Smashing Security

Graham Cluley & Carole Theriault

A helpful and hilarious take on the week's tech SNAFUs. Computer security industry veterans Graham Cluley and Carole Theriault chat with guests about cybercrime, hacking, and online privacy. It's not your typical cybersecurity podcast... Winner of the "Best Cybersecurity Podcast" in 2018 and 2019, and the "Most Entertaining" in 2022, Smashing Security has had over eight million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Rory Cellan-Jones. Follow the podcast on Twitter at @smashinsecurity, and subscribe for free in your favourite podcast app. New episodes released at 7pm EST every Wednesday (midnight UK). read less

Crypto hacker hijinks, government spyware, and Utah social media shocker
2d ago
Crypto hacker hijinks, government spyware, and Utah social media shocker
A cryptocurrency hack leads us down a maze of twisty little passages, Joe Biden's commercial spyware bill, and Utah gets tough on social media sites.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Tweet by Euler Finance confirming security breach - Twitter.Euler Finance to Offer $1M Reward as It Reels From Nearly $200M Exploit - Coindesk.Hackers stole over $500m in cryptocurrency in record-making heist, Ronin says - The Guardian.Hacker Behind $200M Euler Attack Apologizes, Returns Millions in Ether, Dai to Protocol - Coindesk.President Biden kind of mostly bans commercial spyware from US govt - The Register.Utah Law Could Curb Use of TikTok and Instagram by Children and Teens - New York Times. Utah’s social media for kids law could be coming to a state near you - Vox.Utah Governor Spencer Cox signs a landmark social media bill - YouTube.RRR - Netflix.RRR trailer - YouTube.RRR Naatu Naatu dance scene - YouTube.Best films of 2022 in the UK, No 7: RRR - The Guardian.He Died with a Felafel in His Hand - Wikipedia.Swarm - Amazon Prime.Night of the Lepus - Wikipedia.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.
Photo cropping bombshell, TikTok debates, and real estate scams
22-03-2023
Photo cropping bombshell, TikTok debates, and real estate scams
It could be a case of aCropalypse now for Google Pixel users, there's a warning for house buyers, and just why is TikTok being singled out for privacy concerns?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Thom Langford.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Stop pixelating! New tool reveals the secrets of "redacted" documents - Hot for Security.Google Pixel exploit reverses edited parts of screenshots - The Verge.Tweet by researcher Simon Aarons - Twitter.aCropalypse demo.Samsung 'Fake' Moon Shots Controversy Puts Computational Photography in the Spotlight - MacRumors.Android phones can be hacked just by someone knowing your phone number - Graham Cluley.BBC advises staff to delete TikTok from work phones - BBC News.TikTok: UK ministers banned from using Chinese-owned app on government phones - BBC News.TikTok banned from official Welsh government phones - BBC News.Danish public broadcaster advises staff against using TikTok - BBC News.Canada bans TikTok on government devices - BBC News.European Commission bans TikTok on staff devices - BBC News.New bill would ban TikTok in the US but it faces long odds - BBC News.A Retired Teacher and Her Daughter Were Scammed Out of $200,000 Over Email: 'I'm 69 Years Old and Now I'm Broke and Homeless' - Entrepreneur.Retired Colorado teacher left homeless and broke after scammers hijack house sale - MSN.Homebuyers scammed out of nearly $200,000 - YouTube.Stolen life savings Vickie and Sarah Ragle - Go Fund Me.
