375 episodes

Every week, this podcast brings you the cybersecurity and privacy news you need, in a manner that's easy for anyone to understand and even entertaining! The host also interviews top industry leaders, to dig deeper into important topics and recent events. It all that weren't enough, the host also passes along top tips for defending your digital realm.

Firewalls Don't Stop Dragons Podcast Carey Parker

    • Technology
    • 4.9 • 48 Ratings

Every week, this podcast brings you the cybersecurity and privacy news you need, in a manner that's easy for anyone to understand and even entertaining! The host also interviews top industry leaders, to dig deeper into important topics and recent events. It all that weren't enough, the host also passes along top tips for defending your digital realm.

    Please Quit Chrome

    Please Quit Chrome

    Google's Chrome browser has dominated the planet - both on desktop computers and mobile devices. Furthermore, many other popular web browsers are actually based on the same Google-made Chromium browser engine, including Microsoft Edge and Brave Browser. This gives Google an inordinate amount of influence on web standards, in particular preventing better privacy protections. We need to support privacy-forward alternatives lest they disappear.







    In other news: US passes expanded mass surveillance policies instead of curbing them; TikTok ban bill becomes law giving Bytedance a year to sell it; UK's Investigatory Powers Bill amendment passes; photo-sharing app will use users' uploaded images to train AI; Health insurers Kaiser and Change Healthcare are hacked; antivirus software service installs malware on user's systems; FCC fines telecom's $200M; CISA director pushes for vendor accountability; CISA's proactive protection programs are making positive impacts; UK becomes first country to enforce strong and strict IoT security requirements; net neutrality is back; Google again delays killing third party cookies.







    Article Links









    [Electronic Frontier Foundation] U.S. Senate and Biden Administration Shamefully Renew and Expand FISA Section 702, Ushering in a Two Year Expansion of Unconstitutional Mass Surveillance https://www.eff.org/deeplinks/2024/04/us-senate-and-biden-administration-shamefully-renew-and-expand-fisa-section-702-0







    [TechCrunch] Biden signs bill that would ban TikTok if ByteDance fails to sell the app https://techcrunch.com/2024/04/24/biden-signs-bill-that-would-ban-tiktok-if-bytedance-fails-to-sell-the-app/







    [theregister.com] UK's Investigatory Powers Bill to become law despite tech world opposition https://www.theregister.com/2024/04/26/investigatory_powers_bill/







    [TechCrunch] Photo-sharing community EyeEm will license users photos to train AI if they don’t delete them https://techcrunch.com/2024/04/26/photo-sharing-community-eyeem-will-license-users-photos-to-train-ai-if-they-dont-delete-them/







    [TechCrunch] Health insurance giant Kaiser notifies millions of a data breach https://techcrunch.com/2024/04/25/kaiser-permanente-health-plan-millions-data-breach/







    [TechCrunch] Change Healthcare hackers broke in using stolen credentials — and no MFA, says UHG CEO https://techcrunch.com/2024/04/30/uhg-change-healthcare-ransomware-compromised-credentials-mfa/







    [Ars Technica] Hackers infect users of antivirus service that delivered updates over HTTP https://arstechnica.com/security/2024/04/hackers-infect-users-of-antivirus-service-that-delivered-updates-over-http/







    [BleepingComputer] FCC fines carriers $200 million for illegally sharing user location https://www.bleepingcomputer.com/news/technology/fcc-fines-carriers-200-million-for-illegally-sharing-user-location/







    [cybersecuritydive.com] CISA director pushes for vendor accountability and less emphasis on victims’ errors https://www.cybersecuritydive.com/news/cisa-highlights-vendors-errors/714300/







    [therecord.media] More than 800 vulnerabilities resolved through CISA ransomware notification pilot https://therecord.media/vulnerabilities-resolved-through-cisa-pilot







    [therecord.media] UK becomes first country to ban default bad passwords on IoT devices https://therecord.media/united-kingdom-bans-defalt-passwords-iot-devices







    [WIRED] Net Neutrality Returns to a Very Different Internet https://www.wired.com/story/fcc-net-neutrality-rules-vote/







    [Ars Technica] Google delays third-party cookie death again: Now scheduled for 2025 https://arstechnica.

