

Shared Security Podcast
Tom Eston, Scott Wright, Kevin Tackett
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Episodes
Mentioned books

Jul 14, 2015 • 31min
The Shared Security Podcast 42 – Car Theft, Risky Apps, Facebook Security Checkup
Podcast Update: The new website for the Shared Security Podcast will hopefully be live for the next episode! We hope you enjoy the new topics and format!
This is the 42nd episode of the Shared Security Podcast sponsored by the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded June 3, 2015. Below are the show notes, links to articles and news mentioned in the podcast:
Marauder’s Map plugin for Chrome allows geolocation of messenger communications for friends or people in a message thread
Facebook check-up feature being tested which is a new tool that might help users understand and select privacy settings that make sense to them
How social networks make it easy for adopted children to find their birth parents, not always with desirable or expected results. The focus is on a young girl who grew up believing her birth mother was like a Disney princess, and understandably wanted to connect with her. This story shows it isn’t always a good decision, and highlights the need for honesty with young adopted children regarding their past.
Risky mobile apps that parents need to know about.
How new smart key fobs are making it easy for thieves to break into cars with a $17 gadget you can buy online. Some people are starting to put their key fobs in the freezer to shield them from the radio signals used by thieves.
Please send any show feedback to feedback [aT] sharedsecurity.net or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Thanks for listening!
The post The Shared Security Podcast 42 – Car Theft, Risky Apps, Facebook Security Checkup appeared first on Shared Security Podcast.

May 15, 2015 • 43min
Social Media Security Podcast 41 – Podcast Updates, Internet of Things, TV Privacy
This is the 41st episode of the Social Media Security Podcast sponsored by the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded April 29, 2015. Below are the show notes, links to articles and news mentioned in the podcast:
Important Podcast Update!
While we haven’t finalized the details we’re hoping to rename the podcast as “Shared Security”. We have been discussing the fact that the privacy and security topics we’ve been covering are really spreading to more than just social media. Now, we see the important stories as being ones that relate to who and what we trust as connected individuals and businesses. So, we’ve decided that it might be time to rename the podcast to be more inclusive of important security stories beyond just social media, and we’ve decided on a new name for the program…
“Shared Security”
We think Shared Security brings to mind not only social media, but mobile technology, cloud technology, and as I’m sure you’ve heard by now, The Internet of Things (IoT). So our new podcast, Shared Security, will try to bring you timely stories, news and tips for living securely in a connected world. The name also brings to mind the fact that we will increasingly need to share our thoughts on what the risks are and how to deal with them. You can expect the same level of insight and practical guidance, just on a broader scope. We haven’t yet figured out how we will officially change the program name people see on iTunes or the feed for RSS. So for the moment, the feed and official title will be the same…Social Media Security. However, with this episode we’re going to try to cover a broader range of stories, when appropriate. Stay tuned for additional rebranding changes as we roll them out.
As always, we’d like to hear your thoughts!
Scott and Tom
Recent Facebook and Instagram vulnerabilities
Security for the Internet of Things will get really, really bad before it gets good
Samsung TV’s are listening to you
Trend Micro and Ponemon released a study on personal information, privacy and the connected world.
In this report, they mention that Gartner predicts 25 billion connected devices by 2020 – I think that’s a low estimate- The report breaks down the value of certain types of personal information to attackers, like your health condition (for an American it’s $82.90 per record)
Discussion about The 2015 Verizon Data Breach Incident Report
Commentary on the risks from Internet of Things
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 41 – Podcast Updates, Internet of Things, TV Privacy appeared first on Shared Security Podcast.

Mar 16, 2015 • 34min
Social Media Security Podcast 40 – ThreatExchange, Echosec, Facebook Scams
This is the 40th episode of the Social Media Security Podcast sponsored by the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded February 25, 2015. Below are the show notes, links to articles and news mentioned in the podcast:
Facebook’s new ThreatExchange
Fitbit data used in a court case
Echosec is a web application that lets you search a geographical locale for posts on Twitter, Instagram and Flickr
Some new Facebook security tips and tricks
A very special interview with somebody who experienced a scam attempt on Facebook. Great advice on how to defend against these types of scams!
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 40 – ThreatExchange, Echosec, Facebook Scams appeared first on Shared Security Podcast.

