
Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Latest episodes

Feb 8, 2021 • 1h 4min
Free Speech & Deplatforming
Episode 206. The social media events around the January 6th storming of the US Capitol have sparked raging, divisive debates in the US. But the banning of individuals and the deplatforming of apps and groups are not new phenomenons. The Right of Free Speech that is enshrined in the First Amendment to the US Constitution is not limitless. It does have legal boundaries. And private companies, even monopolies, have the legal right to control access to their platforms. But does that make it right? Today, I will wade into this decidedly thorny issue with Troy Hunt, who brings a plethora of global technology and security experience to the debate.
Troy Hunt is an Australian Microsoft Regional Director and a Most Valuable Professional awardee for Developer Security. He’s a blogger, international speaker and author of several online courses, and he runs the very valuable internet security service HaveIBeenPwned.
Further Info
Troy Hunt’s blog on deplatforming: https://www.troyhunt.com/weekly-update-226/ EFF's take: https://www.eff.org/deeplinks/2019/05/censorship-cant-be-only-answer-disinformation-online Legal limits of free speech: https://en.wikipedia.org/wiki/United_States_free_speech_exceptions Listener survey: https://bit.ly/Firewalls-survey-2021 Patron survey: http://bit.ly/Firewalls-patron-survey-2021

Feb 1, 2021 • 60min
Stop Watching Me!
Tracking and data mining has gotten way out of hand. We're not only being tracked online, we're now being tracked around the real world, too. We're truly living in a panopticon - and it's not good for us as individuals or as a democratic society. Today I'll cover several stories that make it clear that we've hit a tipping point. It has to stop. And it's going to require all of us putting pressure on our representatives to lay down some common sense rules to curb surveillance capitalism.
In today’s news: One week left to send in your podcast listener survey; update all your iOS devices ASAP; Apple walks back a controversial OS change that would have allowed some Apple apps to bypass firewalls and VPNs; Microsoft is touting a new Edge browser feature that notifies you when your passwords have been breached; an innocuous-looking police robot is actually paving the way towards chilling mass surveillance; another US intelligence agency has been caught buying the location data of US citizens from data brokers; Apple’s efforts at improving user privacy are ruffling more feathers at Google and Facebook.
Further Info
New Years Resolution ideas for 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/Data Privacy Day checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ Listener survey: https://bit.ly/Firewalls-survey-2021 Patron survey: http://bit.ly/Firewalls-patron-survey-2021

Jan 25, 2021 • 57min
De-Googling Your Life
We all love to beat up on Facebook over user privacy, but the real granddaddy of them all is Google. Google is everywhere. And they almost surely know way more about you than any other company on the planet. In addition to all the "G" apps and services that you know about, Google also owns Android, Chrome browser, Waze, Nest and YouTube. It's extremely hard to avoid using Google. But there are alternatives that will respect your privacy - and today I'll give you a long list of viable options. And with international Data Privacy Day happening this week (Jan 28th), it's a great time to take back control of your data.
In other news: Some malicious Chrome extensions have been scraping Facebook data, a man working for ADT has been caught spying on women using the security cameras he helped to install, Google seems to be dragging their heels on updating their iOS app privacy labels, Malwarebytes says they've been hacked by the same group behind the SolarWinds hacks, WhatsApp has upset many of their users with a new privacy ultimatum, and I'll delve into the national security implications of the recent US Capitol breach.
Further Info
Listener survey: https://bit.ly/Firewalls-survey-2021 Patron survey: http://bit.ly/Firewalls-patron-survey-2021 My Data Privacy Day Checklist: https://firewallsdontstopdragons.com/data-privacy-day-checklist/ Google Alternatives: https://restoreprivacy.com/google-alternatives/Restore Privacy tools: https://restoreprivacy.com/privacy-tools/ No More Google: https://nomoregoogle.com/ Just Get My Data: https://justgetmydata.com/Just Delete Me: https://justdeleteme.xyz/

Jan 18, 2021 • 36min
Choosing a Private Email Service (Part 2)
So I want to switch to a new, privacy-respecting email service. How do I even do that? What happens to all the email I have now? What about my calendar and contacts? Am I going to have to change my email address every time I change email providers? In part 2 of my interview with Fastmail's COO Helen Horstmann-Allen, we'll answer these questions and also address the thorny issue of privileged access by law enforcement.
Helen Horstmann-Allen is the Chief Operating Officer at Fastmail where she provides overall business strategy and product direction for Fastmail and its suite of products. Before Fastmail, she ran her company, Pobox, an email forwarding service, for 20 years before Fastmail acquired it in 2015. Helen graduated from the Wharton School of Business and currently serves on several nonprofit boards in the Philadelphia area.
Further Info
2021 Listener Survey: http://bit.ly/Firewalls-survey-2021 New Year’s Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/ No More Google: https://nomoregoogle.com/ Sign up for Fastmail (referral link): https://ref.fm/u18721448

