Artwork for Smashing Security
Technology

Smashing Security

Graham Cluley

Stories from the world of hacking, cybersecurity, and rogue AI.

Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.

Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.

Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.

New episodes released at 7pm EST every Wednesday (midnight UK).

  • 480 episodes
  • Updated Wednesday

Episodes480

  • Jan 3, 2018 · 26 min

    059: An intro to Bitcoin and Blockchain

    In this special "splinter" episode of the "Smashing Security" podcast we take a look at Bitcoin and Blockchain. What's all the fuss about cryptocurrencies? How can you protect your Bitcoin wallet? And how does the Blockchain work? Lots of questions, and Graham offers to sell his family. Listen to the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Peter Ullrich of the "Explain Blockchain" podcast. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Peter Ullrich. Support Smashing Security Links: Bitcoin Resources from Jameson Lopp Mastering Bitcoin book by Andreas Antonopoulos Explain Bitcoin Like I’m Five Bitcoin Exchanges Silk Road's Ross Ulbricht sentenced to life in prison, without parole Bitcoin Energy Consumption Index Jaxx mobile cryptocurrency wallet Trezor hardware Bitcoin wallet "Explain Blockchain" podcast Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Dec 20, 2017 · 42 min

    058: Face ID, Firefox, and Windows SNAFUs, plus Bitcoin FOMO

    Is Face ID racist? Has Mr Robot infected your Firefox browser? Has Microsoft pushed a buggy password manager onto your Windows PC? All this and much much more is discussed in the special first birthday edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by original co-host Vanja Švajcer. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Vanja Švajcer. Sponsored By: OneLogin: OneLogin provides Single Sign On for customers like Airbus, Royal Mail, BSI, and Dun and Bradstreet. With hundreds of apps being used in the typical workplace, and the average user having to remember about 40 different passwords, we all know that if we don't have a product to remember passwords they end up in spreadsheets, stored in emails, or left on post-it notes. And that is a security nightmare. OneLogin allows IT to say which users have access to which applications at what time and also enforce two factor authentication. So even if credentials are compromised, hackers can’t get access to those corporate services. And, by connecting to Active Directory, access to all of these services is de-provisioned as soon as someone leaves the organisation.Learn more, and download a free guide to identity access management, at www.smashingsecurity.com/onelogin Support Smashing Security Links: Smashing Security #001: "One cup, two hotel guests" - YouTube Mozilla Slipped a ‘Mr. Robot’-Promo Plugin into Firefox and Users Are Pissed This Looking Glass/Mr Robot sh*t really p*sses me off - Reddit Unknown Mozilla dev addon "Looking Glass 1.0.3" on browser... or is it just malware? - Firefox Support Forum Update: Looking Glass Add-on Bono and Tim Cook - YouTube How to remove Bono and U2 from YOUR f*#!ing iPhone - YouTube For 8 days Windows bundled a password manager with a critical plugin flaw Disabling Windows 10 Consumer Experience How Windows 10 Pro installs unwanted apps (Candy Crush) and how to stop it Troy Hunt explains why Face ID Stinks - YouTube 10-year-old kid succeeds in unlocking his mum’s iPhone X, with just a glance Apple's Face ID tech can't tell two Chinese women apart First iPhone X fondlers struggle to admit that Face ID sort of sucks Erase 2017 from your brain. Face ID never happened. The Notch is an illusion How I Learned to Deal with My Bitcoin FOMO Bitcoin FOMO Calculator Oh, My Coins! - Database Of Lost Crypto Assets Missing: hard drive containing Bitcoins worth £4m in Newport landfill site Is Bulgaria sitting on $3.5 BILLION worth of Bitcoin seized from criminals? WeCroak on the App Store Nose Dance! The Original Nose Twerking Miss Santa Face Paint! - YouTube Christmas Nose Twerk! Grinch & Max! - YouTube Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Dec 13, 2017 · 40 min