Tesla twins and deepfake dramas
15-03-2023
Tesla twins and deepfake dramas
The twisted tale of the two Teslas, and a deepfake sandwich.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:B.C. man says he accidentally unlocked and drove someone else’s Tesla using the app - Global News.A College Girl Found Deepfake Porn of Herself Online. Who Did It Shocked Her - Rolling Stone.Denmark Tries to Attract Tourists Using ChatGPT, Deepfakes, and Famous Paintings UK PC Mag.Deepfake Tools Are Made To Facilitate Harassment—So Why Are They Available in the App Store? - MSN.Spot the Deepfake - Microsoft.Sholay trailer - YouTube.Sholay: Review of the monumental Indian epic - YouTube.Rent or buy Sholay - YouTube Movies.Jazz Pianist Brad Mehldau Plays The Beatles - NPR.Brad Mehldau - Brad Mehldau website.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Kolide – Kolide ensures that if your device isn’t secure it can’t access your cloud apps. It’s Zero Trust for Okta. Watch a demo today!Drata – With over 14 frameworks including SOC2, GDPR, HIPAA, and ISO 27001, Drata gets you audit-ready for crucial security standards needed to scale your business. As a listener to Smashing Secuirty you can save 10% off Drata and have implementation fees waived.Support the show:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via
Super grannies, bar trolls, and US Marshals
08-03-2023
Super grannies, bar trolls, and US Marshals
Scammers get pwned by a Canadian granny! Don't be seduced in a bar by an iPhone thief! And will the US Marshals be able to track down the villains who stole their data?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Anna Brading.Plus don’t miss our featured interview with Jason Meller of Kolide.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:They thought they could scam this Windsor grandmother of nearly $10K. She turned the tables on them - CBC.Canada grandma helps stop fraud scheme targeting senior citizens - BBC News.A Basic iPhone Feature Helps Criminals Steal Your Entire Digital Life - Wall Street Journal.Ransomware attack on US Marshals Service affects ‘law enforcement sensitive information’ - CNN.Hackers steal sensitive law enforcement data in a breach of the U.S. Marshals Service - NPR.9 millionaires and billionaires with the most bizarre spending habits - Business Insider.Phishing still the leading way attackers breach security controls: IBM - IT World Canada.New White House cyber strategy picks a fight with ransomware - AXIOS. Happy Valley - BBC.My 80s TV.Everything Everywhere All at Once - IMDB.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Kolide – Kolide ensures that if your device isn't secure it can't access your cloud apps. It's Zero Trust for Okta. Watch a demo today!Drata – With over 14 frameworks including SOC2, GDPR, HIPAA, and ISO 27001, Drata gets you audit-ready for crucial security standards needed to scale your business.  As a...
TikTok, wiretapping, and your deepfake voice is your password
01-03-2023
TikTok, wiretapping, and your deepfake voice is your password
Who has been warning Italian criminals that their phones are wiretapped? Can you trust your voice to protect your bank account? And why is TikTok being singled out by investigators?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Dinah Davis.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Wiretapping Italian police tune in to hear their secrets being sold - The Times.Jeremy Paxman stuns Silvio Berlusconi with Angela Merkel insult allegation - The Guardian.Silvio Berlusconi interviewed by Jeremy Paxman on BBC Newsnight - YouTube.Protests grow in Italy over the wiretapping of journalists - Independent.How I Broke Into a Bank Account With an AI-Generated Voice - Vice.TikTok under investigation by Canadian privacy authorities - BBC.The UN's cyber crime treaty could be a privacy disaster - IT Pro.TikToker outlines how she quit every job she’s had over the ‘most minor inconveniences’ Yahoo News.“Check It Out” episode about nuclear war from July 1980 - YouTube.The North-West Is Our Mother: The Story of Louis Riel's People, the Métis Nation - GoodReads.Fleishman is in Trouble review – Jesse Eisenberg’s endlessly witty divorce drama is almost too good - The Guardian.Fleishman is in Trouble - Disney+Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Kolide – Kolide ensures that if your device isn't secure it can't access your...
