Tom Eston, Scott Wright, Kevin Tackett

Shared Security Podcast

News EN ↓ 568 episodes

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.

Author

Tom Eston, Scott Wright, Kevin Tackett

Category

News

Podcast website

sharedsecurity.net

Latest episode

Jul 6, 2026

Where to listen?

Podcasts in the app Replaio Radio Coming soon

Podcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts

Get it on Google Play Install for free Android 5M+ downloads · 4.8 rating iOS soon

Episodes

Don’t Trust Your AI Girlfriend or Boyfriend, Exposing US Government Data Collection 04.03.2024

In Episode 319, Tom and Kevin discuss the potential data privacy risks associated with having an AI 'girlfriend' or 'boyfriend' and why one should refrain from sharing their personal data with such AIs. They engage in a humorous conversation about the unusual advertisements these AI companions attract, while expressing concerns over their deceptive and sensitive data gathering. The episode also ex...

‘Get to Know Me’ Privacy Risks, Pros and Cons of Publicly Sharing Ring Doorbell Footage 26.02.2024

In episode 318, we discuss the trending 'get to know me' posts on social media platforms like Instagram and the potential risks of sharing personal information publicly, particularly in light of potential misuse for password resetting. We recount a similar trend observed years ago when social media was in its infancy. The second topic covers Ring's decision to discontinue its 'Request for assistan...

25.6 Million Dollar Deepfake Scam, Exploring Canada’s Flipper Zero Ban 19.02.2024

In episode 317, the Tom and Kevin discuss a reported deepfake scam that allegedly led to the theft of 25.6 million from a multinational company and Canada's attempt to ban the Flipper Zero device, believing it plays a role in auto thefts. They critique the Canadian government's understanding of the device and its capabilities, questioning whether the move is political posturing rather than a measu...

Jason Haddix on Bug Bounties and Cybersecurity Career Growth 12.02.2024

In episode 316, we have the pleasure to chat with Jason Haddix, a prominent influencer in the cybersecurity community. With an intriguing career path, from being a 'computer kid', venturing into the nascent dark web, to becoming a respected figure in the Bug Bounty space, his journey is nothing short of inspiration. We dive into the evolution and the current state of Bug Bounty, the emergence of c...

The Problem of Victim Blaming in Cybersecurity: Empathy, Responsibility & Ethical Practices 05.02.2024

In this episode of the Shared Security Podcast, we discuss the concerning issue of victim-blaming in cybersecurity with special guest, Andra Zaharia, host of the Cyber Empathy and We Think We Know podcasts. Key topics include the societal issues within cybersecurity, the role of empathy in business and cybersecurity, leadership's role in empathy and the recent 23andMe data breach. We discuss how c...

Secure Your iPhone: Exploring Stolen Device Protection 29.01.2024

In this episode, host Tom Eston provides a detailed explanation of the 'Stolen Device Protection' for iPhones - a new security feature by Apple. This feature triggers enhanced security factors such as Face ID, Touch ID, and an hour-long security delay for critical actions when the phone is away from familiar locations. Tom also provides guidance on how to enable and disable this feature on iOS 17....

The World of Scambaiting, Preventing Social Media Account Takeovers, Network Wrenches Hacked 22.01.2024

In Episode 313, hosts Tom and Scott discuss the world of scambaiting, discussing what it is, the tactics used, and its effectiveness in stopping scammers. They talk about popular channels like Scammer Payback and Kitboga that show these scams in progress. Then they switch to the best practices to prevent social media account takeovers, highlighting a guide written by Rachel Tobac. Lastly, they sha...

Ohio’s New Social Media Law, Meta’s Link History Feature, 175 Million Passcode Guesses 15.01.2024

In episode 312, Tom and Scott discuss the implications of a new law in Ohio that may require parental consent for children under 16 using social media, including the pros and cons of this legislation. They also discuss Meta's new link history feature and the repercussions it might have on ad targeting on Facebook and Instagram. The episode concludes with a discussion on a court case in Ottawa, whe...

Most Advanced iPhone Exploit Ever, Google’s $5 Billion Settlement, Apple’s Journal App 08.01.2024

In this episode, we discuss the most sophisticated iPhone exploit ever, Google’s agreement to settle a $5 billion lawsuit about tracking users in ‘incognito’ mode, and a new iOS app, Journal. The iPhone exploit, known as Operation Triangulation, has complex chains of events that lead to compromised iPhone security. Meanwhile, the lawsuit against Google claims that the company’s technology was stil...

The Three Keys to Success in Cybersecurity 01.01.2024

In this episode, host Tom Eston shares the three key lessons he's learned over his 18-year career in cybersecurity: effective communication, continuous learning, and empathy. He talks about the importance of understanding and reaching both technical and non-technical audiences, the necessity of continuous learning despite your role, and the power of empathy in contributing to success.

The Year in Review and 2024 Predictions 25.12.2023

In our last episode of the year, we replay our predictions for 2023 reviewing what we got right and what we didn't. We cover various topics, such as Twitter's influence, the future of Mastodon, the ban of TikTok in certain states, and the rising issue of ransomware. In addition, we give credit to Scott for accurately predicting multiple cybersecurity events during the year! We also share our expec...

Password Security for the Elderly: Tips and Best Practices 18.12.2023

In episode 308, we discuss the often overlooked topic of password management for the elderly. Addressing the commonly held belief that writing down passwords is a bad idea, we discuss the nuances and context of this practice. Elderly individuals who may struggle with technology can benefit from recording passwords, but we discuss the importance of putting suitable controls around this. We also tou...

iOS 17 NameDrop Debunking, Real World QR Code Attacks, Impact of Ransomware on Hospitals 11.12.2023

In episode 307, Tom and Scott debunk misinformation circulating about the iOS 17 NameDrop feature by law enforcement and others on social media. Next, they discuss the potential risks of QR code scams, detailing a real-life incident where a woman lost a significant amount of money due to a QR code scam. Finally, the episode concludes with a discussion on a ransomware attack on a large US healthcar...

