Skip to content
Artwork for The Lockdown - Practical Privacy & Security
TechnologyEducationHow To

The Lockdown - Practical Privacy & Security

Ray Heffer

Welcome to The Lockdown. Privacy doesn’t have to be all-or-nothing. The inability to attain extreme levels of privacy shouldn’t deter one from taking any protective measures at all. The show is hosted by Ray Heffer, an expert in the field of privacy and cybersecurity, with each episode touching on a range of topics such as data privacy, password management, and secure browsing habits. Tin-foil hats are optional!
Play
  • 21 episodes
  • Avg 46 min
  • English

Support the show

Goes straight to the publisher. podnod takes nothing.

Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • S2 · E3
    August 14 · 1 hr 13 min

    Hiding in Plain Sight, The Art of OSINT with Tony Daly

    In this episode we're joined by Tony Daly, Managing Director of Seiber, for a deep dive into open-source intelligence (OSINT). Tony discussess what separates professional intelligence work from “spicy Googling,” how seemingly insignificant pieces of public information can expose identities and locations, and why good methodology, verification, proportionality and ethics matter. The conversation also covers digital footprints, social-media privacy, professional OSINT tools, dark-web investigations, AI and search, facial recognition, AI governance, and routes into a career in OSINT. In the show: What professional OSINT actually looks like, including the intelligence lifecycle, priority intelligence requirements, critical thinking, misinformation and disinformation. How investigators pivot from tiny clues to useful intelligence using reverse-image searches, visual similarity, objects in photographs, architecture, signs, number plates and digital footprints. The privacy consequences of oversharing, including location check-ins, travel patterns, family members, executive exposure, corporate intelligence and the surprising intelligence value of apps such as Untappd. The legal and ethical boundaries of OSINT, including proportionality, privacy, Article 8 of the European Convention on Human Rights, surveillance and producing evidence that can withstand scrutiny. Professional OSINT tools and tradecraft, including PimEyes, Maltego, Recorded Future, District 4 Labs/Darkside, DarkOwl, Indago and Epieos, plus the risks involved in dark-web investigations. AI, surveillance and governance, from AI-generated search results and hallucinations to data poisoning, Flock license-plate cameras, police facial recognition and the growing financial-sector focus on AI risk. Building an OSINT career through cybersecurity, anti-money laundering, journalism, due diligence, investigations and travel risk, plus training and communities including Seiber, NCSC Assured Training, OSMOSIS, and SANS. Show Links: Seiber: https://www.seiber.co.uk/ Seiber on LinkedIn: https://www.linkedin.com/company/seiberltd/ Tony Daly at OSMOSIS: https://osmosisassociation.org/team-member/tony-daly/ Careless People by Sarah Wynn-Williams (Amazon): https://www.amazon.com/dp/1250391237 OSINT beginnings with BBC Monitoring: https://publications.parliament.uk/pa/cm201617/cmselect/cmfaff/732/73205.htm The Evolution of Digital Intelligence at the CIA: https://www.cia.gov/stories/story/intelligence-in-a-digital-world-inside-cias-directorate-of-digital-innovation/ OSINT Tools: PimEyes: https://pimeyes.com/ Maltego: https://www.maltego.com/ Recorded Future: https://www.recordedfuture.com/ District 4 Labs: https://www.district4labs.com/ DarkOwl: https://www.darkowl.com/ Indago: https://indagotech.com/ Epieos: https://epieos.com/ Untappd: https://untappd.com/ CyBOK, Cyber Security Body of Knowledge: https://www.cybok.org/ Bellingcat: https://www.bellingcat.com/ Kinahan Cartel: Wanted Narco Boss Exposes Whereabouts by Posting Google Reviews (Bellingcat): https://www.bellingcat.com/news/2024/03/30/kinahan-cartel-wanted-narco-boss-exposes-whereabouts-by-posting-google-reviews Matrix Community Rooms: Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: • https://matrix.to/#/#lockdown-intro:matrix.org • https://matrix.to/#/#lockdown-podcast:matrix.org • https://matrix.to/#/#lockdown-general:matrix.org ★ Support the show on Patreon ★

