Privacy Please

S6, E245 - Hard-coded Secrets and Unencrypted Data: A Digital Security Nightmare


Listen Later

Send us a text

Several popular Chrome extensions, including privacy and security tools, have been found leaking sensitive data through unencrypted HTTP and hard-coded credentials in their code. Security is both hard and easy - hard because of existing unencrypted protocols and trust placed in developers, but easy because fundamental security practices should be common knowledge in 2025.

• Chrome extensions including DualSafe Password Manager and Avast Online Security are leaking sensitive user data
• HTTP vs HTTPS - the 'S' stands for security and encrypts data transmission over the internet
• HTTPS Only extension from EFF forces secure connections when browsing
• Hard-coded credentials in extensions create permanent security vulnerabilities
• Developers sometimes collect excessive data "just in case" rather than minimizing collection
• OWASP (Open Web Application Security Project) provides essential resources for developers
• Technology abstraction makes users less aware of security fundamentals
• The newly restarted OWASP Nomad chapter offers virtual community for application security

Check out our GitHub repository of privacy resources at "Awesome Privacy Engineering Tools" for more information on implementing better privacy practices in development.


Support the show

...more
View all episodesView all episodes
Download on the App Store

Privacy PleaseBy Cameron Ivey

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

29 ratings


More shows like Privacy Please

View all
Freakonomics Radio by Freakonomics Radio + Stitcher

Freakonomics Radio

32,008 Listeners

Anderson Cooper 360 by CNN Podcasts

Anderson Cooper 360

3,855 Listeners

Acquired by Ben Gilbert and David Rosenthal

Acquired

4,649 Listeners

WSJ What’s News by The Wall Street Journal

WSJ What’s News

4,343 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,010 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,022 Listeners

The Privacy Advisor Podcast by Jedidiah Bracy, IAPP Editorial Director

The Privacy Advisor Podcast

68 Listeners

Pod Save America by Crooked Media

Pod Save America

87,290 Listeners

Start Here by ABC News

Start Here

6,433 Listeners

Serious Privacy by Dr. K Royal, Paul Breitbarth & Ralph O'Brien

Serious Privacy

23 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

139 Listeners

She Said Privacy/He Said Security by Jodi and Justin Daniels

She Said Privacy/He Said Security

13 Listeners

Masters of Privacy by Sergio Maldonado

Masters of Privacy

6 Listeners

The Koerner Office - Business Ideas and Small Business Deep Dives with Entrepreneurs by Chris Koerner

The Koerner Office - Business Ideas and Small Business Deep Dives with Entrepreneurs

239 Listeners

Security You Should Know by CISO Series

Security You Should Know

5 Listeners