
Hosted by A Problem Lounge Show · EN
Welcome to "Privacy Please," a podcast for anyone who wants to know more about data privacy and security. Join your hosts Cam and Gabe as they talk to experts, academics, authors, and activists to break down complex privacy topics in a way that's easy to understand.
In today's connected world, our personal information is constantly being collected, analyzed, and sometimes exploited. We believe everyone has a right to understand how their data is being used and what they can do to protect their privacy.
Please subscribe and help us reach more people!
This podcast is part of The Problem Lounge network — conversations about the problems shaping our world, from digital privacy to everyday life.

Send us Fan MailJonathan Sander is back on Privacy Please — and he's brought two blog posts worth arguing about.Sander (42 Notions, now in an operational role at Myota) joins Cam and Gabe to dig into why ransomware resilience should work like New York City's storm surge infrastructure — building something that pays off before disaster strikes, not just a wall you wait behind. Then the conversation turns to AI agents: why Sander tried and failed to build a clean taxonomy for them, the six dimensions he landed on instead (authority, execution location, trigger, persistence, delegation, tool reach), and why the "hybrid agent" — switching between acting on your behalf and acting with power you never had — might be the hardest identity problem in security right now.Also covered: why "back to basics" (secrets, resilience, identity) is Sander's answer for teams panicking about AI, and a real story about an AI agent that deleted a Postgres database and just... apologized.Articles referenced:Ransomware Doesn't Have to Hit Like a Hurricane (Myota): https://www.myota.io/articles/ransomware-doesnt-have-to-hit-like-a-hurricaneWhy We Need an AI Agent Taxonomy Right Now But We Can't Have One (42 Notions): https://blog.42notions.com/why-we-need-an-ai-agent-taxonomy-right-now-but-we-cant-have-one/Chapters:00:00 – Catch-up with Sander14:30 – The hurricane analogy: why Myota built resilience instead of a wall20:30 – What actually makes Myota different from standard backup/cyberstorage22:15 – Why you can't build a clean AI agent taxonomy (and the six dimensions Sander landed on instead)28:50 – The hybrid agent problem: acting "on behalf of" vs. "for the benefit of"45:10 – Sander's one takeaway: get the basics right before chasing the AI hypeSupport the show

Send us Fan MailFull Show NotesThis week on Privacy Please, Cam breaks down four stories that all come back to one theme: choice.GigaWiper — Microsoft researchers uncovered a new backdoor malware built from pieces of older malware families, giving attackers the ability to decide after they're already inside a network how they want to cause damage — from low-level disk wipes to fake ransomware with encryption keys that are never even saved. Multiple security firms are independently tracking it, with no group attribution yet.Connecticut's new AI disclosure law — As of July 1st, companies covered by Connecticut's privacy law must clearly disclose whether their data is used to train large language models like ChatGPT, Gemini, DeepSeek, or Grok. Cam digs into why "disclosure" doesn't always mean "clarity," and what to actually look for in a privacy policy update.California's Delete Act (DROP) — A correction and a deep dive: DROP has been live since January 1st, not launching in August as previously stated. What actually changes on August 1st is enforcement — the date data brokers become legally required to act on deletion requests. Cam walks through exactly how to submit one at privacy.ca.gov.The Phantom Hacker gold bar scam — A 78-year-old Phoenix woman nearly lost $600,000 in gold bars to a scammer posing as a federal official — until she turned the tables and called the FBI herself. Cam covers the arrest, the courier-for-hire business model behind it, and the billion-dollar scale of phantom hacker scams since 2024.Tips for this episode:Back up your data offline — wipers don't negotiate, there's no ransom to pay your way outSearch privacy policy updates for "train," "AI," or "language model" before skimming past themCalifornia residents: submit a DROP request now at privacy.ca.gov so it's queued before enforcement begins on August 1stNo real government agency will ever tell you to convert your money to gold, crypto, or gift cards — hang up and call the agency back yourselfSources referenced:Microsoft Security research on GigaWiperConnecticut Data Privacy Act (CTDPA) amendment, effective July 1, 2026California Delete Act / DROP platform, cppa.ca.govFBI IC3 reporting on Phantom Hacker and gold bar scamsAZFamily coverage of the Gary Christopher arrest, Phoenix Sky Harbor AirportChapter Timestamps00:00 – Cold Open 01:30 – GigaWiper: Choose-Your-Own-Destruction Malware 04:00 – Connecticut's LLM Data Disclosure Law 06:15 – California's Delete Act & DROP Platform 08:30 – The Phantom Hacker Gold Bar Scam 11:30 – Recap & CloseSupport the show

