Artwork for Smashing Security
Technology

Smashing Security

Graham Cluley

Stories from the world of hacking, cybersecurity, and rogue AI.

Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.

Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.

Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.

New episodes released at 7pm EST every Wednesday (midnight UK).

  • 480 episodes
  • Updated Wednesday

Episodes480

  • Oct 10, 2018 · 16 min

    099: Passwords - A Smashing Security splinter (replay)

    With Carole in the wilds of Canada, and Graham knee-deep in a security conference in Glasgow, we drag an episode out from the archives of February 2017 - looking at the thorny subject of passwords. Join computer security veterans Graham Cluley, Carole Theriault, and Vanja Švajcer as they offer some advice and tips for computer users. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Vanja Švajcer. Sponsored By: MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 3, 2018 · 51 min

    098: A Facebook omnishambles

    Millions of Facebook user accounts put at risk after hack! The UK Conservative party's conference app causes a privacy omnishambles! And Facebook (again) has been doing something naughty with the phone numbers you give it for security reasons! Oh, and Maria gets very excited about something to do with Star Trek. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Maria Varmazis. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Boxcryptor: Boxcryptor encrypts your sensitive files and folders in Dropbox, Google Drive, OneDrive and many other cloud storages. It combines the benefits of the most user friendly cloud storage services with the highest security standards worldwide. Encrypt your data right on your device before syncing it to the cloud providers of your choice. Listeners can get a 40% discount on the Boxcryptor Personal License (private use) and Boxcryptor Business (perfect for self-employed) by visiting smashingsecurity.com/boxcryptor Support Smashing Security Links: Our Podcast Awards trophy acceptance video — Even though we didn't actually win, we still thought you might like to see it. Virus Bulletin conference, Montreal — Say "Hi" to Carole if you see her there. Everything that went wrong during Theresa May’s 2017 conference speech - YouTube Die Hard on the One Show - Charlie Brooker's Weekly Wipe - YouTube Conservative Party conference app reveals MPs' numbers - BBC News The Tories Say They Were "Let Down" By A Conference App Platform After It Allowed Access To The Personal Numbers Of Hundreds Of MPs Conference apps are crap and (mostly) pointless Security Update – Facebook Newsroom The Facebook Security Meltdown Exposes Way More Sites Than Facebook Investigating sources of PII used in Facebook’s targeted advertising (PDF) — Research from Northeastern University. Facebook Is Giving Advertisers Access to Your Shadow Contact Information You Gave Facebook Your Number For Security. They Used It For Ads — The EFF is not impressed. The The One Show Show on iTunes manwhohasitall (@manwhohasitall) on Twitter Tiburn Enterprise Star Trek PC at Lenovo Tech World 2018 - YouTube Lenovo Sets Computer to Stun, Unveils Star Trek Enterprise PC Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 26, 2018 · 44 min

    097: Dash cam surveillance, robocall plague, and Zoho woe

    Why was Zoho's website taken offline by its own domain registrar? How are dash cams making you less secure? And why are robocalls on the rise in the United States? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Dave Bittner. Sponsored By: MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING Support Smashing Security Links: Update on Zoho Services Disruption - Zoho Blog Zoho CEO Sridhar Vembu asks for help on Twitter Whoa – oh no, Zoho: Domain name no-show deals CRM biz, 40m punters a crushing blow Domain registrar oversteps taking down Zoho domain, impacts over 30Mil users Blackvue Dash-Cams Broadcasting Live Video and GPS of Your Car PUBLICLY by DEFAULT! - YouTube Tim Woodruff's tweet about BlackVue dash cams Yes, It’s Bad. Robocalls, and Their Scams, Are Surging YouMail - Robocall Index 4.2 Billion Robocalls in August Set All-Time Record for YouMail Robocall Index Does Local Presence Dialing Really Work? National Do Not Call Registry The Robocall Nightmare Is Getting Worse US Court Finds Anti-Robocall Rule Made Nearly Every Smartphone User a Criminal Stop Unwanted Robocalls and Texts - FCC Leatherman Micra 10-in-1 Multi-Tool Techmoan - YouTube The Guild of Ambience - YouTube Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 19, 2018 · 33 min

