Skip to content
PodcastsTechnologyFirewalls Don't Stop Dragons Podcast

Firewalls Don't Stop Dragons Podcast

Carey Parker
Firewalls Don't Stop Dragons Podcast
Latest episode

493 episodes

  • Firewalls Don't Stop Dragons Podcast

    AI Tech Support: Trust, but Verify

    08/10/2026 | 1h 13 mins.
    One of the most underrated uses for modern chatbots, in my estimation, is tech support. I don’t mean the chatbots offered by product websites, I mean using one of the “frontier” model bots to troubleshoot problems via chat conversations. They are extremely good at this – and they are infinitely patient and available 24/7. Today I’ll give you tips on how to try this for yourself. I think you’ll be amazed.

    In the news: DEF CON bans Meta-style glasses; US military warns of personal cell phone use; GDPR suit over 1741 “partners” in share consent; US bans future robovacs; more TV streaming stick bad behavior; FTC sues Hims & Hers over health data sharing; Android “after call” ads malware; user’s private AI chats leaked; clever, annoying Mac malware; HuggingFace breached by OpenAI agent; Iran blamed for hacking 30 Minnesota water utilities.

    Article Links

    News Briefs

    DEF CON bans Meta-style ‘pervert glasses’: https://www.theregister.com/security/2026/07/28/def-con-bans-meta-style-pervert-glasses/5279763

    US military may require some troops in Mideast to surrender cell phones: https://www.reuters.com/business/media-telecom/us-commander-warns-troops-their-videos-help-iran-sources-say-2026-07-29

    Full Stories

    1,741 “informed” consents with one click?! GDPR complaint against dict.cc filed: https://noyb.eu/en/1741-informed-consents-one-click-gdpr-complaint-against-dictcc-filed

    Almost all future robot vacuums were just banned by the US government: https://9to5mac.com/2026/07/29/almost-all-future-robot-vacuums-were-just-banned-by-the-us-government

    Read This Before You Buy That TV Streaming Stick: https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick

    FTC sues Hims & Hers for allegedly sharing patients’ medical data with advertisers Meta and Snap: https://techcrunch.com/2026/07/30/ftc-sues-hims-hers-for-allegedly-sharing-patients-medical-data-with-advertisers-meta-and-snap

    Aftercall ads are driving Android users crazy: https://www.malwarebytes.com/blog/news/2026/07/aftercall-ads-are-driving-android-users-crazy

    Users’ private Claude chats revealed with simple Google search: https://appleinsider.com/articles/26/07/28/privacy-is-dead-personal-ai-prompts-indexed-by-google-search

    This new Mac malware won’t let you use your computer until you surrender your password: https://www.digitaltrends.com/computing/this-new-mac-malware-wont-let-you-use-your-computer-until-you-surrender-your-password

    OpenFace: The Hugging Face Breach and What to Do About It: https://www.lutasecurity.com/post/openface-the-hugging-face-breach-and-what-to-do-about-it

    Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack: https://www.bleepingcomputer.com/news/security/hackers-target-over-30-minnesota-water-utilities-in-coordinated-ot-attack

    Tip of the Week: https://firewallsdontstopdragons.com/ai-tech-support-trust-but-verify/

    Further Info

    Digital Citizen, Phase 1: https://fdsd.me/phase1 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    Update All the Things! https://firewallsdontstopdragons.com/update-all-the-things/ 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Support our mission! https://fdsd.me/support 

    Give the gift of privacy and security: https://fdsd.me/coupons 

    Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 

    Table of Contents

    0:00:07: Intro

    0:00:40: PSA: Update!!

    0:01:36: Countdown to 500

    0:02:37: News Briefs

    0:06:46: News rundown

    0:08:50: GDPR complaint about 1741 “partners”

    0:12:45: US bans foreign robots

    0:16:13: Malicious, cheap streaming sticks

    0:23:33: FTC sues Hims/Hers for sharing health data

    0:27:34: Android “after call” ads

    0:32:17: Private Claude chats in search results

    0:38:18: Cleverly annoying Mac malware

    0:45:31: Hugging Face breach lessons

    0:54:08: Many US water utilites attacked by Iran

    0:59:39: Tip of the Week

    1:11:56: Wrap up
  • Firewalls Don't Stop Dragons Podcast

    Top Cyber Threats 2026

    08/03/2026 | 1h 11 mins.
    With so many cyber threats to report on, it’s easy to get lost in the weeds. It’s good to take a step back and look at the big picture every so often. Today, I’ll review some of the top security and privacy threats with investigative cybersecurity journalist Zack Whittaker from Tech Crunch. We’ll talk about age verification, mercenary spyware, surveillance capitalism, critical infrastructure hacks, AI and the proliferation of tracking in public spaces – and more!

