Tom Eston, Scott Wright, Kevin Tackett

Shared Security Podcast

News EN ↓ 568 episodes

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Author

Tom Eston, Scott Wright, Kevin Tackett

Category

News

Podcast website

sharedsecurity.net

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Privacy Concerns with Digital Driver’s Licenses, The Rise of DeepSeek AI 03.02.2025

In this episode, we explore the rollout of digital driver's licenses in states like Illinois and the potential privacy issues that come with them. Can digital IDs truly enhance convenience without compromising your privacy? We also discuss the new Chinese AI model, DeepSeek, which is affecting U.S. tech companies' stock prices. Join us as we provide insights on these emerging trends and their impl...

Gravy Analytics Breach, Subaru Starlink Vulnerability Exposed 27.01.2025

In this episode, we discuss the latest issues with data brokers, focusing on a breach at Gravy Analytics that leaked 30 million location data points online. We also explore a vulnerability in Subaru's Starlink system that allows unrestricted access to vehicle controls and customer data using just a last name and license plate number. Co-host Kevin Johnson joins the discussion to share insights and...

Meta Ditches Fact-Checking for Community Notes, RedNote and the TikTok Ban 20.01.2025

In this episode, we explore Meta's recent decision to replace traditional fact-checking with community notes and its potential impact on misinformation. We also discuss the implications of a TikTok ban in the U.S., with users migrating to similar apps like RedNote. The conversation covers the challenges of maintaining reliable information in social media and the shifting landscape of news consumpt...

AI Privacy Policies: Unveiling the Secrets Behind ChatGPT, Gemini, and Claude 13.01.2025

Do you ever read the privacy policy of your favorite AI tools like ChatGPT, Gemini, or Claude? In this episode, Scott Wright and Tom discuss the critical aspects of these policies, comparing how each AI engine handles your personal data. They explore the implications of data usage, security, and privacy in AI, with insights from industry giants like Anthropic's CEO, Dario Amodai. Are these AI tool...

Reflecting on Y2K: Lessons for the Next Tech Crisis and AI Safety 06.01.2025

Join us as we reminisce about Y2K, the panic, the preparations, and the lessons learned 25 years later. We also discuss the implications for future technology like AI and potential cybersecurity crises. Plus, in our 'Aware Much' segment, Scott shares tips on protecting your data if your phone is stolen. Happy New Year and welcome to our first episode of 2025!

2024 Year in Review: What We Got Right and Looking to 2025 30.12.2024

In the final episode of the Shared Security Podcast for 2024, join us as we recap our predictions for the year, discuss what we got right and wrong, and highlight our top episodes on YouTube. We also extend a heartfelt thank you to our Patreon supporters and special guests. Plus, stay tuned for our predictions for 2025 and some fun discussions on AI's impact, phishing attacks, and more. Happy New...

Digital License Plate Vulnerabilities, How to Avoid New Text Message Scams 23.12.2024

In this episode Tom, Scott, and Kevin discuss the vulnerabilities of digital license plates and the potential for hackers to exploit them. They explain what digital license plates are and how they work. The 'Aware Much?' segment covers the topic of suspicious text messages and why you should avoid responding to unknown senders. The team also shares personal project frustrations and emphasizes the...

Hack-for-Hire Campaign Targeting Climate Activists, Government Hypocrisy on Encryption 16.12.2024

In Episode 359 of the Shared Security Podcast, the team examines a shocking hack-for-hire operation alleged to target over 500 climate activists and journalists, potentially involving corporate sponsorship by ExxonMobil. They explore the intricate layers of this multifaceted campaign and the broader implications on security risk assessments. Additionally, Scott discusses the massive Salt Typhoon h...

Tanya Janca on Secure Coding, AI in Cybersecurity, and Her New Book 09.12.2024

Join us for an insightful episode of the Shared Security Podcast as Tanya Janca returns for her fifth appearance. Discover the latest on her new book about secure coding, exciting updates in Application Security, and the use of AI in security. Learn how her new book goes deeper into secure coding practices, backed by her practical experiences and detailed research, aimed at empowering developers w...

Australia Bans Social Media for Kids, Holiday Vishing Scams 02.12.2024

In this episode, we discuss Australia's new legislation banning social media for users under 16 and its potential impact. Our hosts also explore the issue of vishing (voicemail phishing), why it's escalating, particularly during the holiday season, and how to protect yourself against these scams. Plus, we celebrate a milestone on our YouTube channel and share some fun community feedback!

Deepfake Fraud, Data Brokers Tracking Military Personnel 25.11.2024

In Episode 356, Tom and Kevin discuss the increasing role of deepfake technology in bypassing biometric checks, accounting for 24 percent of fraud attempts. The show covers identity fraud issues and explores the controversial practices of data brokers selling location data, including tracking US military personnel. The conversation shifts to social media platforms Twitter, Blue Sky, and Mastodon,...

Why It’s Time to Leave Twitter 18.11.2024

In episode 355, Tom discusses his decision to deactivate his Twitter accounts due to privacy concerns with Twitter's new AI policy and changes in the blocking features. He outlines the steps for leaving Twitter, including how to archive and delete tweets, and evaluates alternative platforms such as Bluesky, Mastodon, and Threads for cybersecurity professionals seeking new social media spaces.

