Skip to content
Artwork for The OPSEC Podcast
TechnologyEducationHow ToExplicit

The OPSEC Podcast

Allen Pace

Explore the real world of operational security with host Allen Pace as he takes you through the privacy strategies, security tools, and threat mindsets that protect you when Big Tech won't and the government can't.

Play
  • 21 episodes
  • fortnightly
  • Avg 19 min
  • English
Counted on this page — what you have heard stays on this device, so it is not something the list can be paged by.
  • #26
    Monday · 19 min

    Follow the Money: The Complete Surveillance Picture Built by Your Payment History

    Summary: Every financial transaction creates a permanent record: at the bank, the card network, the payment app, the data broker who purchased it, and the government reporting infrastructure mandated by the Bank Secrecy Act. This episode maps the complete architecture of financial surveillance—from 78,000 government reports filed daily, to Mastercard's transaction data sales, to Plaid's middleware granting hundreds of apps access to your full banking history. --- What Your Financial Data Reveals: - Health conditions (pharmacy patterns, clinic visits) - Political activity (donations, event venues) - Religious practice (charitable giving, places of worship) - Relationship status (dining, travel, shared accounts) - Financial stress (overdrafts, payday lenders, credit utilization) - Daily schedule and location patterns - Household composition --- Key Takeaways: - The Bank Secrecy Act generates massive surveillance as a compliance byproduct—most unrelated to actual crime - Structuring laws mean using cash incorrectly can itself be a federal crime, regardless of intent - Card networks (Mastercard, Visa) sell transaction data commercially; "anonymization" claims are disputed - Plaid aggregates your banking history and shares it with every connected app—most users don't know what they've authorized - Your financial profile is more detailed than your own memory of spending, accessible to multiple commercial and government actors --- Key Actions: 1. Audit Plaid connections: Visit plaid.com/connections to see every app with bank access. Revoke anything unused or unrecognized. 2. Get virtual cards: Use Privacy.com to generate merchant-specific card numbers with spending limits. Free tier available. 3. Read your bank's privacy notice: Exercise your legal right to opt out of third-party data sharing. Banks must offer it; few customers do. 4. Use cash strategically: For medical, personal, and sensitive purchases where you don't want a commercial record. 5. Don't structure deposits: Breaking up cash deposits below $10,000 to avoid Currency Transaction Reports is a federal crime—regardless of whether any underlying crime exists. --- Resources: - FinCEN: Bank Secrecy Act Overview - FinCEN: Currency Transaction Report FAQ - Privacy.com: Virtual Cards - Plaid: Manage Your Connections - PIRG: Mastercard Data Sales Practices - Cato Institute: BSA Reporting Volume FY2025 --- Call To Action: This week, go to plaid.com/connections and revoke every app you don't actively use. It takes five minutes, and you'll almost certainly find connections you forgot you created. Then read your bank's annual privacy notice and opt out of third-party data sharing. It's required to be offered. Exercise it. Your financial record is a behavioral profile. The question is who has access to it. Head to OPSECPodcast.com for everything else. Your privacy and your security is your responsibility.

    • Transcript
  • #25
    August 10 · 9 min

    Podcast Update: What's New, What's Not, and What's Next

    An update from Allen on where the show is headed. Production has been handled by our friends and partners at Grey Dynamics up to this point. Their production engineer is moving on to other opportunities, which gives us the chance to bring the full production process in-house. The show is taking about a month off to set that up, the style and quality are staying exactly the same, and the release schedule is growing: biweekly deep dives through the end of 2026, then a weekly show in 2027 that keeps the deep dives every two weeks and adds shorter "OPSEC Essentials" episodes in between. Paid member-only content is planned for later, and if sponsors ever come aboard, they stay out of the content. The core podcast stays free and stays in your feed.

    • Transcript
  • #24
    July 27 · 26 min

    Permanent Record: How School Data Breaches Put Your Child's Identity on the Market

