Skip to content
PodcastsTechnologyFirewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast

Carey Parker
Firewalls Don't Stop Dragons Podcast
Latest episode

500 episodes

  • Firewalls Don't Stop Dragons Podcast

    Here’s to 500!!

    09/28/2026 | 1h 32 mins.
    Today marks an incredible milestone for this podcast: 500 episodes! Not only is that a crazy long run for any podcast, but I’ve also been astonishingly consistent. I’ve managed to put out an episode of this show every single week for 500 straight weeks! Okay… I did miss one week 8 years ago… I’ll give you that story in today’s podcast. But as always for my “podcentennial” episodes, my guest is the one and only global cybersecurity guru Bruce Schneier. He’s been on the show for every 100th podcast. Today I’ll ask Bruce some deep questions about artificial intelligence and how he sees it impacting our future – not just in the technical realm, but the political and social realms, as well. We also have some special surprises and bonus content for this momentous occasion!

    Interview Notes

    Bruce Schneier: https://www.schneier.com/ 

    Bruce’s DEF CON 34 talk: https://www.youtube.com/watch?v=eEBv0STiYhI 

    Bruce’s books: https://www.schneier.com/books/ 

    Inrupt’s Solid Project: https://www.inrupt.com/solid 

    Apertus AI: https://www.apertus-ai.org/ 

    Cap’N Crunch whistle: https://www.thingiverse.com/thing:6192416 

    Citizenfour: https://www.imdb.com/title/tt4044364/ 

    Techlore: https://techlore.tech/ 

    The New Oil: https://thenewoil.org/en/ 

    Privacy Guides: https://www.privacyguides.org/ 

    Privacy Safe: https://privacysafe.social/ 

    Micah’s book: https://nostarch.com/hacks-leaks-and-revelations 

    UnDisruptable27: https://u27.org

    Yael’s blog: https://yaelwrites.com/ 

    Cult of the Dead Cow:  https://cultdeadcow.com/ 

    Bob Lord’s Hacklore: https://www.hacklore.org/ 

    David Ruiz: https://www.malwarebytes.com/blog/authors/davidruiz 

    Melanie Ensign’s Discernible: https://www.discernibleinc.com/ 

    Further Info

    Help me celebrate this 500th show!!! : https://fdsd500.com 

    Pay it forward and help others : https://fdsd.me/phase2 

    Last chance to get #FDSD500 merch!! https://fdsd.me/merch 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Support the mission: https://fdsd.me/support 

    Table of Contents

    0:00:00: Congratulations, part 1

    0:01:47: Intro

    0:07:12: Congratulations, part 2

    0:10:31: Intro, continued

    0:12:01: Stay tuned…

    0:13:16: Interview setup

    0:15:26: What are the key parts of a modern LLM?

    0:23:03: How do we defend against prompt injection?

    0:27:09: Should AI agents only act on our behalf?

    0:32:10: Who’s responsible when AI attacks?

    0:35:25: Will AIs end up fighting each other?

    0:41:47: How will AI’s speed and scale change security?

    0:46:50: Should we own our personal AI data?

    0:55:03: Can we trust AI with all our data?

    0:59:24: Does AI enhance mass surveillance?

    1:03:09: How do we democratize AI?

    1:06:24: What can we do to manifest the best AI future?

    1:11:08: Wrap-up

    1:11:42: Cap’n Crunch whistle

    1:13:50: Thank you patrons!!!

    1:16:27: FDSD by the numbers

    1:23:25: Phase 1, 2 update

    1:26:17: Phase 3?

    1:26:55: Special bonus guest target

    1:29:18: Patron podcast preview

    1:30:40: Last call for FDSD500 merch

    1:31:14: Looking ahead
  • Firewalls Don't Stop Dragons Podcast

    Solving the AI Paradox

    09/21/2026 | 1h 3 mins.
    In the last week, many news organizations have breathlessly covered the “AI doomer” comments by a former Anthropic employee, who said that many of his colleagues were secretly worried about AI ending all of humanity – and that it could happen in just a few years. But to me, there are more pressing concerns with AI and so far we’ve not responded in useful ways. I have several thoughts.

    In the news: Android patches some severe bugs (update now); Google implements method to securely move passwords and passkeys; Radaris loses its domains in court fight; Boston dumps Flock cameras; Discord is going through with age verification; CISA is cutting programs that help secure critical infrastructure; hackers reveal Flock’s camera software; AI companies are reading chatbot session text; Apple debuts Apple Watch constant audio recording; and an interesting article on how to avoid the AI automation paradox.

