494 episodes
- It’s August, which means it’s time for Hacker Summer Camp once again! I flew out to a sweltering Las Vegas, Nevada, to attend two of the three major cybersecurity (“hacker”) conferences: BSides and DEF CON. I had an amazing week, spending time with new and old friends, meeting some of the people I’ve interviewed in person, lining up more podcast guests, and having wonderfully stimulating conversations with very smart people. While at DEF CON, I managed to record four mini interviews with Bob Lord, Naomi Brockwell, Josh Corman and the Dark Tangent himself, Jeff Moss. I will try to give you some idea what these conferences are like as we discuss several important and timely topics.
Interview Notes
Hacklore: https://www.hacklore.org/
Naomi Brockwell (NBTV): https://www.nbtv.media/
Ludlow Institute: https://www.ludlowinstitute.org/
Surveillance Accountability Act: https://www.surveillanceaccountability.com/
UnDisruptable27: https://u27.org
I Am the Cavalry, BSides 2026 (Monday): https://www.youtube.com/watch?v=r4C8stKbxBM
BSides IATC schedule: https://bsideslv.org/schedule#IATC
Cliff Stoll talk: https://www.youtube.com/live/_uYQr8hfpbI?t=13292s
DEF CON: https://defcon.org/
DEF CON 20 Documentary: https://archive.org/details/DEFCON20Documentary
DEF CON 33 Documentary: https://www.youtube.com/watch?v=pb0kJXSy64E
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support the mission: https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Table of Contents
0:00:07: Intro
0:00:50: Hacker Summer Camp
0:11:30: Interview preface
0:14:26: Bob Lord
0:21:18: Bob afterword
0:24:08: Naomi intro
0:26:09: Naomi Brockwell
0:35:51: Naomi afterword
0:40:58: Josh intro
0:42:58: Josh Corman
0:56:01: Josh afterword
1:01:08: Jeff intro
1:03:00: Jeff Moss
1:23:12: Jeff afterword
1:24:30: Wrap-up
1:26:20: Patron podcast preview
1:26:45: Phase 1 still going
1:27:13: Looking ahead - One of the most underrated uses for modern chatbots, in my estimation, is tech support. I don’t mean the chatbots offered by product websites, I mean using one of the “frontier” model bots to troubleshoot problems via chat conversations. They are extremely good at this – and they are infinitely patient and available 24/7. Today I’ll give you tips on how to try this for yourself. I think you’ll be amazed.
In the news: DEF CON bans Meta-style glasses; US military warns of personal cell phone use; GDPR suit over 1741 “partners” in share consent; US bans future robovacs; more TV streaming stick bad behavior; FTC sues Hims & Hers over health data sharing; Android “after call” ads malware; user’s private AI chats leaked; clever, annoying Mac malware; HuggingFace breached by OpenAI agent; Iran blamed for hacking 30 Minnesota water utilities.
Article Links
News Briefs
DEF CON bans Meta-style ‘pervert glasses’: https://www.theregister.com/security/2026/07/28/def-con-bans-meta-style-pervert-glasses/5279763
US military may require some troops in Mideast to surrender cell phones: https://www.reuters.com/business/media-telecom/us-commander-warns-troops-their-videos-help-iran-sources-say-2026-07-29
Full Stories
1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed: https://noyb.eu/en/1741-informed-consents-one-click-gdpr-complaint-against-dictcc-filed
Almost all future robot vacuums were just banned by the US government: https://9to5mac.com/2026/07/29/almost-all-future-robot-vacuums-were-just-banned-by-the-us-government
Read This Before You Buy That TV Streaming Stick: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick
FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap: https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-for-allegedly-sharing-patients-medical-data-with-advertisers-meta-and-snap
Aftercall ads are driving Android users crazy: https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy
Users’ private Claude chats revealed with simple Google search: https://appleinsider.com/articles/26/07/28/privacy-is-dead-personal-ai-prompts-indexed-by-google-search
This new Mac malware won’t let you use your computer until you surrender your password: https://www.digitaltrends.com/computing/this-new-mac-malware-wont-let-you-use-your-computer-until-you-surrender-your-password
OpenFace: The Hugging Face Breach and What to Do About It: https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-it
Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack
Tip of the Week: https://firewallsdontstopdragons.com/ai-tech-support-trust-but-verify/
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
Update All the Things! https://firewallsdontstopdragons.com/update-all-the-things/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Support our mission! https://fdsd.me/support
Give the gift of privacy and security: https://fdsd.me/coupons
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch
Table of Contents
0:00:07: Intro
0:00:40: PSA: Update!!
