497 episodes
- Probably the single most important device on your home network in terms of security is your Wi-Fi router. In most cases, it’s the only thing between all your networked devices and the Internet’s bad guys. It’s crucial that you’re using an updated (and update-able) device from a reputable maker. I’ll explain why it’s important and how to pick a good router.
In other news: Plex media server urges users to update their software immediately; Meta settles a lawsuit for $18B and promises changes for kids; 153M personal ID cards were stolen and are for sale; ChatGPT has a new plugin to read and manage your iMessages; study shows Windows apps tattling on users; researcher shows how secret ballots can be re-identified; US Senator asks NSA to publish info on how to choose and use a good VPN; Flock vigilantism and vandalism soars; researchers find blatant back doors in cheap Chinese routers.
Article Links
News Briefs
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws: https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html
Meta to pay $18 billion in teen social media addiction settlement: https://proton.me/blog/meta-teen-addiction-settlement
Full Stories
Identity Verification Is Broken. The 153 Million Driver’s Licenses Now for Sale Are Proof: https://gizmodo.com/identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof-2000806437
ChatGPT’s iMessage plugin opens a backdoor in Apple Messages: https://proton.me/blog/chatgpt-apple-messages
Hidden Tracking in Windows Apps: https://adguard.com/en/blog/how-desktop-apps-watch-you-research.html
An Algorithmic Failure Beneath the Secret Ballot: https://blog.citp.princeton.edu/2026/08/03/an-algorithmic-failure-beneath-the-secret-ballot
Confused about which VPN is right, US senator asks the NSA for guidance: https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns
Vigilantism comes for Flock: https://this.weekinsecurity.com/vigilantism-comes-for-flock
Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware: https://www.tomshardware.com/tech-industry/cyber-security/security-researchers-find-surveillance-implants-in-chinese-made-routers-sold-worldwide-three-different-backdoor-like-implants-hidden-in-firmware
Further Info
Phase 2 is under way! : https://fdsd.me/phase2
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
Jellyfin media server: https://jellyfin.org/
Tailscale: https://tailscale.com/
Proton blog: https://proton.me/blog
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Table of Contents
0:00:07: Intro
0:02:26: 6th Edition update
0:04:15: News rundown
0:06:17: Plex media server critical fixes
0:08:47: Meta’s $18B lawsuit loss
0:10:40: 153M ID’s for sale
0:19:11: ChatGPT plugin for iMessage
0:27:28: Windows app tracking
0:38:23: Using AI to reveal your voting
0:48:42: Senator requests NSA VPN guidance
0:53:20: Rise in Flock vandalism
1:01:17: Chinese routers with built-in backdoors
1:09:48: Tip of the Week
1:19:21: Phase 2 reminder
1:20:14: Patron podcast preview
1:20:34: Looking ahead - Software apps today are a hodgepodge of libraries, software development kits, and third party code, all stitched together like Frankenstein’s monster. Furthermore, software developers use common tools to create and deploy this software. The bad guys have figured out that by compromising one of these third party components or the tools used to create the products, they can instantly infect hundreds or thousands of products that all share the same underlying resources. This is a supply chain attack. Today we’ll discuss these single points of failure, how to identify them ahead of time and try to prevent these sorts of attacks with Cassie Crossley, CEO and co-founder of VulNow.
Interview Notes
Cassie Crossley: https://www.linkedin.com/in/cassiecrossley/
VulNow company website: https://vul.now/
VulNow’s Pre-CVE database: https://precve.vulnow.com/
CyBeats company website: https://www.cybeats.com/
Software Supply Chain Security (book): https://www.oreilly.com/library/view/software-supply-chain/9781098133696/
Proton blog on supply chain security: https://proton.me/business/blog/supply-chain-attack
Malus AI re-write tool: https://www.404media.co/this-ai-tool-rips-off-open-source-software-without-violating-copyright/
xkcd on Dependency: https://xkcd.com/2347/
Updated dependency diagram: https://www.grc.com/SN/1078.jpg
Further Info
Phase 2 has begun!! : https://fdsd.me/phase2
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:14: Intro
0:00:35: Phase 2 reminder
0:01:52: Interview setup
0:06:05: What is VulNow?
0:08:34: What software is vulnerable to supply chain attacks?
0:13:16: Have you heard of AI clean room coding?
0:15:34: How do SW supply chain attacks work?
0:21:21: How do we identify the weak points?
0:34:24: What are SBOM’s and how do they work?
0:43:45: What is needed beyond SBOMs?
0:50:32: Can tools reveal the contents of SW?
0:56:13: How do we encourage SBOM creation?
