

Firewalls Don't Stop Dragons Podcast
Carey Parker
A Podcast on Computer Security & Privacy for Non-Techies
Episodes
Mentioned books

Jul 3, 2023 • 1h 2min
Access Backup Plan
You’re using a password manager. You’re even using two-factor authentication. Great! When done properly, this will keep the bad guys out. Unfortunately, if you’re not careful, it may also keep you out. If you forget your master password or lose access to your 2FA device, you’ll be in real trouble… unless you have an access backup plan. This same plan can also help your spouse or next of kin to access your accounts should you die or become incapacitated.
In the news: CISA issues a DDoS warning after multiple attacks; LetMeSpy stalkerware maker suffers a data breach of collected data; researchers use LED power light flicker to break cryptographic keys; Australian PM recommends citizens to power cycle their phones once a day; several artists boycott venues that use facial recognition; Brave browser introduces new localhost access permission; Proton unveils new password manager; Dear Carey questioner asks about PDF readers.
Article Links
[BleepingComputer] CISA issues DDoS warning after attacks hit multiple US orgs https://www.bleepingcomputer.com/news/security/cisa-issues-ddos-warning-after-attacks-hit-multiple-us-orgs/
[TechCrunch] LetMeSpy, a phone tracking app spying on thousands, says it was hacked https://techcrunch.com/2023/06/27/letmespy-hacked-spyware-thousands/
[The Hacker News] Researchers Find Way to Recover Cryptographic Keys by Analyzing LED Flickers https://thehackernews.com/2023/06/researchers-find-way-to-recover.html
[9to5mac.com] Why tips like ‘turn off your iPhone for five minutes’ don’t actually help users https://9to5mac.com/2023/06/26/turn-off-your-iphone-for-5-minutes-advice/
[Rolling Stone] Tom Morello, Zack de la Rocha, and Boots Riley Boycotting Venues That Use Face-Scanning Technology https://www.rollingstone.com/music/music-features/tom-morello-zack-de-la-rocha-facial-recognition-concerts-boycott-1234775909/
[BleepingComputer] Brave Browser boosts privacy with new local resources restrictions https://www.bleepingcomputer.com/news/security/brave-browser-boosts-privacy-with-new-local-resources-restrictions/
[9to5mac.com] Proton Pass end-to-end encrypted password manager is here and free for everyone https://9to5mac.com/2023/06/28/proton-pass-encrypted-password-manager-free/
Tip of the Week – Access Backup Plan: https://firewallsdontstopdragons.com/craft-your-access-backup-plan/
Further Info
Saving your Apple Photo Stream pics: https://support.apple.com/en-us/HT210705
Securityzed podcast: https://www.securityzed.com/podcast-test/securityzed-ltfyn-7xm5l-b8c8s-km25d-jbagp-6k9d4-39cr9-z5nhw-w4jwm
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:00: Photo Stream, Securityzed podcast
0:03:21: News rundown
0:05:10: CISA issues DDoS warning after attacks hit multiple US orgs
0:09:29: LetMeSpy stalkerware maker says it was hacked
0:16:43: Researchers Recover Crypto Keys from LED Flickers
0:24:07: Turn your iPhone off every day for 5 mins?
0:29:39: Artists boycotting venues that Use Face-Scanning Technology
0:34:02: Brave Browser boosts privacy with localhost restrictions
0:41:28: Proton debuts new password manager
0:45:56: Dear Carey question
0:50:05: Tip of the Week
1:00:32: Wrap-up

Jun 26, 2023 • 1h 6min
Hacking in Space
Right now there are thousands of satellites orbiting above our heads performing crucial tasks. At the end of the day, they’re just computers running software – albeit at thousands of miles up and thousands of miles per hour. Can they be hacked? What are the dangers? Aaron Myrick and the Hack-A-Sat team are trying to answer those questions. And they’re doing it by launching an actual satellite into low earth orbit for this year’s DEF CON hacking contest and asking talented hackers from around the world to take their best shot.