    057: Mikko Hyppönen - live from the sauna - talks Bitcoin security

    How to protect yourself from Bitcoin hackers, why you should think twice before giving Amazon the keys to your house, and how a private investigator tried to hack Donald Trump's tax returns. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mikko Hyppönen from F-Secure. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Mikko Hyppönen. Sponsored By: OneLogin: OneLogin provides Single Sign On for customers like Airbus, Royal Mail, BSI, and Dun and Bradstreet. With hundreds of apps being used in the typical workplace, and the average user having to remember about 40 different passwords, we all know that if we don't have a product to remember passwords they end up in spreadsheets, stored in emails, or left on post-it notes. And that is a security nightmare. OneLogin allows IT to say which users have access to which applications at what time and also enforce two factor authentication. So even if credentials are compromised, hackers can’t get access to those corporate services. And, by connecting to Active Directory, access to all of these services is de-provisioned as soon as someone leaves the organisation.Learn more, and download a free guide to identity access management, at www.smashingsecurity.com/onelogin NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: Mikko Hypponen has his ponytail hair cut. - YouTube Cyber Security Sauna podcast Louisiana man admits misusing Trump's Social Security number One of Your Equifax Hack Protections Expires Soon How to protect yourself in the wake of the Equifax data breach Larry Flynt offers $10 million for info that could get Trump impeached Cryptocurrency Market Capitalizations Physical Bitcoins from Denarium TREZOR Bitcoin Wallet Ledger Wallet Amazon drivers forced to deliver 200 parcels a day with no time for toilet breaks while earning less than minimum wage Amazon wants a key to your house. I did it. I regretted it Black Friday Delivery THIEVES: 1 in 5 UK packages missing as thefts SURGE before Christmas Code.org The Arcade Blogger The Happiness of the Katakuris 'Rare Exports: A Christmas Tale' Trailer - YouTube Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Dec 6, 2017 · 41 min

    056: Peeping Toms, prison hacks, and parliamentary passwords

    Why you should check your Airbnb for hidden cameras, a hacker attempts a different kind of jailbreak, and British MPs prove that they really are clueless when it comes to cybersecurity. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who are joined this week by special guest Ian Whalley. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Ian Whalley. Sponsored By: OneLogin: OneLogin provides Single Sign On for customers like Airbus, Royal Mail, BSI, and Dun and Bradstreet. With hundreds of apps being used in the typical workplace, and the average user having to remember about 40 different passwords, we all know that if we don't have a product to remember passwords they end up in spreadsheets, stored in emails, or left on post-it notes. And that is a security nightmare. OneLogin allows IT to say which users have access to which applications at what time and also enforce two factor authentication. So even if credentials are compromised, hackers can’t get access to those corporate services. And, by connecting to Active Directory, access to all of these services is de-provisioned as soon as someone leaves the organisation.Learn more, and download a free guide to identity access management, at www.smashingsecurity.com/onelogin NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: The lax computer security of British MPs - as detailed in their own tweets Nadine Dorries MP tweets about sharing her password Hackers attempt to break into UK MPs' email accounts, as Houses of Parliament targeted by cyber attack Now criminals are ringing up British MPs to ask them their passwords Nadine Dorries MP admits she's always shouting out "What's my password?" Will Quince MP admits he leaves his PC unlocked Nadine Dorries reveals all MPs have porn on their PCs Ann Arbor Man Pleads Guilty to Computer Intrusion Case Man Hacks Jail Computer Network to Get Friend Released Early Prison hacker who tried to free friend now likely to join him inside Court documents (PDF) Tweet from Jason Scott Smile, you’re on hidden webcam Airbnb TV! What are Airbnb’s rules about electronic surveillance devices in listings? Colorise Bot (@colorisebot) on Twitter The science behind @Colorisebot The Leftovers Little Alchemy 2 Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 30, 2017 · 28 min