    • 1 hr 12 min
    The Rise of CBDC

    The Rise of CBDC

    AI has been grabbing all the tech headlines, but cryptocurrency is still innovating and changing. One of the primary goals of cryptocurrency was to be decentralized and therefore not controlled by governments like fiat currency. That is about to change. Central Bank Digital Currency (CBDC) is a new type of cryptocurrency that is created and governed by nation states, which comes with serious implications for privacy and global economics. Thankfully I've got cryptocurrency expert Seth for Privacy on the show to explain how CBDC works and how it will affect us.







    Interview Notes









    Opt Out Podcast: https://optoutpod.com/ 







    Freedom.Tech: https://freedom.tech/ 







    Foundation.xyz: https://foundation.xyz/ 







    CBDC tracker: https://cbdctracker.hrf.org/home 







    Buying Monero: https://freedom.tech/buying-monero-privately/







    Samourai Wallet 1: https://freedom.tech/how-samourai-worked/ 







    Samourai Wallet 2: https://freedom.tech/samourai-to-sparrow/







    Cryptocurrency 101 interview: https://podcast.firewallsdontstopdragons.com/2022/06/06/cryptocurrency-101/ 









    Further Info









    Treasure & Coin Promo: https://fdsd.me/promo424 







    Send me your questions! https://fdsd.me/qna 







    Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book 







    Subscribe to the newsletter: https://fdsd.me/newsletter 







    Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 







    Give the gift of privacy and security: https://fdsd.me/coupons 







    Support our mission! https://fdsd.me/support 







    Generate secure passphrases! https://d20key.com/#/ 









    Table of Contents







    Use these timestamps to jump to a particular section of the show.









    0:00:30: Promo update







    0:01:42: News preview







    0:04:34: AT&T now says over 50M accounts were compromised







    0:11:37: Apple password reset notification attack







    0:16:04: Outlook is Microsoft’s new data collection service







    0:22:40: Kobold letters







    0:29:27: Backdoor in XZ Utils That Almost Happene







    0:39:42: OpenAI and Google reportedly used transcriptions of YouTube videos to train their AI models







    0:45:57: How to Turn Off Meta AI on their various apps







    0:49:07: Vulnerabilities Identified in LG WebOS







    0:52:14: Roku Says More Than 500,000 Accounts Were Compromised







    0:56:05: X May Charge New Users a 'Small Fee' to Post, Like and Reply







    1:00:04: DuckDuckGo Is Taking Its Privacy Fight to Data Brokers







    1:04:19: Google Launches Android Find My Device Network







    1:07:29: The CFPB wants to rein in data brokers







    1:12:23: Tip of the Week: Freeze Your Credit







    1:18:05: Wrap-up







    1:19:06: Looking ahead

    • 1 hr 8 min
    Just Do It: Freeze Your Credit

    Just Do It: Freeze Your Credit

    You've heard people like me recommend this for years. It's time to just do it: freeze your credit report. There are really no downsides at this point. For example, it's now free everywhere in the US, by law. It's also free to temporarily "thaw" your credit. And it's gotten a lot easier to do, too. Freezing your credit is your main defense against financial identity theft. And with the sheer number of data breaches (like the recent massive AT&T leak), the personal information needed to commit identity theft is out there already.







    In other news: AT&T now says 51 million past and current customers' data were leaked; beware of a new password reset 'bomb' campaign; Microsoft is using Outlook to harvest and share your data; a new email scam alters their content after forwarding; a devious and devastating supply chain attack was thwarted in the nick of time; AI organizations are using sneaky techniques to train their models on your data; Meta is lacing its apps with AI, and there's not much you can do about it; LG TVs are hacked; Roku is breached again, this time affecting over 500,000 accounts; Twitter/X looking to charge new users a small fee to try to curb bot accounts; DuckDuckGo unveils trio of new for-pay privacy services; Google launches their own Find My network; and various US government agencies, lacking a real privacy law, attempt to curb privacy abuses using existing powers.