    Public schools have become one of the softest, highest-value targets in the ransomware economy. They hold enormous amounts of sensitive data on children, run on tight budgets with little security staff, and depend on third-party vendors that keep getting breached. This episode maps the current threat landscape: the PowerSchool breach that exposed roughly 62 million students and 9.5 million teachers, the Canvas breach that became the largest education breach on record, the always-on monitoring software watching half the students in the country, and the collapse of the federal support that many districts relied on. Then it covers what districts have to do and, more importantly, what parents and students can actually control. The single highest-leverage action for a parent: freeze your child's credit. Defenses and Resources For districts (CISA guidance): Protecting Our Future: Cybersecurity for K-12 (CISA) Cybersecurity for K-12 Education (CISA) K-12 Ransomware Resources (CISA StopRansomware) K-12 Cyber Incident Map (K12 SIX) For parents and students: How to protect your child from identity theft, including freezing a child's credit (FTC) FERPA and your rights over education records (U.S. Dept. of Education) Children's privacy and COPPA (FTC) Priority Actions 1. Freeze your child's credit at all three bureaus (Equifax, Experian, TransUnion). Free, and it blocks new accounts opened with a stolen SSN. 2. Treat any breach notice as real. Take the free monitoring, but know the freeze is what actually prevents fraud. 3. Ask your district what SIS, LMS, and monitoring software it uses, what data each holds, and for how long. 4. Use the opt-outs you already have (FERPA directory information; COPPA protections for younger kids). 5. Decline optional apps and accounts. You cannot leak what was never collected. 6. Talk to your kid: a school device is not private, and what they type on it is recorded. If your child is in school, freeze their credit this week. It is free, it takes about an hour across the three bureaus, and it closes the exact door a data breach opens. Do that first. Then send one email to your district and ask three questions: what student information system do you use, what monitoring software runs on my child's device, and how long is my child's data retained. You are entitled to ask, and asking tells them parents are paying attention. Head to OPSECPodcast.com for the full episode and every link. Your privacy and your security is your responsibility.

  • S1 · E23
    July 13 · 24 min

    The Smart Home Is a Listening Post: Amazon, Google, and the Surveillance You Paid For

    Most people think of their smart home devices as tools they control. They're not. Echo speakers, Ring cameras, smart TVs, and Google Nest devices are surveillance nodes operated by companies whose business model depends on the data they generate — stored on infrastructure you don't own, accessible to law enforcement through legal channels you didn't agree to, and governed by policies that can change without your consent. In March 2025, Amazon removed the local voice processing option from Echo devices. In February 2026, the FBI recovered footage from a Google Nest camera that had been thought to be offline. This episode documents what each major smart home ecosystem actually does with your data — and what you can do to reduce the exposure. Key Settings to Change Right Now Amazon Echo / Alexa: Alexa App → More → Settings → Alexa Privacy → Manage Your Alexa Data → enable "Don't Save Recordings" -Set voice history auto-deletion to 3 months -Delete voice history manually at: alexa.amazon.com Alexa App → More → Settings → Account Settings → Amazon Sidewalk → **toggle off** Do not place Echo devices in bedrooms, home offices, or rooms where sensitive conversations occur Ring: Ring App → Control Center → Law Enforcement → review and configure sharing settings For warrant-required camera alternatives: Arlo, Apple Home Camera, Wyze, Eufy (Anker) Smart TVs: Samsung: Settings → Support → Terms & Policies → disable "Viewing Information Services" LG:Settings → All Settings → General → Additional Settings → disable "Live Plus" Vizio: Menu → System → Reset & Admin → disable "Smart Interactivity" Sony → Settings → Device Preferences → Usage & Diagnostics → disable; also Settings → Apps → See All Apps → SambaTV → disable or uninstall Google Nest Google Home App → Account → Privacy settings → review recording and storage settings Enable two-step verification on your Google account Review and delete camera history in Google Home Home Network Hardening Segment IoT devices onto a separate network: put all smart home devices (Echo, Ring, smart TVs, thermostats, cameras) on a dedicated network isolated from your computers, phones, and storage. Guest network is the easy entry point; a dedicated IoT VLAN with firewall rules (allow internet, block LAN) is the proper approach. Note: full VLAN segmentation breaks mDNS-dependent integrations (Chromecast, Sonos, HomeKit, Matter) unless you configure mDNS bridging. Add DNS-level blocking at the router — configure NextDNS or Pi-hole as your router's DNS server to block adtech, tracking, and data broker domains across every device on the network — including smart TVs, Alexa, and Ring — without per-device configuration. Hardware option: Firewalla — a dedicated network security appliance that plugs between your modem and router. Provides per-device traffic monitoring, DNS-level blocking, intrusion detection, and IoT segmentation through a mobile app. No router replacement required. Two things to do this week. First: find your smart TV's ACR setting and turn it off — five minutes, done. Second: check whether your router supports a separate guest or IoT network. Put your smart home devices on it. That one step limits what a compromised Echo or smart TV can reach on the rest of your network. If you want to go further, add NextDNS or Pi-hole as your router's DNS — fifteen minutes, whole-network coverage without touching a single device setting. None of these are the default. That's not an accident. All the settings and tools are in these notes. Head to OPSECPodcast.com for everything else. Your privacy and your security is your responsibility. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E22
    June 29 · 27 min

    The Confession Booth: How AI Tools Became the Most Effective Data Collection Infrastructure Ever Built

