DiscoverShared Security Podcast
Shared Security Podcast
Claim Ownership

Shared Security Podcast

Author: Tom Eston, Scott Wright, Kevin Tackett

Subscribed: 712Played: 13,772
Share

Description

Shared Security is the the longest-running cybersecurity and privacy podcast where industry veterans Tom Eston, Scott Wright, and Kevin Tackett break down the week’s security WTF moments, privacy fails, human mistakes, and “why is this still a problem?” stories — with humor, honesty, and hard-earned real-world experience. Whether you’re a security pro, a privacy advocate, or just here to hear Kevin yell about vendor nonsense, this podcast delivers insights you’ll actually use — and laughs you probably need. Real security talk from people who’ve lived it.
581 Episodes
Reverse
Meta Muse is designed to work across a user’s inbox, calendar, browser, connected apps, and other personal services. That makes it useful—and makes its delegated authority a security problem worth examining.Tom Eston and Scott Wright discuss Meta’s stated guardrails for Muse, including isolated execution, connector separation, credential boundaries, and approval flows. They also examine reporting on a Muse authentication-token issue and why a compromised token can matter more when an agent is authorized to act across a person’s digital life.The conversation also covers privacy expectations, reports of human involvement behind AI tasks, liability when an agent makes a harmful decision, and how digital-legacy planning changes when an agent could continue acting after its owner is inactive. The practical takeaway: start with least privilege, separate read from write and spending authority, approve consequential actions, review logs, and keep a fast way to revoke access.** Links mentioned on the show **Ars Technica — Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day https://arstechnica.com/security/2026/09/muse-metas-extraordinarily-privileged-ai-assistant-has-a-serious-0-day/Meta AI Research — How We Built Safety Into Muse https://research.meta.ai/blog/security-and-safety-for-ai-agents-our-approach-with-museMeta Help Center — How Muse handles your privacy, safety and security https://www.meta.com/help/artificial-intelligence/1047255454427887/CNBC — Meta pushes into personal AI agents in Muse Spark family https://www.cnbc.com/2026/09/08/meta-personal-ai-agents-public-reckoning-privacy-safety.htmlWIRED — Meta Releases Muse, a Personal AI Agent With Privacy Built Into It https://www.wired.com/story/meta-releases-muse-a-personal-ai-agent-with-privacy-built-into-it/The Guardian — Meta’s AI agent Muse gives out user’s home address without permission https://www.theguardian.com/technology/2026/sep/28/metas-ai-agent-muse-home-address404 Media — Humans Reading Copilot Prompts and Images https://www.404media.co/humans-reading-copilot-prompts-images/Scott Wright’s Digital Legacy Network LinkedIn group https://www.linkedin.com/groups/39988004** Watch this episode on YouTube **https://youtu.be/rokXbwQgTgU** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **GuardsquareSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contactSpecial thanks to Guardsquare for sponsoring this episode! Guardsquare is the leader in mobile application security, with multi-layered protection for your Android and iOS apps. Learn more at Guardsquare.com.
A familiar voice is no longer proof of identity. Tom Eston and Scott Wright explain how AI voice-cloning scams turn family emergencies, executive requests, and urgent account changes into social-engineering bait—and why the defenses that work are old-fashioned but essential: pause, call back on a known number, use a private code phrase, and require independent approval before money, data, credentials, or access changes hands.** Links mentioned on the show **A scammer can now sound 100% like your wife — LinkedIn post https://www.linkedin.com/posts/saedf_a-scammer-can-now-sound-100-like-your-wife-share-7505586875944853506-TLYq/FTC — Scammers use AI to enhance their family emergency schemes https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemesFTC — Preventing the harms of AI-enabled voice cloning https://www.ftc.gov/policy/advocacy-research/tech-at-ftc/2023/11/preventing-harms-ai-enabled-voice-cloningNational Cybersecurity Alliance — Why your family and coworkers need a safe word in the age of AI https://www.staysafeonline.org/articles/why-your-family-and-coworkers-need-a-safe-word-in-the-age-of-ai** Watch this episode on YouTube **https://youtu.be/6sfXD86bKco** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
Will AI kill us all? Tom Eston, Scott Wright, and Kevin Tackett examine competing AI-risk claims, public calls for guardrails, and the gap between dramatic safety messaging and verifiable internal controls. They discuss realistic harm pathways—from people over-trusting automated systems to distributed operation and weak shutdown options—while challenging the incentives that let companies call for regulation as they keep accelerating.** Links mentioned on the show **Axios — Here’s how AI could kill us all (if the worst fears come true) https://www.axios.com/2026/09/09/ai-doom-pdoom-kill-all-humans-anthropic2026 International AI Safety Report https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026The Digital Legacy Tree — Scott Wright https://digitallegacytree.com/** Watch this episode on YouTube **https://youtu.be/XF6-nhb1i3A** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
A reported dark-web service offering more than 153 million U.S. and Canadian driver’s-license scans for sale has brought the hidden cost of identity verification into focus. Tom, Scott, and Kevin discuss the alleged breach and FBI inquiry, why a license is a durable credential that people cannot simply rotate, and how ID scanners, vendors, and downstream data sharing turn routine checks into a supply-chain risk. They explore real-time identity-document capture, the limits of encryption and retention promises, and privacy-preserving design principles including data minimization, scoped proof, limited sharing, local storage where feasible, and meaningful accountability.** Links mentioned on the show **Gizmodo — Identity Verification Is Broken https://gizmodo.com/identity-verification-is-broken-the-153-million-drivers-licenses-now-for-sale-are-proof-2000806437KrebsOnSecurity — FBI Probes Service Selling 153M+ Drivers Licenses https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/Reuters — FBI probes report of data breach exposing millions of drivers’ licenses https://www.reuters.com/world/us/fbi-says-it-is-investigating-report-that-millions-us-drivers-licenses-exposed-2026-09-02/** Watch this episode on YouTube **https://youtu.be/r_bXkZk_q38** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
Is Hotel WiFi Safe?