    Article Links









    [BleepingComputer] AT&T now says data breach impacted 51 million customers https://www.bleepingcomputer.com/news/security/att-now-says-data-breach-impacted-51-million-customers/







    [AppleInsider] If you're getting dozens of password reset notifications, you're being attacked https://appleinsider.com/articles/24/03/27/if-youre-getting-dozens-of-password-reset-notifications-youre-being-attacked







    [proton.me] Outlook is Microsoft’s new data collection service https://proton.me/blog/outlook-is-microsofts-new-data-collection-service







    [Lutra Security] Kobold letters https://lutrasecurity.com/en/articles/kobold-letters/







    [Schneier Blog] Backdoor in XZ Utils That Almost Happened https://www.schneier.com/blog/archives/2024/04/backdoor-in-xz-utils-that-almost-happened.html







    [Engadget] OpenAI and Google reportedly used transcriptions of YouTube videos to train their AI models https://www.engadget.com/openai-and-google-reportedly-used-transcriptions-of-youtube-videos-to-train-their-ai-models-163531073.html







    [Lifehacker] How to Turn Off Meta AI on Facebook, Instagram, Messenger, and WhatsApp https://lifehacker.com/tech/how-to-turn-off-meta-ai-on-facebook-instagram-messenger-whatsapp







    [bitdefender.com] Vulnerabilities Identified in LG WebOS https://www.bitdefender.com/blog/labs/vulnerabilities-identified-in-lg-webos/







    [Lifehacker] Roku Says More Than 500,000 Accounts Were Compromised in a Cyberattack https://lifehacker.com/tech/roku-cyberattack-compromises-accounts







    [MacRumors] X May Charge New Users a 'Small Fee' to Post, Like and Reply https://www.macrumors.com/2024/04/15/x-small-fee-new-users/







    [WIRED] DuckDuckGo Is Taking Its Privacy Fight to Data Brokers https://www.wired.com/story/duckduckgo-vpn-data-removal-tool-privacy-pro/







    [MacRumors] Google Launches Android Find My Device Network https://www.macrumors.com/2024/04/08/google-android-find-my-device-network-2/







    [ftc.gov] Proposed FTC Order will Prohibit Telehealth Firm from Using or Disclosing Sensitive Data for Advertising Purposes https://www.ftc.gov/news-events/news/press-releases/2024/04/proposed-ftc-order-will-prohibit-telehealth-firm-cerebral-using-or-disclosing-sensitive-data

    • 1 hr 20 min
    Protecting Kids Online

    Protecting Kids Online

    There's a lot of nasty stuff online - things we would prefer our kids not see, at least not until they're mature enough to handle it. Our elected representatives have proposed various regulations to try to protect kids online, and while this is obviously a laudable goal, the devil is always in the details. Many of the proposed solutions have serious negative consequences for both kids and adults, chilling free speech and blocking useful content. I'll discuss the latest iteration of these proposed solutions in the US called the Kids Online Safety Act (KOSA) as well as the similar Online Safety Act in the UK. With me is Joe Mullin, senior policy analyst at the Electronic Frontier Foundation (EFF).







    Interview Notes









    Joe Mullin (EFF): https://www.eff.org/about/staff/joe-mullin 







    EFF on KOSA: https://www.eff.org/deeplinks/2024/02/dont-fall-latest-changes-dangerous-kids-online-safety-act 







    EFF on KOSA in depth: https://www.eff.org/deeplinks/2024/03/analyzing-kosas-constitutional-problems-depth 







    Contact Congress: https://www.eff.org/congress 







    EFF on CA ballot initiative: https://www.eff.org/deeplinks/2024/02/eff-opposes-california-initiative-would-cause-mass-censorship 







    EFF submission to Ofcom: https://www.eff.org/deeplinks/2024/03/effs-submission-ofcoms-consultation-illegal-harms 







    Santa Clara Principles for online content moderation: https://santaclaraprinciples.org/ 









    Further Info









    Treasure & Coin Promo: https://fdsd.me/promo424 







    Send me your questions! https://fdsd.me/qna 







    Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book 







    Subscribe to the newsletter: https://fdsd.me/newsletter 







    Become a patron! https://www.patreon.com/FirewallsDontStopDragons 







    Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 







    Give the gift of privacy and security: https://fdsd.me/coupons 







    Support our mission! https://fdsd.me/support 







    Generate secure passphrases! https://d20key.com/#/









    Table of Contents







    Use these timestamps to jump to a particular section of the show.