    Article Links

    News Briefs

    Google fixes actively exploited Android zero-day on Pixel devices: https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices

    Google is making it easier to switch between password managers on Android: https://techcrunch.com/2026/09/10/google-is-making-it-easier-to-switch-between-password-managers-on-android

    Data Broker Radaris Loses Domains in Privacy Fight – Krebs on Security: https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight

    Boston dumps Flock, says it shared data nationwide in violation of contract: https://arstechnica.com/tech-policy/2026/09/boston-dumps-flock-says-it-shared-data-nationwide-in-violation-of-contract

    Discord Is Bringing Back Age Verification for Millions of Users: https://www.gadgetreview.com/discord-is-bringing-back-age-verification-for-millions-of-users

    CISA Cuts Critical Infrastructure Security Resources: https://www.securitymagazine.com/articles/102561-cisa-cuts-critical-infrastructure-security-resources

    Full Stories

    Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People: https://www.404media.co/hackers-stole-flocks-camera-software-revealing-how-the-company-tracks-cars-and-people-2

    Inside ‘Project Lily’: The Humans Reading Your ChatGPT Chats: https://www.404media.co/inside-project-lily-the-humans-reading-your-chatgpt-chats

    Watch what you say: Apple opens the door to a nightmare world of always-listening tech: https://this.weekinsecurity.com/watch-what-you-say-apple-opens-the-door-to-a-nightmare-world-of-always-listening-tech

    The AI Researcher Who Just Quit Anthropic Says It’s ‘Crunch Time for Humanity’: https://www.wired.com/story/anthropic-researcher-quits-jacob-coxon-ai-fears-humanity

    AI Efficiency Could Cost Us the Next Generation of Experts: https://spectrum.ieee.org/ai-engineer-skills

    Tip of the Week: https://firewallsdontstopdragons.com/solving-the-ai-paradox/ 

    Further Info

    Pay it forward and help others : https://fdsd.me/phase2 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Support our mission! https://fdsd.me/support 

    Table of Contents

    0:00:07: Intro

    0:01:53: News rundown

    0:04:07: Update your Android devices

    0:04:34: Android adopts credential moving tech

    0:06:06: Radaris loses key domains

    0:07:13: Boston ends Flock contract

    0:07:52: Discord brings back age verification

    0:09:38: CISA cuts critical support

    0:11:14: Hackers reveal Flock software

    0:19:10: Humans reading LLM chats

    0:27:09: New Apple watch recording feature

    0:34:28: AI employee sounds alarm

    0:39:22: Efficiency at what cost?

    0:48:54: Tip of the Week

    0:59:56: Wrapup

    1:02:07: Patron podcast preview

    1:02:38: Looking ahead
  • Firewalls Don't Stop Dragons Podcast

    Obscuring the Exit

    09/14/2026 | 1h 4 mins.
    While we do have some state privacy laws in the US that require companies to allow you to opt out of data collection, these companies have devised clever ways to make these options very hard to find and/or very hard to choose in a clear and consistent manner. The Electronic Privacy Information Center (EPIC) has done a study on several such companies and the tricky ways they have obscured the mechanisms to assert your privacy rights. We’ll get all the details from one of the co-authors of this report, Caroline Kraczon.

    Interview Notes

    EPIC: https://epic.org/ 

    Opt out dark patterns: https://epic.org/press-release-epic-releases-new-report-on-manipulative-design-patterns-in-opt-out-processes/ 

    Full report (PDF): https://epic.org/wp-content/uploads/2026/05/Good-Luck-Opting-Out-Manipulative-Design-Patterns-in-Opt-Out-Processes.pdf 

    How to enable Global Privacy Control: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ 

    Yael Graur’s BADBOOL list: https://github.com/yaelwrites/big-ass-data-broker-opt-out-list 

    EasyOptOuts: https://easyoptouts.com/ 

    My series on removing online data:  https://firewallsdontstopdragons.com/osint-reconnaissance/ 

    How to enable GPC: https://firewallsdontstopdragons.com/how-to-enable-global-privacy-control/ 

    Further Info

    Phase 2 has begun!! : https://fdsd.me/phase2 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Support the mission: https://fdsd.me/support 

    Table of Contents

    0:00:13: Intro

    0:01:05: Interview setup

    0:02:32: What are dark patterns?

    0:08:21: What dark patterns did you see?

    0:16:01: How are state-based laws enforced on the open web?

    0:18:03: Which companies did you study?

    0:19:52: Which companies were worst?

    0:23:16: How can data gathering be harmful?

    0:27:29: How is the notice and concent model broken?

    0:33:15: Does AI enable a whole new privacy risk?

    0:35:38: What’s the response been to your report?

    0:37:15: Why is publicly available data exempt?

    0:42:02: How useful are “privacy checkup” tools?

    0:45:13: How effective are privacy laws?

    0:52:00: How can we reduce incentives to collect data?

    0:54:18: What can we do?

    0:59:09: Wrap-up

    1:02:07: Patron podcast preview

    1:02:47: Looking ahead
  • Firewalls Don't Stop Dragons Podcast

    Use a Secure Wi-Fi Router

    09/07/2026 | 1h 21 mins.
    Probably the single most important device on your home network in terms of security is your Wi-Fi router. In most cases, it’s the only thing between all your networked devices and the Internet’s bad guys. It’s crucial that you’re using an updated (and update-able) device from a reputable maker. I’ll explain why it’s important and how to pick a good router.