    AI assistants have been positioned as productivity tools. Structurally, they are the most sophisticated data collection interfaces ever built — ones that convince users to voluntarily disclose their most sensitive information in the form of natural language conversation. This episode covers what ChatGPT, Gemini, and Copilot actually do with your data, the corporate exposure epidemic (77% of employees are transmitting sensitive data to AI tools), how AI has supercharged the data broker industry through psychographic inference, and the government access problem that no privacy setting can fully solve. Key Stats - 4% of AI prompts and 20% of file uploads contain sensitive information (Harmonic Security, 2025) - 3 million sensitive records exposed per organization by GenAI tools in H1 2025 - 77% of enterprise employees leak sensitive data via AI tools - 67% of AI tool interactions happen on personal accounts IT cannot monitor - 802,000 files at risk per organization in Microsoft 365 environments (Copilot access surface) - 16% of business-critical Microsoft 365 data is overshared - Psychographic AI inference: 70%+ accuracy predicting political, religious, psychological traits from behavioral data - OpenAI privacy audit score: 48/100 (Grade D), 2026 Settings to Change Right Now: - ChatGPT: Settings → Data Controls → disable "Improve the model for everyone" - ChatGPT: Settings → Personalization → Manage Memory → audit and delete stored facts - ChatGPT: Use Temporary Chat for sensitive queries - Gemini: myaccount.google.com → Data & Privacy → Gemini Apps Activity → turn off - Copilot: Microsoft account privacy dashboard → review AI data settings Key Takeaways - AI interfaces are designed with conversational warmth specifically because it increases disclosure — that design is a data collection strategy - Deletion does not guarantee destruction: the May 2025 federal court order proved ChatGPT "deleted" conversations can be preserved under legal hold - Default on every major AI platform is collection; opt-out requires navigating settings most users don't know exist - The corporate exposure problem is structural — 67% of AI usage happens on personal accounts IT cannot see - AI psychographic inference manufactures sensitive personal data from behavioral signals — no explicit disclosure required - Privacy-respecting alternatives exist: Confer and Lumo for cloud AI, Ollama for local maximum-security work - Three-tier framework: Confer or Lumo → Ollama for sensitive work → commercial platforms only when the trade-off is consciously accepted Every prompt you type into ChatGPT, Gemini, or Copilot is a data transmission you didn't think of as one. The lawyer who pasted in the brief. The HR director who described the investigation. The founder who uploaded the cap table. None of them made a mistake by their own understanding — but they all made one. Stop treating AI interfaces as private spaces. They are not. Use the tools that were actually built to be — and make that decision before the conversation you can't afford to have retained. Your privacy and your security is your responsibility. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E21
    June 15 · 42 min

    Know Your Threat Level: GrapheneOS vs. SovereignOS — Which One Should You Actually Be Running?

    SovereignOS is a fork of GrapheneOS — Spicy Corp took the gold standard of open-source mobile security and gave it what they call "the Shelby treatment." Like Carroll Shelby re-engineering the Mustang into the GT350, they stripped attack surfaces at the kernel level, replaced stock Google branding, and added operational capabilities GrapheneOS was never designed to include. This episode covers what each system actually does, where each has the edge, and the three-tier decision framework for choosing the one that matches your real threat level. Key Resources GrapheneOS — Official Site & Web Installer (https://grapheneos.org) GrapheneOS Features Overview (https://grapheneos.org/features) GrapheneOS Installation Guide (Web Installer) (https://grapheneos.org/install/web) SovereignOS — Spicy Corp (https://spicycorp.com) GrapheneOS in 2026: An Honest Review — Noctis Privacy (https://noctisprivacy.com/blog/grapheneos-review-2026) GrapheneOS Advanced Privacy Features Guide 2026 (https://www.live-laugh-love.world/blog/grapheneos-advanced-privacy-features-guide-2026/) GrapheneOS vs. SovereignOS: The Shelby Treatment for Secure Phones — Spicy Corp (https://spicycorp.com/2025/07/10/grapheneos-vs-sovereign-os-the-shelby-treatment-for-secure-phones/) SovereignOS Phone — Product Page (Spicy Corp) (https://spicycorp.com/product/sovereignos-phone/) The Three-Tier Decision Framework Tier 1 — Surveillance Capitalism: GrapheneOS. Free, open source, eliminates Google tracking, hardened exploit mitigations. Tier 2 — Elevated Targeting: GrapheneOS with hardened configuration; consider SovereignOS if facing realistic device seizure risk. Tier 3 — Active Adversarial Engagement: SovereignOS. Anti-forensics, covert identity management, silent SMS detection, security temperature modes. GrapheneOS Key Capabilities Hardened memory allocator (defeats heap corruption exploit classes) MTE hardware memory safety (Pixel 8+) Per-app network and sensor permissions Storage Scopes (granular file access control) Vanadium hardened browser Sandboxed Google Play (optional) Full open-source codebase — fully auditable Free SovereignOS Key Capabilities Fork of GrapheneOS — inherits the full GrapheneOS security foundation, then adds operational layer USB data and developer options removed at the kernel level (not disabled — removed) All telemetry endpoints stripped, including "anonymous" ones PIN-to-profile routing (covert identity management, hidden profile switcher) Private Space — hidden app container, separate from profile routing Sentry — dedicated tool protecting against unauthorized access attempts Comms Installer — provisions secure comms stack (Signal, SimpleX, Element) at install from developer sources Multiple wipe triggers: USB connect, Faraday detection, inactivity, failed unlock, duress password (silent wipe — no "ERASING" text) Silent SMS detection (Type 0 / flash SMS — not available in stock GrapheneOS) GPS location spoofing / network fingerprint masking Security temperature modes (Mild / Medium / Hot — one slider, 30+ settings) Stealth branding — stock Google boot animation, no custom OS identifiers visible ATAK plugin support / Meshtastic compatibility Explicit threat defenses: Pegasus, NoviSpy, stalkerware, RATs, banking trojans, rootkits, zero-days Hardware: Pixel 8 through Pixel 10 series (10 models supported) $249.99–$299.99 BYOD, one-time no subscription — spicycorp.com If you are still running stock Android as a daily driver, it's time to level up! Everyone benefits from GrapheneOS. Some require the high performance of SovereignOS. It is time to get serious and make a decision, because your privacy and your security is your responsibility. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E20
    June 1 · 6 min

