The Lockdown - Practical Privacy & Security

Ray Heffer

Welcome to The Lockdown. Privacy doesn’t have to be all-or-nothing. The inability to attain extreme levels of privacy shouldn’t deter one from taking any protective measures at all. The show is hosted by Ray Heffer, an expert in the field of privacy and cybersecurity, with each episode touching on a range of topics such as data privacy, password management, and secure browsing habits. Tin-foil hats are optional!

  1. 5d ago

    S02E02 - You Are The Proxy - Hackers, Experts, and Bad Advice

    In this episode, we continue with a closer look at what cybersecurity competence actually means, and why qualifications, compliance frameworks, and public reputation are poor substitutes for understanding how real attacks work. We explore the cryptography behind Proton Mail, public and private keys, fingerprints, and what you can do with PGP word lists. We’ll also discuss passkeys, account recovery, SIM swaps, ClickFix malware, infostealers, VPN blocking, and the residential proxies that allow malicious traffic to hide behind ordinary household IP addresses. In this week’s episode: Hackers, threat actors, security influencers, and the risks created by confident but inaccurate adviceKerckhoffs’s principle: designing security under the assumption that the enemy knows the systemHow public and private keys work, including Proton Mail encryption, digital signatures, fingerprints, and independent key verificationUsing the PsySecure Workbench and PGP word lists to make cryptographic fingerprints easier to exchange and verifyThe problem with passkeys, and why weak account recovery can undermine their securityClickFix attacks that imitate Cloudflare verification pages and trick users into running malicious terminal commandsHow infostealers target browser data, authenticated sessions, cookies, passwords, and other valuable informationWhy VPN traffic is increasingly blocked or challenged while attackers move toward residential proxies that resemble legitimate usersYou are the proxy: How cheap smart home devices, streaming boxes, thermostats, and cameras, can become hidden residential proxiesThe normalization of identity verification, digital ID checks, and other invasive systemsShow Links: The Hidden Backdoors Inside Millions of Smart Devices (WSJ): https://www.youtube.com/watch?v=apEPPKYgLL0keys.openpgp.org: keys.openpgp.orgPsySecure Workbench: https://psysecure.com/workbenchAn Investigative Framework for Auditing the Security & Privacy of Mobile VPNs: https://www.ndss-symposium.org/wp-content/uploads/2026-s1573-paper.pdfMatrix Community Rooms: Matrix Community Space: https://matrix.to/#/#psysecure:matrix.orgIndividual Room Links: https://matrix.to/#/#lockdown-intro:matrix.orghttps://matrix.to/#/#lockdown-podcast:matrix.orghttps://matrix.to/#/#lockdown-general:matrix.orgHow to check public key fingerprint from the command line: gpg --show-keys --with-fingerprint public_key_file.asc★ Support the show on Patreon ★ ★ Support this podcast on Patreon ★

  2. Jul 10

    S02E01 - Think Like A CISO

    Season 2 of The Lockdown is here, with a renewed focus on the overlap between privacy, security, and open-source intelligence. In this episode, Ray explains why reconnaissance should be treated as the first line of defense, not as the attacker’s free move. This episode lays out a practical way to think like a CISO in both your personal life and inside an organization. The core idea is simple: Minimize What Can Be Known, understand what you are protecting, and close the gap between having security controls and actually being protected by them. Why privacy and security should be treated as two sides of the same coinReconnaissance, OSINT, and how attackers build a picture from public informationThinking like a CISO: threat modeling, risk, residual risk, and compensating controlsPractical privacy choices, including GrapheneOS, browsers, VPNs, prepaid SIMs, and data brokersThe control confidence gap, including SIM swaps, help desk attacks, security questions, and deepfakesReal-world examples of reconnaissance-driven attacks, including MGM, Caesars, Marks & Spencer, and ransomware extortionThe updated OSINT Defense and Security Framework, plus practical homework for individuals and organizationsShow Links OSINT Defense & Security Framework PDFWeekday executive security briefing emailMatrix Community Rooms: • Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: • https://matrix.to/#/#lockdown-intro:matrix.org • https://matrix.to/#/#lockdown-podcast:matrix.org • https://matrix.to/#/#lockdown-general:matrix.org Support the show on Patreon ★ https://www.patreon.com/TheLockdown ★ Support this podcast on Patreon ★

