
Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Latest episodes

Jan 9, 2023 • 58min
Privacy Tide is Turning
Facebook stock is down 65%, they just paid $725M to settle the Cambridge Analytica lawsuit, and they've just been fined over $400M by the EU. But that's not the worst part (for Meta). The EU and its General Data Protection Regulation (GDPR) is basically saying that its entire business model - surveillance capitalism - is wrong and must stop. That's the same business model used by Google, too. It really seems that the tide is finally turning in favor of user privacy as more nails are hammered into the coffin of behavior-based advertising.
In other news: the first LastPass class actions lawsuit has been filed over the recently announced data breach; WhatsApp adds a feature to bypass internet censorship by repressive regimes; Pornhub is now requiring viewers from Louisiana to verifying the age via ID; data from up to 400M Twitter accounts is up for sale; a military device containing information including biometric scans of over 2000 people was bought on eBay for $68; Mom and daughter kicked out of Rockettes show in Radio City Music Hall. Plus, a Dear Carey question and my Tip of the Week.
Article Links
[TechRadar] LastPass is being sued following major cyberattack https://www.techradar.com/news/lastpass-is-being-sued-following-cyberattack
[The Washington Post] WhatsApp adds feature to bypass internet censors in repressive regimes https://www.washingtonpost.com/technology/2023/01/06/whatsapp-proxy-server-address/
[The Verge] Meta agrees to pay $725 million to settle Cambridge Analytica class action lawsuit https://www.theverge.com/2022/12/23/23523862/meta-cambridge-analytica-class-action-lawsuit-settlement-725-million
[The Hacker News] Irish Regulators Fine Facebook $414 Million for Forcing Users to Accept Targeted Ads https://thehackernews.com/2023/01/irish-regulators-fine-facebook-414.html
[Ars Technica] Pornhub requires ID from Louisiana users to comply with state’s new porn law https://arstechnica.com/tech-policy/2023/01/no-porn-without-id-louisiana-law-forces-porn-sites-to-verify-users-ages/
[Naked Security] Twitter data of “+400 million unique users” up for sale – what to do? https://nakedsecurity.sophos.com/2022/12/28/twitter-data-of-400-million-unique-users-up-for-sale-what-to-do/
[The New York Times] For Sale on eBay: A Military Database of Fingerprints and Iris Scans https://www.nytimes.com/2022/12/27/technology/for-sale-on-ebay-a-military-database-of-fingerprints-and-iris-scans.html
[Ars Technica] MSG defends using facial recognition to kick lawyer out of Rockettes show https://arstechnica.com/tech-policy/2022/12/facial-recognition-flags-girl-scout-mom-as-security-risk-at-rockettes-show/
[Lifehacker] You Can Disable Google Sign-in Pop-ups on All Websites https://lifehacker.com/you-can-disable-google-sign-in-pop-ups-on-all-websites-1849913714
Further Info
ANNUAL LISTENER SURVEY!! https://fdsd.me/survey2023
LastPass breach info: https://firewallsdontstopdragons.com/special-lastpass-breach/
Peppering Your Passwords: https://firewallsdontstopdragons.com/password-manager-paranoia/
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:09: Show preview
0:03:01: LastPass updates and first law suit
0:12:22: WhatsApp adds feature allowing censorship bypass
0:15:19: Facebook settles Cambridge Analytica suit for $725M
0:16:50: Irish Regulators Fine Facebook $414 Million
0:21:34: Pornhub requires ID from Louisiana users
0:27:11: 400M+ Twitter users data for sale
0:35:22: Military device with biometric data found on eBay

Jan 2, 2023 • 1h 24min
SPECIAL: LastPass Breach
Right before Christmas, LastPass dropped a bombshell report explaining that bad actors appeared to have made copies of LastPass users' encrypted password vaults. The information was a little short on key details, probably indicating that the investigation is ongoing and we will learn more in the coming weeks. However, we have already learned enough to know that the data breach did leak some important metadata contained in people's password vaults and that any users who had less-than-secure master passwords should be worried that the encrypted contents may now be vulnerable to disclosure. That is about as bad as it gets. Today I will speak with a cybersecurity and authentication expert from CISA about this breach: what we know, what we don't know, what we should learn from the incident, and (most importantly) what LastPass users should do about this.
