
Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Latest episodes

Mar 4, 2024 • 1h 7min
How Our Data is Abused
With the rise of IoT and tracking technologies (both online and in the real word), we are generating staggering amounts of highly personal information. This massive trove of juicy data has drawn the attention of several interested parties outside the realm of consumer marketing. Like chum in the water, it's created a feeding frenzy from data aggregators as well as from law enforcement and intelligence agencies, both foreign and domestic. The journalists at 404 Media have published several blockbuster articles on this data ecosystem which have triggered backlashes from lawmakers and consumers alike. Today I'll speak with two of the founders: Joseph Cox and Jason Koebler.
Interview Notes
404 Media: https://www.404media.co/
404 Media podcast: https://www.404media.co/the-404-media-podcast/
404 Media support: https://www.404media.co/faq/
Formation of 404 Media: https://www.nytimes.com/2023/08/22/business/media/404-media-vice-motherboard.html
Further Info
Send me your questions! https://fdsd.me/qna
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Subscribe to the newsletter: https://fdsd.me/newsletter
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Support our mission! https://fdsd.me/support
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:03: Interview setup
0:02:45: How did 404 Media come to be?
0:12:00: When do we think law enforcement started buying our data?
0:15:39: What's up with companies listening to our conversations?
0:23:01: Where does law enforcement go to get our data?
0:27:46: How are video feeds being gathered and sold?
0:34:23: Can't all this data also be used by "bad guys"?
0:39:13: Is it legal for law enforcement to buy data from foreign sources?
0:44:28: Have your stories triggered responses from the US government?
0:50:01: Trust in media is low these days - how can we fix that?
0:59:37: How can we support good work like yours?
1:03:22: Wrap-up

Feb 26, 2024 • 1h 5min
Mitigating AI Risks
Artificial Intelligence is the buzzword of the day. Since the launch of ChatGPT in November 2022, there has been a flood of AI-based tools and services. Many tech firms are racing to build AI into their products without considering the consequences, let alone taking the time to build in guardrails for privacy and security. Today, I'll tell you about some of the risks, how to mitigate them and explain why you should spend some time playing with AI tools so we can understand how they do (and don't) work.
In other news: Wyze home webcams had yet another security breach; Poland's PM calls out illegal use of Pegasus spyware by opposition party; US military finally notifies 20,000 of email data breach; Skiff was bought by Notion and will shut down services; FTC fines Avast antivirus $16.5M for mining user data; Backdoors in encryption violate human rights according to EU court; LockBit ransomware servers were taken over by multinational law enforcement efforts; Apple's iMessage gaining quantum computer resistant encryption; Signal finally allows users to hide cell phone numbers via usernames; new Android secure browsing features announced.
Article Links
[Lifehacker] Wyze Had a Security Breach (Again) https://lifehacker.com/tech/wyze-security-breach-again
[The Associated Press] Poland’s prime minister says authorities widely used spyware under the previous government https://apnews.com/article/poland-government-pegasus-spyware-tusk-duda-78420fc7099401926d28b5be98669192
[TechCrunch] US military notifies 20,000 of data breach after cloud email leak https://techcrunch.com/2024/02/14/department-defense-data-breach-microsoft-cloud-email/
[The Cut] The Day I Put $50,000 in a Shoe Box and Handed It to a Stranger https://www.thecut.com/article/amazon-scam-call-ftc-arrest-warrants.html
https://pluralistic.net/2024/02/05/cyber-dunning-kruger/
[restoreprivacy.com] Skiff Mail Shutting Down in 6 Months (Try These Alternatives) https://restoreprivacy.com/skiff-shutting-down-alternatives-to-skiff-mail/
[404media.co] FTC Fines Avast $16.5 Million For Selling Browsing Data Harvested by Antivirus https://www.404media.co/impact-ftc-fines-avast-16-5-million-for-selling-browsing-data-harvested-by-antivirus/