  • S2 · E2
    July 31 · 53 min

    You Are The Proxy - Hackers, Experts, and Bad Advice

    In this episode, we continue with a closer look at what cybersecurity competence actually means, and why qualifications, compliance frameworks, and public reputation are poor substitutes for understanding how real attacks work. We explore the cryptography behind Proton Mail, public and private keys, fingerprints, and what you can do with PGP word lists. We’ll also discuss passkeys, account recovery, SIM swaps, ClickFix malware, infostealers, VPN blocking, and the residential proxies that allow malicious traffic to hide behind ordinary household IP addresses. In the show: Hackers, threat actors, security influencers, and the risks created by confident but inaccurate advice Kerckhoffs’s principle: designing security under the assumption that the enemy knows the system How public and private keys work, including Proton Mail encryption, digital signatures, fingerprints, and independent key verification Using the PsySecure Workbench and PGP word lists to make cryptographic fingerprints easier to exchange and verify The problem with passkeys, and why weak account recovery can undermine their security ClickFix attacks that imitate Cloudflare verification pages and trick users into running malicious terminal commands How infostealers target browser data, authenticated sessions, cookies, passwords, and other valuable information Why VPN traffic is increasingly blocked or challenged while attackers move toward residential proxies that resemble legitimate users You are the proxy: How cheap smart home devices, streaming boxes, thermostats, and cameras, can become hidden residential proxies The normalization of identity verification, digital ID checks, and other invasive systems Show Links: The Hidden Backdoors Inside Millions of Smart Devices (WSJ): https://www.youtube.com/watch?v=apEPPKYgLL0 keys.openpgp.org: keys.openpgp.org PsySecure Workbench: https://psysecure.com/workbench An Investigative Framework for Auditing the Security & Privacy of Mobile VPNs: https://www.ndss-symposium.org/wp-content/uploads/2026-s1573-paper.pdf Matrix Community Rooms: Matrix Community Space: https://matrix.to/#/#psysecure:matrix.org Individual Room Links: https://matrix.to/#/#lockdown-intro:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-general:matrix.org How to check public key fingerprint from the command line: gpg --show-keys --with-fingerprint public_key_file.asc ★ Support the show on Patreon ★

  • S2 · E1
    July 10 · 39 min

    It's Time to Think Like A CISO

    Season 2 of The Lockdown is here, with a renewed focus on the overlap between privacy, security, and open-source intelligence. In this episode, Ray explains why reconnaissance should be treated as the first line of defense, not as the attacker’s free move. This episode lays out a practical way to think like a CISO in both your personal life and inside an organization. The core idea is simple: Minimize What Can Be Known, understand what you are protecting, and close the gap between having security controls and actually being protected by them. In the show: Why privacy and security should be treated as two sides of the same coin Reconnaissance, OSINT, and how attackers build a picture from public information Thinking like a CISO: threat modeling, risk, residual risk, and compensating controls Practical privacy choices, including GrapheneOS, browsers, VPNs, prepaid SIMs, and data brokers The control confidence gap, including SIM swaps, help desk attacks, security questions, and deepfakes Real-world examples of reconnaissance-driven attacks, including MGM, Caesars, Marks & Spencer, and ransomware extortion The updated OSINT Defense and Security Framework, plus practical homework for individuals and organizations Show Links OSINT Defense & Security Framework PDF Weekday executive security briefing email Matrix Community Rooms: • Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: • https://matrix.to/#/#lockdown-intro:matrix.org • https://matrix.to/#/#lockdown-podcast:matrix.org • https://matrix.to/#/#lockdown-general:matrix.org Support the show on Patreon ★ https://www.patreon.com/TheLockdown ★ Support this podcast on Patreon ★

  • S1 · E34
    Oct 3, 2025 · 42 min

    034 - Final Episode

    In this final episode of The Lockdown, I reflect on the journey of the podcast, and explaining why I’m redirecting my energy to other projects. I discuss the importance of practical privacy measures, measures over an ‘all-or-nothing’ approach, as well as sharing my thoughts on threat modeling, and address several listener questions about privacy tools and self-hosting. I also introduce a new concept from my recent blog post about the “space between” in cybersecurity, examining how compartmentalization of identities can serve as an early warning system against social engineering attacks. In this week’s episode: Why this is the final episode The all-or-nothing fallacy Airport facial recognition and the Clearview AI threat Threat modeling for different life situations The CIA triad and why 100% security doesn’t exist UK and Swiss digital ID systems and their privacy implications NPM breach case study and the psychology of social engineering Why organizations should compartmentalize communication channels Listener Q&A: MySudo virtual cards, self-hosting setup, and mobile hotspots The new Privacy Tools page on PsySecure.com Matrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: https://matrix.to/#/#lockdown-intro:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-general:matrix.org Show Links: Privacy Tools Page - https://psysecure.com/privacytools/ PsySecure ODSF Framework - https://odsf.psysecure.com "The Space Between" Blog Post - https://psysecure.com/ma-the-space-between-breaches Swiss E-ID System Information - https://www.bk.admin.ch Cyber Kill Chain (Lockheed Martin) - https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html Robert Cialdini's Principles of Persuasion - https://www.influenceatwork.com Daniel Kahneman's Thinking, Fast and Slow - https://www.amazon.com/Thinking-Fast-Slow-Daniel-Kahneman/dp/0374533555 “Nothing in life is as important as you think it is when you are thinking about it.” - Daniel Kahneman, Thinking, Fast and Slow ★ Support this podcast on Patreon ★

  • S1 · E33
    Sep 8, 2025 · 38 min

    033 - Black Mirror - Is the UK's Surveillance State Coming to America?

    In this episode, I share news from my recent trip to the UK, noticing how it seems to have reached the epic proportions of a Black Mirror episode; from the absurd TV licensing program to the new Digital ID Brit cards that will track your behavior. I also explore how the UK may be serving as a testing ground for new levels of behavioral surveillance that could eventually spread globally. I dive into California’s $900 “smart” license plates that track your every move, centralized government digital currencies, and my predictions for the next 20 years of Orwellian surveillance. Support the show on Patreon! In this week’s episode: The UK’s TV licensing system: Legal extortion through private contractors The Reviver R-plate: $900 to track yourself in California and Arizona Brit Cards: UK’s new “voluntary” Digital ID system The Bank of England’s digital pound and programmable money Historical patterns of control: From land ownership to neural interfaces Why the UK is the blueprint for global surveillance rollout Predictions for the next 20-50 years of biosurveillance Matrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: https://matrix.to/#/#lockdown-intro:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-general:matrix.org Show Links: PsySecure ODSF Framework - https://odsf.psysecure.com LCD License Plate (not privacy friendly!) - https://reviver.com/rplate/ Black Mirror S03E01 "Nosedive" - https://www.imdb.com/title/tt5497778/ Bank of England's Digital Pound - https://www.bankofengland.co.uk/the-digital-pound Brit Card Digital ID System - https://www.labourtogether.uk/all-reports/britcard TV Licensing Detector Ads (1980s-90s): The Detector Van - https://www.youtube.com/watch?v=8NmdUcmLFkw "We know exactly where he is" - https://www.youtube.com/watch?v=qF3-S2sCnb8 Keep One Eye Open - https://www.youtube.com/watch?v=mVfOmR7gAek More Powerful Dector Vans! - https://www.youtube.com/watch?v=1Q9CsRRhWQI “One believes things because one has been conditioned to believe them.” - Mustapha Mond (Brave New World ★ Support this podcast on Patreon ★

  • S1 · E32
    Aug 11, 2025 · 21 min

    032 - No Salt Required: Listener Questions Before the Break

    In this episode I address listener feedback and questions, from clarifying my stance on the “Tea” controversy to sharing practical tips from the community about Privacy.com workarounds. This episode covers some loose ends before I take a brief hiatus. I also discuss why I won’t be at Black Hat this year, share thoughts on minimalism versus practicality in privacy, and reveal my favorite Indian restaurant in Vegas for those attending Black Hat! In this week’s episode: Addressing the “Tea” controversy and clarifying my positions on doxing Community solution for Privacy.com and Plaid privacy concerns Contact information protection strategies when family uses social media Future of capture-the-flag challenges and OSINT considerations Conference attendance updates and travel Matrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: https://matrix.to/#/#lockdown-general:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-intro:matrix.org Show Links: Tea app leak article - https://www.bleepingcomputer.com/news/security/tea-app-leak-worsens-with-second-database-exposing-user-chats/ OSMOSIS Institute - https://osmosisinstitute.org/events/ Privacy.com - https://privacy.com “There are no facts, only interpretations.” - Friedrich Nietzsche ★ Support this podcast on Patreon ★

  • S1 · E31
    Aug 4, 2025 · 54 min

    031 - When Privacy Tools Betray You, Safety Apps That Dox and Revoked Anonymous Payments

    In this episode, I discuss the challenges facing privacy-focused payment solutions like Privacy.com, exploring alternatives and the troubling rise of KYC requirements across the industry. I dive deep into the Switzerland privacy crisis that’s forcing Proton to consider relocating their infrastructure, and what this means for encrypted email providers globally. I also cover the catastrophic security failure at Tea, a women’s safety app that exposed 72,000 images including government IDs through basic incompetence, leading to harassment campaigns on 4chan. I wrap up with thoughts on vehicle tracking through DCM/Telematics modules, why buying older vehicles might be the better privacy-conscious choice, and how embracing the stoic lifestyle aligns with both privacy and my own philosophical principles. In this week’s episode: Privacy.com troubles: Account freezes, limited alternatives, and the KYC nightmare Switzerland’s surveillance crisis: Why Proton is threatening to leave and relocating to Germany/Norway Email provider comparison: Proton vs Tutanota vs Atomic Mail, and understanding intelligence alliances Tea app breach: How 72,000 IDs and 1.1 million private messages ended up on 4chan Vehicle tracking: DCM modules, telematics, and why your car is spying on you Philosophy of privacy: Stoicism, minimalism, and why less is more Matrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: https://matrix.to/#/#lockdown-general:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-intro:matrix.org Show Links: Privacy.com - https://privacy.com Cloaked.com - https://cloaked.com Proton Warrant Canary - https://protonvpn.com/blog/transparency-report/ Climate Activist Arrest - https://proton.me/blog/climate-activist-arrest and https://www.wired.com/story/protonmail-amends-policy-after-giving-up-activists-data/ Tuta Crypt - https://tuta.com/documents/tuta-crypt-spec.pdf Proton elliptic curve cryptography - https://proton.me/blog/elliptic-curve-cryptography SimpleLogin - https://simplelogin.io HashiCorp Vault - https://www.vaultproject.io RAM IS SPYING ON YOU (Cozy Living Machine) - https://www.youtube.com/watch?v=0-Y1SUSRqNU Meditations by Marcus Aurelius - https://www.amazon.com/Meditations-New-Translation-Modern-Library-ebook/dp/B000FC1JAI “Very little is needed to make a happy life; it is all within yourself, in your way of thinking.” - Marcus Aurelius ★ Support this podcast on Patreon ★

  • S1 · E30
    Jul 18, 2025 · 52 min

    030 - Info Stealers, GrapheneOS Drama, and Why Video Games and Anti-Virus Are Spyware

    In this episode, I address listener feedback and corrections regarding use of public Wi-Fi, MAC addresses, and aliases. I dive deep into the nuances of MAC address randomization on GrapheneOS versus Apple’s private Wi-Fi addresses, explaining why GrapheneOS offers superior privacy protection. I discuss the real threats of public Wi-Fi in 2025 (hint: it’s not hackers with Wireshark), and share my approach with aliases. I also cover the rising threat of infostealers like Atomic Info Stealer for macOS, the dangerous intersection of gaming cheats and malware, and why I avoid third-party antivirus software. Most importantly, I address the GrapheneOS controversy: the loss of a senior developer to military conscription, Google’s strategic pivot that threatens custom ROMs, and why claims of GrapheneOS “dying” are misinformation spread by those with competing agendas. In this week’s episode: Clarifications and Corrections: Public Wi-Fi, MAC addresses, and alias management MAC address randomization: GrapheneOS vs Apple’s implementation The real threats of public Wi-Fi in 2025 Info stealers and video games can be a privacy nightmare GrapheneOS controversy: Developer conscription, Google’s lockdown, and the future of custom ROMs Why antivirus software might be the malware you’re trying to avoid Matrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: https://matrix.to/#/#lockdown-general:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-intro:matrix.org Show Links: MAC Address Lookup - https://maclookup.app/ OUI Lookup - https://oui.is/ 33mail - https://www.33mail.com/ OpenSnitch - https://github.com/evilsocket/opensnitch Privacy.com - https://privacy.com Lithic - https://lithic.com Kaspersky and Russian Government - https://en.wikipedia.org/wiki/Kaspersky_and_the_Russian_government Google Not Killing AOSP - https://www.androidauthority.com/google-not-killing-aosp-3566882/ GrapheneOS on Developer Conscription - https://grapheneos.social/@GrapheneOS/114359660453627718 GrapheneOS on OEM Partnerships (June 19) - https://grapheneos.social/@GrapheneOS/114671100848024807 GrapheneOS Response to Misinformation - https://grapheneos.social/@GrapheneOS/114825492698412916 GrapheneOS on iPhone Security - https://grapheneos.social/@GrapheneOS/114824816120139544 “Social engineering bypasses all technologies, including firewalls.” - Kevin Mitnick ★ Support this podcast on Patreon ★

  • S1 · E29
    Jul 7, 2025 · 54 min

    029 - Minimize not Militarize and Avoiding Surveillance with GrapheneOS

    In this episode, I explore the difference between the military mindset and the more stealth approach of minimization in cybersecurity. I share the results from the Ghost in the Source Capture the Flag (CTF) challenge, revealing how the winners cracked the AES encryption using dictionary attacks, keyword harvesting and the cipher tool hidden in robots.txt. I discuss why the “assume breach” mentality just leaves the doors wide open, using examples from Kevin Mitnick’s 1981 Pacific Bell infiltration to modern ransomware groups like Scattered Spider who breached MGM and Marks & Spencer through social engineering. I also cover practical tactics for using public Wi-Fi, data curation techniques, the invisible surveillance net including Stingray devices, and provide a deep dive into GrapheneOS covering user profiles, app sandboxing, network controls, sensor permissions, and the proper use of sandboxed Google Play services. In this week’s episode: Ghost in the Source Capture the Flag challenge results The military mindset problem in cybersecurity Strategic use of public Wi-Fi for account creation and privacy techniques Data curation tactics, and “Minimizing What Can Be Known” Invisible surveillance net and Stingray devices GrapheneOS discussion on user profiles, app sandboxing, network controls, sensors permissions, sandboxed Google Play services, and security architecture Matrix Community Rooms Matrix Community Space - https://matrix.to/#/#psysecure:matrix.org Individual Room Links: https://matrix.to/#/#lockdown-general:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-intro:matrix.org Show Links: Noam Chomsky on Internet Privacyhttps://www.youtube.com/watch?v=QIWsTMcBrjQ Noam Chomsky on Advertising - https://www.youtube.com/watch?v=PfIwUlY44CM TryHackMe Platform - https://tryhackme.com Hack the Box - https://hackthebox.com Wired Article on DNC Stingray Surveillance - https://www.wired.com/story/2024-dnc-cell-site-simulator-phone-surveillance/ IntelTechniques Data Removal Guide - https://inteltechniques.com/workbook.html Optery Data Broker Removal - https://optery.com Graphene OS - https://grapheneos.org “We’re dragons. We’re not supposed to live by other people’s rules.” - Hajime Ryudo ★ Support this podcast on Patreon ★

  • S1 · E28
    Jun 20, 2025 · 45 min

    028 - Silence & Stealth - Mailbox, Email & Anti-KYC Phone Strategies

    In this episode, I discuss three key strategies for maintaining privacy and security across your physical mailbox, email, and phone. I discuss the growing Matrix community, explore alternative mailing solutions using co-working spaces, detail a four-tier email strategy, and examine the concerning spread of Flock ALPR cameras. I also share insights on anonymous eSIM options and answer listener questions about dealing with Know-Your-Customer requirements. In this week’s episode: Joining the Matrix community with Element Physical mailbox strategies: UPS stores, virtual CMRA addresses, and co-working spaces Four-tiered email approach using ProtonMail, Fastmail, SimpleLogin, and Gmail sock puppet Mobile phone privacy with Mint Mobile and anonymous eSIM options The Flock ALPR camera threat and how to protect yourself Listener questions: Australian SIM card strategies with KYC requirements Capture the Flag challenge details for June 21st Matrix Community Rooms It seems on Element X, it doesn’t list the rooms associated with the Matrix space, so you can click on each of these links to join the rooms: https://matrix.to/#/#lockdown-general:matrix.org https://matrix.to/#/#lockdown-podcast:matrix.org https://matrix.to/#/#lockdown-intro:matrix.org Show Links: Matrix Clients - https://matrix.org/clients Matrix Community - https://matrix.to/#/#psysecure:matrix.org Smarty Address Lookup - https://www.smarty.com/products/single-address Expired Domains - https://www.expireddomains.net/ Stealths.net (Anonymous eSIMs) - https://stealths.net/ DeFlock.me (ALPR Camera Map) - https://deflock.me/ Flock Safety Privacy Policy - https://www.flocksafety.com/privacy-policy EFF Article on DeFlock - https://www.eff.org/deeplinks/2025/02/anti-surveillance-mapmaker-refuses-flock-safetys-cease-and-desist-demand CTF Challenge Rules - https://psysecure.com/ctf “Imagine this situation where we have the huge electronic intercommunication so that everybody is in touch with everybody else in such a way that it reveals their inmost thoughts, and there is no longer any individuality. No privacy. Everything you are, everything you think, is revealed to everyone.” - “Future of Communications” Alan Watts Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E27
    Jun 13, 2025 · 44 min