    055: Uber, net neutrality, and website hacks

    Uber covers up a data breach, the noose tightens on net neutrality, and Bulletproof's website spills the data beans. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by umm.. nobody because they didn't arrange a special guest. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Sponsored By: NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: Uber paid hackers $100,000 to keep data breach quiet Bulletproof breach notification letter to customers (PDF) Bulletproof Coffee lacks bulletproof security: Nerd brain juice biz hacked, cards gulped Net Neutrality: What You Need to Know Now Racist, threatening attacks on FCC Chair Ajit Pai won't save net neutrality Americans are spending Thanksgiving fighting for net neutrality An update on the fight for the free and open internet Google YouTube Keyboard Shortcuts Tom Baker returns to finish shelved Doctor Who episodes penned by Douglas Adams Bitcoin: How Does it Work? (Roger Ver Interview) Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 29, 2017 · 8 min

    054: A great big fat macOS bug

    Yes, you can log into macOS High Sierra's root account with no password. In this special "emergency" edition of the podcast computer security veterans Graham Cluley and Carole Theriault discuss the breaking news of a serious Apple macOS bug that allows anyone to log into your Mac with root admin rights, without having to enter a password. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Support Smashing Security Links: Tweet by Lemi Ergin Huge MacOS bug lets anyone login as root without a password: what you need to know How to enable the root user on your Mac or change your root password - Apple Support Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 22, 2017 · 40 min

    053: Game of Thrones, a major Amazon cloud leak, and web tracking gone crazy

    The FBI think they've identified the HBO hacker, the US military have been caught with a leaky bucket, and web tracking has just got scarier than ever. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Iain Thomson. Support Smashing Security Links: Uber paid hackers $100,000 to keep data breach quiet HBO offered its hackers $250,000 after attack, leaked email claims Game of Thrones stars’ personal phone numbers leaked, as HBO hackers attempt to extort ransom Smashing Security 037: Boobs, dragons and data breaches Iranian ‘Game of Thrones’ Hacker Demanded $6 Million Bitcoin Ransom From HBO, Feds Say Sealed Indictment Over 400 of the World's Most Popular Websites Record Your Every Keystroke, Princeton Researchers Find No boundaries: Exfiltration of personal data by session-replay scripts Data release: list of websites that have third-party “session replay” scripts The dark side of Replay Sessions that record your every move online Shark Attack 3 - That Famous Line (NSFW!) Father Ted: Dougal the Milkman & the Booby Trap Paddington 2 - the movie Paddington Bear, Singin' in the rain Baby Driver - the movie Baby Driver - 6-Minute Opening Clip Mathmos Lava Lamps Tom Scott's How Lava Lamps Keep the Internet Secure Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 15, 2017 · 39 min

    052: Facebook tackles vengeful scumbags, and a sex toy privacy boob

    Is your dildo listening to you? Do you trust Facebook with your most intimate photos? And just how did a vengeful DDoSer come up with that nickname? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who are joined this week by special guest John Hawes. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: John Hawes. Sponsored By: NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: Give Facebook your nude pics to tackle revenge porn The Facts: Non-Consensual Intimate Image Pilot Using Technology to Protect Intimate Images and Help Build a Safe Community Sex toy company admits to recording users' remote sex sessions, calls it a 'minor bug' PSA: Lovense remote control vibrator app recording "private" sessions without express permission Hack a BT Low Energy (BLE) butt plug Man Uses DDoS-for-Hire Services to Attack Former Employer, Taunts Firm via Email Google's Inactive Account Manager Lee Valley Tools - Woodworking Tools, Gardening Tools, Hardware Snap Circuits What is Snap Circuits? - YouTube Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 9, 2017 · 41 min