Interview Notes
Moonlighter Fact Sheet: https://aerospace.org/fact-sheet/moonlighter-fact-sheet
Hack-A-Sat 4: https://hackasat.com/moonlighter/
Hack-A-Sat GitHub resources: https://github.com/deptofdefense/hack-a-sat-library
Space-Track.org: https://www.space-track.org/
Moonlighter launch: https://vimeo.com/833432259/4ba9b0927b
Further Info
Amulet of Entropy (DEF CON badge): https://amuletofentropy.com/
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:36: Update Apple devices, ASUS routers
0:01:03: Misc updates
0:03:08: Interview setup
0:04:19: What is Aerospace Corp and what do you do there?
0:08:25: What are things satellites do that we might not think about?
0:13:42: Break down some key stats on satellites for us.
0:17:27: How might we be affected by loss of satellites?
0:21:31: How do you hack an orbiting satellite, logistically?
0:24:38: What sorts of attacks are we worried about?
0:26:58: How do we debug problems in orbiting satellites?
0:30:55: How is hacking a satellite different from a computer?
0:35:23: What happens to old satellites?
0:41:26: What is the Hack-A-Sat program about?
0:43:35: How did the target systems work, prior to this year?
0:46:39: What have we learned so far from past contests?
0:51:24: What’s new with Hack-a-Sat 4?
0:52:43: When and how will Moonlighter launch?
0:58:30: What kinds of things can I hack on Moonlighter?
1:00:43: What’s the future for Hack-a-Sat?
1:03:26: Wrap-up

Jun 19, 2023 • 51min
Go Forth, Do Good Deeds
I launched my mission to improve people’s privacy and security almost ten years ago now. It’s been quite a journey and I’ve learned a lot in that time. One thing I’ve realized is that there’s only so much I can do on my own. And so I’ve encouraged the more technically savvy members of my audience to help others where they can. One downside to being a podcaster is that I don’t have much insight into the effectiveness of my exhortations. I have no idea how many people are going forth to do good deeds nor what those deeds are. So today I’m launching a new campaign to solicit stirring stories of good deeds and every quarter or so I will select the most inspiring deed-doers and reward them with one of my dragon challenge coins!
In the news: Clop ransomware gang lists first victims of MOVEit supply chain hacks; firmware bug in Gigabyte motherboards has a fix now; US Congress and intelligence agencies debate reform for mass surveillance program; tissue and fluid samples are being abused by law enforcement for DNA scans; check washing scams are on the rise; how to avoid being scammed by virtual kidnapping schemes; 1Password announces beta support for browser passkey extension; bold new plan for 311 cyber support line.
Article Links
[TechCrunch] Ransomware gang lists first victims of MOVEit mass-hacks, including US banks and universities https://techcrunch.com/2023/06/15/moveit-clop-mass-hacks-banks-universities/
[restoreprivacy.com] Hackers Stole Millions of Driver’s Licenses and IDs from U.S. States https://restoreprivacy.com/hackers-stole-millions-of-drivers-licenses-and-ids-from-u-s-states/
[Tom’s Hardware] Firmware Backdoor Discovered in Gigabyte Motherboards, 250+ Models Affected https://www.tomshardware.com/news/gigabyte-motherboards-come-with-a-firmware-backdoor
[cyberscoop.com] Congress and intelligence officials spar over surveillance reforms https://cyberscoop.com/congress-fbi-section-702/
Senate hearing: https://www.judiciary.senate.gov/oversight-of-section-702-of-the-foreign-intelligence-surveillance-act-and-related-surveillance-authorities
[aclu.org] Donated Blood or an Organ? Police Shouldn’t Have Easy Access to Your DNA https://www.aclu.org/news/privacy-technology/donated-blood-or-an-organ-police-shouldnt-have-easy-access-to-your-dna
[Lifehacker] Why You Should Stop Sending Checks in the Mail, Especially Now https://lifehacker.com/why-you-should-stop-sending-checks-in-the-mail-especia-1850543113
[connectsafely.org] Quick-Guide to Virtual Kidnapping Scams https://connectsafely.org/virtualkidnapping/
[9to5mac.com] 1Password passkey support for the web launches in public beta on the Mac https://9to5mac.com/2023/06/06/1password-passkey-browser-extension/
[WIRED] The Bold Plan to Create Cyber 311 Hotlines https://www.wired.com/story/ut-austin-cybersecurity-clinic-311/
