491 episodes
- Over the last 2-3 months, large software makers such as Microsoft have been releasing tons of fixes for vulnerabilities in their apps and operating systems. Did their software suddenly get a lot worse? No. They’re using the latest AI tools to find these bugs that humans missed and that have been lurking in their software for months or even years – and they’re fixing them. That’s great news… but these fixes won’t do you any good unless you install them. Bad guys are using these same tools to exploit these bugs. There’s never been a better time to update all your devices’ software.
In other news: a hidden car device leaves many cars vulnerable to hacking; most fitness wearables don’t encrypt users’ data end-to-end; Iran is tracking US military phones; CBP accuses citizen of wiping phone using “duress” password; US says Iran is hacking critical infrastructure; US also warns that Russia and China are hacking small office routers; US judge denies broad “stringray” warrant in Ohio; LG to ban proxy apps on their TVs; Maine librarians teach patrons how to remove AI features.
Article Links
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now
Most fitness wearables lack end-to-end encryption and don’t disclose government data demands, says EFF: https://this.weekinsecurity.com/most-fitness-wearables-lack-end-to-end-encryption-and-lack-transparency-reports
Financial Times: US military smartphones targeted through roaming and ad tech: https://harrigan.house.gov/media/in-the-news/financial-times-us-military-smartphones-targeted-through-roaming-and-ad-tech
US accuses American of allegedly wiping his phone using a ‘duress’ password during border search: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search
US government says Iran-linked hackers are disrupting American water and energy providers: https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers
The US government warns that Russia state hackers are coming after your router: https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router
U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents: https://this.weekinsecurity.com/us-judge-denied-feds-month-long-warrant-to-snoop-on-the-phones-of-thousands-of-ohio-residents
LG to Ban Residential Proxies from Smart TV Apps: https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps
These Maine librarians are helping patrons resist AI and Big Tech: https://www.bangordailynews.com/2026/07/02/midcoast/midcoast-culture/maine-librarians-are-helping-patrons-resist-ai-joam40zk0w
Tip of the Week: https://firewallsdontstopdragons.com/update-all-the-things/
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
Zero-Day documentary: https://www.imdb.com/title/tt5446858/
EFF’s Rayhunter: https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying
This Week in Security: https://this.weekinsecurity.com/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Table of Contents
0:00:07: Intro
0:00:25: Phase 1 reminder
0:04:09: Quick news bites
0:05:54: News rundown
0:07:35: Hidden card device vulnerable to hacks
0:15:00: Most fitness wearables lack E2EE
0:19:19: Iran tracking military smartphones
0:26:58: US accuses citizen of wiping phone with “duress” password
0:33:15: US Gov’t claims Iran attaching infrastructure
0:38:03: Russia attacking US routers
0:42:37: Judge denies “Stingray” warrant
0:49:09: LG TV to ban proxy network apps
0:53:57: Maine librarians help patrons remove AI
1:00:54: Tip of the Week
1:10:18: Reminders
1:11:17: Patron podcast preview
1:11:49: Looking ahead - With modern AI tools, how do we know which images and videos are real and which ones are generated? Wouldn’t it be helpful to have some digitally verifiable way to tell where something came from and whether it has been altered? Turns out, that technology already exists. It’s open and free to use, and it’s supported by many technology companies. I’ll be digging into all the details of the Coalition for Content Provenance and Authenticity (C2PA) with Jacobo Castellanos from Witness.org.
Interview Notes
Jacobo Castellanos: https://www.witness.org/portfolio_page/jacobo-castellanos/
Witness: https://witness.org
Coalition for Content Provenance and Authenticity: https://c2pa.org/
Content Authenticity Initiative (CAI): https://contentauthenticity.org/
Content Credentials explainer: https://www.linkedin.com/help/linkedin/answer/a6282984
The Guardian Project: https://guardianproject.info/
Creator Assertions Working Group: https://cawg.io/
ProofMode tool: https://proofmode.org/
C2PA Content Credentials and the Surveillance Risk: https://library.witness.org/product/c2pa-privacy/
How C2PA works: https://contentauthenticity.org/how-it-works
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Table of Contents
0:00:13: Intro
0:01:17: Interview prep
0:02:39: Lingo
0:04:10: What is Witness.org?
0:06:22: What is the purpose of C2PA?
0:09:26: How does C2PA work?
0:17:28: Is C2PA embedded in our devices, too?
0:19:57: Are there fees or licensing required to use C2PA?
0:22:41: Does C2PA info include creator information?
0:26:41: As a user, how do I experience C2PA info?