Verified blue ticks and horny AI chatbots
22-02-2023
Verified blue ticks and horny AI chatbots
Boyfriends who are bots, Facebook's checkmark charge, Twitter Blue, and Will Ferrell's taunt of football fans...All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Testing Meta Verified to Help Creators Establish Their Presence - Meta.As Twitter forces users to remove text message 2FA, it’s in danger of decreasing security - Graham Cluley.A pre-match message from Will Ferrell - QPR Twitter account.BBC Takes Down Story About Will Ferrell After Being Fooled By Fake Twitter Account - Deadline.Replika CEO Says AI Companions Were Not Meant to Be Horny. Users Aren't Buying It - Vice.‘My AI Is Sexually Harassing Me’: Replika Users Say the Chatbot Has Gotten Way Too Horny - Vice.Replika homepage - Replika.Click and Drag - xkcd.1110: Click and Drag - Explain xkcd.xkcd 1110: Click and Drag map - Zoomable map of “Click and drag”Only Murders in the Building - Disney Plus.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Kolide – Kolide ensures that if your device isn't secure it can't access your cloud apps. It's Zero Trust for Okta. Watch a demo today!SecurEnvoy – With growing cyber security threats everyone in your organisation needs multi-factor authentication tailored to their specific access needs and the risk profile of their role. Check out SecurEnvoy’s free guide now.Support the show:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or
Synthetic voices, ChatGPT reflections, and social skirmishes
15-02-2023
Synthetic voices, ChatGPT reflections, and social skirmishes
AI-generated voices are weaponised by online trolls, how ChatGPT reflects who we are as a society, and social media is in the firing line again.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:‘Disrespectful to the Craft:’ Actors Say They’re Being Asked to Sign Away Their Voice to AI - Vice.AI-Generated Voice Firm Clamps Down After 4chan Makes Celebrity Voices for Abuse - Vice.Video Game Voice Actors Doxed and Harassed in Targeted AI Voice Attack - Vice.ChatGPT Can Be Broken by Entering These Strange Words, And Nobody Is Sure Why - Vice.My Strange Day With Bing’s New AI Chatbot - Wired.We asked ChatGPT to write performance reviews and they are wildly sexist (and racist) - Fast Company.How social media affects teen mental health: a missing link - Nature.California bill to let parents sue social media gets second try - Bloomberg.How to protect children from big tech companies - Wall Street Journal.Three out of four parents say social media is a major distraction for students, according to new study - Phys.org.Remarks of President Joe Biden – State of the Union address as prepared for delivery - The White House.Why the past 10 years of American life have been uniquely stupid - The Atlantic.Now Mesa public schools are also declaring that they have failed in educating their children by suing social media - Techdirt.Seattle school...
Jail after VPN fail, criminal messaging apps, and wolf-crying watches
08-02-2023
Jail after VPN fail, criminal messaging apps, and wolf-crying watches
When Ubiquiti suffered a hack the world assumed it was just a regular security breach, but the truth was much stranger... why are police happy that criminals keep using end-to-end encrypted messaging systems... and why is the Apple Watch being accused of crying wolf?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Plus don't miss our featured interview with SecurEnvoy's Chris Martin.Warning: This podcast may contain nuts, adult themes, and rude language.Sponsored by:Bitwarden – Bitwarden vaults are end-to-end encrypted with zero-knowledge encryption, including, the URLs for the websites you have accounts for. Migrate to Bitwarden for a more secure password manager.NordLayer – NordLayer safeguards your company’s network, securing and protecting remote workforces as well as business data. It can even help you ensure security compliance. Get your first month free.SecurEnvoy - With growing cyber security threats everyone in your organisation needs authentication tailored to their specific access needs and the risk profile of their role. Check out SecurEnvoy's free guide now.Episode links:Ubiquiti tells customers to change passwords after security breach - ZD Net.“No way out” trailer - YouTube.Ubiquiti sues journalist, alleging defamation in coverage of data breach - Ars Technica.Man charged with Ubiquiti data breach and extortion was employee assigned to investigate hack - Bitdefender.Final Thoughts on Ubiquiti - Krebs on Security.Former Employee Of Technology Company Pleads Guilty To Stealing Confidential Data And Extorting Company For Ransom - Department of Justice.Dutch Police Read Messages of Encrypted Messenger 'Exclu' - Vice.Shock and applause for Apple Watch's chilling real-life emergency call ad - Campaign Live. 911 call made from Apple Watch of Washington woman buried alive released - Yahoo! News.Apple Watch
