Smashing Security

Graham Cluley
undefined
Nov 7, 2018 • 53min

An Instagram nightmare, crazy iPhone deaths, and election hack claims

One travel blogger finds you don't have to be Kylie Jenner to be targeted by an Instagram hacker. When 40 iPhones at a hospital mysteriously die, what could be the explanation? And, surprise surprise, political parties in the USA are throwing around hacking accusations.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Naked Security's Mark Stockley.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Mark Stockley.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGLastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Kylie Jenner — Instagram.Hacker, angry over unpaid $200, deletes Abu Dhabi-based travel blogger's account — Gulf News.Of Travels & Tales — Delaine Maria D’Costa's blog.Delaine Maria D’Costa's Instagram accountIG hacked! — Delaine Maria D’Costa posts an Instagram story about how she was hacked.Instagram finally supports third-party authentication apps for greater account security — Graham Cluley.Spooky miasmic gas bricks hospital iPhones (mwah ha ha ha) — Naked Security.MRI disabled every iOS device in facility — Reddit.Voting Machine Manual Instructed Election Officials to Use Weak Passwords — Motherboard.After failed hacking attempt SoS launches investigation into Georgia Democratic party — Press release on Secretary of State's website (which, by the way, doesn't use HTTPS).Mid-term elections 2018: Race rows mire campaign home stretch — BBC News.The Cybersecurity 202: Brian Kemp's hacking allegations highlight the challenges of preserving voter confidence — The Washington Post.Georgia governor’s race roiled by election security charges — Associated Press.Elections security: Federal help or power grab? — Politico (2016).Georgia Officials Quietly Patched Security Holes They Said Didn't Exist — ProPublica.The Erasable Pen - Pilot Frixion - Gear for Back to School — YouTube.FriXion Family by PilotSapiens: A Brief History of Humankind by Yuval Noah Harari — We're not listing the Pick of the Week Mark eventually chose as it's too rude.Isle of Dogs movieSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Oct 31, 2018 • 48min

Ethical dilemmas, Girl Scouts, and porn-loving US officials

Who deserves to die in a driverless car crash? Who has been sniffing around the Girl Scouts' email account? And just how long would it take for a geologist to visit 9,000 adult web pages?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by journalist and "Friends" fan Dan Raywood.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Dan Raywood.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Self-Driving Cars: The Ethical Dilemma — YouTube.Moral Machine — A platform for gathering a human perspective on moral decisions made by machine intelligence, such as self-driving cars.Moral Machine - Human Perspectives on Machine Ethics — YouTube.Girl Scouts' personal information affected by recent data breach — ABC30.Girl Scouts Alerted to Possible Data Breach — Infosecurity Magazine.Where does Girl Scout cookie money go? — SAS Learning Post."You're a Big Scrud" — YouTube.USGS IT Security vulnerabilities (PDF) — Office of Inspector General management advisory.Porn-Watching Employee Infected Government Networks With Russian Malware, IG Says — NextGov.100 Feds Found to Be Frequent Workplace Porn-Watchers — Government Executive.Ten Years Ago — See what the internet was doing...The Wayback MachineDead Rock Stars podcastFree RiceWorld Food ProgrammeSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Oct 24, 2018 • 51min

Rule 34, Twitter scams, and Facebook fails

A Facebook friend request leads to arrest, Twitter scams ride again via promoted ads, and adult websites expose their members. Oh, and Graham finds out what Rule 34 is.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Maria Varmazis.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGLastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Robber contacts victim on Facebook to apologize, Reading police say — Reading EagleMaria Varmazis spots a promoted, verified scam tweet — TwitterWhy is Elon Musk promoting this Bitcoin scam? (He’s not) — Naked SecurityTwitter thought Elon Musk's bizarre tweets were evidence he'd been hacked — Graham CluleyHack on 8 adult websites exposes oodles of intimate user data — Ars TechnicaWife Lovers website snapshot — Wayback MachineFriends Reunited — WikipediaThe Beano — WikipediaFormer CIA Chief Explains How Spies Use Disguises — YouTubeWhat Makes ‘The Good Place’ So Good? — The New York TimesThe Good Place Season 1 Trailer — YouTubeTrolley problem — WikipediaIRL Glasses Block All the Screens Around You — WiredIRL Glasses - Glasses that Block Screens by Ivan Cash — KickstarterSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Oct 17, 2018 • 52min