0:30:54: Can C2PA be used to undo changes?
0:32:46: What are C2PA’s limitations?
0:38:36: Does C2PA report data to third parties?
0:41:07: Could C2PA be used to limit information?
0:45:27: Can C2PA info be removed? Reattached?
0:48:35: Is here a global C2PA content registry?
0:49:53: How do certificate authorities work?
0:53:37: Are any laws requiring provenance info?
0:56:56: How can we get involved?
0:59:15: How do we re-establish trust in our news?
1:02:27: Wrap-up
1:03:39: Patron podcast preview
1:05:23: Reminder for Phase 1
1:05:47: Looking ahead - It’s time to start the official countdown to my 500th podcast episode! I’ve been publishing a podcast every single week for over nine years now, which is a rather amazing accomplishment (if I do say so myself). But the entire purpose of the podcast – as well as my book and my blog – has been to try to improve the security and privacy of as many people as possible. So to celebrate this momentous occasion, I’m going to be conducting an experiment to figure out the most effective way to protect our data and devices. And I’m going to need your help.
In the news: Chat Control 1.0 has been resurrected in the EU; Apple’s Hide My Email is failing to do so; Meta patents a new, creepy wearable device; The Intercept’s Signal account was taken over for months; Papa Johns wants to know when your fridge is empty; Opera Browser has a new feature to combat ClickFix attacks; Google disrupted a residential proxy network; John Deere has been forced to support third party repairs; and the Supreme Court further protected our device location history.
Article Links
Chat Control 1.0 sneaks through the EU Parliament: https://www.tomshardware.com/tech-industry/cyber-security/chat-control-1-0-sneaks-through-the-eu-parliament-letting-companies-scan-user-data-without-warrants-legal-tactic-used-to-force-a-majority-required-re-vote-on-eve-of-parliament-break
Apple Hide My Email bug allows 100% of real email addresses to be discovered: https://9to5mac.com/2026/07/01/apple-hide-my-email-bug-seemingly-allows-100-of-real-email-addresses-to-be-discovered
Meta Patents AI Device That Tracks Your Emotions, Watches You Take Your Meds: https://www.404media.co/meta-patents-ai-device-that-tracks-your-emotions-watches-you-take-your-meds
The Intercept’s Signal tipline username was hijacked for months: https://cyberinsider.com/the-intercepts-signal-tipline-username-was-hijacked-for-months
Papa Johns Can Predict When Your Fridge Is Empty: https://www.adexchanger.com/?p=461783
Opera’s new security feature stops copy paste attacks from malicious websites – Engadget: https://www.engadget.com/2206574/opera-new-security-feature-stops-copy-paste-clickfix-attacks
Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices: https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html
The Deere Dam Just Broke: FTC Settlement Empowers Farmers Right To Repair: https://fighttorepair.substack.com/p/the-deere-dam-just-broke-ftc-settlement
Justices rule that cellphone location histories are protected by the Fourth Amendment: https://therecord.media/supreme-court-geofencing-ruling-fourth-amendment
Tip of the Week: https://firewallsdontstopdragons.com/celebrating-500-episodes/
Further Info
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
Hacking the water supply: https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Table of Contents
0:00:07: Intro
0:01:07: Quick headlines
0:03:18: News rundown
0:04:40: Chat Control 1.0 is back
0:09:27: Apple Hide My Email exposes real address
0:13:15: New creepy Meta patent
0:19:16: Intercept loses Signal account
0:23:52: Papa Johns knows when your fridge is empty
0:27:54: Opera implement ClickFix protections
0:32:49: Google foils residential proxy maker
0:38:23: John Deere forced to allow user repairs
0:41:06: SCOTUS restricts location data, again
0:46:04: Tip of the Week
0:53:17: Wrap-up
0:55:01: Hacker summer camp
0:55:42: Patron podcast preview
0:56:13: Looking ahead - Our Constitutional rights were written without any concept of modern technology such as cell phones and the internet. Much of our privacy laws are still geared towards the pre-digital age. Even though the internet is many decades old now, the era of traveling with smartphones and laptops is still relatively new and the laws around privacy have not kept up. Today I’ll be speaking with Nathan Freed Wessler from the ACLU about device searches, particularly at the US border. We’ll also talk about how cases relating to location tracking have evolved since the landmark Carpenter case that Nate successfully argued in front of the Supreme Court almost 10 years ago now.