ChatGPT and the Minister for Foreign Affairs
01-02-2023
ChatGPT and the Minister for Foreign Affairs
Could a senior Latvian politician really be responsible for scamming hundreds of "mothers-of-two" in the UK? (Probably not, despite Graham's theories...) And should we be getting worried about the AI wonder that is ChatGPT?All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Plus don't miss our featured interview with DigiCert’s Brian "PKI" Trzupek.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Artis Pabriks.‘I left my partner and lost £80,000 to a fake Facebook romance’: Manchester mum’s warning over catfishing scam - Manchester World.'I know I have been a fool but these are the things we do for love', says mum duped out of £80k by Facebook lover - Manchester Evening News.Amazon Warns Employees to Beware of ChatGPT - Gizmodo. ChatGPT's soaring popularity has added $5 billion to the wealth of Nvidia's founder as Wall Street bets on AI boom for the chipmaker - Business Insider. ChatGPT raises red flags by acing MBA exam.ChatGPT passes exams from law and business schools - CNN. I asked ChatGPT how to negotiate a raise. Career coaches said I'd probably get one by following the AI chatbot's steps and script - Business Insider. Real estate agents say they can’t imagine working without ChatGPT now - CNN. Science journals ban listing of ChatGPT as co-author on papers - The Guardian. Blakes 7 Bot - an automated bot that posts lines of dialogue from Blakes 7.Yarn - Find video clips by quotes.The New Gurus Podcast - BBC Sounds. Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Bitwarden vaults are end-to-end encrypted with zero-knowledge encryption, including, the URLs for the websites you have accounts for....
No Fly lists, cell phones, and the end of ransomware riches?
25-01-2023
No Fly lists, cell phones, and the end of ransomware riches?
What are prisoners getting up to with mobile phones? Why might ransomware no longer be generating as much revenue for cybercriminals? And how on earth did an airline leave the US government's "No Fly" list accessible for anyone in the world to download?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Maria Varmazis.Warning: This podcast may contain nuts, adult themes, and rude language.Sponsored by:Bitwarden – Bitwarden vaults are end-to-end encrypted with zero-knowledge encryption, including, the URLs for the websites you have accounts for. Migrate to Bitwarden for a more secure password manager. ManageEngine PAM360 – A fully functional privileged access management suite that offers a holistic picture of all the privileged devices, users, and credentials in the IT infrastructure. From managing and governing access to all your enterprise resources to automating the access management life cycle in your organization, PAM360 does it all.NordLayer – NordLayer safeguards your company’s network, securing and protecting remote workforces as well as business data. It can even help you ensure security compliance. Get your first month free.Episode links:The Complete Idiot's Guide to Writing Erotic Romance - Amazon.The Many Ingenious Ways People in Prison Use (Forbidden) Cell Phone - The Marshall Project.How Did They Run an Elaborate “Sextortion” Scam From Prison? Cellphones - The Marshall Project.Alarm Over Death Row Cell Phone Threats - CBS News.How to completely own an airline in 3 easy steps - Maia arson crimew.U.S. airline accidentally exposes ‘No Fly List’ on unsecured server - Daily Dot.Cyber-crime gangs' earnings slide as victims refuse to pay - BBC. Ransomware Revenue Down As More Victims Refuse to Pay - ChainAnalysis.Leaked Ransomware Docs Show Conti Helping Putin From the Shadows - Wired. Luxe Listings Sydney trailer - YouTube.Luxe Listing Sydney - Wikipedia.
