Smashing Security

Graham Cluley
undefined
Aug 29, 2018 • 37min

093: Abandoned domains and dating app dangers

How do fraudsters exploit abandoned domains to steal your company's secrets? How can you better protect your privacy when looking for love online? And who has the longest arms in the animal kingdom?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who were joined briefly by a man in a wind tunnel for this episode.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGSupport Smashing SecurityLinks:What do the drsolomon.com and sands.co.uk domains look like now?Hacking law firms with abandoned domain namesFraudsters Can Access Sensitive Information from Abandoned DomainsHave I Been Pwned: Domain searchJohn and Lorena BobbittHe Used Tinder to Hunt the Women He Raped and Killed, Police SayMissing Paperwork Got Him Out of Jail. Then, Police Say, He Raped and KilledMan jailed after attempting to rob man he met on dating appSearch for images with reverse image searchSwytch lets you use up to five 'burner' UK phone numbers from a single deviceSmashing Security 072: Why are firms so cr*p with our private data?A Hacker's Guide to Protecting Your Privacy While Dating How to Protect Your Privacy While Online DatingGibbons have the longest arms relative to body size of any primateBomb Chicken Teaser Trailer - YouTubeBomb Chicken for Nintendo SwitchFortnite fury over how Google handled its security holeThe Godless Spellchecker podcastSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Aug 22, 2018 • 52min

092: Hacky sack hack hack

Is your used car still connected to its old owner? Just how did Apple manage to identify the teenager hacker who stole 90GB of the firm's files? And why on earth would a firm of lawyers start producing pornographic videos? You'll be surprised by the answers!All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Paul Ducklin.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Connected car data handover headache: There's no quick fix... and it's NOT just Land RoversShock Land Rover Discovery: Sellers could meddle with connected cars if not unboundThe hidden data danger of the ‘Connected’ carYour BMW or Merc may also be at risk of being hacked, because of your iOS appSamy, the MySpace worm written by Samy KamkarApple hacked by 16-year-old who “dreamed” of working for firmMelbourne teen hacked into Apple's secure computer network, court toldPrenda Law stories at TechdirtMinneapolis lawyer pleads guilty to federal fraud, money laundering charges in porn troll schemeCybercrime Investigations podcast with Geoff WhiteFlash Drives for FreedomFinal SpaceSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Aug 15, 2018 • 48min

091: Sextortion, Las Vegas hotels, and Alex Jones

Just how did sextortionists get (some) of the digits in your phone number? Why are some hackers saying they won't be going to DEF CON in Las Vegas anymore? And should Alex Jones from InfoWars be banned from Twitter?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Maria Varmazis.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Maria Varmazis.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGSupport Smashing SecurityLinks:The Podcast Awards - The People's ChoiceSex extortion emails now quoting part of their victim's phone numberNew Extortion Tricks: Now Including Your (Partial) Phone Number!In post-massacre Vegas, security policies clash with privacy valuesKatie Moussouris tweets about her Las Vegas hotel experienceVideo Shows Hotel Security at DEF CON Joking About Posting Photos of Guests' Belongings to SnapchatGoogle Spectre whizz kicked out of Caesars, blocked from DEF CON over hack 'attack' tweetOpen letter to the Hacker Community from DEF CON's Head of SecurityAlex Jones banned from YouTube, Facebook, and Apple, explainedFacebook, Apple, YouTube and Spotify ban Infowars' Alex JonesNow even YouPorn has banned Alex Jones, but he’s still on TwitterTwitter temporarily blocks Alex Jones from tweetingThe Twitter RulesGiving social networking back to you - The Mastodon ProjectCharlottesville: Why one man is suing Alex Jones for defamationShannon Coulter tweets about blocking Fortune 500 companies until Alex Jones is banned from Twitterlichess.org - Free Online ChessMagnus Carlsen playing as Dr Drunkenstein - YouTubeOctopath Traveler for Nintendo SwitchAlex Jones Rants as an Indie Folk Song - YouTubeSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Aug 8, 2018 • 37min