Interview Notes
ACLU: https://aclu.org/
Nate Wessler: https://www.aclu.org/bios/nathan-freed-wessler
My first interview with Nate: https://podcast.firewallsdontstopdragons.com/2022/08/01/now-place-left-to-hide/
ACLU facial recognition suit: https://reason.com/2026/06/11/aclu-sues-after-facial-recognition-falsely-identifies-florida-man-as-a-child-abductor/
Travel Insecurity: https://firewallsdontstopdragons.com/border-insecurity/
Further Info
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:12: Intro
0:02:37: What makes border searches different, legally?
0:08:15: What is the 100 mile rule?
0:12:42: How do digital searches differ from physical?
0:19:26: What is digital contraband?
0:23:33: How does ‘in plain site’ work on a phone?
0:26:29: How has the Carpenter decision held up?
0:32:59: Should Carpenter apply to ALPRs?
0:41:29: How does AI complicate matters?
0:47:11: How should we prepare for border searches?
0:59:49: What about privileged or corporate data?
1:03:33: Can I lock my device before I hand it over?
1:05:30: What’s next for you and the ACLU?
1:08:36: Wrap up
1:11:01: Patron podcast preview
1:11:27: Looking ahead - With the 500th podcast and America’s 250th anniversary approaching, I’ve been doing a lot of thinking about how we can be better digital neighbors and digital citizens. We’re all in this together. Your security and privacy overlaps the security and privacy of many others. It’s important to improve our own situation, but we need to also realize that failing to do so can put others at risk who may be more vulnerable and have more to lose that we do.
In the news: massive Fortinet breach; feds recover activists’ Signal messages; Visa partners with ChatGPT for agentic purchases; Anthropic models banned for export; US shortens cyber fix window to 3 days; EPIC endorses two new privacy bills; Canada’s spy agency hacks devices to clean out botnet; nearly half of LG smart TVs apps contain proxy SDKs; EFF calls out Amazon for shady Android devices containing proxies.
Article Links
Massive breach spills credentials for thousands of sensitive networks: https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks
How Did the Feds Get Into Anti-ICE Activists’ Signal Messages?: https://theintercept.com/2026/06/17/signal-messages-minneapolis-ice-protests
Visa plugs its payment network into ChatGPT, letting AI agents shop and pay for users: https://apnews.com/article/visa-chatgpt-openai-shopping-mastercard-d769dec86344cb4977c98789e8ec492f
The Fable 5 Export Controls Harm US Cyber Defense: https://www.lutasecurity.com/post/the-fable-5-export-controls-harm-us-cyber-defense
US shortens cyber fix window to three days as AI threats rise: https://www.reuters.com/legal/litigation/us-shortens-cyber-fix-window-three-days-ai-threats-rise-2026-06-10
EPIC Endorses Federal Bills Barring Worker Surveillance, Automated Workplace Decisions: https://epic.org/epic-endorses-federal-bills-barring-worker-surveillance-automated-workplace-decisions
Canada’s Spy Agency Used First-of-Its-Kind Warrant to Clean Botnet-Infected Devices: https://thehackernews.com/2026/06/canadas-spy-agency-used-first-of-its.html
Nearly Half of LG Smart TV Apps Contain Residential Proxy SDKs: https://spur.us/blog/smart-tv-apps-residential-proxy-sdks
Primed for Malware: Stop Selling Compromised Android Devices: https://www.eff.org/deeplinks/2026/06/primed-malware-stop-selling-compromised-android-devices
Tip of the Week: https://firewallsdontstopdragons.com/we-can-do-this/
Further Info
Loupe app (Mysk): https://apps.apple.com/us/app/loupe-what-apps-can-see/id6766152470
Loupe app overview (Techlore): https://www.youtube.com/watch?v=_n_SpEWtqog
Free Fable petition: https://freefable.org/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:07: Intro
0:00:23: Quick news bits
0:02:46: News rundown
0:05:01: Massive Fortinet breach
0:12:27: Signal data security limits
0:17:58: Visa integrates with ChatGPT
0:23:01: Free Fable
0:30:35: US shortens cyber fix window
0:32:25: New federal privacy bills
0:35:18: Canada spy agency cleans up botnet
0:40:34: Shady Samsung TV apps
0:50:10: EFF on Android proxy devices
0:55:57: Tip of the Week
1:03:02: Patron podcast preview
1:03:27: Looking ahead
More Technology podcasts
Trending Technology podcasts
About Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Podcast websiteListen to Firewalls Don't Stop Dragons Podcast, All-In with Chamath, Jason, Sacks & Friedberg and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Firewalls Don't Stop Dragons Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.




