[Ars Technica] Backdoors that let cops decrypt messages violate human rights, EU court says https://arstechnica.com/tech-policy/2024/02/human-rights-court-takes-stand-against-weakening-of-end-to-end-encryption/
[Ars Technica] LockBit ransomware group taken down in multinational operation https://arstechnica.com/information-technology/2024/02/lockbit-ransomware-group-taken-down-in-multinational-operation/
[WIRED] Apple’s iMessage Is Getting Post-Quantum Encryption https://www.wired.com/story/apple-pq3-post-quantum-encryption/
[signal.org] Keep your phone number private with Signal usernames https://signal.org/blog/phone-number-privacy-usernames/
[Lifehacker] These New Android Features Will Keep You Safer Online https://lifehacker.com/tech/android-safer-browsing-and-live-threat-detection-rolling-out
Tip of the Week: Mitigating AI Risks https://firewallsdontstopdragons.com/how-to-mitigate-the-risks-of-ai/
Further Info
Send me your questions! https://fdsd.me/qna
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Subscribe to the newsletter: https://fdsd.me/newsletter
Become a patron! https://www.patreon.com/FirewallsDontStopDragons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Support our mission! https://fdsd.me/support
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:44: AT&T outage, hot take
0:03:08: News rundown
0:04:44: Wyze Had a Security Breach (Again)
0:07:27: Poland’s PM says authorities used spyware under the previous government

Feb 19, 2024 • 1h 5min
Car Privacy is Horrid
Modern cars are chock full of sensors and connected to the internet via built-in cellular modems. That's a recipe for massive data collection. Last September, Mozilla's Privacy Not Included team released a blockbuster report how much data our cars were gathering and it was absolutely staggering. According to the hard-to-find privacy policies, your car can collect extremely personal information including precise location, contact lists from your phone, call and message data, and - believe it or not - even "sexual activity". Today, I'll walk through this report and its implications with the head of Mozilla's Privacy Not Included project, Jen Caltrider.
Interview Notes
Mozilla’s Privacy Not Included: https://foundation.mozilla.org/en/privacynotincluded/
Mozilla’s car report: https://foundation.mozilla.org/en/privacynotincluded/articles/its-official-cars-are-the-worst-product-category-we-have-ever-reviewed-for-privacy/
Mozilla's report on AI chatbots: https://foundation.mozilla.org/en/privacynotincluded/articles/happy-valentines-day-romantic-ai-chatbots-dont-have-your-privacy-at-heart/
Donate to Mozilla Foundation: https://donate.mozilla.org/
Mozilla layoffs: https://techcrunch.com/2024/02/13/mozilla-downsizes-as-it-refocuses-on-firefox-and-ai-read-the-memo/
Sign the petition to stop car data gathering! https://foundation.mozilla.org/en/privacynotincluded/articles/car-companies-stop-your-huge-data-collection-programs-en/
Bruce Schneier article in Slate: https://slate.com/technology/2023/12/ai-mass-spying-internet-surveillance.html
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:02:39: What were some top finding from your car privacy report?
0:05:14: Which cars did you review and how did you evaluate them?
0:09:44: How was I notified and how did I consent to my car's privacy policy?
0:10:39: What are cars tracking? Are electric cars any worse than gas cars?
0:13:55: What third party data mining is going on in my car?
0:20:41: Is there a way to opt out of data sharing?
0:24:10: Is less data collected in Europe?
0:26:02: Where is all my data stored? Locally, in the cloud, or both?
0:28:52: Is the data at least secured?
0:29:48: Can dealerships access my data? What about law enforcement?
0:32:28: What about rental or fleet cars? What about passengers?
0:37:24: Do car dealers disclose this data collection to shoppers?
0:39:11: What are some of the security problems with this data collection?
0:45:55: How did car makers and legislators respond to your report?
0:48:36: Do modern privacy laws cover auto data?
0:50:48: So what can we do about this today?
0:54:30: What will Privacy Not Included tackle next?