Norton unlocked, and police leaks
18-01-2023
Norton unlocked, and police leaks
Carole is in her sick bed, which leaves Graham in charge of the good ship "Smashing Security" as it navigates the choppy seas of credential stuffing and avoids the swirling waters of apps being sloppy with sensitive information.Find out more in this latest edition of the "Smashing Security" podcast, hosted by Graham Cluley with special guest BJ Mendelson.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Operation Protect the Innocent - LA Police Department.A Police App Exposed Secret Details About Raids and Suspects - Wired.ODIN Intelligence website is defaced as hackers claim breach - TechCrunch.Norton LifeLock says thousands of customer accounts breached - TechCrunch.Ugh! Norton LifeLock password manager accounts accessed by hackers - Graham Cluley.Reports: Twitter’s sudden third-party client lockouts were intentional - Ars Technica.Spring app - Twitter.Spring app - Mac App Store.Mona app - Mastodon.Tulsa King trailer - YouTube.Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Bitwarden vaults are end-to-end encrypted with zero-knowledge encryption, including, the URLs for the websites you have accounts for. Migrate to Bitwarden for a more secure password manager.ManageEngine PAM360 – A fully functional privileged access management suite that offers a holistic picture of all the privileged devices, users, and credentials in the IT infrastructure. From managing and governing access to all your enterprise resources to automating the access management life cycle in your organization, PAM360 does it all.DigiCert - DigiCert's Trust Lifecycle Manager sets a new bar for unified management of digital trust. Support the show:Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.Become a supporter via
Oxford's dating disaster, cheap security robots, and faking a suicide
11-01-2023
Oxford's dating disaster, cheap security robots, and faking a suicide
Someone called OxShagger thinks he has come up with the perfect Valentine's surprise for Oxford students, but is the way he has gone about "bookworms with benefits" really a good idea? Robot security guards are trundling the streets of - you guessed it - America. And a writer of paranormal bully romances (no, we don't know what that means either) returns from the grave...All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Andrew Agnês.Warning: This podcast may contain nuts, adult themes, and rude language.Sponsored by:Bitwarden - Bitwarden vaults are end-to-end encrypted with zero-knowledge encryption, including, the URLs for the websites you have accounts for. Migrate to Bitwarden for a more secure password manager. ManageEngine PAM360 - A fully functional privileged access management suite that offers a holistic picture of all the privileged devices, users, and credentials in the IT infrastructure. From managing and governing access to all your enterprise resources to automating the access management life cycle in your organization, PAM360 does it all.NordLayer - NordLayer safeguards your company’s network, securing and protecting remote workforces as well as business data. It can even help you ensure security compliance. Get your first month free.Episode links:Dating site for horny Oxford students slammed for privacy violations - Cherwell.OxShag will not be running this term as creator says they ‘made some poor choices’ - The Oxford Tab.Dysfunctional: OxShag to shut down amid controversy - Cherwell.Oxford University dating website for staff and students shut down after ‘huge data breach’ - The Times.CES 2023 Robots: Humanoid Helpers, Coding Pups and Farming Planters - CNet.One of America's most hated companies hired a security robot. It didn't go well - ZDNet.Robot security downtown getting lots of attention, KHON2 News - YouTube.4 New Contracts for 8 Machines to Kick Off New Year at Knightscope -...