    051: Robots, romance, passwords, and CrunchyRoll

    Passwords are under the microscope again, CrunchyRoll leads anime fans to malware, a sexy robot gains Saudi citizenship, and Carole begins her career as an agony aunt. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who are joined this week by special guest Maria Varmazis. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Maria Varmazis. Sponsored By: NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: LastPass reveals the threats posed by passwords in the workplace One in five security professionals still uses paper to manage privileged passwords Passwords - a Smashing Security splinter PSA : Don't enter crunchyroll.com at the moment, it seems they've been hacked Blaze's Security Blog: CrunchyRoll hack delivers malware Crunchyroll.com update Meet Sophia: The first robot declared a citizen by Saudi Arabia - YouTube Hot Robot At SXSW Says She Wants To Destroy Humans Saudi Arabia has a new citizen: Sophia the robot. But what does that even mean? Japan Has Just Granted Residency To An AI Bot In A World First Mythbuster seeks cash for roller skates to wear in virtual reality Jamie Hyneman's Electric Shoes - YouTube Swear Trek (@swear_trek) on Twitter Swear Who (@swear_who) on Twitter Stranger Things: The Game on the iOS App Store Stranger Things: The Game on Google Play Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Nov 2, 2017 · 42 min

    050: MailChimp, Piers Morgan, and The Dark Overlord

    There's little time to celebrate our 50th episode, because there are rants to be had about MailChimp's switch to single opt-in, Graham upsets Piers Morgan on Twitter, and the Dark Overlord hacking gang are up to some pretty horrid tricks. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who didn't bother to organise a special guest this week. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Sponsored By: NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Enterskekt: Entersekt develops authentication and mobile security solutions that make the internet a safer place to bank and shop. Join Entersekt's webinar which promises to tell you EVERYTHING you need to know about "The secret key to PSD2 compliance" by visiting https://www.smashingsecurity.com/entersekt Support Smashing Security Links: Graham declines to appear on Good Morning Britain Piers Morgan responds to Graham Piers Morgan tells Leveson: Daily Mirror did not hack phones Piers Morgan told me how to hack a phone, says Jeremy Paxman Daily Mirror owners must pay £1.2m to celebrity phone-hacking victims Wendi Deng protects Rupert Murdoch from custard pie I can no longer recommend MailChimp Mailchimp backtracks on all their recommendations, enforcing single opt-in Massive email bombs target government email addresses Smashing Security: GDPR - The good and the bad Another Hollywood studio is hacked by The Dark Overlord Hackers hit plastic surgery, threaten to release patient list and photographs ‘Dark Overlord’ Hackers Text Death Threats to Students, Then Dump Voicemails From Victims "Saved you a click" on Reddit Google CEO to fix burger emoji after heated debate cooks up on Twitter "Get Me Roger Stone" Pencil Grip Ignite Elite - Rechargeable USB Flameless Lighter Smashing Security: Bonus behind the scenes - shower time Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 25, 2017 · 44 min

    049: Hacking funeral homes, crypto mining websites, and careful with that hairspray

    Scammers show a lack of imagination after hacking a funeral home, more websites are secretly stealing visitors' resources to mine for cryptocurrency, and everyone is very confused about the USA's airline laptop ban. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's John Leyden. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: John Leyden. Sponsored By: Enterskekt: Entersekt develops authentication and mobile security solutions that make the internet a safer place to bank and shop. Join Entersekt's webinar which promises to tell you EVERYTHING you need to know about "The secret key to PSD2 compliance" by visiting https://www.smashingsecurity.com/entersekt NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: Local funeral home gets hacked in the middle of the night leaving employees without access Local business' Yahoo! account hacked Smashing Security: 014: Protecting webmail Stealth web crypto-cash miner Coin Hive back to the drawing board as blockers move in - The Register Cryptocurrency mining affects over 500 million people. And they have no idea it is happening. Laptops and tablets have been banned from being used on 56 routes to the US Laptop ban: How it works, what devices are forbidden on flights Questions and answers on proposed ban on laptops in luggage - The Washington Post Inspire Candle - Twelve South BBC Two - The Detectives: Murder on the Streets This Chrome extension blocks audio and video autoplay on any website Autoplay blocking is coming to Chrome Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 18, 2017 · 33 min