    COVERT Protocol Action #10: Segment your Online Personas

    Deliberately create separate digital identities or “personas” for different parts of your online life so that your personal information, behavior, and interactions don’t all link back to a single profile. This reduces linkage between activities (shopping, social, work, banking, etc.), limits how much data ad networks and trackers can build about you, and helps contain exposure if one profile is compromised. Creating segmented personas also supports pseudonymization (using alternative identities instead of your real personal details) to minimize privacy risk. Steps to Segment your Online Personas: 1. Define your primary digital roles, ie personal, work, banking. 2. Create unique contact identifiers for each persona, Name, location, email, login credentials. 3. Use alias tools to manage identities, ie MySudo, Cloaked, etc. 4. Maintain compartmentalization, ie Separate browsing contexts, computer profiles, or devices. 5. Review regularly and update as needed. Recommended tools: MySudo - lets you create multiple distinct Sudos (digital profiles) with separate email, phone, and payment details so you can use a different identity for each online purpose without exposing your real contact information. Cloaked - generates unique alias identities (email, phone number, and contact info) for each online service so your real personal details aren’t shared or tracked, helping compartmentalize your online presence. IronVest - privacy-centric browser extension and masking tool that helps block trackers and pseudonymize interactions (including generating proxy info), making it easier to separate and protect different online personas. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E19
    May 18 · 10 min

    COVERT Protocol Action #9: Harden your Home Network

    Strengthen your home network so that your router and connected devices are resilient against attacks, unauthorised access, and privacy invasions. This includes upgrading to more secure firmware, encrypting local and internet traffic, and creating network-level protections that block unwanted connections while allowing only legitimate ones. A hardened home network reduces the risk of compromise for all devices connected to it. Steps to Harden Your Home Network: 1. Upgrade your router firmware or hardware: Replace or upgrade your existing router with one that supports secure, up-to-date, customizable firmware such as OpenWRT, which provides advanced security features, more frequent updates, and strong configuration options compared to many stock router firmwares. 2. Enforce strong Wi-Fi encryption: On your router (especially one running OpenWRT), enable current security standards such as WPA3 or at least WPA2 for wireless networks. Older unsecured modes greatly increase vulnerability to eavesdropping. 3. Set strong administrative credentials: Change the default router admin password to a unique, strong passphrase and disable remote administration over the internet. Default credentials are easily discovered and exploited. 4. Configure network-level VPN: Install and configure a VPN connection at the router level so that all traffic leaving your home network is encrypted and protected from eavesdroppers on public networks and your ISP. Router-level VPN ensures devices that don’t natively support VPN software still benefit from encrypted internet traffic. 5. Segment your network: Create separate network segments or VLANs for trusted devices, guests, and IoT devices so that a compromise in one segment (e.g., insecure IoT) does not easily spread to other critical devices. Recommended tools: OpenWRT routers - GL.iNet Flint 3 (GL-BE9300) - Tri-band Wi-Fi 7 Home Router GL.iNet Slate 7 (GL-BE3600) - Dual-band Wi-Fi 7 Travel Router Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E18
    May 4 · 8 min