    027 - Stop Playing the Game, Join The New Matrix Privacy Community

    In this episode, I discuss breaking free from the Apple ecosystem, the dangers of social media oversharing, and introduce our new Matrix community. I also cover the upcoming capture the flag challenge, share thoughts on the OSINT Defense & Security Framework progress, and rant about security theater at airports and online services that block VPNs. In this week’s episode: Apple’s $95 million lawsuit and the ecosystem lock-in problem Why people overshare on social media and how OSINT can exploit it Introduction to the Matrix community Capture the Flag challenge launching June 21st! Progress update on the OSINT Defense & Security Framework (ODSF) Security theater: VPN blocking and other pointless security measures Alternative YouTube clients for privacy (GrayJay and NewPipe) Show Links: Matrix Community - https://matrix.to/#/#psysecure:matrix.org CTF Challenge - https://psysecure.com/ctf GrayJay (by Futo) - https://grayjay.app NewPipe - https://newpipe.net WiFi Pineapple - https://shop.hak5.org/products/wifi-pineapple System76 Laptops - https://system76.com/laptops Little Snitch (macOS Firewall) - https://www.obdev.at/products/littlesnitch/ “I hope for nothing. I fear nothing. I am free.” - Nikos Kazantzakis Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E26
    May 31, 2025 · 7 min

    026 - Ghost in the Source (Announcement)

    In this brief episode between travels, I announce the “Ghost in the Source” capture the flag challenge, a cryptographic hunt on my website starting June 21st, 2025. At the end of June I will pick 3 lucky winners which will receive a 6-month TryHackMe subscription voucher. I also provide an update on our new Matrix community. In this week’s episode: Announcing the “Ghost in the Source” CTF challenge Challenge details and rules Prize information: 3 x 6-month TryHackMe vouchers! Matrix community update for listener interaction Future plans for OSINT CTF challenges Show Links: CTF Challenge Page - https://psysecure.com/ctf/ “When I float weightless back to the surface, I’m imagining I’m becoming someone else.” - Motoko Kusanagi Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E25
    May 26, 2025 · 38 min

    025 - AI Privacy Concerns with ChatGPT and Claude

    In this episode, I explore the privacy implications of using AI apps like ChatGPT and Claude on mobile devices. I discuss why ChatGPT’s requirement for Google Play Store login and audio recording storage led me to Claude on my GrapheneOS device. I also cover my daily app setup, Windows telemetry blocking with SimpleWall, macOS privacy with Little Snitch, and the potential of System76 Linux laptops. In this week’s episode: Privacy comparison between ChatGPT and Claude AI apps ChatGPT’s audio recording storage and data export concerns GrapheneOS setup without Google Play Store login Using FUTO Keyboard and FUTO Voice for local transcription Essential privacy tools: SimpleWall for Windows and Little Snitch for macOS Windows Subsystem for Linux (WSL) for developers System76 Linux laptops as a privacy-focused alternative Show Links: Anthropic Claude.ai Encryption - https://privacy.anthropic.com/en/articles/10458704... Duck.ai - https://duck.ai Futo Keyboard & Voice - https://futo.org/ Aurora Store - https://auroraoss.com/aurora-store SimpleWall (Windows Firewall) - https://github.com/henrypp/simplewall Little Snitch (macOS) - https://www.obdev.at/products/littlesnitch/ GeoSpy (OSINT Tool) - https://geospy.net System76 Linux Laptops - https://system76.com/ Mental Outlaw YouTube Channel - https://www.youtube.com/@MentalOutlaw DaVinci Resolve - https://www.blackmagicdesign.com/products/davinciresolve OSINT Defense & Security Framework - https://psysecure.com/services/odsf/ “██████REDACTED███” - █████████ Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E24
    May 13, 2025 · 42 min

    024 - Minimize What Can Be Known with the OSINT Defense & Security Framework (OSDF)

    In this episode, I discuss what has been keeping me away from the mic, the Open Source Intelligence Defense and Security Framework (ODSF), and share updates on privacy topics including browser security, autonomous taxis, airport security cameras, and managing cryptocurrency. I also address listener questions about anonymous SIM cards and creating separate online identities. Official Website: https://psysecure.com In this week’s episode: Introducing the Open Source Intelligence Defense and Security Framework (ODSF) Browser privacy comparisons (Firefox, LibreWolf, Brave, Mulvad) Experiences with Waymo autonomous taxis and privacy considerations TSA security cameras and opting out of facial recognition Listener questions about anonymous SIMs in Australia and creating sock puppet accounts Using cryptocurrency Show Links: BIP39 Generator - https://github.com/iancoleman/bip39 Phoenix Wallet - https://phoenix.acinq.co Zeus Wallet - https://zeusln.com LibreWolf Browser - https://librewolf.net/ OSS Document Scanner (GrapheneOS) - https://github.com/Akylas/OSS-DocumentScanner Mullvad Browser (randomDataOnCanvasExtract) - https://github.com/mullvad/mullvad-browser/issues/358 Mullvad Browser (Letterboxing) - https://github.com/mullvad/mullvad-browser/issues/152 “Minimize what can be known.” - Me Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E23
    Feb 24, 2025 · 30 min

    023 - Apple Removes ADP in the UK, the Privacy Implications and Listener Q&A

    In this episode, we dive into Apple’s latest privacy retreat with the removal of Advanced Data Protection (ADP) for iCloud in the UK. We break down why Apple made this move, how ADP works, and what it means for users who care about encryption and data security. If you’re in the UK and using Apple’s ecosystem, this episode is a must-listen as I cover strategies to keep your data secure despite Apple’s decision. In this week’s episode: The UK’s Investigatory Powers Act A technical breakdown of how iCloud ADP was supposed to protect user data. Alternatives to iCloud, including Nextcloud, GrapheneOS, and secure backups. Threat Modeling & The Privacy Spectrum Listener Questions, addressing concerns about online privacy, social media exposure, and what to do when friends dismiss security risks. Show Links: Apple pulls data protection tool (BBC News) - https://www.bbc.com/news/articles/cgj54eq4vejo Apple Intelligence - https://www.macrumors.com/2025/02/11/apple-intelligence-re-enabled-in-latest-updates/ pfSense Guide - https://psysecure.com/complete-setup-guide-to-pfSense Nextcloud Guide - https://psysecure.com/self-hosting-nextlcoud Möbius Sync - https://mobiussync.com/ Obsidian - https://obsidian.md/ “The right to privacy is not merely a right to secrecy. It is a right to control information about oneself.” - Anonymous Podcast music: The R3cluse Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E22
    Feb 3, 2025 · 1 hr 10 min

    022 - Deep Dive into Session Private Messenger with Co-Founder Kee Jefferys

    In this week’s episode, we take a deep dive into Session, a private messaging app, with its co-founder Kee Jefferys. We discuss the philosophy behind Session, its technical architecture, and the broader implications of privacy in a world increasingly hostile to anonymous communication. Kee shares insights on the importance of decentralized networks, the risks of phone number-based messaging, and the role of cryptocurrency in supporting private infrastructure. We also touch on operational security (OPSEC), the real-world challenges of getting people to adopt privacy tools, and how Session is working to improve usability while maintaining strong privacy protections. In this week’s episode: Session Private Messenger – Kee Jefferys explains the origins of Session, its core principles, and how it differs from mainstream messaging apps. The Future of Privacy – Discussion on surveillance, government censorship, and the increasing crackdown on privacy tools. Decentralized Messaging – How Session uses a global network of nodes to provide anonymous and resilient communication. Session Pro & Sustainability – Monetization strategies for Session and how the network sustains itself without compromising user privacy. Avoiding the Privacy Valley of Despair – How privacy-conscious users can avoid burnout and find a practical balance. Censorship & Government Interference – Addressing Russia’s blocking of Session nodes and strategies to bypass censorship. Show Links: Download Session - https://getsession.org Session Lite Paper - https://getsession.org/litepaper Support the Show on Patreon - https://patreon.com/TheLockdown Follow Kee on X - https://x.com/JefferysKee Until they become conscious they will never rebel, and until after they have rebelled they cannot become conscious. - George Orwell, 1984 Podcast music: The R3cluse Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E21
    Jan 20, 2025 · 41 min

