Artwork for Smashing Security
Technology

Smashing Security

Graham Cluley

Stories from the world of hacking, cybersecurity, and rogue AI.

Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.

Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.

Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.

New episodes released at 7pm EST every Wednesday (midnight UK).

  • 480 episodes
  • Updated Wednesday

Episodes480

  • Jun 15, 2022 · 36 min

    Encrypted notes, and a deadly case of AirTag spying

    How did a saxophonist sneak sensitive information in and out of the Soviet Union? How might an Apple AirTag have led to murder? And isn't the world of cryptocurrency and blockchain doing just great? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault. Visit https://www.smashingsecurity.com/279 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Sponsored By: Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Bitwarden: A password manager is an important tool for generating and saving secure credentials for every online account. Bitwarden makes it easy to stay secure and for businesses to share logins with team members and departments. Open source with published 3rd party security audits, Bitwarden is transparent and secure, utilizing end-to-end and zero knowledge encryption with source code that can be scrutinized by all. Learn how Bitwarden can help you do business faster and more securely at bitwarden.com/smashing and start a free business plan trial today. Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only compliance automation platform with a private tenant database. That’s like having your cake and securing it too Countless security professionals from companies including Notion, FullStory, & BambooHR have shared how crucial it has been to have Drata as a trusted partner in the compliance process. Listeners of Smashing Security can get 10% off Drata and waived implementation fees at smashingsecurity.com/drata Support Smashing Security Links: Welsh James Bond Timothy Dalton's cello escape in "The Living Daylights" — YouTube. How a Saxophonist Tricked the KGB by Encrypting Secrets in Music — Wired. Woman accused of killing boyfriend using AirTag tracking — The Register. Andre Smith fatally struck by car outside Tilly's Pub, woman charged — Indy Star. Indianapolis woman Gaylyn Morris accused of tracking boyfriend with Apple AirTag, killing him with car, police say — The Washington Post. An update on AirTag and unwanted tracking — Apple. Apple Updates iPhone with 'Safety Check' for Domestic Victims — Gizmodo. Web3 is going just great. Audm - Listen to feature stories from The Atlantic, WIRED, and more. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 8, 2022 · 40 min

    Tim Hortons, avoiding sanctions, and good faith security research

    Trouble brews with the Tim Hortons app, Mandiant gets in a tussle with a Russian ransomware gang, and should good faith security researchers be at risk of prosecution? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White. Visit https://www.smashingsecurity.com/278 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Geoff White. Sponsored By: Snyk: Snyk is a developer security platform. Integrating directly into development tools, workflows, and automation pipelines, Snyk makes it easy for teams to find, prioritize, and fix security vulnerabilities in code, dependencies, containers, and infrastructure as code. Supported by industry-leading application and security intelligence, Snyk puts security expertise in any developer's toolkit. Get started right now, with a free forever account, at snyk.co/smashing Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Bitwarden: A password manager is an important tool for generating and saving secure credentials for every online account. Bitwarden makes it easy to stay secure and for businesses to share logins with team members and departments. Open source with published 3rd party security audits, Bitwarden is transparent and secure, utilizing end-to-end and zero knowledge encryption with source code that can be scrutinized by all. Learn how Bitwarden can help you do business faster and more securely at bitwarden.com/smashing and start a free business plan trial today. Support Smashing Security Links: Double-double tracking: How Tim Hortons knows where you sleep, work and vacation — Financial Post. Report: Tim Hortons collected location data without consent — The Register. Joint investigation into location tracking by the Tim Hortons App — Office of the Privacy Commissioner of Canada. Mandiant: “No evidence” we were hacked by LockBit ransomware — Bleeping Computer. Department of Justice Announces New Policy for Charging Cases under the Computer Fraud and Abuse Act — Dept of Justice. DOJ: Congress looked into CFAA updates but effort was stalled by extortion concerns — The Record. The (still) unanswered questions around the CFAA and ‘good faith’ security research — SC Magazine. Sex Education — Netflix. Forest fr1ends — Twitter. Inch Calculator. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 1, 2022 · 51 min

    Bad bots, cheeky ransoms, and good deepfakes

    Ransom acts of kindness are top of our mind, as we also explore how bad bots are hogging more and more of the internet's activity, and look at how deepfakes could be a good thing after all. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Ray [REDACTED]. Visit https://www.smashingsecurity.com/277 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Ray [REDACTED]. Sponsored By: Bitwarden: A password manager is an important tool for generating and saving secure credentials for every online account. Bitwarden makes it easy to stay secure and for businesses to share logins with team members and departments. Open source with published 3rd party security audits, Bitwarden is transparent and secure, utilizing end-to-end and zero knowledge encryption with source code that can be scrutinized by all. Learn how Bitwarden can help you do business faster and more securely at bitwarden.com/smashing and start a free business plan trial today. Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing Security Links: Popcorn Time ransomware invites you to get ‘nasty’ to recover your files — Graham Cluley. Rensenware — Wikipedia. GoodWill ransomware forces victims to donate to the poor and provides financial assistance to patients in need — CloudSEK. Bad Bot Report — Imperva. Bad Bot Traffic Report: Almost Half of All 2021 Internet Traffic Was Not Human — CPO Magazine. Automated Threats - web applications — OWASP. Home Stallone [Deepfake] — YouTube. The Emergence of Deepfake Technology: A Review — ResearchGate. Positive Use Cases of Synthetic Media (aka Deepfakes) — Towards Data Science. Deepfake pornography could become an 'epidemic', expert warns — BBC News. Europol report finds deepfake technology could become staple tool for organised crime — Europol. Google quietly bans deepfake training projects on Colab — Bleeping Computer. Japanese man spends £12,500 on ultra-realistic dog costume so he can live like an animal — Daily Mail. Google Colab FAQ. Talky. The Relationship Between Valence and Chills in Music: A Corpus Analysis. Frisson: This playlist is scientifically verified to give you chills — Big Think. A Spotify playlist with 715 songs known to give people chills — Quartz. Songs to give you chills — Spotify playlist. Zen Motoring — BBC iPlayer. Ogmios School of Zen Motoring Ep 1 — YouTube. Zen School of Motoring: TV that will cleanse your spirit like meditation — The Guardian. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • May 25, 2022 · 54 min