    096: Bribing Amazon staff, and blinking deepfakes

    Amazon staff are being bribed to delete negative reviews and leak data, deepfakes are getting more dangerous, an update on John McAfee's bitcoin bet, and our guest gets a shock... All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week (for a while at least) by David Bisson. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: David Bisson. Sponsored By: Boxcryptor: Boxcryptor encrypts your sensitive files and folders in Dropbox, Google Drive, OneDrive and many other cloud storages. It combines the benefits of the most user friendly cloud storage services with the highest security standards worldwide. Encrypt your data right on your device before syncing it to the cloud providers of your choice. Listeners can get a 40% discount on the Boxcryptor Personal License (private use) and Boxcryptor Business (perfect for self-employed) by visiting smashingsecurity.com/boxcryptor Support Smashing Security Links: 'Pull your finger out' - the phrase's meaning and origin Amazon Investigates Employees Leaking Data for Bribes - WSJ Amazon staff said to be taking bribes to leak data Crooked firms bribe customers with free gifts to leave fake reviews Smashing Security 063: Carole's back! (where Maria Varmazis discusses deepfakes) Carnegie Mellon Researchers Develop New Deepfake Method Transferring One Video Into the Style of Another - YouTube The Secret to Detecting Deep Fakes Is in the Eye Blinks Reddit bans ‘deepfakes’ AI porn communities Bitcoin Price Prediction Tracker Serious Eats: The Destination for Delicious JoyofBaking.com How to cook the perfect ... Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 12, 2018 · 42 min

    095: British Airways hack, Mac apps steal browser history, and one person has 285,000 texts leaked

    Malicious script is being blamed for the British Airways hack, Trend Micro's apps are booted out of the Mac App Store for snaffling private data, and Paul Manafort's daughter wants Twitter to remove a link. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by David Emm of Kaspersky Lab. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: David Emm. Sponsored By: MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING Support Smashing Security Links: A Deceitful 'Doctor' in the Mac App Store Alert: Adware Doctor stealing your files - YouTube video Apps that steal users' browser histories kicked out of the Mac App store Trend Micro apologises after Mac apps found scooping up users' browser history British Airways hacked - customer data and details of 380,000 card payments stolen The British Airways Breach: How Magecart Claimed 380,000 Victims British Airways hack: Infosec experts finger third-party scripts on payment pages Law firm launches £500 million group action over British Airways hack British Airways Fly The Flag We'll Take More Care Of You 1979 UK Advert - YouTube Hacked texts from family of former Trump campaign manager surface on the dark web Manafort's Daughter's Lawyers Pressured Twitter to Delete Links to Hacked Text Messages Wikileaks Refused To Publish Manafort Family Texts, So Someone Else Did AirHelp How Employing Autistic People Can Help Stop Cyber-Attacks McFadden's Cold War (@Coldwar_Steve) on Twitter When Phil Mitchell met Trump: Coldwar Steve and his Brexit Britain mashups Noel Edmonds - Wikipedia Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 5, 2018 · 52 min

    094: Rogue browser extensions, Twitter presence, and how to cheat in exams

    What's the danger when browser extensions go bad? Is Twitter sharing your online status a boon for stalkers? And which of the show's hosts is going to admit to cheating in their exams? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by technology journalist David McClelland. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: David McClelland. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps. But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users. Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: MEGA.nz Chrome extension caught stealing passwords, cryptocurrency private keys Security warnings for MEGA Chrome extension users Twitter testing new feature that reveals when you're online... Who other than stalkers actually wants this? Giving social networking back to you - The Mastodon Project Graham Cluley on Mastodon Photomath - Camera calculator Technology Gives Students Innovative Tools for Cheating Students’ cheating takes a high-tech turn Microsoft Education: Take a Test - YouTube Required to install school malware on my personal computer - Reddit The Lord of the Rings (1978 film) - Wikipedia Rotoscoping - Wikipedia Tower – Official Trailer - YouTube Tower - Netflix Cone - Live Color Picker The dress - Wikipedia A professor and his son-in-law came up with a brilliant invention to slash water use by 98% – Ikea is already a partner Altered:Company Altered:Nozzle - YouTube Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 29, 2018 · 37 min

