Byte Sized Security

Marc David

In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go. Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more. Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out. Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.

  1. JUL 5

    Three Privacy Actions You Need Today

    # Byte Sized Security Show Notes ## Episode Title: 3 Immediate Actions to Protect Your Privacy Today ## Episode Summary: In this episode of Byte Sized Security, host Marc David outlines three practical, actionable steps to enhance your privacy protection immediately. With data breaches nearly doubling in 2024 and companies like AT&T and Ticketmaster experiencing massive exposures, these privacy protection measures aren't just theoretical—they're essential defenses against real threats. ## Key Discussion Points: * The alarming state of data breaches in 2024: 10,626 confirmed breaches, nearly double from previous year * Major breaches highlighted: AT&T (73M records), Ticketmaster (560M users), National Public Data (2.9B records) * The average breach costs $4.88 million, or $165 per stolen record * **Step 1**: Enable two-factor authentication everywhere * 2FA stops 99.9% of automated attacks * Use authentication apps instead of SMS * Save backup codes in a safe place * **Step 2**: Audit your privacy settings * Detailed walkthrough for Facebook, Instagram, Twitter/X, and LinkedIn * Phone settings review for both iOS and Android * Revoking unnecessary app permissions * **Step 3**: Protect your connection and digital footprint * Using a VPN to encrypt connections and mask browsing * Reviewing and cleaning your digital footprint * Opting out of data broker sites * Deleting old, unused accounts * The importance of ongoing privacy maintenance ## Tools and Resources Mentioned: * **Authentication Apps:** * [Google Authenticator](https://googleauthenticator.net/) * [Authy](https://authy.com/) * **Recommended VPN Services:** * [NordVPN](https://nordvpn.com/) * [ExpressVPN](https://www.expressvpn.com/) * [Surfshark](https://surfshark.com/) * **Data Broker Removal Services:** * [DeleteMe](https://joindeleteme.com/) * [Privacy Bee](https://privacybee.com/) * [Optery](https://optery.com/) * **Data Broker Sites to Opt Out From:** * [Whitepages](https://www.whitepages.com/) * [PeopleFinder](https://www.peoplefinder.com/) * [Spokeo](https://www.spokeo.com/)

    7 min
  2. JUL 3

    Ep:41 Beware: Your Top VPN App May Be a Chinese Government Spy

    Episode Summary: In this episode, we explore the alarming discovery that many of the top-rated VPN apps on the App Store and Google Play are secretly owned by Chinese companies. These VPNs pose a serious risk to user privacy and security, as Chinese law requires them to hand over all user data to the government without justification. Key Topics Covered: - Chinese-owned VPN apps masquerading as legitimate services - Lack of transparency and disclosure around company ownership - Risks of user data being accessed by the Chinese government - Failure of app stores to properly vet and regulate these VPN apps - Importance of researching VPN providers before using them Main Takeaways: - Many popular VPN apps are secretly owned by Chinese companies, creating a significant risk to user privacy and security. - App stores like the App Store and Google Play are not properly vetting and regulating these potentially compromised VPN apps. - Users must do their own research to ensure the VPN they are using is trustworthy and not owned by a company with ties to the Chinese government. Timestamps for Major Topics: - 0:00 - Introduction to the issue of Chinese-owned VPN apps - 1:30 - Examples of top-ranked VPN apps with hidden Chinese ownership - 3:00 - Explanation of the legal requirements for Chinese companies to hand over user data - 4:30 - Lack of action by app stores to remove or label these problematic VPN apps - 6:00 - Importance of user research and caution when selecting a VPN provider --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    3 min
  3. MAY 30

    Ep40: The AI Layoff Apocalypse Has Already Started — And You’re Next

    The Imminent AI Job Crisis: Are You Prepared? This episode highlights the alarming prediction by Dario Amodei, CEO of Anthropic, that AI could eliminate half of all entry-level white-collar jobs within the next one to five years, potentially raising U.S. unemployment to 20%. While major companies are quietly adopting advanced AI systems, the public and lawmakers remain largely unaware or in disbelief. The episode discusses the impacts of AI on various industries and jobs, stressing the need for urgent action such as an AI 'token tax,' real-time job replacement tracking, legislative briefings, and worker reskilling programs. The message is clear: the AI job crash is imminent, and proactive measures are essential to mitigate its effects. 00:00 The Impending Disappearance of White-Collar Jobs 00:37 Real-World Examples of AI-Induced Job Cuts 01:03 The Rise of AI Agents in the Workplace 01:30 The Alarming Capabilities of Advanced AI 01:48 Public Response and the Threat to Democracy 02:32 Proposed Solutions to the AI Job Crisis 02:57 The Urgency of Immediate Action 03:06 Conclusion: Preparing for the AI Job Crash --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode Behind the Curtain: A white-collar bloodbath -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    5 min
  4. MAY 27