    Webcam extortion, Michael Fish, and food foul-ups

    A browser extension bug let malicious websites spy on webcams, hackers threaten the global food supply chain, and Michael Fish (not that one...) hacked into his female classmates' online accounts, hunting for nude photos and videos. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley. Visit https://www.smashingsecurity.com/276 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Mark Stockley. Sponsored By: GoodAccess: GoodAccess - Free Business Cloud VPN for up to 100 Users. Get a cloud VPN with strong network encryption and unprecedented online threat protection. No hardware. 100% free. Just create your team and enjoy GoodAccess forever. Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated. Try Kolide Free for 14 Days; no credit card required. Rumble: Rumble, made by the creator of Metasploit, finds many devices connected to your network that other solutions miss, including orphaned machines running outdated operating systems. It can even tell you which machines are missing endpoint protection, from your local network to the cloud. Sign up for a free trial and build your asset inventory in minutes. Get your trial at rumble.run Support Smashing Security Links: Vote for your favourite cybersecurity podcast in the European Security Blogger Awards! Michael Fish (the weatherman) — Wikipedia. "I wish I wish Michael Fish" by Rachel & Nicki — YouTube. "John Kettley (Is A Weatherman)" by The Tribe of Toffs — YouTube. Albany Man Sentenced to 111 Months for Stealing Nude Photos of Numerous Victims and Possessing Child Pornography — Department of Justice. Hijacking webcams with Screencastify — Almost Secure. Cyber security: Global food supply chain at risk from malicious hackers — BBC News. 4 Predictions for Food and Agriculture in 2022 — Food Logistics Risks of using AI to grow our food are substantial and must not be ignored, warn researchers — University of Cambridge. With food prices continuing to climb, UN warns of crippling global shortages — NPR. OutHorse Your Email. Solitary Bee Nesting Equipment — Mason Bees. Limelight — BBC Radio 4. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • May 18, 2022 · 1 hr 5 min

    Jail for Bing, and mental health apps may not be good for you

    A man hacks his employer to prove its security sucks, Telegram provides a helping hand to the Eternity Project malware, and what the heck do mental health apps think they're up to? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dr Jessica Barker. Plus don't miss our featured interview with Rumble's Chris Kirsch. Visit https://www.smashingsecurity.com/275 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guests: Chris Kirsch and Jessica Barker. Sponsored By: Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. GoodAccess: GoodAccess - Free Business Cloud VPN for up to 100 Users. Get a cloud VPN with strong network encryption and unprecedented online threat protection. No hardware. 100% free. Just create your team and enjoy GoodAccess forever. Rumble: Rumble, made by the creator of Metasploit, finds many devices connected to your network that other solutions miss, including orphaned machines running outdated operating systems. It can even tell you which machines are missing endpoint protection, from your local network to the cloud. Sign up for a free trial and build your asset inventory in minutes. Get your trial at rumble.run Support Smashing Security Links: Angry IT admin wipes employer’s databases, gets 7 years in prison — Bleeping Computer. A closer look at Eternity Malware — Cyble. Researchers Warn of "Eternity Project" Malware Service Being Sold via Telegram — The Hacker News. Dirty Deeds Done Dirt Cheap: Russian RAT Offers Backdoor Bargains — BlackBerry. Top Mental Health and Prayer Apps Fail Spectacularly at Privacy, Security — Mozilla Foundation. Talkspace privacy & security guide — Mozilla Foundation. BetterHelp privacy & security guide — Mozilla Foundation. Dramatic growth in mental-health apps has created a risky industry — The Economist. Meltdown Three Mile Island — Netflix. The China Syndrome trailer — YouTube. Slow Horses — Apple TV+. Therapist Uncensored podcast. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • May 11, 2022 · 49 min