Bob Lord is a Senior Technical Advisor for the Cybersecurity and Infrastructure Security Agency (CISA) and former Chief Information Security Officer (CISO) for Yahoo.
Interview Notes
SPECIAL REPORT: LastPass Breach: https://firewallsdontstopdragons.com/special-lastpass-breach/
Twitter thread investigating what’s encrypted and what’s not: https://twitter.com/UK_Daniel_Card/status/1606012536582656000
Write-up by a security researcher: https://www.pwndefend.com/2022/12/24/lastpass-breach-the-danger-of-metadata/
Mastodon technical thread #1: https://mastodon.social/@epixoip@infosec.exchange/109585049690097599
Mastodon technical thread #2: https://infosec.exchange/@WPalant/109590750504031700
My “diceware” passphrase generator: https://d20key.com/
My blog on creating strong passphrase: https://firewallsdontstopdragons.com/how-when-to-use-a-passphrase/
How to make stronger passwords: https://firewallsdontstopdragons.com/need-a-bigger-password-haystack/
Classic XKCD cartoons on passphrases: https://xkcd.com/936/
Consumer Reports Security Planner: https://securityplanner.consumerreports.org/
Further Info
Follow me on social media: https://firewallsdontstopdragons.com/contact/
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:47: Ep300 giveaway updates
0:03:15: interview setup
0:08:17: What do we know about the LastPass breaches?
0:13:25: Were all LastPass users affected?
0:15:03: How is my LastPass data secured, exactly?
0:19:53: What is PBKDF2 and why are iterations important?
0:23:10: Did LastPass increase the iterations for all users over time?
0:26:46: Is any information in my password vault not encrypted?
0:29:35: How do I know if my vault password is strong enough?
0:36:13: What if I didn't have a strong vault password? What should I do?
0:41:47: Do we have any evidence that people's vaults have been cracked?
0:45:34: Did LastPass handle this properly?
0:50:50: What can the government do to help here?
0:53:30: Should LastPass users switch to a different service?
0:57:11: Will passwordless authentication solve this problem?
1:01:03: What are the key take-aways here?
1:02:37: My take on the breach and what you should do about it

Dec 26, 2022 • 1h 5min
Building a Better Private Network
All our devices and apps use the internet these days. But what are they doing on the internet, exactly? Who are they talking to? You'd be surprised. But there are tools which will not only let you see what they're up to, but also let you have fine-grain control over what communications you want to allow. But just the mere fact that they're sending and receiving data to and from multiple sources can be revealing, too. While VPN's are good for adding a layer of security, they're really not great at adding privacy - despite having "private" in the name. Thankfully, there's a new service that can help there, too. We'll be discussing network privacy and how we can improve it with the CEO of Safing, Raphael Fiedler.
Raphael Fiedler is the CEO of Safing, a speaker on topics about privacy, and a regular co-host on an InfoSec podcast.
Interview Notes
Safing.io, Portmaster, Safing Privacy Network (SPN): https://safing.io/
Securitized podcast: https://www.securityzed.com/
The Hut Six Story: Breaking the Enigma Codes https://www.amazon.com/Hut-Six-Story-Breaking-Enigma/dp/0947712348
Naomi Brockwell, The Dark Side of VPNs: https://www.youtube.com/watch?v=8MHBMdTBlok
OSI Layer Model: https://en.wikipedia.org/wiki/OSI_model
Nym network: https://nymtech.net/
SPN white paper: https://safing.io/files/whitepaper/Gate17.pdf
Further Info
300th episode promotion: https://fdsd.me/ep300
Patron promotion: https://fdsd.me/coinpromo
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
0:00:35: Promotions update - last call!
