

Firewalls Don't Stop Dragons Podcast
Carey Parker
A Podcast on Computer Security & Privacy for Non-Techies
Episodes
Mentioned books

Dec 29, 2025 • 59min
Best of 2025 Bonus Content
Every week, I record a special, private bonus podcast for my patrons. Normally all of that content is restricted to my supporters. But today I’ve got a sampler platter of some of the best snippets from my bonus Q&A with my interview guests. You’ll hear from Yael Grauer (Consumer Reports), Josh Summers (All Things Secured), Lisa LeVasseur (Internet Safety Labs), Josh Corman (UnDisruptable27), Andy Liddell (EdTech Law Center), Carissa Véliz (author, professor), Eamonn Maguire (Proton), Grace Menna & Adrien Ogee (Cyber Resilience Corps). Enjoy!
Original Interview Links
Ep416: Yael Grauer: https://podcast.firewallsdontstopdragons.com/2025/02/17/security-planner/
Ep420: Josh Summers: https://podcast.firewallsdontstopdragons.com/2025/03/17/all-things-secured/
Ep422: Lisa LeVasseur: https://podcast.firewallsdontstopdragons.com/2025/03/31/microscoping-our-apps/
Ep428: Josh Corman: https://podcast.firewallsdontstopdragons.com/2025/05/12/shelter-from-the-storm/
Ep426: Andy Liddell: https://podcast.firewallsdontstopdragons.com/2025/07/07/defending-student-privacy/
Ep438: Deviant Ollaf: https://podcast.firewallsdontstopdragons.com/2025/07/21/passport-lawyer-locksmith/
Ep446: Carissa Véliz: https://podcast.firewallsdontstopdragons.com/2025/09/15/on-the-ethics-of-ai/
Ep453: Eamonn Maguire: https://podcast.firewallsdontstopdragons.com/2025/10/27/privacy-focused-ai/
Ep454: Grace Menna & Adrien Ogee: https://podcast.firewallsdontstopdragons.com/2025/11/10/becoming-cyber-resilient/
Security Planner: https://securityplanner.consumerreports.org/
App Microscope: https://appmicroscope.org/
Take 9: https://pausetake9.org/
Meshtastic: https://meshtastic.org/
Previous dragon coin promo: https://firewallsdontstopdragons.com/dragon-coin-promo/
CISA Bad Practices: https://www.cisa.gov/news-events/news/bad-practices-0
Further Info
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:07: Intro
0:03:55: Ep416: Yael Grauer
0:10:51: Ep420: Josh Summers
0:16:36: Ep422: Lisa LaVasseur
0:22:21: Ep428: Josh Corman
0:30:03: Ep426: Andy Liddell
0:35:49: Ep438: Deviant
0:41:55: Ep446: Carissa Veliz
0:47:12: Ep450: Jake Braun
0:52:55: Ep454: Grace Menna & Adrien Ogee
0:55:44: Wrap-up

Dec 22, 2025 • 1h 3min
Replay: Stop Reusing Passwords
I’m digging into the vault for a classic interview – a blast from the past! I’ve done 460 episodes over the last nearly 9 years, and some of the best old episodes still hold up well today. I first interviewed Troy Hunt, creator of Have I Been Pwned, in February of 2019. It was Episode 102 and it was entitled “You Must Stop Reusing Passwords”. In this episode we talk a little about the origins of HIBP, password security, data breaches and brokers, and how to keep our accounts secure. I’ve added some new commentary, but the original episode is preserved in all of its glory!
Interview Notes
Have I Been Pwned? https://haveibeenpwned.com/
NIST updated password guidelines: https://pages.nist.gov/800-63-4/sp800-63c.html
Proton summary of NIST changes: https://proton.me/blog/nist-password-guidelines
Password haystacks: https://firewallsdontstopdragons.com/need-a-bigger-password-haystack/
Choosing a strong PIN: https://firewallsdontstopdragons.com/how-to-choose-a-pin/
Using passphrases: https://podcast.firewallsdontstopdragons.com/2021/05/24/how-when-to-use-a-passphrase/
On passkeys: https://podcast.firewallsdontstopdragons.com/2023/05/22/problems-with-passkeys/
Further Info
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:07: Intro
0:00:32: Interview setup
0:02:52: What is Have I Been Pwned?
0:05:37: What is a data breach?
0:06:42: Where do you get data breach records?
0:08:18: What is the “dark web”?
0:10:35: How do YOU get breach data?
0:11:43: What were some of the worst data breaches?
0:15:09: Who is behind these breaches?
0:17:03: How often are data brokers hacked?
0:19:47: Is it that hard to protect our data?
0:21:22: Is there no liability for not protecting data?
0:24:16: What about breach disclosure laws?
0:26:00: Do class action lawsuits provide accountability?
0:29:00: How can consumers evaluate a company’s data security?
0:32:35: Is data collection inherently bad?
0:34:43: How can we best use HIBP?
0:36:59: Should sites be rejecting known-bad passwords?
0:39:37: Why do some sites limit the use of special characters?
0:41:50: How up-to-date is HIBP data?
0:44:25: What does registering for notifications do?
0:45:39: What is your “opt out” feature?
0:46:25: Can hackers use HIBP for nefarious purposes?
0:48:16: Any other password advice?
0:50:27: Which services integrate with HIBP?
0:52:19: Wrap-up
0:54:52: New password guidelines
1:01:45: Patron podcast preview
1:02:12: Looking ahead