  3. 10/03/2025

    034 - Final Episode

    In this final episode of The Lockdown, I reflect on the journey of the podcast, and explaining why I’m redirecting my energy to other projects. I discuss the importance of practical privacy measures, measures over an ‘all-or-nothing’ approach, as well as sharing my thoughts on threat modeling, and address several listener questions about privacy tools and self-hosting. I also introduce a new concept from my recent blog post about the “space between” in cybersecurity, examining how compartmentalization of identities can serve as an early warning system against social engineering attacks. In this week’s episode: Why this is the final episodeThe all-or-nothing fallacyAirport facial recognition and the Clearview AI threatThreat modeling for different life situationsThe CIA triad and why 100% security doesn’t existUK and Swiss digital ID systems and their privacy implicationsNPM breach case study and the psychology of social engineeringWhy organizations should compartmentalize communication channelsListener Q&A: MySudo virtual cards, self-hosting setup, and mobile hotspotsThe new Privacy Tools page on PsySecure.comMatrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.orgIndividual Room Links: https://matrix.to/#/#lockdown-intro:matrix.orghttps://matrix.to/#/#lockdown-podcast:matrix.orghttps://matrix.to/#/#lockdown-general:matrix.orgShow Links: Privacy Tools Page - https://psysecure.com/privacytools/PsySecure ODSF Framework - https://odsf.psysecure.com"The Space Between" Blog Post - https://psysecure.com/ma-the-space-between-breachesSwiss E-ID System Information - https://www.bk.admin.chCyber Kill Chain (Lockheed Martin) - https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.htmlRobert Cialdini's Principles of Persuasion - https://www.influenceatwork.comDaniel Kahneman's Thinking, Fast and Slow - https://www.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374533555“Nothing in life is as important as you think it is when you are thinking about it.”- Daniel Kahneman, Thinking, Fast and Slow  ★ Support this podcast on Patreon ★

  4. 09/08/2025

    033 - Black Mirror - Is the UK's Surveillance State Coming to America?

    In this episode, I share news from my recent trip to the UK, noticing how it seems to have reached the epic proportions of a Black Mirror episode; from the absurd TV licensing program to the new Digital ID Brit cards that will track your behavior. I also explore how the UK may be serving as a testing ground for new levels of behavioral surveillance that could eventually spread globally. I dive into California’s $900 “smart” license plates that track your every move, centralized government digital currencies, and my predictions for the next 20 years of Orwellian surveillance. Support the show on Patreon! In this week’s episode: The UK’s TV licensing system: Legal extortion through private contractorsThe Reviver R-plate: $900 to track yourself in California and ArizonaBrit Cards: UK’s new “voluntary” Digital ID systemThe Bank of England’s digital pound and programmable moneyHistorical patterns of control: From land ownership to neural interfacesWhy the UK is the blueprint for global surveillance rolloutPredictions for the next 20-50 years of biosurveillanceMatrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.orgIndividual Room Links: https://matrix.to/#/#lockdown-intro:matrix.orghttps://matrix.to/#/#lockdown-podcast:matrix.orghttps://matrix.to/#/#lockdown-general:matrix.orgShow Links: PsySecure ODSF Framework - https://odsf.psysecure.comLCD License Plate (not privacy friendly!) - https://reviver.com/rplate/Black Mirror S03E01 "Nosedive" - https://www.imdb.com/title/tt5497778/Bank of England's Digital Pound - https://www.bankofengland.co.uk/the-digital-poundBrit Card Digital ID System - https://www.labourtogether.uk/all-reports/britcardTV Licensing Detector Ads (1980s-90s): The Detector Van - https://www.youtube.com/watch?v=8NmdUcmLFkw"We know exactly where he is" - https://www.youtube.com/watch?v=qF3-S2sCnb8Keep One Eye Open - https://www.youtube.com/watch?v=mVfOmR7gAekMore Powerful Dector Vans! - https://www.youtube.com/watch?v=1Q9CsRRhWQI“One believes things because one has been conditioned to believe them.”- Mustapha Mond (Brave New World ★ Support this podcast on Patreon ★

