reason either, but laws like the Digital Millennium Copyright Act (DMCA) and the Computer Fraud and Abuse Act (CFAA) have been abused to give these companies inordinate say over who can perform repairs on their products. In part 2 of my interview with the EFF's Cory Doctorow, we discuss the right to repair and wrap up our overall discussion with possible solutions and action items for the concerned consumer.
Cory Doctorow is a science fiction author, activist, journalist and blogger. He’s the author of several novels including HOMELAND, LITTLE BROTHER and WALKAWAY. He is the former European director of the Electronic Frontier Foundation and co-founded the UK Open Rights Group.
Further Info:
Adversarial Interoperability: https://www.eff.org/deeplinks/2019/10/adversarial-interoperability Donate to EFF: https://supporters.eff.org/donate Electronic Frontier Alliance: https://www.eff.org/fight
Here's a riddle for you: when does something you paid good money not actually belong to you? Answer: when that device is part of the Internet of Things. Why? Because without the express permission and continued support of the company that sold you that device, it becomes a worthless piece of junk. All of our modern "smart" devices are inextricably tied to their cloud-based services and automatic software updates. In part 1 of my interview with Cory Doctorow, we'll talk about how we got into this situation, including several shocking examples.
Cory Doctorow is a science fiction author, activist, journalist and blogger. He’s the author of several novels including HOMELAND, LITTLE BROTHER and WALKAWAY. He is the former European director of the Electronic Frontier Foundation and co-founded the UK Open Rights Group.
Further Info:
Adversarial Interoperability: https://www.eff.org/deeplinks/2019/10/adversarial-interoperability Donate to EFF: https://supporters.eff.org/donate
It's that time of year again: tax time! And that means it's also time for tax scams. I'll give you some tips on how to avoid them, and also help you find the real "Free File" versions of your favorite online tax filing software.
In other news: a German man fooled Google Maps with a wagon full of phones; Hue smart bulbs patched a serious vulnerability; Ring doorbell offers more security and privacy controls; a nasty Android Bluetooth vulnerability found and fixed; extracting data from a computer using screen brightness; and the US government's use of third-party location trackers.
Further Info
ProPublica interview on history of Free File: http://podcast.firewallsdontstopdragons.com/2020/01/13/why-free-file-isnt-free/Free File: https://firewallsdontstopdragons.com/how-to-really-free-file-your-taxes/Avoid tax scams: https://firewallsdontstopdragons.com/preventing-tax-return-fraud/Winston Privacy: https://winstonprivacy.com/
We install antivirus software to protect us, not exploit us. Like a bodyguard, AV programs needs full, unfettered access to everything in order to properly do the job. That requires complete and absolute trust. And probably a non-disclosure agreement. Unfortunately, antivirus software doesn't offer you an NDA promise. Avast, the maker of one of the top five AV software applications, has recently been shown to collect and sell entensive customer information to third parties. While they claim to anonymize the data, it's often easy to re-identify people when correlating this data with other databases. Thanks to some reporting by Vice and PCMag, Avast is shutting down this lucrative side business after a serious backlash. I'll tell you how you can mitigate your exposure to rampant data sharing.
In other news, Sonos angers many long-time customers by declaring an end to supporting older devices; over 250M customer records have been exposed on five public servers with zero protections for about 14 years; Clearview, the company boasting a database of 3B face photos, has come under fire from social media companies and the US Congress; iOS 13 and Android 10 location privacy restrictions have dropped location tracking by nearly 70%; and Mozilla has banned almost 200 plugins for tracking users and violating its malware policies.
Happy Data Privacy Day! My guest today is none other than Bruce Schneier: world renowned security guru and author of several great books, including the Data and Goliath and Click Here to Kill Everybody! Bruce and I discuss the current state of data privacy and what it's going to take to rein in the corporations that are buying and selling our data with abandon.
Bruce Schneier is an internationally renowned security technologist Bruce Schneier has authored over one dozen books--most recently Click Here to Kill Everybody--and hundreds of articles, essays, and academic papers. His influential newsletter Crypto-Gram and his blog Schneier on Security are read by over 250,000 people.
Further Information:
Transcript of my interview with Bruce Schneier: http://podcast.firewallsdontstopdragons.com/wp-content/uploads/2019/01/Ep100-interview.txtData Privacy Day Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/
A small company has amassed over 3 billion online photos from social media and other public sources, creating perhaps the largest facial database in existence - far larger than even the FBI's database. The images are often connected to a person's full name, address, and people they know. The company, called Clearview, has sold access to this database to over 600 law enforcement agencies, allowing them to quickly identify someone from a single picture. While this has allowed them to solve several cases, it also means that we have basically lost the ability to be anonymous in public. There are no rules around this - but there need to be.
In other news, if you haven't updated Windows in the last week, you need to do it right now; same goes for Internet Explorer (though you should really just switch to Firefox); Apple and FBI are once again facing off over iPhone encryption; the vast majority of modern cable modems are vulnerable to a devastating hack; and for at least this year, you shouldn't abbreviate with just "20" on anything important.
Further Info:
NY Times article on Clearview: https://www.nytimes.com/2020/01/18/technology/clearview-privacy-facial-recognition.html Sandboxie: https://www.sandboxie.com/ VirtualBox: https://www.virtualbox.org/ CableHaunt: https://cablehaunt.com/
The IRS already knows what I made, what taxes I've paid, and even what my mortgage interest was last year. Why do I have to fill out tax forms? Turns out there's a very specific reason, and you're not going to like it. At the turn of the century, tax preparers like TurboTax and H&R Block negotiated a deal with the US government that prevented this very thing. In exchange, these tax companies agreed to offer a "Free File" online tax program for most tax filers. But while perhaps honoring the letter of that agreement, they used dark patterns and other subtle psychological tricks to push tax payers into pricey, unnecessary tax applications. Justin Elliott from ProPublica will explain the sordid history of "free" online tax preparation and the cat-and-mouse game companies like Intuit (maker of TurboTax) have been playing with regulators.
Justin Elliott has been a reporter since 2012 with ProPublica, where he has covered money and influence in the Obama and Trump administrations, the American Red Cross and TurboTax maker Intuit. He has produced stories for outlets including The New York Times and National Public Radio, and his work has spurred congressional investigations and changes to federal legislation.
Further Info:
ProPublica Free File stories: https://www.propublica.org/series/the-turbotax-trap IRS official Free FIle site: https://www.irs.gov/filing/free-file-do-your-federal-taxes-for-free How to file for free: https://www.propublica.org/article/how-to-file-state-federal-taxes-free-2020
It's not too late! You can still snag a free upgrade to Windows 10 from Microsoft. If you're still running Windows 7, it's time to avail yourself of this offer. Microsoft is ending support for Windows 7 on January 24, 2020. That means that you will no longer get software updates - in particular, security fixes. The official offer to upgrade to Windows 10 at no cost supposedly ended in July 2016, but Microsoft still offers a legitimate way to upgrade for free. I'll tell you how.
In other news, cybersecurity experts are on the alert following our lethal attack on a senior Iranian military figure, Facebook was again caught using your two-factor authentication mobile number for non-security purposes, there's another massive leak of Facebook user data, Amazon blames its customers for Ring device hacks, a bug in GPS watches allows anyone to track your location, and the new California Consumer Privacy Act (CCPA) goes into effect.
Further Info:
Spread the Word: https://firewallsdontstopdragons.com/spread-the-word/ New Year's Resolutions: https://firewallsdontstopdragons.com/2020-new-years-resolutions/ Upgrade to Win10 for free: https://www.zdnet.com/article/heres-how-you-can-still-get-a-free-windows-10-upgrade/ Protect Your Privacy on Windows 10: https://spreadprivacy.com/windows-10-privacy-tips/
2019 has come and gone, and 2020 is upon us! You know what that means: New Years Resolutions! I've put together a Top Ten list of suggestions that will significantly improve your computer security and online privacy! Some of these are easy and some are going to require some effort... but you have a whole year to do them!
This will also be a great episode to forward to friends and family, introduce them to the show and help build up our "herd immunity".
Further Info
2020 New Years Resolutions blog: https://firewallsdontstopdragons.com/2020-new-year's-resolutions/Give Thanks and Donate: https://firewallsdontstopdragons.com/give-thanks-donate/Key resources: https://firewallsdontstopdragons.com/resources/Terms and Conditions May Apply: http://tacma.net/tacma.php Support me! https://www.patreon.com/FirewallsDontStopDragons
We know that we're tracked, but what remains largely invisible is the massive economy working behind the scenes (or "mirror") to buy, sell, trade and bid on you and your data. I've seen estimates that claim there are up to 4000 data brokers in the US alone. And what's worse is that they are largely unregulated, making the data market a total free-for-all. What can you do to curb this tracking and selling of data? We'll discuss that in the conclusion of my interview with the EFF's Bennett Cyphers.
Bennett Cyphers is a staff technologist on the Tech Projects team at the Electronic Frontier Foundation (EFF). He contributes to a variety of different projects within EFF, most of them tied to privacy and competition. In the past year, he's worked on the tracker-blocking browser extension Privacy Badger, provided technical advice to lawyers and activists, and read and re-read the California Consumer Privacy Act. Before coming to EFF, he was a policy intern at Access Now and earned a Master's degree for work on privacy-preserving machine learning. In his spare time he designs t-shirts for fake punk rock bands.
Further Info
EFF’s Behind the One-Way Mirror: https://www.eff.org/wp/behind-the-one-way-mirror Setting Apple ID to zero (“limit ad tracking”): https://blog.tenjin.com/idfa-sends-all-zeros-on-ios-10-devices-2/Best & Worst Gifts for 2019: https://firewallsdontstopdragons.com/best-worst-gifts-2019/ The Scoring of America: https://www.worldprivacyforum.org/wp-content/uploads/2014/04/WPF_Scoring_of_America_April2014_fs.pdfCorporate Surveillance in Everyday Life: https://crackedlabs.org/en/corporate-surveillance
If you've listened to even a handful of my shows, you are well aware that you're being tracked around the web. But even I was surprised by some of the things I learned in the recent white paper from the Electronic Frontier Foundation entitled "Behind the One-Way Mirror: A Deep Dive Into the Technology of Corporate Surveillance". One of the prime authors of this report, Bennett Cyphers, came on my show to walk us through the myriad and shocking ways that ad tech companies have found to identity us as we surf the web, use our smartphones, and even walk around the real world.
Bennett Cyphers is a staff technologist on the Tech Projects team at the Electronic Frontier Foundation (EFF). He contributes to a variety of different projects within EFF, most of them tied to privacy and competition. In the past year, he's worked on the tracker-blocking browser extension Privacy Badger, provided technical advice to lawyers and activists, and read and re-read the California Consumer Privacy Act. Before coming to EFF, he was a policy intern at Access Now and earned a Master's degree for work on privacy-preserving machine learning. In his spare time he designs t-shirts for fake punk rock bands.
Further Info
EFF’s Behind the One-Way Mirror: https://www.eff.org/wp/behind-the-one-way-mirror Setting Apple ID to zero (“limit ad tracking”): https://blog.tenjin.com/idfa-sends-all-zeros-on-ios-10-devices-2/Best & Worst Gifts for 2019: https://firewallsdontstopdragons.com/best-worst-gifts-2019/
We don't often think about the security and privacy of our regular old "snail mail", but we need to. According to recent activity observed by researchers of the dark web, the bad guys have been regaining interest in identity theft schemes involving physical letters. And in many cases, they can steal your mail without ever opening your mailbox. I'll tell you what you can do to reduce your risk.
In other news, thousands of Disney+ accounts were hacked on the first day, a massive data breach exposed over a billion user records, PayPal is set to acquire shopping platform Honey for $4B, and Avast and AVG browser extensions are spying on Chrome and Firefox users.
It's that time of year again - time to see which popular gifts make my privacy/security Naughty and Nice lists! You want to make sure that when you're giving gifts to your loved ones that you're not also giving gifts to hackers and data miners!
I'll also start to catch you up on several of the news stories from the past few weeks including Google's access to private medical info of tens of millions of people, a researcher finding 146 different Android bugs coming right out of the box, more creepy updates on the Ring Doorbell, and a very welcome federal court ruling about your rights at the US border.
Today in part 2 of my deeply insightful interview with author Kris Shaffer, we discuss how marketers and foreign powers have been capturing our attention and even manipulating our responses. We'll discuss how these techniques were used in the 2016 US presidential election and in other critical voting situations. In many cases, it's sufficient to make people stay home or to sow doubt in the election results. But we'll also discuss whether some of these sames tools and techniques can be used to expose manipulation and tip the scales back in our favor.
Kris Shaffer, PhD (Yale University, 2011), is a data scientist and Senior Computational Disinformation Analyst for Yonder. He co-authored "The Tactics and Tropes of the Internet Research Agency", a report prepared for the United States Senate Select Committee on Intelligence about Russian interference in the 2016 U.S. presidential election. Kris has consulted for multiple U.S. government agencies, non-profits, and universities on matters related to digital disinformation, data ethics, and digital pedagogy. Kris is the author of Data versus Democracy: How Big Data Algorithms Shape Opinions and Alter the Course of History, published July 2019 by Apress.
Further Info
Data versus Democracy: https://www.apress.com/us/book/9781484245392 Kris Shaffer’s website: https://pushpullfork.com Weapons of Math Destruction: https://weaponsofmathdestructionbook.com/ Automating Inequality: https://virginia-eubanks.com/ The Great Hack: https://www.thegreathack.com/ Give Thanks and Donate: https://firewallsdontstopdragons.com/give-thanks-donate/
They say we are in the Information Age and that data is the new oil. But many (including my guest, Kris Shaffer) are saying that was is truly valuable today is attention, not information. Information is so plentiful now that it almost has no value. And because just about everything on the internet is free, we're paying for it with our attention. Marketers have gone to great lengths to study human behavior and they know exactly how to get and keep our attention. Unfortunately, these techniques can also be used to distract us and manipulate us. We'll discuss this and much more in today's interview (part 1 of 2).
Kris Shaffer, PhD (Yale University, 2011), is a data scientist and Senior Computational Disinformation Analyst for Yonder. He co-authored "The Tactics and Tropes of the Internet Research Agency", a report prepared for the United States Senate Select Committee on Intelligence about Russian interference in the 2016 U.S. presidential election. Kris has consulted for multiple U.S. government agencies, non-profits, and universities on matters related to digital disinformation, data ethics, and digital pedagogy. Kris is the author of Data versus Democracy: How Big Data Algorithms Shape Opinions and Alter the Course of History, published July 2019 by Apress.
Further Info
Data versus Democracy: https://www.apress.com/us/book/9781484245392 Kris Shaffer’s website: https://pushpullfork.com Carey’s Best & Worst Gifts for 2019: https://firewallsdontstopdragons.com/best-worst-gifts-2019/
Marketing companies have come up with may clever ways to track our travels around the web, hoping to garner as much information about us as they can. At the same time, privacy-conscious organizations have given us tools to maintain our anonymity by countering these tracking technologies. It's the usual arms race - one that privacy advocates were mostly winning, with VPN's, blocking third party cookies, and privacy-enhancing browser plugins. But now we're faced with the nuclear option: browser fingerprinting. Our browsers cough up dozens of detailed bits of information about us: OS type and version, browser type and version, fonts and plugins installed, monitor resolution, and much more. When taken together, this information creates a fingerprint of our system - one that is often very unique. Preventing this sort of fingerprinting is extremely difficult, making most of the above privacy-enhancing techniques useless. I'll tell you how it works and what you can do to mitigate this.
In other news: Facebook sues NSO Group for using WhatsApp to track people; Google buys FitBit (and all its data); Apple's privacy website is revamped; Microsoft Office is building in much-needed protections against infected files; and researchers figure out how to hack Siri, Alexa and Google Home from afar using lasers.
How are our identities stolen? What happens to our identity information after its been stolen? Once we realize we've been hacked, what can we do to mitigate the damage and recover from the consequences? I'll discuss this and much more with Amyn Gilani from 4iQ - including why you shouldn't be participating in all those fun social media quizzes.
Amyn Gilani leads strategy and product at 4iQ. Previously, he was a Chief Technologist at Booz Allen Hamilton where he provided expertise to federal and commercial clients focusing on incident response, red teaming, threat hunting, and cybersecurity operations engineering. Prior to joining Booz Allen, Amyn was a Vice President in Information Security at Goldman Sachs where he led Red Team Operations and emulated sophisticated attacks against securities trading platforms and payment systems. He began his career serving in the United States Air Force as an intelligence analyst and was on detail at National Security Agency and United States Cyber Command.
Further Info:
4iQ: https://4iq.com/Report identity theft and other resources: https://www.identitytheft.gov/Defending Digital podcast: https://defendingdigital.com/carey-parker-firewalls-dont-stop-dragons/
I've been a Dropbox user for many, many years. But recently, they've gotten really pushy - trying to get me to save all my photos and docs there, integrating with MS Office when I didn't ask it to, and pushing me to upgrade. Now it tells me I need to deactivate all but three devices (I have probably 7-8). I've been looking for a secure and (more importantly) private alternative for a while now, and this pushed me to move. Today I'll compare several cloud sync services and tell you why I picked Sync.com.
In other news: Firefox keeps delivering excellent privacy features and gets top ranks in two new reports; NordVPN was "hacked" but you shouldn't be worried; ISP are lobbying hard to stop DNS over HTTPS in browsers; some clever researchers show how to create legitimate Amazon Echo and Google Home apps that can eavesdrop and phish for passwords; and macOS Catalina arrives with several bugs but also several welcome new security features.
Further Info:
Sign up for Sync.com (referral gets us both 1GB extra); http://www.sync.com/get-started?_sync_refer=bd7921700Switch to Firefox: https://www.mozilla.org/en-US/firefox/new/
You've got ransomware! Now what? If you had the foresight to create safe backups, you can restore your data and move on. Sometimes the hackers screw up and you can actually recover your files directly without paying for the key. But in many cases, you have no real choice but to pay. Cyber insurance can not only help you cover those costs, but insurers can deal directly with the hackers for you and help you with the restoration process.
Joshua Motta is the CEO and Co-founder of Coalition, the fastest-growing provider of cyber insurance for small to medium sized businesses. Having worked at the intersection of the intelligence, finance, and technology sectors at the CIA, Goldman Sachs, and most recently as an early employee and CxO of Cloudflare, he gained valuable insights into the minds of hackers and how — and why — they target specific organizations, as well as how organizations can most effectively manage cyber risk. He founded Coalition to provide a better way to protect small and midsize businesses from breaches and cyber incidents.
Further Info:
Coalition Cyber Insurer: https://www.thecoalition.com/Help with ransomware: https://www.nomoreransom.org/en/index.html
As our world becomes increasingly technical and interconnected, we become more susceptible to technical misfortunes and feel more impact when they inevitably occur. In the first half of my interview with Joshua Motta, we'll talk about the recent rise in ransomware attacks: how people and companies get infected, what we know about the hackers, and why ransomware is such an effective and debilitating attack. Joshua will even explain how ransomware has become a cottage industry unto itself.
Joshua Motta is the CEO and Co-founder of Coalition, the fastest-growing provider of cyber insurance for small to medium sized businesses. Having worked at the intersection of the intelligence, finance, and technology sectors at the CIA, Goldman Sachs, and most recently as an early employee and CxO of Cloudflare, he gained valuable insights into the minds of hackers and how — and why — they target specific organizations, as well as how organizations can most effectively manage cyber risk. He founded Coalition to provide a better way to protect small and midsize businesses from breaches and cyber incidents.
Further Info:
Coalition Cyber Insurer: https://www.thecoalition.com/Help with ransomware: https://www.nomoreransom.org/en/index.html
What happens to all the files, photos, songs and other data on your devices when you resell them or throw them away? Well, if you don't do anything, all that data is still there, waiting for someone else to access it. A recent study showed that 60% of used hard drives still had accessible data on them. Today I'll tell you how to properly wipe the data from your smartphones and computers before you get rid of them.
And there were a lot of other news items this week, including severe bugs in both Apple and Android smartphones, Cloudflare's wonderful new free mobile VPN app called Warp, a bug in WhatsApp that could allow complete takeover of your device, how to pronounce "GIF", the SIMJacker hack that affects well over a billion phones, and yet around call by the government to "backdoor" our encrypted communications.