    Interview Notes

    This Week in Security: https://this.weekinsecurity.com/ 

    Zack at TechCrunch: https://techcrunch.com/author/zack-whittaker/ 

    Zack’s homepage: https://zackwhittaker.com/ 

    Project Sunshine: https://projectsunshine.org/about 

    Filtr (Wipr) ad blocker for iPhone: https://techcrunch.com/2026/06/04/filtr-is-a-new-privacy-tool-that-blocks-ads-in-almost-every-iphone-and-mac-app/ 

    Apple iPhone security: https://ssd.eff.org/module/how-to-get-to-know-iphone-privacy-and-security-settings 

    Google Android security: https://ssd.eff.org/module/how-to-get-to-know-android-privacy-and-security-settings 

    Zach’s list: 404media.co, metacurity.com, indicator.media, krebsonsecurity.com, techdirt.com, garbageday.email, thehandbasket.co, karlbode.com, risky.biz, lawdork.com, citationneeded.news, erininthemorning.com 

    Further Info

    Digital Citizen, Phase 1: https://fdsd.me/phase1 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Table of Contents

    0:00:12: Intro

    0:02:08: Interview setup

    0:03:03: What is age gating?

    0:07:45: What are the risks of age verification?

    0:15:30: How do ads get our data?

    0:21:33: How can ad data be abused?

    0:28:11: What is mercenary spyware?

    0:34:53: How do you protect against spyware?

    0:41:04: How dangerous are nation-state attacks?

    0:43:54: How do we defend against foreign attacks?

    0:47:43: Does AI benefit defenders or attackers more?

    0:51:24: How do we mitigate public mass surveillance?

    0:57:01: What else worries you?

    1:00:34: What’s next for you?

    1:02:30: Wrap-up

    1:07:50: Patron podcast preview

    1:09:02: Looking ahead
  • Firewalls Don't Stop Dragons Podcast

    Update All the Things

    07/27/2026 | 1h 14 mins.
    Over the last 2-3 months, large software makers such as Microsoft have been releasing tons of fixes for vulnerabilities in their apps and operating systems. Did their software suddenly get a lot worse? No. They’re using the latest AI tools to find these bugs that humans missed and that have been lurking in their software for months or even years – and they’re fixing them. That’s great news… but these fixes won’t do you any good unless you install them. Bad guys are using these same tools to exploit these bugs. There’s never been a better time to update all your devices’ software.

    In other news: a hidden car device leaves many cars vulnerable to hacking; most fitness wearables don’t encrypt users’ data end-to-end; Iran is tracking US military phones; CBP accuses citizen of wiping phone using “duress” password; US says Iran is hacking critical infrastructure; US also warns that Russia and China are hacking small office routers; US judge denies broad “stringray” warrant in Ohio; LG to ban proxy apps on their TVs; Maine librarians teach patrons how to remove AI features.

    Article Links

    A Device Hidden in Cars Across the US Leaves Them Vulnerable to Hacking and Paralysis. Patch It Now: https://www.wired.com/story/a-device-hidden-in-cars-across-the-us-leaves-them-vulnerable-to-hacking-and-paralysis-patch-it-now

    Most fitness wearables lack end-to-end encryption and don’t disclose government data demands, says EFF: https://this.weekinsecurity.com/most-fitness-wearables-lack-end-to-end-encryption-and-lack-transparency-reports

    Financial Times: US military smartphones targeted through roaming and ad tech: https://harrigan.house.gov/media/in-the-news/financial-times-us-military-smartphones-targeted-through-roaming-and-ad-tech

    US accuses American of allegedly wiping his phone using a ‘duress’ password during border search: https://techcrunch.com/2026/07/24/us-accuses-american-of-allegedly-wiping-his-phone-using-a-duress-password-during-border-search