Tip of the Week: Go Forth, Do Good Deeds: https://fdsd.me/quest
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:47: News preview
0:03:01: Clop Ransomware hits several public and privacy organizations
0:11:32: Firmware Backdoor Discovered in Gigabyte Motherboards
0:17:04: Congress and intelligence officials spar over surveillance reforms
0:24:13: Police Shouldn’t Have Easy Access to Your DNA
0:28:03: Why You Should Stop Sending Checks in the Mail
0:31:43: Quick-Guide to Virtual Kidnapping Scams
0:37:02: 1Password passkey support for the web launches in public beta
0:38:22: The Bold Plan to Create Cyber 311 Hotlines
0:41:02: Tip of the Week: Go forth, do good deeds
0:49:30: Look ahead

Jun 12, 2023 • 1h 6min
Making a Difference
At some point, when you care enough about a particular cause, you shift from following the issue to actually trying to advance the issue – to make a difference. The easiest way to do this is to find groups that are already working for this cause and supporting them with donations of your time and/or money. But what do you do if you can’t find such a group, or maybe there’s no local chapter? Well, you can start your own! It’s not as hard as it sounds – and in fact, there exist organizations that can help you. Today I’ll speak with Rory Mir from the Electronic Frontier Alliance along with leaders from two successful EFA-affiliated groups: Freddy Martinez from Lucy Parsons Labs and Chris Bushick from PDX Privacy.
Interview Notes
Reach out to EFF organizing team: organizing@eff.org
Electronic Frontier Alliance (EFA): https://www.eff.org/efa
Meetup groups: https://meetup.com
Lucy Parsons Labs: https://lucyparsonslabs.com/
PDX Privacy: https://www.pdxprivacy.org/
EFF on the EARN IT Act: https://www.eff.org/deeplinks/2023/05/dangerous-earn-it-bill-advances-out-committee-several-senators-offer-objections
Further Info
Dragon Coins! https://fdsd.me/coin2
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
0:00:25: Interview setup
0:04:32: Introductions and overview of EFA
0:09:12: Lucy Parsons Project overview
0:10:52: PDX Privacy overview
0:12:28: How has the EFA helped you with your projects?
0:15:33: What other types of groups work with the EFA?
0:17:49: What did you do before? What was it like starting your group?
0:23:02: How can you go about finding sources of funding?
0:25:25: What sorts of grants are available?
0:30:09: What accomplishments are you most proud of?
0:34:48: What were some of your biggest challenges?
0:38:51: Do you ever feel like you’re David versus Goliath?
0:42:26: How can I find existing groups that I can support or join?
0:45:58: What’s the first step in starting my own group?
0:49:31: If you were starting over again, what would you have done differently?
0:49:56: Do I need to incorporate or create a legal entity?
0:53:02: Can a non-profit organization make money?
0:57:32: Any parting thoughts you’d like to share?
1:00:32: Wrap-up
1:03:11: Looking ahead
1:04:09: Upcoming challenge coin campaign

Jun 5, 2023 • 1h 6min
Blocking .zip Domains
Two weeks ago, I told you about the availability of two new top-level domains that also happen to be popular file name extensions: .zip and .mov. The ambiguity will undoubtedly be exploited by ne’er-do-wells to trick people into doing something they shouldn’t do. There are clever ways to manipulate website addresses that would trick even tech-savvy people into clicking malicious links. Today I’ll tell you how these tricks work and explain you can avoid all of these issues by simply blocking these new domains.
In other news: iTunes for Windows patches a nasty bug; Android malware downloaded over 420 million times; Android phones vulnerable to fingerprint brute-force attacks; Luxottica exposes 300 million customer records; free VPN service SuperVPN exposes 360 million user records; Amazon gets slap on the wrist for Ring video doorbell private data access; KeePass “master password crack” not as bad as it sounds; Twitter adding Content Notes ‘fact checks’ to images; Microsoft now scanning inside password-protected zip files; drone pilot is NOT killed by drone; AI is NOT likely to cause human extinction; and Brave introduces new Off The Record browsing mode. Plus my Dear Carey question: recommended cheat sheet for computer safety.