  5. 08/04/2025

    031 - When Privacy Tools Betray You, Safety Apps That Dox and Revoked Anonymous Payments

    In this episode, I discuss the challenges facing privacy-focused payment solutions like Privacy.com, exploring alternatives and the troubling rise of KYC requirements across the industry. I dive deep into the Switzerland privacy crisis that’s forcing Proton to consider relocating their infrastructure, and what this means for encrypted email providers globally. I also cover the catastrophic security failure at Tea, a women’s safety app that exposed 72,000 images including government IDs through basic incompetence, leading to harassment campaigns on 4chan. I wrap up with thoughts on vehicle tracking through DCM/Telematics modules, why buying older vehicles might be the better privacy-conscious choice, and how embracing the stoic lifestyle aligns with both privacy and my own philosophical principles. In this week’s episode: Privacy.com troubles: Account freezes, limited alternatives, and the KYC nightmareSwitzerland’s surveillance crisis: Why Proton is threatening to leave and relocating to Germany/NorwayEmail provider comparison: Proton vs Tutanota vs Atomic Mail, and understanding intelligence alliancesTea app breach: How 72,000 IDs and 1.1 million private messages ended up on 4chanVehicle tracking: DCM modules, telematics, and why your car is spying on youPhilosophy of privacy: Stoicism, minimalism, and why less is moreMatrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.orgIndividual Room Links: https://matrix.to/#/#lockdown-general:matrix.orghttps://matrix.to/#/#lockdown-podcast:matrix.orghttps://matrix.to/#/#lockdown-intro:matrix.orgShow Links: Privacy.com - https://privacy.comCloaked.com - https://cloaked.comProton Warrant Canary - https://protonvpn.com/blog/transparency-report/Climate Activist Arrest - https://proton.me/blog/climate-activist-arrest and https://www.wired.com/story/protonmail-amends-policy-after-giving-up-activists-data/Tuta Crypt - https://tuta.com/documents/tuta-crypt-spec.pdfProton elliptic curve cryptography - https://proton.me/blog/elliptic-curve-cryptographySimpleLogin - https://simplelogin.ioHashiCorp Vault - https://www.vaultproject.ioRAM IS SPYING ON YOU (Cozy Living Machine) - https://www.youtube.com/watch?v=0-Y1SUSRqNUMeditations by Marcus Aurelius - https://www.amazon.com/Meditations-New-Translation-Modern-Library-ebook/dp/B000FC1JAI“Very little is needed to make a happy life; it is all within yourself, in your way of thinking.”- Marcus Aurelius ★ Support this podcast on Patreon ★

  6. 07/18/2025

    030 - Info Stealers, GrapheneOS Drama, and Why Video Games and Anti-Virus Are Spyware