Send us Fan MailLast year, every major outlet ran the same story: 16 billion passwords exposed. Apple. Google. Facebook. The largest breach in history.It was overblown. Security experts tore it apart within 48 hours.But here's the thing: the real story underneath that headline is actually scarier. And nobody covered it.It's called infostealer malware. It's been quietly running on millions of devices — stealing passwords, bypassing MFA, and feeding an underground credential economy that's behind nearly every major breach of the last two years. Ticketmaster. AT&T. Coinbase. All of it traces back here.In this episode, I dig back into that story and break down:Why the 16 billion number was a "fearset, not a dataset"What infostealer malware actually is and how it gets on your deviceWhy MFA doesn't fully protect you from this (and what does)The underground marketplace where your stolen credentials are sold within 48 hoursThe stat that should genuinely keep you up at night: 67 secondsSix things you can do right now to protect yourselfSHOW NOTESEpisode: Your Password Is Already For SaleLast year, the 16 billion password story dominated headlines. The headline was overblown — but the real threat underneath it, infostealer malware, is what nobody talked about. It's an industrial-scale credential theft economy running quietly in the background, and it's the engine behind almost every major data breach of the last two years. We dug back into it because it's only gotten worse.Resources mentioned:Check if your email has been breached: haveibeenpwned.comFree password manager: bitwarden.comPremium password manager: 1password.comKey sources:Cybernews — original 16 billion credential report (June 2025)CyberScoop — "The 16 billion password breach story is a farce"Flashpoint / DeepStrike — 1.8 billion credentials stolen in 2025 reportMicrosoft Security Blog — Lumma Stealer breakdownIBM X-Force Threat Intelligence Index 2025Verizon Data Breach Investigations Report 2025SANS Institute commentaryConnect: 🌐 theproblemlounge.com 📺 YouTube: The Problem Lounge NetworkSupport the show

Send us Fan MailGabe and I dig into Shiny Hunters and why the scariest cyberattacks now look like ordinary logins instead of dramatic break-ins. We map how credential theft, social engineering, and SaaS data exports turn basic security hygiene into the difference between a close call and a headline. • Shiny Hunters’ scale, loose structure, and why takedowns rarely stick • Why ransomware and extortion keep growing as a business model • How the tactics evolve from Microsoft 365 and developer creds to SaaS platforms like Salesforce • Credential stuffing, vishing, and smishing as “low-friction” intrusion paths • The Snowflake-style failure mode of missing MFA and weak password practices • Password reuse and how consumer breaches can cascade into enterprise access • Data retention and why old records increase privacy risk • Vendor risk and the shared responsibility model for identity and data • Practical steps that improve security without relying on perfect users If you guys have not been to our website, theproblemlounge.com, check it out. Got some new blogs up there. Sign up for the newsletter. Support us, follow us. Let’s get this out to more people. Support the show