Further Info:
Hope to Wipe Your Data: https://firewallsdontstopdragons.com/wipe-data-before-dumping-devices/Windows 10 privacy settings: https://spreadprivacy.com/windows-10-privacy-tips/
So what happens when your face print (or any biometric info) is stolen from a server? You can't change your face like you can change your password. Is there anything you can do to avoid your face being scanned or prevent your face from being recognized? What can you do right now to halt the use of facial recognition technologies while we sort out all the social implications? The answers to these questions and more in the second half of my interview with EPIC's Jeramie Scott!
Jeramie Scott is Senior Counsel at EPIC and Director of the EPIC Domestic Surveillance Project. His work focuses on the privacy issues implicated by domestic surveillance programs with a particular focus on drones, AI, biometrics, and social media monitoring. Mr. Scott regularly litigates open government cases and cases arising under the Administrative Procedure Act. He is also a co-editor of "Privacy in the Modern Age: The Search for Solutions” and the author of “Social Media and Government Surveillance: The Case for Better Privacy Protections of Our Newest Public Space.” Prior to joining EPIC, Mr. Scott graduated from the New York University Law School where he was a clinic intern at the Brennan Center's Liberty and National Security Program. His work at the Brennan Center focused on civil liberty issues arising from local law enforcement surveillance.
Further Info:
Electronic Privacy Information Center (EPIC): https://epic.orgPrivacy in the Modern Age: The Search for Solutions: https://www.amazon.com/Privacy-Modern-Age-Search-Solutions/dp/1620971070Glenn Greenwald's TED Talk on Privacy: https://www.ted.com/talks/glenn_greenwald_why_privacy_mattersPetition to ban the use of FRT: https://www.banfacialrecognition.com/
Use of facial recognition technology (FRT) is exploding around the globe. While touted as a convenience for checking in for a flight or crossing the border, the opportunities for abuse are staggering. People act differently when they feel they're being watched. There's a reason we have sayings like "dance like no one is watching". But US agencies like TSA and CBP have gained access to treasure troves of faces from DMV and passport databases, without ever asking our permission, and they're rolling out FRT across the nation. There are no laws or regulations on the use of this technology, and little thought being given to how constant, mass surveillance will affect our democratic and human rights. In the first part of my two-part interview with Jeremie Scott (EPIC), we'll discuss how we got here.
Jeramie Scott is Senior Counsel at EPIC and Director of the EPIC Domestic Surveillance Project. His work focuses on the privacy issues implicated by domestic surveillance programs with a particular focus on drones, AI, biometrics, and social media monitoring. Mr. Scott regularly litigates open government cases and cases arising under the Administrative Procedure Act. He is also a co-editor of "Privacy in the Modern Age: The Search for Solutions” and the author of “Social Media and Government Surveillance: The Case for Better Privacy Protections of Our Newest Public Space.” Prior to joining EPIC, Mr. Scott graduated from the New York University Law School where he was a clinic intern at the Brennan Center's Liberty and National Security Program. His work at the Brennan Center focused on civil liberty issues arising from local law enforcement surveillance.
Further Info:
Electronic Privacy Information Center (EPIC): https://epic.orgPrivacy in the Modern Age: The Search for Solutions: https://www.amazon.com/Privacy-Modern-Age-Search-Solutions/dp/1620971070
No doubt sensing the impending US privacy regulations, Google has released a plan to "enhance" user privacy... by finding different ways to track you. Instead of relying on cookies and fingerprinting, Google proposes that we just come out in the open and formalize tracking technologies. While that could give users more transparency and a modicum of control, the bottom line is that Google is really just trying desperately to save its business model (ads based on tracking). While there are actually some good ideas in their proposal, many of the technologies they're putting forward could be even worse for your privacy than the current schemes. Today I'll walk through the EFF's excellent analysis of these propositions and give my own take.
Further Info:
EFF: Don't Play in Google's Privacy Sandbox: https://www.eff.org/deeplinks/2019/08/dont-play-googles-privacy-sandbox-1 EFF's Panopticlick tool: https://panopticlick.eff.org/
Today we speak with EFF's Matthew Guariglia about the creepy new partnership between Amazon's Ring Doorbell division and local law enforcement. Recent disclosures reveal that Amazon has partnered with over 400 police agencies to market their product and share surveillance footage. While these footage requests can supposedly be refused by the Ring owners, there appear to be circumstances where Amazon will provide footage without consent. The marketing of Ring has changed from convenience to an automated neighborhood watch program, where the police have been coached in how to drum up interest in the product and to assuage fears over sharing their private footage.
Matthew Guariglia is a policy analyst for surveillance and privacy at the Electronic Frontier Foundation. He is also a visiting research scholar at the University of California-Berkeley and holds a PhD in U.S. history. His work focuses on the relationship between race, immigration, policing and government surveillance in the past and present. You can find his writing in the Washington Post, VICE, and the Freedom of information-centered outlet MuckRock. To find his writing you can follow him on Twitter at @mguariglia or visit MatthewGuariglia.com.
Further Info
EFF's Street Level Surveillance : https://www.eff.org/issues/street-level-surveillance Protecting Civic Spaces: https://privacyinternational.org/long-read/2852/protecting-civic-spaces
Evaluating VPN providers on privacy is really, really hard. Even if you read all their privacy claims, how do you know if they're telling the truth? I've read many reviews on many sites, but the recent review from The Wirecutter is the most comprehensive and helpful review I've ever come across. It focused first and foremost on privacy - something many other reviews fail to do, instead focusing on more readily verifiable aspects like speed, number of servers, and cost. In recent years, some top VPN providers have turned to third party, independent auditors to verify their privacy claims and published the results. This is what allows for a truly privacy-focused review. Many top contenders like ExpressVPN and NordVPN didn't make the cut due to lack of transparency compared to the providers that topped Wirecutter's list. Who won? Listen to today's show to find out.
In other news, iPhones have been vulnerable to some nasty website hacks for several years, Facebook finally releases a tool to manage your "off-Facebook" data (though it fails), Kaspersky antivirus products have been marking all their users with a unique, trackable ID, and Kazakhstan tries to implement mass surveillance of its citizens and ends up being foiled (thankfully) by the three major browser makers.
Further Info:
Choosing a VPN Provider: https://firewallsdontstopdragons.com/choosing-a-vpn-service/
In the second half of my interview with EFF's Aaron Mackey, we'll discuss why our federal agencies are not enforcing the laws already on the books that should be protecting your privacy, the real implications of tracking someone's location, other ways in which we're tracked, and how you - as a consumer and citizen - can best defend yourself and advocate for better enforcement and protections.
Aaron Mackey works on free speech, privacy, government surveillance and transparency. Before joining EFF in 2015, Aaron was in Washington, D.C. where he worked on speech, privacy, and freedom of information issues at the Reporters Committee for Freedom of the Press and the Institute for Public Representation at Georgetown Law. Aaron graduated from Berkeley Law in 2012, where he worked for EFF while a student in the Samuelson Law, Technology & Public Policy Clinic. He also holds an LLM from Georgetown Law. Prior to law school, Aaron was a journalist at the Arizona Daily Star in Tucson, Arizona. He received his undergraduate degree in journalism and English from the University of Arizona in 2006, where he met his amazing wife, Ashley. They have two young children.
Further Info:
Donate to EFF: https://supporters.eff.org/donate/Surveillance Self Defense Guide: https://ssd.eff.orgEFF's California lawsuit: https://www.eff.org/cases/geolocation-privacyReport abused location information: geolocation@eff.orgEFF IMSI Catcher white paper: https://www.eff.org/files/2019/07/09/whitepaper_imsicatchers_eff_0.pdf
In January 2019, Motherboard broke a story about how cellular providers were allowing your location information to be sold to several third parties, effectively allowing anyone to buy the real-time location of any cell phone. The Electronic Frontier Foundation has brought a suit against AT&T and others, claiming that this practice broke several state and federal laws. Today in part one of my interview with the EFF's Aaron Mackey, we'll discuss this case and why our location data can expose so much about us.
Aaron Mackey works on free speech, privacy, government surveillance and transparency. Before joining EFF in 2015, Aaron was in Washington, D.C. where he worked on speech, privacy, and freedom of information issues at the Reporters Committee for Freedom of the Press and the Institute for Public Representation at Georgetown Law. Aaron graduated from Berkeley Law in 2012, where he worked for EFF while a student in the Samuelson Law, Technology & Public Policy Clinic. He also holds an LLM from Georgetown Law. Prior to law school, Aaron was a journalist at the Arizona Daily Star in Tucson, Arizona. He received his undergraduate degree in journalism and English from the University of Arizona in 2006, where he met his amazing wife, Ashley. They have two young children.
Further Info:
Donate to EFF: https://supporters.eff.org/donate/Surveillance Self Defense Guide: https://ssd.eff.orgEFF's California lawsuit: https://www.eff.org/cases/geolocation-privacyReport abused location information: geolocation@eff.org
Marketing firms love to tell us that we control our privacy - you simply need to opt out of tracking! Like Dorothy, we've had the power all along. Just click your heels three times and uncheck all those pesky tracking options under Settings... somewhere. Which, statistically speaking, no one ever does. It's the Tyranny of the Default. I'll discuss why it's so hard. (Spoiler alert, it's on purpose.)
Also in today's show: Apple massively expands its bug bounty program; several "air gapped" US elections systems found on the internet; Instagram pulls a Cambridge Analytica move; watch out for fake Equifax settlement sites; another sex hook-up app exposes its user's private information; and it's time to update your Android devices (if you can).
Further Info:
Instagram data leak: https://www.businessinsider.com/startup-hyp3r-saving-instagram-users-stories-tracking-locations-2019-8Election Systems exposed online: https://www.vice.com/en_us/article/3kxzk9/exclusive-critical-us-election-systems-have-been-left-exposed-online-despite-official-denialsOfficial FTC/Equifax settlement site: https://ftc.gov/equifax or https://www.equifaxbreachsettlement.com/Changing WiFi Router (and other IoT) default passwords: https://firewallsdontstopdragons.com/the-s-in-iot-is-for-security/The Cop Out that is Opt Out: https://firewallsdontstopdragons.com
In today's show, I'll discuss the Capitol One hack that affected over 100 million card users and applicants. I'll also cover the latest in the backlash against Apple, Google and Amazon over humans listening in on your private digital assistant voice recordings. The Ring doorbell, whose parent company was bought by Amazon, is quickly becoming a darling of local law enforcement agencies due to its ability to share surveillance footage. School districts are being hit with ransomware and being bilked for hundreds of thousands of dollars. And finally, Netflix has created a sobering documentary about the Facebook and Cambridge Analytics scandal, covering not just the 2016 US elections but also Brexit and many other voter influence campaigns around the globe.
Further Info:
The Great Hack on Netflix: https://www.netflix.com/Title/80117542RSA Conference Blog book review: https://www.rsaconference.com/blogs/bens-book-of-the-month-review-of-firewalls-dont-stop-dragons-a-step-by-step-guide-to-computer-security-for-non-techiesApress Beginner's Book series: https://www.amazon.com/stores/page/7383A13D-EAFC-426B-A944-5B6C1B6886E9
Two years after the massive Equifax breach, the Federal Trade Commission (FTC) has reached a tentative settlement that will purportedly provide some restitution to the 148 million Americans who whose data was leaked. Unfortunately, there are lots of little devils in the details - not to mention the this settlement has yet to be approved. However, you can (and probably should) go ahead and submit your claim. I'll give you all the details and tell you how do it.
In other news, Firefox is coming out with a premium, for-pay version of its privacy-centric web browser, the Pentagon has revealed technology that will allow them to identify people surreptitiously from up to 200 meters away, some of your Apple's Siri recordings are being listened to by real humans, I'll give my take on the FaceApp scandal, and finally, if you have a Logitech wireless keyboard or mouse, you're going to watch to update the software to patch a nasty bug.
Further Info:
Logitech Wireless Keyboard/Mouse security update: https://support.logi.com/hc/en-001/community/posts/360032078393-Logitech-Response-to-Research-FindingsEquifax settlement claim site: https://www.equifaxbreachsettlement.com/Free (official) annual credits reports: https://www.annualcreditreport.com/index.action
In the second half of my interview with Winston Privacy CEO Richard Stokes, we talk about why your data is so valuable to advertisers and what you can do to limit all this tracking. In particular, we'll discuss the Winston box which acts as a sort of force field around your home network, preventing all your "smart" and "internet of things" devices from reporting on your every move.
Richard is the CEO and founder of Winston Privacy. Previously, he was the founder of AdGooroo.com, one of the first digital market research services, and later became the Global Head of Innovation for Kantar Media. He founded Winston Privacy in response to the increasing abuses of privacy taking place in the AdTech industry. Additionally, he's the author of "The Ultimate Guide to Pay-Per-Click Advertising". He has a Computer Science degree from the University of Illinois at Champaign-Urbana and an MBA from Kellogg / Northwestern University.
Further Info:
Winston Privacy: https://winstonprivacy.com/Pre-Order: https://www.indiegogo.com/projects/winston-take-back-control-of-your-online-privacy#/
Protecting your privacy today is hard. It's really hard. It's too hard. Every 'smart' device you own is tattling on you, constantly, to dozens of companies. Your phone, your tablet, your PC, your TV, your streaming box, your DVR, your smart thermostat, your internet-connected medical devices... The list goes on and it gets longer every day. What if you could not only see all these illicit communications but also block them all, in one feel swoop? In part one of my interview with Richard Stokes, this former AdTech CEO will reveal what finally caused him to not only leave the industry but to develop a promising new product that puts users back in control of their privacy.
Richard is the CEO and founder of Winston Privacy. Previously, he was the founder of AdGooroo.com, one of the first digital market research services, and later became the Global Head of Innovation for Kantar Media. He founded Winston Privacy in response to the increasing abuses of privacy taking place in the AdTech industry. Additionally, he's the author of "The Ultimate Guide to Pay-Per-Click Advertising". He has a Computer Science degree from the University of Illinois at Champaign-Urbana and an MBA from Kellogg / Northwestern University.
Further Info:
Winston Privacy: https://winstonprivacy.com/Pre-Order: https://www.indiegogo.com/projects/winston-take-back-control-of-your-online-privacy#/
The US government is once again looking to break or hobble encrypted communications in the name of national security and law enforcement. They claim that we're "going dark" - that modern end-to-end encryption used in apps like Signal and Wickr that protect user privacy are preventing them from keeping us safe and bringing the bad guys to justice. Cryptographers and technology companies have soundly squashed the idea of putting "backdoors" in these systems that supposedly only the "good guys" can go through. But now these agencies have come up with a proposal that neatly sidesteps these issues: they simply want to be added as another "end" to the end-to-end scrambled session. A "ghost" in the chat, and BCC that neither of the original participants are made aware of. But this has several problems, as well.
In other news, FigLeaf has conducted a survey of users about online privacy that shows major shifts in thinking since just before the Cambridge Analytica/Facebook scandal; "pre-saving" new releases on Spotify and other music streaming services is allowing music companies unbelievable access to your personal info; and Mozilla (maker of Firefox) has created a creative tool that let's you fool online advertisers into thinking you're someone completely different.
Why do most VPN apps suck so badly? How do you know which VPN service providers you can trust with your privacy? How is it that our internet service providers know so much about our web surfing habits? Today I explore these questions and more with John Graham-Cumming, the CTO of the internet performance and security company. He will also tell us about a new VPN service coming soon from Cloudflare called Warp that may finally address all of these problems.
John is a computer programmer and author. He studied mathematics and computation at Oxford and stayed for a doctorate in computer security. As a programmer he has worked in Silicon Valley and New York, the UK, Germany, and France. His open source POPFile program won a Jolt Productivity Award in 2004. John is the author of a travel book for scientists published in 2009 called The Geek Atlas.
Further Info:
Cloudflare's 1.1.1.1 App: https://1.1.1.1/Cloudflare's Crypto Week Blog: https://blog.cloudflare.com/welcome-to-crypto-week-2019/ Big Brother 2.0: https://firewallsdontstopdragons.com/big-brother-2-0/
How many of your "smart" devices are smart enough to update their own software? For that matter, how many of them can upgrade at all? It's a good bet that most of them run some flavor of the free and open-source Linux operating system. A nasty bug was just found that affects almost all Linux systems, allowing a simple remote command to bring the system to its knees. There have been other bugs found in Linux and there will be more. If your device's software can't be updated, it will always be vulnerable. I'll go over some basic IoT security tips to mitigate your vulnerability, but in the end, older IoT devices that can't be upgraded should just be pitched.
In other news, Firefox just patched two critical vulnerabilities, Dell's built-in remote assistance software can be remotely hacked, Venmo transactions are still painfully public by default, a Spanish soccer apps turns its fans into unwitting narcs, and Facebook has launched a new cryptocurrency called Libra.
In today's show I have a sobering discussion with the EFF's Eva Galperin about the rise of stalkerware (sometimes called "spouseware"). It's become all too easy for abusive, unscrupulous people to spy on their significant others, tracking their every move, monitoring all their communications. We'll talk about how our phones can be subverted and what measures you can take to prevent it. Eva also provides practical and prudent advice for people who suspect they may be victims of stalkerware.
Eva Galperin is EFF's Director of Cybersecurity. Prior to 2007, when she came to work for EFF, Eva worked in security and IT in Silicon Valley and earned degrees in Political Science and International Relations from SFSU. Her work is primarily focused on providing privacy and security for vulnerable populations around the world. To that end, she has applied the combination of her political science and technical background to everything from organizing EFF's Tor Relay Challenge, to writing privacy and security training materials (including Surveillance Self Defense and the Digital First Aid Kit), and publishing research on malware in Syria, Vietnam, Kazakhstan. When she is not collecting new and exotic malware, she practices aerial circus arts and learning new languages.
Further Info
Surveillance Self Defense: https://ssd.eff.org/EFF Newsletter: https://supporters.eff.org/subscribeDonate to the EFF: https://supporters.eff.org/donate/
Google Chrome is the most popular web browser on the planet by far, used by about two thirds of all web surfers. But Google is an advertising company and ad blockers are a direct threat to their business model. Google is planning to make a highly controversial change to Chrome's plugin framework that would break some popular ad blocking extensions like uBlock Origin, forcing them to use much less effective techniques for blocking ads.
Compare that to Mozilla's Firefox browser, which just announced even more built-in tracking and ad-blocking capabilities - many of which will be on by default. The evidence is clear: Firefox respects your privacy and is giving your more and more tools with which to protect it; Chrome is doing the opposite. It's time to switch to Firefox and ditch Chrome.
In other news, Maine has just signed bill into law which will require internet service providers to get your explicit consent before collecting and selling your web surfing data, Apple has announced several privacy-enhancing features to debut in iOS 13 this fall, and Windows Remote Desktop Services are under attack by hackers.
Further Info:
Patch your old Windows Systems Now! https://firewallsdontstopdragons.com/a-worrisome-windows-worm/Switch from Google Chrome to Firefox: https://firewallsdontstopdragons.com/its-time-switch-to-firefox/Firefox's content blocking settings: https://support.mozilla.org/en-US/kb/content-blocking
Is it possible to hide your tracks online? Is it even worth the effort to try? How do you know which companies, products and services you can trust? Is government regulation the answer? We'll address all of these questions today in part 2 of my interview with David Ruiz. David will give you several great resources for getting more informed and also for getting more involved in the fight for privacy.
David Ruiz is a pro-privacy, pro-security writer for Malwarebytes Labs, where he covers online privacy, legislation, and the interplay between technology and the law.
Further Info
Who Has Your Back? https://www.eff.org/who-has-your-back-2018Privacy Not Included: https://foundation.mozilla.org/en/privacynotincluded/Terms of Service; Didn't Read: https://tosdr.org/Malwarebytes poll on privacy: https://blog.malwarebytes.com/security-world/2019/03/labs-survey-finds-privacy-concerns-distrust-of-social-media-rampant-with-all-age-groups/Top 6 Takeaways from poll: https://blog.malwarebytes.com/101/2019/05/the-top-six-takeaways-for-user-privacy/Help me to help you! https://www.patreon.com/FirewallsDontStopDragons
In January of this year, Malwarebytes (a world-class antivirus software maker) conducted a massive poll on privacy that included 4000 people from 66 different countries. On today's show, I will delve into the key takeaways from this poll and some rather (pleasantly) surprising results. (Tune in next week for part 2.)
