In this episode, we continue with a closer look at what cybersecurity competence actually means, and why qualifications, compliance frameworks, and public reputation are poor substitutes for understanding how real attacks work. We explore the cryptography behind Proton Mail, public and private keys, fingerprints, and what you can do with PGP word lists. We’ll also discuss passkeys, account recovery, SIM swaps, ClickFix malware, infostealers, VPN blocking, and the residential proxies that allow malicious traffic to hide behind ordinary household IP addresses. In this week’s episode: Hackers, threat actors, security influencers, and the risks created by confident but inaccurate adviceKerckhoffs’s principle: designing security under the assumption that the enemy knows the systemHow public and private keys work, including Proton Mail encryption, digital signatures, fingerprints, and independent key verificationUsing the PsySecure Workbench and PGP word lists to make cryptographic fingerprints easier to exchange and verifyThe problem with passkeys, and why weak account recovery can undermine their securityClickFix attacks that imitate Cloudflare verification pages and trick users into running malicious terminal commandsHow infostealers target browser data, authenticated sessions, cookies, passwords, and other valuable informationWhy VPN traffic is increasingly blocked or challenged while attackers move toward residential proxies that resemble legitimate usersYou are the proxy: How cheap smart home devices, streaming boxes, thermostats, and cameras, can become hidden residential proxiesThe normalization of identity verification, digital ID checks, and other invasive systemsShow Links: The Hidden Backdoors Inside Millions of Smart Devices (WSJ): https://www.youtube.com/watch?v=apEPPKYgLL0keys.openpgp.org: keys.openpgp.orgPsySecure Workbench: https://psysecure.com/workbenchAn Investigative Framework for Auditing the Security & Privacy of Mobile VPNs: https://www.ndss-symposium.org/wp-content/uploads/2026-s1573-paper.pdfMatrix Community Rooms: Matrix Community Space: https://matrix.to/#/#psysecure:matrix.orgIndividual Room Links: https://matrix.to/#/#lockdown-intro:matrix.orghttps://matrix.to/#/#lockdown-podcast:matrix.orghttps://matrix.to/#/#lockdown-general:matrix.orgHow to check public key fingerprint from the command line: gpg --show-keys --with-fingerprint public_key_file.asc★ Support the show on Patreon ★ ★ Support this podcast on Patreon ★