1:01:35: As consumers, how do we know who to trust?
1:06:09: What’s next for you?
1:08:46: Wrap-up
1:13:23: Patron podcast preview
1:14:19: Looking ahead - As part of my celebration of the upcoming 500th podcast, I’m launching Phase 2 of my “cyber neighbor” campaign to both help as many people be more secure and private as possible, but to also learn from this experience so I can improve these campaigns in the future. In particular, as I write the 6th edition of my book, I’m funneling this feedback into improving those Tips, as well.
In the news: Flock considered utilizing ride share and delivery vehicles to expand their ALPR network; judge rules ‘tower dump’ warrants unconstitutional; BMW’s show Spider-Man ads; hackers reuse expired domains for scams and malware; US warns of more PLC attacks; US proposal would allow private companies to launch cyber attacks on foreign groups; terabytes of credentials stolen in supply chain attack; customer downloads his 515-page McDonald’s dossier; AI agent hacks gym site to book a class; town claims Flock reactivated cameras without notice; and Chrome trials new device-bound session credentials.
Article Links
News Briefs
Flock wanted to put license plate cameras on 350,000 Uber and Lyft dashcams: https://www.techspot.com/news/113407-flock-wanted-put-license-plate-cameras-350000-uber.html
‘Tower dump’ warrants ruled unconstitutional: https://thehill.com/regulation/court-battles/6013559-mississippi-judge-declares-towers-dumps-unconstitutional
BMWs are showing a commercial at startup: https://boingboing.net/2026/08/06/bmws-are-showing-a-spider-man-movie-ad-at-startup.html
Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware: https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html
Full Stories
US warns of AI-powered attacks on Siemens PLCs in critical infrastructure: https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attacks-on-siemens-plcs-in-critical-infrastructure
In a first, US will allow some private firms to carry out cyberattacks: https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks
Terabytes of credentials leaked in massive supply-chain attack: https://arstechnica.com/security/2026/08/terabytes-of-credentials-leaked-in-massive-supply-chain-attack
McDonald’s Built a 515-Page Dossier on Me. It Says I’ll Never Stop Eating There: https://www.wired.com/story/mcdonalds-built-a-515-page-dossier-on-me-it-says-ill-never-leave
Told to book a gym class, an AI agent hacked the site instead to move its user up the waitlist: https://the-decoder.com/told-to-book-a-gym-class-an-ai-agent-hacked-the-site-instead-to-move-its-user-up-the-waitlist
Littleton claims Flock reactivated its cameras without notifying the town: https://www.lowellsun.com/2026/07/31/littleton-claims-flock-reactivated-its-cameras-without-notifying-the-town
Chrome adopts what may be the best protection yet against account takeovers: https://arstechnica.com/security/2026/08/chrome-adopts-what-may-be-the-best-protection-yet-against-account-takeovers
Tip of the Week: https://firewallsdontstopdragons.com/digital-citizen-phase-2/
Further Info
Phase 2: https://fdsd.me/phase2
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
NoALPRs: https://noalprs.com/
FlockYou project: https://github.com/colonelpanichacks/flock-you
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Table of Contents
0:00:07: Intro
0:00:26: Public service announcements
0:03:20: News rundown
0:05:25: Flock in Uber, Lyft, delivery vehicles
0:07:13: Tower dump warrants ruled unconstitutional
0:08:33: Some BMW’s show Spider-Man ad
0:10:49: Hackers use expired domains for scams
0:13:24: US warns of AI attacked on PLCs
0:18:05: US authorizes private cyber attacks
0:24:53: Terabytes of credentials leaked in supply chain attack
0:32:13: McDonald’s customer dossier
0:39:44: AI agent hacks gym site
0:45:22: Town claims Flock reactivated its cameras
0:49:39: Google trialing device-bound session cookies
0:57:00: Tip of the Week
1:04:31: Wrap-up
1:05:22: Patron podcast preview
1:05:45: Looking ahead - It’s August, which means it’s time for Hacker Summer Camp once again! I flew out to a sweltering Las Vegas, Nevada, to attend two of the three major cybersecurity (“hacker”) conferences: BSides and DEF CON. I had an amazing week, spending time with new and old friends, meeting some of the people I’ve interviewed in person, lining up more podcast guests, and having wonderfully stimulating conversations with very smart people. While at DEF CON, I managed to record four mini interviews with Bob Lord, Naomi Brockwell, Josh Corman and the Dark Tangent himself, Jeff Moss. I will try to give you some idea what these conferences are like as we discuss several important and timely topics.