Jan 11, 2021 • 38min
Choosing a Private Email Service (Part 1)
What could I learn about you if I read all your emails? Like, all of them. Since you started sending email. Beyond private conversations, I would also likely know every web site you have a relationship or account with, every online purchase you've made, every club or organization you've been a part of, and all the appointments you've made. I can also make a pretty comprehensive list of everyone you know. And that's just the tip of the iceberg. If I analyze the content of your emails, I could almost certainly determine your political leanings, sexual preferences, religion, income, location(s), and more. So why don't we put more thought into choosing our email provider? In part one of my interview with Fastmail's COO, Helen Horstmann-Allen, we'll discuss how email privacy really works and why it's so crucially important.
Helen Horstmann-Allen is the Chief Operating Officer at FastMail where she provides overall business strategy and product direction for Fastmail and its suite of products. Before Fastmail, she ran her company, Pobox, an email forwarding service, for 20 years before Fastmail acquired it in 2015. Helen graduated from the Wharton School of Business and currently serves on several nonprofit boards in the Philadelphia area.
Further Info
CONTEST LINK!! http://bit.ly/Firewalls-200 New Year's Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/ No More Google: https://nomoregoogle.com/Sign up for Fastmail (referral link): https://ref.fm/u18721448 Arnold’s take: https://www.youtube.com/watch?v=mz3zFsTp2Pk

Jan 4, 2021 • 60min
The Great SolarWinds Hack
The Russian SVR has had backdoor access to hundreds if not thousands of government and corporate networks for nearly nine months. And if not for private security firm FireEye, we might never have known. The SolarWinds supply chain hack may be the biggest, most consequential cybersecurity event ever. And it will literally be years before we understand the full impacts. However, from what we know so far, this was not an "attack" or "act of war" ... it was straight-up espionage, which is widely accepted as normal during peacetime. The US does this all the time, as do all modern nations. And yet, espionage and infiltration are the first steps in any actual attack. It's a fine line. We'll discuss it today.
In other news: Adobe Flash is finally dead - it's time to remove it; Facebook is being sued by almost all 50 states and the Federal Trade Commission; butt-flap pajamas flooded internet ads; GoDaddy plays a cruel Christmas prank on its employees; Microsoft, McAfee and many others have joined forces to fight ransomware; and Signal messenger was NOT hacked by Cellebrite.
Further Info
CONTEST LINK!! http://bit.ly/Firewalls-200 Follow me on Facebook!! https://bit.ly/Firewalls-FacebookFollow me on YouTube!! https://bit.ly/Firewalls-YouTubeNew Year's Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/ Uninstall Adobe Flash:Windows: https://helpx.adobe.com/flash-player/kb/uninstall-flash-player-windows.htmlMac: https://helpx.adobe.com/flash-player/kb/uninstall-flash-player-mac-os.html

Dec 28, 2020 • 1h 20min
200th Podcast & New Year’s 2021!
The dumpster fire that was 2020 is almost behind us, and it's time to look forward to a brighter future in 2021! By a stroke of fortuitous coincidence, this is also my 200th podcast! To celebrate these two important milestones, we have a world-renowned security guru for our guest, Bruce Schneier, and I'll be giving away over $1800 worth of great stuff to help you improve your privacy and security in 2021! And if all of that weren't enough, I'll also be sharing with you several top-notch to-do list ideas for your 2021 New Year's resolutions - not just from myself, but from several top industry experts! It's an amazing star-studded, prize-riddled, info-packed podcast!
Special Guest Appearances By:
Bruce Schneier (Chief of Security Architecture at Inrupt)Dr Ann Cavoukian (Executive Director at Global Privacy & Security by Design Centre)Dr Andy Yen (CEO/Co-Founder ProtonMail)Cory Doctorow (author & activist)David Ruiz (Malwarebytes)Helen Horstmann-Allen (COO Fastmail)Beah Burger-Lenehan (Director, Product at DuckDuckGo)Marshall Erwin (Chief Security Officer, Mozilla)Todd Weaver (Founder/CEO Purism)Rich Stokes (Founder/CEO Winston Privacy)
Further Info:
CONTEST LINK!! http://bit.ly/Firewalls-200Contest info: https://firewallsdontstopdragons.com/new-years-2021-giveaway/New Year's Resolutions 2021: https://firewallsdontstopdragons.com/new-years-resolutions-2021/Inrupt: https://inrupt.com/solidSolid Project: https://solidproject.org/Follow me on Facebook!! https://bit.ly/Firewalls-FacebookFollow me on YouTube!! https://bit.ly/Firewalls-YouTube