    0:00:56: Eclipse!







    0:01:50: Treasure & Coin promo update







    0:02:29: Interview preview







    0:03:41: What are the primary concerns today with kids on the internet?







    0:08:24: What laws already exist to protect kids online?







    0:17:05: What are the key provisions of KOSA?







    0:25:04: What content is KOSA trying to restrict based on age?







    0:34:22: What did we learn from the UK's Online Safety Act?







    0:38:47: Doesn't KOSA interfere with Section 230?







    0:44:41: How does KOSA impact content access for adults?







    0:50:17: Are our representatives seeking insights from groups like EFF?







    0:54:58: Are there onlione safety regulations EFF could support?







    0:58:55: Do you have any advice for parents on protecting their kids online?







    1:06:55: Interview wrap-up







    1:08:59: Patron bonus content







    1:09:28: Looking ahead

    • 1 hr 10 min
    Answering Listener Questions

    Answering Listener Questions

    Today I answer some of the most interesting listener questions from the past several months, including: how to do you get SMS 2FA codes while traveling abroad; should I periodically change all my passwords; how do hackers attack IoT devices inside my home network; can a website fingerprint me based on a hardware security key; can you recommend an email client that protects your privacy; if I give my IoT device permission to see my local network, does that include the guest network; how to hackers find vulnerabilities and figure out how to attack them; why can't I use my VPN on an airplane to stream Netflix; how can I protect my cryptocurrency and smartphone. Also, I give my take on the crazy TikTok ban legislation.







    Links









    New Year’s Resolutions for 2024: https://firewallsdontstopdragons.com/new-years-resolutions-for-2024/ 







    GRC’s Shields Up! Tool: https://www.grc.com/shieldsup 







    Secure your home network: https://firewallsdontstopdragons.com/secure-your-network-part-1-scan/ 







    My Take on TikTok Ban: https://firewallsdontstopdragons.com/my-take-on-tiktok-ban/







    The TikTok Situation is a Mess: https://lifehacker.com/tech/the-tiktok-situation-is-a-mess 







    EFF on TikTok: https://www.eff.org/deeplinks/2024/03/5-big-unanswered-questions-about-tiktok-bill  







    The US Wants to Ban TikTok: https://www.404media.co/the-u-s-wants-to-ban-tiktok-for-the-sins-of-every-social-media-company/









    Further Info









    Send me your questions! https://fdsd.me/qna 







    Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book 







    Subscribe to the newsletter: https://fdsd.me/newsletter 







    Become a patron! https://www.patreon.com/FirewallsDontStopDragons 







    Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 







    Give the gift of privacy and security: https://fdsd.me/coupons 







    Support our mission! https://fdsd.me/support 







    Generate secure passphrases! https://d20key.com/#/ 









    Table of Contents







    Use these timestamps to jump to a particular section of the show.









    0:00:38: Couple quick updates







    0:02:37: Getting SMS 2FA codes while traveling abroad







    0:07:37: Should I periodically change all my passwords?







    0:13:23: How do hackers attack IoT devices inside my home network?







    0:19:10: Can a website fingerprint me based on a hardware security key?







    0:24:42: Can you recommend an email client that protects your privacy?







    0:29:30: If I give my IoT device permission to see my local network, does that include the guest network?







    0:33:18: How to hackers find vulnerabilities and figure out how to attack them?







    0:37:35: Why can't I use my VPN on an airplane to stream Netflix?







    0:43:57: How can I protect my cryptocurrency and smartphone?







    0:50:05: AT&T breach update







    0:50:56: My Take on TikTok







    0:57:28: Wrap-up

    • 58 min
    He Said She Said

    He Said She Said

    Today I talk with Justin and Jodi Daniels about that state of privacy today, how we can help consumers and companies better understand the importance of privacy and security, and how companies are dealing with these aspects internally. We talk about the state of privacy regulations (or the lack thereof), why companies are failing to protect their customers, and what we can do about that.