Secret Roomba snaps, Christmas cab scams, and the future of AI
21-12-2022
Secret Roomba snaps, Christmas cab scams, and the future of AI
Beware your Roomba's roving eye, the Finns warn of AI threats around the corner, and watch out when hailing a taxi cab in Dublin...All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Register's Iain Thomson.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:A Roomba recorded a woman on the toilet. How did screenshots end up on Facebook? - MIT Technology Review.Building Smart Robots Requires Responsible Development - Roomba CEO Colin Angle on LinkedIn.OpenAI predicts biz can break a billion in revs by 2024 - The Register.The security threat of AI-enabled cyberattacks (PDF) - The Finnish Transport and Communications Agency, Traficom.Ireland Christmas weather ‘roller-coaster’ amid new ‘Beast from the East’ threat - Irish Mirror.Christmas revellers warned about sophisticated taxi scam as €300,000 is stolen from victims - MSN. Taxi cab scam has cleaned out €300,000 from bank accounts of victims - Irish Independent. “La Cabina” - YouTube.“Last and First Men” by Olaf Stapledon - Wikipedia.”The other side of night” by Adam Hamdy - Pan MacMillan Press. Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Support the show:You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or
Lensa AI, and a dog called Bob
14-12-2022
Lensa AI, and a dog called Bob
Drug dealers come unstuck while using the Encrochat encrypted-messaging app, and we put the Lensa AI avatar-generation tool under the microscope.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault.Plus - don't miss our featured interview with Rico Acosta, IT manager at Bitwarden.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Smashing Security 229: Dating leaks, right to repair, and a stinky bishop - Smashing Security.Hard cheese: Stilton snap shared via EncroChat leads to drug dealer's downfall - The Register.Operation Venetic: Pet dog and accidental selfies help convict international drugs traffickers - NCA.What does the Lensa AI app do with my self-portraits and why has it gone viral? - The Guardian. Lensa, the AI portrait app, has soared in popularity. But many artists question the ethics of AI art - NBC News.I Uploaded Photos of Myself to the New Lensa A.I. Portrait Generator. The Results Were Stunning, Strange… and Super Creepy - Artnet.People keep sharing their AI-generated portraits: What to know about Lensa, and why some push back on it - USA Today.How Is Everyone Making Those A.I. Selfies? - New York Times. Lensa AI: Security concerns regarding app behind colourful selfies on social media - The National News. ‘Magic Avatar’ App Lensa Generated Nudes From My Childhood Photos - Wired. Celebrities Are Obsessed With This Amazing New AI Portrait App - Hello Giggles. This AI Self-Portrait App is Taking Over the Internet - Medium.Wednesday Shows Off Her Moves - YouTube.
AI chatbot or the start of Skynet? Eufy privacy, and hot desks
07-12-2022
AI chatbot or the start of Skynet? Eufy privacy, and hot desks
An AI chatbot is causing a stir - both impressing and terrifying users in equal measure. A security researcher discovers that a "smart" cam that doesn't use the internet is err.. using the internet. And university students revolt over under-the-belt surveillance. All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Host Unknown's Thom Langford.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:While anticipation builds for GPT-4, OpenAI quietly releases GPT-3.5 - TechCrunch.OpenAI upgrades GPT-3, stunning with rhyming poetry and lyrics - Ars Technica.GPT-3.5 finds a security vulnerability - Twitter.Mind-Blowing examples of OpenAI ChatGPT for Security, Infosec & Hacking - YouTube.OpenAI's new ChatGPT bot: 10 dangerous things it's capable of - Bleeping Computer.What GPT-3.5 really thinks about us humans - Twitter.We asked GPT-3.5 to write a story about the “Smashing Security” hosts - Twitter.GPT-Chat - OpenAI.Researcher Paul Moore questions Eufy about its privacy - Twitter.Eufy’s “local storage” cameras can be streamed from anywhere, unencrypted - Ars Technica.Eufy privacy statement - Eufy.‘NO’: Grad Students Analyze, Hack, and Remove Under-Desk Surveillance Devices Designed to Track Them - Vice. Max Von Himmel Twitter Feed - Twitter. It’s Not Science, Just Surveillance (and it's Under Your Desk) - TWC newsletter. Northeastern University - Northeastern University homepage.