    Ep39: AI in the Workplace: Adapt or Be Replaced

    Adapt or Replace: How AI is Changing Entry-Level Job Markets AI has already impacted the job market significantly, particularly affecting entry-level positions. The script highlights that entry-level hiring has decreased due to the integration of AI, which automates routine tasks. Companies are reconsidering traditional roles and opting for more efficient AI solutions. Job seekers are faced with two choices: compete against AI or learn to leverage it to improve productivity. The script emphasizes the importance of mastering AI tools to stay relevant in the workforce and outlines steps to integrate AI proficiency into daily routines and resumes. 00:00 AI Isn't Coming for Your Job 00:02 The Impact of AI on Entry-Level Jobs 00:18 Automation and Workflow Changes 00:39 Adapting to the AI Revolution 00:46 The Future of Work: Competing with AI 01:07 Embracing AI Tools for Success 01:15 The Consequences of Ignoring AI 01:31 Final Thoughts: Adapt or Be Replaced --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    3 min
  5. MAY 21

    Spot Phishing Emails: Stay Safe

    # Episode: "Avoiding the Phishing Bait: How to Spot Scam Emails" ## Episode Summary In this episode of Byte Sized Security, host Marc David breaks down how to identify phishing emails. He provides practical tips to recognize scam attempts and protect your personal information from fraudulent emails. ## Key Discussion Points - Introduction to phishing scams and why they're dangerous - Identifying typos and grammar mistakes in suspicious emails - How to verify the sender's email address and domain - The importance of inspecting links before clicking - Why urgency and alarming messages are red flags - How to properly report suspicious emails - The value of regular security software updates ## Resources Mentioned - Email security features (spam/phishing reporting tools) - Security software (mentioned to keep updated) - [Amazon.com](https://www.amazon.com) (referenced as an example of legitimate domain) ## Takeaway Always verify email details carefully before taking action, never rush to respond to urgent requests, and maintain vigilance to protect your personal information. --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    3 min
  6. MAY 19

    Deepfakes and Digital Deception: The 2025 Threat

    **Episode Summary:** Marc David dives into the rapidly evolving world of deepfakes and digital deception, projecting forward to 2025. The episode explores the alarming growth in deepfake use, driven by accessible AI technology and user-friendly tools. Mark discusses the severe consequences for businesses (e.g., fraudulent CEO announcements, financial scams like the Polish bank incident), politics (e.g., election manipulation), and personal lives. The discussion also covers emerging solutions, including AI-powered detection tools like those from MIT's DeepTrace Lab, the role of regulations like GDPR, and practical steps listeners can take, such as using verification software like Truepic. The core message is the importance of vigilance and questioning the authenticity of digital content. **Key Discussion Points:** * **The Explosion of Deepfake Use (00:21):** * A 900% increase in deepfake videos was found by Sensity researchers in 2021. * The problem is projected to have quadrupled by 2025. * **Drivers of the Deepfake Surge (00:35):** * Accessible and user-friendly AI technology. * Cheaper software accelerating spread. * **Impact on Businesses (00:48):** * Potential for CEO deepfakes to announce fraudulent mergers or layoffs. * Real-world example: A Polish bank lost millions in 2023 due to a deepfake scam involving an urgent fake call to redirect funds. * **Impact on Politics (01:10):** * Deepfakes manipulating elections (e.g., doctored videos of candidates). * Erosion of voter trust. * **Current Preparedness & Solutions (01:21):** * We are not yet fully equipped, but solutions are evolving. * **Detection Tools (01:25):** AI systems learning to recognize deepfakes by detecting minute digital artifacts. * MIT's DeepTrace Lab: Provides tools analyzing AI generation flaws. * **Policy and Regulations (01:42):** * Europe's GDPR now covers AI-generated media. * The US is considering similar steps. * **What You Can Do (01:52):** * Stay informed. * Report suspicious content. * Support legislative actions against deepfakes. * Use available verification tools. * **Today's Takeaway (02:04):** * Be vigilant. * Question authenticity until trust is verifiable. **Tools & Sites Mentioned:** * **Sensity:** (Research mentioned from 2021 regarding the 900% increase in deepfake videos). Sensity was an AI threat intelligence company, later acquired. The research highlighted the scale of the problem. * **MIT DeepTrace Lab:** A research initiative at MIT focusing on detecting deepfakes and manipulated media. * Website: [https://deeptrace.csail.mit.edu/](https://deeptrace.csail.mit.edu/) * **GDPR (General Data Protection Regulation):** Europe's privacy and data protection law, now addressing AI-generated media. * Official Information: [https://gdpr-info.eu/](https://gdpr-info.eu/) * **Truepic:** A company offering photo and video verification technology. * Website: [https://truepic.com/](https://truepic.com/) ------ I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a...