David Ruiz is a pro-privacy, pro-security writer for Malwarebytes Labs, where he covers online privacy, legislation, and the interplay between technology and the law.
Further Info
Malwarebytes poll on privacy: https://blog.malwarebytes.com/security-world/2019/03/labs-survey-finds-privacy-concerns-distrust-of-social-media-rampant-with-all-age-groups/Top 6 Takeaways from poll: https://blog.malwarebytes.com/101/2019/05/the-top-six-takeaways-for-user-privacy/
It shouldn't surprise you to learn that Google can read your Gmail. You may even realize that Google is scanning your emails for things like trip itineraries, which allows them to automatically add flights and hotel reservations to your Google Calendar, for example. But you may not realize how much other juicy info is there to be mined, like online purchases. Every email receipt you've received since you've had your Gmail account has almost surely been parsed and indexed. In today's show, I'll tell you how you can view this history and even delete it (painful as it may be).
In other news, an FCC commissioner has released an update on the selling of location data by cell phone providers, San Francisco is poised to become the first major US city to ban the government use of facial recognition systems, and many popular games have been found to give away tons of user data.
Further Info
Check your Google purchase history: https://myaccount.google.com/purchases
Facebook co-founder Chris Hughes makes a heartfelt and cogent argument for breaking up the world's dominant social media company, Facebook. The litmus test for the US Government has focused too much on impact to consumer pricing, which has little to do with "free" services such as Facebook. It's time to also consider social and consumer impact.
In other news, a photo storage service has been caught using your images to train facial recognition systems without proper disclosure, Google has unveiled plans to allow users to auto-delete certain sensitive user data after a specified number of months, and Facebook has cranked up the creepy factor by encouraging you to identity up to nine of your friends that you are secretly crushing on.
Further Info
New York Times Privacy Project: https://www.nytimes.com/2019/05/07/opinion/google-sundar-pichai-privacy.htmlIt's Time to Break Up Facebook: https://www.nytimes.com/2019/05/09/opinion/sunday/chris-hughes-facebook-zuckerberg.htmlFirewalls Don't Stop Dragons links & errata: https://github.com/Apress/firewalls-dont-stop-dragons
A disturbing study in the JAMA Network Open journal showed that almost all of 36 mental health apps they downloaded were sharing your data to some extent - many without proper or even any disclosure. Many shared basic data with Facebook and Google, and a few shared very sensitive information like health diaries and self reports of substance abuse. I'll give you some tips on how you can protect yourself.
In other news, Firefox plugins were all shut off over the weekend due to a Mozilla certificate expiring, bad guys are using Google ads to trick you into paying money to fake customer support sites, data from 80M US households was found lying around on Microsoft servers, and Princeton has a cool new app that will tell you which of your IoT devices may be snitching on you.
Further Info
Terms of Service; Didn't Read: https://tosdr.org/ Princeton IoT Inspector: https://iot-inspector.princeton.edu/Spring Cleaning for you apps: https://firewallsdontstopdragons.com/close-security-holes/
Facebook has once again gone too far and, when caught, asked for forgiveness and promised to change. First it was revealed that Facebook has been requesting since May 2016 that new users provide their email account passwords in order to verify their email addresses - without giving any obvious way to opt out. When caught, they said they would stop doing this. However, it was then revealed that Facebook "unintentionally" hoovered up the email contact lists of 1.5 million Facebook users that gave them their email passwords! I'll tell you how you can review and delete any contacts you've shared (intentionally or otherwise) with Facebook... as well as how to just delete Facebook!
In other news, Microsoft has dropped the requirement to periodically change your password in Windows 10, another IoT vulnerability has been found that affects millions of devices, I have an update on the supposed Amazon employee Echo spying, and finally I'll explain why browser makers are throwing in the towel and allowing 'ping' tracking (and how you can still block this).
How do you deal with the threat of identity theft? Follow Adam Levin's 3 M's: 1) minimize your exposure, 2) monitor your accounts, and 3) manage the damage. We discuss these techniques and much more in part two of my interview with Adam Levin, author of Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves.
Adam Levin is a consumer advocate with more than 40 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. You may have seen Adam on one of his several TV appearances, as well.
Further Info:
Adam Levin's website: https://adamlevin.com/Adam's book, Swiped: https://adamlevin.com/swiped-book-adam-levin/CyberScout: https://www.cyberscout.com/ Bruce Schneier's Data and GoliathKevin Mitnick's The Art of InvisibilityBrian Kreb's Spam Nation and his blogIdentity Theft Resource CenterConsumer Federation of AmericaPrivacy Rights Clearinghouse
Identity theft is arguably one of the worst cyber crimes in terms of deep and lasting impact to the victim. This runs the gamut from simple credit card fraud to committing crimes in someone else's name. We'll talk about the entire spectrum today in part one of my interview with Adam Levin, author of Swiped: How to Protect Yourself in a World Full of Scammers, Phishers, and Identity Thieves.
Adam Levin is a consumer advocate with more than 40 years of experience in security, privacy, personal finance and many other things. He is the former director of the New Jersey Division of Consumer Affairs and current chairman and founder of CyberScout. You may have seen Adam on one of his several TV appearances, as well.
Further Info:
Adam Levin's website: https://adamlevin.com/Adam's book, Swiped: https://adamlevin.com/swiped-book-adam-levin/CyberScout: https://www.cyberscout.com/
Bad guys have been using scary emails and pop-up messages to bilk unsuspecting victims of millions of dollars for a long time now. But recent scams purporting to be from the CIA have taken things to a new level. In today's show, I'll walk you through one variant of this scam and teach you how to spot similar scare scams.
In other news, government spyware has made its way into everyday apps on the Google Play Store, WinRAR has a serious bug that you need to patch, hundreds of millions of Facebook records were found lying around unprotected in the cloud, ASUS computer users were targeted by ShadowHammer malware, and Cloudflare has a new mobile VPN app you should take a look at.
Further Info
Install and configure Cloudflare's 1.1.1.1 DNS: https://developers.cloudflare.com/1.1.1.1/setting-up-1.1.1.1/ASUS malware checker: https://shadowhammer.kaspersky.com/
How often have you run across something so obviously bad or behind the times that you just want to scream: Hey, fix this already! Electronic Frontier Foundation to the rescue! Gennie Gebhart explains the EFF's new #FixItAlready campaign - a "most wanted" list of no-brainer bugs and shortcomings in today's most popular services and products that just should not be. Examples include no end-to-end encryption of Twitter DMs, using two-factor Facebook phone numbers for marketing, and not being able to set your own password on iCloud or Windows 10 hard drive encryption.
Gennie Gebhart is the Associate Director of Research at the Electronic Frontier Foundation, where she does research and advocacy on consumer privacy and security issues. She holds a Master of Library and Information Science from the University of Washington.
Further Info:
Fix It Already! https://fixitalready.eff.org/Donate to EFF: https://supporters.eff.org/donate/join-eff-4
What happens to your digital life when you die? The answer is only slightly less philosophical than what happens to your soul. The laws, as least in the US, haven't kept up with the times and there aren't clear rules for who has legal rights to your online accounts or the files you've stored in the cloud. In today's episode, I'll tell you how to prepare for your inevitable digital afterlife.
In other news, Facebook revealed that 100's of millions of its users passwords were left open on internal servers, ransomware has hit one of the world's largest producers of aluminum, the Pwn2Own bug hunt contest shows us how to do responsible disclosures, a critical flaw has been found in implanted defibrillators leaving them vulnerable to hacking, and DARPA is hoping to fix our broken voting systems.
Further Reading
My blog article on Digital Afterlife: https://firewallsdontstopdragons.com/preparing-for-your-digital-afterlife/Facebook's password screwup: https://krebsonsecurity.com/2019/03/facebook-stored-hundreds-of-millions-of-user-passwords-in-plain-text-for-years/Critical defibrillator bugs: https://arstechnica.com/information-technology/2019/03/critical-flaw-lets-hackers-control-lifesaving-devices-implanted-inside-patients
In second half of my interview with EFF's Bill Budington, Bill helps us understand how we can at least attempt to disguise ourselves on the web and basically try to blend in with the crowd. We'll also see how tools like EFF's Panopticlick can hep us pinpoint the things that are making us stand out, which enables us to be tracked more easily. Finally, we'll discuss several browsers and plugins that can help you preserve your privacy.
If you missed Part 1, you can listen to it here: http://podcast.firewallsdontstopdragons.com/2019/03/10/enter-the-panopticon-pt1/.
Guest Bio:
Bill is a Senior Staff Technologist at the Electronic Frontier Foundation (EFF). He works on privacy and security-enhancing projects, such as the HTTPS Everywhere browser add-on and Panopticlick, a tool that alerts users users to how vulnerable they are to browser tracking. He has also contributed to projects such as Let's Encrypt and SecureDrop.
Further Info:
Is your browser giving you away? EFF's Panopticlick will tell you: https://panopticlick.eff.orgEFF's Surveillance Self Defense guide - learn how to keep yourself safe online! https://ssd.eff.org/Help EFF to help you: https://supporters.eff.org/
In the first part of my discussion with Bill Budington from the EFF, we're going to talk about some of the key ways in which we are tracked around the web as we surf from site to site. I'll ask Bill who is tracking up, why they're tracking us, and we'll get into some of the clever and downright devious methods by which we are tracked and recognized on the web.
In part 2 (next week) Bill will help us understand why it's so hard to disguise ourselves on the web and how tools like EFF's Panopticlick can show us what's going on under the covers. We'll also offer up some solutions or at least mitigations for all this tracking.
Guest Bio:
Bill is a Senior Staff Technologist at the Electronic Frontier Foundation (EFF). He works on privacy and security-enhancing projects, such as the HTTPS Everywhere browser add-on and Panopticlick, a tool that alerts users users to how vulnerable they are to browser tracking. He has also contributed to projects such as Let's Encrypt and SecureDrop.
Further Info:
Is your browser giving you away? EFF's Panopticlick will tell you: https://panopticlick.eff.orgEFF's Surveillance Self Defense guide - learn how to keep yourself safe online! https://ssd.eff.org/Help EFF to help you: https://supporters.eff.org/donate/join-4
The Mayor of Tampa, Florida, had this Twitter account hacked due to "the usual weaknesses, including poor passwords." The hackers used the account to tweet pornographic images and even an incoming ballistic missile alert. Comcast's Xfinity Mobile service used a default account security PIN of "0000", which allowed several customers to have their accounts taken over. You not only need strong passwords, you need strong second factor authentication. That's defense in depth.
In other news, Microsoft's Edge browser was found to have a whitelist for almost 60 websites that bypass the Flash Player click-to-run protections, a Canadian province is allowing the mass sale of anonymized medical records, the fast Thunderbolt USBC ports are found to be vulnerable to a memory access hack called Thunderclap.
Artificial Intelligence (AI) has been around for decades, but has only recently begun to fulfill the promise of truly replicating human-like decision making. The Information Age has generated enormous quantities of data and modern technology has given us unprecedented power to ingest and analyze this data. AI systems today control airplanes, financial and insurance systems, and even criminal sentencing recommendations. We can use AI to conduct law enforcement and intelligence gather operations. AI has even generated audio, video and photos that are completely fake but nearly impossible for a human to detect. Our guest today, Lorraine Kisselburgh, is working with international organization to define common-sense guidelines for the creation and use of these AI systems, to maximize potential and minimize abuse.
Lorraine Kisselburgh (Ph.D., Purdue University) is a Scholar with the Electronic Privacy Information Center in Washington, D.C., a former professor of media, technology, and society, and a visiting lecturer in the Center for Entrepreneurship at Purdue University. She studies the social implications of emerging technologies, including privacy and ethics in emerging technology contexts. Her research has been awarded funding from the National Science Foundation and the Department of Homeland Security, and recognized by the National Academy of Engineering. She currently serves on the executive committee of Association of Computing Machinery’s (ACM) US Technology Policy Committee (USTPC) and was a member of the ACM Task Force on Code of Ethics.
Email: lorraine@purdue.eduWebsite: www.lkisselburgh.netTwitter: @lkisselburgh, @EPICPrivacyFacebook: EPICPrivacy
Further Information:
Universal Guidelines for AI: https://thepublicvoice.org/AI-universal-guidelines/Electronic Privacy Informantion Center (EPIC): https://www.epic.org/"Deep Fake" Obama PSA: https://www.youtube.com/watch?v=cQ54GDm1eL0 Lyrebird fake Trump and Obama voices: https://soundcloud.com/user-535691776/dialogOpenAI fake news articles: https://arstechnica.com/information-technology/2019/02/researchers-scared-by-their-own-work-hold-back-deepfakes-for-text-ai/AI Now Institute: https://ainowinstitute.org/Berkman Klein Center for Internet and Society: https://cyber.harvard.edu/Data & Society Intelligence and Autonomy Initiative: https://autonomy.datasociety.net/WEF’s AI and Machine Learning: https://www.weforum.org/communities/artificial-intelligence-and-machine-learning
The European Union has recalled a GPS smart watch meant to be worn by children so that their parents can keep tabs on them. Unfortunately, due to horrible security, anyone can track these watches - and even send messages to the children. The Internet of Things (IoT) is well-known for having lax or non-existent security protections. Connecting our children's toys to the internet in this manner is raising serious (and valid) privacy concerns.
In other news, there's a devious new Facebook and Google phishing scam that would fool many pros, the Chrome browser will soon help you spot fake look-alike websites, Apple cracks down on apps that surreptitiously record their users' interactions with their apps, and many modern Android phones are vulnerable to hacking simply by loading a malicious image.
Help Me to Help You!
Visit my page on Patreon for details: https://www.patreon.com/FirewallsDontStopDragons
Last week I told you about the literally billions of email addresses and passwords that were released by hackers as "Collections 1-5". I also told you how you can check to see if your information was contained in these (or other dumped data) by checking haveibeenpwnd.com. And today I'm interviewing the man behind this wonderful, free service: Troy Hunt! He tells us how he gets his hands on all of this data and what we should be doing to mitigate the damage from these inevitable breaches. The worst thing you can do? Reusing passwords on multiple sites!
In today's episode, I also reveal the winners of my Pod-Centennial contest! Five lucky people will be getting signed copies of my book, signed copies of Bruce Schneier's latest book (Click Here to Kill Everybody), and a selection of other cybersecurity books!
Troy Hunt is an Australian Microsoft Regional Director and Microsoft Most Valuable Professional for Developer Security. You'll regularly find Troy in the press talking about security and even testifying before US Congress on the impact of data breaches.
Further Info
HaveIBeenPwned.comEthics of running a data breach search service: https://www.troyhunt.com/the-ethics-of-running-a-data-breach-search-service/Authentication evolved: https://www.troyhunt.com/passwords-evolved-authentication-guidance-for-the-modern-era/
Last week we saw perhaps the single largest data breach dump in history, close on the heels of another massive data disclosure from the same group. Dubbed "Collections 1-5", together these data dumps represent literally billions of unique user email addresses and passwords. Using the online tool Have I Been Pwned will tell you whether your email address or password is contained in this hacker's treasure trove. I will also tell you how you can mitigate the damage from this and future breaches.
In other news, Apple's FaceTime app contains a huge bug that could let other people eavesdrop on you and potentially even view you through your camera; Google and Firefox are offering competing visions of browser privacy with controversial new features; and a recent Mac malvertising campaign is using a classic technique called steganography to disguise its malicious intentions.
Further Information
Have I Been Pwned: https://haveibeenpwned.com/Pod-Centennial Contest Details: https://firewallsdontstopdragons.com/celebrate-my-pod-centennial/CLICK HERE TO ENTER the PodCentennial Contest!
We're celebrating international Data Privacy Day along with the 100th episode of Firewalls Don't Stop Dragons! And what a show we have! My guest today is none other than Bruce Schneier: internationally renowned security technologist and author of 14 books, including the best-seller Click Here to Kill Everybody)! Bruce and I discuss the current state of data privacy and what it's going to take to rein in the corporations that are buying and selling our data with abandon.
In this show I will also walk through my personal privacy checklist, including several things you could do RIGHT NOW to improve your online privacy. Along the way, I will share some tips from some of my favorite past guests on the show.
But that's not all! To celebrate my Pod-Centennial, I'm giving away 5 signed copies of my book as well as 5 signed copies of Bruce's latest book, a stack of some of my favorite cybersecurity books, and MORE! You have to listen to this show to learn how to enter the contest - so there's no better time to subscribe and listen!
Further Information:
Transcript of my interview with Bruce Schneier: http://podcast.firewallsdontstopdragons.com/wp-content/uploads/2019/01/Ep100-interview.txtData Privacy Day Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/Pod-Centennial Contest Details: https://firewallsdontstopdragons.com/celebrate-my-pod-centennial/CLICK HERE TO ENTER
Bruce Schneier interview transcriptDownload
Ancestry analysis firm 23andMe has just inked a 4-year, $300M deal to share its DNA samples with the colossal pharmaceutical company GlaxoSmithKline. What are they going to do your genetic material? Good question. Did you carefully read and understand your Terms of Service? Sure you did. I'll tell you how you can ask 23andMe (or Ancestry.com) to discard your samples.
In other news, some users are finding that they aren't allowed to delete their Facebook apps from their phones, a new federal case has strengthened your privacy rights when it comes to phone searches, and the Weather Channel app has been selling your location data to third parties.
Last month Australia passed a sweeping surveillance law, quickly and without meaningful debate, called the Assistance and Access Act. Like the UK's Investigatory Powers Act of 2016. this law aims to give authorities unprecedented power to force makers of messaging services to break their software and lie to their users. Danny O'Brien, International Director for the Electronic Frontier Foundation, helps us understand the true implications of these law and why they are truly harmful to democracy.
Guest Information
Danny O'Brien has been an activist for online free speech and privacy for over 20 years. In his home country of the UK, he fought against repressive anti-encryption law, and helped make the UK Parliament more transparent with FaxYourMP. He was EFF's activist from 2005 to 2007, and its international outreach coordinator from 2007-2009. After three years working to protect at-risk online reporters with the Committee to Protect Journalists, he returned to EFF in 2013 to supervise EFF's global strategy. He is also the co-founder of the Open Rights Group, Britain's own digital civil liberties organization.
Twitter: @EFF, @malaWebsite: https://www.eff.org/
Further Information:
Truly Secure Messaging: https://firewallsdontstopdragons.com/truly-secure-mobile-calls-and-messaging-for-free/Why Privacy Matters (TED Talk): https://www.ted.com/talks/glenn_greenwald_why_privacy_mattersThe Value of Privacy: https://www.schneier.com/blog/archives/2006/05/the_value_of_pr.htmlDonate to the EFF! https://supporters.eff.org/donate/join-4
Just because you're not paranoid doesn't mean they're not following you. A new study finds that Android phones tattle on you up to 340 times a day.
It's that time of year again - time to make your New Years Resolutions! You know all those really important things I've been telling you to do, but you haven't done? Well, I'm listing out the top ones on today's show - and challenging each of you to check them off this year!
There's also a lot of news to catch you up on: why the green padlock symbol doesn't mean what you think it does, an update on the SuperMicro computer spy chips, fitness apps stealing $120 from its users, scammers calling seniors pretending to be grandkids, US border agents not taking care of your private data, and a stunning NY Times study about all the apps that are tracking your location
Further Reading
NY Times article on location tracking: https://www.nytimes.com/interactive/2018/12/10/business/location-data-privacy-apps.htmlReview my podcast! https://itunes.apple.com/us/podcast/firewalls-dont-stop-dragons-podcast/id1213366517?mt=2# Worst passwords of 2018: https://www.teamsid.com/100-worst-passwords/
Several US states are trialing programs to replace the venerable plastic driver's license card with a new smartphone app. Unlike the "dumb" physical cards, the app would always be up to date. One study showed that 77% of all US adults have a smartphone. If you're an adult under the age of 30, that percentage jumps to 94%. But as our guest, Chad Marlow, explains this is a solution in search of a problem. It comes with significant risks for both privacy and democracy.