0:01:36: Countdown to 500
0:02:37: News Briefs
0:06:46: News rundown
0:08:50: GDPR complaint about 1741 “partners”
0:12:45: US bans foreign robots
0:16:13: Malicious, cheap streaming sticks
0:23:33: FTC sues Hims/Hers for sharing health data
0:27:34: Android “after call” ads
0:32:17: Private Claude chats in search results
0:38:18: Cleverly annoying Mac malware
0:45:31: Hugging Face breach lessons
0:54:08: Many US water utilites attacked by Iran
0:59:39: Tip of the Week
1:11:56: Wrap up - With so many cyber threats to report on, it’s easy to get lost in the weeds. It’s good to take a step back and look at the big picture every so often. Today, I’ll review some of the top security and privacy threats with investigative cybersecurity journalist Zack Whittaker from Tech Crunch. We’ll talk about age verification, mercenary spyware, surveillance capitalism, critical infrastructure hacks, AI and the proliferation of tracking in public spaces – and more!
Interview Notes
This Week in Security: https://this.weekinsecurity.com/
Zack at TechCrunch: https://techcrunch.com/author/zack-whittaker/
Zack’s homepage: https://zackwhittaker.com/
Project Sunshine: https://projectsunshine.org/about
Filtr (Wipr) ad blocker for iPhone: https://techcrunch.com/2026/06/04/filtr-is-a-new-privacy-tool-that-blocks-ads-in-almost-every-iphone-and-mac-app/
Apple iPhone security: https://ssd.eff.org/module/how-to-get-to-know-iphone-privacy-and-security-settings
Google Android security: https://ssd.eff.org/module/how-to-get-to-know-android-privacy-and-security-settings
Zach’s list: 404media.co, metacurity.com, indicator.media, krebsonsecurity.com, techdirt.com, garbageday.email, thehandbasket.co, karlbode.com, risky.biz, lawdork.com, citationneeded.news, erininthemorning.com
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Table of Contents
0:00:12: Intro
0:02:08: Interview setup
0:03:03: What is age gating?
0:07:45: What are the risks of age verification?
0:15:30: How do ads get our data?
0:21:33: How can ad data be abused?
0:28:11: What is mercenary spyware?
0:34:53: How do you protect against spyware?
0:41:04: How dangerous are nation-state attacks?
0:43:54: How do we defend against foreign attacks?
0:47:43: Does AI benefit defenders or attackers more?
0:51:24: How do we mitigate public mass surveillance?
0:57:01: What else worries you?
1:00:34: What’s next for you?
1:02:30: Wrap-up
1:07:50: Patron podcast preview
1:09:02: Looking ahead - Over the last 2-3 months, large software makers such as Microsoft have been releasing tons of fixes for vulnerabilities in their apps and operating systems. Did their software suddenly get a lot worse? No. They’re using the latest AI tools to find these bugs that humans missed and that have been lurking in their software for months or even years – and they’re fixing them. That’s great news… but these fixes won’t do you any good unless you install them. Bad guys are using these same tools to exploit these bugs. There’s never been a better time to update all your devices’ software.
In other news: a hidden car device leaves many cars vulnerable to hacking; most fitness wearables don’t encrypt users’ data end-to-end; Iran is tracking US military phones; CBP accuses citizen of wiping phone using “duress” password; US says Iran is hacking critical infrastructure; US also warns that Russia and China are hacking small office routers; US judge denies broad “stringray” warrant in Ohio; LG to ban proxy apps on their TVs; Maine librarians teach patrons how to remove AI features.
