

Shared Security Podcast
Tom Eston, Scott Wright, Kevin Tackett
Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
Episodes
Mentioned books

May 10, 2021 • 30min
World Password Day, Tesla Hacking via Drone, Ipsos Screenwise Panel
Do we still need World Password Day? Hacking a Tesla via a drone, and a privacy warning about the Ipsos Screenwise panel.
** Links mentioned on the show **
World password day – May 6th
https://www.darkreading.com/vulnerabilities—threats/will-2021-mark-the-end-of-world-password-day-/a/d-id/1340911
Tesla Car Hacked Remotely From Drone via Zero-Click Exploit
https://www.securityweek.com/tesla-car-hacked-remotely-drone-zero-click-exploit
What is this Ipsos/Google Screenwise Panel?
(Tom received a letter randomly in the mail with a real dollar bill attached. The panel gives Google access to everything your family does on the Internet through a wifi router that they control in your home. In return, they pay you a few bucks for your app usage and Internet history)
https://screenwisepanel.com/
https://lushdollar.com/the-screenwise-meter-panel/
YouTube video where Snowden reveals scammer live
** Watch this episode on YouTube **
https://youtu.be/ptZFEMzPdrY
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post World Password Day, Tesla Hacking via Drone, Ipsos Screenwise Panel appeared first on Shared Security Podcast.

May 3, 2021 • 23min
Remembering Dan Kaminsky, Apple AirDrop Vulnerability
Remembering Dan Kaminsky who was one of the greatest security researchers of our time plus details on a new Apple Airdrop vulnerability.
** Links mentioned on the show **
Remembering Dan Kaminsky
https://www.nytimes.com/2021/04/27/technology/daniel-kaminsky-dead.html
Apple AirDrop Bug Could Leak Your Personal Info to Anyone Nearby
https://thehackernews.com/2021/04/apple-airdrop-bug-could-leak-your.html
https://www.komando.com/security-privacy/apple-airdrop-security-flaw/787628/
** Watch this episode on YouTube **
https://youtu.be/N6T6qcRfTBA
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post Remembering Dan Kaminsky, Apple AirDrop Vulnerability appeared first on Shared Security Podcast.

May 1, 2021 • 28min
3 Ways to Keep Your Cryptocurrency Safe
Are you investing in cryptocurrency or thinking about it? Be sure to listen or watch our April monthly show for our top 3 ways to keep your cryptocurrency safe!
** Links mentioned on the show **
10 Ways to Keep Your Cryptocurrency Safe
https://money.usnews.com/investing/cryptocurrency/slideshows/ways-to-keep-your-cryptocurrency-safe
Beware of These Top Bitcoin Scams
https://www.investopedia.com/articles/forex/042315/beware-these-five-bitcoin-scams.asp
9 Best Crypto Wallets (Software and Hardware) in 2021
https://cryptotrader.tax/blog/best-crypto-wallet
** Watch this episode on YouTube **
https://youtu.be/plOnfKhePXY
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post 3 Ways to Keep Your Cryptocurrency Safe appeared first on Shared Security Podcast.

Apr 26, 2021 • 21min
Instagram Anti-Abuse Tool, Apple Advertiser Restrictions, Terrible Passwords
Instagram is rolling out new features to help block spam and abusive messages, Apple releases iOS 14.5 to restrict tracking by advertisers, and a discussion about why people continue to choose terrible passwords.
** Links mentioned on the show **
Instagram debuts new tool to stop abusive message salvos made through new accounts
https://www.zdnet.com/article/instagram-debuts-new-means-to-stop-senders-of-abusive-messages-contacting-you-through-new-accounts/
Apple releases long-awaited iOS update to restrict tracking by advertisers
https://www.cbsnews.com/news/iphone-ios-privacy-update/?mc_cid=6359ff7e82&mc_eid=ab953fc709
These are the terrible passwords that people are still using. Here’s how to do better
https://www.zdnet.com/article/these-are-the-terrible-passwords-that-people-are-still-using-heres-how-to-do-better/
** Watch this episode on YouTube **
https://youtu.be/Q0QMpb0J4pE
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post Instagram Anti-Abuse Tool, Apple Advertiser Restrictions, Terrible Passwords appeared first on Shared Security Podcast.

Apr 19, 2021 • 24min
Data Breaches vs. Data Leaks, FBI Exchange Server Controversy
This week Tom and Kevin are back with an all new episode! Data breaches vs. recent data leaks, and the controversy over the FBI operation conducted to remove web shells from compromised Microsoft Exchange servers.
** Links mentioned on the show **
Facebook Data Breach: Here’s What To Do Now
https://www.forbes.com/sites/kateoflahertyuk/2021/04/06/facebook-data-breach-heres-what-to-do-now/?sh=32c7c9235708
LinkedIn says some user data scraped and posted for sale
https://www.reuters.com/article/us-linkedin-dataprotection-idUSKBN2BW1D3
Scraped personal data of 1.3 million Clubhouse users has reportedly leaked online
https://www.msn.com/en-us/money/other/personal-data-of-13-million-clubhouse-users-has-reportedly-leaked-online-days-after-linkedin-and-facebook-also-suffered-data-breaches/ar-BB1fweCz
FBI nuked web shells from hacked Exchange Servers without telling owners
https://www.bleepingcomputer.com/news/security/fbi-nuked-web-shells-from-hacked-exchange-servers-without-telling-owners/
** Watch this episode on YouTube **
https://youtu.be/4QeFEwj64ck
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post Data Breaches vs. Data Leaks, FBI Exchange Server Controversy appeared first on Shared Security Podcast.