    Hands off my biometrics, and a wormhole squirmish

    Clearview AI receives something of a slap in the face, and who is wrestling over an internet wormhole? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault. And don't miss our featured interview with Artur Kane of GoodAccess. Visit https://www.smashingsecurity.com/274 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Artur Kane. Sponsored By: GoodAccess: GoodAccess - Free Business Cloud VPN for up to 100 Users. Get a cloud VPN with strong network encryption and unprecedented online threat protection. No hardware. 100% free. Just create your team and enjoy GoodAccess forever. Rumble: Rumble, made by the creator of Metasploit, finds many devices connected to your network that other solutions miss, including orphaned machines running outdated operating systems. It can even tell you which machines are missing endpoint protection, from your local network to the cloud. Sign up for a free trial and build your asset inventory in minutes. Get your trial at rumble.run Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated. Try Kolide Free for 14 Days; no credit card required. Support Smashing Security Links: Carl Sagan - Cosmos - Space Travel — YouTube. Wormhole.com 'Tired' Carl Sagan Fan Sells Wormhole.com to Crypto Giant Jump for $50K After Lawsuit — Decrypt. ACLU vs Clearview AI — American Civil Liberties Union. Clearview AI Offered Free Trials To Police Around The World — Buzzfeed News. US State Privacy Legislation Tracker — IAPP. The Secretive Company That Might End Privacy as We Know It — The New York Times. In Big Win, Settlement Ensures Clearview AI Complies With Groundbreaking Illinois Biometric Privacy Law — American Civil Liberties Union OwlKitty — YouTube. Review: The Balldo Made Me Rethink Sex in the Most Absurd Way Possible — Wired. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • May 4, 2022 · 50 min

    Password blips, and who's calling the airport?

    We find out why calls to Dublin airport's noise complaints line have soared, and Carole quizzes Graham to celebrate World Password Day. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault. And don't miss our special featured interview with Clint Dovholuk of NetFoundry. Visit https://www.smashingsecurity.com/273 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Clint Dovholuk. Sponsored By: Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. NetFoundry: NetFoundry's OpenZiti is an open source, free and easy way for the world to embed zero trust networking into anything. Embed SDKs inside your app, tunnelers to run on all major operating systems, or deploy an Edge Router for any cloud. No networking engineering skills required. No more pain of inbound ports, VPNs, complex firewall rules, public DNS, and more. Learn more and try it for yourself at netfoundry.io/smashingsecurity/ Support Smashing Security Links: Houston Zoo asks FBI to investigate text-message attack — Houston Chronicle. Trunk calls for Rory Lion flood telephone lines — Irish Independent. Airport Noise & Noise Reports — Dublin Airport. Dublin Airport got 12,272 noise complaints last year from just one person — Irish Independent. Compromised Passwords Responsible for Hacking Breaches — Securelink. Verizon 2021 DBIR Results & Analysis — Verizon. Three random words — NCSC. What’s wrong with What3Words? — YouTube. Why What3Words is not suitable for safety critical applications — Cybergibbons. What3Words – The Algorithm — Cybergibbons. Why bother with What Three Words? — Terence Eden. River (TV series) — Wikipedia. Wearing shoes inside the house is gross – and there’s science to back that up — The Guardian. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Apr 27, 2022 · 50 min

    Going ape over the Kardashians, and the face of romance scams

    Members of The Bored Ape Yacht Club get that sinking feeling, a face unwittingly launches hundreds of romance scams, and is an as-yet unseen Kim Kardashian sex tape a load of old Roblox? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by the BBC's cyber correspondent Joe Tidy. Visit https://www.smashingsecurity.com/272 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Joe Tidy. Sponsored By: Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated. Try Kolide Free for 14 Days; no credit card required. NetFoundry: NetFoundry's OpenZiti is an open source, free and easy way for the world to embed zero trust networking into anything. Embed SDKs inside your app, tunnelers to run on all major operating systems, or deploy an Edge Router for any cloud. No networking engineering skills required. No more pain of inbound ports, VPNs, complex firewall rules, public DNS, and more. Learn more and try it for yourself at netfoundry.io/smashingsecurity/ Support Smashing Security Links: Jimmy Fallon and Paris Hilton show off their Bored Ape Yacht Club NFTs. — Twitter. NFTs Stolen After Bored Ape Yacht Club Instagram, Discord Hacked — CoinDesk. Image of scam posted on Bored Ape Yacht Club's Instagram account — Twitter. Bored Ape Yacht Club confirms it had two-factor authentication enabled — Twitter. Kardashians deny faking Roblox sex tape scene — BBC News. How an Army colonel became the face of romance scams around the world — Task and Purpose. Army Col. Daniel Blackmon: The accidental face of military romance scams — Task and Purpose. Daily Dorries — Twitter (parental discretion advised) Hacking the House: do MPs care about cyber-security? — BBC News. Rob Brydon's Directors Commentary — YouTube. "This Is How Michael Caine Speaks" from The Trip — YouTube. American Vigilante — Crowd Network. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Apr 20, 2022 · 50 min