    093: Abandoned domains and dating app dangers

    How do fraudsters exploit abandoned domains to steal your company's secrets? How can you better protect your privacy when looking for love online? And who has the longest arms in the animal kingdom? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who were joined briefly by a man in a wind tunnel for this episode. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING Support Smashing Security Links: What do the drsolomon.com and sands.co.uk domains look like now? Hacking law firms with abandoned domain names Fraudsters Can Access Sensitive Information from Abandoned Domains Have I Been Pwned: Domain search John and Lorena Bobbitt He Used Tinder to Hunt the Women He Raped and Killed, Police Say Missing Paperwork Got Him Out of Jail. Then, Police Say, He Raped and Killed Man jailed after attempting to rob man he met on dating app Search for images with reverse image search Swytch lets you use up to five 'burner' UK phone numbers from a single device Smashing Security 072: Why are firms so cr*p with our private data? A Hacker's Guide to Protecting Your Privacy While Dating How to Protect Your Privacy While Online Dating Gibbons have the longest arms relative to body size of any primate Bomb Chicken Teaser Trailer - YouTube Bomb Chicken for Nintendo Switch Fortnite fury over how Google handled its security hole The Godless Spellchecker podcast Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 22, 2018 · 51 min

    092: Hacky sack hack hack

    Is your used car still connected to its old owner? Just how did Apple manage to identify the teenager hacker who stole 90GB of the firm's files? And why on earth would a firm of lawyers start producing pornographic videos? You'll be surprised by the answers! All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Paul Ducklin. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Paul Ducklin. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: Connected car data handover headache: There's no quick fix... and it's NOT just Land Rovers Shock Land Rover Discovery: Sellers could meddle with connected cars if not unbound The hidden data danger of the ‘Connected’ car Your BMW or Merc may also be at risk of being hacked, because of your iOS app Samy, the MySpace worm written by Samy Kamkar Apple hacked by 16-year-old who “dreamed” of working for firm Melbourne teen hacked into Apple's secure computer network, court told Prenda Law stories at Techdirt Minneapolis lawyer pleads guilty to federal fraud, money laundering charges in porn troll scheme Cybercrime Investigations podcast with Geoff White Flash Drives for Freedom Final Space Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 15, 2018 · 48 min

    091: Sextortion, Las Vegas hotels, and Alex Jones

    Just how did sextortionists get (some) of the digits in your phone number? Why are some hackers saying they won't be going to DEF CON in Las Vegas anymore? And should Alex Jones from InfoWars be banned from Twitter? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Maria Varmazis. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Maria Varmazis. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING Support Smashing Security Links: The Podcast Awards - The People's Choice Sex extortion emails now quoting part of their victim's phone number New Extortion Tricks: Now Including Your (Partial) Phone Number! In post-massacre Vegas, security policies clash with privacy values Katie Moussouris tweets about her Las Vegas hotel experience Video Shows Hotel Security at DEF CON Joking About Posting Photos of Guests' Belongings to Snapchat Google Spectre whizz kicked out of Caesars, blocked from DEF CON over hack 'attack' tweet Open letter to the Hacker Community from DEF CON's Head of Security Alex Jones banned from YouTube, Facebook, and Apple, explained Facebook, Apple, YouTube and Spotify ban Infowars' Alex Jones Now even YouPorn has banned Alex Jones, but he’s still on Twitter Twitter temporarily blocks Alex Jones from tweeting The Twitter Rules Giving social networking back to you - The Mastodon Project Charlottesville: Why one man is suing Alex Jones for defamation Shannon Coulter tweets about blocking Fortune 500 companies until Alex Jones is banned from Twitter lichess.org - Free Online Chess Magnus Carlsen playing as Dr Drunkenstein - YouTube Octopath Traveler for Nintendo Switch Alex Jones Rants as an Indie Folk Song - YouTube Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 8, 2018 · 36 min

    090: Fortnite for Android, and the FCC's DDoS BS

    Fortnite players are told they'll have to disable a security setting on Android, the FCC finally admits that it wasn't hit by a DDoS attack, and Verizon's VPN smallprint raises privacy concerns. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by David Bisson. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: David Bisson. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: You'll have to disable a recommended Android security setting to install Fortnite Fortnite is putting users at risk, to prove a point about Google's Android monopoly Introducing Android 9 Pie Safe-WiFi Wireless Private Network - Verizon Wireless Verizon Didn’t Bother to Write a Privacy Policy for its ‘Privacy Protecting’ VPN Terms of Service for the Verizon Safe Wi Fi App McAfee Privacy Notice Verizon customers can sue ad company over “zombie” cookies, judges rule Ajit Pai blames Obama administration over FCC DDoS attack that didn't happen Inside the FCC's risky IT overhaul The Triceratops Who Loved Me: A Primal Urges Extreme Fantasy - Amazon A Good Movie To Watch Overcooked! 2 for Nintendo Switch Christopher Robin: Winnie the Pooh film denied release in China Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 1, 2018 · 44 min