IoT failures, and Donald Trump dating disaster

Yes, Smashing Security has reached its 100th episode!Despite our celebratory mood, we don't forget to take a look at the security stories of the last week - including an alarming IoT failure and a dating app disaster for Donald Trump devotees.All this and much more is discussed in this very special 100th edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Boxcryptor: Boxcryptor encrypts your sensitive files and folders in Dropbox, Google Drive, OneDrive and many other cloud storages. It combines the benefits of the most user friendly cloud storage services with the highest security standards worldwide. Encrypt your data right on your device before syncing it to the cloud providers of your choice.Listeners can get a 40% discount on the Boxcryptor Personal License (private use) and Boxcryptor Business (perfect for self-employed) by visiting smashingsecurity.com/boxcryptorSupport Smashing SecurityLinks:The very first episode of Smashing Security: "One cup, two hotel guests" — Sorry about the poor audio quality. Turns out we got better...Yale UK announces some "unplanned network maintenance" — TwitterYale UK's network maintenance isn't going well — TwitterCllr Steve Wortley is not very happy with Yale UK — TwitterBeth is not impressed with Yale UK either — TwitterKirstie Pendry doesn't fancy waking her entire street at 5am — TwitterYale Smart Home Borkage: Server Issues Cause Alarm App Fail — Computer Business ReviewYale Weds: Just some system maintenance, nothing to worry about. Yale Thurs: Nobody's smart alarm app works — The RegisterHundreds of 'smart' locks bricked by flubbed remote update — Graham CluleyHotel guests locked in their rooms by ransomware? It doesn't make sense — Graham Cluley71% of Tinder users say political differences are a deal breaker — MSNBCNew Dating App for Trump Supporters Seeks to ‘Make America Date Again’ — NewsweekThe ‘Donald Daters’ Trump Dating App Exposed Its Users’ Data — MotherboardDonald Daters, a dating app for Trump supporters, leaked its users’ data — TechcrunchHow I “found” the database of the Donald Daters AppRobert Baptiste's video of Donald Daters vulnerability — TwitterBlue Peter — WikipediaTony Walsh's beautiful tribute to Blue Peter will give you goosebumps — CBBC on TwitterJanet Ellis — WikipediaSophie Ellis-Bextor — WikipediaTony Walsh's performance of 'This Is The Place' at the Manchester attack vigil — YouTubeA Scary Time by Lynzy Lab — YouTubeSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Oct 10, 2018 • 17min

099: Passwords - A Smashing Security splinter (replay)

With Carole in the wilds of Canada, and Graham knee-deep in a security conference in Glasgow, we drag an episode out from the archives of February 2017 - looking at the thorny subject of passwords.Join computer security veterans Graham Cluley, Carole Theriault, and Vanja Švajcer as they offer some advice and tips for computer users.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Vanja Švajcer.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGLastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Smashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Oct 3, 2018 • 51min

098: A Facebook omnishambles

Millions of Facebook user accounts put at risk after hack! The UK Conservative party's conference app causes a privacy omnishambles! And Facebook (again) has been doing something naughty with the phone numbers you give it for security reasons! Oh, and Maria gets very excited about something to do with Star Trek.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Maria Varmazis.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Boxcryptor: Boxcryptor encrypts your sensitive files and folders in Dropbox, Google Drive, OneDrive and many other cloud storages. It combines the benefits of the most user friendly cloud storage services with the highest security standards worldwide. Encrypt your data right on your device before syncing it to the cloud providers of your choice.Listeners can get a 40% discount on the Boxcryptor Personal License (private use) and Boxcryptor Business (perfect for self-employed) by visiting smashingsecurity.com/boxcryptorSupport Smashing SecurityLinks:Our Podcast Awards trophy acceptance video — Even though we didn't actually win, we still thought you might like to see it.Virus Bulletin conference, Montreal — Say "Hi" to Carole if you see her there.Everything that went wrong during Theresa May’s 2017 conference speech - YouTubeDie Hard on the One Show - Charlie Brooker's Weekly Wipe - YouTubeConservative Party conference app reveals MPs' numbers - BBC NewsThe Tories Say They Were "Let Down" By A Conference App Platform After It Allowed Access To The Personal Numbers Of Hundreds Of MPsConference apps are crap and (mostly) pointlessSecurity Update – Facebook NewsroomThe Facebook Security Meltdown Exposes Way More Sites Than FacebookInvestigating sources of PII used in Facebook’s targeted advertising (PDF) — Research from Northeastern University.Facebook Is Giving Advertisers Access to Your Shadow Contact InformationYou Gave Facebook Your Number For Security. They Used It For Ads — The EFF is not impressed.The The One Show Show on iTunesmanwhohasitall (@manwhohasitall) on TwitterTiburn Enterprise Star Trek PC at Lenovo Tech World 2018 - YouTubeLenovo Sets Computer to Stun, Unveils Star Trek Enterprise PCSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Sep 26, 2018 • 44min

