Shared Security Podcast

Shared Security Podcast

By Tom Eston, Scott Wright, Kevin TackettNewsTechnologyTech News
Download on the App Store

Shared Security Podcast episodes

  • Microsoft Lost Its Keys, Voice Cloning Scams, The Biden-Harris Cybersecurity Labeling Program
    In this episode, we discuss the recent Microsoft security breach where China-backed hackers gained access to numerous email inboxes, including those of several federal government agencies, using a stolen Microsoft signing key to forge authentication tokens.
    A TikTok influencer used a voice cloning app to expose a cheating boyfriend. But wait, there's more to this story than meets the eye! We discuss the serious implications of voice cloning and how its being used for new types of phone scams.
    Lastly, we discuss the recent announcement by the Biden-Harris administration about their new cybersecurity labeling program for smart devices. Will this program help or hinder the security of smart devices?
    34 min
  • First Ban on Selling Location Data, Prohibiting Password Managers, Real-Time Crime Center Concerns
    In this episode we discuss how Massachusetts lawmakers are pushing a groundbreaking bill to ban the buying and selling of location data from mobile devices. This legislation raises vital questions about consumer privacy, digital stalking, and national security threats.
    Next, we discuss the pros and cons of prohibiting external password managers within organizations. Join the conversation as we weigh the benefits, downsides, and best practices surrounding this hotly debated topic.
    Finally, we discuss the rise of Real-Time Crime Centers (RTCCs) and the concerns they raise regarding mass surveillance, privacy rights, and data misuse.
    33 min
  • Meta’s Threads and Your Privacy, Airline Reservation Scams, IDOR Srikes Back
    In this episode, we explore the rise of Threads, a new social media app developed by Meta, which has already attracted 10 million users in just seven hours. However, there's a catch – the app collects extensive personal data, sparking concerns about privacy.
    Next, we dive into the world of airline reservation scams, exposing how fraudsters exploit a loophole to deceive unsuspecting travelers. Learn how to protect yourself and avoid being swindled by these ticket scams.
    Finally, we discuss the security vulnerability discovered in Eaton's smart security alarm systems, highlighting the significant risks of IDOR (Insecure Direct Object Reference) vulnerabilities and the potential for unauthorized access.
    25 min
  • MOVEit Cyberattack, The Problem with Password Rotations, Military Alert on Free Smartwatches
    Several major organizations, including British Airways and the BBC, fell victim to the recent MOVEit cyberattack. We discuss the alarming trend of hackers targeting trusted suppliers to gain access to customer data, potentially holding companies and individuals for ransom.
    Is it better to change passwords regularly or focus on creating complex ones? We discuss the pitfalls of frequent password changes, such as predictable patterns and delayed responses to security breaches.
    The Department of the Army's Criminal Investigation Division issues a military-wide alert about a program offering free smartwatches to US service members. We discuss the concerns surrounding these devices, from malicious actors targeting personal data to engaging in "brushing" activities.
    27 min
  • The FTC’s Complaint Against Ring, Detecting Malware Infected Apps, America’s Most Cybersecure Companies
    The FTC charged Ring, the Amazon-owned home security camera company, for compromising customer privacy and having inadequate security measures. Employees accessed private videos, while hackers exploited vulnerabilities and now Ring needs to reimburse customers $5.8 million dollars. The FTC complaint emphasizes that Ring's actions disregarded privacy and security, putting consumers at risk.
    Google has removed the iRecorder - Screen Recorder app from the Play Store after it was discovered that it was infected with malware capable of stealing personal information. We discuss several ways to spot malicious apps on your smartphone helping you protect and safeguard your personal information.
    Finally, we discuss Forbes' collaboration with SecurityScorecard to identify America's Most Cybersecure Companies, and the ethical dilemma that this presents to companies that may not have given their permission to be listed. We also discuss why these lists may make companies a target by hackers (anyone remember the "Hacker Safe" badges?).