    089: Data breaches, ransomware, Bitcoin robberies, and typewriters

    Ransomware rears its head again, Dixons Carphone reveals its data breach was almost 1000% worse than they previously thought, a man is accused of stealing five million dollars worth of cryptocurrency through hijacking mobile phones, and a Canadian guy called Norman is rushing to get the typewriters out of storage. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by journalist Geoff White. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Geoff White. Sponsored By: MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: Shipping company’s networks in the Americas crippled by ransomware attack Yahoo addresses used by Cosco following ransomware attack BitPaymer Ransomware Infection Forces Alaskan Town to Use Typewriters for a Week Jim Hagemann Snabe, Maersk chairman, describing their recovery from the NotPetya ransomware - YouTube Dixons Carphone admits hack far bigger than originally thought Dixons Carphone breach statement (June 2018) Dixons Carphone updated breach statement (July 2018) ‘Tell your dad to give us Bitcoin’ How a Hacker Allegedly Stole Millions by Hijacking Phone Numbers Smashing Security 086: Elon Musk submarine scams and 2FA bypass Slow Burn: A Podcast About Watergate Bill Clinton: "I did not have sexual relations with that woman" - YouTube How an Ex-Cop Rigged McDonald’s Monopoly Game and Stole Millions Legion Season 2 Teaser Trailer - YouTube Legion Season 2 - Amazon Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 25, 2018 · 42 min

    088: PayPal’s Venmo app even makes your drug purchases public

    Websites still using HTTP are marked as "not secure" by Chrome, 85,000 Google employees haven't been phished for a year, and if you're buying drugs via PayPal’s Venmo app you should say goodbye to privacy. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Scott Helme. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Theme tune: "Vinyl Memories" by Mikael Manvelyan. Assorted sound effects: AudioBlocks. Special Guest: Scott Helme. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: Vote for Smashing Security in the podcast awards! Smashing Security 039: Woah - are we talking to a cyborg? Google: Security Keys Neutralized Employee Phishing Yubico Less than 10% of Gmail users have enabled two-factor authentication Google's Advanced Protection Program What is Google’s Advanced Protection Program? - YouTube Two-factor authentication versus two-step verification One small step for a browser, one giant leap for web security! Chrome browser flags Daily Mail and other sites as 'not secure' How to change Chrome's settings to be more in-your-face when you visit an unencrypted HTTP site Public by Default - Venmo Stories of 2017 Why I Blasted Your “Drug” Deals on Twitter PayPal's Venmo App Exposes Most Transactions via Its API Reporting Trump's First Year: The Fourth Estate - BBC Why No HTTPS? The World's Largest Websites Not Redirecting Insecure Requests to HTTPS Scott Helme tweets about NewsNow's support for both HTTP and HTTPS NewsNow.co.uk Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 18, 2018 · 44 min

    087: How Russia hacked the US election

    Regardless of whether Donald Trump believes Russia hacked the Democrats in the run-up to the US Presidential election or not, we explain how they did it. And Carole explores some of the creepier things being done in the name of surveillance. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Sponsored By: MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: Vote for Smashing Security in the podcast awards! Scammers strike as Elon Musk retracts vile Twitter accusation against cave rescuer Donald Trump 'encourages Russia to hack Clinton emails' - YouTube Indictment against 12 Russian hackers Bears in the Midst: Intrusion into the Democratic National Committee This is the email that hacked Hillary Clinton’s campaign chief Guccifer 2.0’s schoolboy error reveals he’s hacking from Moscow Amazon Rekognition – Video and Image Amazon shareholders demand company stop selling facial recognition technology to governments Metropolitan Police's facial recognition technology 98% inaccurate, figures show Looking to Listen: Audio-Visual Speech Separation California Shopping Centers Are Spying for an ICE Contractor California passes landmark privacy legislation Walmart's Newly Patented Technology For Eavesdropping On Workers Presents Privacy Concerns Find a track - BBC Music The Staircase - Netflix Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 11, 2018 · 39 min