    Justin and Jodi host a podcast together called She Said Privacy, He Said Security. They've also co-written a book called "Data Reimagined: Building trust one byte at a time".







    Interview Notes









    Justin & Jodi Daniels’ podcast: https://redcloveradvisors.com/podcasts/







    Justin Daniels: https://www.linkedin.com/in/justinsdaniels/







    Jodi Daniels: https://www.linkedin.com/in/jodihoffmandaniels/ 







    Red Clover Advisors: https://redcloveradvisors.com/







    Baker Donelson: https://www.bakerdonelson.com/ 







    Data Reimagined book: https://redcloveradvisors.com/book-sales/ 







    International Association of Privacy Professionals (IAPP): https://iapp.org/ 







    Information Commissioner’s Office (ICO): https://ico.org.uk/ 







    YourAdChoices (AboutAds.info): https://youradchoices.com/ 







    How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ 







    Jeff Jockisch top 10: https://www.linkedin.com/posts/jozian_privacypodcast-peopleschoice-privacyawards-activity-7155591864593637376-Q3bi/ 









    Further Info









    Coin & Treasure Promo: https://fdsd.me/promo424







    Send me your questions: https://fdsd.me/qna 







    Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book 







    Subscribe to the newsletter: https://fdsd.me/newsletter 







    Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 







    Give the gift of privacy and security: https://fdsd.me/coupons 







    Support our mission! https://fdsd.me/support 







    Generate secure passphrases! https://d20key.com/#/ 









    Table of Contents







    Use these timestamps to jump to a particular section of the show.









    0:01:33: Interview setup







    0:03:31: Tell me about your podcast and how you got into this space.







    0:06:40: How do you explain privacy to regular, everyday people?







    0:09:37: How can we help people better understand the need for privacy?







    0:11:10: What are the newest threats to our privacy?







    0:14:58: So how do we know what to trust?







    0:17:07: What mistakes do companies make when crafting and implementing privacy policies?







    0:21:37: How should companies embrace privacy?







    0:25:51: What's life like for a Chief Privacy Officer today?







    0:30:22: Can we blame companies for monetizing our data since it's legal to do so?







    0:34:01: How do we combat privacy problems with security tech?







    0:37:11: Why can't the US government pass a federal privacy law?







    0:42:54: Would it help to pass laws that mandate transparency?







    0:46:11: What about a universal opt-out mechanism?







    0:47:24: Is mainstream media covering privacy and security properly?

    • 1 hr

Customer Reviews

4.9 out of 5
48 Ratings

48 Ratings

Lisbon P ,

Knowledgeable and so very helpful

I listen to Carey every night , so much insight to all this security ,this elderly person couldn’t believe it. I have your latest book and absolutely love it and pass lots of info to my friends .your book is a must read for everyone and your podcast is must hear.Thank you Carey

Signed Lisbon

Marc601 ,

My favorite

My favorite cyber security, privacy podcast. Mr. Parker is very knowledgeable, clean, and leaves politics out of the discussion. He explains things in easy to understand ways. His book is wonderful too. Thanks Mr. Parker, you’re the best.

Rerye1 ,

My new go-to privacy and security spot

Stumbled on FDSG from Lock and Code podcast. So helpful to listen to well-researched info while doing house chores! Join me in donating, as this podcast is produced at cost. At highest risk are Seniors— learn more at AARP. I know too many completely unaware— or admittedly lazy — or both, about protecting themselves. I know a senior who handed all her passwords over to a scammer. I warned her before she went ahead, but she would not believe me. Still does not, with scammers laughing all the way to the bank.

Top Podcasts In Technology

No Priors: Artificial Intelligence | Technology | Startups
Conviction | Pod People
All-In with Chamath, Jason, Sacks & Friedberg
All-In Podcast, LLC
Lex Fridman Podcast
Lex Fridman
Acquired
Ben Gilbert and David Rosenthal
Hard Fork
The New York Times
TED Radio Hour
NPR

You Might Also Like

Surveillance Report
Techlore & The New Oil
Darknet Diaries
Jack Rhysider
The 404 Media Podcast
404 Media
Click Here
Recorded Future News
Hacking Humans
N2K Networks
CyberWire Daily
N2K Networks