Application Security Trends & Challenges with Tanya Janca 04.12.2023

In episode 306, noteworthy guest Tanya Janca returns to discuss her recent ventures and her vision for the future of AppSec. She reflects on the significant changes she has observed since her career at Microsoft, before discussing her new role at Semgrep that recently acquired WeHackPurple. Tanya sheds light on her decision to partner with Semgrep, a company that aligns with her vision of providin...

Apple Finally Adopts RCS, AI Powered Scams Targeting the Elderly 27.11.2023

In this episode, Tom shows off AI generated images of a "Lonely and Sad Security Awareness Manager in a Dog Pound" and the humorous outcomes. The conversation shifts to Apple's upcoming support for Rich Communication Services (RCS) and the potential security implications. Lastly, Tom and Kevin reflect on reports of AI-powered voice cloning scams targeting elderly Americans, and argue that the true...

Paying Big Tech for Privacy, New Privacy Policy Study, Biden’s Executive Order on AI 20.11.2023

In this week's episode of the Shared Security Podcast, hosts Tom Eston, Scott Wright and Kevin Johnson tackle a number of topics related to AI, privacy and security. They begin with an amusing discussion about their respective roles on the podcast, before shifting to big tech's use of user data and whether subscribers should pay to not have their data used. The focus then turns to a recent move by...

SEC vs. SolarWinds CISO, Classiscam Scam-as-a-Service 13.11.2023

In this episode we discuss the SEC's charges against SolarWinds' CISO for misleading investors about a major cyberattack. Plus don't miss our discussion about the shady world of "Classiscam Scam-as-a-Service," a very popular cyber criminal service that creates fake user accounts, posts fraudulent reviews, and boosts the reputation of dishonest sellers while defrauding e-commerce platforms.

Okta Hacked Again, Quishing Is The New Phishing, Google Play Protect Real-Time Scanning 06.11.2023

In this episode, we explore the recent Okta breach where hackers obtained sensitive customer data via unauthorized access to the Okta support system. Next, we discuss the emerging threat of "quishing," a combination of voice calls and phishing that preys on unsuspecting victims. Finally, we discuss Google Play Protect's new feature, "Real-time App Analysis," which enhances Android device security...

How to Opt Out of CPNI Data Sharing 30.10.2023

Did you know that your mobile phone provider can give data like phone numbers you've called and received, the time and date of those calls, and even your location data to their parent companies, affiliates, and agents? In this episode we show you how to opt out so you can stop your data from being being shared!

Special Guest Jayson E. Street, Phantom Hacker Scams, 23andMe User Data For Sale 23.10.2023

In milestone episode 300, Jayson E. Street (a renowned hacker, helper, and human who has successfully robbed banks, hotels, government facilities, and Biochemical companies on five continents) joins us to share what he's been up to recently and to talk about his new role at Secure Yeti. Next, we explore the alarming rise of 'phantom hacker' scams targeting the elderly. The FBI issues a stern warni...

Educating the Next Cybersecurity Generation with Tib3rius 16.10.2023

In this episode, we explore the remarkable journey of Tib3rius, a web application hacking expert and content creator. In this engaging conversation, we discuss: - Tib3rius' passion for community education and content creation. What fuels his desire to empower the next generation of cybersecurity professionals? - His expertise and enthusiasm for web application hacking, and we explore the transform...

Your Car is a Privacy Nightmare, Password Creation Best Practices, Sony Hacked Again 09.10.2023

In this episode, we discuss the Mozilla Foundation's alarming report that reveals why cars are the top privacy concern. Modern vehicles, equipped with data-collecting tech, pose significant risks to consumers' privacy, with data sharing even extending to law enforcement. Listen in to our discussion as we explore the urgent need for transparency and *gasp* regulations in the automotive industry. Ne...

Is My Boss Spying on Me, Instagram Painting Scam, Kia and Hyundai TikTok Challenge 02.10.2023

In this episode, we explore the growing trend of AI surveillance in corporations, where cutting-edge technology is used to monitor employees, optimize productivity, and raise ethical concerns. Next, we uncover a disturbing Instagram scam that lures unsuspecting victims into a trap, highlighting the deceptive tactics employed by cyber criminals on social media. Finally, discover the startling vulne...

Content Creation, Mental Health in Cyber, The MGM Ransomware Attack 25.09.2023

In this episode Matt Johansen, Security Architect at Reddit and Vulnerable U newsletter and YouTube content creator, joins host Tom Eston to discuss Matt's background as one of the original "Security Twits", his career journey, his passion for mental health advocacy, the significance of the recent MGM ransomware attack, and a discussion on the pros and cons of paying ransoms.

The Changing Role of the CISO with Ryan Davis, Chief Information Security Officer at NS1 18.09.2023

In this episode Ryan Davis, Chief Information Security Officer at NS1, speaks with host Tom Eston about the changing role of the CISO, acquisitions, what the biggest challenges are, and Ryan's advice for those considering a career as a CISO. This is one episode you don't want to miss if you're curious what a CISO does, thinking about becoming one, or currently a CISO yourself.

Listen to the Shared Security Podcast podcast in Replaio

Radio and podcasts in one app - free, with no sign-up. Install today and do not miss the launch

Get it on Google Play

Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.