    36 min
  • How to Break Into a Cybersecurity Career – Phillip Wylie
    In this exciting episode of our podcast we have the pleasure of speaking with Phillip Wylie, a remarkable professional with a captivating career in cybersecurity. Join us as we discuss Phillip's unique journey and uncover valuable insights on breaking into the cybersecurity field. From his origins as a professional wrestler who once bravely faced off against a bear, to his evolution into a respected penetration tester, author, trainer, mentor, and public speaker, Phillip's experiences are nothing short of extraordinary. Join us as Phillip shares his inspiring origin story and sheds light on the following topics:
    Unveiling the Transformation: From Pro Wrestler to Penetration Tester
    Bridging the Gap: Phillip's Evolution from Pentester to Author and Trainer
    Navigating the Cybersecurity Landscape: Phillip's Advice for Aspiring Professionals
    Are Cybersecurity Certifications Still Valuable?
    How to Engage and Connect with Phillip
    Join us for this episode as we discuss the remarkable career journey of Phillip Wylie!
    25 min
  • Netflix Cracks Down on Password Sharing, AI Legal Research Gone Wrong, Fake Identities and Surveillance Firms
    Netflix plans to crack down on the widespread practice of password sharing among households. We discuss their new verification feature and its impact on user experience and security.
    A lawyer finds himself in hot water after relying on ChatGPT for legal research. We investigate the consequences of referencing non-existent legal cases, the lawyer's claim of unawareness about the AI's potential for false information, and the broader concerns surrounding the risks of AI, including misinformation and bias.
    Threat intelligence firms are using fake online personas to gather data on Discord, Reddit, WhatsApp, and other apps. Watchdog groups have raised concerns about the potential violation of civil liberties and lack of oversight of this activity.
    24 min
  • Meta’s $1.3 Billion Fine, AI Hoax Hysteria, Montana’s TikTok Ban
    In this episode, we discuss Meta's record-breaking $1.3 billion fine by the EU for unlawfully transferring user data, shedding light on the increasing risks faced by tech companies in violating privacy rules.
    Highly realistic images of a Pentagon explosion went viral on Twitter, causing a stock market dip. We discuss the risks associated with Twitter's verification system and the issue of AI and deepfaked images.
    Montana makes headlines as the first US state to ban TikTok. We discuss the ban's motives, the challenges of implementation, and the broader concerns about personal data protection and online freedom.
    26 min
  • Google Now Supports Passkeys, Risky New Top Level Domains, Twitter’s Encryption Dilemma
    In this episode, we explore the arrival of passwordless Google accounts that use "passkeys," which offer enhanced usability and security. We discuss the benefits of passkeys over traditional passwords, but also why passkeys are not quite ready for prime time use.
    Next, we discuss Google Domains' introduction of new top-level domains (TLDs) like .zip and .mov, raising concerns about the potential use for malicious activities. We separate fact from fiction, and discuss the real risks involved.
    Lastly, we examine Twitter's long-awaited encrypted direct messaging feature. We explore the limitations and criticisms surrounding its implementation, highlighting the importance of true end-to-end encryption solutions like Signal.
    26 min

About Shared Security Podcast

From the publisher's feed

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy…

More shows like Shared Security Podcast

Hacked by Hacked

Hacked

191 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

2,011 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

373 Listeners

Risky Business by Risky Business Media

Risky Business

375 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

653 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

Smashing Security by Graham Cluley

Smashing Security

318 Listeners

Click Here by Recorded Future News

Click Here

421 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

8,054 Listeners

Cybersecurity Today by David Shipley

Cybersecurity Today

179 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

191 Listeners

Defense in Depth by CISO Series

Defense in Depth

73 Listeners

Cybersecurity Headlines by CISO Series

Cybersecurity Headlines

138 Listeners

The 404 Media Podcast by 404 Media

The 404 Media Podcast

397 Listeners