• Get the App
  • Moon FM - The Ultimate Podcast App
  • Get the App
Firewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast

Carey Parker

A Podcast on Computer Security & Privacy for Non-Techies

  • 1 hour 21 minutes
    Use a Secure Wi-Fi Router

    Probably the single most important device on your home network in terms of security is your Wi-Fi router. In most cases, it’s the only thing between all your networked devices and the Internet’s bad guys. It’s crucial that you’re using an updated (and update-able) device from a reputable maker. I’ll explain why it’s important and how to pick a good router.

    In other news: Plex media server urges users to update their software immediately; Meta settles a lawsuit for $18B and promises changes for kids; 153M personal ID cards were stolen and are for sale; ChatGPT has a new plugin to read and manage your iMessages; study shows Windows apps tattling on users; researcher shows how secret ballots can be re-identified; US Senator asks NSA to publish info on how to choose and use a good VPN; Flock vigilantism and vandalism soars; researchers find blatant back doors in cheap Chinese routers.

    Article Links

    News Briefs

    1. Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws: https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html
    2. Meta to pay $18 billion in teen social media addiction settlement: https://proton.me/blog/meta-teen-addiction-settlement

    Full Stories

    1. Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof: https://gizmodo.com/identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof-2000806437
    2. ChatGPT’s iMessage plugin opens a backdoor in Apple Messages: https://proton.me/blog/chatgpt-apple-messages
    3. Hidden Tracking in Windows Apps: https://adguard.com/en/blog/how-desktop-apps-watch-you-research.html
    4. An Algorithmic Failure Beneath the Secret Ballot: https://blog.citp.princeton.edu/2026/08/03/an-algorithmic-failure-beneath-the-secret-ballot
    5. Confused about which VPN is right, US senator asks the NSA for guidance: https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns
    6. Vigilantism comes for Flock: https://this.weekinsecurity.com/vigilantism-comes-for-flock
    7. Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware: https://www.tomshardware.com/tech-industry/cyber-security/security-researchers-find-surveillance-implants-in-chinese-made-routers-sold-worldwide-three-different-backdoor-like-implants-hidden-in-firmware

    Further Info

    • Phase 2 is under way! : https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • Jellyfin media server: https://jellyfin.org/ 
    • Tailscale: https://tailscale.com/ 
    • Proton blog: https://proton.me/blog 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 

    Table of Contents

    • 0:00:07: Intro
    • 0:02:26: 6th Edition update
    • 0:04:15: News rundown
    • 0:06:17: Plex media server critical fixes
    • 0:08:47: Meta’s $18B lawsuit loss
    • 0:10:40: 153M ID’s for sale
    • 0:19:11: ChatGPT plugin for iMessage
    • 0:27:28: Windows app tracking
    • 0:38:23: Using AI to reveal your voting
    • 0:48:42: Senator requests NSA VPN guidance
    • 0:53:20: Rise in Flock vandalism
    • 1:01:17: Chinese routers with built-in backdoors
    • 1:09:48: Tip of the Week
    • 1:19:21: Phase 2 reminder
    • 1:20:14: Patron podcast preview
    • 1:20:34: Looking ahead
    7 September 2026, 11:55 am
  • 1 hour 15 minutes
    Supply Chain Attacks

    Software apps today are a hodgepodge of libraries, software development kits, and third party code, all stitched together like Frankenstein’s monster. Furthermore, software developers use common tools to create and deploy this software. The bad guys have figured out that by compromising one of these third party components or the tools used to create the products, they can instantly infect hundreds or thousands of products that all share the same underlying resources. This is a supply chain attack. Today we’ll discuss these single points of failure, how to identify them ahead of time and try to prevent these sorts of attacks with Cassie Crossley, CEO and co-founder of VulNow.