    Crypto break-in, Google blurring, and mics not muting

    A man loses $650,000 from his cryptocurrency wallet after his Apple iCloud account is hacked, video conferencing apps may not be muting your mic quite the way you imagined, and Google has unblurred military bases in Russia... or has it? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner. Visit https://www.smashingsecurity.com/271 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Dave Bittner. Sponsored By: NetFoundry: NetFoundry's OpenZiti is an open source, free and easy way for the world to embed zero trust networking into anything. Embed SDKs inside your app, tunnelers to run on all major operating systems, or deploy an Edge Router for any cloud. No networking engineering skills required. No more pain of inbound ports, VPNs, complex firewall rules, public DNS, and more. Learn more and try it for yourself at netfoundry.io/smashingsecurity/ Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated. Try Kolide Free for 14 Days; no credit card required. Support Smashing Security Links: Domenic Iacovone on Twitter. Learn A Geordie Accent - Newcastle Accent Tutorial — YouTube. Serpent explains the scam on Twitter. How an Apple iCloud Exploit Lost a Crypto Trader Over $650K — CNET. MetaMask advises its users to check their iCloud backup settings — Twitter. Scam message received by Graham from his niece's Instagram account. 19 Places On The Planet Google Earth Is Hiding From You — Travel Triangle. Google denies Ukrainian reports it unblurred satellite Maps imagery in Russia — The Verge. Buran shuttle — Google Maps. 'Mute' button in conferencing apps may not actually mute your mic — Bleeping Computer. You’re muted — or are you? Videoconferencing apps may listen even when mic is off — University of Wisconsin-Madison. Gerry Anderson: A Life Uncharted — BritBox. Gerry Anderson: A Life Uncharted trailer — YouTube. Bloodline — Netflix. Succession — HBO. Succession review – brilliant dissection of a dysfunctional dynasty — The Guardian. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Apr 13, 2022 · 51 min

    Bearded Barbie, EDR scams, and hobbyist crime detectives

    Pulchritudinous women with glossy long hair are targeting Israeli officials via Facebook - but why? Scammers have found a new way to gain access to your most sensitive information - but how? And armchair detectives are helping investigating cold cases involving DNA - but should they? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis. Visit https://www.smashingsecurity.com/270 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Maria Varmazis. Sponsored By: Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Keeper Security: Keeper Security’s enterprise password management platform locks down logins, payment cards, confidential documents, API keys, and database passwords in a patented Zero-Knowledge encrypted vault. And, it takes less than an hour to deploy across your organization. Sign up for a Keeper free trial for your organization today, and get a free 3-year personal plan, at keepersecurity.com/smashing Support Smashing Security Links: How Barbie's body size would look in real life — Daily Mail. Operation Bearded Barbie: APT-C-23 Campaign Targeting Israeli Officials — Cybereason. Hackers Gaining Power of Subpoena Via Fake “Emergency Data Requests” — Brian Krebs. What we know about the increase in U.S. murders in 2020 — Pew Research Center. The History of DNA: From Crime Scenes to Consumer Goods — University of West Florida. How an Unlikely Family History Website Transformed Cold Case Investigations — The New York Times. DNA Databases Are Boon to Police But Menace to Privacy, Critics Say — PEW. Philanthropists Push Police Searches of DNA Databases — The New York Times. Help solve crimes with your DNA — DNASolves. Hackers Attacked Two Leading Genetic Genealogy Websites — BuzzFeed. How to Pronounce Moët & Chandon? And WHY?! — YouTube. How to Pronounce Wednesday? (CORRECTLY) — YouTube. Julien Miquel on YouTube. Support Maria Varmazis as she raises money for Cancer Research — Pan-Mass Challenge. The House (2022 film) — Wikipedia. The House — Netflix. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Apr 6, 2022 · 50 min

    Trezor Deep Throat, a CCTV stalker, and Amazon's list of banned words

    There's monkey business involving cryptocurrency thieves and MailChimp, a stalker exploits his ex-partner's CCTV cameras, and what are the naughty words Amazon doesn't want its staff using? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Zoë Rose. Visit https://www.smashingsecurity.com/269 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Zoë Rose. Sponsored By: Keeper Security: Keeper Security’s enterprise password management platform locks down logins, payment cards, confidential documents, API keys, and database passwords in a patented Zero-Knowledge encrypted vault. And, it takes less than an hour to deploy across your organization. Sign up for a Keeper free trial for your organization today, and get a free 3-year personal plan, at keepersecurity.com/smashing Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing Security Links: Trezor wallets hacked? Don’t be duped by phishing attack email — Graham Cluley. Tweet by Trezor. Ongoing phishing attacks on Trezor users — Trezor. Hacker accessed 319 crypto- and finance-related Mailchimp accounts, company said — The Record. Stalker used woman's own CCTV cameras to watch her at home — Liverpool Echo. Operation: SafeEscape. Work Trend Index: Microsoft’s latest research on the ways we work — Microsoft. Research: A Little Recognition Can Provide a Big Morale Boost — HBR. 50% of companies want workers back in office 5 days a week — CNBC. New Amazon Worker Chat App Would Ban Words Like “Union” — The Intercept. Trust No One — Netflix. Smashing Security episode 114: Darknet Diaries, death, and beauty apps — Where we discussed the mysterious case of Gerry Cotten and QuadrigaCX. Find QuadrigaCX’s missing $190 million, and you could win a $100,000 bounty — Graham Cluley. Hamilton One Essential S1 Magicfold Premium Buggy — Kruidvat NL. Infantino 4-in-1 Flip Advanced Draagzak BK-05204 — Bol. Cosco Scenera Next Convertible Car Seat, Boulder — Canadian Tire. Literature Clock. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Mar 30, 2022 · 48 min