Guest Info: Chad Marlow (ACLU)
Chad Marlow is a senior advocacy and policy counsel at the ACLU. He principally focuses on privacy, surveillance, and technology issues. His work on issues ranging from net neutrality and police body cameras to government surveillance and consumer privacy has been a frequent subject of national and international media coverage. He is the author of fifteen ACLU model bills. He spearheaded the ACLU’s nationwide #TakeCTRL and Community Control Over Police Surveillance (CCOPS) campaigns.
Twitter: @chadaaronmarlow, @ACLUWebsite: ACLU.org
Further Reading
Could Plastic Driver’s Licenses Become a Thing of the Past? : https://www.pewtrusts.org/en/research-and-analysis/blogs/stateline/2018/11/20/could-plastic-drivers-licenses-become-a-thing-of-the-pastWhy Privacy Matters (TED Talk): https://www.ted.com/talks/glenn_greenwald_why_privacy_matters
It's bad enough that online ads are watching us, but now billboards and other real world ads are watching us, too. Using video cameras and signals from our smart devices, marketers are tailoring their billboards and digital signage based on our appearance and even our identity. Sean O'Brien from Yale Privacy Lab explains how this is done and the significant privacy implications of this practice. He'll also tell you how you to protect our privacy. Sean O'Brien is a Lecturer in Law at Yale Law School with expertise in cybersecurity, privacy, and mobile device forensics. He is Director of Business Development at Purism SPC, a company dedicated to digital privacy and security and founder of Yale Privacy Lab.
Twitter: @YalePrivacyLab Yale Privacy Lab: https://privacylab.yale.edu Citizen FOSS guide: https://github.com/YalePrivacyLab/citizen-foss Original article from Medium: https://medium.com/s/thenewnew/irl-ads-are-taking-scary-inspiration-from-social-media-7088e8241beb
Marriott reports this week that it has exposed up to 500 million Starwood guests’ data going back as far as 2014. Affected hotels include Sheraton, Westin, W Hotels, Starwood timeshares and more, While it’s still not clear how much data may have been stolen, what is clear is that corporations are still not guarding their data properly. In today’s show, I’ll tell you what sort of customer information was vulnerable and what you can do to protect yourself.
In other news, Ford’s CEO voices plans to monetize their customers’ data, the USPS has a mail preview service that you’ll want to sign up for before the bad guys do it on your behalf, and if you’ve ever had the creepy feeling that customer support reps can see what you’re typing in chat support before you send it… it’s because they can! More Info:
Starwood's breach info page: https://info.starwoodhotels.com How to freeze your credit: https://firewallsdontstopdragons.com/using-credit-freeze-for-self-defense/ Best & Worst gifts for 2018: https://firewallsdontstopdragons.com/best-worst-gifts-2018/
Our mobile phones today are chock full of private information and are constantly tattling about our whereabouts and activities. Most phones today have GPS, WiFi, Bluetooth, motion detectors, magnetic field detectors, microphones, cameras, and of course cellular radios. Some even have facial recognition built right in. With all this personal data and telemetry information, is it even possible to prevent tracking and information leakage?
Today we discuss these topics and more with Daniel Davis from DuckDuckGo - a company dedicated to protecting your privacy. He and I discuss DuckDuckGo’s new privacy-focused smartphone app, along with other tips and techniques to guard your privacy on your mobile devices.
Daniel Davis is a Community Manager at DuckDuckGo, the Internet privacy company helping you take control of your personal information online. DuckDuckGo has its roots as the search engine that doesn't track you, and has expanded to protect you no matter where the Internet takes you.
For Further Insight:
Website: https://duckduckgo.com Twitter URL: https://twitter.com/duckduckgo LinkedIn URL: https://www.linkedin.com/company/duck-duck-go DuckDuckGo Privacy Essentials: https://duckduckgo.com/app Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
The gift-giving season is once again upon us! “Smart” devices make great presents, but you want to make sure that you’re not also giving a gift to the hackers out there! In this special, annual holiday episode, I’ll tell you about some of the best and the worst holiday gifts and accessories, from a security and privacy viewpoint. Thinking about giving someone a DNA analysis kit? You might want to think twice! Which computers and smart devices are the most secure? And are there products I can buy to help make them more secure? You bet! I have all the angles covered for you in this week’s show!
See also my blog article: The Best & Worst Gifts for 2018
Just because the caller ID says it’s the IRS or the Social Security Administration, don’t believe it. It’s almost surely a scammer trying to get your money or information. Government agencies don’t call people to confirm information in their records about you or with threats if you don’t pay up. And the caller ID information you see often has no relation whatsoever to who is actually calling or where they’re calling from. In today’s episode, I’ll tell you how to handle these scammer calls.
I’ll also tell you about a massive, nationwide database of biometrics that was just created, how Consumer Reports and Mozilla are helping you to make smart security and privacy decisions on new products, and how a PhD from MIT is on a mission to fix our horrendously insecure voting systems.
Your physical world is governed by many laws and regulations that protect your freedom and privacy. Why should the digital world be any different? Todd Weaver, CEO and Found of Purism, explains how Big Tech managed to write the rules for the digital world and why those rules are at odds with your freedom, security and privacy. But it doesn’t have to be this way. As citizens, we can force those representing us to protect our digital civil rights. As consumers, we have options for computers and smartphones you can buy right now that will assert your digital civil rights.
Serial entrepreneur and successful businessman, Todd has been recognized for his visionary strategy, technical leadership, and relentless drive, with more than 20 years of entrepreneurial experience, using, installing, and promoting Free Software. Todd has consistently predicted market directions and executed disruptive technologies in a wide range of industries, including in-store entertainment, collaborative financial solutions, and starting the first online cable company. Todd has a deep understanding of the hardware manufacturing process, and an unwavering belief for users to retain their essential freedoms via free software, making Purism (the marriage of high quality hardware and free software), his most ambitious, disruptive, and exciting venture yet.
For Further Insight:
The Future of Computing and Why You Should Care: https://www.youtube.com/watch?v=nFwBh9QZTwg Purism products: https://puri.sm/products/
Website: https://puri.sm Twitter URL: https://twitter.com/Puri_sm
We all know how marketers are tracking our every move on the world wide web. But now they’re starting to track you in the real world, too. Security cameras exist everywhere, but companies have now decided to add facial recognition software to those systems in order to track where you go, what you look at, who you’re with and how effective their ads are.
I’ll also tell you why the Firefox browser is taking bold new steps to protect your web browsing privacy and how Apple’s CEO Tim Cook believes tech companies must take steps to safeguard their customer’s data.
For Further Insight:
Tim Cook’s speech on privacy: https://www.youtube.com/watch?v=kVhOLkIs20A Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
The reports of net neutrality’s death have been greatly exaggerated. We still have time for Congress to reinstate the federal rules that were struck down by the FCC. In the meantime, states like California are taking matters into their own hands, passing landmark state-level legislation to preserve a level playing field on the Internet.
Ernesto Falcon from the Electronic Frontier Foundation (EFF) explains why Net Neutrality is not dead and how states are stepping in to try to fill the gap. Prior to joining EFF, Ernesto worked as a legislative staffer for two Members of Congress (2004-2010). He then became Vice President of Government Affairs at Public Knowledge where he advocated on behalf of consumers on copyright issues and broadband competition. During his tenure, Public Knowledge was successful in achieving one of the largest consumer victories in telecom policy by defeating AT&T’s merger with T-Mobile. The following year, PK and EFF scored a major victory for consumers by rallying the Internet community to defeat the Stop Online Piracy Act (SOPA). After eight years in Washington DC, he returned to his home state of California to go to law school at McGeorge School of Law in order to strengthen his digital rights advocacy. Now, as an attorney, he is excited to rejoin the fight for consumers and Internet freedom.
For Further Insight: Website: https://eff.org/ Follow on Twitter: https://twitter.com/EFFFalcon LinkedIn: https://www.linkedin.com/in/ernestofalcon/
Bloomberg claims that Chinese manufacturers have implanted tiny spy chips into many of our computer systems. Apple, Amazon and others strenuously deny this. Who’s telling the truth? In today’s show, I’ll cover both sides of this story, discuss the various ways in which our global manufacturing and supply chain systems could be compromised, and delve into the several deeper considerations for these sorts of stories.
In other news, Facebook has lowered its estimate of the number of users affected by the recent breach to a mere 29 million, Google has shuttered its flagging Google+ service after news of a breach leaked last week, I give you the highlights of my 320-page LexisNexis dossier, and finally I give you several tips for patching holes in your defenses in honor of National Cybersecurity Awareness Month.
For Further Insight:
Deleting your Google+ account: https://www.cnet.com/how-to/how-to-delete-your-google-account-data-breach/ Supply chain security 101: https://krebsonsecurity.com/2018/10/supply-chain-security-101-an-experts-view/ Make sure you’re registered to vote! https://votesaveamerica.com/verify Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Ransomware, the malware that locks up your data and hold it for ransom, has been growing by leaps and bounds in the past few years, WHY? Because it works. Hackers trick you into installing the malware which encrypts your most precious files and demands that you pay Bitcoin to get the key that unlocks them. It’s like a burglar broke into your house and put all your valuables in a safe in your living room, demanding payment for the combination. Allan Liska explains why ransomware has become a favorite tool of both hackers and nation states, how to protect your computers, and even what you can do if you are unfortunate enough to be infected.
Allan Liska is an intelligence analyst at Recorded Future. Allan has more than 15 years’ experience in information security and has worked as both a blue teamer and a red teamer for the intelligence community and the private sector. Allan has helped countless organizations improve their security posture using more effective and integrated intelligence. Allan is also one of the organizers of BSides Bordeaux and has presented at security conferences around the world on a variety of topics. He is the author of The Practice of Network Security, Building an Intelligence-Led Security Program, and Securing NTP: A Quickstart Guide and the co-author of DNS Security: Defending the Domain Name System and Ransomware: Defending Against Digital Extortion.
For Further Insight:
Ransomwhere (Ransomware protection for Mac): https://objective-see.com/products/ransomwhere.html No More Ransom (if you get infected): https://www.nomoreransom.org/
Website: www.bsidesbdx.org Twitter: https://twitter.com/uuallan LinkedIn: https://www.linkedin.com/in/allan2/
Between 50 and 90 million Facebook users’ accounts were exposed, appearing to give hackers full access as if they were logged in as you. Facebook has fixed the bug, but it’s not yet clear whose accounts may have been compromised. In other news, researchers have determined that Facebook is using your security contact information and information shared by others you know to target you with ads.
In other privacy news, Google’s Chrome browser version 69 will automatically log you into the browser if you log in to any of Google many services - without warning or consent. While Google claims that none of your history or data is uploaded, the quiet change appears to violate their own privacy policies and has rankled many privacy advocates (including yours truly).
For Further Insight: Why I’m Done With Chrome: https://blog.cryptographyengineering.com/2018/09/23/why-im-leaving-chrome/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
One of the best ways to avoid identity fraud is to freeze your credit reports. Thanks to a new law that just went into effect, freezing and unfreezing your credit is now completely free! Freezing your credit will prevent fraudsters from opening new loans and credit cards in your name, sticking you with the bill. When you actually need to open new credit, you can temporarily thaw your account (also free). I’ll tell you how.
In other news, hackers have found flaws in two different government online payment systems, researchers have identified popular iPhone and Mac apps that are stealing your personal information, and Google has struct a secret deal with at least one major credit card company to get access to your real life purchase information.
For Further Insight:
Secret data sharing deal between Google and MasterCard: https://www.bloomberg.com/news/articles/2018-08-30/google-and-mastercard-cut-a-secret-ad-deal-to-track-retail-sales iPhone apps stealing location data: https://www.macrumors.com/2018/09/07/iphone-apps-location-data-monetization/ Freeze your credit: https://krebsonsecurity.com/2018/09/credit-freezes-are-free-let-the-ice-age-begin/
Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Did you know that Google owns Android, Waze, YouTube, Pixel phones and Chromebooks? Did you know that almost 90% of Google’s revenue comes from advertising? There’s hardly any part of your online life that isn’t somehow tracked by Google. By using Google’s email, calendar, docs, search, browser, cloud storage and even phones, we are allowing Google to know just about everything about us.
But there are viable alternatives that will respect your privacy. Daniel Davis from DuckDuckGo (a search privacy-first search company) will help us understand how and why Google tracks us, and then provide practical replacements for Google’s most popular services and products.
Daniel Davis is a Community Manager at DuckDuckGo, the Internet privacy company helping you take control of your personal information online. DuckDuckGo has its roots as the search engine that doesn't track you, and has expanded to protect you no matter where the Internet takes you.
For Further Insight: Website: https://duckduckgo.com Twitter: https://twitter.com/duckduckgo LinkedIn: https://www.linkedin.com/company/duck-duck-go Facebook: https://www.facebook.com/duckduckgo/
How to Live Without Google: https://spreadprivacy.com/how-to-remove-google/
Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
TRANSCRIPT OF FULL INTERVIEW Carey Parker: Hi everybody, welcome back to Firewalls Don't Stop Dragons. I got another great interview show for you today. I know I've had three interviews in a row. It's not normal. Usually I try to go back and forth, but it just hasn't worked out that way lately. I've got some great people available for the reason I just couldn't pass it up.
Carey Parker: Today we're gonna be talking with Daniel Davis from DuckDuckGo and DuckDuckGo, if you recall, is the privacy centered search engine that's an alternative to Google search engine and that is what we're going to be talking about today. So we hear all the new stories about Facebook and Cambridge Analytica and all the things that have been exposed and all the things that Facebook knows about you. And what we really need to realize is that all of that just pales in comparison to what Google knows about most of us. Google is all up in everything that we do, and I think you'll actually be surprised to learn that all the different ways that Google is in our lives.
Carey Parker: And so as all these scandals around privacy been coming around, I finally just decided personally that I've got to extract myself from Google, and they have some great products. These free products that they've had that I have used for many, many, many years are honestly great functionally, they're wonderful. And because like Facebook because everybody uses them, it's just so easy to share calendars, to share documents to ... email of course is not quite the same because at least emails are standard that many different services support, so you don't have to both be on Gmail in order to send email, which thank God. But, anyway, there are just so many things that Google's part of lives and we're going to cover that in the interview, So I'm not going to give too much away now.
Carey Parker: But the point of this interview, what I tasked Daniel with and they've got an article at DuckDuckGo about how to get rid of Google, how to live your life without Google products. And it goes through all the top Google products and gives you a really viable alternative. But to me that wasn't good enough. What I wanted to know was, okay, if I'm deeply embedded in Google and I've got all this data and all my friends know my Gmail address and I'm sharing Google calendars with people, it's not just enough to know here's an alternative, but how do I actually switch from one to the other? And so we're going to talk about that today with Daniel Davis and let's jump right in.
Carey Parker: He's got some really great info and we'll start off talking a little bit about what the real backgro...
AT&T is operating top secret Internet monitoring facilities for the NSA in the heart of 8 major US cities according to a blockbuster report from The Intercept. Sitting on top of major digital communications arteries, these surveillance systems can track and record most communications within the US as well as many outside our physical borders. David Ruiz from the Electronic Frontier Foundation explains why these sorts of systems go way beyond the foreign spying mandate of the NSA and hoover up hordes of “incidental” data on ordinary, law-abiding US citizens.
David Ruiz is a writer covering NSA surveillance and federal surveillance policy for Electronic Frontier Foundation, a digital rights non-profit. As 2017 closes, he is deeply involved in covering the multiple bills before Congress that seek to reform or reauthorize Section 702 of the FISA Amendments Act, a law that is currently one of the U.S. government's most powerful surveillance tools. Previously, David worked as a journalist covering legal affairs for some of Silicon Valley's largest companies, including Google, Facebook, Twitter and Uber. He has also had his work featured in KQED, The East Bay Express, SFGate.com, The Sacramento Bee and KZSU Stanford 90.1 FM. Beyond writing, David also hosts a personal podcast called Death Knell, which explores the grieving process after death.
For Further Insight: Website: davidalruiz.com Follow on Twitter: @davidalruiz @EFF Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Frontline’s United States of Secrets: https://www.pbs.org/video/frontline-united-states-secrets-part-one/ The Intercept, AT&T NSA Spy Hubs: https://theintercept.com/2018/06/25/att-internet-nsa-spy-hubs/ EFF’s response to Intercept: https://www.eff.org/deeplinks/2018/07/eight-att-buildings-and-ten-years-litigation-shining-light-nsa-surveillance
The 2018 DEFCON Vote Hacking Village showed once again that our voting machines are way too easy to hack. Even though election system manufacturers refuse to allow independent researchers to vet their products directly, hackers at DEFCON have managed to get their hands on several systems in use today, and show that they are trivial to compromise. Jacob Hoffman-Andrews from the EFF explains what all of this means and the measures we need to take to address these shortcomings.
The PAVE Act that’s currently before Congress would provide mechanisms to mitigate the weaknesses of our voting systems by requiring a paper trail for all votes and risk-limiting audits to validate vote totals with minimal effort and cost. The companion Secure Elections Act is now a much weaker bill and would need to have these provisions restored.
Jacob Hoffman-Andrews is a lead developer on Let's Encrypt, the free and automated Certificate Authority. He also works on EFF's Encrypt the Web initiative and helps maintain the HTTPS Everywhere browser extension. Prior to working at EFF, Jacob was on Twitter's anti-spam and security teams. One the security team, he implemented HTTPS-by-default with forward secrecy, key pinning, HSTS, and CSP. On anti-spam, he deployed new machine-learned models to detect and block spam in realtime. Before Twitter, he worked at Google, variously on the maps, transit, and shopping teams.
For Further Insight: Website: https://www.eff.org/about/staff/jacob-hoffman-andrews Follow on Twitter: https://twitter.com/j4cob
Facebook’s “Protect” Virtual Private Network is anything but “private”. Facebook has been using this VPN to monitor all of your web surfing, adding even more information about its users to its colossal database. Apple removed the app from it’s App Store due to violations of its recently upgraded privacy policies. You should delete the app from your phone and use a better VPN.
In other news, banks are using 2,000 data points about how you tap, swipe, type, click and move to try to prevent fraud, DEFCON hackers have found more bugs in our election systems (though the headlines got it mostly wrong), Amazon Echo might be able to scare off burglars, and DNA service 23andMe is starting to dial back access to your data for third party developers.
Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Security researchers have demonstrated that a modern all-in-one printer machine can be compromised using technology from the 1970s: the venerable fax machine. If you have a fancy printer/fax, you need to update its software ASAP. Presenters are this year’s DEFCON hacker conference have shown that they can compromise HP printer/fax machines by sending it a maliciously formatted fax message.
I’ll also tell you about a scary and effective sextortion scam, a dire warning from the FBI about a coming ATM cashout heist, some more browser plugins that are tracking all the websites you visit, and why turning of Location History in your Google settings isn’t actually stopping Google from tracking where you go.
Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
What do you get when you cross cryptography with a wall of lava lamps? Believe it or not, a much more secure Internet. Cloudflare’s CTO John Graham-Cumming will explain why all our modern communications require sources of randomness to remain secure, and how his company has used a wall of 100 lava lamps to serve as a serious source of entropy. John will explain how to pick strong passwords using dice, how you can predict random numbers, and whether quantum computing will render all of our crypto technology useless. Book: The Code Book: The Science of Secrecy from Ancient Egypt to Quantum Cryptography John Graham-Cumming, CTO of Cloudflare, is a computer programmer and author. He studied mathematics and computation at Oxford and stayed for a doctorate in computer security. As a programmer he has worked in Silicon Valley and New York, the UK, Germany, and France. His open source POPFile program won a Jolt Productivity Award in 2004. John is the author of a travel book for scientists published in 2009 called The Geek Atlas and has written articles for The Times, The Guardian, The Sunday Times, the San Francisco Chronicle, New Scientist and other publications.