    4 min
  7. FEB 3

    Ep36: DeepSeek AI – The Real Issue Isn't China, It’s AI Security

    AI Security and Competition: Unpacking the Debate Around DeepSeek This episode delves into the controversy surrounding DeepSeek, a Chinese AI considered by some as a national security threat. It questions whether this stance is legitimate or merely a tactic by big tech to stifle competition. The episode highlights multiple security breaches across the AI industry, including OpenAI and Google, arguing that the core issue lies in how AI handles security rather than its origin. The discussion also explores the suspicious uniformity in the anti-DeepSeek narrative, the potential motivations of big AI corporations to maintain monopolies, and the necessity of reading AI privacy policies. Additionally, the episode critiques the U.S. response to AI competition, drawing parallels to historical moments like the Sputnik era, and advocates for stronger AI security regulations and more open-source innovation. Listeners are encouraged to reflect on whether the fear of DeepSeek is justified or manipulated by big tech interests. 00:00 Introduction: The DeepSeek Controversy 00:08 Data Leaks: A Global Issue 00:39 The Suspicious Narrative Against DeepSeek 01:24 Big AI's Fear of Open Source 01:35 Smart AI Usage Tips 02:29 The Real Issue: AI Governance 03:15 The AI Moat Playbook 04:08 Big Tech's Control Over AI 05:49 The Global AI Competition 09:45 Security and Privacy Concerns 17:22 Conclusion: The Future of AI --- I do hope you enjoyed this episode of the podcast. Here's some helpful resources including any sites that were mentioned in this episode. -- Sites Mentioned in this Episode DeepSeek Privacy Policy - The DeekSeek Privacy Policy -- Find subscriber links on my site, add to your podcast player, or listen on the web players on my site: Listen to Byte Sized Security -- Support this Podcast with a Tip: Support Byte Sized Security -- If you have questions for the show, feedback or topics you want covered. Please send a short email to marc@bytesizedsecurity.show with the Subject line of "Byte-Sized Security" so I know it's about the podcast. Connect with me on TikTok: https://www.tiktok.com/@bytesizedsecurity

    21 min

About

In a world where cyberattacks are becoming more commonplace, we all need to be vigilant about protecting our digital lives, whether at home or at work. Byte Sized Security is the podcast that provides snackable advice on cybersecurity best practices tailored for professionals on the go. Hosted by information security expert, Marc David, each 15-20 minute episode provides actionable guidance to help listeners safeguard their devices, data, and organizations against online threats. With new episodes released every Monday, Byte Sized Security covers topics like social engineering, password management, multi-factor authentication, security awareness training, regulatory compliance, incident response, and more. Whether you're an IT professional, small business owner, developer, or just someone interested in learning more about cybersecurity, Byte Sized Security is the quick, easy way to pick up useful tips and insights you can immediately put into practice. The clear, jargon-free advice is perfect for listening on your commute, during a lunch break, or working out. Visit bytesizedsecurity.com to access episodes and show notes with key takeaways and links to useful resources mentioned in each episode. Don't let cybercriminals catch you off guard - get smart, fast with Byte Sized Security! Tune in to boost your cybersecurity knowledge and help secure your part of cyberspace.