Send us Fan MailSHOW NOTES The Pornhub breach is being reported as a data story. It's actually a story about shame as a weapon.In December 2025, a hacker group called ShinyHunters claimed to have stolen 200 million records from Pornhub Premium users — including email addresses, locations, and intimate watch and search history. They sent extortion demands. The data was verified as real.In this episode of Privacy Please, Cameron Ivey breaks down:✅ What was actually stolen — and why it's worse than most breaches ✅ The three-way blame game between Pornhub, Mixpanel, and a mysterious 2023 employee access ✅ Why ShinyHunters is one of the most dangerous and active hacker groups operating right now ✅ The bigger question nobody's asking: why does this data still exist? ✅ Five things you can do right now to protect yourself🔗 RESOURCES MENTIONED:Check your email in breaches: haveibeenpwned.comFreeze your credit: annualcreditreport.com (links to all three bureaus)Data removal: DeleteMe — joindeleteme.comFollow the reporting: bleepingcomputer.com | malwarebytes.com/blog📰 SOURCE REPORTING:BleepingComputer — ShinyHunters extortion demand (December 2025)Malwarebytes — Pornhub/Mixpanel/SoundCloud breach roundupEuronews — Pornhub investigation coverageReuters — user data verificationPanda Security — breach overview🎙️ Privacy Please is part of the Problem Lounge Network 🌐 theproblemlounge.com 📺 YouTube: The Problem Lounge NetworkIf this one hit different — share it. Support the show

Send us Fan MailIn this episode of Privacy Please, Cameron Ivey investigates Palantir Technologies — a data analytics company founded in 2003 with CIA backing that has quietly become embedded across nearly every major arm of the U.S. federal government.This week's investigation covers:The USDA Deal On April 22nd, the Department of Agriculture signed a $300 million blanket purchase agreement with Palantir to build "One Farmer, One File" — a unified digital profile for every American farmer. The deal was awarded without competitive bidding.The IRS Bombshell The same week, The Intercept revealed — based on documents obtained by watchdog group American Oversight — that Palantir has been running financial crime surveillance operations inside the IRS since 2018. The IRS has paid Palantir over $130 million for access to a platform that cross-references bank records, tax filings, transaction histories, and more across millions of Americans.The Immigration Enforcement Machine Palantir's ICE contracts — now over $145 million — power the agency's case management, deportation targeting, and real-time location tracking of immigrants. A tool called ELITE creates individual dossiers on deportation targets by pulling data from the Department of Health and Human Services.The Pushback That's Working New York City's public hospital network canceled its Palantir contract after community organizing and City Council pressure. In the UK, 229,000 people have signed petitions to remove Palantir from the National Health Service. Public pressure is moving the needle.Five Things You Can Do Right Now Cameron closes with specific, actionable steps every listener can take — from requesting your IRS transcript to freezing your credit to contacting your representative about sole-source contracting.Privacy Please is part of the Problem Lounge Network. New episodes weekly. theproblemlounge.comChapter Markers 00:00 — Cold Open01:30 — Intro & Show Welcome02:45 — Act One: The USDA Deal06:00 — Act Two: Who Is Palantir?11:30 — Act Three: The Empire Expands (ICE, Policing)17:00 — Act Four: Your Tax Returns Are In There Too24:00 — Act Five: The Layer Nobody's Talking About30:00 — Act Six: The Part That Gives Me Hope34:30 — What You Can Actually Do (5 Tips)39:00 — Closing Reflection (Adjust timestamps after editing)Support the show

Send us Fan MailA normal data breach steals names and passwords. This one may have stolen the recipe for building the world’s most powerful AI models, and it happened through software most people will never notice until it breaks. We follow the Mercor breach from the first warning signs to the moment poisoned Python packages hit PyPI and spread in minutes across systems that were set to auto-update. We walk through what Mercor actually does in the AI economy, especially RLHF (Reinforcement Learning from Human Feedback), and why that behind-the-scenes work shapes how tools from OpenAI, Anthropic, Meta, and Google behave. Then we unpack Lite LLM, the open source “plumbing” that connects apps to multiple AI services, and how a supply chain attack can bypass the company you’re targeting by compromising the dependencies everyone trusts. From there, the focus shifts to the fallout: contractors whose Social Security numbers and identity documents may be exposed, companies scrambling to assess backdoors and credential theft, and the bigger fear that proprietary AI training data sets and labeling strategies are being auctioned on the dark web. We also dig into the compliance controversy around SOC2 and ISO 27001 style certifications and what happens when security audits become performance instead of protection. If you care about cybersecurity, data privacy, AI governance, and open source risk, listen through to the end for concrete steps you can take right now. Subscribe, share this with a friend who uses AI tools, and leave a review with your take on who should be held accountable.Support the show

