Shared Security Podcast

Tom Eston, Scott Wright, Kevin Tackett
undefined
8 snips
Oct 5, 2026 • 18min

Meta Muse: When Your AI Assistant Becomes the Attack Surface

Meta Muse promises to manage inboxes, calendars, browsers, and connected apps, but its sweeping authority creates a tempting attack surface. The discussion explores sandboxing, credential isolation, approval controls, token vulnerabilities, and reports of humans completing supposedly automated tasks. It also tackles privacy, liability for harmful decisions, Meta’s trust problem, and the unsettling future of AI agents acting after their owners can no longer intervene.
undefined
10 snips
Sep 28, 2026 • 15min

When Familiar Voices Become Scam Calls

AI voice cloning is turning familiar voices into powerful scam tools, from fake family emergencies to urgent executive requests. The discussion explores emotional manipulation, deepfake-driven election misinformation, and how scammers target money, credentials, and account access. It also covers family safe words, trusted call-backs, and practicing responses before a convincing impersonation arrives.
undefined
7 snips
Sep 21, 2026 • 16min

Will AI Kill Us All? Real Risks, Real Controls

How likely is AI to cause catastrophe, and who gets to define “safe”? Tom Eston, Scott Wright, and Kevin Tackett examine extinction warnings, corporate calls for regulation, and the incentives behind the AI arms race. They explore over-trusted automation, rapid wrong decisions, distributed systems that resist shutdown, and whether AI hype distracts from more immediate threats like climate change and nuclear conflict.
undefined
8 snips
Sep 14, 2026 • 20min

153 Million Driver’s Licenses for Sale: Why Identity Verification Is Broken

A reported dark-web service offering 153 million driver’s-license scans sparks a deeper look at identity verification. The discussion examines ID-scanning vendors, data brokers, weak storage practices, real-time capture, and the risks of outsourcing trust. It also explores privacy-preserving alternatives such as data minimization, limited sharing, local storage, and stronger accountability.
undefined
Sep 7, 2026 • 15min

Is Hotel WiFi Safe?

Hotel Wi‑Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft’s CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware delivery.They cover what HTTPS and VPNs actually protect, why a lock icon does not prove a page is legitimate, the warning signs that should make travelers disconnect, and when a cellular hotspot is the better choice. Scott also shares an update on his Digital Legacy Tree book and tools.** Links mentioned on the show **Microsoft Threat Intelligence — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/FBI hotel Wi‑Fi guidance https://watech.wa.gov/fbi-warns-cyber-risks-when-telecommuters-use-hotel-wi-fiFCC — Cybersecurity Tips for International Travelers https://www.fcc.gov/consumers/guides/cybersecurity-tips-international-travelersScott Wright — Digital Legacy Tree book and tools https://securityperspectives.com/digital-legacy-tools** Watch this episode on YouTube **https://youtu.be/TBqKfiGayfo** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
undefined
Aug 31, 2026 • 28min

Could a Pattern on Your Clothing Fool Facial Recognition? Interview with Bill Swearingen

Can a pattern on your clothing change what a camera thinks it sees? Tom talks with Black Hat USA 2026 speaker Bill Swearingen about adversarial clothing research, why person detection and facial recognition are different problems, and what model limitations mean for biometric surveillance, privacy, and accountability.** Links mentioned on the show **Black Hat USA 2026 briefing https://blackhat.com/us-26/briefings/schedule/#could-a-pattern-on-your-clothing-fool-facial-recognition-53532noRecognition Kickstarter https://www.kickstarter.com/projects/norecognition/norecognition-ai-adversarial-clothingBill speaking at DEF CON 34 (video) https://www.youtube.com/watch?v=WyPmt8CE5L4noRecognition research https://norecognition.org/researchConnect with Bill on LinkedInhttps://www.linkedin.com/in/billswearingen/** Watch this episode on YouTube **https://youtu.be/jw_WJNIYErQ** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **GuardsquareSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at https://guardsquare.com.SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
undefined
Aug 24, 2026 • 21min

What Happens to Your Digital Life When You Die?