    Interview Notes

    • Cassie Crossley: https://www.linkedin.com/in/cassiecrossley/ 
    • VulNow company website: https://vul.now/
    • VulNow’s Pre-CVE database: https://precve.vulnow.com/ 
    • CyBeats company website: https://www.cybeats.com/
    • Software Supply Chain Security (book): https://www.oreilly.com/library/view/software-supply-chain/9781098133696/ 
    • Proton blog on supply chain security: https://proton.me/business/blog/supply-chain-attack 
    • Malus AI re-write tool: https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/ 
    • xkcd on Dependency: https://xkcd.com/2347/ 
    • Updated dependency diagram: https://www.grc.com/SN/1078.jpg 

    Further Info

    • Phase 2 has begun!! : https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support the mission: https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 
    • Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    • 0:00:14: Intro
    • 0:00:35: Phase 2 reminder
    • 0:01:52: Interview setup
    • 0:06:05: What is VulNow?
    • 0:08:34: What software is vulnerable to supply chain attacks?
    • 0:13:16: Have you heard of AI clean room coding?
    • 0:15:34: How do SW supply chain attacks work?
    • 0:21:21: How do we identify the weak points?
    • 0:34:24: What are SBOM’s and how do they work?
    • 0:43:45: What is needed beyond SBOMs?
    • 0:50:32: Can tools reveal the contents of SW?
    • 0:56:13: How do we encourage SBOM creation?
    • 1:01:35: As consumers, how do we know who to trust?
    • 1:06:09: What’s next for you?
    • 1:08:46: Wrap-up
    • 1:13:23: Patron podcast preview
    • 1:14:19: Looking ahead
    31 August 2026, 11:55 am
  • 1 hour 6 minutes
    Digital Citizen: Phase 2

    As part of my celebration of the upcoming 500th podcast, I’m launching Phase 2 of my “cyber neighbor” campaign to both help as many people be more secure and private as possible, but to also learn from this experience so I can improve these campaigns in the future. In particular, as I write the 6th edition of my book, I’m funneling this feedback into improving those Tips, as well.

    In the news: Flock considered utilizing ride share and delivery vehicles to expand their ALPR network; judge rules ‘tower dump’ warrants unconstitutional; BMW’s show Spider-Man ads; hackers reuse expired domains for scams and malware; US warns of more PLC attacks; US proposal would allow private companies to launch cyber attacks on foreign groups; terabytes of credentials stolen in supply chain attack; customer downloads his 515-page McDonald’s dossier; AI agent hacks gym site to book a class; town claims Flock reactivated cameras without notice; and Chrome trials new device-bound session credentials.

    Article Links

    News Briefs

    1. Flock wanted to put license plate cameras on 350,000 Uber and Lyft dashcams: https://www.techspot.com/news/113407-flock-wanted-put-license-plate-cameras-350000-uber.html
    2. ‘Tower dump’ warrants ruled unconstitutional: https://thehill.com/regulation/court-battles/6013559-mississippi-judge-declares-towers-dumps-unconstitutional
    3. BMWs are showing a commercial at startup: https://boingboing.net/2026/08/06/bmws-are-showing-a-spider-man-movie-ad-at-startup.html
    4. Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware: https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html

    Full Stories

    1. US warns of AI-powered attacks on Siemens PLCs in critical infrastructure: https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure
    2. In a first, US will allow some private firms to carry out cyberattacks: https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks
    3. Terabytes of credentials leaked in massive supply-chain attack: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack
    4. McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There: https://www.wired.com/story/mcdonalds-built-a-515-page-dossier-on-me-it-says-ill-never-leave
    5. Told to book a gym class, an AI agent hacked the site instead to move its user up the waitlist: https://the-decoder.com/told-to-book-a-gym-class-an-ai-agent-hacked-the-site-instead-to-move-its-user-up-the-waitlist
    6. Littleton claims Flock reactivated its cameras without notifying the town: https://www.lowellsun.com/2026/07/31/littleton-claims-flock-reactivated-its-cameras-without-notifying-the-town
    7. Chrome adopts what may be the best protection yet against account takeovers: https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-account-takeovers
    8. Tip of the Week: https://firewallsdontstopdragons.com/digital-citizen-phase-2/ 