Interplanetary file systems, iSpoof, and don't delete Twitter
30-11-2022
Interplanetary file systems, iSpoof, and don't delete Twitter
Why deleting your Twitter account may be a very bad idea, how the police unravelled the iSpoof fraud gang, and a trip into outer space (or at least interplanetary file systems).All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by original show co-host Vanja Švajcer.What an amazing 6 years of bickering it has been… thanks to all of you who have tuned in, appeared on the show, or supported us! 🙏Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Smashing Security #001: “One cup, two hotel guests” - YouTube.Whoopi Goldberg Quitting Twitter: “As Of Tonight I’m Done” - Deadline.Stephen Fry Joins Celebrity Twitter Exodus, Says “Goodbye” With Scrabble Message - Deadline.Twitter Users Warned Not To Delete Their Accounts - Here’s Why - ForbesHow to deactivate your account - Twitter.InterPlanetary File System - Wikipedia.Cyber Criminal Adoption of IPFS for Phishing, Malware Campaigns - Cisco Talos.Decentralized IPFS networks forming the 'hotbed of phishing' - The Register.UK police arrest 120 in largest-ever cyber fraud crackdown - Computer Weekly. Grote spoofingdienst uit de lucht gehaald door internationale samenwerking - Politie.nl.Received a text from the Metropolitan Police about iSpoof? - Cel solicitors.iSpoof' service dismantled, main operator and 145 users arrested - Bleeping Computer.iSpoof: What is iSpoof and how did police take down scam call site linked to 200,000 victims? - The Scotman.Listen to the...
EV charging risks, FTX, and an ancient apocalypse
23-11-2022
EV charging risks, FTX, and an ancient apocalypse
Deepfake shenanigans strike users of troubled crypto firm FTX, the perils of charging your electric vehicle, and is Microsoft's takeover of Activision good news for video game fanatics.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by John Hawes of AMTSO.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Larry David promotes FTX in Superbowl ad - YouTube.Crypto giant FTX collapses into bankruptcy - BBC News.FTX's new CEO: "Never in my career have I seen such a complete failure" - CBS News.Tom Brady, Giselle Bündchen, Larry David & Steph Curry Caught In FTX Crypto Fallout With Class Action Suit - Deadline.Bankman-Fried's FTX, senior staff, parents bought Bahamas property worth $300 milion - Reuters.Tweet showing Sam Bankman-Fried deepfake scam - Twitter.FTX Founder Deepfake Offers Refund to Victims in Verified Twitter Account Scam - Vice.Crypto.com CEO admits company accidentally sent 320,000 ETH ($416 million) to another crypto exchange a few weeks prior - Web3 is going great.Sandia studies vulnerabilities of electric vehicle charging infrastructure - Sandia Labs.Review of Electric Vehicle Charger Cybersecurity Vulnerabilities, Potential Impacts, and Defenses - MDPI.Shocker: EV charging infrastructure is seriously insecure - The Register.Microsoft to acquire Activision Blizzard to bring the joy and community of gaming to everyone, across every device - Microsoft.Gaming for everyone, everywhere: our view on the Activision Blizzard acquisition - Microsoft.
Housing market scams, Twitter 2FA, and the fesshole
16-11-2022
Housing market scams, Twitter 2FA, and the fesshole
Elon Musk is still causing chaos at Twitter (and it's beginning to impact users), are scammers selling your house without your permission, and Google gets stung with a record-breaking fine.All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by The Cyberwire's Dave Bittner.Plus don't miss our featured interview with Pentera's Shakel Ahmed talking about automating continuous cyber defence validation.Warning: This podcast may contain nuts, adult themes, and rude language.Episode links:Graham offers Dave Bittner some advice on “Welcome Datacomp”... in 1995! - Usenet.Elon Musk apologises to users for Twitter being slow - Twitter.Former Twitter employee doesn’t think Elon Musk knows what he’s talking about - Twitter.Eric Frohnhoefer says Elon Musk is wrong - Twitter.Twitter engineer calls out Elon Musk for technical BS in unusual career move - The Register.Elon Musk says that he is turning off microservices “bloatware” - Twitter.Twitter’s SMS Two-Factor Authentication Is Melting Down - Wired.Elon only trusts Elon - Platformer.Elon’s paranoid purge - Platformer.Google to pay nearly $400 million over deceptive location tracking practices - The Record.Follow Smashing Security on Mastodon.South Bay Man Pleads Guilty to Participating in a Multimillion-Dollar Real Estate Scam Involving Fake Open Houses at Not-for-Sale Homes - Justice.gov.A South Bay man accepted hundreds of offers from open houses. But the homes weren’t for sale - LA Times. The typing of the Regex.Fesshole - Twitter.If Books Could Kill -...