    021 - Digital Minimalism and Why Your Messages Aren't Really Private

    In this week's episode we dive deep into both the psychological and privacy implications of social media apps. I reflect on my observations during recent travels, and explore how social media platforms are distorting human connections while simultaneously collecting vast amounts of personal data. The episode also tackles the technical aspects of email systems to the limitations of encrypted messaging apps, providing practical advice for maintaining privacy. In this week's episode: Listener Questions - Deep dive into pfSense vs OPNsense, mobile VPN usage, and dealing with license plate readers Social Media Privacy - Analysis of social media's psychological impact and privacy issues with data collection practices Proper Account Deletion - Step-by-step guide for securely deleting social media accounts Sock Puppet Accounts - Maintaining anonymous online identities Email Privacy - Historical perspective and current state of email security WhatsApp Security - A discussion on encryption and device security Show Links: Support the Show on Patreon - https://patreon.com/TheLockdown GrapheneOS - https://grapheneos.org The Neuroscience of Engagement - https://medium.com/design-bootcamp/the-neuroscience-of-engagement-b50531a9313b "The right information at the right time is deadlier than any weapon." - Dolores Abernathy (Westworld) Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E20
    Jan 6, 2025 · 57 min

    020 - The State of Privacy in 2025

    This week on The Lockdown, The Practical Privacy & Security Podcast, we’re kicking off the new year with reflections, updates, and a deep dive into key privacy issues that are shaping 2025. From privacy settings on iOS and GrapheneOS, to AI assistants and their potential privacy pitfalls, this episode covers practical advice, insights, and solutions for everyday users. Additionally, I explore new state-level privacy laws across the U.S. and what they mean for both businesses and individuals. In this week’s episode: Reflecting on personal privacy practices and professional projects. A look at U.S. state privacy regulations taking effect in 2025. Privacy and security implications of voice assistants like Siri, Alexa, and Google Assistant. Detailed privacy settings for iOS and why GrapheneOS is the better alternative. AI assistants like ChatGPT and Claude, and their risks. Privacy concerns with vehicles, focusing on data leaks and constant surveillance. The intersection of cybersecurity and OSINT in modern attacks. Show Links: Apple offers $95 million in Siri privacy violation settlement Amazon to pay $31 million in privacy violation penalties for Alexa voice assistant and Ring camera Nulide / FindMyDevice · GitLab British journalist could face years in prison for refusing to hand over his passwords to the police - Il Fatto Quotidiano Volkswagen EV data leak exposes personal information of 3.3 million people Tesla data helped police after Las Vegas truck explosion, but experts have wider privacy concerns Support this show: https://www.patreon.com/c/TheLockdown Official website: https://psysecure.com/podcast/ "If you want to keep a secret, you must also hide it from yourself." -George Orwell Podcast music: The R3cluse Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E19
    Dec 13, 2024 · 1 hr 1 min

    019 - A Conversation with Luke Mulks from Brave Software

    In this episode I speak with Luke Mulks, who is the VP of Business Operations at Brave Software. We discuss the privacy concerns over traditional web-based ads, and why Brave is offering a privacy-first alternative. Show Links: Brave Software: https://brave.com/podcast/ The Brave Technologist Podcast: https://brave.com/podcast/ "Well who's gonna monitor the monitors of the monitors?" - Carla Dean (Enemy of the State) Podcast music: Recluse by Ray Heffer Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

  • S1 · E18
    Nov 29, 2024 · 49 min

    018 - Back to the Basics and not Overthinking Privacy

    In this episode, we go back to the basics as I discuss what I would do today if I were starting from scratch. It begins with deleting social media accounts, especially Facebook. Additionally, we have an update from Optery in response to listener feedback. We discuss tools like LibreWolf, Brave, and GrapheneOS, and compare privacy approaches for mobile devices, including Pixel and iPhone. A segment is dedicated to starting a privacy-first journey, from deleting social media accounts to adopting secure communication and password management practices. The episode also touches on how AI, including large language models (LLMs), is reshaping privacy concerns by building highly accurate profiles of users. In this week’s episode: Don't overthink privacy, especially web browsers with Brave, Firefox, and LibreWolf Back to the basics starting with deleting social media Pixel vs iPhone (GrapheneOS) Show Links: Self-hosting Nextcloud: https://psysecure.com/self-hosting-nextlcoud LibreWolf: https://librewolf.net/ GrapheneOS: https://grapheneos.org/ Meta fined $1.3b: https://www.nytimes.com/2023/05/22/business/meta-facebook-eu-privacy-fine.html Surveillance Watch: https://www.surveillancewatch.io/ "The world outside, the world that you know, it’s gone. It doesn’t exist." – Christof Podcast music: Recluse by Ray Heffer Official Website: https://psysecure.com Podcast music: The R3cluse ★ Support this podcast on Patreon ★

Showing 1–20 of 21 episodes