    COVERT Protocol Action #8: Audit and Clean Your Online Exposure

    Systematically reduce your publicly visible personal information by identifying where your data appears online (search engines, data brokers, people-search sites) and using services to request removal or opt-out, so third parties and automated systems can’t easily collect, sell, or expose your PII. This step helps protect against spam, identity theft, unsolicited marketing, and malicious activity such as doxxing. Steps to scrubbing your online footprint: 1. Scan for exposure: Search major search engines (e.g., Google) for your name, email, phone number, and other PII to see what’s publicly visible. Note where your data appears. 2. Use a removal service: Sign up for a data removal service to automate opt-out requests to data brokers and people-search sites that hold or publish your personal information. 3. Submit opt-out requests: Depending on the service, you may need to confirm the data to remove or authorize the provider to act on your behalf. 4. Verify removal: After the service processes requests, check periodically (every few months) to confirm your data has been removed or suppressed, and resubmit if necessary. 5. Monitor ongoing exposure: Some services continually monitor your footprint and renew removal requests as new records appear. 6. Repeat periodically: Online exposure evolves over time; schedule regular scrubs to maintain a minimised digital footprint. Recommended tools: Pentester.com: primarily a vulnerability and digital footprint scanner that helps discover compromised credentials or exposed data, and can be used to identify where your personal information might be leaking online. DeleteMe a long-established privacy service that contacts data brokers and people-search sites on your behalf to remove your personal information; it covers hundreds of brokers with ongoing updates. Incogni: a comprehensive personal information removal service that scans numerous data broker sites and submits removal requests, often including coverage of many niche or lesser-known sources. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E17
    April 20 · 14 min

    COVERT Protocol Action #7: Harden your Devices

    Harden your Devices: strengthen the security and privacy of your phones, tablets, laptops, and desktop computers by reducing their attack surface, protecting stored data, and blocking common threats. This includes encrypting data at rest, securing network traffic, tightening web browsing, and using malware protection. Hardened devices are much safer if lost, stolen, or actively targeted. Steps to Harden Your Devices: 1. Enable full disk encryption (FDE): Turn on encryption for your device’s storage so that data is unreadable without your passcode, even if the device is lost or stolen. Most modern OSes allow this (e.g., BitLocker on Windows, FileVault on macOS). 2. Use a VPN connection: Install and configure a reputable Virtual Private Network (VPN) on each device. This encrypts your network traffic when you are on untrusted Wi-Fi or public networks, making it harder for attackers to intercept your communications. 3. Harden your browser: Choose a browser that respects privacy, or harden Firefox yourself. Enforce HTTPS for secure connections.Install privacy/security extensions (e.g., script blockers, ad blockers) to reduce tracking and malicious content. Regularly clear cookies and site data. This reduces exposure to trackers and exploitation. 4. Harden you device: Keep software updated. Install antivirus/anti-malware software. Remove unnecessary software. Use least-privilege accounts. Review privacy/security settings. Back up your data Recommended tools: Privacy Browsers: Brave, LibreWolf, DuckDuckGo Private Browser Browser Extensions: NoScript, uBlock Origin, Firefox Multi Account Containers VPN Service: Proton, Mulvad, NordVPN Antivirus Software: Bitdefender, Avira, Malwarebytes Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E16
    March 30 · 35 min

    COVERT Protocol Action #6: Audit Your Children Social Media Accounts

    Throughout the latest episode, we have discussed operational security in professional settings. Today, we are bringing Gabriel Fanelli, director of training at Grey Dynamics and a former United States SIGINT operator with a Bronze Star commendation, to talk about something more than hardening your devices and obfuscating your networks: Family Security First of all, you are not your kids' best friends; you are their protector and last line of defence against all the threat actors lurking in the dark corners of the Internet. Having said that, here is what you will learn in the episode. The Types of Threats Present in Video Games and Online Forums How To Explain Family Security Procedures to Your Spouse How to Talk To Your Kids About Grooming and Extortion Social Media Rules to Have Around the House Maintaining Your Kid's Security While He Plays Online Games Followers Vetting Processes and Second Device Auditing Your children and your family's security and privacy are your responsibility. They don't have the ability or capability to do it themselves, and you already know what's out there. Harden Up. #Opsec #Security #Family #Home #Veteran Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E15
    March 9 · 7 min

    COVERT Protocol Action #5: Audit Your Social Media Accounts

    Audit your social-media exposure, review all your public or private social-media accounts and online profiles; check what personal information (photos, posts, bio data, connections) is visible; then remove, reduce, or restrict exposure of anything risky or unnecessary. Steps to audit your social media exposure: 1. Make a full list of every social-media profile or public/social online account you’ve ever created (active or dormant). Include mainstream platforms and smaller/less-used ones. 2. Visit each account and carefully examine what can be seen publicly: profile pictures, bio information (name, location, birthdate, contact info), past posts, comments, photos, tags, friend lists. 3. Adjust privacy and visibility settings on each account so that only trusted contacts (friends/followers) can see sensitive content. Delete, lock down or hide: personal details, contact info, location data, old posts. 4. Remove or deactivate any accounts you no longer use, or that you don’t want publicly visible. Dormant accounts may still leak personal data. 5. Scan for “people-search” or public-record sites listing you (or old usernames/email) check what information about you is exposed outside social media. 6. Periodically repeat the audit (every 3–6 months) privacy settings and platform defaults can change; content from connections (tags, shares) or old posts may re-expose you. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E14
    February 23 · 7 min

    COVERT Protocol Action #4: Harden your Communications and Services

    AI assistants have been positioned as productivity tools. Structurally, they are the most sophisticated data collection interfaces ever built — ones that convince users to voluntarily disclose their most sensitive information in the form of natural language conversation. This episode covers what ChatGPT, Gemini, and Copilot actually do with your data, the corporate exposure epidemic (77% of employees are transmitting sensitive data to AI tools), how AI has supercharged the data broker industry through psychographic inference, and the government access problem that no privacy setting can fully solve. Key Stats 4% of AI prompts and 20% of file uploads contain sensitive information (Harmonic Security, 2025) 3 million sensitive records exposed per organization by GenAI tools in H1 2025 77% of enterprise employees leak sensitive data via AI tools 67% of AI tool interactions happen on personal accounts IT cannot monitor 802,000 files at risk per organization in Microsoft 365 environments (Copilot access surface) 16% of business-critical Microsoft 365 data is overshared Psychographic AI inference: 70%+ accuracy predicting political, religious, psychological traits from behavioral data OpenAI privacy audit score: 48/100 (Grade D), 2026 Settings to Change Right Now ChatGPT: Settings → Data Controls → disable "Improve the model for everyone" ChatGPT: Settings → Personalization → Manage Memory → audit and delete stored facts ChatGPT: Use Temporary Chat for sensitive queries Gemini: myaccount.google.com → Data & Privacy → Gemini Apps Activity → turn off Copilot: Microsoft account privacy dashboard → review AI data settings Key Takeaways AI interfaces are designed with conversational warmth specifically because it increases disclosure — that design is a data collection strategy Deletion does not guarantee destruction: the May 2025 federal court order proved ChatGPT "deleted" conversations can be preserved under legal hold Default on every major AI platform is collection; opt-out requires navigating settings most users don't know exist The corporate exposure problem is structural — 67% of AI usage happens on personal accounts IT cannot see AI psychographic inference manufactures sensitive personal data from behavioral signals — no explicit disclosure required Privacy-respecting alternatives exist: Confer and Lumo for cloud AI, Ollama for local maximum-security work Three-tier framework: Confer or Lumo → Ollama for sensitive work → commercial platforms only when the trade-off is consciously accepted Every prompt you type into ChatGPT, Gemini, or Copilot is a data transmission you didn't think of as one. The lawyer who pasted in the brief. The HR director who described the investigation. The founder who uploaded the cap table. None of them made a mistake by their own understanding — but they all made one. Stop treating AI interfaces as private spaces. They are not. Use the tools that were actually built to be — and make that decision before the conversation you can't afford to have retained. Your privacy and your security is your responsibility. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E13
    February 9 · 6 min

    COVERT Protocol Action #3: Implement Multi-Factor Authentication whenever possible

    Implement multi-factor authentication (MFA) on every account, using the strongest method available with a graduated approach: 1. Audit all important accounts (email, banking, cloud storage, social media, password manager) to check whether MFA is supported. 2. For each account, go to the security or login settings and enable MFA. Choose the strongest method the service supports. 3. If using an authenticator app or hardware key, save backup/recovery codes securely (in case you lose your phone or key). 4. For accounts using SMS/email 2FA consider upgrading to a stronger method when available, especially for sensitive accounts. 5. Test the MFA setup by logging out and logging back in to confirm that the second factor works as expected. Recommended Tools Authy: a widely used authenticator app that generates time-based codes for TOTP-based MFA. Proton Authenticator: privacy-focused app for generating MFA codes offline. YubiKey: a hardware security key providing FIDO2/WebAuthn authentication for the strongest protection. More At: https://opsecpodcast.com/ Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E12
    January 26 · 5 min