    In other news: Plex media server urges users to update their software immediately; Meta settles a lawsuit for $18B and promises changes for kids; 153M personal ID cards were stolen and are for sale; ChatGPT has a new plugin to read and manage your iMessages; study shows Windows apps tattling on users; researcher shows how secret ballots can be re-identified; US Senator asks NSA to publish info on how to choose and use a good VPN; Flock vigilantism and vandalism soars; researchers find blatant back doors in cheap Chinese routers.

    Article Links

    News Briefs

    Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws: https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html

    Meta to pay $18 billion in teen social media addiction settlement: https://proton.me/blog/meta-teen-addiction-settlement

    Full Stories

    Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof: https://gizmodo.com/identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof-2000806437

    ChatGPT’s iMessage plugin opens a backdoor in Apple Messages: https://proton.me/blog/chatgpt-apple-messages

    Hidden Tracking in Windows Apps: https://adguard.com/en/blog/how-desktop-apps-watch-you-research.html

    An Algorithmic Failure Beneath the Secret Ballot: https://blog.citp.princeton.edu/2026/08/03/an-algorithmic-failure-beneath-the-secret-ballot

    Confused about which VPN is right, US senator asks the NSA for guidance: https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns

    Vigilantism comes for Flock: https://this.weekinsecurity.com/vigilantism-comes-for-flock

    Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware: https://www.tomshardware.com/tech-industry/cyber-security/security-researchers-find-surveillance-implants-in-chinese-made-routers-sold-worldwide-three-different-backdoor-like-implants-hidden-in-firmware

    Further Info

    Phase 2 is under way! : https://fdsd.me/phase2 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    Jellyfin media server: https://jellyfin.org/ 

    Tailscale: https://tailscale.com/ 

    Proton blog: https://proton.me/blog 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Support our mission! https://fdsd.me/support 

    Table of Contents

    0:00:07: Intro

    0:02:26: 6th Edition update

    0:04:15: News rundown

    0:06:17: Plex media server critical fixes

    0:08:47: Meta’s $18B lawsuit loss

    0:10:40: 153M ID’s for sale

    0:19:11: ChatGPT plugin for iMessage

    0:27:28: Windows app tracking

    0:38:23: Using AI to reveal your voting

    0:48:42: Senator requests NSA VPN guidance

    0:53:20: Rise in Flock vandalism

    1:01:17: Chinese routers with built-in backdoors

    1:09:48: Tip of the Week

    1:19:21: Phase 2 reminder

    1:20:14: Patron podcast preview

    1:20:34: Looking ahead
  • Firewalls Don't Stop Dragons Podcast

    Supply Chain Attacks

    08/31/2026 | 1h 15 mins.
    Software apps today are a hodgepodge of libraries, software development kits, and third party code, all stitched together like Frankenstein’s monster. Furthermore, software developers use common tools to create and deploy this software. The bad guys have figured out that by compromising one of these third party components or the tools used to create the products, they can instantly infect hundreds or thousands of products that all share the same underlying resources. This is a supply chain attack. Today we’ll discuss these single points of failure, how to identify them ahead of time and try to prevent these sorts of attacks with Cassie Crossley, CEO and co-founder of VulNow.

    Interview Notes

    Cassie Crossley: https://www.linkedin.com/in/cassiecrossley/ 

    VulNow company website: https://vul.now/

    VulNow’s Pre-CVE database: https://precve.vulnow.com/ 

    CyBeats company website: https://www.cybeats.com/

    Software Supply Chain Security (book): https://www.oreilly.com/library/view/software-supply-chain/9781098133696/ 

    Proton blog on supply chain security: https://proton.me/business/blog/supply-chain-attack 

    Malus AI re-write tool: https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/ 

    xkcd on Dependency: https://xkcd.com/2347/ 

    Updated dependency diagram: https://www.grc.com/SN/1078.jpg 

    Further Info

    Phase 2 has begun!! : https://fdsd.me/phase2 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Support the mission: https://fdsd.me/support 

    Give the gift of privacy and security: https://fdsd.me/coupons 

    Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    0:00:14: Intro

    0:00:35: Phase 2 reminder

    0:01:52: Interview setup

    0:06:05: What is VulNow?

    0:08:34: What software is vulnerable to supply chain attacks?

    0:13:16: Have you heard of AI clean room coding?

    0:15:34: How do SW supply chain attacks work?

    0:21:21: How do we identify the weak points?

    0:34:24: What are SBOM’s and how do they work?

    0:43:45: What is needed beyond SBOMs?

    0:50:32: Can tools reveal the contents of SW?

    0:56:13: How do we encourage SBOM creation?

    1:01:35: As consumers, how do we know who to trust?

    1:06:09: What’s next for you?

    1:08:46: Wrap-up

    1:13:23: Patron podcast preview

    1:14:19: Looking ahead
More Technology podcasts
About Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Podcast website

Listen to Firewalls Don't Stop Dragons Podcast, Bourbon with Brad and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features