Heated seats, car privacy, and Graham’s porn video
Sep 21, 2023
auto_awesome
Andrew Agnês, a member of Host Unknown, and Mark Jow from Gigamon join cybersecurity veterans Graham Cluley and Carole Theriault in discussing topics such as car privacy concerns, heated car seats subscription, and an unusual email from YouPorn. They also touch on automated compliance with Drita, Rask AI's video translation, and the importance of secure data transmission in the cloud.
Car manufacturers are collecting unnecessary personal data from cars and using it for unrelated purposes.
Gigamon's survey highlights a gap between perception and reality in hybrid cloud security, emphasizing the need for better solutions.
Cars have the worst privacy practices among IoT devices, with car companies collecting excessive personal data and using it for targeted marketing purposes.
Deep dives
The Following Events are Based on a Pack of Lies - A Dark Comic Drama
The Following Events are Based on a Pack of Lies is a dark comic drama created by Vince Gilligan, the creator of Breaking Bad and Better Call Saul. The show follows Alice as she tries to save her wealthy and newly widowed author from her estranged husband, who is posing as an eco disruptor. The show is full of twists and turns and explores themes of gaslighting and deception.
Rask AI - Realistic Voice Translation
Rask AI is an online platform that allows users to upload videos and have their voice translated into different languages. It can extract the audio or even lip sync the translated voice with the original video. This tool is useful for content creators who want to reach audiences in different countries without needing to speak the languages themselves.
Gigamon Hybrid Cloud Security Survey 2023 - Perception vs Reality
Gigamon recently conducted a survey of senior IT and security leaders and found a perception versus reality gap when it comes to hybrid cloud security. While the majority of respondents claimed to have the required levels of visibility and confidence in repelling attacks, a significant number also reported breaches, often without knowing how they occurred. The survey highlights the challenge of effectively dealing with encrypted data and the need for better solutions to ensure the security of organizations' networks and data.
Privacy Concerns in Connected Cars
A team of researchers at the Mozilla Foundation has conducted an extensive investigation into the privacy practices of 25 car brands. The study revealed that all 25 brands collected more personal data than necessary and used it for purposes unrelated to operating the vehicle or managing customer relationships. For example, Subaru's privacy policy stated that passengers who used connected services had consented to allowing the company to use and potentially sell their personal information. Additionally, Nissan's privacy notice mentioned the collection and potential sharing of sensitive personal information like sexual activity, health diagnoses, and genetic information for targeted marketing purposes. The study concluded that cars, as a category of products, had the worst privacy practices among all the IoT devices investigated by the team.
Call for Transparency and Privacy Standards
Given the concerning findings of the privacy investigation, the Mozilla community is urging car companies to reconsider their extensive data collection practices. They are calling for greater transparency and are asking car companies to halt their data collection programs. Mozilla proposes the creation of a privacy score or similar rating system for connected devices like cars, allowing consumers to make informed decisions about the privacy practices of different brands. The goal is to ensure that companies prioritize user privacy and data protection while delivering connected features and functionality. By joining this initiative and adding their names to the list, individuals can show their support for stronger privacy standards in the automotive industry.
Do you know what data your car is collecting about you? Do you think it's right for a car manufacturer to collect a subscription to keep your bottom warm? And just why has YouPorn sent an email to Graham about his sex video?
All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by cybersecurity veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Andrew Agnês.
Plus don't miss our featured interview with Gigamon's Mark Jow.
Warning: This podcast may contain nuts, adult themes, and rude language.
Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Device Trust for Okta. Watch the demo today!
Gigamon – Download the Gigamon Hybrid Cloud Security Survey to learn about the hidden dangers of encrypted traffic.
Drata – With over 14 frameworks including SOC2, GDPR, HIPAA, and ISO 27001, Drata gets you audit-ready for crucial security standards needed to scale your business. As a listener to Smashing Security you can save 10% off Drata and have implementation fees waived.
SUPPORT THE SHOW:
Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
Become a supporter via Patreon or Apple Podcasts for ad-free episodes and our early-release feed!