    US government says Iran-linked hackers are disrupting American water and energy providers: https://techcrunch.com/2026/07/23/us-government-says-iran-linked-hackers-are-disrupting-american-water-and-energy-providers

    The US government warns that Russia state hackers are coming after your router: https://arstechnica.com/security/2026/07/the-us-government-warns-that-russia-state-hackers-are-coming-after-your-router

    U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents: https://this.weekinsecurity.com/us-judge-denied-feds-month-long-warrant-to-snoop-on-the-phones-of-thousands-of-ohio-residents

    LG to Ban Residential Proxies from Smart TV Apps: https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps

    These Maine librarians are helping patrons resist AI and Big Tech: https://www.bangordailynews.com/2026/07/02/midcoast/midcoast-culture/maine-librarians-are-helping-patrons-resist-ai-joam40zk0w

    Tip of the Week: https://firewallsdontstopdragons.com/update-all-the-things/ 

    Further Info

    Digital Citizen, Phase 1: https://fdsd.me/phase1 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    Zero-Day documentary: https://www.imdb.com/title/tt5446858/ 

    EFF’s Rayhunter: https://www.eff.org/deeplinks/2025/03/meet-rayhunter-new-open-source-tool-eff-detect-cellular-spying 

    This Week in Security: https://this.weekinsecurity.com/ 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Table of Contents

    0:00:07: Intro

    0:00:25: Phase 1 reminder

    0:04:09: Quick news bites

    0:05:54: News rundown

    0:07:35: Hidden card device vulnerable to hacks

    0:15:00: Most fitness wearables lack E2EE

    0:19:19: Iran tracking military smartphones

    0:26:58: US accuses citizen of wiping phone with “duress” password

    0:33:15: US Gov’t claims Iran attaching infrastructure

    0:38:03: Russia attacking US routers

    0:42:37: Judge denies “Stingray” warrant

    0:49:09: LG TV to ban proxy network apps

    0:53:57: Maine librarians help patrons remove AI

    1:00:54: Tip of the Week

    1:10:18: Reminders

    1:11:17: Patron podcast preview

    1:11:49: Looking ahead
  • Firewalls Don't Stop Dragons Podcast

    Digital Provenance

    07/20/2026 | 1h 6 mins.
    With modern AI tools, how do we know which images and videos are real and which ones are generated? Wouldn’t it be helpful to have some digitally verifiable way to tell where something came from and whether it has been altered? Turns out, that technology already exists. It’s open and free to use, and it’s supported by many technology companies. I’ll be digging into all the details of the Coalition for Content Provenance and Authenticity (C2PA) with Jacobo Castellanos from Witness.org.

    Interview Notes

    Jacobo Castellanos: https://www.witness.org/portfolio_page/jacobo-castellanos/ 

    Witness: https://witness.org 

    Coalition for Content Provenance and Authenticity: https://c2pa.org/ 

    Content Authenticity Initiative (CAI): https://contentauthenticity.org/ 

    Content Credentials explainer: https://www.linkedin.com/help/linkedin/answer/a6282984 

    The Guardian Project: https://guardianproject.info/ 

    Creator Assertions Working Group: https://cawg.io/ 

    ProofMode tool: https://proofmode.org/ 

    C2PA Content Credentials and the Surveillance Risk: https://library.witness.org/product/c2pa-privacy/ 

    How C2PA works: https://contentauthenticity.org/how-it-works 

    Further Info

    Digital Citizen, Phase 1: https://fdsd.me/phase1 

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Table of Contents

    0:00:13: Intro

    0:01:17: Interview prep

    0:02:39: Lingo

    0:04:10: What is Witness.org?

    0:06:22: What is the purpose of C2PA?

    0:09:26: How does C2PA work?

    0:17:28: Is C2PA embedded in our devices, too?

    0:19:57: Are there fees or licensing required to use C2PA?

    0:22:41: Does C2PA info include creator information?

    0:26:41: As a user, how do I experience C2PA info?

    0:30:54: Can C2PA be used to undo changes?

    0:32:46: What are C2PA’s limitations?

    0:38:36: Does C2PA report data to third parties?

    0:41:07: Could C2PA be used to limit information?

    0:45:27: Can C2PA info be removed? Reattached?

    0:48:35: Is here a global C2PA content registry?

    0:49:53: How do certificate authorities work?

    0:53:37: Are any laws requiring provenance info?