090: Fortnite for Android, and the FCC's DDoS BS

Fortnite players are told they'll have to disable a security setting on Android, the FCC finally admits that it wasn't hit by a DDoS attack, and Verizon's VPN smallprint raises privacy concerns.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by David Bisson.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: David Bisson.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:You'll have to disable a recommended Android security setting to install FortniteFortnite is putting users at risk, to prove a point about Google's Android monopolyIntroducing Android 9 PieSafe-WiFi Wireless Private Network - Verizon WirelessVerizon Didn’t Bother to Write a Privacy Policy for its ‘Privacy Protecting’ VPNTerms of Service for the Verizon Safe Wi Fi AppMcAfee Privacy NoticeVerizon customers can sue ad company over “zombie” cookies, judges rule Ajit Pai blames Obama administration over FCC DDoS attack that didn't happenInside the FCC's risky IT overhaulThe Triceratops Who Loved Me: A Primal Urges Extreme Fantasy - AmazonA Good Movie To WatchOvercooked! 2 for Nintendo SwitchChristopher Robin: Winnie the Pooh film denied release in ChinaSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Aug 1, 2018 • 45min

089: Data breaches, ransomware, Bitcoin robberies, and typewriters

Ransomware rears its head again, Dixons Carphone reveals its data breach was almost 1000% worse than they previously thought, a man is accused of stealing five million dollars worth of cryptocurrency through hijacking mobile phones, and a Canadian guy called Norman is rushing to get the typewriters out of storage.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by journalist Geoff White.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Geoff White.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGLastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Shipping company’s networks in the Americas crippled by ransomware attackYahoo addresses used by Cosco following ransomware attackBitPaymer Ransomware Infection Forces Alaskan Town to Use Typewriters for a WeekJim Hagemann Snabe, Maersk chairman, describing their recovery from the NotPetya ransomware - YouTubeDixons Carphone admits hack far bigger than originally thoughtDixons Carphone breach statement (June 2018)Dixons Carphone updated breach statement (July 2018)‘Tell your dad to give us Bitcoin’ How a Hacker Allegedly Stole Millions by Hijacking Phone NumbersSmashing Security 086: Elon Musk submarine scams and 2FA bypassSlow Burn: A Podcast About WatergateBill Clinton: "I did not have sexual relations with that woman" - YouTubeHow an Ex-Cop Rigged McDonald’s Monopoly Game and Stole MillionsLegion Season 2 Teaser Trailer - YouTubeLegion Season 2 - AmazonSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Jul 25, 2018 • 43min

088: PayPal’s Venmo app even makes your drug purchases public

Websites still using HTTP are marked as "not secure" by Chrome, 85,000 Google employees haven't been phished for a year, and if you're buying drugs via PayPal’s Venmo app you should say goodbye to privacy.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Scott Helme.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Theme tune: "Vinyl Memories" by Mikael Manvelyan.Assorted sound effects: AudioBlocks.Special Guest: Scott Helme.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Vote for Smashing Security in the podcast awards!Smashing Security 039: Woah - are we talking to a cyborg?Google: Security Keys Neutralized Employee PhishingYubicoLess than 10% of Gmail users have enabled two-factor authenticationGoogle's Advanced Protection ProgramWhat is Google’s Advanced Protection Program? - YouTubeTwo-factor authentication versus two-step verificationOne small step for a browser, one giant leap for web security!Chrome browser flags Daily Mail and other sites as 'not secure'How to change Chrome's settings to be more in-your-face when you visit an unencrypted HTTP sitePublic by Default - Venmo Stories of 2017Why I Blasted Your “Drug” Deals on TwitterPayPal's Venmo App Exposes Most Transactions via Its APIReporting Trump's First Year: The Fourth Estate - BBCWhy No HTTPS? The World's Largest Websites Not Redirecting Insecure Requests to HTTPSScott Helme tweets about NewsNow's support for both HTTP and HTTPSNewsNow.co.ukSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Jul 18, 2018 • 45min

087: How Russia hacked the US election

Regardless of whether Donald Trump believes Russia hacked the Democrats in the run-up to the US Presidential election or not, we explain how they did it. And Carole explores some of the creepier things being done in the name of surveillance.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGLastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Vote for Smashing Security in the podcast awards!Scammers strike as Elon Musk retracts vile Twitter accusation against cave rescuerDonald Trump 'encourages Russia to hack Clinton emails' - YouTubeIndictment against 12 Russian hackersBears in the Midst: Intrusion into the Democratic National CommitteeThis is the email that hacked Hillary Clinton’s campaign chiefGuccifer 2.0’s schoolboy error reveals he’s hacking from MoscowAmazon Rekognition – Video and Image Amazon shareholders demand company stop selling facial recognition technology to governmentsMetropolitan Police's facial recognition technology 98% inaccurate, figures showLooking to Listen: Audio-Visual Speech SeparationCalifornia Shopping Centers Are Spying for an ICE ContractorCalifornia passes landmark privacy legislationWalmart's Newly Patented Technology For Eavesdropping On Workers Presents Privacy ConcernsFind a track - BBC MusicThe Staircase - NetflixSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Jul 11, 2018 • 39min