0:02:11: Interview preview
0:04:41: How did Safing start? What problems are you trying to solve?
0:07:57: What are the most likely threats to our home network?
0:10:12: Are our devices and apps tattling on us?
0:14:14: What can an application firewall do for us?
0:17:04: Given broad use of HTTPS, do we need VPNs like we used to?
0:19:30: Can we collect useful analytics and still preserve privacy?
0:23:46: Which VPN marketing claims are bogus or misleading?
0:29:31: How does a decentralized VPN work?
0:33:10: What is the value of a decentalized VPN?
0:35:13: How is your SPN different from a VPN?
0:41:10: Who owns the SPN exit nodes?
0:43:27: Can your SPN mix traffic amongst backbone providers?
0:48:18: Can an SPN do anything to prevent fingerprinting?
0:51:14: Does a multi-connection SPN confuse some websites or apps?
0:54:28: How does the SPN compare to Tor or Apply Private Relay?
1:00:22: What's the roadmap look like for Portmaster and SPN?
1:03:30: Wrap-up

Dec 19, 2022 • 1h 12min
Best of 2022!
The year is almost over and as we head into the holiday season I wanted to reminisce with some of my favorite snippets from the last year! Unlike in previous 'best of' shows, I've actually included some new snippets from my private podcast, to give you a little taste of the bonus content that I create for my patrons! The links in the show notes will take you to the full episodes, including all the relevant 'further information' links associated with them.
Happy holidays, everyone!!
Article Links
Ep267: Luck Favors the Prepared https://podcast.firewallsdontstopdragons.com/2022/04/11/luck-favors-the-prepared/
Ep279: Necessary Chaos: https://podcast.firewallsdontstopdragons.com/2022/07/04/necessary-chaos/
Ep272: Tomatoes & Telegraphs: https://podcast.firewallsdontstopdragons.com/2022/05/23/tomatoes-telegraphs/
Ep275: Cryptocurrency 101: https://podcast.firewallsdontstopdragons.com/2022/06/06/cryptocurrency-101/
Ep283: No Place Left to Hide: https://podcast.firewallsdontstopdragons.com/2022/08/01/now-place-left-to-hide/
Ep287: The Night the Lights Went Out in Vegas: https://podcast.firewallsdontstopdragons.com/2022/08/29/the-night-the-lights-went-out-in-vegas/
Ep289: Decoding Computers & Software: https://podcast.firewallsdontstopdragons.com/2022/09/12/decoding-computers-software/
Ep292: Capture the Flag for Fun & Profit: https://podcast.firewallsdontstopdragons.com/2022/10/03/capture-the-flag-for-fun-profit/
Steganography: https://en.wikipedia.org/wiki/Steganography
Further Info
Give the gift of security and privacy! https://fdsd.me/coupons
300th episode promotion: https://fdsd.me/ep300
Patron promotion: https://fdsd.me/coinpromo
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:02:17: Ep267: How the internet works
0:10:23: Ep279: Getting into electronics and hacking
0:16:22: Ep273: The invention of the one-time pad
0:24:36: Ep275: Why do we need cryptocurrency?
0:30:26: Ep283 BONUS: What's it like arguing in front of the Supreme Court?
0:35:33: Ep283: This suspect looks just like Woody Harrelson!
0:40:26: Ep287: The time DEF CON almost ended
0:49:15: Ep289: The historical origins of software and storage
0:56:28: Ep292: Ender's Game-ing a hacker tournament
1:02:20: Ep288 Merlin's Musings: Steganography
1:10:39: Wrap-up

Dec 12, 2022 • 1h 9min
We Are the Cavalry
Today when computer systems fail, they can cause real, physical harm. In just the last few years, we've seen cyber attacks interfere with our food supply, tamper with city water supplies, and disrupt gas pipelines. While cheap consumer electronics often have poor security, medical devices like insulin pumps and pacemakers are also vulnerable to attack - and the consequences of failure can be lethal. The free market doesn't reward better security. Regulations are weak or nonexistent, regulators are understaffed and underfunded. Targeted organizations lack sufficient funding, training and personnel to prepare and respond. They need help. I Am the Cavalry aims to engage technologists and hackers to ride to the rescue.
Joshua Corman is VP of Cyber Safety Strategy at Claroty, Founder of I am The Cavalry, and formerly served as Chief Strategist for CISA regarding COVID, healthcare, and public safety.
Interview Links
I Am The Cavalry: https://iamthecavalry.org/
BSides 2022 Cavalry presentation: https://www.youtube.com/watch?v=aw3egJej7so
The Cavalry Isn’t Coming (DEF CON 21 talk): https://www.youtube.com/watch?v=2kMGdkOMSK0
Rugged Software Manifesto: https://github.com/rugged-software/rugged-software.github.io
CISA Bad Practices: https://www.cisa.gov/BadPractices
CISA Information Sharing and Awareness: https://www.cisa.gov/information-sharing-and-awareness
Maslow’s Hierarchy of Needs: https://www.simplypsychology.org/maslow.html
Click Here to Kill Everyone: https://www.schneier.com/books/click-here/
SBOM interview: https://podcast.firewallsdontstopdragons.com/2021/07/19/its-time-to-drop-the-sbom/
My Jeff Moss interview: https://podcast.firewallsdontstopdragons.com/2022/08/29/the-night-the-lights-went-out-in-vegas/
Further Info
300th episode promotion: https://fdsd.me/ep300
Patron promotion: https://fdsd.me/coinpromo
Send me your questions! https://fdsd.me/qna
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons
Donate directly with Monero! https://firewallsdontstopdragons.com/contact/
Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:28: Giveaway and promotion update
0:02:46: Holiday gift ideas
0:03:59: Interview preview
0:08:35: How did I Am the Cavalry get started?
0:16:52: How does focusing on physical harms change your approach to cybersecurity?
0:20:33: Why is it so important to 'meet people where they are'?
0:23:40: How do you best help organizations that are target rich but cyber poor?
0:31:47: What is the crawl, walk, run progression?
0:34:33: Why is it so important to compartmentalize systems?
0:35:56: How do we do a better job of designing security in from the start?
0:39:01: Is it safer for small companies to use managed services?
0:42:17: What role should the government play here?
0:52:57: If I want to get help for my organization, where should I go?
0:58:18: What's next for the Cavalry and how can I get involved?
1:05:09: Interview wrap-up
1:06:35: Book recommendations
1:07:43: Preview of upcoming shows

Dec 5, 2022 • 1h 9min
Tis the Season for Scams
Tis the season for giving... and unfortunately, also for taking. Scammers tend to be extremely active during the holiday season. We're buying lots of stuff online, having lots of packages delivered. We're away from our homes for extended periods of time. We're giving money to charities. We're firing up new tech toys. The bad guys know this and are happy to take advantage of our chaotic holiday schedule and unusual levels of spending and giving. I'll give you some top tips to avoid being a victim this holiday season.
In other news: the SFPD wants to arm its law enforcement robots; the TSA is expanding the use of facial recognition at airports; Microsoft warns of malware coming from Google Ads; a new study shows that computer repair shops may be accessing your personal data; WhatsApp data breach affects nearly 500M users; Twitter data breach was far worse than reported; Meta shuts down covert US propaganda operation; US watchdog raises warning for offshore oil and gas rig security; a new malware campaign bypasses Windows protections; LastPass admits to customer data breach caused by previous breach; and Anker's Eufy cameras caught sending data to cloud without user consent.
Article Links
[Electronic Frontier Foundation] Red Alert: The SFPD want the power to kill with robots https://www.eff.org/deeplinks/2022/11/red-alert-sfpd-want-power-kill-robots
[The Washington Post] TSA now wants to scan your face at security. Here are your rights. https://www.washingtonpost.com/technology/2022/12/02/tsa-security-face-recognition/
[BleepingComputer] Brave starts showing "privacy-preserving" ads in search results https://www.bleepingcomputer.com/news/technology/brave-starts-showing-privacy-preserving-ads-in-search-results/
[Tech.co] Microsoft Warns Hackers Use Google Ads to Deliver Ransomware https://tech.co/news/microsoft-warns-hackers-google-ads-ransomware
[Ars Technica] Thinking about taking your computer to the repair shop? Be very afraid https://arstechnica.com/information-technology/2022/11/half-of-computer-repairs-result-in-snooping-of-sensitive-data-study-finds/
[TechRadar] WhatsApp data breach sees nearly 500 million user records up for sale https://www.techradar.com/news/whatsapp-data-breach-sees-nearly-500-million-user-records-up-for-sale
[9to5mac.com] Massive Twitter data breach was far worse than reported, reveal security researchers https://9to5mac.com/2022/11/25/massive-twitter-data-breach/
[BleepingComputer] Meta links U.S. military with covert Facebook influence operation https://www.bleepingcomputer.com/news/security/meta-links-us-military-with-covert-facebook-influence-operation/
[TechCrunch] US offshore oil and gas rigs at ‘significant’ risk of cyberattacks, warns watchdog https://techcrunch.com/2022/11/22/offshore-oil-gas-cyberattacks-watchdog/
[TechRadar] This new malware is able to bypass all of Microsoft's security warnings https://www.techradar.com/news/this-new-malware-is-able-to-bypass-all-of-microsofts-security-warnings
[Naked Security] LastPass admits to customer data breach caused by previous breach https://nakedsecurity.sophos.com/2022/12/02/lastpass-admits-to-customer-data-breach-caused-by-previous-breach/
[MacRumors] Anker's Eufy Cameras Caught Uploading Content to the Cloud Without User Consent https://www.macrumors.com/2022/11/29/eufy-camera-cloud-uploads-no-user-consent/
Tip of the Week: Tis the Season for Scams: https://firewallsdontstopdragons.com/how-to-avoid-holiday-scams/
Further Info
Boston Dynamics robodog: https://www.youtube.com/watch?v=6Zbhvaac68Y
This Person Doesn’t Exist: https://thispersondoesnotexist.com/
300th episode promotion: https://fdsd.me/ep300
Patron promotion: https://fdsd.me/coinpromo
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book

Nov 28, 2022 • 1h 7min
300th Episode!!
I can't believe I've been doing this for 300 weeks - almost 6 years now! And returning for his 3rd "podcentennial" episode is world-renowned security guru Bruce Schneier! Today we'll discuss hacking - not just in the realm of computers, but in legal, political, social and economic spaces. And then we'll talk about how artificial intelligence and computer automation are starting to play a significant role in hacking all of these realms. Computers and AI expand the scope, scale and speed of hacking and we're honestly not prepared for it.
To celebrate the 300th episode and the coming release of the 5th edition of my book, today I'm kicking off a big giveaway with lots of prizes and a killer promotion for patrons on Patreon! (See below for links.)
Bruce Schneier is an internationally renowned technologist and security guru. He is the author of over one dozen books, including his latest, A Hacker’s Mind, due out in February, I believe. He has testified before Congress and has served on several government committees and corporate boards, written many seminal papers, has a very popular blog called Crypto-Gram, and last but not least, Bruce is the Chief of Security Architecture at Inrupt.