    Further Info

    • Phase 2: https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • NoALPRs: https://noalprs.com/ 
    • FlockYou project: https://github.com/colonelpanichacks/flock-you 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:26: Public service announcements
    • 0:03:20: News rundown
    • 0:05:25: Flock in Uber, Lyft, delivery vehicles
    • 0:07:13: Tower dump warrants ruled unconstitutional
    • 0:08:33: Some BMW’s show Spider-Man ad
    • 0:10:49: Hackers use expired domains for scams
    • 0:13:24: US warns of AI attacked on PLCs
    • 0:18:05: US authorizes private cyber attacks
    • 0:24:53: Terabytes of credentials leaked in supply chain attack
    • 0:32:13: McDonald’s customer dossier
    • 0:39:44: AI agent hacks gym site
    • 0:45:22: Town claims Flock reactivated its cameras
    • 0:49:39: Google trialing device-bound session cookies
    • 0:57:00: Tip of the Week
    • 1:04:31: Wrap-up
    • 1:05:22: Patron podcast preview
    • 1:05:45: Looking ahead
    24 August 2026, 11:55 am
  • 1 hour 27 minutes
    DEF CON 34

    It’s August, which means it’s time for Hacker Summer Camp once again! I flew out to a sweltering Las Vegas, Nevada, to attend two of the three major cybersecurity (“hacker”) conferences: BSides and DEF CON. I had an amazing week, spending time with new and old friends, meeting some of the people I’ve interviewed in person, lining up more podcast guests, and having wonderfully stimulating conversations with very smart people. While at DEF CON, I managed to record four mini interviews with Bob Lord, Naomi Brockwell, Josh Corman and the Dark Tangent himself, Jeff Moss. I will try to give you some idea what these conferences are like as we discuss several important and timely topics.

    Interview Notes

    • Hacklore: https://www.hacklore.org/ 
    • Naomi Brockwell (NBTV): https://www.nbtv.media/ 
    • Ludlow Institute: https://www.ludlowinstitute.org/ 
    • Surveillance Accountability Act: https://www.surveillanceaccountability.com/ 
    • UnDisruptable27: https://u27.org 
    • I Am the Cavalry, BSides 2026 (Monday): https://www.youtube.com/watch?v=r4C8stKbxBM 
    • BSides IATC schedule: https://bsideslv.org/schedule#IATC 
    • Cliff Stoll talk: https://www.youtube.com/live/_uYQr8hfpbI?t=13292s 
    • DEF CON: https://defcon.org/
    • DEF CON 20 Documentary: https://archive.org/details/DEFCON20Documentary 
    • DEF CON 33 Documentary: https://www.youtube.com/watch?v=pb0kJXSy64E 

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support the mission: https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:50: Hacker Summer Camp
    • 0:11:30: Interview preface
    • 0:14:26: Bob Lord
    • 0:21:18: Bob afterword
    • 0:24:08: Naomi intro
    • 0:26:09: Naomi Brockwell
    • 0:35:51: Naomi afterword
    • 0:40:58: Josh intro
    • 0:42:58: Josh Corman
    • 0:56:01: Josh afterword
    • 1:01:08: Jeff intro
    • 1:03:00: Jeff Moss
    • 1:23:12: Jeff afterword
    • 1:24:30: Wrap-up
    • 1:26:20: Patron podcast preview
    • 1:26:45: Phase 1 still going
    • 1:27:13: Looking ahead
    17 August 2026, 11:55 am
  • 1 hour 13 minutes
    AI Tech Support: Trust, but Verify

    One of the most underrated uses for modern chatbots, in my estimation, is tech support. I don’t mean the chatbots offered by product websites, I mean using one of the “frontier” model bots to troubleshoot problems via chat conversations. They are extremely good at this – and they are infinitely patient and available 24/7. Today I’ll give you tips on how to try this for yourself. I think you’ll be amazed.