Dec 12, 2014 • 33min
Social Media Security Podcast 39 – Snapcash, Yik Yak, LinkedIn Security and Privacy Tips
This is the 39th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone. This episode was hosted by Tom Eston, Scott Wright recorded December 12, 2014. Below are the show notes, links to articles and news mentioned in the podcast:
“Snapcash” has been announced by the creators of Snapchat. Can Snapchat gain enough consumer confidence to break into the payments field?
Yik Yak is a social app for browsing anonymous chats in your locale and it’s gaining popularity with teens and causing some problems for schools.
Yik Yak is also not as private or anonymous as you think as a new security vulnerability was just disclosed!
How to opt out of Twitter’s new app tracking feature
Facebook’s updated Privacy Policy? Not much new, but policies have been reworded to be somewhat less onerous to read
Facebook At Work – Will it work?
Scott and Tom share our opinions on the big Sony Pictures security breach
Scott shares some best practices on how to secure your LinkedIn account. Tom shares some good tips to make your LinkedIn account more private. Here are a few of the tips we discussed:
1) Turn on HTTPS for all sessions:
– Check the “Secure Connections” box in the security settings page
2) Turn on Two-Step Verification
– The security settings page will tell you whether or not two-step verification is already set up
– You can turn it on, and provide a mobile phone where SMS messages will be sent
Both are accessible by doing the following while logged in to your LinkedIn account on the Web:
a) Hover the mouse cursor over your profile picture
b) Click on the Account tab in the bottom left of the page
c) Click on “Manage Security Settings”
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 39 – Snapcash, Yik Yak, LinkedIn Security and Privacy Tips appeared first on Shared Security Podcast.

Nov 5, 2014 • 31min
Social Media Security Podcast 38 – Corporate Policy, Whisper Privacy Flaws, Snapchat Hack
This is the 38th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone. This episode was hosted by Tom Eston, Scott Wright recorded October 21, 2014. Below are the show notes, links to articles and news mentioned in the podcast:
An enterprise level story about how hard it is to block specific sites, and what can be done about it
Twitter’s former security head condemns Whisper’s privacy flaws
Twitter sues the US Government over national security data
Twitter quickly withholds tweets for Turkey’s ‘national security’
Twitter ‘news’ spreads faster than Ebola
Snapchat third party service hacked
Facebook Fake Likes Exposed
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 38 – Corporate Policy, Whisper Privacy Flaws, Snapchat Hack appeared first on Shared Security Podcast.

Oct 2, 2014 • 59min
Social Media Security Podcast 37 – Special Guest Kevin Johnson (@Secureideas), Managing Your Digital Footprint
This is the 37th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone. This episode was hosted by Tom Eston, Scott Wright and special guest Kevin Johnson recorded September 19th 2014. Below are the show notes, links to articles and news mentioned in the podcast:
Special Topic! Managing Your Digital Footprint (thanks to Chris John Riley for the idea!)
Personal objectives for using social media
Types of footprints you might have (likes, comments, photos, tags, etc.)
Ways you can be exposed, and how to find them (Google search, Facebook search, Linkedin Search, etc.)
Ways to manage exposure going forward
This site has a good, short set of tips to review: http://krishnade.com/digital-footprint/
LinkedIn address book guessing…
http://omnifeed.com/article/www.komonews.com/news/local/LinkedIn-flaw-helps-hackers-discover-email-addresses-275537041.html
The LinkedIn LION – Are You Exposing Yourself to the Hyenas?
https://www.linkedin.com/today/post/article/20140812143638-171396975-the-linkedin-lion-are-you-exposing-yourself-to-the-hyenas
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 37 – Special Guest Kevin Johnson (@Secureideas), Managing Your Digital Footprint appeared first on Shared Security Podcast.

