RSS Amplifier

Podcast

Shared Security Podcast

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you…

sharedsecurity.netSource feed ↗10 episodes

Live Last read · last published · next check

Written by

Latest episodes

Saves to your Listen queue, to pick up on another day or another device.

Flock Cameras Exposed: Traffic Tickets, ALPRs, and Vehicle Surveillance

Flock cameras and automated license plate readers are often sold as tools for finding stolen cars, wanted suspects, missing people, and serious threats. But what happens when that same infrastructure starts being used for everyday traffic enforcement, broader vehicle surveillance, or searchable location databases? In this episode, Tom, Kevin, and Scott discuss a 404 Media report about police…

Play

GrapheneOS Phone Wipe Case: When Privacy Tools Become Evidence

A federal case involving a GrapheneOS phone wipe during an airport search raises a bigger question for privacy-minded users: can using strong mobile security features be treated as evidence of criminal intent? Tom and Scott break down what happened, why border searches are different, and what this could mean for secure phones and everyday privacy. Tom and Scott also discuss duress codes, realistic…

Play

OpenAI Says Its AI Hacked Another Company on Its Own

OpenAI disclosed an unusual AI security incident involving a frontier model evaluation and Hugging Face, but the episode cuts through the hype: was this true autonomous intent, an agent following bad scope boundaries, or a warning about giving AI systems real tools and permissions? Tom, Scott, and Kevin discuss why anthropomorphizing AI makes the story harder to evaluate, what companies should…

Play

Your Monitor Can Install Adware Now?

You plug in a new monitor. Windows detects the hardware, pulls down a vendor companion app, and the first thing you see is… a McAfee ad. That’s the story that kicks off this episode, but the bigger issue is not just one annoying popup. Hardware setup has become a software delivery channel. Drivers, companion apps, RGB utilities, printer suites, vendor dashboards, trialware, telemetry, ads, and…

Play

Surveillance Pricing: When Your Data Sets the Price

This week on Shared Security, Tom and Scott dig into surveillance pricing: the use of personal data, behavioral profiles, shopping history, location signals, income assumptions, household information, and AI-driven targeting to decide what price or discount different people see for the same product. The conversation connects New Jersey’s proposed grocery surveillance-pricing ban, Consumer…

Play

Signal Phishing and Russian Intelligence Targeting Messaging Apps

Russian intelligence services are targeting Signal, WhatsApp, and Telegram users — not by breaking encryption, but by stealing accounts through phishing, QR code tricks, linked-device abuse, and backup recovery key theft. Tom and Kevin break down the FBI warning, the $10 million Rewards for Justice bounty, and the practical security lesson for anyone relying on encrypted messaging: your app can be…

Play

The Supreme Court Just Put Limits on Geofence Warrants

The Supreme Court says constitutional privacy protections can apply to cellphone location history and geofence warrant data. Tom Eston and Scott Wright discuss the privacy implications of geofence warrants — requests that can sweep up information about many people near a location, not just a named suspect — and why this ruling matters for anyone carrying a smartphone. They also connect the ruling…

Play

Jay Beale on Kubernetes, DEF CON, and AI Attack Paths

This week on Shared Security, Tom and Kevin sit down with Jay Beale — founder of InGuardians, long-time Black Hat trainer, creator/contributor behind Kubernetes security training, and part of the team behind the DEF CON Kubernetes CTF. Jay shares stories from decades of offensive security work, including the time Tom hired him for a physical penetration test and Jay somehow ended up inside a call…

Play

Can the Government Shut Down Frontier AI Overnight?

The U.S. government reportedly ordered Anthropic to suspend access to two of its newest frontier AI models, Fable 5 and Mythos 5, citing national security concerns tied to a possible jailbreak. Anthropic complied, but pushed back on the reasoning, arguing that the reported behavior was narrow and that similar capabilities already exist in other advanced AI models. In this episode, Tom, Scott, and…

Play

Guarding AI Agents: Boundaries and Safeguards

AI agents are useful, but they become risky when they can take action in real systems. In this episode, Tom Eston discusses recent reporting about attackers tricking Meta’s AI support chatbot into helping hijack Instagram accounts, and why that story matters far beyond social media. Tom explains practical guardrails for AI agents: read-only access first, human approval for consequential actions,…

Play