Interview Notes
Hacklore: https://www.hacklore.org/
Naomi Brockwell (NBTV): https://www.nbtv.media/
Ludlow Institute: https://www.ludlowinstitute.org/
Surveillance Accountability Act: https://www.surveillanceaccountability.com/
UnDisruptable27: https://u27.org
I Am the Cavalry, BSides 2026 (Monday): https://www.youtube.com/watch?v=r4C8stKbxBM
BSides IATC schedule: https://bsideslv.org/schedule#IATC
Cliff Stoll talk: https://www.youtube.com/live/_uYQr8hfpbI?t=13292s
DEF CON: https://defcon.org/
DEF CON 20 Documentary: https://archive.org/details/DEFCON20Documentary
DEF CON 33 Documentary: https://www.youtube.com/watch?v=pb0kJXSy64E
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Table of Contents
0:00:07: Intro
0:00:50: Hacker Summer Camp
0:11:30: Interview preface
0:14:26: Bob Lord
0:21:18: Bob afterword
0:24:08: Naomi intro
0:26:09: Naomi Brockwell
0:35:51: Naomi afterword
0:40:58: Josh intro
0:42:58: Josh Corman
0:56:01: Josh afterword
1:01:08: Jeff intro
1:03:00: Jeff Moss
1:23:12: Jeff afterword
1:24:30: Wrap-up
1:26:20: Patron podcast preview
1:26:45: Phase 1 still going
1:27:13: Looking ahead - One of the most underrated uses for modern chatbots, in my estimation, is tech support. I don’t mean the chatbots offered by product websites, I mean using one of the “frontier” model bots to troubleshoot problems via chat conversations. They are extremely good at this – and they are infinitely patient and available 24/7. Today I’ll give you tips on how to try this for yourself. I think you’ll be amazed.
In the news: DEF CON bans Meta-style glasses; US military warns of personal cell phone use; GDPR suit over 1741 “partners” in share consent; US bans future robovacs; more TV streaming stick bad behavior; FTC sues Hims & Hers over health data sharing; Android “after call” ads malware; user’s private AI chats leaked; clever, annoying Mac malware; HuggingFace breached by OpenAI agent; Iran blamed for hacking 30 Minnesota water utilities.
Article Links
News Briefs
DEF CON bans Meta-style ‘pervert glasses’: https://www.theregister.com/security/2026/07/28/def-con-bans-meta-style-pervert-glasses/5279763
US military may require some troops in Mideast to surrender cell phones: https://www.reuters.com/business/media-telecom/us-commander-warns-troops-their-videos-help-iran-sources-say-2026-07-29
Full Stories
1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed: https://noyb.eu/en/1741-informed-consents-one-click-gdpr-complaint-against-dictcc-filed
Almost all future robot vacuums were just banned by the US government: https://9to5mac.com/2026/07/29/almost-all-future-robot-vacuums-were-just-banned-by-the-us-government
Read This Before You Buy That TV Streaming Stick: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick
FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap: https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-for-allegedly-sharing-patients-medical-data-with-advertisers-meta-and-snap
Aftercall ads are driving Android users crazy: https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy
Users’ private Claude chats revealed with simple Google search: https://appleinsider.com/articles/26/07/28/privacy-is-dead-personal-ai-prompts-indexed-by-google-search
This new Mac malware won’t let you use your computer until you surrender your password: https://www.digitaltrends.com/computing/this-new-mac-malware-wont-let-you-use-your-computer-until-you-surrender-your-password
OpenFace: The Hugging Face Breach and What to Do About It: https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-it
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack
Tip of the Week: https://firewallsdontstopdragons.com/ai-tech-support-trust-but-verify/
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
Update All the Things! https://firewallsdontstopdragons.com/update-all-the-things/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:07: Intro
0:00:40: PSA: Update!!
0:01:36: Countdown to 500
0:02:37: News Briefs
0:06:46: News rundown
0:08:50: GDPR complaint about 1741 “partners”
0:12:45: US bans foreign robots
0:16:13: Malicious, cheap streaming sticks
0:23:33: FTC sues Hims/Hers for sharing health data
0:27:34: Android “after call” ads
0:32:17: Private Claude chats in search results
0:38:18: Cleverly annoying Mac malware
0:45:31: Hugging Face breach lessons
0:54:08: Many US water utilites attacked by Iran
0:59:39: Tip of the Week
1:11:56: Wrap up
More Technology podcasts
Trending Technology podcasts
About Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Podcast websiteListen to Firewalls Don't Stop Dragons Podcast, DGTL Voices with Ed Marx and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Firewalls Don't Stop Dragons Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.

