    048: KRACK, North Korea, and an 18th century cyber attack

    KRACK! Has the Wi-Fi vulnerability got you worried? Did North Korea hack a British TV company to prevent a "slanderous farce" from being made? And what have Dutch police learnt from Pokémon? All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Virus Bulletin's Martijn Grooten. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Martijn Grooten. Sponsored By: NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: UK TV drama about North Korea hit by cyber-attack - BBC News The World Once Laughed at North Korean Cyberpower. No More. - The New York Times Naked Attraction: Channel 4 show returns and viewers observe 'missing detail' on female contestants | The Independent 'Krack' wi-fi breach means every modern network and device is vulnerable to hack, researcher says - The Independent KRACK Attacks: Breaking WPA2 KRACK Wi-Fi attack - the rules haven't changed Policing in the future uses citizen detectives, Pokémon Go-like app Politiepokémon op komst - Telegraaf.nl Blokus - Wikipedia Blokee - Inspired by Blokus - Online Board Game The crooked timber of humanity - 1843 Magazine The Victorian Internet - tomstandage.com Watch 100 people try to eat durian, a fruit that smells like hot garbage Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 11, 2017 · 40 min

    047: Kaspersky, AI, and a well-handled data breach

    America turns the heat up on Kaspersky anti-virus, Disqus announces a data breach, Elon Musk plans a bolthole on Mars to escape our robot overlords, and Graham gets to play chess with Garry Kasparov. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by technology journalist and broadcaster David McClelland. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: David McClelland. Sponsored By: NetSparker: NetSparker is a web application security scanner that can automatically find security flaws in your website and fix them before hackers can exploit them. If you want to automatically check your web applications for cross site scripting, SQL Injection & other vulnerabilities and coding errors that can leave you and your business exposed to malicious hacker attacks, then you need NetSparker.Download a free demo now. Support Smashing Security Links: Altered Images - Happy Birthday Graham met Garry Kasparov Graham about to lose a game of chess to Garry Kasparov Sign in Office Depot store (via @gadievron on Twitter) Kaspersky accused of close ties to sauna-loving Russian spies Russian Hackers Stole NSA Data on U.S. Cyber Defense - WSJ What is Kaspersky's role in NSA data theft? Here are three likely outcomes - ZDNet Eugene Kaspersky says U.S. government can examine his company's source code McAfee joins the anti-Kaspersky witch hunt in shitty attempt to sell a few boxes Disqus security alert: User info breach Disqus reveals data breach, but wins points for transparency – HOTforSecurity It's 4PM on Friday, almost time to log off and, oh look, Disqus says it's been hacked - The Register A World Leader in AI Just Established an Ethics Committee for Artificial Intelligence The Artificial Intelligence Revolution: Part 1 - Wait But Why Open Letter on Autonomous Weapons - Future of Life Institute Sam Harris: Can we build AI without losing control over it? - TED Talk Elon Musk’s Billion-Dollar Crusade to Stop the A.I. Apocalypse - Vanity Fair Artificial Intelligence Is Our Future. But Will It Save Or Destroy Humanity? Artificial Intelligence - Internet Encyclopedia of Philosophy Google's AI Chief Is 'Definitely Not Worried About the AI Apocalypse Elon Musk is wrong. The AI singularity won't kill us all Robots - Flight of the Conchords "SEAGULLS! (Stop It Now)" -- A Bad Lip Reading of The Empire Strikes Back - YouTube David Stranack's post on the Smashing Security Facebook group TimeScapes by Nigel Stanford CYMATICS: Science Vs. Music - Nigel Stanford AUTOMATICA - Nigel Stanford Automatica Robot tests Comrade Detective - Wikipedia Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Oct 4, 2017 · 38 min