086: Elon Musk submarine scams and 2FA bypass

The world has been gripped with the story of that soccer team, those poor boys... but enough about England's World Cup hopes being dashed, it's time for another episode of "Smashing Security".Crypto scamming Thai cave rescue scoundrels! $25 million to make anti-fake news videos! TimeHop data breach! Phone number port out scams!All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by the author of "Social media is bullshit", B J Mendelson.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Special Guest: B J Mendelson.Sponsored By:LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:Vote for "Smashing Security" in the Podcast AwardsThai Cave rescue scammers pose as Elon MuskWhy was Elon Musk at the Thai cave rescue?The full story of Thailand’s extraordinary cave rescueBad Checks: Twitter's Identity Crisis Is Costing Users More Than BitcoinYouTube Pledges $25 Million to Help Fight Fake NewsTimehop security incidentwhat3words | Addressing the worldJustified Season 1 Promo / trailer - YouTubeDear Joan and Jericha: agony aunts of the most ribald kindSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Jul 4, 2018 • 37min

085: Doctor Who, Facebook patents, and Bob's Burgers

Doctor Who's TARDIS has sprung a data leak, Facebook's creepy patents are unmasked, and an app to keep women safe on dates has surprising origins.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Special Guest: Maria Varmazis.Sponsored By:MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHINGLastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses.Support Smashing SecurityLinks:BBC Goes to Court to Identify 'Doctor Who' LeakerDoctor Who episodes leak online - should you download them?Reality Winner pleads guilty after being unmasked by microdotsGerman researchers defeat printers' doc-tracking dotsAre you happy with this technology that Facebook’s developing?Emma Sayle - CEO. Wife. Mother. Liberator. Feminist.Killing Kittens Parties Liberating Women WorldwideKate Middleton's friend holds orgies in sharia hotelSafe Date – Stay Safe And Get Peace Of Mind When DatingKilling Kittens sex party founder hopes new DateSafe app can improve women's safetyGeoGuessr - Let's explore the world!Playground Buddy - Helping Families Find PlaygroundsBlue Apron is releasing a smart, strong, sensual Bob’s Burgers meal kitEvery Burger From Bob's Burgers RankedSmashing Security merchandise (t-shirts, mugs, stickers and stuff)
undefined
Jun 27, 2018 • 34min

084: No! My voice is not my password

Who's been collecting the voice prints of millions of people saying "My voice is my password"? Why has it become tougher for law enforcement to scoop up cellphone data? And who's been turning up your central heating?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by John Hawes of AMTSO.Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes.Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening!Warning: This podcast may contain nuts, adult themes, and rude language.Special Guest: John Hawes.Sponsored By:VirusTotal: VirusTotal Intelligence is one of the world’s largest malware intelligence services. Security professionals rely on it to better understand the effects of malware in enterprise networks.Find out more at https://www.virustotal.com/learnSupport Smashing SecurityLinks:Voice ID showcases latest digital development for HMRC customersHMRC takes 5 million taxpayers’ Voice IDs without consent – Big Brother WatchUK taxman has amassed voice profiles of 5.1 million taxpayers BBC fools HSBC voice recognition security systemKnock down ginger — What Graham meant to say when he referred to "Postman's knock"Victory! Supreme Court Says Fourth Amendment Applies to Cell Phone TrackingThermostats, Locks and Lights: Digital Tools of Domestic AbuseSafety Net: the National Safe & Strategic Technology ProjectUS Tech Safety hotlinesUK National Domestic Violence HelplineWorldwide helpline directoryMusic-Map - The Tourist Map of MusicDel AmitriRon SexsmithBBC Radio 4 - Short CutsTandoori Lambchop Sent to Space (Meatspace) - YouTubeAdam Buxton podcast with Charlie BrookerSmashing Security merchandise (t-shirts, mugs, stickers and stuff)

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app