    LinkedIn deepfakes, doxxing Russian spies, and a false alarm

    Strange goings-on on LinkedIn, Ukraine publishes a list of alleged Russian FSB agents, and police in Pittsburgh investigate an odd report of an active shooter. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Lazarus Heist's Geoff White. Visit https://www.smashingsecurity.com/268 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Geoff White. Sponsored By: Keeper Security: Keeper Security’s enterprise password management platform locks down logins, payment cards, confidential documents, API keys, and database passwords in a patented Zero-Knowledge encrypted vault. And, it takes less than an hour to deploy across your organization. Sign up for a Keeper free trial for your organization today, and get a free 3-year personal plan, at keepersecurity.com/smashing Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing Security Links: North Korea tests its ‘largest intercontinental ballistic missile’ — YouTube. LinkedIn Professional Community Policies — LinkedIn. Community Report — LinkedIn. The latest marketing tactic on LinkedIn: AI-generated faces — NPR. List of FSB agents — Ukraine Ministry of Defence. How the Dutch foiled Russian 'cyber-attack' on OPCW — BBC News. Boris Nemtsov: Murdered Putin rival 'tailed' by agent linked to FSB hit squad — BBC News. Police: Autocorrected text triggered large police presence on Pittsburgh’s North Side — WPXI. Pickle me up: Hilarious autocorrect fails, from Krispy Koreans to wet, sloppy kids — Daily Mail. After Life — Netflix. After Life trailer — YouTube. "Time on Rock - A Climber's Route into the Mountains" by Anna Fleming — Canongate Books. Severance — Apple TV. Severance trailer — YouTube. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Mar 23, 2022 · 53 min

    Virtual kidnapping, two helipads, and a naughty Apple employee

    A Russian bank tells its customers to stop installing security updates, an Apple employee ends up in hot water, and learn our tips to avoid being virtually kidnapped. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading. Visit https://www.smashingsecurity.com/267 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Anna Brading. Sponsored By: Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated. Try Kolide Free for 14 Days; no credit card required. Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only compliance automation platform with a private tenant database. That’s like having your cake and securing it too Countless security professionals from companies including Notion, FullStory, & BambooHR have shared how crucial it has been to have Drata as a trusted partner in the compliance process. Listeners of Smashing Security can get 10% off Drata and waived implementation fees at smashingsecurity.com/drata Support Smashing Security Links: Smashing Security 263: Problèmes de Weefeee, AI artists, and Web 3.0 — In which Mark Stockley discusses the NFT he created in Smashing Security's honour. Graham or Carole? - Untitled Collection #173407394 — OpenSea. Mark Stockley reveals the Smashing Security NFT is being resold... for $3 million — Twitter. Секрет Шехерезады. Яхта Путина за 75 000 000 000 ₽ — YouTube (best watched with the subtitles on...) ‘Mysterious’: the $700m superyacht in Italy some say belongs to Putin — The Guardian. "The road from Moscow to Kyiv passes through Belgravia" — Video from Led By Donkeys, posted on Twitter. Burger King owner says operator in Russia refuses to shut shops — The Guardian. Pitcairn Islands relays most spam per person, reveals Sophos — Sophos. Pitcairn spam haven, North Korea definitely isn't — The Guardian. Sabotage: Code added to popular NPM package wiped files in Russia and Belarus — Ars Technica. Activists are targeting Russians with open-source "protestware" — MIT Technology Review. JavaScript library updated to wipe files from Russia systems — The Register. After ‘protestware’ attacks, a Russian bank has advised clients to stop updating software — The Verge. Irish petrol station offers 24-7 laundry service — Petrol Plaza. Clip from Mel Gibson movie "ransom", starring Mel Gibson — YouTube. FBI warns of ‘virtual kidnapping’ scheme executed on Miami couple — Local 10. FBI Chicago Warns Public About Virtual Kidnapping Scams — FBI. Former Employee Charged With Defrauding Apple, Money Laundering, And Tax Crimes — Department of Justice. U.S. charges former Apple buyer with defrauding more than $10 million from company — Reuters. Mandy — BBC iPlayer. Diane Morgan as Mandy — YouTube. Heardle — The daily musical intros game. Color wheel, a color palette generator — Adobe Color. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Mar 16, 2022 · 58 min