Apr 12, 2021 • 51min
Best of Episode: Interview with Jayson E. Street
This week is another best of episode with the man, the myth, the legend, Jayson E. Street! In this episode Jayson shares with us several of his greatest hacking and social engineering adventures. This is one classic episode you don’t want to miss!
** Links mentioned on the show **
Follow Jayson on Twitter
https://twitter.com/jaysonstreet
Check out Jayson’s books on Amazon
https://www.amazon.com/Jayson-E-Street/e/B002KRHDMO?ref=sr_ntt_srch_lnk_2&qid=1618086907&sr=8-2
** Watch this episode on YouTube **
https://youtu.be/Q3hp0PDxCqw
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post Best of Episode: Interview with Jayson E. Street appeared first on Shared Security Podcast.

Apr 5, 2021 • 30min
Best of Episode: Interview with Rachel Tobac
This week is a best of episode with special guest Rachel Tobac, CEO of Social Proof Security. In this episode we discuss social engineering, how to get more women in cybersecurity, and of course Rachel’s favorite David Lynch movies. This is one previous episode you don’t want to miss!
** Links mentioned on the show **
Connect with Rachel on Twitter
https://twitter.com/RachelTobac
Find out more about Social Proof Security
https://www.socialproofsecurity.com/
** Watch this episode on YouTube **
https://youtu.be/LNbaxT9cZgU
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post Best of Episode: Interview with Rachel Tobac appeared first on Shared Security Podcast.

Mar 31, 2021 • 24min
SMS Two-Factor Authentication, New Internet Hygiene Model
Is it time to finally move away from SMS text based two-factor authentication? Plus a discussion about a new model that can help consumers with improving their Internet hygiene.
** Links mentioned on the show **
Can We Stop Pretending SMS Is Secure Now?
https://krebsonsecurity.com/2021/03/can-we-stop-pretending-sms-is-secure-now/
The Consumer Authentication Strength Maturity Model (CASMM)
https://danielmiessler.com/blog/casmm-consumer-authentication-security-maturity-model/
Tom Eston’s interview on the Secure Dad Podcast about Online Privacy
https://www.thesecuredad.com/post/how-to-protect-your-privacy-online
** Watch this episode on YouTube **
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post SMS Two-Factor Authentication, New Internet Hygiene Model appeared first on Shared Security Podcast.

Mar 29, 2021 • 6min
Top 3 Privacy Tips for Travel
This week, co-host Tom Eston shares his top 3 tips to stay more private when you travel this year on vacation.
** Links mentioned on the show **
Smartphone privacy screens (Amazon)
https://www.amazon.com/s?k=smartphone+privacy+screen&ref=nb_sb_noss_1
Laptop privacy screens (Amazon)
https://www.amazon.com/s?k=laptop+privacy+screen&ref=nb_sb_noss_2
** Watch this episode on YouTube **
https://youtu.be/2izHDB80qgA
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post Top 3 Privacy Tips for Travel appeared first on Shared Security Podcast.

Mar 22, 2021 • 24min
Facebook and Apple Privacy Debate, Employee Phishing Test Gone Wrong
Scott and Kevin finally get together to debate Facebook and Apple privacy, and why you shouldn’t conduct a phishing test to trick employees into thinking they will get free Covid-19 vaccines.
** Links mentioned on the show **
Apple CEO sounds warning of algorithms pushing society towards catastrophe
https://www.zdnet.com/article/apple-ceo-sounds-warning-of-algorithms-pushing-society-towards-catastrophe/
https://clickarmor.ca/2021/02/is-this-the-beginning-of-the-end-for-facebook/
Internal Memo: ICF Next Used Promise of Employee Vaccinations as Phishing Test
https://www.adweek.com/agencyspy/internal-memo-icf-next-used-promise-of-employee-vaccinations-as-phishing-test/171253/
** Watch this episode on YouTube **
https://youtu.be/Lqwtp9W_CNU
** Thank you to our sponsors! **
Silent Pocket
Visit silent-pocket.com to check out Silent Pocket’s amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code “sharedsecurity”.
Click Armor
To find out how “gamification” of security awareness training can reduce cyber risks related to phishing and social engineering, and to get a free trial of Click Armor’s gamified awareness training platform, visit: https://clickarmor.ca/sharedsecurity
** Help support the show **
Looking for an affordable, reliable, no logs VPN provider? Support the podcast by purchasing a Private Internet Access VPN subscription via our affiliate link: http://www.privateinternetaccess.com/pages/buy-vpn/sharedsecurity
** Subscribe and follow the show **
Sign-up for our email newsletter to receive our free Facebook Privacy & Security Guide, new and updates about the show, contest announcements, and special offers from our sponsors: http://eepurl.com/dwcc8D
Subscribe on your favorite podcast app: https://sharedsecurity.net/subscribe
Contact us: https://sharedsecurity.net/contact
Website: https://sharedsecurity.net
YouTube: https://www.youtube.com/c/SharedSecurityPodcast
Twitter: https://twitter.com/sharedsec
Instagram: https://instagram.com/sharedsecurity
The post Facebook and Apple Privacy Debate, Employee Phishing Test Gone Wrong appeared first on Shared Security Podcast.