    In this episode, I address listener feedback and corrections regarding use of public Wi-Fi, MAC addresses, and aliases. I dive deep into the nuances of MAC address randomization on GrapheneOS versus Apple’s private Wi-Fi addresses, explaining why GrapheneOS offers superior privacy protection. I discuss the real threats of public Wi-Fi in 2025 (hint: it’s not hackers with Wireshark), and share my approach with aliases. I also cover the rising threat of infostealers like Atomic Info Stealer for macOS, the dangerous intersection of gaming cheats and malware, and why I avoid third-party antivirus software. Most importantly, I address the GrapheneOS controversy: the loss of a senior developer to military conscription, Google’s strategic pivot that threatens custom ROMs, and why claims of GrapheneOS “dying” are misinformation spread by those with competing agendas. In this week’s episode: Clarifications and Corrections: Public Wi-Fi, MAC addresses, and alias managementMAC address randomization: GrapheneOS vs Apple’s implementationThe real threats of public Wi-Fi in 2025Info stealers and video games can be a privacy nightmareGrapheneOS controversy: Developer conscription, Google’s lockdown, and the future of custom ROMsWhy antivirus software might be the malware you’re trying to avoidMatrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.orgIndividual Room Links: https://matrix.to/#/#lockdown-general:matrix.orghttps://matrix.to/#/#lockdown-podcast:matrix.orghttps://matrix.to/#/#lockdown-intro:matrix.orgShow Links: MAC Address Lookup - https://maclookup.app/OUI Lookup - https://oui.is/33mail - https://www.33mail.com/OpenSnitch - https://github.com/evilsocket/opensnitchPrivacy.com - https://privacy.comLithic - https://lithic.comKaspersky and Russian Government - https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_governmentGoogle Not Killing AOSP - https://www.androidauthority.com/google-not-killing-aosp-3566882/GrapheneOS on Developer Conscription - https://grapheneos.social/@GrapheneOS/114359660453627718GrapheneOS on OEM Partnerships (June 19) - https://grapheneos.social/@GrapheneOS/114671100848024807GrapheneOS Response to Misinformation - https://grapheneos.social/@GrapheneOS/114825492698412916GrapheneOS on iPhone Security - https://grapheneos.social/@GrapheneOS/114824816120139544“Social engineering bypasses all technologies, including firewalls.”- Kevin Mitnick ★ Support this podcast on Patreon ★

  7. 07/07/2025

    029 - Minimize not Militarize and Avoiding Surveillance with GrapheneOS

    In this episode, I explore the difference between the military mindset and the more stealth approach of minimization in cybersecurity. I share the results from the Ghost in the Source Capture the Flag (CTF) challenge, revealing how the winners cracked the AES encryption using dictionary attacks, keyword harvesting and the cipher tool hidden in robots.txt. I discuss why the “assume breach” mentality just leaves the doors wide open, using examples from Kevin Mitnick’s 1981 Pacific Bell infiltration to modern ransomware groups like Scattered Spider who breached MGM and Marks & Spencer through social engineering. I also cover practical tactics for using public Wi-Fi, data curation techniques, the invisible surveillance net including Stingray devices, and provide a deep dive into GrapheneOS covering user profiles, app sandboxing, network controls, sensor permissions, and the proper use of sandboxed Google Play services. In this week’s episode: Ghost in the Source Capture the Flag challenge resultsThe military mindset problem in cybersecurityStrategic use of public Wi-Fi for account creation and privacy techniquesData curation tactics, and “Minimizing What Can Be Known”Invisible surveillance net and Stingray devicesGrapheneOS discussion on user profiles, app sandboxing, network controls, sensors permissions, sandboxed Google Play services, and security architectureMatrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.orgIndividual Room Links: https://matrix.to/#/#lockdown-general:matrix.orghttps://matrix.to/#/#lockdown-podcast:matrix.orghttps://matrix.to/#/#lockdown-intro:matrix.orgShow Links: Noam Chomsky on Internet Privacyhttps://www.youtube.com/watch?v=QIWsTMcBrjQNoam Chomsky on Advertising - https://www.youtube.com/watch?v=PfIwUlY44CMTryHackMe Platform - https://tryhackme.comHack the Box - https://hackthebox.comWired Article on DNC Stingray Surveillance - https://www.wired.com/story/2024-dnc-cell-site-simulator-phone-surveillance/IntelTechniques Data Removal Guide - https://inteltechniques.com/workbook.htmlOptery Data Broker Removal - https://optery.comGraphene OS - https://grapheneos.org“We’re dragons. We’re not supposed to live by other people’s rules.”- Hajime Ryudo ★ Support this podcast on Patreon ★

5
out of 5
26 Ratings

About

Welcome to The Lockdown. Privacy doesn’t have to be all-or-nothing. The inability to attain extreme levels of privacy shouldn’t deter one from taking any protective measures at all. The show is hosted by Ray Heffer, an expert in the field of privacy and cybersecurity, with each episode touching on a range of topics such as data privacy, password management, and secure browsing habits. Tin-foil hats are optional!

You Might Also Like