For Further Insight: Website: jgc.org Follow on Twitter: https://twitter.com/jgrahamc Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
How can you go wrong trying to stop sex trafficking? FOSTA, that’s how. The Fight Online Sex Trafficking Act (FOSTA) tried to fix something that wasn’t broke: under pre-existing law, we already had common sense regulations in place to prosecute online services that facilitated sex trafficking. But perhaps in an effort to appear tough on sex crimes, the US Congress passed additional regulations that are difficult to enforce and possibly even unconstitutional. The result may be more harm that good, robbing sex workers of resources that tools that served to protect them and squelching legitimate online content.
I delve into this topic with the EFF’s Elliot Harmon, covering the history of legislation in this area and analyzing the nuances of this tricky area of law. We also explore the political and financial reasons the FOSTA/SESTA bills appeared to have such broad support and how these laws closely parallel copyright enforcement bills.
Elliot Harmon is the associate director of activism at EFF. He advocates for free speech and the right to innovate online, with particular emphasis on patents, copyright, open access, and Section 230. Before coming to EFF, Elliot served as director of communications at Creative Commons, an organization that helps creators share their works with the public via open copyright licenses. Before that, he worked as a writer and curator for TechSoup, a technology resource for the nonprofit community. He has degrees from the University of South Dakota and the California College of the Arts.
For Further Insight: Website: https://www.eff.org/about/staff/elliot-harmon Rep Chris Cox on how Section 230 came into being: https://www.youtube.com/watch?v=iBEWXIn0JUY&t=3m55s Why Hollywood might see FOSTA as a step toward a filtered Internet: https://www.eff.org/deeplinks/2018/03/how-fosta-will-get-hollywood-filters-theyve-long-wanted Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
A small company has recently bought up a bunch of mobile phone add-ons and browser plugins, and apparently decided to start snooping on its customers. The apps have been downloaded by over 11 million people and appear to be keeping track of every single web site you visit. In another story, a plugin that is supposed to help you pin things on Pinterest is actually injecting code into web pages. While this appears to be just a coding accident, these two stories should be a wake-up call. I’ll tell you what you can do about it.
In other news, Facebook, Google and others are helping you take your data to competing services, 23andMe is sharing your DNA with Big Pharma, a nasty new Bluetooth bug has been found, and Chrome is now marking many more websites as “insecure”. Tune in and I’ll explain how this all affects you!
There’s a data gold rush going on in the United States and without regulation, it’s turning into a Wild West of data mining. Modern humans generate tons of data exhaust every single day: what you buy, what you eat, what you watch, where you live and work and what you do in your free time. These activities and habits may speak volumes about your health risk factors - and therefore how expensive you will be to cover with health insurance. In today’s show, I’ll share some chilling insights from a conference where data brokers and health insurers are using this data to predict how much it will cost them to insure you - and potentially raise your rates or even find ways to avoid covering you at all.
In other news, Apple has released a new privacy feature to protect your iPhone from hacking, the popular mobile payment firm Venmo is sharing your transaction information with the world, researchers have developed an app to stop your laser printer from tattling on you, and Google’s new Confidential Mode email isn’t so confidential.
For Further Insight:
Change Venmo privacy settings: https://help.venmo.com/hc/en-us/articles/210413717-Payment-Activity-Privacy Get your LexisNexis report: https://personalreports.lexisnexis.com/access_your_full_file_disclosure.jsp Find and obfuscate secret tracking dots from your printer: http://seeingyellow.com/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Where were you on the night of June 22nd? Your cellular provider knows. And until that date just a few weeks ago, if law enforcement wanted that info, all they had to do was ask. But we’re not just talking about one night… they know every place you’ve been, throughout the day, every day, going back months or even years. Thankfully, the Supreme Court ruled that law enforcement must now get a warrant to obtain this highly sensitive information and show probable cause.
In our interview today, I have a truly thought-provoking discussion around the landmark Carpenter vs United States ruling with Shahid Buttar, a lawyer and grassroots organizer for the Electronic Frontier Foundation (EFF). We delve into the history behind cell phone data access in the United States and why a basic right to privacy is fundamental to any democracy.
Shahid Buttar leads EFF's grassroots and student outreach efforts. He's a constitutional lawyer focused on the intersection of community organizing and policy reform as a lever to shift legal norms, with roots in communities across the country resisting mass surveillance. From 2009 to 2015, he led the Bill of Rights Defense Committee as Executive Director.
After graduating from Stanford Law School in 2003, where he grew immersed in the movement to stop the war in Iraq, Shahid worked for a decade in Washington, D.C. He first worked in private practice for a California-based law firm, with public interest litigation projects advancing campaign finance reform and marriage equality for same-sex couples (as early as 2004, when LGBT rights remained politically marginal). From 2005 to 2008, he helped build a national progressive legal network and managed the communications team at the American Constitution Society for Law & Policy, before founding the program to combat racial & religious profiling at Muslim Advocates.
For Further Insight:
Website: https://eff.org/efa Twitter URL: https://twitter.com/Sheeyahshee / https://twitter.com/EFF Facebook URL: https://www.facebook.com/EFF Become part of the Electronic Frontier Alliance: organizing@eff.org Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
We’ve talked about encryption in just about every single one of these shows but we’ve never actually talked about what it means to encrypt something. Did you know that Julius Caesar used cryptography to send secret messages to his generals? You may have heard about the vaunted Enigma Machine used by the Germans in World War II, but how did it work? I’ll walk you through the basics of creating secret codes and how to crack them - the science of cryptography and cryptanalysis!
Secret codes have one big problem, though: coded messages stick out like a sore thumb. When you capture a spy with a piece of paper full of gibberish, you can bet it’s a coded message. But what if you could hide your messages in plain site? That’s called steganography and I’ll explain how crafty people have hidden messages since the days of the Ancient Greeks.
For Further Insight:
The Code Book by Simon Singh The Code Breakers by David Kahn Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Wouldn’t it be great if you could speed up every single website you visit without paying a dime? Every time you go to a website, your computer or smartphone first has to look up how to get to get there - just like we used to have to look up people’s numbers in the phone book. The service we all use is the Domain Name System (DNS), and by default, your DNS provider is probably not very fast.
Today, John Graham-Cumming (the CTO of Cloudflare) will carefully explain how this works and why his company’s 1.1.1.1 DNS service is so much faster than the default one you’re probably all using. Furthermore, Cloudflare’s service will keep your web surfing habits totally private - something your default service is almost surely NOT doing.
John Graham-Cumming, CTO of Cloudflare, is a computer programmer and author. He studied mathematics and computation at Oxford and stayed for a doctorate in computer security. As a programmer he has worked in Silicon Valley and New York, the UK, Germany, and France. His open source POPFile program won a Jolt Productivity Award in 2004. John is the author of a travel book for scientists published in 2009 called The Geek Atlas and has written articles for The Times, The Guardian, The Sunday Times, the San Francisco Chronicle, New Scientist and other publications.
For Further Insight: Website: jgc.org Follow on Twitter: https://twitter.com/jgrahamc
Cloudflare’s 1.1.1.1 DNS service Steve Gibson’s DNS Benchmarking tool: https://www.grc.com/dns/benchmark.htm DNS Perf speed check: https://www.dnsperf.com/
This was a huge week for location privacy rights. In a 5-4 ruling, the Supreme Court has ruled that law enforcement must now obtain a warrant to obtain your cell phone location history. You cell provider knows where you are 24/7 and keeps records of your whereabouts that can go back for years. Until this ruling, this location information was considered to be unprotected and could be freely provided to law enforcement without notice or permission.
In related news, all major US cellular providers have voluntarily terminated agreements to provide your location to third party vendors due to several recent cases of abuse. On the other hand, Apple’s new iOS 12 will come with a feature that will automatically send detailed location information to 911 operators when you make an emergency call. We’ll talk about how end-to-encryption in WhatsApp has allowed girls in ISIS-controlled Syria to maintain their schooling. And if you have a really old web browser, it’s time to update it - at least if you still want to shop online!
Android devices are everywhere - not just smartphones, but smart TVs, DVRs, streaming TV boxes and tablets. And many of these devices a shipping with a wide open backdoor for hackers. The Android debug port is supposed to only be used during software development, but many manufacturers are shipping popular Android-based products with this debug interface wide open. Hackers can easily use this interface to hack these devices, often from anywhere on the planet.
In other news, California is trying to follow Vermont’s lead by introducing consumer data protection regulations, but many huge tech companies are trying desperately to defeat the measure. I’ll update you on the VPNFilter malware that is affecting more and more of our home WiFi routers, yet another critical Adobe Flash bug, and a $99 “unbreakable” smart padlock that can be hacked in under two seconds.
For Further Insight: Locking down your home routers: https://firewallsdontstopdragons.com/the-s-in-iot-is-for-security/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
There are estimated to be 2500-4000 data brokers in the United States who are collecting, buying and selling your information. Vermont has become the first state to pass laws to regulate this data mining that is largely working in the dark with zero accountability. We need more laws like this and I’ll tell you what you can do in the meantime to take more control over your personal and private data.
Also in the news, Apple has announced some fantastic new security and privacy features for it’s upcoming iOS and macOS releases, Facebook has screwed up again, turning posts from 14M people public when they were supposed to be private, and My Heritage DNA service annouces that its 92M customer passwords were stolen.
For Further Insight:
Opting out of data collection: https://www.stopdatamining.me/opt-out-list/ Opting out of marketing, phone calls: https://www.worldprivacyforum.org/2015/08/consumer-tips-top-ten-opt-outs/ Know that they have on you: https://www.aboutthedata.com/portal/registration/step1 Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
When is a Virtual Private Network (VPN) not really private? Answer: When your VPN provider tracks where you go and sells that information to someone else. Today we’ll talk about a recent study that shows that many of the top free VPN services make their money by collecting and selling your browsing information. That seems to violate the “P” part of “VPN”, but let’s face it: if the product is free, then you are probably the product. I’ll help you find a VPN service that is truly private.
In other news, Amazon’s Echo was recently caught recording a private conversation and sending it to a seemingly random person - should you be worried? Also, I’ll explain why shouting at your hard drives can cause corruption and tell you about a great new feature of the Privacy Badger browser plugin that will stop Facebook from tracking you.
For Further Insight: Don’t shout at your hard drives: https://www.youtube.com/watch?v=tDacjrSCeq4 Choosing a truly private VPN: https://www.privacytools.io/#vpn Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Summer is upon us and for many of us that means travel - but before you even pack your bags, you need to listen to this podcast! In my interview with Michael Kaiser (the Executive Director of the National Cyber Security Alliance), we discuss all the cyber security and privacy issues you need to consider: before you go and while you’re traveling. Going abroad this summer? There are even more things you need to consider well before you leave!
I also tell you why everyone needs to reboot their WiFi routers - by request of the FBI, no less! A Russian-made piece of malware called VPNFilter has infected half a million routers world-wise, and the remedy in most cases is simply to power-cycle or reboot your router. It’s easy to do and we should also take a few minutes to do it.
Michael Kaiser joined the National Cyber Security Alliance (NCSA) in 2008. As NCSA’s executive director, Mr. Kaiser engages diverse constituencies—business, government and other nonprofit organizations—in NCSA’s broad public education and outreach efforts to promote a safer, more secure and more trusted Internet.
Mr. Kaiser leads NCSA in several major awareness initiatives, including National Cyber Security Awareness Month (NCSAM) each October, Data Privacy Day (Jan. 28) and STOP. THINK. CONNECT., the global online safety awareness and education campaign. NCSA builds efforts through public-private partnerships that address cybersecurity and privacy issues for a wide array of target audiences, including individuals, families and the education and business communities. In 2009, Mr. Kaiser was named one of SC Magazine’s information security luminaries.
Mr. Kaiser has served on several nonprofit boards. He is currently the chair and a founding board member of SPINUSA, a national nonprofit based in Massachusetts, and has served on the Board of Trustees of the College of the Atlantic in Bar Harbor, Maine, and New Destiny Housing Corporation in New York City.
For Further Insight: Web site: staysafeonline.org Follow on Twitter: https://twitter.com/MKaiserNCSA Facebook: https://www.facebook.com/staysafeonline/ LinkedIn: https://www.linkedin.com/in/michael-kaiser-3579752b NCSA’s Cyber Trip Advisor: https://www.stopthinkconnect.org/resources/preview/tip-sheet-ncsas-cyber-trip-advisor Reboot your router and set your admin password: https://firewallsdontstopdragons.com/the-s-in-iot-is-for-security/
On May 25th, the European Union will begin enforcing the GDPR - a sweeping set of regulations designed to return control of user data back to the users. These rules apply to EU people, not EU companies - so if you have a business or website that deal with folks from the EU, then you need to comply with these rules. Note that even if it’s just a newsletter, you could be on the hook for damages if you didn’t obtain proper consent from your subscribers.
Ruth Carter is an Arizona attorney and an authority on intellectual property, business startups, contracts, and internet law. She is an American Bar Association Legal Rebel, a Phoenix Business Journal 40 Under 40, and a Super Lawyers Southwest Rising Star. Ruth also wrote three best-selling books on guerrilla marketing and social media law including The Legal Side of Blogging: How Not to get Sued, Fired, Arrested, or Killed. Ruth is also a professional speaker and has spoken at South by Southwest, Content Marketing World, Intelligent Content Conference, Women in Travel Summit, BlogHer, Dad 2.0 Summit, Ungagged, Phoenix Comicon (now Phoenix Comic Fest), and BlogPaws. She's also been featured in the Wall Street Journal, Entrepreneur, CEO Blog Nation, U.S. News, and on NPR.
For Further Insight:
Website: GeekLawFirm.com Twitter: https://twitter.com/rbcarter LinkedIn: https://www.linkedin.com/in/ruthcarter Facebook: https://www.facebook.com/carterlawfirmpllc Book: https://www.amazon.com/The-Legal-Side-Blogging-ebook/dp/B009K4U5RU/ Terms of Service; Didn’t Read: https://tosdr.org/ Ruth’s blogs on complying with GDPR: http://carterlawaz.com/category/gdpr/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Ever since WhatsApp was acquired by Facebook in 2014 for a staggering $19B, the extremely popular global messaging app has been losing its focus on privacy. WhatsApp co-founder Jan Koum (who grew up in the Soviet Union) has now left Facebook, and with him WhatsApp may have lost its last hope for retaining the user protections Koum carefully put in place. If you even considered leaving Facebook, you should consider leaving WhatsApp.
In the news, we’ll talk about a software bug that may leave 350,000 internal defibrillators to hacking, the looming hail-Mary chance to save net neutrality, a new credit bureau you might want to freeze, more computer CPU chip bugs coming, a Twitter password change requirement, new iOS and Firefox privacy features, and getting into your next concert using just your face.
For Further Insight:
Everything you need to know about credit freezes: https://krebsonsecurity.com/2018/05/another-credit-freeze-target-nctue-com/ Freezing your credit at NCTUE: 866-349-5355 Save Net Neutrality! https://battleforthenet.com Try Signal! Get your friends to try it, too!! https://www.signal.org/ Blog article with more info: https://firewallsdontstopdragons.com/ditch-whatsapp-use-signal/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Phil Zimmermann fought a multi-year court battle and risked years in jail in order to defend your right to privacy. Phil created an email encryption system called Pretty Good Privacy (PGP) in 1991 that is still the gold standard for private email today. I sat down with Phil to discuss his legacy and why we are truly in the Golden Age of Surveillance, despite claims by law enforcement that all communications are “going dark”.
Philip R. Zimmermann is the creator of Pretty Good Privacy, an email encryption software package. Originally designed as a human rights tool, PGP was published for free on the Internet in 1991. This made Zimmermann the target of a three-year criminal investigation, because the government held that US export restrictions for cryptographic software were violated when PGP spread worldwide. Despite the lack of funding, the lack of any paid staff, the lack of a company to stand behind it, and despite government persecution, PGP nonetheless became the most widely used email encryption software in the world. After the government dropped its case in early 1996, Zimmermann founded PGP Inc. That company was acquired by Network Associates Inc (NAI) in 1997. In 2002 PGP was acquired from NAI by a new company called PGP Corporation, where Zimmermann served as special advisor and consultant until its acquisition by Symantec in 2010. Since 2004, his focus has been on secure telephony for the Internet, developing the ZRTP protocol and creating products that use it, including Silent Phone and Zfone. Zimmermann is Co-founder of Silent Circle, a provider of secure communications services.
For Further Insight: Website: https://www.philzimmermann.com/
Our electronics and appliance manufacturers are desperately trying to turn all of their “dumb” products into “smart” ones by connecting them to the Internet - the new Internet of Things (IoT). And while dialing down your thermostat from the office and asking your portable speaker for today’s forecast is great, how can you trust that these devices aren’t spying on you or going rogue? In most cases, you can’t - which is why you need to wall them off from your computers
Today I’ll tell you how everyone can segregate these insecure devices using the WiFi router you already own. I’ll also tell you about a promising new project from Microsoft that may make future IoT devices much more secure, how Facebook is moving 1.5B users out from under GDPR protections, how services like 23andMe and Ancestry.com can be used to catch serial killers, and why the FBI may be lying about information “going dark”.
For Further Insight: How to put your IoT devices on the guest network: http://firewallsdontstopdragons.com/the-s-in-iot-is-for-security/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Google truly does know everything. Law enforcement is now turning to the search company to locate potential crime suspects. Google owns Android and Waze, along with several other smartphone apps - many of which have full access to your whereabouts. Police are now asking Google for lists of users who were near crimes when they occurred in hopes of finding suspects.
How does this jibe with our Fourth Amendment rights and what can we do to protect our privacy in the Golden Age of Surveillance? I have an eye-opening conversation with Nathan Freed Wessler of the ACLU on how courts and lawmakers are struggling to deal with demands for data from Google and other sources by law enforcement agencies anxious to make use of the treasure trove of personal information they’re amassing.
Nathan Freed Wessler is a staff attorney with the ACLU Speech, Privacy, and Technology Project, where he focuses on litigation and advocacy around surveillance and privacy issues, including government searches of electronic devices, requests for sensitive data held by third parties, and use of surveillance technologies. In 2017, he argued Carpenter v. United States in the U.S. Supreme Court, seeking to establish that the Fourth Amendment requires law enforcement to get a search warrant before requesting cell phone location data from a person’s cellular service provider.
For Further Insight: Website: www.aclu.org Follow on Twitter: https://twitter.com/NateWessler Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Chairman Ajit Pai and the FCC voted to gut net neutrality late last year - but the fight is not over. The United States Senate can overturn these rule changes with a simple majority of 51 votes. Right now, we have 50. We need just one more vote. This process has a 60-day deadline, which is April 23rd. We have one week left to reverse these changes and preserve Net Neutrality. If you have a Republican Senator, now is the time to call them and express your support!
I’ll discuss the new “multi-breach” of Sears, Kmart, Delta and MyFitnessPal, including what you need to do if you were affected. I’ll talk about Facebook CEO’s Mark Zuckerberg’s testimony in front of Congress and why most of the Congress folks completely missed the point. And while all of that was going on, Facebook was working in the background to severely weaken data collection regulations.
For Further Insight:
Delta.com breach info: https://www.delta.com/response Sears/Kmart breach info: https://searsholdings.com/update Save Net Neutrality - act by April 23! https://www.battleforthenet.com/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Would you take your computer in for repair if you knew the technicians would be scanning your hard drive looking for anything suspicious while they had the hood up? It’s something that apparently we all need to be considering now. A recent lawsuit against a California doctor has revealed that the FBI has been paying Best Buy Geek Squad technicians to search for illegal content on the computers that were sent in for repairs. The relationship appears to go back at least 10 years.
Today I speak with Aaron Mackey, a staff attorney at the Electronic Frontier Foundation - the organization who discovered this connection through the use of Freedom of Information Act queries. I’ll also briefly update on the latest Facebook scandals and their attempts to address the massive privacy issues.
Aaron Mackey joined EFF in 2015 after moving from Washington, D.C. where he worked on speech, privacy, and freedom of information issues at the Reporters Committee for Freedom of the Press and the Institute for Public Representation at Georgetown Law. Aaron graduated from Berkeley Law in 2012, where he worked for EFF while a student in the Samuelson Law, Technology & Public Policy Clinic. Prior to law school, Aaron was a journalist at the Arizona Daily Star in Tucson, Arizona. He received his undergraduate degree in journalism and English from the University of Arizona in 2006, where he met his amazing wife, Ashley. They have two young children.