Dec 15, 2025 • 1h 18min
Best of 2025!
Cory Doctorow, an influential author and technology activist, dives into the socio-economic impacts of AI and the shifting dynamics of labor. He explains the concepts of centaurs and reverse centaurs, highlighting how automation can both enhance and complicate work processes. Doctorow also discusses the precarious nature of algorithm-driven jobs and raises concerns about growing inequality in the job market. His insights offer a thought-provoking look at the future of work in an automated world.

Dec 8, 2025 • 60min
40 Years of Phrack
Dive into the vibrant history of Phrack, a pioneering zine that emerged from the early BBS culture. Explore the quirky world of phone phreaking, blue boxes, and the economics of accessing remote networks. Discover the ethos behind hacking as an art form and the significance of the Hacker Manifesto. Delve into the legacy of influential articles like 'Smashing the Stack' and ponder the evolution of hacker culture amid today's AI advancements. This journey captures the spirit of innovation and rebellion in the digital age.

Dec 1, 2025 • 1h 9min
Be Wary of Holiday Scams
As the holiday season approaches, scammers ramp up their activities. The discussion covers alarming current scams, including the ClickFix malware trick and a clever Apple Support phishing scheme. Learn how to protect yourself from clipboard attacks and the importance of using hardware security keys. The podcast also touches on recent cybersecurity news, like the FCC scrapping essential rules and the end of a flight records program. Plus, there are festive gift suggestions, focusing on privacy-conscious options and tools to safeguard your network.

Nov 24, 2025 • 1h 29min
Best & Worst Gifts for 2025!
Join smart-home expert Stacey Higginbotham, cybersecurity manager Yael Grauer, and security consultant Jeff Landale as they dive into holiday tech gifting. They share strategies for choosing gifts that prioritize privacy and ease of setup. Expect tales of tech gift disasters and a candid discussion on invasive AI ads and problematic devices to avoid. The trio also highlights alternative non-tech gifts and offers tips for ensuring a smooth gifting experience. Tune in for insights that will help you navigate the tricky landscape of tech presents!

Nov 17, 2025 • 1h 18min
Erasing Your Online Data
Dive into the murky waters of online privacy! Learn how data brokers collect your personal information and discover an easy way to remove it. Meta's new policy allows ads based on your AI chats, while Google's shopping tool raises eyebrows about AI handling purchases. Explore OpenTable's controversial guest profiling and the revelation of the first AI-driven espionage campaign. With lawmakers pushing VPN bans and new health privacy regulations on the table, the landscape of your digital safety is evolving fast.

5 snips
Nov 10, 2025 • 1h 50min
Becoming Cyber Resilient
In a powerful discussion, Grace Menna, a public interest cybersecurity fellow, joins legal expert Michael Razeeq, emergency management coordinator Eric Franco, and COO Adrien Ogee. They explore the urgent need for cybersecurity volunteers to support under-resourced organizations facing increasing cyber threats. Topics include the formation of the Cyber Resilience Corps, the challenges of trust and confidentiality in volunteer efforts, and strategies for sustainable funding. The team emphasizes the importance of empowering communities to be self-sufficient and advocates for legal reforms to improve cybersecurity practices.