Scott Wright joins Shared Security to discuss his Digital Legacy Tree framework and upcoming book, The Digital Legacy Tree. We talk about what happens to your accounts, passwords, devices, files, money, cloud storage, crypto, and online identity if you die, become incapacitated, or are suddenly unavailable — and how to plan for trusted access without weakening your security today.The conversation covers why “just use a password manager” is not enough, the roots-trunk-leaves model for organizing access, dependencies, and priorities, platform legacy-contact options, and the one practical first step: set up legacy or emergency contacts on your most critical accounts.** Links mentioned on the show **Scott Wright — securityperspectives.com (Digital Legacy Tree, Digital Legacy Tools, book beta review)https://securityperspectives.com/digital-legacy-tools/RUFADAA — Revised Uniform Fiduciary Access to Digital Assets Act https://en.wikipedia.org/wiki/Revised_Uniform_Fiduciary_Access_to_Digital_Assets_ActOpenID Foundation (digital legacy / account handover research) https://openid.netPrior Shared Security episode — What Happens to Your Social Media Accounts After You Die? https://sharedsecurity.net/2021/08/31/what-happens-to-your-social-media-accounts-after-you-die/** Watch this episode on YouTube **[YOUTUBE URL]** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **GuardsquareSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
undefined
Aug 17, 2026 • 25min

Flock Cameras Exposed: Traffic Tickets, ALPRs, and Vehicle Surveillance

Flock cameras and automated license plate readers are often sold as tools for finding stolen cars, wanted suspects, missing people, and serious threats. But what happens when that same infrastructure starts being used for everyday traffic enforcement, broader vehicle surveillance, or searchable location databases?In this episode, Tom, Kevin, and Scott discuss a 404 Media report about police allegedly using a Flock camera image to issue a traffic ticket, why that story is a warning sign for ALPR mission creep, and how systems marketed for public safety can become general-purpose surveillance infrastructure. They also talk about citizen pushback, vendor substitution, police discretion, data retention, audit logs, racialized camera deployment, rideshare dashcam surveillance proposals, and new technology that could associate phones and other wireless devices with identifiable vehicles.The core question is not whether stolen cars should be found or serious crimes should be investigated. The question is whether communities understand what they are approving when they install or renew ALPR systems — and whether policy promises like “we don’t use this for traffic enforcement” are actually enforceable.** Links mentioned on the show **404 Media: Police Used Flock to Give a Man a Traffic Ticket https://www.404media.co/police-used-flock-to-give-a-man-a-traffic-ticket/EFF: Traffic Violation! License Plate Reader Mission Creep Is Already Here https://www.eff.org/deeplinks/2026/03/traffic-violation-license-plate-reader-mission-creep-already-hereEFF: Victory! Flock Ends Rollout of Audio Distress Detection of Human Voices https://www.eff.org/deeplinks/2026/07/victory-flock-ends-rollout-audio-distress-detection-human-voices404 Media: Cops Used Flock to Track a Man Across State Lines to Create Pretext to Search His Car for Weed https://www.404media.co/cops-used-flock-to-track-a-man-across-state-lines-to-create-pretext-to-search-his-car-for-weed/DeFlock https://deflock.org/404 Media: Cities Are Ditching Flock, Immediately Replacing It With Axon License Plate Readers https://www.404media.co/cities-are-ditching-flock-immediately-replacing-it-with-axon-license-plate-readers/404 Media: Flock Pitched a Plan To Turn Uber and Lyft Drivers Into Roaming Surveillance Vehicles https://www.404media.co/flock-pitched-a-plan-to-turn-uber-and-lyft-drivers-into-roaming-surveillance-vehicles/The Conversation: New tech adds phone tracking to license plate readers https://theconversation.com/new-tech-adds-phone-tracking-to-license-plate-readers-associating-devices-with-identifiable-cars-288876** Watch this episode on YouTube **https://youtu.be/mSnQE33WRVE** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **GuardsquareSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contactSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.
undefined
8 snips
Aug 10, 2026 • 16min

GrapheneOS Phone Wipe Case: When Privacy Tools Become Evidence

A federal case about a GrapheneOS phone wipe sparks a debate on whether using strong mobile security can be treated as suspicious. The hosts unpack border search rules and why airports pose special legal risks. They explain duress codes and silent wipe features. Travel threat models and who uses hardened phones are discussed. A digital legacy project update closes out the conversation.
undefined
9 snips
Aug 3, 2026 • 23min

OpenAI Says Its AI Hacked Another Company on Its Own

A controversial AI security incident is unpacked, questioning whether a model acted autonomously or followed bad scope boundaries. The conversation tackles risks of giving AI real tools and permissions. Listeners hear why anthropomorphizing systems and ambiguous prompts make incidents harder to assess. Practical themes include logging, containment, permissions, and incident readiness.

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app