

Shared Security Podcast
Tom Eston, Scott Wright, Kevin Johnson
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Johnson break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Episodes
Mentioned books

Aug 21, 2023 • 22min
Business Email Compromise Scams Revisited
In this best of episode from December 2021, we revisit Business Email Compromise (BEC) scams. What are they, how to identify them, and why BEC scams have resulted in well over $3 billion in losses since 2016, more than any other type of fraud in the U.S. We also share our tips on how to […]
The post Business Email Compromise Scams Revisited appeared first on Shared Security Podcast.

Aug 14, 2023 • 18min
The Current and Future State of Email Security with Andy Yen, CEO of Proton
Andy Yen, the CEO and founder of Proton, shares his insights on the evolution of email security. With a background in particle physics and experience at CERN, he discusses the shift towards privacy-focused email services. Yen highlights the importance of using email aliases for enhanced security against phishing and spam. He also addresses the dual role of AI, noting its potential to both improve and threaten email safety. Finally, he outlines Proton’s mission to foster a privacy-centric ecosystem, emphasizing user empowerment in the digital age.

Aug 7, 2023 • 27min
Common Sense Advice for Hacker Summer Camp, AI Chatbot Attacks, What’s a Flipper Zero?
In this episode, we discuss our common sense tips to stay safe and secure while attending “Hacker Summer Camp”: BSides, Black Hat, and DEF CON hacking conferences in Las Vegas. Next, we discuss the vulnerabilities and potential adversarial attacks on large language models like ChatGPT and other AI chat bots. Finally, we discuss the Flipper […]
The post Common Sense Advice for Hacker Summer Camp, AI Chatbot Attacks, What’s a Flipper Zero? appeared first on Shared Security Podcast.

Jul 31, 2023 • 26min
Your Digital Immortality is Coming, Apple and Google Are Data Gatekeepers, Satellite Security Risks Revealed
In this episode, we explore the implications and ethical dilemmas of immortality in the digital world. Listen to our discussion about this cutting-edge technology and its potential impact on our privacy. Next, we discuss the growing trend of Apple and Google becoming custodians of our digital lives. Have these tech companies gone too far? Join […]
The post Your Digital Immortality is Coming, Apple and Google Are Data Gatekeepers, Satellite Security Risks Revealed appeared first on Shared Security Podcast.

Jul 24, 2023 • 33min
Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program
In this episode, we discuss the recent Microsoft security breach where China-backed hackers gained access to numerous email inboxes, including those of several federal government agencies, using a stolen Microsoft signing key to forge authentication tokens. A TikTok influencer used a voice cloning app to expose a cheating boyfriend. But wait, there’s more to this […]
The post Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program appeared first on Shared Security Podcast.

Jul 17, 2023 • 33min
First Ban on Selling Location Data, Prohibiting Password Managers, Real-Time Crime Center Concerns
In this episode we discuss how Massachusetts lawmakers are pushing a groundbreaking bill to ban the buying and selling of location data from mobile devices. This legislation raises vital questions about consumer privacy, digital stalking, and national security threats. Next, we discuss the pros and cons of prohibiting external password managers within organizations. Join the […]
The post First Ban on Selling Location Data, Prohibiting Password Managers, Real-Time Crime Center Concerns appeared first on Shared Security Podcast.

Jul 10, 2023 • 24min
Meta’s Threads and Your Privacy, Airline Reservation Scams, IDOR Srikes Back
In this episode, we explore the rise of Threads, a new social media app developed by Meta, which has already attracted 10 million users in just seven hours. However, there’s a catch – the app collects extensive personal data, sparking concerns about privacy. Next, we dive into the world of airline reservation scams, exposing how […]
The post Meta’s Threads and Your Privacy, Airline Reservation Scams, IDOR Srikes Back appeared first on Shared Security Podcast.

Jul 3, 2023 • 27min
MOVEit Cyberattack, The Problem with Password Rotations, Military Alert on Free Smartwatches
Several major organizations, including British Airways and the BBC, fell victim to the recent MOVEit cyberattack. We discuss the alarming trend of hackers targeting trusted suppliers to gain access to customer data, potentially holding companies and individuals for ransom. Is it better to change passwords regularly or focus on creating complex ones? We discuss the […]
The post MOVEit Cyberattack, The Problem with Password Rotations, Military Alert on Free Smartwatches appeared first on Shared Security Podcast.

Jun 26, 2023 • 35min
Security Podcasting, Hacking Stories, and The State of Firmware Security with Paul Asadoorian
Paul Asadoorian, OG security podcaster and host of the popular Paul’s Security Weekly podcast, joins us in this episode to talk about his career as one of the original security podcasters. Paul’s been podcasting for more than 17 years! Paul also shares with us some of his greatest hacking stories and don’t miss our lively […]
The post Security Podcasting, Hacking Stories, and The State of Firmware Security with Paul Asadoorian appeared first on Shared Security Podcast.

Jun 19, 2023 • 35min
The FTC’s Complaint Against Ring, Detecting Malware Infected Apps, America’s Most Cybersecure Companies
The FTC charged Ring, the Amazon-owned home security camera company, for compromising customer privacy and having inadequate security measures. Employees accessed private videos, while hackers exploited vulnerabilities and now Ring needs to reimburse customers $5.8 million dollars. The FTC complaint emphasizes that Ring’s actions disregarded privacy and security, putting consumers at risk. Google has removed […]
The post The FTC’s Complaint Against Ring, Detecting Malware Infected Apps, America’s Most Cybersecure Companies appeared first on Shared Security Podcast.