Advanced Persistent Teenagers, Okta Bug Allowed Logins Without a Correct Password 11.11.2024

In episode 354, we discuss the emergence of the term 'Advanced Persistent Teenagers' (APT) as a “new” cybersecurity threat. Recorded just before the election, the hosts humorously predict election outcomes while exploring the rise of teenage hackers responsible for major breaches. The episode also covers a notable Okta vulnerability that allowed someone to login without the correct password and it...

Fallout from the Change Healthcare Breach, Mortgage Wire Fraud What You Need To Know 04.11.2024

In episode 353, we discuss the February 2024 ransomware attack on Change Healthcare, resulting in the largest data breach of protected health information in history. Notifications have been sent to 100 million Americans, including hosts Tom and Kevin. We explore the implications of this significant breach and whether paying ransoms is a viable solution. In the 'Aware Much' segment, Scott explains...

Internet Archive Hacked, Introducing The AI Toilet Camera 28.10.2024

In this episode, we discuss the significant data breach at the Internet Archive, affecting 33 million users. We also examine the introduction of an AI-integrated toilet camera by Throne, designed for health monitoring by analyzing bodily waste, and the ensuing privacy concerns. We explore these technological advancements alongside other unusual tech innovations, touching upon security issues with...

Hacked Robot Vacuums, Secret Printer Tracking Dots 21.10.2024

In episode 351, hosts Tom and Scott explore an unusual incident where robot vacuums were hacked to shout obscenities, exposing significant IoT security issues. The discussion includes the mechanics of the Bluetooth hack and its broader cybersecurity implications. Additionally, the 'Aware Much?' segment reveals the world of hidden printer tracking dots, used for tracing document origins and their h...

Emergency Satellite Messaging, Stagnation in User Cybersecurity Habits 14.10.2024

In the milestone 350th episode of the Shared Security Podcast, the hosts reflect on 15 years of podcasting, and the podcast's evolution from its beginnings in 2009. They discuss the impact of a current hurricane on Florida, offering advice on using iPhone and Android satellite communication features during emergencies. The 'Aware Much' segment focuses on the lack of change in user behavior towards...

Kia Security Flaw Exposed, NIST’s New Password Guidelines 07.10.2024

In this episode, the hosts discuss a significant vulnerability found in Kia's web portal that allows remote control of various car features via their app, potentially enabling unauthorized unlocking and tracking. The conversation highlights the broader issue of web vulnerabilities in the automotive industry. Also covered are NIST's updated password guidelines, eliminating complexity rules and peri...

Discord’s New End-to-End Encryption, LinkedIn Using Your Data for AI Training 30.09.2024

In episode 348 of the Shared Security Podcast, Tom and Scott discuss Discord's new end-to-end encryption for audio and video calls, involving the DAVE Protocol, third-party vetting by Trail of Bits, and its impact on users. They also address LinkedIn's controversial move to automatically opt users into using their data to train AI models without initial consent, suggestions for opting out, and the...

Supply Chain Sabotage: The Exploding Pager Incident, Instagram’s New Teen Privacy Measures 23.09.2024

In Episode 347, we discuss the recent alarming incidents involving exploding pagers targeting Hezbollah operatives in Lebanon, which resulted in multiple casualties. We clarify why this is not a cyber attack and should not cause widespread panic about personal device safety. Additionally, we cover Instagram's new policies to default teen accounts to private and the implications for parental contro...

The Rise of AI Voicemail Scams, Political Donation Privacy Concerns 16.09.2024

In episode 346, we discuss new AI-driven voicemail scams that sound convincingly real and how to identify them. We also explore recent research on the privacy concerns surrounding donations to political parties through their websites. Additionally, we celebrate the 15th anniversary of the podcast and share some reflections and fun facts about the journey. Join us for this insightful and informativ...

Shocking SQL Injection in TSA App, Bitcoin ATM Scams Targeting Seniors 09.09.2024

This week, we discuss a critical SQL injection vulnerability discovered in an app used by the TSA, raising ethical questions about responsible disclosure. Plus, we shed light on the alarming rise of Bitcoin ATM scams exploiting older adults, providing essential tips to protect your loved ones from these devious schemes. Tune in for unique insights and vital cybersecurity advice!

Telegram is NOT an Encrypted Messaging App, Must-See Documentaries 02.09.2024

In this episode, we explore the recent arrest of Telegram founder Pavel Durov in France and discuss the app's encryption claims. Is Telegram truly an encrypted messaging app? Joining the conversation is co-host Kevin Johnson, bringing his trademark opinions. We also talk about some intriguing documentaries, including 'LulaRich' about the LuLaRoe leggings company and 'Class Action Park' about a dan...

Google’s Monopoly: The Debate Heats Up, Amazon Alexa Privacy Tips 26.08.2024

This week, we discuss Google's recent accusation by the U.S. Justice Department for being a monopoly and its implications for privacy and cybersecurity. We also cover essential privacy settings for Alexa smart speakers and their importance. Join the hosts, Tom, Kevin, and Scott, for an engaging conversation on these topics, along with a segment from ClickArmor on cybersecurity training. Plus, a re...

The Inefficiency of People-Search Removal Tools, Massive Data Breach Impacting U.S. Citizens 19.08.2024

In episode 342, we discuss the effectiveness of people-search removal tools like DeleteMe and Reputation Defender, based on a study by Consumer Reports. We also cover how almost every American's social security number has potentially been stolen by hackers and shared on the dark web. Scott and Tom talk about the importance of protecting your personal information and methods to do so, including man...

Listen to the Shared Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.