    086: Elon Musk submarine scams and 2FA bypass

    The world has been gripped with the story of that soccer team, those poor boys... but enough about England's World Cup hopes being dashed, it's time for another episode of "Smashing Security". Crypto scamming Thai cave rescue scoundrels! $25 million to make anti-fake news videos! TimeHop data breach! Phone number port out scams! All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by the author of "Social media is bullshit", B J Mendelson. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: B J Mendelson. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: Vote for "Smashing Security" in the Podcast Awards Thai Cave rescue scammers pose as Elon Musk Why was Elon Musk at the Thai cave rescue? The full story of Thailand’s extraordinary cave rescue Bad Checks: Twitter's Identity Crisis Is Costing Users More Than Bitcoin YouTube Pledges $25 Million to Help Fight Fake News Timehop security incident what3words | Addressing the world Justified Season 1 Promo / trailer - YouTube Dear Joan and Jericha: agony aunts of the most ribald kind Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jul 4, 2018 · 37 min

    085: Doctor Who, Facebook patents, and Bob's Burgers

    Doctor Who's TARDIS has sprung a data leak, Facebook's creepy patents are unmasked, and an app to keep women safe on dates has surprising origins. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Maria Varmazis. Sponsored By: MetaCompliance: People are the key to minimizing your Cyber Security risk posture. MetaCompliance makes this easier by providing a single platform for Phishing, Cybersecurity training, Policy, Privacy and Incident management.Go to smashingsecurity.com/metacompliance Promo Code: SMASHING LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: BBC Goes to Court to Identify 'Doctor Who' Leaker Doctor Who episodes leak online - should you download them? Reality Winner pleads guilty after being unmasked by microdots German researchers defeat printers' doc-tracking dots Are you happy with this technology that Facebook’s developing? Emma Sayle - CEO. Wife. Mother. Liberator. Feminist. Killing Kittens Parties Liberating Women Worldwide Kate Middleton's friend holds orgies in sharia hotel Safe Date – Stay Safe And Get Peace Of Mind When Dating Killing Kittens sex party founder hopes new DateSafe app can improve women's safety GeoGuessr - Let's explore the world! Playground Buddy - Helping Families Find Playgrounds Blue Apron is releasing a smart, strong, sensual Bob’s Burgers meal kit Every Burger From Bob's Burgers Ranked Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 27, 2018 · 33 min

    084: No! My voice is not my password

    Who's been collecting the voice prints of millions of people saying "My voice is my password"? Why has it become tougher for law enforcement to scoop up cellphone data? And who's been turning up your central heating? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by John Hawes of AMTSO. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: John Hawes. Sponsored By: VirusTotal: VirusTotal Intelligence is one of the world’s largest malware intelligence services. Security professionals rely on it to better understand the effects of malware in enterprise networks.Find out more at https://www.virustotal.com/learn Support Smashing Security Links: Voice ID showcases latest digital development for HMRC customers HMRC takes 5 million taxpayers’ Voice IDs without consent – Big Brother Watch UK taxman has amassed voice profiles of 5.1 million taxpayers BBC fools HSBC voice recognition security system Knock down ginger — What Graham meant to say when he referred to "Postman's knock" Victory! Supreme Court Says Fourth Amendment Applies to Cell Phone Tracking Thermostats, Locks and Lights: Digital Tools of Domestic Abuse Safety Net: the National Safe & Strategic Technology Project US Tech Safety hotlines UK National Domestic Violence Helpline Worldwide helpline directory Music-Map - The Tourist Map of Music Del Amitri Ron Sexsmith BBC Radio 4 - Short Cuts Tandoori Lambchop Sent to Space (Meatspace) - YouTube Adam Buxton podcast with Charlie Brooker Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 20, 2018 · 27 min

    083: Fake email derails clarinetist's dream

    Hell hath no fury like a jealous clarinetist's girlfriend! Your Google ChromeCast could be letting stalkers find out where you live! And why on earth is Graham recommending people write their passwords down in a book!? Join computer security veterans Graham Cluley and Carole Theriault on a shorter episode of the "Smashing Security" podcast than normal, as they're awfully busy touring up and down the country doing things in front of live audiences. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: View from Carole's hotel room in Manchester Eric Abramovitz plays the clarinet - YouTube McGill music student awarded $350,000 after girlfriend stalls career Eric Abramovitz vs Jennifer (Jooyeon) Lee - Court documents Google’s Newest Feature: Find My Home Steve Gibson's Three Router Solution to IOT Insecurity Google Removes 'Don't Be Evil' Clause From Its Code of Conduct Password Minder Infomercial - YouTube LaDonna - This American Life Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 13, 2018 · 39 min