For Further Insight: Website: www.eff.org Twitter URL: https://twitter.com/aaron_d_mackey Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons - https://www.eff.org/deeplinks/2018/03/geek-squads-relationship-fbi-cozier-we-thought How to delete (or curtail) Facebook: https://firewallsdontstopdragons.com/its-time-to-delete-facebook/
At Facebook, it’s critically important to remember that you are not the customer, you’re the product. None of Facebook’s users pay a dime for its service and yet Facebook makes tens of billions of dollars a year. Facebook makes money off of you and your data. And as we’ve seen in the last two weeks, that business model is ripe for abuse. It’s long since time that we, as consumers, reject the current Internet business model: the collection and sale of phenomenal amounts of highly personal data.
In today’s episode, I’ll discuss the Cambridge Analytica scandal and why a Facebook VP believes that growth is good at any cost. I’ll spell out all the reasons why I’m deleting my Facebook account - and why you should strongly consider doing the same. At the very least, you should see what information Facebook has on you, so you can make an informed decision - I’ll tell you how to do that, too.
For Further Insight: Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons Further Reading: https://firewallsdontstopdragons.com/its-time-to-delete-facebook/
Your privacy and 4th amendments rights were dealt another blow last week, while no one was really looking. Congress opened the door to more warrantless surveillance by tacking on a little-known, unvetted bill to the monster spending legislation passed last week. This bill, benignly titled the Clarifying Overseas Use of Data (“CLOUD”) Act, removes the need for foreign countries to obtain a search warrant before demanding data from US companies. This bill was never debated. It wasn’t reviewed or marked up by a single committee. There were no hearings. But it is now law. David Ruiz, from the Electronic Frontier Foundation, helps us to understand the stark implications of this new law and together we explore how it can be used to completely circumvent your 4th Amendment rights.
David Ruiz is a writer covering NSA surveillance and federal surveillance policy for Electronic Frontier Foundation, a digital rights non-profit. As 2017 closes, he is deeply involved in covering the multiple bills before Congress that seek to reform or reauthorize Section 702 of the FISA Amendments Act, a law that is currently one of the U.S. government's most powerful surveillance tools. Previously, David worked as a journalist covering legal affairs for some of Silicon Valley's largest companies, including Google, Facebook, Twitter and Uber. He has also had his work featured in KQED, The East Bay Express, SFGate.com, The Sacramento Bee and KZSU Stanford 90.1 FM. Beyond writing, David also hosts a personal podcast called Death Knell, which explores the grieving process after death.
For Further Insight: Website: davidalruiz.com Follow on Twitter: https://twitter.com/davidalruiz Little Brother by Cory Doctorow Donate to the Electronic Frontier Foundation Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Have you ever really stopped to consider the sheer amount of data Facebook has on you? How long have you had your Facebook account? How many pictures have you posted and tagged? How many relationships have you had? Facebook has all that data, and much more - all your posts, your messages, your status changes, your likes, your comments, your profile (every version), your photos and videos… Facebook knows all. Do you have the Facebook app on your smartphone? Then it probably also has all of your phone contacts, ever. What many people don’t know is that you can actually download your entire Facebook dossier, and it’ll blow your mind. I’ll tell you how.
In other news, Intel has fixes coming soon for its chips while AMD chips have several newly discovered vulnerabilities. Alexa has been laughing at some of you, Apple has a nice web page to help you control what your kids can access, PayPal shares your data with over 600 companies, and the Geek Squad has been snooping around on your computers for the FBI.
For Further Insight:
Apple’s Families page: https://www.apple.com/families/ Download your Facebook data: https://www.facebook.com/help/302796099745838 Download your Google data: https://support.google.com/accounts/answer/3024190?hl=en Download your Twitter data: https://help.twitter.com/en/managing-your-account/how-to-download-your-twitter-archive Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
If a vote falls in a ballot box, but there’s no one there to see it - does it count? Marian Schneider, President of Verified Voting, explains why so many of our national voting systems have absolutely no way of being audited. Digital technology has been a wonderful boon for this world, but when it comes to something as fundamental to democracy as casting a vote, you simply must have a physical record that you can verify by hand if necessary. It may already be too late for the 2018 midterm elections, but we simply must have this fixed for 2020. We’ll tell you how you can get involved and make a real difference. This is a non-partisan issue that affects us all.
As the President of Verified Voting, Marian Schneider brings a strong grounding in the legal and constitutional elements governing voting rights and elections, as well as experience in election administration at the state level. Immediately before becoming President of Verified Voting, Marian served as Special Advisor and Deputy Secretary for Elections and Administration, to Pennsylvania Gov. Tom Wolf. Marian received her J.D. from The George Washington University, where she was a member of the Law Review, and earned her B.A. degree cum laude from the University of Pennsylvania.
For Further Insight:
Website: www.verifiedvoting.org Follow on Twitter: https://twitter.com/VerifiedVoting Facebook: https://www.facebook.com/VerifiedVoting/
Facebook has wants your face. Guess we should have seen that coming. While Facebook has been using face recognition for years now, it began notifying users in December of much broader use of this technology. Of course, they will tell you that you are the prime beneficiary, but by accepting this new feature you may be enabling Facebook to do much more. Tune in and I’ll tell you all about it, including how to turn it off!
We’ll also discuss how Apple is taking heat for moving some of its iCloud customers’ encryption keys to China, some great new privacy features coming soon to both Firefox and Android, and how you can see all your snail mail online (and maybe others can, too).
For Further Insight: How to turn off FB facial recognition: https://mashable.com/2018/02/28/how-to-turn-off-facebook-face-recognition/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Should you cover your webcam? Is anti-virus software worth the money? How do you know if you’ve been hacked? How do you know what software you can trust? We’ll cover all of these topics and more with Patrick Wardle, a computer security expert and ex-NSA hacker. While Patrick’s focus is Mac security, we also discuss PCs and mobile devices, and much more!
Patrick Wardle is the Chief Research Officer at Digita Security and founder of Objective-See. Having worked at NASA and the NSA, and as well as presented at countless security conferences, he is intimately familiar with aliens, spies, and talking nerdy. Patrick is passionate about all things related to macOS security and thus spends his days finding Apple 0days, analyzing macOS malware and writing free open-source security tools to protect Mac users.
For Further Insight:
Website: https://objective-see.com/ Twitter URL: https://twitter.com/patrickwardle Optional guest headshot: https://2016.zeronights.org/wp-content/uploads/2016/09/Patrick_Wardle.jpeg Support Patrick! https://www.patreon.com/objective_see Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
You know the best way to limit what malware can do on your system? Limit what YOU can do! Software on computers generally inherits the privileges of the current user. The problem is that the default account that comes with all computers has full administrator privileges - you can do anything. And whatever you can do, malware can also do. The solution is to always have a non-admin account that you use for day-to-day activities, reserving your admin account for very special tasks. According to experts, using a non-admin account could have mitigated 80% of critical Microsoft bugs in 2017.
I’ll also talk about Chrome’s new “ad filter” that falls well short, a bug on Apple devices that will allow a single character to crash your messaging apps, a new “turducken” Microsoft vulnerability, a nasty Skype bug that Microsoft claims takes “too much effort to fix”, and a new Facebook app feature called “protect” that should really be called “spy”.
For Further Insight: How to set up non-admin accounts: http://firewallsdontstopdragons.com/use-non-admin-account/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Do you know where your software’s been? If you’re downloading your apps and driver software from third parties, you may be getting more than you bargained for. Software download sites may be attaching unwanted extras to your installers in order to make money. And bad guys are also hacking these sites to trick you into downloading malware. I’ll tell you how to ensure your software is pristine.
In other news, Equifax admits that it lost even more sensitive information in the massive hack that affected over 145 million customers last year. Some key Apple source code in revealed that may help hackers attack your iPhone. And Lenovo announces critical bugs in the WiFi software on many of its ThinkPad laptops.
Our mobile phones today are chock full of private information and are constantly tattling about our whereabouts and activities. Most phones today have GPS, WiFi, Bluetooth, motion detectors, magnetic field detectors, microphones, cameras, and of course cellular radios. Some even have facial recognition built right in. With all this personal data and telemetry information, is it even possible to prevent tracking and information leakage? CLICK FOR FULL TRANSCRIPT OF INTERVIEW Today we discuss these topics and more with Daniel Davis from DuckDuckGo - a company dedicated to protecting your privacy. He and I discuss DuckDuckGo’s new privacy-focused smartphone app, along with other tips and techniques to guard your privacy on your mobile devices.
Daniel Davis is a Community Manager at DuckDuckGo, the Internet privacy company helping you take control of your personal information online. DuckDuckGo has its roots as the search engine that doesn't track you, and has expanded to protect you no matter where the Internet takes you. CLICK FOR FULL TRANSCRIPT OF INTERVIEW For Further Insight:
Website: https://duckduckgo.com Twitter URL: https://twitter.com/duckduckgo LinkedIn URL: https://www.linkedin.com/company/duck-duck-go
New DuckDuckGo mobile app: https://duckduckgo.com/app DuckDuckGo privacy guides: https://spreadprivacy.com/tag/device-privacy-tips/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
It's that time of year again: tax time. And that means it's also high season for identity thieves and scammers. Millions of people are affected by fake tax return filings every year. Phone and email scams lure unsuspecting victims to give away their money or identity. In today’s episode, I’ll tell you how to protect yourself.
In this week’s news, we’ll talk about why California won’t let you cover your license plate while parked, discuss yet another Adobe Flash bug, and explain how fitness trackers may be revealing covert military sites around the world.
For Further Insight:
Full blog article on tax return fraud: https://firewallsdontstopdragons.com/preventing-tax-return-fraud/ Think someone filed a fraudulent tax return in your name? Check this article: https://krebsonsecurity.com/2018/01/file-your-taxes-before-scammers-do-it-for-you/ Set up your MySSA account, even if you’re years away from retirement: https://www.ssa.gov/myaccount/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Data Privacy Day is upon us, and today is the day you take back your online privacy. And I’m going to help you do it. There’s no more standing on the sidelines and hoping someone else will fix this for you. You need to get off your butt and do something - and today is the day to do it.
Corporations have sold loads of compelling and powerful “free” tools and services. But if the product is free, then you are the product. Making us watch ads was all well and good, until those ads started watching us back. They’ve gone too far and now we are duty-bound to push back. Privacy is a human right and our privacy has never been more in jeopardy that right now. Now is the time to assert your rights and make your voices heard.
For Further Insight:
http://firewallsdontstopdragons.com/data-privacy-day-checklist/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Bitcoin has been all over the news lately, and rightly so. The digital “coin” was worth $1000 a year ago, and peaked at nearly $20,000 last month - an increase of 2000% in one year! And yet it’s lost almost half that value in the last two weeks. What is Bitcoin, anyway? Should you invest in it? How would you even do that if you wanted to?
I’ve invited Berkley security researcher Nick Weaver back to the program to answer these questions and many more! Nick’s an enlightened and entertaining guest, and he pulls no punches. And trust me, Nick has some very strong opinions on cryptocurrencies like Bitcoin and the crazy market dynamics surrounding them!
Nick Weaver received a B.A. in Astrophysics and Computer Science in 1995, and his Ph.D. in Computer Science in 2003 from the University of California at Berkeley. Although his dissertation was on novel FPGA architectures, he also was highly interested in Computer Security, including postulating the possibility of very fast computer worms in 2001. In 2003, he joined the International Computer Science Institute (ICSI), first as a postdoc and then as a staff researcher. His primary research focus is on network security, notably worms, botnets, and other internet-scale attacks, and network measurement. Other areas have included both hardware acceleration and software parallelization of network intrusion detection, defenses for DNS resolvers, and tools for detecting ISP-introduced manipulations of a user's network connection.
For Further Insight: Website: http://www1.icsi.berkeley.edu/~nweaver Follow on Twitter: https://twitter.com/ncweaver Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Despite being available for seven years, less than 10% of Google users have taken advantage of two-factor authentication. And yet, two-factor (or “two-step”) authentication is probably the best option today for most people to truly lock down their most important online accounts. I’ll tell you why it’s so effective and explain how you set it up.
We’ll also talk about the security news of the week including yet another Intel chip bug that could allow bad guys to hack your laptop in under 30 seconds, a high-tech targeted attack on WhatsApp and Signal users, a Netflix phishing campaign that’s trying to get your credit card info, and a nasty bit of Mac malware that can compromise all your web communications.
For further Insight: Sites that support two-factor auth: https://twofactorauth.org/ Setting up and using Google Authenticator: http://firewallsdontstopdragons.com/two-factor-authentication/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
When can anyone search through your most intimate records and belongings? When you throw them away, of course! The US Supreme Court has already ruled that the Fourth Amendment doesn’t protect your garbage can or recycle bin. Today we talk about a very interesting case in Oregon where local reporters turned the tables on the authorities, with very interesting results.
I’ll also update you on the latest WiFi security standards, a police department that awarded cybersecurity quiz takers with infected USB drives, and some welcome (but limited) changes to border search policies for electronic devices.
For Further Insight:
Portland dumpster diving: http://www.wweek.com/portland/article-1616-rubbish.html-2 Picking a good shredder: http://firewallsdontstopdragons.com/take-out-trash-securely/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
This week a couple of truly nasty computer hardware bugs were revealed by security researchers. Dubbed Meltdown and Spectre, the exploits take advantage of performance features found in Intel CPU chips as far back as 1995 and most other modern CPUs from AMD and ARM. Luckily, chip and software makers have been working in the background for months on fixes and mitigations, and many of them have already been deployed.
I’ll walk you through what these bugs are, what they actually mean to you, and what you can do to limit your exposure to them. Sadly, this is probably just the first of many hardware bugs that will be revealed - and hardware bugs are often very hard if not impossible to fix without simply replacing the entire device.
For Further Insight:
Official website for Meltdown/Spectre: https://meltdownattack.com/ Helpful list of affected systems and current state of fixes: https://gizmodo.com/check-this-list-to-see-if-you-re-still-vulnerable-to-me-1821780843 How to surf the web safely: http://firewallsdontstopdragons.com/browser-safety-choose-weapon/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Can law enforcement force you to divulge your passwords? How do you limit the scope of a search warrant on an iPhone? Is powerful encryption technology creating ‘warrant-free zones’ in cyberspace? Or are we actually in the Golden Age of Surveillance?
Today I speak with Andrew Crocker (Staff Attorney at the Electronic Frontier Foundation) about how our Constitutional rights work in cyberspace. We’ll talk about the locked iPhone in the Texas mass shooting case and discuss how it relates to the San Bernardino case from 2015 and the Crypto Wars of the 1990’s.
Andrew Crocker is a staff attorney on the Electronic Frontier Foundation’s civil liberties team. He focuses on EFF’s national security and privacy docket, as well as the Coders' Rights Project. While in law school, Andrew worked at the Berkman Center for Internet and Society, the American Civil Liberties Union’s Speech, Privacy, and Technology Project, and the Center for Democracy and Technology. He received his undergraduate and law degrees from Harvard University and an M.F.A. in creative writing from New York University.
For Further Insight: Website: https://www.eff.org/ Follow on Twitter: https://twitter.com/agcrocker, https://twitter.com/EFF
Donate to the EFF! https://supporters.eff.org/donate Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
It’s that time of year again - time for New Years Resolutions! While you consider going to the gym or maybe drinking a little less, we’re in the Information Age now - and that means you need to get your digital house in order, too!
In our first show of 2018, I’ll give you several great projects to improve your cybersecurity and privacy - some easy, some that will take some time - but all of them are crucial in today’s world of hackers and prying eyes. With these top tips, you’ll be protected against malware, computer crashes, mass surveillance, and overzealous marketers!
For Further Insight:
LastPass password manager: https://www.lastpass.com/ TunnelBear VPN: https://www.tunnelbear.com/ Firefox web browser: https://www.mozilla.org/en-US/firefox/ Backblaze cloud backup: https://www.backblaze.com/cloud-backup.html#af9kxp Signal secure messaging app: https://signal.org/ ProtonMail: https://protonmail.com/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
While you have some down time over the holidays, it’s a great opportunity to learn something new. I humbly suggest some cybersecurity and privacy “homework” that is both entertaining and educational! Like watching documentaries? Maybe you prefer to curl up by the fire with a good book? I’ve got you covered!
In the news this week, we have yet another staggeringly large data breach - though it’s not clear whether the bad guys found it before it was locked down. Is your iPhone 6 or 7 running slower than it used to? You may not be imagining it - Apple did it on purpose, and I explain why.
For Further Insight:
EFF’s Surveillance Self-Defense: https://ssd.eff.org/en Stay Safe Online: https://staysafeonline.org/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Net Neutrality suffered a severe but expected setback this week when the new FCC repealed the protections enacted in 2015 by a 3-2 party line vote, without any public hearings or investigation into flawed comment system. Call your Congressman!
Bitcoin value has soared in the last few months… but what the heck is a Bitcoin? I’ll explain what all the buzz is about. I’ll also tell you about massive database of 1.4 billion cracked passwords and give you several tips for buying those last-minute holiday gifts online!
For Further Insight:
11 Lies about Net Neutrality: https://www.popsci.com/net-neutrality-lies Net Neutrality isn’t dead: https://www.battleforthenet.com/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Many of the most important voices on the web today are individuals or small, low-budget organizations: human rights groups, investigative journalists, political dissidents, and fighters for democracy in repressive regimes. These groups don’t have the wherewithal to defend themselves against hackers and bad state actors that would prefer their voices not be heard.
Projects like Cloudflare’s Galileo and Google’s Shield help these at-risk groups to weather the heaviest of Internet storms, making sure that their voices cannot be silenced - without having to pay a dime. Doug Kramer, General Counsel for Cloudflare, helps us understand why these projects and groups are so important and how these programs help to protect their websites from attack.
Doug Kramer is General Counsel of Cloudflare, where he is responsible for managing the legal, policy, and trust and safety teams. In this role, Doug helps address the broad range of issues that touch the company's operations around the world. Prior to joining Cloudflare, Doug worked for seven years in senior positions in the Obama Administration, including as Deputy Assistant to the President and White House Staff Secretary, as the Deputy Administrator of the US Small Business Administration, and General Counsel at USAID. He previously worked in private practice in Washington, DC and Kansas City. He received Bachelor’s degree in Philosophy and English from Georgetown University and his J.D. from University of Chicago Law School.
For Further Insight:
Website: https://www.cloudflare.com Project Galileo: https://www.cloudflare.com/galileo/ Project Shield: https://projectshield.withgoogle.com/public/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
The gift-giving season is upon us and technology presents are always popular! But what you may not realize that the hackers and marketers out there are secretly hoping you’ll give your friends and family certain gifts, too!
In this special holiday episode, I’ll tell you about some of the best and the worst holiday gifts and accessories, from a security and privacy viewpoint. Thinking about giving someone a DNA analysis kit? You might want to think again! Which computers and smart devices are the most secure? And are there products I can buy to help make them more secure? You bet! Tune in - I’ve got you covered!
For Further Insight:
Read this before buying a DNA test: https://vitals.lifehacker.com/what-you-should-know-before-you-gift-someone-a-dna-test-1820774515 Best WiFi Routers: https://thewirecutter.com/reviews/best-wi-fi-router/ Setting your Router’s DNS to Quad9: http://firewallsdontstopdragons.com/evading-malware-quad9-dns/ Data and Goliath: https://www.schneier.com/books/data_and_goliath/ Little Brother: https://craphound.com/littlebrother/download/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
It’s been a rough week or so for Apple products, in particular their new Macintosh operating system version called High Sierra. A horrendous security bug was released last week that would let anyone have full, unfettered access to your computer - possible even remotely. That’s about as bad as it gets, folks. I’ll tell you all about it, including how to fix it once and for all.
We’ll also talk about some insidious HP computer software that is sending tracking information back to the mother ship without proper warning or consent, how some clever thieves have figured out how to steal cars by faking out your keyless entry system, and why now is the time to support Net Neutrality.