0:58:40: Wrap-up

Feb 12, 2024 • 53min
Avoiding Tax Scams
It's tax time here again in the USA, and therefore it's also time for tax scams. I'll explain how to recognize common tax scams, how to respond to them, how to prevent scammers from taking over your IRS account and even filing fraudulent tax returns in your name.
In other news: the Mother of All Breaches (MOAB) contains 26 billion records; 23andMe is in trouble after massive data breach and pending class action lawsuits; a viral story about a smart toothbrush botnet isn't true... but could have been; a clever hack of older computer TPM modules could expose encrypted hard drive data (but it's not easy to do); Malwarebytes has issued their 2024 malware report; the FBI and CISA are raising the alarm over Chinese hackers and key US infrastructure, as well as taking action to prevent it; you might want to consider creating a family password to defeat voice clone scams; Mozilla has released a new data deletion service; and Privacy4Cars has an interesting new mechanism for universally opting out of data collection.
Article Links
[cybernews] Mother of all breaches reveals 26 billion records https://cybernews.com/security/billions-passwords-credentials-leaked-mother-of-all-breaches/
[Fast Company] 23andMe at risk of being delisted from the Nasdaq as lawsuits mount https://www.fastcompany.com/91020738/23andme-risk-delisted-nasdaq-class-action-lawsuits
[404media.co] The Viral Smart Toothbrush Botnet Story Almost Certainly Isn't Real https://www.404media.co/the-viral-toothbrush-ddos-botnet-story-almost-certainly-isnt-real/
[Tom's Hardware] YouTuber breaks BitLocker encryption in less than 43 seconds with sub-$10 Raspberry Pi Pico https://www.tomshardware.com/pc-components/cpus/youtuber-breaks-bitlocker-encryption-in-less-than-43-seconds-with-sub-dollar10-raspberry-pi-pico
[9to5Mac] Report: Mac security threats on the rise, here’s what to watch out for https://9to5mac.com/2024/02/06/report-mac-security-threats-on-the-rise/
[NBC News] FBI director to warn Chinese hackers aim to 'wreak havoc' on US critical infrastructure https://www.nbcnews.com/politics/national-security/fbi-director-warn-chinese-hackers-aim-wreak-havoc-us-critical-infrastr-rcna136524
[Ars Technica] Chinese malware removed from SOHO routers after FBI issues covert commands https://arstechnica.com/security/2024/01/chinese-malware-removed-from-soho-routers-after-fbi-issues-covert-commands/
[cisa.gov] CISA and FBI Release Secure by Design Alert Urging Manufacturers to Eliminate Defects in SOHO Routers https://www.cisa.gov/news-events/alerts/2024/01/31/cisa-and-fbi-release-secure-design-alert-urging-manufacturers-eliminate-defects-soho-routers
[9to5Mac] FCC outlaws voice cloning robocalls after AI-generated voice claimed to be President Biden https://9to5mac.com/2024/02/08/voice-cloning-robocalls/
[Electronic Frontier Foundation] Worried about AI voice clone scams? Create a family password https://www.eff.org/deeplinks/2024/01/worried-about-ai-voice-clone-scams-create-family-password
[The Verge] Firefox maker Mozilla has a new subscription to keep your info out of data brokers’ clutches https://www.theverge.com/2024/2/6/24062765/mozilla-monitor-plus-firefox-paid-subscription-privacy-data-broker-removal-requests
[optoutcode.com] A Privacy4Cars Universal Opt-Out Concept https://optoutcode.com/
Tip of the Week: Avoiding Tax Scams https://firewallsdontstopdragons.com/how-to-avoid-tax-scams/
Further Info
Secure Your Network: https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/
Davos speech, original: https://www.youtube.com/watch?v=fJoEPRQMBuY
Davos speech, translated: https://www.youtube.com/live/6Fwv9Cek2F4?feature=shared&t=98
How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/
How to send files securely: https://firewallsdontstopdragons.com/how-to-send-files-securely-like-tax-info/
Send me your questions! https://fdsd.