Further Info
300th episode promotion: https://firewallsdontstopdragons.com/enter-to-win-300th-podcast-giveaway/
Patron promotion: https://www.patreon.com/posts/december-patron-75151773
The Coming AI Hackers: https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html
A Hacker’s Mind book: https://www.schneier.com/books/a-hackers-mind/
Give the gift of security & privacy: https://firewallsdontstopdragons.com/give-the-gift-of-security-and-privacy/
Check out my Best & Worst Gifts Guide for 2022: https://firewallsdontstopdragons.com/best-worst-gifts-2022/
The Coming AI Hackers: https://www.schneier.com/academic/archives/2021/04/the-coming-ai-hackers.html
A Hacker’s Mind book: https://www.schneier.com/books/a-hackers-mind/
The Trolley Problem: https://en.wikipedia.org/wiki/Trolley_problem
Gödel's incompleteness theorems: https://en.wikipedia.org/wiki/G%C3%B6del's_incompleteness_theorems
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/
Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons
Donate directly with Monero! https://firewallsdontstopdragons.com/contact/
Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:31: Interview preview
0:02:29: Interview start
0:03:13: How does hacking differ from inventing or just cheating?
0:07:14: What is artificial intelligence and when will it be like teh sci-fi version?
0:11:32: Do we have to worry about AI replacing us or taking over?
0:13:57: Can we program human values into AI systems?
0:18:09: Why are reward and goal alignment so crucial for AI?
0:20:28: Will we ever implicitly trust AI if we can't explain its answers?
0:25:37: Do we put too much trust in some AI systems?
0:27:59: How might AI systems be used to hack financial or political systems?
0:33:26: Can we govern AI systems with human laws?
0:36:40: Are non-computer systems more susceptible to hacks due to uncodified norms?
0:42:41: Can AI think outside the box if it doesn't understand the box?
0:48:05: How does terrorism hack our brains and how do we prevent that?
0:53:35: What are some Utopian possibilities for AI?
0:55:08: How do we get more public interest technologists?
0:56:28: Interview wrap-up
0:58:19: 300th podcast giveaway!
1:01:49: Patron promotion!

Nov 21, 2022 • 1h 16min
Best & Worst Gifts for 2022
Black Friday is just around the corner, which marks the unofficial launch of the holiday shopping season. As you're considering what gifts to give to your loved ones this year, I want to make sure you're thinking about the privacy and security aspects. To that end, I have updated my annual Best and Worst Gift Guide and I will go over the highlights in this episode for my Tip of the Week. But I also have a special new gift idea this year: security and privacy coupons that you can download and give to your loved ones!
In the news: USPS tells customers to avoid using the big blue mailboxes for gifts and important letters during the holiday season; Google pays nearly $400M fine to 40 states who sued over location tracking; Medibank refuses to pay ransom for data and criminals are starting to leak sensitive medical records online; TransUnion reports a data breach; FBI director warns that TikTok is a national security risk; Lenovo laptops are exposed to UEFI malware risks (update now); a mysterious company with government ties and a history of spying has become a root certificate authority; the British government is scanning its citizens devices looking for vulnerabilities in hopes of fixing them; almost 50% of all Mac malware can be traced to a single, security application; Apple apps are sending tons of analytics data to Apple even when analytics are disabled; I answer a listener question (Dear Carey) about the best Mastodon clients, in the wake of the Twitter collapse.
Article Links
[Lifehacker] Avoid Using Blue Mailboxes During the Holidays, USPS Warns https://lifehacker.com/avoid-using-blue-mailboxes-during-the-holidays-usps-wa-1849773201
[The Hacker News] Google to Pay $391 Million Privacy Fine for Secretly Tracking Users' Location https://thehackernews.com/2022/11/google-to-pays-391-million-privacy-fine.html
[CPO Magazine] Medibank Refuses Ransom Payments, Hackers Leak Stolen Health Data to Dark Web https://www.cpomagazine.com/cyber-security/medibank-refuses-ransom-payments-hackers-leak-stolen-health-data-to-dark-web/
[BGR] TransUnion data breach compromises financial information of consumers https://bgr.com/tech/transunion-data-breach-compromises-financial-information-of-consumers/
[USA TODAY] FBI director says TikTok poses national security threat, and he's 'extremely concerned' https://www.usatoday.com/story/tech/2022/11/16/tiktok-poses-national-security-threat-fbi/10709987002/
[Ars Technica] Lenovo driver goof poses security risk for users of 25 notebook models https://arstechnica.com/information-technology/2022/11/lenovo-patches-secure-boot-vulnerabilities-that-imperil-25-notebook-models/
[The Washington Post] Mysterious company with government ties plays key internet role https://www.washingtonpost.com/technology/2022/11/08/trustcor-internet-addresses-government-connections/
[Bleeping Computer] British govt is scanning all Internet devices hosted in UK https://www-bleepingcomputer-com.cdn.ampproject.org/c/s/www.bleepingcomputer.com/news/security/british-govt-is-scanning-all-internet-devices-hosted-in-uk/amp/
[Tom's Guide] Almost 50% of macOS malware reportedly comes from single app — delete it now https://www.tomsguide.com/news/new-report-says-nearly-half-of-macos-malware-comes-from-single-app-delete-it-now
[Gizmodo] Apple Is Tracking You Even When Its Own Privacy Settings Say It’s Not, New Research Says https://gizmodo.com/apple-iphone-analytics-tracking-even-when-off-app-store-1849757558
Dear Carey: Mastodon clients.
https://joinmastodon.org/apps
https://bilge.world/mastodon-ios-apps
Further Info
Best & Worst Gifts for 2022: https://firewallsdontstopdragons.com/best--worst-gifts-2022/
Privacy & Security Coupons: https://fdsd.me/coupons
Give thanks and donate! https://firewallsdontstopdragons.com/give-thanks-donate/
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://firewallsdo...

Nov 14, 2022 • 1h 1min
Surveying the Digital Explosion
Connected computers have changed the world perhaps more than any other single invention. The impacts of nearly instant global communication and effectively infinite, perfect storage of information are at once undeniable and difficult to fully comprehend. And yet, technologists, bureaucrats and corporate leaders make decisions on a daily basis that should be considering the repercussions. Just because you can do something doesn't mean you should. Today, we'll discuss the digitization of the world and some of the more important impacts it has had and is having on society with the authors of the book Blown to Bits: Your Life, Liberty, and Happiness After the Digital Explosion.
Harry Lewis, former Dean of Harvard College, is Gordon McKay Professor of Computer Science at Harvard. Ken Ledeen is the Chairman and Chief Executive Officer at Nevo Technologies, Inc., a software development and information technology consulting firm located in Cambridge, Massachusetts. Wendy Seltzer is Strategy Lead and Counsel to the World Wide Web Consortium (W3C) at MIT, improving the Web’s security, availability, and interoperability through standards.
Further Info
Buy or download Blown to Bits: https://www.bitsbook.com/thebook/
Weird Marketing Tales interviewed me: https://weirdmarketingtales.com/why-firewalls-dont-stop-dragons-carey-parker-privacy-security/
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/
Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887
Become a Patron! https://www.patreon.com/FirewallsDontStopDragons
Donate directly with Monero! https://firewallsdontstopdragons.com/contact/
Would you like me to speak to your group about security and/privacy? http://bit.ly/Firewalls-Speaker
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:03:16: interview start
0:04:03: What brought you all together to write this book?
0:05:28: What are the biggest changes since the first edition?
0:10:04: What were the impacts of the Edward Snowden revelations?
0:12:44: How do we resolve the tension between privacy and law enforcement?
0:16:43: Are computer systems free from bias?
0:19:22: How do algorithms impact judicial decisions?
0:20:45: Why is it hard to explain how AI systems make decisions?
0:28:33: What is net neutrality and who are the gatekeepers today on the internet?
0:31:59: Have we lost the original Utopian ideal of the internet?
0:35:41: How have content moderation and personalization affected our experience?
0:40:48: How do these companies hyper-personalize the web?
0:45:44: Are we changing our own behaviors to game the algorithms?
0:47:35: Are bits more fragile than parchment and cave paintings?
0:53:29: What gives you hope? What keeps you up at night?
0:58:12: Interview wrap-up
0:59:34: Upcoming shows, promotions, interviews

Nov 7, 2022 • 59min
Redirect Ransom
QR codes are not inherently dangerous. They're effectively links we can click in the real world using the camera app on our phone. Like hyperlinks on a web page, QR code "links" can take you to good websites or bad websites. They can also disguise their ultimate destination by using URL shortening services like bitly or owly. But now "free" QR code generator websites - that is, sites that will let you create one of these QR codes by entering the HTTP link you want it to take people to - are using these redirects to basically hold your QR code for ransom. The QR codes they give you use the redirect links to insert themselves into the middle - and after some time, they will stop working until you subscribe and pay them money. If you've already printed these codes on hundreds of business cards or dozens of plaques for your restaurant, they they've really got you over a barrel. I'll help you avoid these scams.
In other news: Microsort warns that attackers are quickly leveraging newly reported zero-days; some Chrome extensions are making money by inserting affiliate links for thousands of websites; Microsoft appears to be readying a useful PC cleanup tool for release; Apple clarifies its policy on security updates for older OS releases; a report details how hidden AI algorithms are affecting the lives of DC residents; facial recognition systems are being installed in many soccer stadiums; Uber is planning to bombard their users with ads; Clearview AI has been fined 30M euros by France; Apple is ramping up its own ads on its various apps and devices; and I answer another Dear Carey question, this one on the case that is bringing Section 230 in front of the Supreme Court.
Article Links
[Hacker News] Microsoft Warns of Uptick in Hackers Leveraging Publicly-Disclosed 0-Day Vulnerabilities https://thehackernews.com/2022/11/microsoft-warns-of-uptick-in-hackers.html
[BleepingComputer] Chrome extensions with 1 million installs hijack targets’ browsers https://www.bleepingcomputer.com/news/security/chrome-extensions-with-1-million-installs-hijack-targets-browsers/
[PCWorld] Microsoft’s surprise PC Manager system optimizer takes aim at CCleaner https://www.pcworld.com/a rticle/1360140/microsoft-releases-beta-of-a-ccleaner-style-pc-manager-tool.html
[Ars Technica] Apple clarifies security update policy: Only the latest OSes are fully patched https://arstechnica.com/gadgets/2022/10/apple-clarifies-security-update-policy-only-the-latest-oses-are-fully-patched/
[WIRED] Algorithms Quietly Run the City of DC—and Maybe Your Hometown https://www.wired.com/story/algorithms-quietly-run-the-city-of-dc-and-maybe-your-hometown/
[WIRED] Soccer Fans, You’re Being Watched https://www.wired.com/story/soccer-world-cup-biometric-surveillance/
[Gizmodo] Uber Plans to Advertise to You At Every Stage of Your Ride, Using Your Own Data https://gizmodo.com/uber-ads-ride-share-uber-eats-1849678092
[Naked Security] Clearview AI image-scraping face recognition service hit with €20m fine in France https://nakedsecurity.sophos.com/2022/10/26/clearview-ai-image-scraping-face-recognition-service-hit-with-e20m-fine-in-france/
[Lifehacker] How to Block Apple’s Own Ads on Your iPhone https://lifehacker.com/how-to-block-apple-s-own-ads-on-your-iphone-1849703889
Tip of the Week: https://firewallsdontstopdragons.com/qr-code-scams-revisited/
Further Info
Send me your questions! https://fdsd.me/qna
Support me! https://fdsd.me/support
Subscribe to the newsletter: https://firewallsdontstopdragons.com/newsletter/new-newsletter/
Check out my book, Firewalls Don’t Stop Dragons: https://www.amazon.com/gp/product/1484261887
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:42: Countdown to 300