Dec 21, 2020 • 1h 9min
Best of 2020!
I've painstakingly scoured the last 50 episodes to select the best of the best, the cream of the crop, the top tips for the year 2020! If you're already a subscriber, this will be a great refresher - and maybe give you a chance to do some of those things you had meant to do but somehow never got around to doing it! And if you're a new subscriber, then you can catch up on some of what you missed! This would also be a great episode to share with friends and family who you feel might also benefit from improving their cyber security and data privacy! Enjoy! And Happy Holidays!!
Further Info
Don't miss the HUGE 200th episode next week! https://firewallsdontstopdragons.com/200th-podcast-a-brighter-future/Follow me on Facebook!! https://bit.ly/Firewalls-Facebook Follow me on YouTube!! https://bit.ly/Firewalls-YouTube

Dec 14, 2020 • 59min
Setting the Digital Standard (Part 2)
One today's show, Ben Moskowitz from Consumer Reports will tell us about an extremely useful tool they've created to help you improve your personal security and privacy, customized to your particular needs, called the Security Scanner. Just answer a few simple questions and it will give you a checklist of specific ways to be more secure, ranked by time, effort and cost.
Consumer Reports is also pioneering a comprehensive, open-source program that will allow consumers, manufacturers, advocacy organizations, and more to formally evaluate the privacy and security aspects of products and services. This will allow buyers to compare products more accurately and give manufacturers incentives to make better products.
Benjamin Moskowitz is the Director of Consumer Reports’ Digital Lab, a major initiative to expand CR’s work on privacy, digital security, and emerging concerns in digital consumer protection. Previously, he served as Director of Development for Innovation for the International Rescue Committee, where he secured more than $29 million in funding as a founding member of the Airbel Center—a research and development unit that designs, tests, and scales life-changing solutions for refugees and people affected by conflict.
Further Info
Consumer Reports Security Planner: https://securityplanner.consumerreports.org/ The Digital Standard: https://thedigitalstandard.org/ Virtual screening of Coded Bias: https://action.consumerreports.org/coded_bias Contribute! https://digital-lab.consumerreports.org/ Become a CR Member: https://www.consumerreports.org/membership Privacy Front & Center study: https://thedigitalstandard.org/downloads/CR_PrivacyFrontAndCenter_102020_vf.pdf Best & Worst Gift Guide 2020: https://firewallsdontstopdragons.com/best-worst-gifts-2020/ Follow me on Facebook!! https://bit.ly/Firewalls-Facebook Follow me on YouTube!! https://bit.ly/Firewalls-YouTubeRequest book for review: https://form.jotform.com/203127587895064

Dec 7, 2020 • 45min
Setting the Digital Standard (Part 1)
Are consumers really concerned about security and privacy in the products they buy? And if so, how could manufacturers capitalize on these attributes to sell more of their products? Consumer Reports has recently published an important, comprehensive study of consumer attitudes towards privacy and security, including the historical evolution of these feelings. The result is a roadmap which companies can use to better serve this fast-growing market. Today we'll discuss this study and its implications with Ben Moskowitz from CR's Digital Lab.
Benjamin Moskowitz is the Director of Consumer Reports' Digital Lab, a major initiative to expand CR’s work on privacy, digital security, and emerging concerns in digital consumer protection. Previously, he served as Director of Development for Innovation for the International Rescue Committee, where he secured more than $29 million in funding as a founding member of the Airbel Center—a research and development unit that designs, tests, and scales life-changing solutions for refugees and people affected by conflict.
Further Info:
Privacy Front & Center study: https://thedigitalstandard.org/downloads/CR_PrivacyFrontAndCenter_102020_vf.pdfConsumer Reports Security Planner: https://securityplanner.consumerreports.org/The Digital Standard: https://thedigitalstandard.org/Virtual screening of Coded Bias: https://action.consumerreports.org/coded_biasContribute! https://digital-lab.consumerreports.org/Become a CR Member: https://www.consumerreports.org/membershipMy new YouTube Channel: https://www.youtube.com/channel/UC0aUElaV7hDubXSpDJkiSrARequest book for review: https://form.jotform.com/203127587895064