
Hosted by Lou Covey · EN

We've been getting an influx of announcements regarding shoulder surfing and technology that protects against it. However, we haven't found a single incident that actually, involved breaking into a device by looking over someone's shoulder. Instead, every report involves stealing someone's phone that hasn't been properly protected by biometrics or MFA.So we put out a call to ask experts about the validity of the problem and Stephanie Schneider from LastPass stepped into the breach. As we thought, you don't really need much to stop it, if it even happens.This podcast is sponsored by Haven, from Mirrortab

Cybersecurity is never more crucial than when it hits home. This past week, my daughter, who runs a small event planning business, was targeted by a phishing exploit known as a Click-Fix, designed to get her to go to a fake website to harvest her Google log-in credentials. She didn't fall for it and we had a lovely discussion about how she recognized it and stopped it in it's tracks.But I thought it would be a good case study for our sponsor, Haven, from Mirrortab, so I got Colin Britton, COO of Mirrortab on the horn and talked about how their free browser extension could have aided the defense. Luckily, my daughter had enough security awareness that precluded the need, but she has it installed now, just in case. And Colin revealed that the Haven service is expanding to a business application.

It has been a while since we talked with Ian Thorton-Trump, CISO and prognosticator at Inversion6, so we were happy when he dropped us a note and reminded us of that lack. Boy, was this one a barn burner.Across the world, pessimism reigns in geopolitics with cybersecurity at the dead center of it. Asymmetric warfare is less about kinetic attacks by terrorists and more about nation-states using the internet to attack and disrupt enemies, and sometimes friends, all over the world. That has resulted in distrust, broken relations, and dysfunctional governments. But from his vantage point in the UK, Ian sees a brighter future ahead and the US will be in the lead, once again.So grab a coffee and a danish and get ready to put a smile on the day.

The idea that humans can be excluded from technology operations has been an aspiration in the AI industry, and that interest is NOT going away. But companies are pushing the idea less and redefining how important humans are in the process, described as humans in the loop, at the helm and in the middle depending on whom you are talking to,A lot of the aspirational efforts have been in automating security operations centers (SOCs), but, like much of the threat that AI will eventually replace all humanity, is being tempered by reality. Many companies are pushing the idea autonomous response in SOCs tempered with human involvement. The latest is Blackpoint Cyber who have announced their first offering in the area. We are talking with Chief Security and Trust Officer Wil Santiago about how human involvement in security is still a requirement now and for the foreseeable future.This episode is sponsored by Haven

Meta is like Hotel California. You can enter but you can't leave.That's the story I hear over and over. It isn't true. I did and have never looked back.The claims that Meta platforms can improve your business, keep relationships alive, inform the electorate and make a better society have been disproven again and again, but the thing keeps growing. It does that by suppressing the belief that there are alternatives.This podcast talks about how you, your group, your business and your friends can leave the toxic cesspit and find success and mental health in the decentralized world.Sponsored by Haven.Most security tools only know how to shout. Haven doesn't. It's a Chrome browser extension that spots phishing links and attempts before you click, and stays quiet the rest of the time. Free for individual use, at starthaven.com.

This week I talked to the good folks at the Digital Citizens Alliance about a report on residential proxies.Say what? Residential proxies? What the heck are those? They are the apps and hardware products people use to connect to the internet, and they are as secure as a sieve is water tight. The Wall Street Journal published a report on them June 15 and. Back in March the FBI issued an alert abut the dangers they pose. The DCA produced their own report that was, frankly, more informative about the problem.The podcast is sponsored by Haven, a free internet browser extension that protects you from phishing links and malicious sites before you ever click.

Back in April, Microsoft released an advisory about phishing gang infiltrating Microsoft Teams meetings. In stunning turn of events, it wasn't a weakness in the Microsoft product but in users turning off or bypassing multiple security controls for external users, and then forgetting to turn them back on. This is what is known as configuration drift. We talked with Reach Security's CEO Garrett Hamilton.

The data broker market is worth half a trillion dollars and growing at a rate of 7.3 percent annually through 2033. That means they don’t care that you want your privacy. They are making too much money selling your personal information to care. That lack of concern doesn’t just affect an individual’s privacy. It threatens their security and that of nation states.There is a technology niche dedicated to fixing that problem: the personal data removal and online privacy market. The problem is it’s worth a 10th of the data broker market so it doesn’t have the political clout of data brokers. And nowhere is the problem bigger than the healthcare industry, according to Rob Shavell, CEO of Deleteme.This episode is sponsored by Haven, a free browser extension that protects you from phishing links and malicious sites before you ever click.

A public relations firm in the United Kingdom, Whiteoaks International, said the quiet part out loud about cybersecurity marketing: that much of it is fiction if not outright fraudulent.I sat down with the rest of the Cyber Protection Magazine team, Patrick Boch and Joe Basques to have a frank discussion about this issue. Frankly, any journalist knew this to be true but to hear it come from a practicing agency was rather surprising.

Just to prove that even the most secure practitioners, like your truly, can fall for the “free lunch” offer, I inadvertently signed up for a shady but completely legal “cash back” offer. Not only did I not get any cash back I got charged for it, had to cancel a debit card and walked through the process (which I described in Cyber Protection Magazine this week.But I also called up Brian Silverstein, CEO of MirrorTab (whom we talked with a couple of weeks ago) about how to be aware when these things pop up unexpectedly and his company's plans to deal with not just scams, but scammy deals.