Nov 3, 2025 • 1h 2min
Removing Old Accounts
Today we’ll wrap up my series of tips for enumerating all your old online accounts and deciding whether to delete them or just dumb down the personal data they have on you. There are several things to consider – we’ll go through them all!
In other news: a study ranks the most private AI chatbots; LinkedIn is set to use your personal data to train their AI; ChatGPT has released an AI browser; new phishing scam for password manager creds; Gmail did not leak 183M passwords; man discovers his robot vacuum sharing lots of personal data; more info on Cellebrite’s mobile hacking abilities; Flock expanded its surveillance with Ring and drones; and group finds that half of our satellite communications are not encrypted.
Article Links
Which Generative AI Is Most Privacy-Respecting? https://www.obscureiq.com/which-generative-ai-is-most-privacy-respecting/
LinkedIn will use your data to train AI – how to opt out https://proton.me/blog/linkedin-ai-training
Chatgpt Atlas Browser https://www.washingtonpost.com/technology/2025/10/22/chatgpt-atlas-browser/
Phishing scam uses fake death notices to trick LastPass users https://www.malwarebytes.com/blog/news/2025/10/phishing-scam-uses-fake-death-notices-to-trick-lastpass-users
No, Gmail has not suffered a massive 183 million passwords breach https://www.techradar.com/pro/security/no-gmail-has-not-suffered-a-massive-183-million-passwords-breach-but-you-should-still-look-after-your-data
Man Alarmed to Discover His Smart Vacuum Was Broadcasting a Secret Map of His House https://futurism.com/robots-and-machines/robot-vacuum-broadcasting
Someone Snuck Into a Cellebrite Microsoft Teams Call and Leaked Phone Unlocking Details https://www.404media.co/someone-snuck-into-a-cellebrite-microsoft-teams-call-and-leaked-phone-unlocking-details/
Ring cameras are about to get increasingly chummy with law enforcement https://arstechnica.com/gadgets/2025/10/ring-cameras-are-about-to-get-increasingly-chummy-with-law-enforcement/
Exclusive: Flock Safety paid over $300 million for 17-month-old drone startup Aerodome https://techcrunch.com/2024/10/23/flock-safety-paid-over-300-million-for-17-month-old-drone-startup-aerodome/
Leak From the Sky: It Turns Out a Lot of Satellite Data Is Unencrypted” https://www.pcmag.com/news/leak-from-the-sky-it-turns-out-a-lot-of-satellite-data-is-unencrypted
Tip of the Week: https://firewallsdontstopdragons.com/removing-old-accounts/
Further Info
Data Diet series: https://firewallsdontstopdragons.com/data-diet-introduction/
Backing up 2FA seed codes: https://firewallsdontstopdragons.com/how-to-backup-2fa-seed-codes/
Using email aliases: https://firewallsdontstopdragons.com/how-to-use-email-aliases-part-1/
Claudito: https://github.com/micahflee/claudito
LM Studio: https://lmstudio.ai/
Dark Wire book: https://www.hachettebookgroup.com/titles/joseph-cox/dark-wire/9781541702691/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:07: Intro
0:00:27: News briefs
0:01:49: News preview
0:03:53: Which AI Is Most Privacy-Respecting?
0:09:21: LinkedIn will use your data to train AI
0:14:23: ChatGPT’s new Altas browser
0:21:46: Phishing scam uses fake death notices
0:25:32: Gmail has NOT suffered a massive password breach
0:27:57: Man finds smart vacuum sending maps of home
0:33:41: More Cellebrite capability details leak
0:38:28: Flock inks deal with Ring cameras
0:42:57: Flock Safety buys drone company
0:46:52: Half of satellite comms are unencrypted
0:51:26: Tip of the Week
1:00:01: Patron podcast preview
1:00:18: Looking ahead
1:01:39: New patron promotion coming?

Oct 27, 2025 • 1h 37min
Privacy-Focused AI
In this engaging discussion, Eamonn Maguire, Director of Engineering for AI at Proton, dives into the urgent privacy concerns surrounding AI chatbots. He highlights the risks of data harvesting and the implications of training AI on personal information. Eamonn explains Proton's innovative Lumo model, designed to prioritize privacy with zero access encryption and a no-logs policy. He also shares the importance of transparency, the potential of open-source technology, and how local-only options can enhance user security in a rapidly evolving digital landscape.