For Further Insight:
Fixing Apple’s horrible “root” bug: http://firewallsdontstopdragons.com/fixing-apple-root-bug/ Save Net Neutrality! https://www.battleforthenet.com/ John Oliver on Net Neutrality (includes adult language): https://www.youtube.com/watch?v=92vuuZt7wak Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
In the era of mass surveillance, our communications are being hoovered up, searched and stored by both corporations and intelligence agencies, without a warrant and with almost zero transparency. While we should be fighting for our right to privacy, creating and amending laws is hard and can take years. Dr Andy Yen is the CEO of ProtonMail, a secure email service based in Switzerland. Today we discuss why it’s important for even regular, “uninteresting” people to use a truly secure and private email service.
In the news this week, hundreds of top websites are tracking everything you do and Intel comes clean about a horrendous flaw in their secretive Management Engine that is part of every CPU they’ve made in the last 8 years. I’ll tell what you can do about it. Also, in the Tip of the Week, I’ll tell you about a new free service that can protect you from bad websites.
Dr. Andy Yen is the CEO and Co-Founder of Protonmail. Andy has over 8 years of experience in distributed computing for demanding particle physics applications. Andy was a researcher at CERN from 2009 to 2015, where ProtonMail's founding team met. He has a PhD in Physics from Harvard and a degree in Economics from Caltech.
For Further Insight:
Website: https://protonmail.com/ Twitter URL: https://twitter.com/ProtonMail LinkedIn URL: https://www.linkedin.com/in/andy-yen-03a9676 Quad9’s free DNS service protects you as you surf: http://firewallsdontstopdragons.com/evading-malware-quad9-dns/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
In our next installment of the Castle Defense 101 series, I’ll help you to choose the web browser that will keep you safe and protect your privacy. We’ll talk about the big four (Safari, Internet Explorer, Firefox and Chrome) as well as some others you’ve never heard of. I walk you through the things you need to consider when comparing these browsers and explain why the choice can be tricky. In the end, I’ll share my personal browser strategy and recommend several free browser add-ons that will make you even safer!
In the news: Facebook recommends that you upload your nude photos so that they can protect you and a cheeky New Zealand company has created a new automated service that enables some sweet revenge on all those spam emailers.
For Further Insight:
ExpressVPN Browser rankings: https://www.expressvpn.com/blog/best-browsers-for-privacy/ RE: Scam, spammer chatbot: https://www.rescam.org/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
The law that enables the warrantless collection and searching of the communications of US citizens is set to expire at the end of 2017. In today’s show, David Ruiz and I discuss several bills in Congress that attempt to curb the rampant abuses of this legislation (Section 702 of the FISA law). These long-overdue reforms go a long way towards restoring the principles of the Fourth Amendment and reclaiming basic civil liberties that we let slip away in fear after 9/11.
In the news this week, I’ll update you on the Reaper botnet and tell you about an effort to safeguard our elections systems before the next major election. I’ll also help you double-check your smartphone app permissions, making sure they don’t have any more access than they need to things like your camera, microphone, location, and contacts.
David Ruiz is a writer covering NSA surveillance and federal surveillance policy for Electronic Frontier Foundation, a digital rights non-profit. As 2017 closes, he is deeply involved in covering the multiple bills before Congress that seek to reform or reauthorize Section 702 of the FISA Amendments Act, a law that is currently one of the U.S. government's most powerful surveillance tools. Previously, David worked as a journalist covering legal affairs for some of Silicon Valley's largest companies, including Google, Facebook, Twitter and Uber. He has also had his work featured in KQED, The East Bay Express, SFGate.com, The Sacramento Bee and KZSU Stanford 90.1 FM. Beyond writing, David also hosts a personal podcast called Death Knell, which explores the grieving process after death.
For Further Insight: Website: www.davidalruiz.com Follow on Twitter: https://twitter.com/davidalruiz
Additional Resources:
Surveillance watchdog, Open Technology Institute: https://www.newamerica.org/oti/ End the Backdoor! https://www.endthebackdoor.com/ Lock Down Your LAN (IoT security): http://firewallsdontstopdragons.com/locking-internet-things-iot/ Protect yourself from nosy apps: http://firewallsdontstopdragons.com/smartphone-privacy-reining-nosy-apps/
We have a lot to catch up on! This week we discuss a Bad Rabbit, a grim Reaper, and some risky Russians. A new WannaCry-like ransomware is hitting Russia and Ukraine, Kaspersky Labs is dealing with a PR nightmare, and a new botnet is forming up that could make last year’s Mirai botnet that took down Netflix, Twitter and AirBND look like small potatoes. We also have some hopeful Android news and discuss how Bitcoin mining might save us from the ad-based web.
For Further Insight:
Before paying a ransom for your data, check this site! www.nomoreransom.org Full article on Reaper and securing your IoT devices: http://firewallsdontstopdragons.com/locking-internet-things-iot/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Web ads are the bane of our web-surfing existence, and yet people repeatedly reject the notion of paying for web content. How do we strike a balance? Today I speak at length with Ben Williams from Eyeo, the maker of one of the most popular web browser plugins of all time: AdBlock Plus. His company pioneered the notion of ‘acceptable ads’ and has returned some semblance of sanity to our web browsing experience, while preserving the revenue model that has allowed most web sites to remain free. We discuss the history and future of ads on the web, including the threat of ‘malvertising’ that can actually infect your computer.
In the news, I’ll get you up to speed on the hideous KRACK WiFi bug that affects billions of devices worldwide and explain why it’s not all it’s cracked up to be.
Ben Williams is from the greatest commonwealth of them all, Kentucky, and has lived in Berlin, Washington, DC and now in Bonn, Germany. Before joining eyeo, the company that makes Adblock Plus and Flattr, as communications director, he worked in non-profits mainly. He likes cooking, cassettes, records, writing and hiking.
For Further Insight: Website: https://adblockplus.org/ Follow on Twitter: https://twitter.com/B__e__n__w Linkedin: https://www.linkedin.com/in/benpwilliams/
Help updating your wifi router: https://www.lifewire.com/how-to-upgrade-your-wireless-routers-firmware-2487671 Download AdBlock Plus: https://adblockplus.org/ Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
In the second of my two-part interview with activist and author Cory Doctorow, we discuss how copy protection schemes (called “Digital Rights Management”) is trying to control how you watch, save, and share the digital movies, books and music you thought you owned. Cory explains how the World Wide Web Consortium (W3C) has caved into corporate interests and set the stage for serious future security issues with all web browsers.
In the news this week are some serious bugs in both Microsoft and Apple products, an update on an important court case involving the First Amendment and DreamHost, and long-overdue updates to the accepted ‘best practices’ on creating passwords (and an apology from the guy who caused us all so much grief). My tip of the week will speed up your web browsing and help protect your surfing privacy. Listen to Part 1: The Mouse That Scored, How Copyright Went Wrong Cory Doctorow is a science fiction author, activist, journalist and blogger — the co-editor of Boing Boing (boingboing.net) and the author of WALKAWAY, a novel for adults, a YA graphic novel called IN REAL LIFE, the nonfiction business book INFORMATION DOESN’T WANT TO BE FREE, and young adult novels like HOMELAND, PIRATE CINEMA and LITTLE BROTHER and novels for adults like RAPTURE OF THE NERDS and MAKERS. He works for the Electronic Frontier Foundation, is a MIT Media Lab Research Affiliate, is a Visiting Professor of Computer Science at Open University and co-founded the UK Open Rights Group. Born in Toronto, Canada, he now lives in Los Angeles.
For Further Insight: Website: www.craphound.com Follow on Twitter: https://twitter.com/doctorow Donate to the EFF! https://supporters.eff.org/donate Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons Book: Buy the Book: Walkaway: A Novel Additional Resources: Donate to the EFF! https://supporters.eff.org/donate Decentraleyes (privacy plugin for your browser): https://decentraleyes.org/
In the first of a two-part interview, activist and author Cory Doctorow explains how copyright law has failed to keep up with the realities of the modern digital world, potentially exposing consumers and researchers to crushing lawsuits and generally stifling innovation. Unlike physical books and LP records, every song or movie you stream, every eBook you read, every app you download is accompanied by long, arcane licensing agreements that we never read. Cory explains why this makes no sense and why we must update this body of law to protect consumers and unleash new products.
In the news, I’ll tell you about some password bugs in macOS, new security measures coming in Android’s Oreo release, and update you on the Equifax debacle. My Tip of the Week will help you avoid some nasty wireless vulnerabilities affecting literally billions of device (including laptops and smartphones). Listen to Part 2: Do We Own Any Media We Buy Anymore? Cory Doctorow is a science fiction author, activist, journalist and blogger — the co-editor of Boing Boing (boingboing.net) and the author of WALKAWAY, a novel for adults, a YA graphic novel called IN REAL LIFE, the nonfiction business book INFORMATION DOESN’T WANT TO BE FREE, and young adult novels like HOMELAND, PIRATE CINEMA and LITTLE BROTHER and novels for adults like RAPTURE OF THE NERDS and MAKERS. He works for the Electronic Frontier Foundation, is a MIT Media Lab Research Affiliate, is a Visiting Professor of Computer Science at Open University and co-founded the UK Open Rights Group. Born in Toronto, Canada, he now lives in Los Angeles.
For Further Insight: Website: www.craphound.com Follow on Twitter: https://twitter.com/doctorow Donate to the EFF! https://supporters.eff.org/donate Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons Buy the Book: Walkaway: A Novel
Just because you’re not paranoid doesn’t mean they’re not tracking you! And just because you feel that you have nothing to hide doesn’t mean you shouldn’t be worried about privacy. In today’s edition of my Castle Defense 101 series, I spell out why privacy matters and why companies and governments are hell bent on violating it. I’ll also explain the myriad ways by which your web habits are tracked and then give you several simple ways you can protect yourself.
Have you ever used the CCleaner app on your computer? If so, you’ll want to hear about a recent hack of this app’s installer and how to fix it.
For Further Insight:
Want to see what just one company knows about you? https://aboutthedata.com/ Why Privacy Matters: https://www.ted.com/talks/glenn_greenwald_why_privacy_matters How easy are you to track on the web? https://panopticlick.eff.org/
Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Will the robots rise up and take over? Or will Artificial Intelligence usher in a Utopian future? These concepts may have seemed like science fiction just 10-20 years ago, but visionaries like Elon Musk are warning us to take the notion of true AI very seriously. Like any powerful tool, the impact of AI will depend on how we develop and use it. In this week’s episode, I discuss the good, the bad and the ugly implications of AI and machine learning with technologist Albert Stepanyan.
We’ve learned more about the Equifax debacle since last week - I’ll catch you up on everything you need to know, including another important tip on how to monitor your credit and protect yourself from identity theft.
Albert Stepanyan is an A.I. Evangelist and Entrepreneur who loves code. He hasan entrepreneurial mindset with a passion for coding. Currently, he acts as the CEO and lead strategist at Develandoo, a software accelerator that is changing the way companies build products. His experience includes acting as CTO of a Munich-based Startup accelerator, lead engineer at various enterprises, and lead engineer or technical co-founder on more than 50 high-profile projects..
For Further Insight: Web site: www.cyberhulk.net Follow on Twitter: https://twitter.com/albertcyberhulk LinkedIn: https://www.linkedin.com/in/cyberhulk/
Further Reading: Equifax hack and response: http://firewallsdontstopdragons.com/equifax-hack-identity-theft/ Free annual credit reports: https://www.ftc.gov/faq/consumer-protection/get-my-free-credit-report Great article on what we need to do: https://www.schneier.com/blog/archives/2017/09/on_the_equifax_.html
Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
Equifax, one of the three major credit bureaus, was hacked - over 143 million U.S. accounts may have been leaked, making them much more vulnerable to identity theft and fraud. In this episode, I help you understand the potential impacts of this breach and give you several important actions you can take to protect yourself, including instituting a credit freeze on your account. Chris Romeo, CEO and Founder of Security Journey will help us understand the severity of this major news story and what we need to do to protect ourselves moving forward!
Is there such a thing as a good hacker? We will tackle what it takes to be a hacker - and why you actually might want to become one! Hackers are not all bad guys in hoodies hunched over a laptop. The hacker mentality is much more about a desire to tinker and solve puzzles, just applied to computers - and we need good hackers to help us combat the bad ones.
Chris Romeo is CEO and co-founder of Security Journey. His passion is to bring security belt programs to all organizations, large and small. He was the Chief Security Advocate at Cisco Systems for five years, where he guided Cisco’s Security Advocates, empowering engineers to “build security in” to all products at Cisco. He led the creation of Cisco’s internal, end-to-end security belt program launched in 2012. Chris has twenty years of experience in security, holding positions across the gamut, including application security, penetration testing, and incident response. Chris holds the CISSP and CSSLP.
Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons
For Further Insight: Website, www.securityjourney.com Follow on Twitter, @SecurityJourney Facebook, https://www.facebook.com/SecJourney/
Additional Resources: Freeze your credit at all three credit bureaus: Equifax, Experian and TransUnion. Get your free annual credit reports: https://www.ftc.gov/faq/consumer-protection/get-my-free-credit-report
Do you have backup copies of all your family photos and home videos? What about your tax documents and other financial data? Maybe you have a collection of priceless family history information that you’ve painstakingly compiled over many years. Unless you’re keeping copies of those files in multiple places (including at least one place outside your home!), you’re flying without a net. You’re one minor or major disaster away from losing them forever. Luckily, there are several simple and cost-effective solutions for automatically backing up all your files, photos, music and movies. In today’s show, part two of the Castle Defense 101 series, I’ll lay out a foolproof strategy for protecting your most precious digital data!
For Further Insight: Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons Backblaze offers an affordable, easy-to-use cloud backup solution - try it for free! For complete step-by-step help with backups and over 100 other tips, check out my book, Firewalls Don’t Stop Dragons.
There are bills before Congress to use drones along our border for mass surveillance and provisions to capturing all manner of biometric data when you travel. How will that data be used and who will have access? We break it all down for you and tell you how to voice your opinions. India McKinney and Adam Schwartz from the EFF are with me this week to explain several ways that your privacy rights are under serious attack at the U.S. border.
Your favorite PDF viewer is probably riddled with security vulnerabilities. I cover some recent news about Foxit PDF Reader and help you find safer alternatives with my Tip of the Week.
India McKinney is a Legislative Analyst with the Electronic Frontier Foundation, primarily focusing on privacy and surveillance issues in upcoming legislation. Prior to joining EFF, India spent over 10 years in Washington, DC as a legislative staffer to three members of Congress from California. Her work there largely focused on the appropriations process, specifically analyzing and funding programs in the Departments of Veterans Affairs, Homeland Security, and Justice. Her biggest legislative accomplishment was authorizing, funding and then naming a new outpatient VA/DoD clinic that will serve over 80,000 people.
Adam Schwartz is a Senior Staff Attorney at the Electronic Frontier Foundation. Adam works to ensure that new technologies expand instead of shrink our privacy, freedom of speech, and other civil liberties. Before joining EFF, Adam worked as a Senior Staff Attorney at the American Civil Liberties Union of Illinois. Adam graduated in 1995 from the Howard University School of Law.
For Further Insight: Website: https://eff.org/ Follow on Twitter: https://twitter.com/EFF Facebook: https://www.facebook.com/eff/
Additional Resources For You: Help me to help you! Visit: https://patreon.com/FirewallsDontStopDragons EFF’s Defending Privacy at the U.S. Border: A Guide for Travelers Carrying Digital Devices Sumatra PDF Reader: https://www.sumatrapdfreader.org/download-free-pdf-viewer.html
Jeffrey Ritter, author of “Achieving Digital Trust”, is back to help us understand the phenomenon of “fake news” and to explain why it’s not a new thing. We talk about how deception and misdirection have been around since the dawn of marketing and how we can train ourselves to navigate these treacherous waters in the Information Age.
Google is claiming they can match your offline, real-world purchases with their online ad tracking and the US government is proposing legislation that might finally being some much-needed security standards to the burgeoning “Internet of Things” marketplace.
Jeffrey Ritter currently serves as an External Lecturer at two of the world’s great universities for computer science, Johns Hopkins University and the University of Oxford, where he teaches graduate level courses in privacy engineering, information governance, and information security policy design. His career includes legal services to global corporations, leadership in the work of the United Nations and the American Bar Association, and ongoing academic research and writing on digital trust.
For Further Insight: Website: www.jeffreyritter.com Follow on Twitter: https://twitter.com/Jeffrey_Ritter LinkedIn: https://www.linkedin.com/in/jeffreyritter/
Further Reading: Can you trust what you hear? https://www.theverge.com/2017/4/24/15406882/ai-voice-synthesis-copy-human-speech-lyrebird Can you trust what you see? https://boingboing.net/2017/07/17/fake-obama-speech-is-the-begin.html Opt out of Google tracking: https://myaccount.google.com/privacy#activity Achieving Digital Trust: The New Rules for Business at the Speed of Light, is available on Amazon.com
Chris Romeo regales us with tales of safe-cracking robots, demonic car washes, possessed Teslas, and hacking of voting machines! Where did this all happen? At the hacker conferences, of course! We’ll help you understand how hackers really think and what they really do every year in Las Vegas at the DEFCON and BlackHat conferences.
Chris Romeo is CEO and co-founder of Security Journey. His passion is to bring security belt programs to all organizations, large and small. He was the Chief Security Advocate at Cisco Systems for five years, where he guided Cisco’s Security Advocates, empowering engineers to “build security in” to all products at Cisco. He led the creation of Cisco’s internal, end-to-end security belt program launched in 2012. Chris has twenty years of experience in security, holding positions across the gamut, including application security, penetration testing, and incident response. Chris holds the CISSP and CSSLP.
For Further Insight: Website, www.securityjourney.com Follow on Twitter, @SecurityJourney Facebook, https://www.facebook.com/SecJourney/
Additional Resources: Hackers: Heroes of the Computer Revolution by Steven Levy
WITH HOVER… YOUR PRIVACY IS INCLUDED Get 10% off your first domain name order!
In this final segment, we address the classic conundrum: law enforcement believes that your servers hold key information that would prevent a devastating terror attack, but revealing the information may violate the privacy of the client, or even other unrelated people. What do you do? Ladar Levison answers that very question. Prior to the interview, I explain what "secure email" really means and what it entails - it’s not nearly as simple as it might seem. And time is running out to submit your backup horror stories or maybe success stories! Send your tales to CareyParker@AmericaOutLoud.com for your chance to win a free copy of my book!
Ladar Levison serves as the founder, president, and chief executive of Lavabit, where he has worked the past 12 years. Lavabit was created because Mr. Levison believes that privacy is a fundamental, necessary right for a functioning, free and fair democratic society. Presently, Mr. Levison is focused on Lavabit’s Dark Mail Initiative, which aims to make end-to-end email encryption automatic and ubiquitous, while continuing to vigorously advocate for the privacy and free speech rights of all.
For Further Insight:
Website: www.lavabit.com Follow on Twitter: https://twitter.com/kingladar
Additional Resources:
Sign up for Lavabit secure email: https://lavabit.com/ Learn more about secure email: https://easycrypt.co/email-privacy-crash-course-part-1-introduction/
Ladar Levison is the CEO and Founder of Lavabit - a secure email service whose most famous customer was Edward Snowden. In part one of my two-part interview with Ladar, we discuss what happened when the FBI came knocking on his door, demanding access to his private security keys. Ladar shares some deep insights into the notion of privacy and intelligence gathering in this country, and how to strike the proper balance.
I will also update you on the hot news from two top hacker conferences, including a nasty Mac virus and a bug in Broadcom WiFi chips found in over 1 BILLION devices worldwide. And I will tell you about one of the oldest and best fact-checking sites on the web, and why they need your help.
For Further Insight:
Website: www.lavabit.com Follow on Twitter: https://twitter.com/kingladar
Additional Resources:
Sign up for Lavabit secure email: https://lavabit.com/ How to remove Flash: http://firewallsdontstopdragons.com/ditch-flash/ The web’s original fact checker: http://snopes.com/
Is trust just an emotion or is it more than that? In this week’s episode, I speak at length with Jeffrey Ritter: a lawyer, diplomat, researcher and author of the book “Achieving Digital Trust”. We get to the heart of what it means to trust, how trust is gained and lost, and how living in the Information Age has had such a profound impact on all of the above. Jeffrey has some deep insights on how we can cope with the high rate of data and decision making inherent in this modern life - and shares some interesting stories along the way!