    In the news: DEF CON bans Meta-style glasses; US military warns of personal cell phone use; GDPR suit over 1741 “partners” in share consent; US bans future robovacs; more TV streaming stick bad behavior; FTC sues Hims & Hers over health data sharing; Android “after call” ads malware; user’s private AI chats leaked; clever, annoying Mac malware; HuggingFace breached by OpenAI agent; Iran blamed for hacking 30 Minnesota water utilities.

    Article Links

    News Briefs

    1. DEF CON bans Meta-style ‘pervert glasses’: https://www.theregister.com/security/2026/07/28/def-con-bans-meta-style-pervert-glasses/5279763
    2. US military may require some troops in Mideast to surrender cell phones: https://www.reuters.com/business/media-telecom/us-commander-warns-troops-their-videos-help-iran-sources-say-2026-07-29

    Full Stories

    1. 1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed: https://noyb.eu/en/1741-informed-consents-one-click-gdpr-complaint-against-dictcc-filed
    2. Almost all future robot vacuums were just banned by the US government: https://9to5mac.com/2026/07/29/almost-all-future-robot-vacuums-were-just-banned-by-the-us-government
    3. Read This Before You Buy That TV Streaming Stick: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick
    4. FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap: https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-for-allegedly-sharing-patients-medical-data-with-advertisers-meta-and-snap
    5. Aftercall ads are driving Android users crazy: https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy
    6. Users’ private Claude chats revealed with simple Google search: https://appleinsider.com/articles/26/07/28/privacy-is-dead-personal-ai-prompts-indexed-by-google-search
    7. This new Mac malware won’t let you use your computer until you surrender your password: https://www.digitaltrends.com/computing/this-new-mac-malware-wont-let-you-use-your-computer-until-you-surrender-your-password
    8. OpenFace: The Hugging Face Breach and What to Do About It: https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-it
    9. Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack
    10. Tip of the Week: https://firewallsdontstopdragons.com/ai-tech-support-trust-but-verify/

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • Update All the Things! https://firewallsdontstopdragons.com/update-all-the-things/ 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 
    • Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:40: PSA: Update!!
    • 0:01:36: Countdown to 500
    • 0:02:37: News Briefs
    • 0:06:46: News rundown
    • 0:08:50: GDPR complaint about 1741 “partners”
    • 0:12:45: US bans foreign robots
    • 0:16:13: Malicious, cheap streaming sticks
    • 0:23:33: FTC sues Hims/Hers for sharing health data
    • 0:27:34: Android “after call” ads
    • 0:32:17: Private Claude chats in search results
    • 0:38:18: Cleverly annoying Mac malware
    • 0:45:31: Hugging Face breach lessons
    • 0:54:08: Many US water utilites attacked by Iran
    • 0:59:39: Tip of the Week
    • 1:11:56: Wrap up
    10 August 2026, 11:55 am
  • 1 hour 11 minutes
    Top Cyber Threats 2026

    With so many cyber threats to report on, it’s easy to get lost in the weeds. It’s good to take a step back and look at the big picture every so often. Today, I’ll review some of the top security and privacy threats with investigative cybersecurity journalist Zack Whittaker from Tech Crunch. We’ll talk about age verification, mercenary spyware, surveillance capitalism, critical infrastructure hacks, AI and the proliferation of tracking in public spaces – and more!

    Interview Notes

    • This Week in Security: https://this.weekinsecurity.com/ 
    • Zack at TechCrunch: https://techcrunch.com/author/zack-whittaker/ 
    • Zack’s homepage: https://zackwhittaker.com/ 
    • Project Sunshine: https://projectsunshine.org/about 
    • Filtr (Wipr) ad blocker for iPhone: https://techcrunch.com/2026/06/04/filtr-is-a-new-privacy-tool-that-blocks-ads-in-almost-every-iphone-and-mac-app/ 
    • Apple iPhone security: https://ssd.eff.org/module/how-to-get-to-know-iphone-privacy-and-security-settings 
    • Google Android security: https://ssd.eff.org/module/how-to-get-to-know-android-privacy-and-security-settings 
    • Zach’s list: 404media.co, metacurity.com, indicator.media, krebsonsecurity.com, techdirt.com, garbageday.email, thehandbasket.co, karlbode.com, risky.biz, lawdork.com, citationneeded.news, erininthemorning.com 