    COVERT Protocol Action #2: Audit and Secure Your Financial Accounts

    Your money is one of the most targeted assets you own, and one of the easiest to compromise if left unattended. Modern financial attacks start with reused passwords, exposed debit cards, unsecured networks, and excessive data leakage. In this episode of The OPSEC Podcast, we apply the full Covert Protocol framework — Control, Obfuscate, Verify, Encrypt, Reduce, Track — to financial security. From eliminating debit card exposure and deploying masked credit cards, to removing banking apps from mobile devices and enforcing transaction alerts, this is about tightening control and reducing attack surface. Audit every account. Limit access. Monitor relentlessly. Your privacy (and your money) are your responsibility. #OPSEC #CovertProtocol #FinancialSecurity #OperationalSecurity #PrivacyFirst #DigitalHygiene #ThreatReduction #CyberAwareness #PersonalSecurity #RiskManagement Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E11
    January 12 · 9 min

    COVERT Protocol Action #1: Implement a Password Manager

    Allen Pace presents the Covert Protocol, a structured methodology that will combine through different episodes the OPSEC Podcast principles with the CIA Triad practices. By using these two frameworks in tandem, this process aims to equip everyday users (like you) with both the strategic mindset and the practical tools needed to increase security, reduce vulnerabilities, and enhance personal privacy in both the digital and physical realms. Action 1#: Implement a Password Manager Recommended tools: 1. Bitwarden: a popular, open-source password manager that supports syncing, autofill, passkeys, and cross-device use. 2. Proton Pass: a privacy-focused password manager with encryption and strong privacy posture. 3. KeePassXC: an offline/local password manager that stores the vault on your device for maximum control and minimal external dependencies. Steps to implement: 1. Pick a password manager tool (see Recommended tools below) and install it on your primary devices (computer, phone, tablet). Make sure it supports MFA for the vault itself for future hardening. 2. Create a strong master password/passphrase - this should be long, complex, and unique (don’t reuse it anywhere). 3. Begin adding your online account credentials to the vault. For each new account: generate a long random password via the manager, then save it in the vault. For existing accounts: replace weak or reused passwords with new vault-generated ones. 4. If using a cloud-based manager: set up syncing across devices so you have access on laptop, phone, etc. If using an offline/local manager: make regular encrypted backups of the vault (e.g. to an external drive or secure location). 5. From now on, use the vault’s auto-fill or copy/paste feature when logging in, rather than memorizing or reusing passwords elsewhere. #OPESCPodcast #CovertProtocol #CyberSec #Intelligence Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E10
    Dec 8, 2025 · 29 min

    Walmart to WhatsApp: The Hidden Systems Mapping Your Behaviour

    For the past decade, people have underestimated the most powerful surveillance system ever built, not by intelligence agencies, but by corporations. Every movement you make, every store you walk into, every website you open, every conversation near your phone, it’s all collected, correlated, sold, and fed back into behavioural models more invasive than anything that Langley or the Kremlin could ever have dreamed of. Your phone doesn’t just listen. It watches how you walk. It measures how you move. Not only that, but it predicts your emotional state, loneliness cycles, purchasing intent, and even what you’ll search next, before you search it. And you’re paying for the privilege. In this episode of The OPSEC Podcast, Allen and Ahmed break down how modern surveillance works when everyone (from convenience stores to dating apps to foreign intelligence services) is harvesting your data. Not by hacking you, but by exploiting the sensors you voluntarily carry. You’ll discover: How retail stores use enhanced camera networks to track your movement, biometrics, and purchasing behaviour Why your phone’s gyroscope, accelerometer, and Bluetooth signals can identify you even if everything else is turned off How dating apps use motion-sensor analytics to determine when you're lonely, then target you. Why are executives travelling to China with their personal phones are walking SIGINT targets. The truth about burner phones, why 99% of people use them wrong, and how surveillance teams detect them instantly. Why Europe is sleepwalking into a surveillance state through digital ID, KYC expansion, and anti-encryption laws. The hidden danger of bringing compromised devices back into your home network after international travel How modern ads appear seconds after conversations, and why it’s not a coincidence Privacy isn’t dying, it’s being optimised out of existence. Your devices broadcast more intel about you than most people will ever realise. And unless you actively shut down those signals, someone is always listening. Your privacy is your responsibility. Do your due diligence, or accept the consequences. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E9
    Nov 17, 2025 · 23 min

    Faraday Shielding: The Counter-Surveillance Tool For Family Holidays and Everyday Carry