Article Links
[MacRumors] PSA: If You Run Windows, Make Sure to Update iTunes to Fix Security Vulnerability https://www.macrumors.com/2023/06/01/itunes-windows-vulnerability/
[Lifehacker] This Android Malware Was Downloaded Over 420 Million Times https://lifehacker.com/this-android-malware-was-downloaded-over-420-million-ti-1850492306
[BleepingComputer] Android phones are vulnerable to fingerprint brute-force attacks https://www.bleepingcomputer.com/news/security/android-phones-are-vulnerable-to-fingerprint-brute-force-attacks/
[bitdefender.com] Luxottica 2021 breach: 300 million customer records up for grabs online https://www.bitdefender.com/blog/hotforsecurity/luxottica-2021-breach-300-million-customer-records-up-for-grabs-online/
[hackread.com] Free VPN Service SuperVPN Exposes 360 Million User Records https://www.hackread.com/free-vpn-service-supervpn-leaks-user-records/
[AppleInsider] Amazon gets slap on the wrist over privacy violations with Ring cameras https://appleinsider.com/articles/23/05/31/amazon-gets-slap-on-the-wrist-over-privacy-violations-with-ring-cameras
[Naked Security] Serious Security: That KeePass “master password crack”, and what we can learn from it https://nakedsecurity.sophos.com/2023/05/31/serious-security-that-keepass-master-password-crack-and-what-we-can-learn-from-it/
[Mashable] Twitter will now put Community Notes ‘fact checks’ on images https://mashable.com/article/twitter-notes-on-media-images
[Ars Technica] Microsoft is scanning the inside of password-protected zip files for malware https://arstechnica.com/information-technology/2023/05/microsoft-is-scanning-the-inside-of-password-protected-zip-files-for-malware/
[VICE] USAF Official Says He ‘Misspoke’ About AI Drone Killing Human Operator in Simulated Test https://www.vice.com/en/article/4a33gj/ai-controlled-drone-goes-rogue-kills-human-operator-in-usaf-simulated-test
[Schneier Blog] On the Catastrophic Risk of AI https://www.schneier.com/blog/archives/2023/06/on-the-catastrophic-risk-of-ai.html
[brave.com] Request “Off the Record” https://brave.com/privacy-updates/26-request-off-the-record/
Tip of the Week: Blocking .zip Domains: https://firewallsdontstopdragons.com/how-to-block-the-new-zip-domain/
Further Info
How to send files securely: https://firewallsdontstopdragons.com/how-to-send-files-securely-like-tax-info/
Checklist of Tips for my book: https://firewallsdontstopdragons.com/wp-content/uploads/2023/02/FDSDv5-workbook-v1.pdf
10 Years After Snowden: https://www.eff.org/deeplinks/2023/05/10-years-after-snowden-some-things-are-better-some-were-still-fighting
The Wayback Machine: https://web.archive.org/
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:27: DEF CON update
0:02:40: News preview
0:04:59: If you use iTunes on Windows, update your app soon
0:06:25: Android malware was downloaded over 420M times
0:10:29: Android phones vulnerable to fingerpint brute force attacks
0:16:59: Luxottica breach exposes 300 million records
0:20:00: Free VPN service SuperVPN exposes 360 million user records
0:24:21: Amazon gets slap on the wrist over Ring privacy violations
0:26:10: KeePass “master password crack”
0:29:59: Twitter to put Community Notes on images
0:32:48: Microsoft is scanning contents of password-protection zip files
0:37:47: AI drone did NOT kill its human operator
0:43:19: About that AI article leading to human extinction
0:50:54: Brave browser’s new Off The Record feature
0:56:14: Dear Carey: cheatsheet for computer cleanup?
0:58:01: Tip of the Week: Blocking .zip domains
1:03:36: Wrap up and look ahead

May 29, 2023 • 1h 15min
Vehicle Privacy Report
Modern cars are more like smartphones on wheels. Like our cell phones, they are chock full of sensors, computer chips and software, and they’re connected to the internet 24/7 via cellular modems. What data is being collected? Who owns this data? How secure is your data? Who is it being shared with? And most importantly, what – if anything – can you do about it? Since we last spoke with Privacy4Car’s Andrea Amico, his company has released a powerful new Vehicle Privacy Report tool that aims to answer at least some of these questions and help you to be a more informed car buyer. Today we’ll delve into the murky world of car data collection and privacy.
Andrea Amico is one of the nation’s leading authorities on vehicle privacy and cybersecurity. He is also the founder of Privacy4Cars, the first and only privacy-tech company focused on identifying the challenges posed by vehicle data.
Interview Notes
Privacy4Cars: https://privacy4cars.com/
Vehicle Privacy Report tool: https://vehicleprivacyreport.com/
Assert your data rights: https://privacy4cars.com/personal-use/assert-your-data-rights/
Previous interview: Driving Data Privacy for Cars https://podcast.firewallsdontstopdragons.com/2021/09/13/driving-data-privacy-for-cars/
New privacy rules will impact your shop: https://www.autoserviceworld.com/new-privacy-rules-will-impact-your-shop/
Who Is Collecting Data From Your Car? https://themarkup.org/the-breakdown/2022/07/27/who-is-collecting-data-from-your-car
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:04:38: What has happened with Privacy4Cars since we last spoke?
0:06:17: Why are cars collecting so much data? How private is this data?
0:09:31: You say cars are “cell phones on wheels” – what does that mean?
0:10:24: Are cars connected even when turned off?
0:11:55: What types of data is my car collecting?
0:14:16: Do electric cars gather more data than regular cars?
0:16:54: Do cameras built into your car represent a privacy risk?
0:21:51: Who can access my car’s data? Can I access it myself?
0:27:25: Who owns the data in rental or fleet cars? What about wrecked cars?
0:32:24: Cars now have smartphone apps – what data are they collecting?
0:37:18: How do I know if I’ve opted in to data collection?
0:40:42: Can I opt of of data collection? If so, how?
0:44:20: What about Apple’s CarPlay or Google’s Android Auto?
0:49:37: How do I know which cars best respect my privacy?
0:55:08: How does the Vehicle Privacy Report tool work?
0:57:14: What does this tool tell me about a car?
1:00:43: What’s the value of this tool for car makers and dealerships?
1:06:09: What’s next for your company and the reporting tool?
1:09:49: Interview follow-up notes

May 22, 2023 • 1h 2min
Problems with Passkeys
Everyone hates dealing with passwords. This has led to a mad search for ‘password-killer’ technology. After several failed attempts, there’s finally a worthy contender: passkeys. The technology has been around for years – it’s the basis for hardware keys like YubiKey. But no one wanted to have to carry the little things all the time. With passkeys, you get the same phishing-proof, passwordless goodness but tied to a device you always have: your smartphone. Websites are slowly rolling out the ability to secure your accounts with passkeys, and Apple, Google and Microsoft are building support for passkeys into their operating systems. But I would caution you to wait a bit before jumping on the bandwagon – I’ll explain why in today’s show.
In other news: update all your Apple devices; FBI and NSA break the notorious Snake malware; Intel deploys microcode security update; location data on 2M Toyoya customers exposed for years; new .zip and .mov domains are dangerously ambiguous; new crafty Chinese router malware; online age verification will cause serious problems; Apple will allow you to ‘bank’ your voice soon.
Article Links
[Tom’s Guide] Apple issues urgent fix to block zero-day attacks — update your iPhone and Mac now https://www.tomsguide.com/news/apple-issues-urgent-fix-to-block-zero-day-attacks-update-your-iphone-and-mac-now
[tech.co] FBI & NSA Cut the Head Off Notorious Russian Snake Malware https://tech.co/news/nsa-fbi-russian-snake-malware
[Tom’s Hardware] Intel Deploys Undisclosed Microcode Security Update For CPUs Going Back To Coffee Lake https://www.tomshardware.com/news/intel-microcode-security-update
[BleepingComputer] Toyota: Car location data of 2 million customers exposed for ten years https://www.bleepingcomputer.com/news/security/toyota-car-location-data-of-2-million-customers-exposed-for-ten-years/
[Digital Trends] Hackers are using a devious new trick to infect your devices https://www.digitaltrends.com/computing/hackers-are-abusing-zip-mov-domain-names/
[9to5mac.com] Researchers find security flaw in Wemo Smart Plug, Belkin says it won’t release a patch https://9to5mac.com/2023/05/16/wemo-smart-plug-security-flaw-no-patch-coming/
[Ars Technica] Malware turns home routers into proxies for Chinese state-sponsored hackers https://arstechnica.com/information-technology/2023/05/malware-turns-home-routers-into-proxies-for-chinese-state-sponsored-hackers/
[Electronic Frontier Foundation] Age Verification Mandates Would Undermine Anonymity Online https://www.eff.org/deeplinks/2023/03/age-verification-mandates-would-undermine-anonymity-online
[9to5mac.com] Everyone should use Personal Voice; it does in 15 minutes what currently takes several weeks https://9to5mac.com/2023/05/19/everyone-should-use-personal-voice/
Tip of the Week: The Pros & Cons of Passkeys https://firewallsdontstopdragons.com/the-pros-and-cons-of-passkeys/
Further Info
Meross MSS115 Matter-enabled smart plug: https://shop.meross.com/products/meross-matter-smart-wi-fi-plug-mini-mss115
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:10: Update on new location tracker spec
0:02:52: News preview
0:05:30: FBI & NSA Cut the Head Off Notorious Russian Snake Malware
0:07:27: Intel Deploys Undisclosed Microcode Security Update
0:11:12: Toyota location data of 2M customers exposed for years
0:15:34: Phishers looking to capitalize on ambiguous new TLDs
0:19:32: Security flaws in Wemo Smart Plug won’t be fixed
0:25:08: Malware turns home routers into proxies for Chinese hackers
0:30:53: Age Verification Mandates Would Undermine Anonymity Online
0:39:23: Apple to offer new “voice-banking” technology
0:43:42: Dear Carey/Tip of the Week
0:59:19: Upcoming shows, coin promotion

May 15, 2023 • 1h 6min
Probing the Ministry of Truth
In the book “1984” (published in 1949), George Orwell envisioned a Big Brother that would control the media and dictate what was “truth”. But Orwell didn’t predict that “telescreens” would fit in our pockets or that we would willingly carry them with us 24/7, even to the bathroom. He also didn’t foresee that we would willingly subscribe to sources of mis- and disinformation in the form of social media. Today I speak with the co-author of the book “Ministry of Truth”, Vincent Hendricks, about the current state of social media and its influence on democracy and society.
Vincent F. Hendricks, author of THE MINISTRY OF TRUTH: BigTech’s Influence On Facts, Feelings And Fictions, is Professor of Formal Philosophy at the University of Copenhagen. He is the Director of the Center for Information and Bubble Studies (CIBS) funded by the Carlsberg Foundation.
Interview Notes
“Ministry of Truth” book: https://www.vince-inc.com/vincent/?p=7625
“1984” by George Orwell: https://en.wikipedia.org/wiki/Nineteen_Eighty-Four
“Reality Lost” (free PDF book): https://link.springer.com/book/10.1007/978-3-030-00813-0
Vincent Hendricks website: https://www.vince-inc.com/vincent/
More from Vincent: https://www.oecd-forum.org/users/vincent-f-hendricks
Blocking Google popups (and other annoyances): https://firewallsdontstopdragons.com/how-to-block-google-popups/
Further Info
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/
Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:02:23: Pre-inteview notes
0:03:51: Why did you write this book?
0:06:06: What is the current state of social media content moderation?
0:10:41: How equally are moderation rules applied to all users?
0:12:44: Do algorithms just feed our desire for stuff that’s not good for us?
0:16:39: Are things really worse today or just different?
0:21:21: Do private companies have a moral duty to support a “public square”?
0:26:23: Are social media companies warping the public discourse?
0:28:58: Is TikTok really more of a threat than Facebook or Twitter?
0:31:15: Are any of the proposed TikTok solutions viable?
0:35:41: Why can’t the US Congress pass a real privacy law?
0:38:00: Can we fix some key social media ills by adding some friction?
0:41:10: How will AI systems like ChatGPT impact disinformation?
0:44:15: Can AI also have positive impacts on social media?
0:48:10: How are social media platforms like casinos?
0:50:28: How are social media platforms like Orwell’s Ministry of Truth?
0:51:34: How much responsibility do we have here?
0:57:42: What tips do you have for using social media today?
1:02:59: Interview wrap-up
1:03:28: Privacy and security book club
1:04:37: Patron perks
1:05:02: Preview of upcoming shows

May 8, 2023 • 1h 9min
Blocking Google Popups
Have you noticed Google getting really pushy lately with offers to “sign in with Google”? You’re not alone. Many websites offer the ability to create a free account so that you can “personalize your experience”, but lately Google has been popping up an very annoying window to prompt you to create this account by signing in with your Google account. First of all, you almost never need to create an account to view the site. But second, even if you do want to create an account, you shouldn’t be linking that account with Google. You’re creating a data sharing arrangement that is completely unnecessary and not in your best interests. I’ll explain how to block these irritating popups (and many like them) for good.
In other news: 1Password was not hacked, but recent messages might have worried you; new macOS malware stealer app; five things scammers hope you search for; Microsoft Edge is recording your web surfing data; Windows 10 will never receive another feature update; Microsoft is rewriting core Windows software in a memory-safe language; study claims 83% of passwords can be hacked in one second; Google adds support for passkeys; Apple issues first Rapid Security Response with confusing messages; NYPD hands out 500 free AirTags to combat auto thefts; Apple and Google partner on industry spec to thwart unwanted tracking devices; Google adds cloud backup for 2FA without end-to-end encryption; Amazon Clinic requires you to sign away privacy rights; Washington State pass health data privacy law; my take on recent efforts to undermine encryption and restrict access to social media.
Article Links
[Digital Trends] No, 1Password wasn’t hacked – here’s what really happened https://www.digitaltrends.com/computing/1password-secret-keys-not-hacked/
[9to5mac.com] PSA: ‘Atomic macOS Stealer’ malware can compromise iCloud Keychain passwords, credit cards, crypto wallets https://9to5mac.com/2023/04/28/atomic-macos-stealer-malware-steal-passwords/
[Lifehacker] Five Things Scammers Are Hoping You Google https://lifehacker.com/five-things-scammers-are-hoping-you-google-1850405964
[The Verge] Microsoft Edge is leaking the sites you visit to Bing https://www.theverge.com/2023/4/25/23697532/microsoft-edge-browser-url-leak-bing-privacy
[Lifehacker] Microsoft Will Never Update Windows 10 Again (But You Can Keep Using It) https://lifehacker.com/microsoft-will-never-update-windows-10-again-but-you-c-1850386188
[theregister.com] Microsoft is busy rewriting core Windows code in memory-safe Rust https://www.theregister.com/2023/04/27/microsoft_windows_rust/
[9to5mac.com] Study reveals top 20 most used passwords; 83% can be cracked in a second https://9to5mac.com/2023/05/02/most-used-passwords-report/
[The Hacker News] Google Introduces Passwordless Secure Sign-In with Passkeys for Google Accounts https://thehackernews.com/2023/05/google-introduces-passwordless-secure.html
[AppleInsider] Apple issues Rapid Security Response update for iOS 16.4.1, macOS 13.3.1 https://appleinsider.com/articles/23/05/01/apple-issues-rapid-security-response-update-for-ios-1641-macos-1331
[AppleInsider] New York hands out 500 AirTags in car theft crackdown https://appleinsider.com/articles/23/05/01/new-york-hands-out-500-airtags-in-car-theft-crackdown
[Apple] Apple, Google partner on an industry specification to address unwanted tracking https://www.apple.com/newsroom/2023/05/apple-google-partner-on-an-industry-specification-to-address-unwanted-tracking/
[Gizmodo] Google’s New Two-Factor Authentication Isn’t End-to-End Encrypted, Tests Show https://gizmodo.com/google-authenticator-two-factor-not-end-encrypted-1850377102
[The Washington Post] To become an Amazon Clinic patient, first you sign away some privacy https://www.washingtonpost.com/technology/2023/05/01/amazon-clinic-hipaa-privacy/
[The Verge] Washington passes law requiring consent before companies collect health data https://www.theverge.com/2023/4/28/23702246/washington-health-data-law-consent-collect-sell
[Yahoo] India has blocked 14 mobile messenger apps on security fears https://www.yahoo.com/lifestyle/india-blocked-14-mobile-messenger-074000711.html
[CNN] Arkansas governor signs sweeping bill imposing a minimum age limit for social media usage https://www.cnn.com/2023/04/12/tech/arkansas-social-media-age-limit/index.html
[act.eff.org] The “Earn It” Act is Back, Seeking To Scan Us All https://act.eff.org/action/the-earn-it-act-is-back-seeking-to-scan-us-all
Tip of the Week: Block Google Sign-In Popups: https://firewallsdontstopdragons.com/how-to-block-google-popups/
Further Info
TP-Link software update: https://www.tp-link.com/us/support/download/archer-ax21/v3/#Firmware
Install uBlock Origin: https://ublockorigin.com/
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:25: Follow-up on previous stories
0:02:01: Security updates
0:02:37: News preview
0:05:02: 1Password was NOT hacked
0:06:57: New Atomic macOS Stealer malware discovered
0:09:56: Five things scammers are hoping you’re googling for
0:13:53: Microsoft Edge is leaking the sites you visit to Bing
0:16:27: Microsoft to stop updating Windows 10 features
0:19:21: Microsoft is rewriting core Windows code to be memory-safe
0:22:07: 83% of passwords cracked in one second! (not really)
0:25:17: Google introduces passkey support
0:30:56: Apple’s first Rapid Security Response was confusing
0:36:05: NYPD hands out free AirTags to crack down on car theft
0:37:58: Google, Apple propose standard to address unwanted tracking
0:40:31: Google’s new 2FA sync is not end-to-end encrypted
0:44:51: Amazon Clinic requires you to give away your privacy
0:48:51: Washington State passed heath data protection law
0:51:17: My take on recent efforts to restrict social media, strong encryption
0:57:00: Tip of the Week: Blocking Popups
1:07:13: Wrap up

May 1, 2023 • 56min
STOPping Mass Surveillance
There’s a big difference between mass surveillance and targeted surveillance based on a court-approved, limited-scope search warrant. But advances in technology have made warrant-less, dragnet surveillance exceptionally easy and stunningly effective. Local law enforcement agencies have deployed several types of surveillance systems in our communities, but have strongly resisted calls for transparency and oversight. Furthermore, police have simply bypassed the need for a warrant and pesky Fourth Amendment rights by just buying surveillance data from private companies. My guests today – Albert Fox Cahn and Evan Enzer, from the Surveillance Technology Oversight Project (S.T.O.P.) – will explain what’s going on, why it’s a danger to our privacy rights and democratic principles, and what we can do to fix it.
Interview Notes
Surveillance Technology Oversight Project: https://www.stopspying.org/
STOP on Twitter & TikTok: @STOPSpyingNY
Donate to S.T.O.P. https://www.stopspying.org/donate
STOP Trojan House report: https://www.stopspying.org/the-trojan-house
Public Oversight of Surveillance Technology (POST) Act: https://www.nyc.gov/site/nypd/about/about-nypd/policy/post-act.page
Community Control of Police Surveillance (CCOPS): https://www.eff.org/issues/community-control-police-surveillance-ccops
Electronic Frontier Alliance: https://www.eff.org/fight
EFF’s Atlas of Surveillance: https://atlasofsurveillance.org/
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:33: Interview setup
0:03:26: What is the Surveillance Technology Oversight Project?
0:07:57: What are the most common mass surveillance technologies?
0:10:15: How does Shot Spotter work and what are the dangers?
0:13:02: Do these technologies actually reduce crime?
0:14:38: Is law enforcement required to disclose info on these systems?
0:17:35: How transparent is the funding around these projects?
0:19:21: Who has access to this surveillance data?
0:21:20: 9/11 revealed a lack of data sharing – what’s the right balance?
0:22:42: Is privately obtained surveillance data subject to 4th Amendment rights?
0:23:53: What is the “third party doctrine” and how does it apply here?
0:26:15: How does purchased data differ from data obtained via warrant?
0:27:56: How does the practice of “parallel construction” work?
0:29:22: What is my legal right to privacy when in public spaces?
0:31:09: What are my legal rights to “surveil” law enforcement?
0:32:44: How are police using copyright law to curtail video taping?
0:34:13: Who watches the watchers? Is there any oversight of mass surveillance?
0:36:52: How do you uncover surveillance use and abuse?
0:38:45: How can we mitigate consumer surveillance tech?
0:41:53: Are there any tools or techniques to mitigate public surveillance?
0:46:22: What’s the solution here? How do we rein in mass surveillance?
0:50:06: How can people get involved in the fight against mass surveillance?
0:51:51: Interview wrap-up
0:54:51: Looking ahead