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 

    Table of Contents

    • 0:00:12: Intro
    • 0:02:08: Interview setup
    • 0:03:03: What is age gating?
    • 0:07:45: What are the risks of age verification?
    • 0:15:30: How do ads get our data?
    • 0:21:33: How can ad data be abused?
    • 0:28:11: What is mercenary spyware?
    • 0:34:53: How do you protect against spyware?
    • 0:41:04: How dangerous are nation-state attacks?
    • 0:43:54: How do we defend against foreign attacks?
    • 0:47:43: Does AI benefit defenders or attackers more?
    • 0:51:24: How do we mitigate public mass surveillance?
    • 0:57:01: What else worries you?
    • 1:00:34: What’s next for you?
    • 1:02:30: Wrap-up
    • 1:07:50: Patron podcast preview
    • 1:09:02: Looking ahead
    3 August 2026, 11:55 am
  • 1 hour 14 minutes
    Update All the Things

    Over the last 2-3 months, large software makers such as Microsoft have been releasing tons of fixes for vulnerabilities in their apps and operating systems. Did their software suddenly get a lot worse? No. They’re using the latest AI tools to find these bugs that humans missed and that have been lurking in their software for months or even years – and they’re fixing them. That’s great news… but these fixes won’t do you any good unless you install them. Bad guys are using these same tools to exploit these bugs. There’s never been a better time to update all your devices’ software.

    In other news: a hidden car device leaves many cars vulnerable to hacking; most fitness wearables don’t encrypt users’ data end-to-end; Iran is tracking US military phones; CBP accuses citizen of wiping phone using “duress” password; US says Iran is hacking critical infrastructure; US also warns that Russia and China are hacking small office routers; US judge denies broad “stringray” warrant in Ohio; LG to ban proxy apps on their TVs; Maine librarians teach patrons how to remove AI features.

    Article Links

    1. A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now
    2. Most fitness wearables lack end-to-end encryption and don’t disclose government data demands, says EFF: https://this.weekinsecurity.com/most-fitness-wearables-lack-end-to-end-encryption-and-lack-transparency-reports
    3. Financial Times: US military smartphones targeted through roaming and ad tech: https://harrigan.house.gov/media/in-the-news/financial-times-us-military-smartphones-targeted-through-roaming-and-ad-tech
    4. US accuses American of allegedly wiping his phone using a ‘duress’ password during border search: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search
    5. US government says Iran-linked hackers are disrupting American water and energy providers: https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers
    6. The US government warns that Russia state hackers are coming after your router: https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router
    7. U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents: https://this.weekinsecurity.com/us-judge-denied-feds-month-long-warrant-to-snoop-on-the-phones-of-thousands-of-ohio-residents
    8. LG to Ban Residential Proxies from Smart TV Apps: https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps
    9. These Maine librarians are helping patrons resist AI and Big Tech: https://www.bangordailynews.com/2026/07/02/midcoast/midcoast-culture/maine-librarians-are-helping-patrons-resist-ai-joam40zk0w
    10. Tip of the Week: https://firewallsdontstopdragons.com/update-all-the-things/ 

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • Zero-Day documentary: https://www.imdb.com/title/tt5446858/ 
    • EFF’s Rayhunter: https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying 
    • This Week in Security: https://this.weekinsecurity.com/ 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:25: Phase 1 reminder
    • 0:04:09: Quick news bites
    • 0:05:54: News rundown
    • 0:07:35: Hidden card device vulnerable to hacks
    • 0:15:00: Most fitness wearables lack E2EE
    • 0:19:19: Iran tracking military smartphones
    • 0:26:58: US accuses citizen of wiping phone with “duress” password
    • 0:33:15: US Gov’t claims Iran attaching infrastructure
    • 0:38:03: Russia attacking US routers
    • 0:42:37: Judge denies “Stingray” warrant
    • 0:49:09: LG TV to ban proxy network apps
    • 0:53:57: Maine librarians help patrons remove AI
    • 1:00:54: Tip of the Week
    • 1:10:18: Reminders
    • 1:11:17: Patron podcast preview
    • 1:11:49: Looking ahead
    27 July 2026, 11:55 am
  • 1 hour 6 minutes
    Digital Provenance