Article Links
A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now
Most fitness wearables lack end-to-end encryption and don’t disclose government data demands, says EFF: https://this.weekinsecurity.com/most-fitness-wearables-lack-end-to-end-encryption-and-lack-transparency-reports
Financial Times: US military smartphones targeted through roaming and ad tech: https://harrigan.house.gov/media/in-the-news/financial-times-us-military-smartphones-targeted-through-roaming-and-ad-tech
US accuses American of allegedly wiping his phone using a ‘duress’ password during border search: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search
US government says Iran-linked hackers are disrupting American water and energy providers: https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers
The US government warns that Russia state hackers are coming after your router: https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router
U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents: https://this.weekinsecurity.com/us-judge-denied-feds-month-long-warrant-to-snoop-on-the-phones-of-thousands-of-ohio-residents
LG to Ban Residential Proxies from Smart TV Apps: https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps
These Maine librarians are helping patrons resist AI and Big Tech: https://www.bangordailynews.com/2026/07/02/midcoast/midcoast-culture/maine-librarians-are-helping-patrons-resist-ai-joam40zk0w
Tip of the Week: https://firewallsdontstopdragons.com/update-all-the-things/
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
Zero-Day documentary: https://www.imdb.com/title/tt5446858/
EFF’s Rayhunter: https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying
This Week in Security: https://this.weekinsecurity.com/
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Table of Contents
0:00:07: Intro
0:00:25: Phase 1 reminder
0:04:09: Quick news bites
0:05:54: News rundown
0:07:35: Hidden card device vulnerable to hacks
0:15:00: Most fitness wearables lack E2EE
0:19:19: Iran tracking military smartphones
0:26:58: US accuses citizen of wiping phone with “duress” password
0:33:15: US Gov’t claims Iran attaching infrastructure
0:38:03: Russia attacking US routers
0:42:37: Judge denies “Stingray” warrant
0:49:09: LG TV to ban proxy network apps
0:53:57: Maine librarians help patrons remove AI
1:00:54: Tip of the Week
1:10:18: Reminders
1:11:17: Patron podcast preview
1:11:49: Looking ahead - With modern AI tools, how do we know which images and videos are real and which ones are generated? Wouldn’t it be helpful to have some digitally verifiable way to tell where something came from and whether it has been altered? Turns out, that technology already exists. It’s open and free to use, and it’s supported by many technology companies. I’ll be digging into all the details of the Coalition for Content Provenance and Authenticity (C2PA) with Jacobo Castellanos from Witness.org.
Interview Notes
Jacobo Castellanos: https://www.witness.org/portfolio_page/jacobo-castellanos/
Witness: https://witness.org
Coalition for Content Provenance and Authenticity: https://c2pa.org/
Content Authenticity Initiative (CAI): https://contentauthenticity.org/
Content Credentials explainer: https://www.linkedin.com/help/linkedin/answer/a6282984
The Guardian Project: https://guardianproject.info/
Creator Assertions Working Group: https://cawg.io/
ProofMode tool: https://proofmode.org/
C2PA Content Credentials and the Surveillance Risk: https://library.witness.org/product/c2pa-privacy/
How C2PA works: https://contentauthenticity.org/how-it-works
Further Info
Digital Citizen, Phase 1: https://fdsd.me/phase1
Countdown to FDSD500!! https://fdsd500.com
Get your FDSD500 merch!! https://fdsd.me/merch
My book: https://fdsd.me/book
My newsletter: https://fdsd.me/newsletter
Table of Contents
0:00:13: Intro
0:01:17: Interview prep
0:02:39: Lingo
0:04:10: What is Witness.org?
0:06:22: What is the purpose of C2PA?
0:09:26: How does C2PA work?
0:17:28: Is C2PA embedded in our devices, too?
0:19:57: Are there fees or licensing required to use C2PA?
0:22:41: Does C2PA info include creator information?
0:26:41: As a user, how do I experience C2PA info?
0:30:54: Can C2PA be used to undo changes?
0:32:46: What are C2PA’s limitations?
0:38:36: Does C2PA report data to third parties?
0:41:07: Could C2PA be used to limit information?
0:45:27: Can C2PA info be removed? Reattached?
0:48:35: Is here a global C2PA content registry?
0:49:53: How do certificate authorities work?
0:53:37: Are any laws requiring provenance info?
0:56:56: How can we get involved?
0:59:15: How do we re-establish trust in our news?
1:02:27: Wrap-up
1:03:39: Patron podcast preview
1:05:23: Reminder for Phase 1
1:05:47: Looking ahead
More Technology podcasts
Trending Technology podcasts
About Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Podcast websiteListen to Firewalls Don't Stop Dragons Podcast, All-In with Chamath, Jason, Sacks & Friedberg and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


Firewalls Don't Stop Dragons Podcast
Scan code,
download the app,
start listening.
download the app,
start listening.