    For more than a decade, intelligence agencies, data brokers, and criminal syndicates have quietly relied on the same vulnerability: your wireless signals. Your phone, your credit cards, your passport, your key fobs — they all broadcast data constantly, whether you realise it or not. And every signal can be intercepted, cloned, profiled, or used against you. In this episode of The OPSEC Podcast, we break down a hard truth: modern tracking doesn’t require hacking — just proximity. Bluetooth skimmers, RFID harvesters, rogue NFC readers, silent ping collectors… they’re everywhere, especially during the holiday travel boom. You’ll learn how Faraday sleeves, RFID-blocking wallets, and shielded travel kits shut down these attacks by cutting off the signals entirely. Not with software. Not with “anti-tracking apps.” But with the same electromagnetic isolation techniques used in classified facilities and intelligence operations since the 1940s. In this episode, you’ll discover: How Bluetooth hijacking and RFID skimming actually work (and why tourists are the easiest targets) Why your phone still broadcasts identifiers even when it’s “off” The difference between consumer-grade Faraday products vs. intelligence-grade shielding Why doubling-layer protection (sleeve + wallet, sleeve + bag) mirrors professional tradecraft The silent rise of contactless credit card theft in crowded holiday shopping zones Why a $10 RFID sleeve can stop a $500 attack before it begins The truth about Faraday backpacks, travel organisers, and which brands actually hold up How to integrate Faraday protection into daily OPSEC without looking like a tactical wannabe If intelligence agencies rely on signal isolation to protect classified hardware, identities, and operational assets, why shouldn’t you use the same principles to protect your phone, passport, and money? Your devices broadcast more about you than you think. Your security is your responsibility. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E8
    Nov 3, 2025 · 20 min

    Masked Payment Cards: Operational Tradecraft for Protecting Financial Footprints

    From an operational-security perspective, financial metadata is one of the most actionable intelligence vectors available to adversaries and fraudsters alike. In this episode of The OPSEC Podcast, host Alan Pace — speaking from field experience — delivers a concise intelligence-grade briefing on masked payment cards (e.g., Privacy.com) and how to incorporate them into a practical OPSEC posture for the holiday shopping surge. What you’ll learn: • The threat model: how e-commerce breaches, merchant telemetry, and secondary data linkages convert routine transactions into persistent identifiers. • Capability assessment of masked card services: merchant-locking, single-use tokens, disposable virtual cards, and how each mitigates specific attack vectors. • Operational procedures: safe account linking, rotation of credentials post-link, and handling of recurring payments to deny blindside billing. • Regional tradecraft: practical alternatives when Privacy.com isn’t available (Revolut, IronVest, Moon/PayWithMoon) and the tradeoffs imposed by KYC/GDPR regimes. • Rules of engagement: when a masked card improves your security posture — and when it merely shifts trust to another third party. This episode reads like a field directive: adopt masked payment cards as a standard control for online purchases, instrument them with strict lifecycle management (create → limit → monitor → kill), and treat payment tokens as mission-critical assets. Practical, repeatable, and defensive — because operational security begins at the point of payment. Hosted on Acast. See acast.com/privacy for more information.

  • S1 · E7
    Oct 20, 2025 · 37 min

    How the CIA Owned an Encryption Company for 50 Years (And Why Your VPN Might Be Next)

    For 50 years, 130 governments trusted Crypto AG to protect their most secret communications. Every single message was being read by the CIA and German intelligence. Operation Rubicon was the longest-running espionage operation in history. The CIA secretly bought a Swiss encryption company in 1970, installed backdoors in every device, and sold “secure” communications to governments worldwide. Nobody suspected a thing – until 2020. Now it’s happening again. But this time, they’re buying your VPN companies. Kape Technologies – an Israeli company founded by former adware criminals with ties to Unit 8200 (Israel’s NSA) – quietly bought ExpressVPN in 2021. They also own CyberGhost, PIA, and Zenmate. Plus all the VPN “review” sites that conveniently rank their products at the top. In this episode of The OPSEC Podcast, you’ll discover: Why Chinese VPNs like Turbo VPN are 51% owned by the Communist Party (and why they target American teenagers on TikTok) How Russian VPNs like Kaspersky are legally required to give the FSB access to all your traffic Why “free VPNs” turn your computer into a botnet zombie (the Hola VPN scandal) What VPNs actually do vs. the anonymity BS they claim in their marketing The only 3 VPN companies that pass the trust sniff test: ProtonVPN, Mullvad, and NordVPN A VPN does not equal automatic privacy. It’s outsourcing trust from one party to another. If you take trust from your ISP and give it to a malicious actor, you’re worse off than having no VPN at all. Free VPNs make YOU the product. Israeli companies inject adware. Chinese companies feed data to the CCP. Russian companies hand everything to the FSB. Check who owns the VPN – not just where the servers are located. Because if the CIA launched a VPN service promising “guaranteed privacy,” they’d sell exactly zero subscriptions. So why trust companies with the same intelligence agency connections? Your privacy is your responsibility. Do your due diligence or accept the consequences. Hosted on Acast. See acast.com/privacy for more information.

Showing 1–20 of 21 episodes