    0:56:56: How can we get involved?

    0:59:15: How do we re-establish trust in our news?

    1:02:27: Wrap-up

    1:03:39: Patron podcast preview

    1:05:23: Reminder for Phase 1

    1:05:47: Looking ahead
  • Firewalls Don't Stop Dragons Podcast

    Countdown to Episode 500!

    07/13/2026 | 57 mins.
    It’s time to start the official countdown to my 500th podcast episode! I’ve been publishing a podcast every single week for over nine years now, which is a rather amazing accomplishment (if I do say so myself). But the entire purpose of the podcast – as well as my book and my blog – has been to try to improve the security and privacy of as many people as possible. So to celebrate this momentous occasion, I’m going to be conducting an experiment to figure out the most effective way to protect our data and devices. And I’m going to need your help.

    In the news: Chat Control 1.0 has been resurrected in the EU; Apple’s Hide My Email is failing to do so; Meta patents a new, creepy wearable device; The Intercept’s Signal account was taken over for months; Papa Johns wants to know when your fridge is empty; Opera Browser has a new feature to combat ClickFix attacks; Google disrupted a residential proxy network; John Deere has been forced to support third party repairs; and the Supreme Court further protected our device location history.

    Article Links

    Chat Control 1.0 sneaks through the EU Parliament: https://www.tomshardware.com/tech-industry/cyber-security/chat-control-1-0-sneaks-through-the-eu-parliament-letting-companies-scan-user-data-without-warrants-legal-tactic-used-to-force-a-majority-required-re-vote-on-eve-of-parliament-break

    Apple Hide My Email bug allows 100% of real email addresses to be discovered: https://9to5mac.com/2026/07/01/apple-hide-my-email-bug-seemingly-allows-100-of-real-email-addresses-to-be-discovered

    Meta Patents AI Device That Tracks Your Emotions, Watches You Take Your Meds: https://www.404media.co/meta-patents-ai-device-that-tracks-your-emotions-watches-you-take-your-meds

    The Intercept’s Signal tipline username was hijacked for months: https://cyberinsider.com/the-intercepts-signal-tipline-username-was-hijacked-for-months

    Papa Johns Can Predict When Your Fridge Is Empty: https://www.adexchanger.com/?p=461783

    Opera’s new security feature stops copy paste attacks from malicious websites – Engadget: https://www.engadget.com/2206574/opera-new-security-feature-stops-copy-paste-clickfix-attacks

    Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices: https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html

    The Deere Dam Just Broke: FTC Settlement Empowers Farmers Right To Repair: https://fighttorepair.substack.com/p/the-deere-dam-just-broke-ftc-settlement

    Justices rule that cellphone location histories are protected by the Fourth Amendment: https://therecord.media/supreme-court-geofencing-ruling-fourth-amendment

    Tip of the Week: https://firewallsdontstopdragons.com/celebrating-500-episodes/ 

    Further Info

    Countdown to FDSD500!! https://fdsd500.com 

    Get your FDSD500 merch!! https://fdsd.me/merch 

    Hacking the water supply: https://www.wired.com/story/what-happens-if-china-hacks-the-us-water-supply-war-game-volt-typhoon 

    My book: https://fdsd.me/book 

    My newsletter: https://fdsd.me/newsletter 

    Support our mission! https://fdsd.me/support 

    Table of Contents

    0:00:07: Intro

    0:01:07: Quick headlines

    0:03:18: News rundown

    0:04:40: Chat Control 1.0 is back

    0:09:27: Apple Hide My Email exposes real address

    0:13:15: New creepy Meta patent

    0:19:16: Intercept loses Signal account

    0:23:52: Papa Johns knows when your fridge is empty

    0:27:54: Opera implement ClickFix protections

    0:32:49: Google foils residential proxy maker

    0:38:23: John Deere forced to allow user repairs

    0:41:06: SCOTUS restricts location data, again

    0:46:04: Tip of the Week

    0:53:17: Wrap-up

    0:55:01: Hacker summer camp

    0:55:42: Patron podcast preview

    0:56:13: Looking ahead
More Technology podcasts
About Firewalls Don't Stop Dragons Podcast
A Podcast on Computer Security & Privacy for Non-Techies
Podcast website

Listen to Firewalls Don't Stop Dragons Podcast, Tomorrow, Today and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features