Feb 5, 2024 • 1h 13min
Securing Your Mac
Are Macs really safer than PCs? What should you do to make your Mac more secure? How do you know if your Mac has a virus? And how do you know which security apps you can trust? I'll dig into all of these questions and more today with Mac security guru Patrick Wardle.
Patrick Wardle is the founder of the Objective-See Foundation. Having worked at NASA and the NSA, as well as presented at countless security conferences Patrick is passionate about all things related to macOS security, writing books on macOS malware, and releasing free open-source security tools to protect Mac users.
Interview Notes
Objective See (free Mac tools): https://objective-see.org/
The Art of Mac Malware (book): https://taomm.org/
Objective by the Sea conference: https://objectivebythesea.org/
Apple’s Malware protections: https://support.apple.com/guide/security/protecting-against-malware-sec469d47bd8/1/web/1
Reinstall macOS in Recovery Mode: https://support.apple.com/en-us/HT204904
Jamf presentation on Apple anti-malware tools: https://www.jamf.com/resources/videos/a-closer-look-at-macos-built-in-security-tools/
Further Info
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:45: Interview setup
0:04:06: What have you been up to since we last had you on the show?
0:13:40: Are Macs safer than PCs?
0:17:34: How effective are modern antivirus programs?
0:22:25: Which are the better AV software programs?
0:24:45: Tell us about the Mac security apps that you created
0:27:53: How does Lulu differ from a regular firewall?
0:32:00: How do you know which security software you can trust?
0:38:00: How do we combat security fatigue?
0:43:22: Does the Apple App Store protect me from bad apps?
0:52:09: What's your take on Apple's new Lockdown Mode?
0:53:34: How do I know if my computer is infected with malware?
0:58:03: What should I do to protect my brand new Mac?
1:01:23: What worries you most right now? What gives you hope?
1:04:43: What's next for you?
1:10:31: Wrap-up

Jan 29, 2024 • 1h 8min
Data Privacy Week 2024
While every week is Data Privacy Week here at Firewalls Don't Stop Dragons, the rest of the world stops to join us in focusing on how and why to protect your personal data. I'll give you some of my top privacy tips and refer you to a lot of top privacy resources.
In the news: Microsoft executives' emails are hacked by a nation-state actor; Facebook is gathering even more data with the help of other companies; a company is using real-time bidding to track us and sell to intelligence agencies; Mozilla outlines how incumbent browser owners tilt the playing field in favor of the owner; the EU is driving major changes to how iOS will work (but only in the EU); Brave browser simplifies its anti-fingerprinting options; Facebook limits how adult strangers can DM minors; FTC brings actions against GoodRx and Intuit; Samsung matches Google's 7-year OS update update promise; and Apple rolls out Stolen Device Protection feature.
Article Links
[msrc.microsoft.com] Microsoft Actions Following Attack by Nation State Actor Midnight Blizzard https://msrc.microsoft.com/blog/2024/01/microsoft-actions-following-attack-by-nation-state-actor-midnight-blizzard/
[Consumer Reports] Each Facebook User Is Monitored by Thousands of Companies https://www.consumerreports.org/electronics/privacy/each-facebook-user-is-monitored-by-thousands-of-companies-a5824207467/
[404media.co] Inside a Global Phone Spy Tool Monitoring Billions https://www.404media.co/inside-global-phone-spy-tool-patternz-nuviad-real-time-bidding/
[Mozilla] Platform Tilt: Documenting the Uneven Playing Field for an Independent Browser Like Firefox https://blog.mozilla.org/netpolicy/2024/01/19/platform-tilt
[MacRumors] Here Are All the iPhone Changes Coming to EU Users by March 6 https://www.macrumors.com/2024/01/26/iphone-changes-coming-to-eu-users/
[brave.com] Brave browser simplifies its fingerprinting protections https://brave.com/privacy-updates/28-sunsetting-strict-fingerprinting-mode/