    046: Good beard bad beard

    Bearded man entangled in dark web drugs market bust, Google researches how to make browser security warnings less confusing, and (ahem) "bedroom entertainment systems" probed for security holes. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Rich Baldry. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Rich Baldry. Support Smashing Security Links: Feds catch a lord of the 'dark web' suspected of drug deals - Miami Herald Trip to world beard competition ends in arrest for alleged dark web drug dealer - The Guardian Austin Facial Hair Club The World Beard and Moustache Championships Glorious Portraits from the 2017 World Beard And Mustache Championship Where the wild warnings are: Root causes of Chrome HTTPS certificate errors [PDF] Screwdriving. Locating and exploiting smart adult toys - Pen Test Partners Wi-Fi sex toy with built-in camera fails penetration test - The Register Forums Topo by Ergodriven Dirk Gently's Holistic Detective Agency - IMDb Dead roach in Utah man’s milkshake becomes Twitter hero - KSL.com Trevor The Roach: A Tribute Movie Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 27, 2017 · 36 min

    045: Deloitte fail, CCleaner, and dotards on Twitter

    Deloitte suffers an embarrassing hack, CCleaner spreads malware, and Twitter explains why it isn't planning to ban Donald Trump from Twitter anytime soon. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Phil Wood of Cisco. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Phil Wood. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: Graham Cluley on Twitter: "Turns out I slept in a cheesegrater last night" Deloitte hit by cyber-attack revealing clients’ secret emails - The Guardian Source: Deloitte Breach Affected All Company Email, Admin Accounts — Krebs on Security Deloitte is a sitting duck: Key systems with RDP open, VPN and proxy 'login details leaked' • The Register CCleanup: A Vast Number of Machines at Risk - Talos Intelligence blog CCleaner Command and Control Causes Concern - Talos Intelligence North Korean Minister: Trump's 'Declaration Of War' Means N.K. Can Shoot Down U.S. Bombers - NPR Twitter PublicPolicy on Twitter The Twitter Rules - Twitter Help Center Wildergorn colour-in posters Star Trek: Discovery - CBS Rick and Morty - Wikipedia Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 25, 2017 · 6 min

    044: Bonus behind the scenes - shower time

    Carole wants to know why Graham keeps FaceTiming her from the shower. Can you help solve the mystery? ("Bonus" behind-the-scenes content.) Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Support Smashing Security Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 20, 2017 · 29 min

    043: Backups - a necessary evil?

    In this special "splinter" episode of the "Smashing Security" podcast we tackle the tricky subject of backups - when did you last backup your data? how and what should you backup? and where should you store them? Lots of questions and Graham gets to do his Tina Turner impression. Listen to the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Maria Varmazis. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Maria Varmazis. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: Tina Turner - Private Dancer - YouTube The Ed Sullivan Show - 'Baranton Sisters' - “Foot Jugglers” (Aired February 2, 1969) - YouTube How to create a robust data backup plan (and make sure it works) How to back up your iPhone, iPad, and iPod touch - Apple Support How to back up your Android phone or tablet: The ultimate guide Crashplan stops offering its consumer backup solution Carbonite cloud backup Backblaze Online Backup Mozy Cloud Storage & Backup Amazon Glacier CloudBerry Lab - Cross-Platform Cloud Backup Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 13, 2017 · 45 min

    042: Equifax, BlueBorne, and the iPhone X

    Equifax's shambolic response to its huge data breach, a scary-sounding Bluetooth exploit, and Apple's iPhone X comes with Face ID. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest Javvad Malik of AlienVault. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Javvad Malik. Sponsored By: Rapid7: Identifying, prioritizing and managing vulnerabilities all the way through to remediation is not only possible, it can be simple. Right now.Build a vulnerability management program that works for you with Insight VM, by Rapid7. Get started with your free 30 day trial now. Support Smashing Security Links: We tested Equifax's data breach checker — and it's basically useless | ZDNet Equifax hack: 44 million Britons' personal details feared stolen in major US data breach "The front page of Equifax's UK website. They don't seem to have room to mention the data breach affecting up to 44 million Brits." - Twitter Chatbot lets you sue Equifax for up to $25,000 without a lawyer - The Verge How to protect yourself in the wake of the Equifax data breach Ayuda! (Help!) Equifax Has My Data! — Krebs on Security BlueBorne Information from the Research Team - Armis Labs The five biggest questions about Apple’s new facial recognition system - The Verge Can the government force you to unlock your own phone? | The Guardian UK police have a new tactic to circumvent strong iPhone encryption: steal the unlocked phone out of the criminal’s hand | 9to5Mac Chessable The science that makes chess learning easier - Chessable.com You can actually be allergic to exercise - Pop Science Dr Mandell's Push and Pull Technique (20-Second Neck Pain Relief) - YouTube It's all about the Squinch! - YouTube Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Sep 7, 2017 · 46 min

    041: Hacking Instagram, facial failures, and spying bosses

    It's easy to phone up a celebrity on Instagram following security breach, facial recognition at Notting Hill Carnival can't tell the girls from the boys, and companies are spying on their workers' activities. All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by special guest David Bisson. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: David Bisson. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: "Who Is Marcus Hutchins?" — Krebs on Security Ahem, Kim Kardashian Is Naked Up A Tree - Huffington Post Hackers Claim Apparent Instagram Fightback Will Not Stop Them From Selling Stolen ‘Doxagram’ Data - The Daily Beast A Note on Security from Instagram’s CTO - Instagram Blog London police’s use of facial recognition falls flat on its face – Naked Security Misidentification and improvised rules - we lift the lid on the Met's Notting Hill facial recognition operation - Liberty Statement from police commander for Notting Hill Carnival 2016 - Metropolitan Police UK govt steams ahead with £5m facial recog system amid furore over innocents' mugshots - The Register ECHR court reverses ruling on sacking over private messages - BBC News Monitoring at work - UK Citizens Advice Through the Keyhole: Privacy in the Workplace, an Endangered Right - American Civil Liberties Union Employers, Schools, and Social Networking Privacy - American Civil Liberties Union The Big Sick (2017) - IMDb Group Therapy Radio | Streaming live every Friday - YouTube Above & Beyond - SoundCloud Above & Beyond present Group Therapy 250 How To Fix a Toilet And Other Things We Can't Do Without Search Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy

  • Aug 30, 2017 · 47 min

    040: The show that cost Troy Hunt 14 dollars

    Are public figures lying about being hacked? What were online criminals doing with 711 million email addresses? And how could scammers profit from Hurricane Harvey? All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Troy Hunt. Follow the show on Twitter at @SmashinSecurity, or visit our website for more episodes. Remember: Subscribe on Apple Podcasts, or your favourite podcast app, to catch all of the episodes as they go live. Thanks for listening! Warning: This podcast may contain nuts, adult themes, and rude language. Special Guest: Troy Hunt. Sponsored By: Recorded Future: Recorded Future is the real-time threat intelligence company whose patented machine learning technology continuously analyzes technical, open, and dark web sources to give organizations unmatched insight into emerging threats.Sign up for free daily threat intelligence updates at https://recordedfuture.com/intel Support Smashing Security Links: Trump appointee says for the 'past several years' he has been the victim of 'multiple cyber attacks' — Graham Cluley. Trump appointee: Comment calling Obama's mother a 'w@!re' result of 'Internet crimes' against me — CNN. Inside the Massive 711 Million Record Onliner Spambot Dump — Troy Hunt. Have I been pwned? — Check if your email has been compromised in a data breach Harvey Hoax: There are no sharks on Houston's flooded freeways — WCVB 5. Photo of planes at flooded Houston airport is a fake — Daily Mail. Charity Listing - BBB Wise Giving Alliance — Give.org. Wise giving in the wake of Hurricane Harvey — FTC. The Phoenix Comic Little Ripper Lifesaver Drones Spot Sharks Electronically — YouTube. ChirpChange Smashing Security on Facebook Smashing Security merchandise (t-shirts, mugs, stickers and stuff) Privacy & Opt-Out: https://redcircle.com/privacy