    Cyberflashing, Kaspersky, and secret spies

    Germany tells consumers to stop using Kaspersky anti-virus products, OSINT reveals a secret government department (with help from an Apple AirTag), and the UK says it's taking a hard line on cyberflashing. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Chris Kirsch. Visit https://www.smashingsecurity.com/266 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Chris Kirsch. Sponsored By: Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only compliance automation platform with a private tenant database. That’s like having your cake and securing it too Countless security professionals from companies including Notion, FullStory, & BambooHR have shared how crucial it has been to have Drata as a trusted partner in the compliance process. Listeners of Smashing Security can get 10% off Drata and waived implementation fees at smashingsecurity.com/drata Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing Security Links: Kaspersky Has Close Ties to Russian Spies — Bloomberg. Kaspersky hit by new below-the-belt sauna spy attack — Graham Cluley. A practical guide to making up a sensation — Eugene Kaspersky. US intelligence chiefs don’t trust Kaspersky. But why? — Graham Cluley. UK cyber agency targets Kaspersky in warning on Russian software — Reuters. Group-IB founder arrested in Moscow on state treason charges — The Record. BSI warning about using Kaspersky. Kaspersky statement regarding the BSI warning — Kaspersky. Collateral Damage — on Cybersecurity — Open letter from Eugene Kaspersky. Apple's AirTag uncovers a secret German intelligence agency — Apple Insider. Bundesservice Telekommunikation — wie ich versehentlich eine Tarnbehörde in der Bundesverwaltung fand — Lilith Wittmann. Bundesservice Telekommunikation — enttarnt: Dieser Geheimdienst steckt dahinter — Lilith Wittmann. Loophole in law means men will still get away with sending penis pictures — Cambridgeshire Live. Cyberflashing to be criminalised under new online safety bill — The Independent. ‘Cyberflashing’ to become a criminal offence — UK Government. Is there hidden sexual abuse going on in your school? — TES Magazine. 13 genius ways to respond to unsolicited dick pics — Cosmopolitan. Whatever Happened to Pizza at McDonald's? A Podcast Answers a Fast-Food Question That Nobody Is Asking — The New York Times. Forget Adnan and Richard Simmons, ‘Whatever Happened to Pizza at McDonald’s?’ Is the Mystery-Solving Podcast You Need — Vulture. Cook-Out on Oculus Quest — Oculus. Cook-Out: A Sandwich Tale trailer — YouTube. 100,000 Stars. Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Mar 9, 2022 · 54 min

    The Nigerian supercop and Alexa vs. Alexa

    The most famous policeman in Nigeria is in hot water over his links to Hushpuppi, has your Amazon Echo been talking to itself, and can an AI girlfriend save your marriage? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault. Plus don't miss our featured interview with Jason Meller of Kolide. Visit https://www.smashingsecurity.com/265 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Jason Meller. Sponsored By: Drata: Is your organization finding it difficult to achieve compliance and scale its security posture? As G2’s highest rated cloud compliance software, Drata streamlines your SOC 2, ISO 27001, PCI DSS, GDPR & HIPAA compliance and provides 24-hour continuous control monitoring so you focus on scaling securely. Drata is also the only compliance automation platform with a private tenant database. That’s like having your cake and securing it too Countless security professionals from companies including Notion, FullStory, & BambooHR have shared how crucial it has been to have Drata as a trusted partner in the compliance process. Listeners of Smashing Security can get 10% off Drata and waived implementation fees at smashingsecurity.com/drata Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated. Try Kolide Free for 14 Days; no credit card required. Support Smashing Security Links: Abba Kyari shows off that he has had a road named after him — Instagram. Birthday wishes for Abba Kyari — Instagram. Smashing Security episode 186: This one's for all the Karens! — In which we first discussed the Hushpuppi case. Adeola Fayehun discusses Abba Kyari's arrest — YouTube. Alexa Privacy – Learn how Alexa works — Amazon. Alexa vs Alexa (AvA). Amazon Alexa compromise possible through own speakers — The Register. The Rescue — Wikipedia. The Rescue — Apple TV. 'I fell in love with my AI girlfriend - and it saved my marriage' — Sky News. Smashing Security merchandise (t-shirts, mugs, stickers and stuff Privacy & Opt-Out: https://redcircle.com/privacy

  • Mar 2, 2022 · 47 min

    Hacked car chargers, Telegram sextortionists, and secret bossware

    Why might Russian EV chargers be displaying an anti-Putin message? Why are Telegram groups sharing sharing explicit images of women without their consent? And who is watching you in the workplace? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Jessica Barker. Visit https://www.smashingsecurity.com/264 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Jessica Barker. Sponsored By: Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. Support Smashing Security Links: Three ways you can help the people of Ukraine from the UK — The Guardian. How You Can Help Ukraine — London City Hall. Ukrainian Astronomers Named a Star 'Putin Is a D**khead' — The Atlantic. Video of hacked EV charger — AutoEnterprise on Facebook. Explanation for EV charger outage — Rosseti on Facebook. Russian Electric Vehicle Chargers Hacked, Tell Users ‘PUTIN IS A DICKHEAD’ — Vice. Roblox Currency ‘Robux’ Is Outperforming the Ruble — Vice. Why won’t Telegram take down my naked photos? — BBC News. Telegram revenge porn scandal: police investigate as more than 50 000 men share explicit content of women and underaged girls — Politika. Ex-Leeds student OnlyFans star rakes in £2m pouring beans on herself and pretending to be a giant — Leeds Live. Post Office scandal explained: Why a public inquiry is examining the Horizon sub-postmasters scandal — Inews. TUC warns against employee monitoring after Post Office scandal — Personnel Today. Post Office scandal: What the Horizon saga is all about — BBC News. I’ll be watching you - What is workplace monitoring? — TUC. TUC and legal experts warn of “huge gaps” in British law over use of AI at work — TUC. Intrusive worker surveillance tech risks “spiralling out of control” without stronger regulation, TUC warns — TUC. Kind of Bloop — An 8-Bit Tribute to Miles Davis' Kind of Blue. Space Force — Netflix. Who Won the US Military Vs. Space Force Trademark Dispute? — CBR. 'Space Force? Is that Real?' Guardians Still Struggling with an Unconvinced Public — Military.com. Yoga with Kassandra — YouTube. Five Parks Yoga w/ Erin Sampson — YouTube. YOGA UPLOAD with Maris Aylward — YouTube. Breathe and Flow — YouTube. Two Birds Yoga — YouTube. Smashing Security merchandise (t-shirts, mugs, stickers and stuff Privacy & Opt-Out: https://redcircle.com/privacy