    With modern AI tools, how do we know which images and videos are real and which ones are generated? Wouldn’t it be helpful to have some digitally verifiable way to tell where something came from and whether it has been altered? Turns out, that technology already exists. It’s open and free to use, and it’s supported by many technology companies. I’ll be digging into all the details of the Coalition for Content Provenance and Authenticity (C2PA) with Jacobo Castellanos from Witness.org.

    Interview Notes

    • Jacobo Castellanos: https://www.witness.org/portfolio_page/jacobo-castellanos/ 
    • Witness: https://witness.org 
    • Coalition for Content Provenance and Authenticity: https://c2pa.org/ 
    • Content Authenticity Initiative (CAI): https://contentauthenticity.org/ 
    • Content Credentials explainer: https://www.linkedin.com/help/linkedin/answer/a6282984 
    • The Guardian Project: https://guardianproject.info/ 
    • Creator Assertions Working Group: https://cawg.io/ 
    • ProofMode tool: https://proofmode.org/ 
    • C2PA Content Credentials and the Surveillance Risk: https://library.witness.org/product/c2pa-privacy/ 
    • How C2PA works: https://contentauthenticity.org/how-it-works 

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 

    Table of Contents

    • 0:00:13: Intro
    • 0:01:17: Interview prep
    • 0:02:39: Lingo
    • 0:04:10: What is Witness.org?
    • 0:06:22: What is the purpose of C2PA?
    • 0:09:26: How does C2PA work?
    • 0:17:28: Is C2PA embedded in our devices, too?
    • 0:19:57: Are there fees or licensing required to use C2PA?
    • 0:22:41: Does C2PA info include creator information?
    • 0:26:41: As a user, how do I experience C2PA info?
    • 0:30:54: Can C2PA be used to undo changes?
    • 0:32:46: What are C2PA’s limitations?
    • 0:38:36: Does C2PA report data to third parties?
    • 0:41:07: Could C2PA be used to limit information?
    • 0:45:27: Can C2PA info be removed? Reattached?
    • 0:48:35: Is here a global C2PA content registry?
    • 0:49:53: How do certificate authorities work?
    • 0:53:37: Are any laws requiring provenance info?
    • 0:56:56: How can we get involved?
    • 0:59:15: How do we re-establish trust in our news?
    • 1:02:27: Wrap-up
    • 1:03:39: Patron podcast preview
    • 1:05:23: Reminder for Phase 1
    • 1:05:47: Looking ahead

    20 July 2026, 11:55 am
  • 57 minutes 32 seconds
    Countdown to Episode 500!

    It’s time to start the official countdown to my 500th podcast episode! I’ve been publishing a podcast every single week for over nine years now, which is a rather amazing accomplishment (if I do say so myself). But the entire purpose of the podcast – as well as my book and my blog – has been to try to improve the security and privacy of as many people as possible. So to celebrate this momentous occasion, I’m going to be conducting an experiment to figure out the most effective way to protect our data and devices. And I’m going to need your help.

    In the news: Chat Control 1.0 has been resurrected in the EU; Apple’s Hide My Email is failing to do so; Meta patents a new, creepy wearable device; The Intercept’s Signal account was taken over for months; Papa Johns wants to know when your fridge is empty; Opera Browser has a new feature to combat ClickFix attacks; Google disrupted a residential proxy network; John Deere has been forced to support third party repairs; and the Supreme Court further protected our device location history.