Is Hotel WiFi Safe?

2026-09-0714:33

Hotel Wi‑Fi is not automatically unsafe, but it is never a network you should blindly trust. Tom Eston and Scott Wright break down Microsoft’s CaptiveCrunch reporting, including how manipulated captive portals can lead to credential phishing, device-code abuse, and malware delivery.They cover what HTTPS and VPNs actually protect, why a lock icon does not prove a page is legitimate, the warning signs that should make travelers disconnect, and when a cellular hotspot is the better choice. Scott also shares an update on his Digital Legacy Tree book and tools.** Links mentioned on the show **Microsoft Threat Intelligence — CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/FBI hotel Wi‑Fi guidance https://watech.wa.gov/fbi-warns-cyber-risks-when-telecommuters-use-hotel-wi-fiFCC — Cybersecurity Tips for International Travelers https://www.fcc.gov/consumers/guides/cybersecurity-tips-international-travelersScott Wright — Digital Legacy Tree book and tools https://securityperspectives.com/digital-legacy-tools** Watch this episode on YouTube **https://youtu.be/TBqKfiGayfo** Become a Shared Security Supporter **Get exclusive access to bonus episodes, listen to new episodes before they are released, receive a monthly shout-out on the show, and get a discount code for 15% off merch at the Shared Security store. Become a supporter today by going to our YouTube channel's membership section: https://www.youtube.com/channel/UCg9CCDIYkDDqwEZ3UYaxjnA/join** Thank you to our sponsors! **SLNTVisit https://slnt.com to check out SLNT's amazing line of Faraday bags and other products built to protect your privacy. As a listener of this podcast you receive 10% off your order at checkout using discount code "sharedsecurity".** Subscribe and follow the podcast **Subscribe on YouTube: https://www.youtube.com/c/SharedSecurityPodcastFollow us on Bluesky: https://bsky.app/profile/sharedsecurity.bsky.socialFollow us on Mastodon: https://infosec.exchange/@sharedsecurityJoin us on Reddit: https://www.reddit.com/r/SharedSecurityShow/Visit our website: https://sharedsecurity.netSubscribe on your favorite podcast app: https://sharedsecurity.net/subscribeSign-up for our email newsletter to receive updates about the podcast, contest announcements, and special offers from our sponsors: https://shared-security.beehiiv.com/subscribeLeave us a rating and review: https://ratethispodcast.com/sharedsecurityContact us: https://sharedsecurity.net/contact
loading
Comments