[9to5Mac] Adult strangers won’t be able to send DMs to teens on Instagram or Facebook https://9to5mac.com/2024/01/25/teens-on-instagram-safeguards/
[ftc.gov] FTC Statement on Intuit TurboTax Case https://www.ftc.gov/news-events/news/press-releases/2024/01/statement-samuel-levine-director-ftc-bureau-consumer-protection-regarding-commissions-order-opinion
[ftc.gov] FTC Enforcement Action to Bar GoodRx from Sharing Consumers’ Sensitive Health Info for Advertising https://www.ftc.gov/news-events/news/press-releases/2023/02/ftc-enforcement-action-bar-goodrx-sharing-consumers-sensitive-health-info-advertising
[9to5Google] Samsung Galaxy S24 follows Google Pixel 8’s lead with 7 years of Android updates https://9to5google.com/2024/01/17/samsung-galaxy-s24-android-updates-policy/
[AppleInsider] How to use Stolen Device Protection https://appleinsider.com/articles/24/01/23/how-to-use-stolen-device-protection
Tip of the Week: Data Privacy Checklist https://fdsd.me/dpc
Further Info
Carey’s Data Privacy Checklist (just updated!): https://fdsd.me/dpc
Proton’s mention: https://www.linkedin.com/posts/protonprivacy_protonprivacyreadinglist-activity-7155246272273170432-XlM0
Jeff Jockisch’s Best Privacy Podcast results: https://www.linkedin.com/posts/jozian_privacypodcast-peopleschoice-privacyawards-activity-7146196804940820481-yB-P
Send me your questions! https://fdsd.me/qna
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Subscribe to the newsletter: https://fdsd.me/newsletter
Become a patron! https://www.patreon.com/FirewallsDontStopDragons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Support our mission! https://fdsd.me/support
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:29: Recent accolades

Jan 22, 2024 • 1h 11min
Rise of the Slaughterbots
Drones are everywhere today. Cheap and tiny accelerometers, gyroscopes and processors have allowed us to create drones that anyone can afford and everyone can fly. Drones have been used by law enforcement and military forces, as well - for surveillance but also for killing. With the rapid development of AI technologies, what happens when we make these drones autonomous? What are the implications for privacy and security? I'll discuss this and more with Nick Weaver, computer and cybersecurity expert, and chief mad scientist at Skerry Technologies.
Interview Notes
Nick Weaver: https://www1.icsi.berkeley.edu/~nweaver/
NYPD drone use: https://www.washingtonpost.com/nation/2023/09/01/drones-labor-day-parties-new-york/
AI drone “kills” its operator: https://www.reuters.com/article/factcheck-ai-drone-kills/fact-check-simulation-of-ai-drone-killing-its-human-operator-was-hypothetical-air-force-says-idUSL1N38023R/
The Future of Drone Warfare: https://www.schneier.com/blog/archives/2023/10/the-future-of-drone-warfare.html
Betaflight: https://github.com/betaflight/betaflight
Ardupilot: https://github.com/ArduPilot/ardupilot
PX4: https://github.com/PX4/PX4-Autopilot
Small Business Innovation Research: https://www.sbir.gov/
Further Info
Data Privacy Week: https://staysafeonline.org/programs/data-privacy-week/
Carey’s Data Privacy Checklist (just updated!): https://fdsd.me/dpc
Nominate someone for a challenge coin: https://fdsd.me/quest
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Send me your questions! https://fdsd.me/qna
Support our mission! https://fdsd.me/support
Subscribe to the newsletter: https://fdsd.me/newsletter
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Would you like me to speak to your group about security and/or privacy? https://fdsd.me/speakerrequest
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:21: Data Privacy Week teaser
0:01:11: Apple backdoor clarification
0:03:14: Interview setup
0:07:15: What first got you interested in autonomous drone technology?
0:10:27: What technologies have enabled the explosion of cheap drones?
0:15:22: What are the capabilities of modern consumer drones?
0:17:54: Are there any legal restrictions on flying drones?
0:20:44: Are there privacy laws around drone surveillance?
0:22:24: How are drones used by law enforcement?
0:25:14: How are drones being used for criminal purposes?