    082: World Cup cybersecurity, crypto crashes, and a bang of a password fail

    Coinrail cryptocurrency exchange goes offline after hack, Russia appears to be 'live testing' cyber attacks, and Florida stopped running background checks on gun buyers because of forgotten password. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's football-mad John Leyden. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: John Leyden. Sponsored By: VirusTotal: VirusTotal Intelligence is one of the world’s largest malware intelligence services. Security professionals rely on it to better understand the effects of malware in enterprise networks. Find out more at https://www.virustotal.com/learn Support Smashing Security Links: Bitcoin price takes a dive after another cryptocurrency exchange hack Mikko Hypponen on Twitter explains why cryptocurrency exchanges get hacked $1m by 2020: John McAfee will still ‘eat his own d*ck’ if he’s wrong about Bitcoin 2018 FIFA World Cup Russia Russia appears to be 'live testing' cyber attacks - Former UK spy boss Robert Hannigan French TV network taken off air after attack by pro-ISIS hackers TV5Monde attack proves hacking attribution is very difficult TV station exposé its own passwords on l'air. A Franglais report VPNFilter botnet has hacked 500,000 routers. Reboot and patch now! VPNFilter exploits endpoints, targets new devices Florida Didn't Run FBI Background Checks on Gun Buyers for a Year Because of a Forgotten Login Adam Putnam’s office stopped reviewing concealed weapons background checks for a year because it couldn’t log in Background Check Procedures: State by State Department of Agriculture investigative report Is It Normal? What is the Camino de Santiago? Eating and Drinking on the Camino de Santiago Pulperia Ezequiel - Great place to eat pulpo (octopus) Britannica Insights Is a Chrome Extension to Fix False Google Results Britannica Insights - Chrome Web Store Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Jun 6, 2018 · 25 min

    081: Hacker no-hopers, Wessex Water has a word, and we win an award

    The mastermind behind the Owari botnet doesn't seem to have learnt anything from his victims, and someone at Wessex Water forgets to remove an embarrassing sentence from a letter sent to customers... All this and much much more is discussed in the latest edition of the award-winning "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who recorded a shorter podcast than normal this week as they were far too busy recovering from receiving the best security podcast award! Follow the award-winning show on Twitter at @SmashinSecurity, or visit our website for more award-winning episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the award-winning episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Sponsored By: LastPass: LastPass Enterprise simplifies password management for companies of every size, with the right tools to secure your business with centralized control of employee passwords and apps.But, LastPass isn’t just for enterprises, it’s an equally great solution for business teams, families and single users.Go to lastpass.com/smashing to see why LastPass is the trusted enterprise password manager of over 33 thousand businesses. Support Smashing Security Links: We did it! Smashing Security’s Carole celebrates with the best security podcast award!… Full results from the Infosec18 European Blogger Awards Hacker Fail: IoT botnet command and control server accessible via default credentials Pwn goal: Hackers used the username root, password root for botnet control database login Tweet by Vesselin Bontchev Mailshot meltdown as Wessex Water gets sweary about a poor chap called Tom Apology from Wessex Water on Twitter Excel pivot table data leak leads to £120,000 fine for London council Smashing Security review criticises Graham's enunciation Simplenote Standard Notes Evil Genius trailer - YouTube Case 81: Brian Wells - Casefile Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • May 30, 2018 · 34 min

    080: Country bans Facebook, eavesdropping Alexa, and PornHub VPN

    The country of Papua New Guinea is planning a month-long nationwide ban of Facebook, PornHub wants to keep your online activities more private, and Amazon Alexa forwards a married couple's private conversation to a random contact. All this and much much more is discussed in the latest 100% GDPR-compliant edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by ESET's Tommi Uhlemann. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Tommi Uhlemann. Sponsored By: VirusTotal: VirusTotal Intelligence is one of the world’s largest malware intelligence services. Security professionals rely on it to better understand the effects of malware in enterprise networks.Find out more at https://www.virustotal.com/learn Support Smashing Security Links: Papua New Guinea to ban Facebook for a month Shutting down facebook in PNG is a reality Pornhub launches VPNhub, a VPN service with free, unlimited bandwidth Pornhub hack: Hackers hijacked ads with malware in year-long attack Be cautious, free VPNs are selling your data to 3rd parties How to hear (and delete) every conversation your Amazon Alexa has recorded Woman says her Amazon device recorded private conversation, sent it out to random contact Smashing Security 044: Bonus behind the scenes - shower time Here's How To Deactivate Alexa Calling After You Sign Up Passive Aggressive Passwords Ebaybae on Instagram Brave Browser The Complete Privacy & Security Podcast discusses the Brave browser See Smashing Security LIVE on tour in the UK Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy