• Get the App
  • Moon FM - The Ultimate Podcast App
  • Get the App
Firewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast

Carey Parker

A Podcast on Computer Security & Privacy for Non-Techies

  • 54 minutes 40 seconds
    Hold Off on Muse

    Meta has released a very powerful new AI agent app called Muse. Likewise, OpenAI has released a similar app called Dots. Both apps feature charming, friendly and decidedly non-threatening avatars to perhaps assuage your fears of AI. But these agents ask for extensive access to your data and devices, which in my view is – as for right now – too dangerous. We’ve already seen these agents doing things their owners were not expecting and did not want. I’ll tell those stories and give you my advice on using AI agents.

    In other news: Android 17 adds welcome security features; weakness found in important encryption algorithm; update TeamViewer ASAP; some Samsung fridges bricked by SW update; CA closes data broker law loophole; USPS trialing cameras on vehicles; iPhone inactivity reboot thwarted? ; malware steals water utility credentials; US military and FBI employee records stolen; Amazon blocks Meta’s AI agent; Muse reads user’s Apple Messages;

    Article Links

    News Briefs

    1. Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools. [thehackernews.com – The Hacker News]: https://thehackernews.com/2026/10/android-17-advanced-protection-locks.html
    2. New Attack Against RSA – Schneier on Security. [schneier.com – Bruce Schneier – Sep 28, 2026]: https://www.schneier.com/blog/archives/2026/09/new-attack-against-rsa.html
    3. TeamViewer urges users to patch severe flaws “as soon as possible”. [bleepingcomputer.com – Sergiu Gatlan]: https://www.bleepingcomputer.com/news/security/teamviewer-urges-users-to-patch-severe-flaws-as-soon-as-possible
    4. Owners mourn spoiled food after firmware update bricks Samsung smart fridges. [arstechnica.com – Scharon Harding – Sep 23, 2026]: https://arstechnica.com/gadgets/2026/09/owners-mourn-spoiled-food-after-firmware-update-bricks-samsung-smart-fridges
    5. California Expands Privacy Protections by Strengthening Deletion Rights. [privacy.ca.gov – nicolecameron – Sep 27, 2026]: https://privacy.ca.gov/2026/09/california-expands-privacy-protections-by-strengthening-deletion-rights
    6. USPS To Put Cameras in Trucks That Scan Roads for ‘Community Safety’. [404media.co – Joseph Cox – Sep 30, 2026]: https://www.404media.co/usps-to-put-cameras-in-trucks-that-scan-roads-for-community-safety
    7. Cops Can Bypass iPhone’s Automatic Reboot to Get Into Locked Phones, Leaked Video Claims. [404media.co – Lorenzo Franceschi-Bicchierai – Oct 1, 2026]: https://www.404media.co/cops-can-bypass-iphone-automatic-inactivity-reboot-graykey

    Full Stories

    1. Stolen passwords are exposing America’s water providers to hackers. [techcrunch.com – Zack Whittaker – Sep 22, 2026]: https://techcrunch.com/2026/09/22/stolen-passwords-are-exposing-americas-water-providers-to-hackers
    2. Hackers stole millions of US military personnel records during months-long data breach. [techcrunch.com – Zack Whittaker – Sep 30, 2026]: https://techcrunch.com/2026/09/30/hackers-stole-millions-of-us-military-personnel-records-during-months-long-data-breach
    3. ‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees. [404media.co – Joseph Cox – Sep 22, 2026]: https://www.404media.co/we-hacked-the-fbi-hackers-say-they-have-data-on-all-fbi-employees
    4. Amazon Blocks Meta’s Muse AI Assistant. [daringfireball.net]: https://daringfireball.net/linked/2026/09/22/amazon-blocks-muse
    5. Meta’s New Muse AI Agent Read My Private Messages. I Never Asked It To. [inc.com – Jason Aten – Sep 19, 2026]: https://www.inc.com/jason-aten/metas-new-muse-ai-agent-read-my-private-messages-i-never-asked-it-to/91408202 
    6. Tip of the Week: https://firewallsdontstopdragons.com/hold-off-on-muse-dots/ 

    Further Info

    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 
    • Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:49: News rundown
    • 0:02:43: New Android 17 security features
    • 0:04:18: RSA encryption weakened?
    • 0:06:52: Update TeamViewer now
    • 0:07:44: Samsung fridges bricked
    • 0:09:23: CA closes data loophole
    • 0:11:10: USPS trialing cameras on vehicles
    • 0:13:23: iPhone inactivity reboot thwarted?
    • 0:15:22: Malware steals water utility creds
    • 0:19:27: US military records stolen
    • 0:22:19: Massive FBI data breach
    • 0:31:01: Amazon blocks Meta’s Muse
    • 0:37:30: Muse reads Apple Messages
    • 0:46:13: Tip of the Week
    • 0:53:04: Patron podcast preview
    • 0:53:42: Looking ahead

    5 October 2026, 11:55 am
  • 1 hour 32 minutes
    Here’s to 500!!

    Today marks an incredible milestone for this podcast: 500 episodes! Not only is that a crazy long run for any podcast, but I’ve also been astonishingly consistent. I’ve managed to put out an episode of this show every single week for 500 straight weeks! Okay… I did miss one week 8 years ago… I’ll give you that story in today’s podcast. But as always for my “podcentennial” episodes, my guest is the one and only global cybersecurity guru Bruce Schneier. He’s been on the show for every 100th podcast. Today I’ll ask Bruce some deep questions about artificial intelligence and how he sees it impacting our future – not just in the technical realm, but the political and social realms, as well. We also have some special surprises and bonus content for this momentous occasion!

    Interview Notes

    • Bruce Schneier: https://www.schneier.com/ 
    • Bruce’s DEF CON 34 talk: https://www.youtube.com/watch?v=eEBv0STiYhI 
    • Bruce’s books: https://www.schneier.com/books/ 
    • Inrupt’s Solid Project: https://www.inrupt.com/solid 
    • Apertus AI: https://www.apertus-ai.org/ 
    • Cap’N Crunch whistle: https://www.thingiverse.com/thing:6192416 
    • Citizenfour: https://www.imdb.com/title/tt4044364/ 
    • Techlore: https://techlore.tech/ 
    • The New Oil: https://thenewoil.org/en/ 
    • Privacy Guides: https://www.privacyguides.org/ 
    • Privacy Safe: https://privacysafe.social/ 
    • Micah’s book: https://nostarch.com/hacks-leaks-and-revelations 
    • UnDisruptable27: https://u27.org
    • Yael’s blog: https://yaelwrites.com/ 
    • Cult of the Dead Cow:  https://cultdeadcow.com/ 
    • Bob Lord’s Hacklore: https://www.hacklore.org/ 
    • David Ruiz: https://www.malwarebytes.com/blog/authors/davidruiz 
    • Melanie Ensign’s Discernible: https://www.discernibleinc.com/ 

    Further Info

    • Help me celebrate this 500th show!!! : https://fdsd500.com 
    • Pay it forward and help others : https://fdsd.me/phase2 
    • Last chance to get #FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support the mission: https://fdsd.me/support 

    Table of Contents

    • 0:00:00: Congratulations, part 1
    • 0:01:47: Intro
    • 0:07:12: Congratulations, part 2
    • 0:10:31: Intro, continued
    • 0:12:01: Stay tuned…
    • 0:13:16: Interview setup
    • 0:15:26: What are the key parts of a modern LLM?
    • 0:23:03: How do we defend against prompt injection?
    • 0:27:09: Should AI agents only act on our behalf?
    • 0:32:10: Who’s responsible when AI attacks?
    • 0:35:25: Will AIs end up fighting each other?
    • 0:41:47: How will AI’s speed and scale change security?
    • 0:46:50: Should we own our personal AI data?
    • 0:55:03: Can we trust AI with all our data?
    • 0:59:24: Does AI enhance mass surveillance?
    • 1:03:09: How do we democratize AI?
    • 1:06:24: What can we do to manifest the best AI future?
    • 1:11:08: Wrap-up
    • 1:11:42: Cap’n Crunch whistle
    • 1:13:50: Thank you patrons!!!
    • 1:16:27: FDSD by the numbers
    • 1:23:25: Phase 1, 2 update
    • 1:26:17: Phase 3?
    • 1:26:55: Special bonus guest target
    • 1:29:18: Patron podcast preview
    • 1:30:40: Last call for FDSD500 merch
    • 1:31:14: Looking ahead
    28 September 2026, 11:55 am
  • 1 hour 3 minutes
    Solving the AI Paradox

    In the last week, many news organizations have breathlessly covered the “AI doomer” comments by a former Anthropic employee, who said that many of his colleagues were secretly worried about AI ending all of humanity – and that it could happen in just a few years. But to me, there are more pressing concerns with AI and so far we’ve not responded in useful ways. I have several thoughts.

    In the news: Android patches some severe bugs (update now); Google implements method to securely move passwords and passkeys; Radaris loses its domains in court fight; Boston dumps Flock cameras; Discord is going through with age verification; CISA is cutting programs that help secure critical infrastructure; hackers reveal Flock’s camera software; AI companies are reading chatbot session text; Apple debuts Apple Watch constant audio recording; and an interesting article on how to avoid the AI automation paradox.

    Article Links

    News Briefs

    1. Google fixes actively exploited Android zero-day on Pixel devices: https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices
    2. Google is making it easier to switch between password managers on Android: https://techcrunch.com/2026/09/10/google-is-making-it-easier-to-switch-between-password-managers-on-android
    3. Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security: https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight
    4. Boston dumps Flock, says it shared data nationwide in violation of contract: https://arstechnica.com/tech-policy/2026/09/boston-dumps-flock-says-it-shared-data-nationwide-in-violation-of-contract
    5. Discord Is Bringing Back Age Verification for Millions of Users: https://www.gadgetreview.com/discord-is-bringing-back-age-verification-for-millions-of-users
    6. CISA Cuts Critical Infrastructure Security Resources: https://www.securitymagazine.com/articles/102561-cisa-cuts-critical-infrastructure-security-resources

    Full Stories

    1. Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People: https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2
    2. Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats: https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats
    3. Watch what you say: Apple opens the door to a nightmare world of always-listening tech: https://this.weekinsecurity.com/watch-what-you-say-apple-opens-the-door-to-a-nightmare-world-of-always-listening-tech
    4. The AI Researcher Who Just Quit Anthropic Says It’s ‘Crunch Time for Humanity’: https://www.wired.com/story/anthropic-researcher-quits-jacob-coxon-ai-fears-humanity
    5. AI Efficiency Could Cost Us the Next Generation of Experts: https://spectrum.ieee.org/ai-engineer-skills
    6. Tip of the Week: https://firewallsdontstopdragons.com/solving-the-ai-paradox/ 

    Further Info

    • Pay it forward and help others : https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 

    Table of Contents

    • 0:00:07: Intro
    • 0:01:53: News rundown
    • 0:04:07: Update your Android devices
    • 0:04:34: Android adopts credential moving tech
    • 0:06:06: Radaris loses key domains
    • 0:07:13: Boston ends Flock contract
    • 0:07:52: Discord brings back age verification
    • 0:09:38: CISA cuts critical support
    • 0:11:14: Hackers reveal Flock software
    • 0:19:10: Humans reading LLM chats
    • 0:27:09: New Apple watch recording feature
    • 0:34:28: AI employee sounds alarm
    • 0:39:22: Efficiency at what cost?
    • 0:48:54: Tip of the Week
    • 0:59:56: Wrapup
    • 1:02:07: Patron podcast preview
    • 1:02:38: Looking ahead
    21 September 2026, 11:55 am
  • 1 hour 4 minutes
    Obscuring the Exit

    While we do have some state privacy laws in the US that require companies to allow you to opt out of data collection, these companies have devised clever ways to make these options very hard to find and/or very hard to choose in a clear and consistent manner. The Electronic Privacy Information Center (EPIC) has done a study on several such companies and the tricky ways they have obscured the mechanisms to assert your privacy rights. We’ll get all the details from one of the co-authors of this report, Caroline Kraczon.

    Interview Notes

    • EPIC: https://epic.org/ 
    • Opt out dark patterns: https://epic.org/press-release-epic-releases-new-report-on-manipulative-design-patterns-in-opt-out-processes/ 
    • Full report (PDF): https://epic.org/wp-content/uploads/2026/05/Good-Luck-Opting-Out-Manipulative-Design-Patterns-in-Opt-Out-Processes.pdf 
    • How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ 
    • Yael Graur’s BADBOOL list: https://github.com/yaelwrites/big-ass-data-broker-opt-out-list 
    • EasyOptOuts: https://easyoptouts.com/ 
    • My series on removing online data:  https://firewallsdontstopdragons.com/osint-reconnaissance/ 
    • How to enable GPC: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ 

    Further Info

    • Phase 2 has begun!! : https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support the mission: https://fdsd.me/support 

    Table of Contents

    • 0:00:13: Intro
    • 0:01:05: Interview setup
    • 0:02:32: What are dark patterns?
    • 0:08:21: What dark patterns did you see?
    • 0:16:01: How are state-based laws enforced on the open web?
    • 0:18:03: Which companies did you study?
    • 0:19:52: Which companies were worst?
    • 0:23:16: How can data gathering be harmful?
    • 0:27:29: How is the notice and concent model broken?
    • 0:33:15: Does AI enable a whole new privacy risk?
    • 0:35:38: What’s the response been to your report?
    • 0:37:15: Why is publicly available data exempt?
    • 0:42:02: How useful are “privacy checkup” tools?
    • 0:45:13: How effective are privacy laws?
    • 0:52:00: How can we reduce incentives to collect data?
    • 0:54:18: What can we do?
    • 0:59:09: Wrap-up
    • 1:02:07: Patron podcast preview
    • 1:02:47: Looking ahead
    14 September 2026, 11:55 am
  • 1 hour 21 minutes
    Use a Secure Wi-Fi Router

    Probably the single most important device on your home network in terms of security is your Wi-Fi router. In most cases, it’s the only thing between all your networked devices and the Internet’s bad guys. It’s crucial that you’re using an updated (and update-able) device from a reputable maker. I’ll explain why it’s important and how to pick a good router.

    In other news: Plex media server urges users to update their software immediately; Meta settles a lawsuit for $18B and promises changes for kids; 153M personal ID cards were stolen and are for sale; ChatGPT has a new plugin to read and manage your iMessages; study shows Windows apps tattling on users; researcher shows how secret ballots can be re-identified; US Senator asks NSA to publish info on how to choose and use a good VPN; Flock vigilantism and vandalism soars; researchers find blatant back doors in cheap Chinese routers.

    Article Links

    News Briefs

    1. Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws: https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html
    2. Meta to pay $18 billion in teen social media addiction settlement: https://proton.me/blog/meta-teen-addiction-settlement

    Full Stories

    1. Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof: https://gizmodo.com/identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof-2000806437
    2. ChatGPT’s iMessage plugin opens a backdoor in Apple Messages: https://proton.me/blog/chatgpt-apple-messages
    3. Hidden Tracking in Windows Apps: https://adguard.com/en/blog/how-desktop-apps-watch-you-research.html
    4. An Algorithmic Failure Beneath the Secret Ballot: https://blog.citp.princeton.edu/2026/08/03/an-algorithmic-failure-beneath-the-secret-ballot
    5. Confused about which VPN is right, US senator asks the NSA for guidance: https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns
    6. Vigilantism comes for Flock: https://this.weekinsecurity.com/vigilantism-comes-for-flock
    7. Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware: https://www.tomshardware.com/tech-industry/cyber-security/security-researchers-find-surveillance-implants-in-chinese-made-routers-sold-worldwide-three-different-backdoor-like-implants-hidden-in-firmware

    Further Info

    • Phase 2 is under way! : https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • Jellyfin media server: https://jellyfin.org/ 
    • Tailscale: https://tailscale.com/ 
    • Proton blog: https://proton.me/blog 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 

    Table of Contents

    • 0:00:07: Intro
    • 0:02:26: 6th Edition update
    • 0:04:15: News rundown
    • 0:06:17: Plex media server critical fixes
    • 0:08:47: Meta’s $18B lawsuit loss
    • 0:10:40: 153M ID’s for sale
    • 0:19:11: ChatGPT plugin for iMessage
    • 0:27:28: Windows app tracking
    • 0:38:23: Using AI to reveal your voting
    • 0:48:42: Senator requests NSA VPN guidance
    • 0:53:20: Rise in Flock vandalism
    • 1:01:17: Chinese routers with built-in backdoors
    • 1:09:48: Tip of the Week
    • 1:19:21: Phase 2 reminder
    • 1:20:14: Patron podcast preview
    • 1:20:34: Looking ahead
    7 September 2026, 11:55 am
  • 1 hour 15 minutes
    Supply Chain Attacks

    Software apps today are a hodgepodge of libraries, software development kits, and third party code, all stitched together like Frankenstein’s monster. Furthermore, software developers use common tools to create and deploy this software. The bad guys have figured out that by compromising one of these third party components or the tools used to create the products, they can instantly infect hundreds or thousands of products that all share the same underlying resources. This is a supply chain attack. Today we’ll discuss these single points of failure, how to identify them ahead of time and try to prevent these sorts of attacks with Cassie Crossley, CEO and co-founder of VulNow.

    Interview Notes

    • Cassie Crossley: https://www.linkedin.com/in/cassiecrossley/ 
    • VulNow company website: https://vul.now/
    • VulNow’s Pre-CVE database: https://precve.vulnow.com/ 
    • CyBeats company website: https://www.cybeats.com/
    • Software Supply Chain Security (book): https://www.oreilly.com/library/view/software-supply-chain/9781098133696/ 
    • Proton blog on supply chain security: https://proton.me/business/blog/supply-chain-attack 
    • Malus AI re-write tool: https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/ 
    • xkcd on Dependency: https://xkcd.com/2347/ 
    • Updated dependency diagram: https://www.grc.com/SN/1078.jpg 

    Further Info

    • Phase 2 has begun!! : https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support the mission: https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 
    • Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    • 0:00:14: Intro
    • 0:00:35: Phase 2 reminder
    • 0:01:52: Interview setup
    • 0:06:05: What is VulNow?
    • 0:08:34: What software is vulnerable to supply chain attacks?
    • 0:13:16: Have you heard of AI clean room coding?
    • 0:15:34: How do SW supply chain attacks work?
    • 0:21:21: How do we identify the weak points?
    • 0:34:24: What are SBOM’s and how do they work?
    • 0:43:45: What is needed beyond SBOMs?
    • 0:50:32: Can tools reveal the contents of SW?
    • 0:56:13: How do we encourage SBOM creation?
    • 1:01:35: As consumers, how do we know who to trust?
    • 1:06:09: What’s next for you?
    • 1:08:46: Wrap-up
    • 1:13:23: Patron podcast preview
    • 1:14:19: Looking ahead
    31 August 2026, 11:55 am
  • 1 hour 6 minutes
    Digital Citizen: Phase 2

    As part of my celebration of the upcoming 500th podcast, I’m launching Phase 2 of my “cyber neighbor” campaign to both help as many people be more secure and private as possible, but to also learn from this experience so I can improve these campaigns in the future. In particular, as I write the 6th edition of my book, I’m funneling this feedback into improving those Tips, as well.

    In the news: Flock considered utilizing ride share and delivery vehicles to expand their ALPR network; judge rules ‘tower dump’ warrants unconstitutional; BMW’s show Spider-Man ads; hackers reuse expired domains for scams and malware; US warns of more PLC attacks; US proposal would allow private companies to launch cyber attacks on foreign groups; terabytes of credentials stolen in supply chain attack; customer downloads his 515-page McDonald’s dossier; AI agent hacks gym site to book a class; town claims Flock reactivated cameras without notice; and Chrome trials new device-bound session credentials.

    Article Links

    News Briefs

    1. Flock wanted to put license plate cameras on 350,000 Uber and Lyft dashcams: https://www.techspot.com/news/113407-flock-wanted-put-license-plate-cameras-350000-uber.html
    2. ‘Tower dump’ warrants ruled unconstitutional: https://thehill.com/regulation/court-battles/6013559-mississippi-judge-declares-towers-dumps-unconstitutional
    3. BMWs are showing a commercial at startup: https://boingboing.net/2026/08/06/bmws-are-showing-a-spider-man-movie-ad-at-startup.html
    4. Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware: https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html

    Full Stories

    1. US warns of AI-powered attacks on Siemens PLCs in critical infrastructure: https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure
    2. In a first, US will allow some private firms to carry out cyberattacks: https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks
    3. Terabytes of credentials leaked in massive supply-chain attack: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack
    4. McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There: https://www.wired.com/story/mcdonalds-built-a-515-page-dossier-on-me-it-says-ill-never-leave
    5. Told to book a gym class, an AI agent hacked the site instead to move its user up the waitlist: https://the-decoder.com/told-to-book-a-gym-class-an-ai-agent-hacked-the-site-instead-to-move-its-user-up-the-waitlist
    6. Littleton claims Flock reactivated its cameras without notifying the town: https://www.lowellsun.com/2026/07/31/littleton-claims-flock-reactivated-its-cameras-without-notifying-the-town
    7. Chrome adopts what may be the best protection yet against account takeovers: https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-account-takeovers
    8. Tip of the Week: https://firewallsdontstopdragons.com/digital-citizen-phase-2/ 

    Further Info

    • Phase 2: https://fdsd.me/phase2 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • NoALPRs: https://noalprs.com/ 
    • FlockYou project: https://github.com/colonelpanichacks/flock-you 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:26: Public service announcements
    • 0:03:20: News rundown
    • 0:05:25: Flock in Uber, Lyft, delivery vehicles
    • 0:07:13: Tower dump warrants ruled unconstitutional
    • 0:08:33: Some BMW’s show Spider-Man ad
    • 0:10:49: Hackers use expired domains for scams
    • 0:13:24: US warns of AI attacked on PLCs
    • 0:18:05: US authorizes private cyber attacks
    • 0:24:53: Terabytes of credentials leaked in supply chain attack
    • 0:32:13: McDonald’s customer dossier
    • 0:39:44: AI agent hacks gym site
    • 0:45:22: Town claims Flock reactivated its cameras
    • 0:49:39: Google trialing device-bound session cookies
    • 0:57:00: Tip of the Week
    • 1:04:31: Wrap-up
    • 1:05:22: Patron podcast preview
    • 1:05:45: Looking ahead
    24 August 2026, 11:55 am
  • 1 hour 27 minutes
    DEF CON 34

    It’s August, which means it’s time for Hacker Summer Camp once again! I flew out to a sweltering Las Vegas, Nevada, to attend two of the three major cybersecurity (“hacker”) conferences: BSides and DEF CON. I had an amazing week, spending time with new and old friends, meeting some of the people I’ve interviewed in person, lining up more podcast guests, and having wonderfully stimulating conversations with very smart people. While at DEF CON, I managed to record four mini interviews with Bob Lord, Naomi Brockwell, Josh Corman and the Dark Tangent himself, Jeff Moss. I will try to give you some idea what these conferences are like as we discuss several important and timely topics.

    Interview Notes

    • Hacklore: https://www.hacklore.org/ 
    • Naomi Brockwell (NBTV): https://www.nbtv.media/ 
    • Ludlow Institute: https://www.ludlowinstitute.org/ 
    • Surveillance Accountability Act: https://www.surveillanceaccountability.com/ 
    • UnDisruptable27: https://u27.org 
    • I Am the Cavalry, BSides 2026 (Monday): https://www.youtube.com/watch?v=r4C8stKbxBM 
    • BSides IATC schedule: https://bsideslv.org/schedule#IATC 
    • Cliff Stoll talk: https://www.youtube.com/live/_uYQr8hfpbI?t=13292s 
    • DEF CON: https://defcon.org/
    • DEF CON 20 Documentary: https://archive.org/details/DEFCON20Documentary 
    • DEF CON 33 Documentary: https://www.youtube.com/watch?v=pb0kJXSy64E 

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support the mission: https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:50: Hacker Summer Camp
    • 0:11:30: Interview preface
    • 0:14:26: Bob Lord
    • 0:21:18: Bob afterword
    • 0:24:08: Naomi intro
    • 0:26:09: Naomi Brockwell
    • 0:35:51: Naomi afterword
    • 0:40:58: Josh intro
    • 0:42:58: Josh Corman
    • 0:56:01: Josh afterword
    • 1:01:08: Jeff intro
    • 1:03:00: Jeff Moss
    • 1:23:12: Jeff afterword
    • 1:24:30: Wrap-up
    • 1:26:20: Patron podcast preview
    • 1:26:45: Phase 1 still going
    • 1:27:13: Looking ahead
    17 August 2026, 11:55 am
  • 1 hour 13 minutes
    AI Tech Support: Trust, but Verify

    One of the most underrated uses for modern chatbots, in my estimation, is tech support. I don’t mean the chatbots offered by product websites, I mean using one of the “frontier” model bots to troubleshoot problems via chat conversations. They are extremely good at this – and they are infinitely patient and available 24/7. Today I’ll give you tips on how to try this for yourself. I think you’ll be amazed.

    In the news: DEF CON bans Meta-style glasses; US military warns of personal cell phone use; GDPR suit over 1741 “partners” in share consent; US bans future robovacs; more TV streaming stick bad behavior; FTC sues Hims & Hers over health data sharing; Android “after call” ads malware; user’s private AI chats leaked; clever, annoying Mac malware; HuggingFace breached by OpenAI agent; Iran blamed for hacking 30 Minnesota water utilities.

    Article Links

    News Briefs

    1. DEF CON bans Meta-style ‘pervert glasses’: https://www.theregister.com/security/2026/07/28/def-con-bans-meta-style-pervert-glasses/5279763
    2. US military may require some troops in Mideast to surrender cell phones: https://www.reuters.com/business/media-telecom/us-commander-warns-troops-their-videos-help-iran-sources-say-2026-07-29

    Full Stories

    1. 1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed: https://noyb.eu/en/1741-informed-consents-one-click-gdpr-complaint-against-dictcc-filed
    2. Almost all future robot vacuums were just banned by the US government: https://9to5mac.com/2026/07/29/almost-all-future-robot-vacuums-were-just-banned-by-the-us-government
    3. Read This Before You Buy That TV Streaming Stick: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick
    4. FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap: https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-for-allegedly-sharing-patients-medical-data-with-advertisers-meta-and-snap
    5. Aftercall ads are driving Android users crazy: https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy
    6. Users’ private Claude chats revealed with simple Google search: https://appleinsider.com/articles/26/07/28/privacy-is-dead-personal-ai-prompts-indexed-by-google-search
    7. This new Mac malware won’t let you use your computer until you surrender your password: https://www.digitaltrends.com/computing/this-new-mac-malware-wont-let-you-use-your-computer-until-you-surrender-your-password
    8. OpenFace: The Hugging Face Breach and What to Do About It: https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-it
    9. Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack
    10. Tip of the Week: https://firewallsdontstopdragons.com/ai-tech-support-trust-but-verify/

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • Update All the Things! https://firewallsdontstopdragons.com/update-all-the-things/ 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 
    • Support our mission! https://fdsd.me/support 
    • Give the gift of privacy and security: https://fdsd.me/coupons 
    • Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    • 0:00:07: Intro
    • 0:00:40: PSA: Update!!
    • 0:01:36: Countdown to 500
    • 0:02:37: News Briefs
    • 0:06:46: News rundown
    • 0:08:50: GDPR complaint about 1741 “partners”
    • 0:12:45: US bans foreign robots
    • 0:16:13: Malicious, cheap streaming sticks
    • 0:23:33: FTC sues Hims/Hers for sharing health data
    • 0:27:34: Android “after call” ads
    • 0:32:17: Private Claude chats in search results
    • 0:38:18: Cleverly annoying Mac malware
    • 0:45:31: Hugging Face breach lessons
    • 0:54:08: Many US water utilites attacked by Iran
    • 0:59:39: Tip of the Week
    • 1:11:56: Wrap up
    10 August 2026, 11:55 am
  • 1 hour 11 minutes
    Top Cyber Threats 2026

    With so many cyber threats to report on, it’s easy to get lost in the weeds. It’s good to take a step back and look at the big picture every so often. Today, I’ll review some of the top security and privacy threats with investigative cybersecurity journalist Zack Whittaker from Tech Crunch. We’ll talk about age verification, mercenary spyware, surveillance capitalism, critical infrastructure hacks, AI and the proliferation of tracking in public spaces – and more!

    Interview Notes

    • This Week in Security: https://this.weekinsecurity.com/ 
    • Zack at TechCrunch: https://techcrunch.com/author/zack-whittaker/ 
    • Zack’s homepage: https://zackwhittaker.com/ 
    • Project Sunshine: https://projectsunshine.org/about 
    • Filtr (Wipr) ad blocker for iPhone: https://techcrunch.com/2026/06/04/filtr-is-a-new-privacy-tool-that-blocks-ads-in-almost-every-iphone-and-mac-app/ 
    • Apple iPhone security: https://ssd.eff.org/module/how-to-get-to-know-iphone-privacy-and-security-settings 
    • Google Android security: https://ssd.eff.org/module/how-to-get-to-know-android-privacy-and-security-settings 
    • Zach’s list: 404media.co, metacurity.com, indicator.media, krebsonsecurity.com, techdirt.com, garbageday.email, thehandbasket.co, karlbode.com, risky.biz, lawdork.com, citationneeded.news, erininthemorning.com 

    Further Info

    • Digital Citizen, Phase 1: https://fdsd.me/phase1 
    • Countdown to FDSD500!! https://fdsd500.com 
    • Get your FDSD500 merch!! https://fdsd.me/merch 
    • My book: https://fdsd.me/book 
    • My newsletter: https://fdsd.me/newsletter 