Jeffrey Ritter currently serves as an External Lecturer at two of the world’s great universities for computer science, Johns Hopkins University and the University of Oxford, where he teaches graduate level courses in privacy engineering, information governance, and information security policy design. His career includes legal services to global corporations, leadership in the work of the United Nations and the American Bar Association, and ongoing academic research and writing on digital trust.
I’ll also tell you how you can share your financial account information more securely using aggregator accounts and how to win a free copy of my book by sending me your best computer backup stories! Send your stories to CareyParker@AmericaOutLoud.com.
For Further Insight: Website: www.jeffreyritter.com Follow on Twitter: https://twitter.com/Jeffrey_Ritter LinkedIn: https://www.linkedin.com/in/jeffreyritter/ Achieving Digital Trust: The New Rules for Business at the Speed of Light, is available on Amazon.com
What could be more crucial to a democracy than a voting system we can trust? Today I speak with Barbara Simons, President of VerifiedVoting.org, on why so many of our US election systems are vulnerable to hacking without leaving a trace. The solutions to these issues are well known and straightforward, and yet we can’t seem to come together in a unified way to implement them. We’ll discuss why the current systems are so bad, what needs to be done, and tell you what you can do to help.
I will also tell you about a new file backup tool from Google, 14M Verizon customer records found online with no protection, why you might be wary about leaving your keys lying around in plain sight, and how to improve your privacy with Post-It Notes!
Barbara Simons has been on the Board of Advisors of the U.S. Election Assistance Commission since 2008. She published Broken Ballots: Will Your Vote Count?, a book on voting machines co-authored with Douglas Jones. She also co-authored the report that led to the cancellation of Department of Defense’s Internet voting project (SERVE) in 2004 because of security concerns. In 2015 she co-authored the report of the U.S. Vote Foundation entitled The Future of Voting: End-to-End Verifiable Internet Voting, which included in its conclusions that “every publicly audited, commercial Internet voting system to date is fundamentally insecure.” Simons is a former President of the Association for Computing Machinery (ACM), the oldest and largest international educational and scientific society for computing professionals. She is President of Verified Voting and is retired from IBM Research.
Get 10% off your first domain name order!
For Further Insight: Web site: VerifiedVoting.org Follow on Twitter: https://twitter.com/VerifiedVoting
Further Reading: Does your state have proper voting machines? Do they have procedures for audits? https://www.verifiedvoting.org/ Google’s backup service: https://techcrunch.com/2017/07/12/google-launches-a-new-backup-sync-desktop-app-for-uploading-files-and-photos-to-the-cloud/ Change your Verizon PIN: https://www.verizonwireless.com/support/account-pin-faqs/ Copy a key with a photo: https://www.key.me/
Lose all your photos when your hard drive crashed? Did a cloud backup save your bacon when you had your phone stolen? Tell me your best backup stories for a chance to win a free copy of my book! Send them to CareyParker@AmericaOutLoud.com!
Passwords are the bane of our modern existence. Why the hell haven’t we figured out a better way to prove who we are? Today is the first in a series of educational shows that I’ve dubbed Castle Defense 101: Defending Your Digital Drawbridge. In our inaugural session, we’ll take a deep dive into the problem of passwords. What really makes a good password and how do I choose one? How can I possibly remember all these passwords? How often do I need to change my password? Why do we even need passwords, anyway - can’t we just use fingerprints or something? I will answer all of these questions and then some. I’ll even tell you why you should only ever know one single password! And finally, I’ll tell you how you can win a free copy of my book, Firewalls Don’t Stop Dragons! Domain names SAVE10% off your first order! For Further Insight: Some excellent password managers: LastPass , 1Password , Dashlane , Passwords Are Dead Long Live Passwords Firewalls Don't Stop Dragons: A Step-By-Step Guide to Computer Security for Non-Techies
Lawrence Abrams is the creator and CEO of Bleeping Computer, and he and I delve into the latest malware sweeping the globe called NotPetya (among other things). The supposed ransomware appears to be just plain mean, destroying all the data on your hard drive whether you pay the ransom or not. We’ll tell you what you need to know, including how to protect yourself and what to do if you think you might be infected. We talk about the usefulness of anti-virus software and give you the info you need to pick the right one for you. Finally, in my Tip of the Week, I explain why you need more than one account on your computer and how it can help to mitigate and isolate malware attacks.
Lawrence Abrams is the creator and owner of BleepingComputer.com. Lawrence’s area of expertise includes malware research, ransomware, and computer forensics.
For Further Insight: Web site: BleepingComputer.com Twitter: https://twitter.com/BleepinComputer Facebook: https://www.facebook.com/BleepingComputer LinkedIn: https://www.linkedin.com/in/lawrence-abrams-43074a10/
Further Reading: BleepingComputer’s how to remove malware Windows antivirus software: Malwarebytes, ESET, Emsisoft, Kaspersky Creating non-admin accounts: Windows or MacOS
Are you ready for the next YouTube, Netflix or Hulu? Then you need to fight to save net neutrality. Today I discuss the threatened gutting of the hard-fought net neutrality rules with Ernesto Falcon from the Electronic Frontier Foundation. The new FCC chairman, Ajit Pai, is looking to undo the protections put into place that would allow the next Internet startup to compete on a level playing field. Internet Service Providers would like to put their massive thumbs on the digital scale, tipping the advantage to companies that can afford to pay or even to favor their own content. Now that we have deep-pocketed incumbents, we need net neutrality rules to allow the new guys a chance to compete fairly.
In the news, we’ll discuss the 198M voter profiles that were left unprotected on the web, Microsoft’s abandonment of SMBv1 (that’s a good thing), Google’s move to respect your email privacy, and Girl Scouts becoming cyber experts! In my Tip of the Week, I’ll tell you how to avoid giving away too much information when needing to sign up to access web content.
Prior to joining EFF, Ernesto worked as a legislative staffer for two Members of Congress (2004-2010). He then became Vice President of Government Affairs at Public Knowledge where he advocated on behalf of consumers on copyright issues and broadband competition. During his tenure, Public Knowledge was successful in achieving one of the largest consumer victories in telecom policy by defeating AT&T’s merger with T-Mobile. The following year, PK and EFF scored a major victory for consumers by rallying the Internet community to defeat the Stop Online Piracy Act (SOPA). After eight years in Washington DC, he returned to his home state of California to go to law school at McGeorge School of Law in order to strengthen his digital rights advocacy. Now, as an attorney, he is excited to rejoin the fight for consumers and Internet freedom.
For Further Insight: Website: https://eff.org/ Follow on Twitter: https://twitter.com/EFFFalcon
Additional Resources: Tell the FCC not to gut net neutrality: https://DearFCC.org Tell your representatives, too: https://act.eff.org/action/tell-congress-don-t-surrender-the-internet FOSCAM security vulnerabilities: http://thehackernews.com/2017/06/online-ip-camera-hacking.html Disposable and shared email accounts: mailinator.com, 10minutemail.com, bugmenot.com
If you use public WiFi of any sort at the hotel, airport, or coffee shop (AND WHO DOESN'T), then you need to pay attention. A VPN could be a viable answer to protect your data and your devices. The other big challenge is your Internet Service Provider at home is probably capturing and selling your web browsing info - there is something you can do at home to protect yourself as well.
Dave Peck helped to create one of the best Virtual Private Network products on the market, and today he and I will discuss why you need a VPN and how to pick one. Dave is an independent software developer and co-founder of GetCloak.com, a very easy-to-use VPN service.
Not clicking on links apparently isn’t good enough anymore - now you can’t even hover over them! Also, Microsoft and Adobe have some software updates that fix critical bugs in Windows and Flash. And for the Tip of the Week, I’ll tell you why you really just need to uninstall Flash completely and how to do it. Transfer your domain names and save 40% in June! https://hover.com/transfermydomain
For Further Insight: Web site: https://davepeck.org/ Follow on Twitter: https://twitter.com/dangerdave
Further Reading: Why It’s Hard to Pick a VPN: https://davepeck.org/2017/04/16/why-its-hard-to-choose-a-vpn-provider/ Cloak VPN: https://www.getcloak.com/ TunnelBear VPN: https://www.tunnelbear.com/ VyprVPN: http://www.goldenfrog.com/vyprvpn/special/vpn-seasonal-special?offer_id=78&aff_id=3809 How to Uninstall Flash: http://firewallsdontstopdragons.com/ditch-flash/ How to Uninstall Shockwave: https://krebsonsecurity.com/2014/05/why-you-should-ditch-adobe-shockwave/
The Internet of Things will soon include cars... what could possibly go wrong? If all the cars on the road could tell each other what they were doing, would that make us safer? Maybe. But if your car is constantly broadcasting this information, that would also make it trivial to track you everywhere you go. Worse yet, any time you put something on a network, it is immediately a target for hackers. Crashing a computer is one thing; crashing a car is quite different, but this is quickly becoming a reality we have to deal with.
I will also tell you about an interesting new ‘travel mode’ feature from 1Password and talk about the Fireball adware that is already on over 250 million computers. We’ll wrap up with a new Tip of the Week, just in time for summer storm season!
Jamie Williams is a staff attorney at the Electronic Frontier Foundation, where she is part of the civil liberties team. Jamie focuses on the First and Fourth Amendment implications of new technologies. She also co-taught Internet Law at University of California Berkeley, School of Law. Jamie joined EFF in 2014 as a Frank Stanton Legal Fellow. Prior to joining EFF, Jamie clerked for Judge Saundra Brown Armstrong in the Northern District of California. Before her clerkship, she was a litigation associate at Paul Hastings LLP and an attorney law clerk at the Alameda County Public Defender. Jamie has a J.D. from the University of California, Berkeley School of Law (Boalt Hall) and a B.A. in journalism from the University of Wisconsin, Madison.
Mr. Kaiser has served on several nonprofit boards. He is currently the chair and a founding board member of SPINUSA, a national nonprofit based in Massachusetts, and has served on the Board of Trustees of the College of the Atlantic in Bar Harbor, Maine, and New Destiny Housing Corporation in New York City.
For Further Insight: Web site: www.eff.org Follow on Twitter: https://twitter.com/jamieleewi LinkedIn: https://www.linkedin.com/in/jamie-williams-60635555/
Further Reading: EFF article on v2v communication issues: https://www.eff.org/deeplinks/2017/05/danger-ahead-governments-plan-vehicle-vehicle-communication-threatens-privacy Automated License Plate Readers: https://www.eff.org/sls/tech/automated-license-plate-readers/faq#faq-Are-private-companies-using-ALPRs Who has your back? https://www.eff.org/who-has-your-back-2016 Finding and removing Fireball adware: http://computerfixguide.com/how-can-i-remove-fireball-malware-effectively/ Best UPS: http://thewirecutter.com/reviews/best-uninterruptible-power-supply-ups/
Do you have a “smart” TV? Or an Internet-connected baby monitor? Then you are a part of the Internet of Things (IoT)! Welcome to the world of everyday devices being connected to the network, allowing you to change the temperature of your home while traveling, check up on your dogs from work, and have a Bluetooth speaker that can also fetch tomorrow’s weather forecast. While there are lots of great uses for these devices, their security (or lack thereof) is making many of us vulnerable to attack.
Today I speak at length with John Graham-Cumming, CTO of Cloudflare, about the Internet of Things and how it’s already wreaking havoc on our world. We’ll tell you how to be smart about your smart devices!
We’ll also talk about the massive OneLogin password system breach and how hackers are increasingly turning to social media to target people for phishing attacks.
John Graham-Cumming is a computer programmer and author. He studied mathematics and computation at Oxford and stayed for a doctorate in computer security. As a programmer he has worked in Silicon Valley and New York, the UK, Germany and France and currently works at CloudFlare. His open source POPFile program won a Jolt Productivity Award in 2004.
He is the author of a travel book for scientists published in 2009 called The Geek Atlas and has written articles for The Times, The Guardian, The Sunday Times, The San Francisco Chronicle, New Scientist and other publications. In 2009 he successfully petitioned the British Government to apologize for the mistreatment of British mathematician Alan Turing. He is a licensed radio amateur.
For Further Insight: Website: http://jgc.org Follow on Twitter: https://twitter.com/jgrahamc
Additional Resources: Save 40% off next year’s domain registration (and get FREE privacy) https://hover.com/transfermydomain Social media increasingly used by hackers: https://www.nytimes.com/2017/05/28/technology/hackers-hide-cyberattacks-in-social-media-posts.html The Geek Atlas: https://www.amazon.com/Geek-Atlas-Places-Science-Technology/dp/0596523203 EFF’s page to help send comments to FCC on Net Neutrality: https://dearfcc.org/
Summer is upon us and for many of us that means travel - but before you even pack your bags, you need to listen to this podcast! In my second interview with Michael Kaiser (the Executive Director of the National Cyber Security Alliance), we discuss all the cyber security and privacy issues you need to consider: before you go and while you’re traveling. Going abroad this summer? There are even more things you need to consider well before you leave!
Also in this episode, I’ll tell you why Twitter’s new privacy policy changes are not in your favor, and how to fix it. Android’s next major software release, due out later this year, should finally address some of the major problems with getting updates. And I answer two questions from listeners on how best to deal with getting off mailing lists and tell you how secure Apple’s Message system really is.
Michael Kaiser joined the National Cyber Security Alliance (NCSA) in 2008. As NCSA’s executive director, Mr. Kaiser engages diverse constituencies—business, government and other nonprofit organizations—in NCSA’s broad public education and outreach efforts to promote a safer, more secure and more trusted Internet.
Mr. Kaiser leads NCSA in several major awareness initiatives, including National Cyber Security Awareness Month (NCSAM) each October, Data Privacy Day (Jan. 28) and STOP. THINK. CONNECT., the global online safety awareness and education campaign. NCSA builds efforts through public-private partnerships that address cybersecurity and privacy issues for a wide array of target audiences, including individuals, families and the education and business communities. In 2009, Mr. Kaiser was named one of SC Magazine’s information security luminaries.
Mr. Kaiser has served on several nonprofit boards. He is currently the chair and a founding board member of SPINUSA, a national nonprofit based in Massachusetts, and has served on the Board of Trustees of the College of the Atlantic in Bar Harbor, Maine, and New Destiny Housing Corporation in New York City.
For Further Insight: Web site: staysafeonline.org Follow on Twitter: https://twitter.com/MKaiserNCSA Facebook: https://www.facebook.com/staysafeonline/ LinkedIn: https://www.linkedin.com/in/michael-kaiser-3579752b
Additionally Important: NCSA’s Cyber Trip Advisor: https://www.stopthinkconnect.org/resources/preview/tip-sheet-ncsas-cyber-trip-advisor Undoing the new Twitter privacy settings: https://www.eff.org/deeplinks/2017/05/how-opt-out-twitters-new-privacy-settings Secure messaging apps: WhatsApp: https://www.whatsapp.com/ Signal: https://whispersystems.org/
The WannaCry virus hit over 200,000 computers in over 150 countries in a matter of days. While WannaCry spread quickly, it had some fatal flaws that prevented it from doing a lot more damage. However, these flaws will soon be fixed - Round 2 of this virus is already upon us. I speak with Michael Kaiser from the National Cyber Security Alliance to find the lessons we need to learn and what we need to do to protect ourselves from the next generations of this nasty malware. We also take a good look at who might be to blame for all of this and some thorny issues exposed by this attack. In other news, I’ll tell you how to find out if your HP laptop might be logging all of your keystrokes and how to fix it.
Michael Kaiser joined the National Cyber Security Alliance (NCSA) in 2008. As NCSA’s executive director, Mr. Kaiser engages diverse constituencies—business, government and other nonprofit organizations—in NCSA’s broad public education and outreach efforts to promote a safer, more secure and more trusted Internet.
Mr. Kaiser leads NCSA in several major awareness initiatives, including National Cyber Security Awareness Month (NCSAM) each October, Data Privacy Day (Jan. 28) and STOP. THINK. CONNECT., the global online safety awareness and education campaign. NCSA builds efforts through public-private partnerships that address cybersecurity and privacy issues for a wide array of target audiences, including individuals, families and the education and business communities. In 2009, Mr. Kaiser was named one of SC Magazine’s information security luminaries.
Mr. Kaiser has served on several nonprofit boards. He is currently the chair and a founding board member of SPINUSA, a national nonprofit based in Massachusetts, and has served on the Board of Trustees of the College of the Atlantic in Bar Harbor, Maine, and New Destiny Housing Corporation in New York City.
For Further Insight: Web site: staysafeonline.org Follow on Twitter: https://twitter.com/MKaiserNCSA Facebook: https://www.facebook.com/staysafeonline/ LinkedIn: https://www.linkedin.com/in/michael-kaiser-3579752b
Additionally Important: 10% off your first domain name order! https://www.hover.com/welcome/Firewalls HP key logger: https://www.bleepingcomputer.com/news/security/keylogger-found-in-audio-driver-of-hp-laptops/ Got ransomware? Go here before paying! https://www.nomoreransom.org/ Start With Security: https://www.ftc.gov/tips-advice/business-center/guidance/start-security-guide-business Dept Homeland Security C-Cubed: https://www.dhs.gov/ccubedvp
The WannaCry ransomware worm spread across the planet is a matter of hours, infecting over 200,000 computers in just a matter of hours - this included hospitals in the UK, phone service in Spain, and even a Russian ministry. The malware was stopped dead by one security researcher who basically got lucky. In today’s show, I will explain what WannaCry is and how to ensure that you are protected again this nasty bug and others just like it that will surely be coming. My guest today is security research Nick Weaver who will help us understand what the real threats are for most people - it’s not just hackers! He explains why we’re vulnerable and gives us a lot of great and timely tips on how to protect your computers and mobile devices (spoiler alert: you need to ditch Android and go with Apple).
Nicholas Weaver received a B.A. in Astrophysics and Computer Science in 1995, and his Ph.D. in Computer Science in 2003 from the University of California at Berkeley. Although his dissertation was on novel FPGA architectures, he also was highly interested in Computer Security, including postulating the possibility of very fast computer worms in 2001. In 2003, he joined the International Computer Science Institute (ICSI), first as a postdoc and then as a staff researcher. His primary research focus is on network security, notably worms, botnets, and other internet-scale attacks, and network measurement. Other areas have included both hardware acceleration and software parallelization of network intrusion detection, defenses for DNS resolvers, and tools for detecting ISP-introduced manipulations of a user's network connection.
For Further Insight: Website: http://www1.icsi.berkeley.edu/~nweaver Follow on Twitter: @ncweaver
Further Reading: Article on WannaCry by our guest: https://lawfareblog.com/crying-about-wannacry-notable-features-newest-ransomeware-attack Microsoft help on WannaCry malware: https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/ John Oliver on Net Neutrality: https://www.youtube.com/watch?v=92vuuZt7wak Tell the FCC how you feel about Net Neutrality! http://gofccyourself.com/
This week I’ll tell you why you should not be using Microsoft’s Edge Browser, how to find out if you were bitten by a very clever Google Docs phishing scheme, and why you can’t believe every voice you hear. Along the way, I’ll give you my recommendations on the best web browser to use as well as how to revoke permissions you may have granted to Twitter, Facebook and Google over the years that may be leaving your vulnerable. Finally, I’ll tell you how Intel finally found and fixed a flaw in their backdoor chip for managing PC’s, how to see if your computer is affected, and why backdoors can let the bad guys in just as easily as the good guys.
For Further Insight:
Lyrebird: https://soundcloud.com/user-535691776 Google app permissions: https://myaccount.google.com/permissions Twitter app permissions: http://lifehacker.com/5905299/clean-our-your-twitter-app-permissions-as-part-of-your-spring-cleaning-regimen Facebook app permisssions: http://lifehacker.com/5904590/clean-out-your-facebook-app-permissions-as-part-of-your-spring-cleaning-regimen Intel chip security bulletin: https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr ShieldsUp! https://www.grc.com/x/ne.dll?bh0bkyd2