Send us Fan MailYou already knew you were the product. But did you know you're also the teacher?Companies are quietly feeding your emails, your work decisions, your customer interactions, and your daily patterns into AI systems — systems designed to automate exactly what you do. And most people have no idea it's happening.In this episode of Privacy Please, we break down how it works, who's doing it, why your right to delete your own data is functionally broken in the AI era, and what you can actually do about it.What we cover:How "function creep" turns your data into AI training fuel without new consentThe GitHub policy change that's happening right now — and how to opt outWhy employees at Amazon, Google, and JPMorgan described training AI as "building your own coffin."The deletion problem — why you can't remove yourself from a trained modelPractical steps to audit your tools and protect yourself todayLinks:GitHub opt-out: github.com/settings/copilot/featuresKhan v. Figma lawsuit: rainintelligence.comFTC on AI data practices: ftc.govCheck your state privacy rights: iapp.org/resources/article/us-state-privacy-legislation-trackerDelete old posts: redact.devPrivacy Please is part of The Problem Lounge network. 🌐 theproblemlounge.com 🎙️ Subscribe on Apple Podcasts, Spotify, or wherever you listenSupport the show

Send us Fan MailYour anonymous account isn't anonymous anymore. Researchers just proved it costs $4 to find out who you are.In February 2026, a team from ETH Zurich and Anthropic published a paper that quietly ended the era of practical online anonymity. Their AI pipeline, using nothing but your posts, comments, and forum activity, correctly identified 67% of pseudonymous users from a pool of 89,000 candidates. No name. No photo. No metadata. Just your words.This episode breaks down exactly how it works, why it's different from every deanonymization scare before it, who's most at risk, and what you can actually do about it.In this episode:How the ESRC pipeline (Extract, Search, Reason, Calibrate) worksWhy previous anonymity attacks required structured data, and this one doesn'tWhy commercial AI safety guardrails didn't stop itWhat "practical obscurity" meant, and why it's goneConcrete steps to reduce your exposure todayLinks:Research paper: arxiv.org/abs/2602.16800Delete your Reddit history: redact.devTor Project: torproject.orgSignal: signal.orgPrivacy Please is part of The Problem Lounge network. 🌐 theproblemlounge.com 🎙️ Subscribe on Apple Podcasts, Spotify, or wherever you listenSupport the show

Send us Fan MailCameron and Gabe sit down with Girish Redekar, co-founder and CEO of Sprinto, to pull back the curtain on one of the most misunderstood areas of security: compliance.Girish built his first startup, RecruiterBox, to 3,500 customers before selling it, and it was the painful, expensive, duct-taped compliance process he experienced firsthand that sparked the idea for Sprinto. Today, Sprinto helps companies move beyond point-in-time audits into something far more valuable: continuous, autonomous trust.In this episode, we dig into:Why passing a SOC 2 or ISO 27001 audit doesn't mean you're actually secureThe three stages of compliance maturity — and how to climb themWhat "compliance debt" is and why it's quietly eating your businessHow smart CISOs use their security posture as a revenue driver, not a back-office cost centerThe "$100/month" challenge: what actually moves the needle for startupsHow AI is reshaping compliance programs — for better or worseWhy Girish spent over a year talking to customers before writing a single line of codePlus: the "sell more jeans" framework every CISO should know, Rich Hickey, The Mom Test, and the toilet paper question.🔗 Find Sprinto at sprinto.com Support the show