  • Feb 23, 2022 · 1 hr 6 min

    Problèmes de Weefeee, AI artists, and Web 3.0

    Ooh la la! Horreur Wi-Fi en France! Some folks have experienced the drawbacks of Web 3.0 as their NFTs are stolen, and should computers own the copyright over the art they produce? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley. And don't miss our featured interview with Sean Herbert of baramundi. Visit https://www.smashingsecurity.com/263 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guests: Mark Stockley and Sean Herbert. Sponsored By: Kolide: At Kolide, we believe the supposedly Average Person is the key to unlocking a new class of security detection, compliance, and threat remediation. So do the hundreds of organizations that send important security notifications to employees from Kolide’s Slack app. Collectively, we know that organizations can dramatically lower the actual risks they will likely face with a structured, message-based approach. More importantly, they’ll be able to engage end-users to fix nuanced problems that can’t be automated. Try Kolide Free for 14 Days; no credit card required. baramundi: Optimize your IT processes with the baramundi Management Suite and make optimal use of resources by automating time-consuming routine tasks. Stay in control and maximize your productivity by automating routine tasks. The Unified Endpoint Management Software can be installed and implemented quickly, is intuitive to use, has a modular structure and offers a high level of usability and transparency. Try out the free 30-Day full version for yourself today at baramundi.com/smashingsecurity Support Smashing Security Links: Les dents, le brouilleur et au lit! — ANFR. Dad takes down town's internet by mistake to get his kids offline — Bleeping Computer. TV licenses and detector vans in the United Kingdom — Wikipedia. My first impressions of web3 — Moxie Marlinspike. Graham or Carole? - NFT for sale — OpenSea. $1.7 million in NFTs stolen in apparent phishing attack on OpenSea users — The Verge. Art Copyright, Explained — Artsy. The US Copyright Office says an AI can’t copyright its art — The Verge. Ruling on "A Recent Entrance to Paradise" — Copyright Review Board. Appeals court blasts PETA for using selfie monkey as ‘an unwitting pawn’ — The Verge. 'Monkey selfie' case: Photographer wins two year legal fight against Peta over the image copyright — The Independent. What I Wish They Taught Me about Copyright in Art School — Library of Congress. Who is Banksy and why did he lose the trademark for four of his most famous works? — Sydney Morning Herald. The Tinder Swindler — Netflix. You Can’t Make This Up: The Making of a Swindler (Part one) — Podcast going behind the scenes of "The Tinder Swindler." Why insects do not (and cannot) attack healthy plants — YouTube. Eye of the Storm — BBC iPlayer. Smashing Security merchandise (t-shirts, mugs, stickers and stuff Privacy & Opt-Out: https://redcircle.com/privacy

  • Feb 16, 2022 · 57 min

    Macro progress, eyeball-tracking ads, and encryption backdoors

    How does Microsoft hope to defeat the macro terror? How is the UK Government trying to influence the public's opinion on end-to-end encryption? And what is MoviePass hoping to do with your eyeballs? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Thom Langford. Visit https://www.smashingsecurity.com/262 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Thom Langford. Sponsored By: Kolide: Kolide is a SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack. Kolide is perfect for organizations that want to move beyond a traditional lock-down model and move to one where employees are educated about security and device management while fixing nuanced problems. We call this approach Honest Security. You can try Kolide on an unlimited number of devices with all its features for free and without a credit card for 14 days. baramundi: Optimize your IT processes with the baramundi Management Suite and make optimal use of resources by automating time-consuming routine tasks. Stay in control and maximize your productivity by automating routine tasks. The Unified Endpoint Management Software can be installed and implemented quickly, is intuitive to use, has a modular structure and offers a high level of usability and transparency. Try out the free 30-Day full version for yourself today at baramundi.com/smashingsecurity Support Smashing Security Links: Macros from the internet are blocked by default in Office — Microsoft. A potentially dangerous macro has been blocked — Microsoft. The Death of "Please Enable Macros" and What it Means — Check Point Research. No Place to Hide. Why we need EndToEndEncryption and why it’s essential for our safety, our children’s safety, and for everyone’s future — Alec Muffet. Smashing Security episode 68: Malware from outer space! MoviePass Relaunching Next Summer — Variety. MoviePass is back but with eyeball tracking to make you watch ads — Daily Mail. MoviePass 2.0 Wants to Track Your Eyeballs to Make Sure You Watch Ads — Vice. Starlink. 2000 AD - the Galaxy's Greatest Comic! Future Shock! The Story of 2000AD — IMDB. 40 Strange Etiquette Rules Through the Years — Good Housekeeping. Smashing Security merchandise (t-shirts, mugs, stickers and stuff Privacy & Opt-Out: https://redcircle.com/privacy