    Article Links

    1. Chat Control 1.0 sneaks through the EU Parliament: https://www.tomshardware.com/tech-industry/cyber-security/chat-control-1-0-sneaks-through-the-eu-parliament-letting-companies-scan-user-data-without-warrants-legal-tactic-used-to-force-a-majority-required-re-vote-on-eve-of-parliament-break
    2. Apple Hide My Email bug allows 100% of real email addresses to be discovered: https://9to5mac.com/2026/07/01/apple-hide-my-email-bug-seemingly-allows-100-of-real-email-addresses-to-be-discovered
    3. Meta Patents AI Device That Tracks Your Emotions, Watches You Take Your Meds: https://www.404media.co/meta-patents-ai-device-that-tracks-your-emotions-watches-you-take-your-meds
    4. The Intercept’s Signal tipline username was hijacked for months: https://cyberinsider.com/the-intercepts-signal-tipline-username-was-hijacked-for-months
    5. Papa Johns Can Predict When Your Fridge Is Empty: https://www.adexchanger.com/?p=461783
    6. Opera’s new security feature stops copy paste attacks from malicious websites – Engadget: https://www.engadget.com/2206574/opera-new-security-feature-stops-copy-paste-clickfix-attacks
    7. Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices: https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html
    8. The Deere Dam Just Broke: FTC Settlement Empowers Farmers Right To Repair: https://fighttorepair.substack.com/p/the-deere-dam-just-broke-ftc-settlement
    9. Justices rule that cellphone location histories are protected by the Fourth Amendment: https://therecord.media/supreme-court-geofencing-ruling-fourth-amendment
    10. Tip of the Week: https://firewallsdontstopdragons.com/celebrating-500-episodes/ 

    Further Info

    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • Hacking the water supply: https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 

    Table of Contents

    • 0:00:07: Intro
    • 0:01:07: Quick headlines
    • 0:03:18: News rundown
    • 0:04:40: Chat Control 1.0 is back
    • 0:09:27: Apple Hide My Email exposes real address
    • 0:13:15: New creepy Meta patent
    • 0:19:16: Intercept loses Signal account
    • 0:23:52: Papa Johns knows when your fridge is empty
    • 0:27:54: Opera implement ClickFix protections
    • 0:32:49: Google foils residential proxy maker
    • 0:38:23: John Deere forced to allow user repairs
    • 0:41:06: SCOTUS restricts location data, again
    • 0:46:04: Tip of the Week
    • 0:53:17: Wrap-up
    • 0:55:01: Hacker summer camp
    • 0:55:42: Patron podcast preview
    • 0:56:13: Looking ahead
    13 July 2026, 11:55 am
  • 1 hour 12 minutes
    Defending Device Data

    Our Constitutional rights were written without any concept of modern technology such as cell phones and the internet. Much of our privacy laws are still geared towards the pre-digital age. Even though the internet is many decades old now, the era of traveling with smartphones and laptops is still relatively new and the laws around privacy have not kept up. Today I’ll be speaking with Nathan Freed Wessler from the ACLU about device searches, particularly at the US border. We’ll also talk about how cases relating to location tracking have evolved since the landmark Carpenter case that Nate successfully argued in front of the Supreme Court almost 10 years ago now.

    Interview Notes

    • ACLU: https://aclu.org/ 
    • Nate Wessler: https://www.aclu.org/bios/nathan-freed-wessler 
    • My first interview with Nate: https://podcast.firewallsdontstopdragons.com/2022/08/01/now-place-left-to-hide/
    • ACLU facial recognition suit: https://reason.com/2026/06/11/aclu-sues-after-facial-recognition-falsely-identifies-florida-man-as-a-child-abductor/ 
    • Travel Insecurity: https://firewallsdontstopdragons.com/border-insecurity/ 