0:27:12: What level of autonomy or AI can be found in consumer drones today?
0:29:41: How hard is it to turn a DJI drone into an autonomous killbot?
0:35:49: What sorts of countermeasures have we developed against drones?
0:45:11: What roles have drones played in modern warfare?
0:48:40: Can you detect drones on radar?
0:50:22: Have drones influenced modern military tactics?
0:52:33: Are there treaties restricting automomous killing machines?
0:55:51: What's the future of automonous drone tech?
0:58:46: Is it difficult today to make your own drone?
1:06:24: Interview wrap-up
1:09:08: Annual listener survey update

Jan 15, 2024 • 1h 22min
New Year’s Resolutions: 2024
The new year is here! And I've got a handful of solid tips for you that you should absolutely plan to accomplish in 2024! I also have a lot of news to catch you up on:
23andMe blames its customers for their data breach; Burger King in Brazil using facial recognition to offer discounts based on how hungover you look; Russian agents hack live webcams to hone in on targets in Ukraine; fake celebrity ads for medicare scam on YouTube; Facebook's Link History is a confusing new tracking feature; FTC orders location data broker to stop selling your info; Google new location history changes may spell the end for geofence warrants; AirDrop anonymity cracked by China; well-hidden iPhone backdoor discovered by Kaspersky; UK tries to further expand surveillance capabilities; the Beeper Mini messaging saga is over; and a marketing company is offering to listen in on real time conversations to target ads.
Article Links
[TechCrunch] 23andMe tells victims it’s their fault that their data was breached https://techcrunch.com/2024/01/03/23andme-tells-victims-its-their-fault-that-their-data-was-breached/
[Dark Reading] Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv https://www.darkreading.com/ics-ot-security/russian-agents-use-residential-webcams-to-gather-info-for-missile-attack-on-kyiv
[404media.co] Deepfaked Celebrity Ads Promoting Medicare Scams Run Rampant on YouTube https://www.404media.co/joe-rogan-taylor-swift-andrew-tate-ai-deepfake-youtube-medicare-ads/
[Gizmodo] Meet ‘Link History,’ Facebook’s New Way to Track the Websites You Visit https://gizmodo.com/meet-link-history-facebook-s-new-way-to-track-the-we-1851134018
[ftc.gov] FTC Order Prohibits Data Broker X-Mode Social and Outlogic from Selling Sensitive Location Data https://www.ftc.gov/news-events/news/press-releases/2024/01/ftc-order-prohibits-data-broker-x-mode-social-outlogic-selling-sensitive-location-data
[Electronic Frontier Foundation] Is This the End of Geofence Warrants? https://www.eff.org/deeplinks/2023/12/end-geofence-warrants
[9to5Mac] AirDrop cracked by China, revealing phone number and email address of sender https://9to5mac.com/2024/01/09/airdrop-cracked-by-china/
[Schneier Blog] New iPhone Exploit Uses Four Zero-Days https://www.schneier.com/blog/archives/2024/01/new-iphone-exploit-uses-four-zero-days.html
Security Now, Ep955: https://youtu.be/fJHzq4YOv68?si=WTdyr5LCXV4xJh-k&t=2105
[POLITICO Europe] Britain’s got some of Europe’s toughest surveillance laws. Now it wants more https://www.politico.eu/article/uk-bulking-up-spying-regime-breakneck-speed/
[MacRumors] Beeper Mini Resorts to Jailbreaking iPhones to Rescue Blue Bubbles https://www.macrumors.com/2023/12/21/beeper-mini-jailbroken-iphones-rescue-imessage/
[404media.co] Marketing Company Claims That It Actually Is Listening to Your Phone and Smart Speakers to Target Ads https://www.404media.co/cmg-cox-media-actually-listening-to-phones-smartspeakers-for-ads-marketing/
Tip of the Week: https://firewallsdontstopdragons.com/new-years-resolutions-for-2024/
Further Info
Take the annual listener survey! https://fdsd.me/survey2024
Send me your questions! https://fdsd.me/qna
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Subscribe to the newsletter: https://fdsd.me/newsletter
Become a patron! https://www.patreon.com/FirewallsDontStopDragons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Support our mission! https://fdsd.me/support
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:00:38: Listener survey
0:01:57: News rundown
0:04:35: 23andMe blames victims for their data breach
0:09:39: Russian Agents Hack Webcams to Guide Missile Attacks on Kyiv
0:15:19: Deepfaked Celebrity Ads Promoting Medicare Scams ...