Mastodon 101, and the Hushpuppi saga
09-11-2022
Mastodon 101, and the Hushpuppi saga
Graham offers some security and privacy advice for those exodusing Twitter to Mastodon, and Carole slams the door shut on a notorious scammer with a huge Instagram following.All this and more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, who aren't joined by a guest this week.Warning: This podcast may contain nuts, adult themes, some snorting, and rude language.Episode links:Mastodon: What you need to know for your security and privacy - Graham Cluley.Follow Graham Cluley on Mastodon.Hushpuppi: Notorious Nigerian fraudster jailed for 11 years in US - BBC. Influencer involved in $1.1 million Qatar school financing scam jailed - Alarabiya. Influencer ‘Ray Hushpuppi’ jailed over plan to launder $300m - The Guardian. Hushpuppi’s wife, Imams write judge as US court sentences fraudster today - Premium Times.Living trailer - YouTube.Kleo - Netflix. Smashing Security merchandise (t-shirts, mugs, stickers and stuff)Sponsored by:Kolide – the SaaS app that sends employees important, timely, and relevant security recommendations concerning their Mac, Windows, and Linux devices, right inside Slack.Bitwarden – Password security you can trust. Bitwarden is an open source password manager trusted by millions of individuals, teams, and organizations worldwide for secure password storage and sharing.Sealit - Zero Trust Data Protection: protect, share, and monitor confidential emails and files - without passwords. Integrated with Gmail, Outlook, and file systems. Learn more and take advantage of Sealit's special offer to "Smashing Security" listeners.Support the show:You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.Become a
Twitter turmoil, AI animal chatters, and metaverse at work
02-11-2022
Twitter turmoil, AI animal chatters, and metaverse at work
Twitter has a new chief twit in the form of Elon Musk and he's causing problems, scientists say artificial intelligence may help us communicate with animals, and is the office of the future set in the metaverse?All this and much much more is discussed in the latest edition of the "Smashing Security" podcast by computer security veterans Graham Cluley and Carole Theriault, joined this week by Mark Stockley.Warning: This podcast may contain nuts, adult themes, dolphin noises, and rude language.Episode links:Twitter employees are sleeping on the office floor to meet Elon Musk’s deadlines - The Verge.Elon Musk shows what being Chief Twit is all about across weird weekend - The Register.Pranksters pretending to be laid-off Twitter employees leave San Francisco HQ - YouTube.Twitter Limits Content-Enforcement Work as US Election Looms - Bloomberg.Twitter’s Yoel Roth comments on the firm’s trust and safety staff having their access to moderation and enforcement tools frozen - Twitter. Paul Pelosi Conspiracy Theory Trends on Twitter After Elon Musk Pushes It - Rolling Stone.Yoel Roth describes how Twitter will warn users of misleading information - Twitter.Yoel Roth describes “surge in hateful conduct on Twitter” - Twitter.The Demise of Digg: How an Online Giant Lost Control of the Digital Crowd - Harvard.Follow Graham on Mastodon.How tech is helping us talk to animals - Vox.“The Sounds of Life: How Digital Technology Is Bringing Us Closer to the Worlds of Animals and Plants” - Book by Karen Bakker.Project CETI - The Cetacean Translation Initiative. Not to be mixed-up with Project SETI.The Dark Side Of VR - The Intercept.