    Further Info

    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support the mission: https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 
    • Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    • 0:00:12: Intro
    • 0:02:37: What makes border searches different, legally?
    • 0:08:15: What is the 100 mile rule?
    • 0:12:42: How do digital searches differ from physical?
    • 0:19:26: What is digital contraband?
    • 0:23:33: How does ‘in plain site’ work on a phone?
    • 0:26:29: How has the Carpenter decision held up?
    • 0:32:59: Should Carpenter apply to ALPRs?
    • 0:41:29: How does AI complicate matters?
    • 0:47:11: How should we prepare for border searches?
    • 0:59:49: What about privileged or corporate data?
    • 1:03:33: Can I lock my device before I hand it over?
    • 1:05:30: What’s next for you and the ACLU?
    • 1:08:36: Wrap up
    • 1:11:01: Patron podcast preview
    • 1:11:27: Looking ahead
    6 July 2026, 11:55 am
  • 1 hour 4 minutes
    We Can Do This
    With the 500th podcast and America's 250th anniversary approaching, I've been doing a lot of thinking about how we can be better digital neighbors and digital citizens. We're all in this together. Your security and privacy overlaps the security and privacy of many others. It's important to improve our own situation, but we need to also realize that failing to do so can put others at risk who may be more vulnerable and have more to lose that we do. In the news: massive Fortinet breach; feds recover activists' Signal messages; Visa partners with ChatGPT for agentic purchases; Anthropic models banned for export; US shortens cyber fix window to 3 days; EPIC endorses two new privacy bills; Canada's spy agency hacks devices to clean out botnet; nearly half of LG smart TVs apps contain proxy SDKs; EFF calls out Amazon for shady Android devices containing proxies. Article Links Massive breach spills credentials for thousands of sensitive networks: https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks How Did the Feds Get Into Anti-ICE Activists’ Signal Messages?: https://theintercept.com/2026/06/17/signal-messages-minneapolis-ice-protests Visa plugs its payment network into ChatGPT, letting AI agents shop and pay for users: https://apnews.com/article/visa-chatgpt-openai-shopping-mastercard-d769dec86344cb4977c98789e8ec492f The Fable 5 Export Controls Harm US Cyber Defense: https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense US shortens cyber fix window to three days as AI threats rise: https://www.reuters.com/legal/litigation/us-shortens-cyber-fix-window-three-days-ai-threats-rise-2026-06-10 EPIC Endorses Federal Bills Barring Worker Surveillance, Automated Workplace Decisions: https://epic.org/epic-endorses-federal-bills-barring-worker-surveillance-automated-workplace-decisions Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices: https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs: https://spur.us/blog/smart-tv-apps-residential-proxy-sdks Primed for Malware: Stop Selling Compromised Android Devices: https://www.eff.org/deeplinks/2026/06/primed-malware-stop-selling-compromised-android-devices Tip of the Week: https://firewallsdontstopdragons.com/we-can-do-this/  Further Info Loupe app (Mysk): https://apps.apple.com/us/app/loupe-what-apps-can-see/id6766152470  Loupe app overview (Techlore): https://www.youtube.com/watch?v=_n_SpEWtqog  Free Fable petition: https://freefable.org/  My book: https://fdsd.me/book  My newsletter: https://fdsd.me/newsletter  Support our mission! https://fdsd.me/support  Give the gift of privacy and security: https://fdsd.me/coupons  Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch  Table of Contents 0:00:07: Intro 0:00:23: Quick news bits 0:02:46: News rundown 0:05:01: Massive Fortinet breach 0:12:27: Signal data security limits 0:17:58: Visa integrates with ChatGPT 0:23:01: Free Fable 0:30:35: US shortens cyber fix window 0:32:25: New federal privacy bills 0:35:18: Canada spy agency cleans up botnet 0:40:34: Shady Samsung TV apps 0:50:10: EFF on Android proxy devices 0:55:57: Tip of the Week 1:03:02: Patron podcast preview 1:03:27: Looking ahead
    29 June 2026, 11:55 am
  • More Episodes? Get the App

Discover

  • Featured
  • Top Charts
  • Popular

More

  • Get the App
  • News
  • Setting
  • Privacy Policy
  • Submit Your Podcast

Contact

  • [email protected]
  • Twitter
Your feedback is valuable to us. Should you encounter any bugs, glitches, lack of functionality or other problems, please email us at [email protected] or join where you can talk directly to the dev team.
© MoonFM 2026. All rights reserved.