Jan 8, 2024 • 1h 4min
Investigating Data Leaks
Data breaches are usually produced by hackers looking for financial gain. Data leaks, on the other hand, are usually published by whistleblowers or perhaps accidentally disclosed via negligence. Journalists today are inundated by such data leaks - to the point where specialized tools and techniques are required to parse through the piles of digital detritus to ascertain the value and import that they may represent. Micah Lee has been performing this function for The Intercept for many years, including analyzing the Snowden documents. And he has just released a book that outlines the tools, techniques and procedures he uses for this arduous process. Today we discuss the importance and impact of whistleblowers, the state of data leaks today, and how it has impacted modern journalism.
Interview Notes
Micah’s book: https://hacksandleaks.com/
Excerpt article: https://theintercept.com/2023/12/16/hacked-datasets-verification/
Micah’s GIthub project: https://github.com/micahflee/hacks-leaks-and-revelations
COINTELPRO documentary: https://en.wikipedia.org/wiki/1971_(2014_film)
“The Burglary” book: https://www.amazon.com/Burglary-Discovery-Edgar-Hoovers-Secret/dp/0307962954
EFF’s Surveillance Self-Defense Guide: https://ssd.eff.org/
Further Info
Take the annual listener survey! https://fdsd.me/survey2024
Vote for my show as the best privacy podcast! http://tinyurl.com/PPPCAwards2024
Send me your questions! https://fdsd.me/qna
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book
Subscribe to the newsletter: https://fdsd.me/newsletter
Become a patron! https://www.patreon.com/FirewallsDontStopDragons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Give the gift of privacy and security: https://fdsd.me/coupons
Support our mission! https://fdsd.me/support
Generate secure passphrases! https://d20key.com/#/
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:29: Pre-show notes
0:03:32: Interview prep
0:05:57: Tell us more about the book and why you wrote it.
0:08:11: What's the difference between a data breach and a data leak?
0:10:02: What are some of history's most importank leaks?
0:16:14: How do journalists typically obtain leaked data?
0:22:04: You've just obtained a massive blob of data. How do you analyze it?
0:27:05: How do you handle leaked data ethnically?
0:30:14: Do you warn the owners of leaked data before you reveal it?
0:32:23: I want to blow the whistle? What should I do? What shoudn't I do?
0:36:28: I've extracted my data. How do I securely share it with a journalist?
0:38:57: What are the legal ramifications of whistleblowing?
0:41:57: How hard is it to analyze digital data? What tools do you use?
0:44:39: Are there dangers to analyzing leaked data?
0:46:43: How do organizations try to identify data leakers?
0:49:42: Will AI tools like ChatGPT help to analyze data leaks?
0:52:19: What can the average person take away from all of this?
0:54:15: How do you know which news sources you can trust today?
0:56:08: Interview wrap-up
0:57:10: Micah blocked on Twitter?
0:57:55: Text parsing tools
0:58:30: Show links
0:58:53: Bonus podcast preview
0:59:42: Annual listener survey raffle info

Jan 1, 2024 • 58min
Best of 2023 Bonus Content
A sampler platter of the best snippets from bonus Q&A sessions with cybersecurity professionals and digital rights advocates. Topics include cyberattacks on hospitals, politics of privacy, hacking contests, AI ethics, Burning Man descriptions, challenges of rain in the desert, proxy hams for online anonymity, and reflections from previous episodes.
Remember Everything You Learn from Podcasts
Save insights instantly, chat with episodes, and build lasting knowledge - all powered by AI.