    Table of Contents

    • 0:00:12: Intro
    • 0:02:08: Interview setup
    • 0:03:03: What is age gating?
    • 0:07:45: What are the risks of age verification?
    • 0:15:30: How do ads get our data?
    • 0:21:33: How can ad data be abused?
    • 0:28:11: What is mercenary spyware?
    • 0:34:53: How do you protect against spyware?
    • 0:41:04: How dangerous are nation-state attacks?
    • 0:43:54: How do we defend against foreign attacks?
    • 0:47:43: Does AI benefit defenders or attackers more?
    • 0:51:24: How do we mitigate public mass surveillance?
    • 0:57:01: What else worries you?
    • 1:00:34: What’s next for you?
    • 1:02:30: Wrap-up
    • 1:07:50: Patron podcast preview
    • 1:09:02: Looking ahead
    3 August 2026, 11:55 am
  • 1 hour 14 minutes
    Update All the Things
    Over the last 2-3 months, large software makers such as Microsoft have been releasing tons of fixes for vulnerabilities in their apps and operating systems. Did their software suddenly get a lot worse? No. They're using the latest AI tools to find these bugs that humans missed and that have been lurking in their software for months or even years - and they're fixing them. That's great news... but these fixes won't do you any good unless you install them. Bad guys are using these same tools to exploit these bugs. There's never been a better time to update all your devices' software. In other news: a hidden car device leaves many cars vulnerable to hacking; most fitness wearables don't encrypt users' data end-to-end; Iran is tracking US military phones; CBP accuses citizen of wiping phone using "duress" password; US says Iran is hacking critical infrastructure; US also warns that Russia and China are hacking small office routers; US judge denies broad "stringray" warrant in Ohio; LG to ban proxy apps on their TVs; Maine librarians teach patrons how to remove AI features. Article Links A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now Most fitness wearables lack end-to-end encryption and don't disclose government data demands, says EFF: https://this.weekinsecurity.com/most-fitness-wearables-lack-end-to-end-encryption-and-lack-transparency-reports Financial Times: US military smartphones targeted through roaming and ad tech: https://harrigan.house.gov/media/in-the-news/financial-times-us-military-smartphones-targeted-through-roaming-and-ad-tech US accuses American of allegedly wiping his phone using a 'duress' password during border search: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search US government says Iran-linked hackers are disrupting American water and energy providers: https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers The US government warns that Russia state hackers are coming after your router: https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents: https://this.weekinsecurity.com/us-judge-denied-feds-month-long-warrant-to-snoop-on-the-phones-of-thousands-of-ohio-residents LG to Ban Residential Proxies from Smart TV Apps: https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps These Maine librarians are helping patrons resist AI and Big Tech: https://www.bangordailynews.com/2026/07/02/midcoast/midcoast-culture/maine-librarians-are-helping-patrons-resist-ai-joam40zk0w Tip of the Week: https://firewallsdontstopdragons.com/update-all-the-things/  Further Info Digital Citizen, Phase 1: https://fdsd.me/phase1  Countdown to FDSD500!! https://fdsd500.com  Get your FDSD500 merch!! https://fdsd.me/merch  Zero-Day documentary: https://www.imdb.com/title/tt5446858/  EFF’s Rayhunter: https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying  This Week in Security: https://this.weekinsecurity.com/  My book: https://fdsd.me/book  My newsletter: https://fdsd.me/newsletter  Table of Contents 0:00:07: Intro 0:00:25: Phase 1 reminder 0:04:09: Quick news bites 0:05:54: News rundown 0:07:35: Hidden card device vulnerable to hacks 0:15:00: Most fitness wearables lack E2EE 0:19:19: Iran tracking military smartphones 0:26:58: US accuses citizen of wiping phone with "duress" password 0:33:15: US Gov't claims Iran attaching infrastructure 0:38:03: Russia attacking US routers 0:42:37: Judge denies "Stingray" warrant 0:49:09: LG TV to ban proxy network apps 0:53:57: Maine librarians help patrons remove AI 1:00:54: Tip of the Week 1:10:18: Reminders 1:11:17: Patron podcast preview 1:11:49: Looking ahead
    27 July 2026, 11:55 am
  • More Episodes? Get the App

Discover

  • Featured
  • Top Charts
  • Popular

More

  • Get the App
  • News
  • Setting
  • Privacy Policy
  • Submit Your Podcast

Contact

  • [email protected]
  • Twitter
Your feedback is valuable to us. Should you encounter any bugs, glitches, lack of functionality or other problems, please email us at [email protected] or join where you can talk directly to the dev team.
© MoonFM 2026. All rights reserved.