  • Feb 9, 2022 · 50 min

    North Korea hacked, DEA cosplay, and Horizon Worlds drama

    Who's wearing the pyjamas while they take down North Korea's internet? Is it a case of cop or cosplay in Oregon? And what's to fear about the metaverse? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner. Visit https://www.smashingsecurity.com/261 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Dave Bittner. Sponsored By: 1Password: 1Password Families makes sharing passwords, logins, credit cards and more a (romantic) walk in the park. From now until February 28th, when you sign up for - or upgrade your individual account to - a 1Password Families membership, you’ll get $20 off the entire year! Learn more at smashingsecurity.com/love1password baramundi: Optimize your IT processes with the baramundi Management Suite and make optimal use of resources by automating time-consuming routine tasks. Stay in control and maximize your productivity by automating routine tasks. The Unified Endpoint Management Software can be installed and implemented quickly, is intuitive to use, has a modular structure and offers a high level of usability and transparency. Try out the free 30-Day full version for yourself today at baramundi.com/smashingsecurity Support Smashing Security Links: Space Station Photos Show North Korea at Night, Cloaked in Darkness — National Geographic. North Korea Hacked Him. So He Took Down Its Internet — Wired. North Korean hackers attempt to hack security researchers investigating zero-day vulnerabilities — Hot for Security. Woman ‘Tricked’ to Believe She Was a D.E.A. Agent Trainee, Official Says — New York Times. Alleged DEA imposter in Portland took woman on ‘ride-alongs,’ had her flash fake badge to find informants among homeless people, complaint says — Oregon Live. Meta forced to add ‘personal boundaries’ to the Metaverse after woman was sexually harassed in virtual reality — The Independent. Horizon Worlds metaverse app could pose danger for kids, experts say — Washington Post. The metaverse has a groping problem already — MIT Technology Review. Sexual harassment in the metaverse? Woman says she was virtually raped — USA Today. Talking Telephone Numbers Breakdown w/ separated Transmission & Talkback audio — YouTube. 2013 Tony Awards Director On FIRE!!! — YouTube. Ghosts — BBC iPlayer. Chateau Snavely — A terrible Fawlty Towers remake from 1978, with Betty White. Amanda's By the Sea — A terrible Fawlty Towers remake from 1983, with Bea Arthur. Payne — A terrible Fawlty Towers remake from 1999, which doesn't star anyone from The Golden Girls. Couples Therapy — BBC iPlayer. Couples Therapy trailer — YouTube. Smashing Security merchandise (t-shirts, mugs, stickers and stuff Privacy & Opt-Out: https://redcircle.com/privacy

  • Feb 2, 2022 · 47 min

    New hire mystery, hacktivist ransomware, and digi-dating

    Who's that new guy working at your company, and why don't you recognise him from the interview? How are hacktivists raising the heat in Belarus? And should you be fully vaxxed for your online date? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis. Visit https://www.smashingsecurity.com/260 to check out this episode’s show notes and episode links. Follow the show on Twitter at @SmashinSecurity, or on the Smashing Security subreddit, or visit our website for more episodes. Remember: Follow us on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Maria Varmazis. Sponsored By: 1Password: Secure online payments and grow your business with Brex and 1Password. Brex and 1Password have partnered to make online payments secure and frictionless. 1Password customers can now use Brex virtual credit cards to check out online with just two clicks. 1Password's integration with Brex is available right now to 1Password Teams and Business customers based in the United States. Learn more at smashingsecurity.com/brex Uptycs: Uptycs is a cloud-native security analytics platform built to protect the modern attack surface. Uptycs zeros in on the blind spots that are preventing you from rapidly identifying and responding to existing threats and vulnerabilities in your ecosystem. Uptycs normalizes telemetry from across macOS, Linux, Windows, and containers; records system activity for historical investigation even when no alert has fired; and enables you to build complex custom detections in addition to its industry-leading MITRE ATT&CK mapping. Uptycs provides observability across both cloud workloads and endpoints in a single centralized platform. Find out more and try it for free at uptycs.com Support Smashing Security Links: The new hire who showed up is not the same person we interviewed — Ask a Manager. How to Spot Fake Candidates in Video Interviews — Nick Shah on LinkedIn. How To Avoid The Fake Candidate Scam in the Tech Industry — Focus GTS. Tweet by Belarusian Cyber-Partisans. Tweet showing screenshots of hacked railroad. ‘We Can Hurt Them in Ways They Don’t Understand’: Ukraine on Russia Cyber-War — Vice. Pandemic fuels new trends in the online dating world — WXYZ Detroit. 'Swipe left for unvaxxed’: Vaccine status complicates the scene on dating apps — France 24. Tips for private and safe dating on Tinder — Kaspersky. Survey Says Bumble Users Are Burned Out on One Thing in Particular — Bumble. Cookie Clicker. Getting Curious with Jonathan Van Ness — Netflix. Chicken fattee with rice, crispbread and yoghurt recipe — Moro. Chocolate and Apricot Tart report — Happy Foodie. Smashing Security merchandise (t-shirts, mugs, stickers and stuff Privacy & Opt-Out: https://redcircle.com/privacy