097: Dash cam surveillance, robocall plague, and Zoho woe

Why was Zoho's website taken offline by its own domain registrar? How are dash cams making you less secure? And why are robocalls on the rise in the United States?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Dave Bittner.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGSupport Smashing SecurityLinks:Update on Zoho Services Disruption - Zoho BlogZoho CEO Sridhar Vembu asks for help on TwitterWhoa – oh no, Zoho: Domain name no-show deals CRM biz, 40m punters a crushing blowDomain registrar oversteps taking down Zoho domain, impacts over 30Mil usersBlackvue Dash-Cams Broadcasting Live Video and GPS of Your Car PUBLICLY by DEFAULT! - YouTubeTim Woodruff's tweet about BlackVue dash camsYes, It’s Bad. Robocalls, and Their Scams, Are SurgingYouMail - Robocall Index4.2 Billion Robocalls in August Set All-Time Record for YouMail Robocall IndexDoes Local Presence Dialing Really Work?National Do Not Call RegistryThe Robocall Nightmare Is Getting WorseUS Court Finds Anti-Robocall Rule Made Nearly Every Smartphone User a CriminalStop Unwanted Robocalls and Texts - FCCLeatherman Micra 10-in-1 Multi-ToolTechmoan - YouTubeThe Guild of Ambience - YouTube Smashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Sep 19, 2018 • 34min

096: Bribing Amazon staff, and blinking deepfakes

Amazon staff are being bribed to delete negative reviews and leak data, deepfakes are getting more dangerous, an update on John McAfee's bitcoin bet, and our guest gets a shock...All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week (for a while at least) by David Bisson.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: David Bisson.Sponsored By:Boxcryptor: Boxcryptor encrypts your sensitive files and folders in Dropbox, Google Drive, OneDrive and many other cloud storages. It combines the benefits of the most user friendly cloud storage services with the highest security standards worldwide. Encrypt your data right on your device before syncing it to the cloud providers of your choice.Listeners can get a 40% discount on the Boxcryptor Personal License (private use) and Boxcryptor Business (perfect for self-employed) by visiting smashingsecurity.com/boxcryptorSupport Smashing SecurityLinks:'Pull your finger out' - the phrase's meaning and originAmazon Investigates Employees Leaking Data for Bribes - WSJAmazon staff said to be taking bribes to leak dataCrooked firms bribe customers with free gifts to leave fake reviewsSmashing Security 063: Carole's back! (where Maria Varmazis discusses deepfakes)Carnegie Mellon Researchers Develop New Deepfake MethodTransferring One Video Into the Style of Another - YouTubeThe Secret to Detecting Deep Fakes Is in the Eye BlinksReddit bans ‘deepfakes’ AI porn communitiesBitcoin Price Prediction TrackerSerious Eats: The Destination for DeliciousJoyofBaking.comHow to cook the perfect ... Smashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Sep 12, 2018 • 42min

095: British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked

Malicious script is being blamed for the British Airways hack, Trend Micro's apps are booted out of the Mac App Store for snaffling private data, and Paul Manafort's daughter wants Twitter to remove a link.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by David Emm of Kaspersky Lab.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: David Emm.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGSupport Smashing SecurityLinks:A Deceitful 'Doctor' in the Mac App StoreAlert: Adware Doctor stealing your files - YouTube videoApps that steal users' browser histories kicked out of the Mac App storeTrend Micro apologises after Mac apps found scooping up users' browser historyBritish Airways hacked - customer data and details of 380,000 card payments stolenThe British Airways Breach: How Magecart Claimed 380,000 VictimsBritish Airways hack: Infosec experts finger third-party scripts on payment pagesLaw firm launches £500 million group action over British Airways hackBritish Airways Fly The Flag We'll Take More Care Of You 1979 UK Advert - YouTubeHacked texts from family of former Trump campaign manager surface on the dark webManafort's Daughter's Lawyers Pressured Twitter to Delete Links to Hacked Text MessagesWikileaks Refused To Publish Manafort Family Texts, So Someone Else DidAirHelpHow Employing Autistic People Can Help Stop Cyber-AttacksMcFadden's Cold War (@Coldwar_Steve) on TwitterWhen Phil Mitchell met Trump: Coldwar Steve and his Brexit Britain mashupsNoel Edmonds - WikipediaSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Sep 5, 2018 • 52min

094: Rogue browser extensions, Twitter presence, and how to cheat in exams

What's the danger when browser extensions go bad? Is Twitter sharing your online status a boon for stalkers? And which of the show's hosts is going to admit to cheating in their exams?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by technology journalist David McClelland.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: David McClelland.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:MEGA.nz Chrome extension caught stealing passwords, cryptocurrency private keysSecurity warnings for MEGA Chrome extension usersTwitter testing new feature that reveals when you're online... Who other than stalkers actually wants this?Giving social networking back to you - The Mastodon ProjectGraham Cluley on MastodonPhotomath - Camera calculatorTechnology Gives Students Innovative Tools for CheatingStudents’ cheating takes a high-tech turnMicrosoft Education: Take a Test - YouTubeRequired to install school malware on my personal computer - RedditThe Lord of the Rings (1978 film) - WikipediaRotoscoping - WikipediaTower – Official Trailer - YouTubeTower - NetflixCone - Live Color PickerThe dress - WikipediaA professor and his son-in-law came up with a brilliant invention to slash water use by 98% – Ikea is already a partnerAltered:CompanyAltered:Nozzle - YouTubeSmashing Security merchandise (t-shirts, mugs, stickers and stuff)

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app