Aug 26, 2014 • 31min
Social Media Security Podcast 36 – Your Cats Metadata, Facebook Messenger, User Risk Awareness
This is the 36th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded August 20th 2014. Below are the show notes, links to articles and news mentioned in the podcast:
HTML5 Canvas Fingerprint — Widely Used Unstoppable Web Tracking Technology
What the Internet Can See From Your Cat Pictures. Everyone also knows where your cat lives…
Discussion about Facebook Messenger Privacy. Is it really that big of a deal?
Misplaced fear about Facebook Messenger for Android
Ars Technica interviews Facebook CSO Joe Sullivan about improving corporate security
Another interview with Joe Sullivan by Washington Post about the post-Snowden effect on Internet companies
Kaspersky study of Facebook user risk awareness
Kaspersky app called Friend or Foe, and their top 5 security mistakes Facebook users make
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 36 – Your Cats Metadata, Facebook Messenger, User Risk Awareness appeared first on Shared Security Podcast.

Jul 24, 2014 • 29min
Social Media Security Podcast 35 – Facebook News Feed Psychology, Complex Passwords, Dumb Criminals
This is the 35th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded July 17th 2014. Below are the show notes, links to articles and news mentioned in the podcast:
Facebook altered 689,000 users’ News Feeds for a psychology experiment
How to Stop Facebook From Using Your Browsing History
Hacking Facebook’s Legacy API, Part 1: Making Calls on Behalf of Any User
How to Teach Humans to Remember Really Complex Passwords
Why I quit Facebook and we are sharing much more than you think
Burglar logs in to Facebook in victim’s house, forgets to sign off (really?)
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 35 – Facebook News Feed Psychology, Complex Passwords, Dumb Criminals appeared first on Shared Security Podcast.

Jul 1, 2014 • 37min
Social Media Security Podcast 34 – Facebook Privacy, LinkedIn Scammers, Naughty Employees
This is the 34th episode of the Social Media Security Podcast sponsored by SecureState and the Streetwise Security Zone. This episode was hosted by Tom Eston and Scott Wright recorded June 18th 2014. Below are the show notes, links to articles and news mentioned in the podcast:
Facebook Switches Default Setting to Private to Prevent Oversharing
Facebook Fights Malware With Free Security Software
Facebook Microphone Update To Store Data: Social Media Giant Confirms New Feature Will Aggregate Information
Facebook responds to this privacy issue
How to “Hack” Someone’s “Private” Friends List on Facebook to See All of Their Friends
6 tips on how to avoid Linkedin Scammers
Some HP Employees Were Busted For This Hilariously Awful Attack Against Competitor, Splunk
Bruce Schneier posted a link to this article about how ISIS in Iraq is using their free mobile app to mass tweet on behalf of individual users, without triggering spam blocks.
Tom talked about SecureState’s free phishing awareness tool called “King Phisher”. This tool can be used to conduct your own phishing awareness campaigns. Check out the webinar and download the tool.
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 34 – Facebook Privacy, LinkedIn Scammers, Naughty Employees appeared first on Shared Security Podcast.

May 22, 2014 • 44min
Social Media Security Podcast 33 – Heartbleed, Hashtag Fail, Social Impersonation
Guess what? We’re back! This is the 33rd episode of the Social Media Security Podcast sponsored by SecureState. This episode was hosted by Tom Eston and Scott Wright recorded May 15, 2014. Below are the show notes, links to articles and news mentioned in the podcast:
Social Media sites affected by Heartbleed
NYPD Twitter hashtag campain FAIL
Facebook Fail pages for brands like ADT alarm service
New Snowden Docs Highlight “Weaknesses” In Facebook Data Security
Snapchat security failure
Facebook class action lawsuit status
Canada’s Privacy Commissioner rules on Facebook remedies in case of harrassment by child imposter
Interesting view on Android permissions requested by FB apps (and proposed solution)
People snubbed on Facebook feel less “meaningful existence,” study finds
Tom’s presentation on Enterprise Open Source Intelligence Gathering (OSINT)
Please send any show feedback to feedback [aT] socialmediasecurity.com or comment below. You can also call our voice mail box at 1-613-693-0997 if you have a question for our Q&A section on the next episode. Don’t forget to subscribe to the podcast in iTunes, follow us on Twitter and like us on Facebook. Thanks for listening!
The post Social Media Security Podcast 33 – Heartbleed, Hashtag Fail, Social Impersonation appeared first on Shared Security Podcast.


