Explore every episode of the podcast Privacy Please
Dive into the complete episode list for Privacy Please. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.
Rows per page:
50
1–50 of 280
Title
Pub. Date
Duration
S7, E278 - Anthropic Researcher Quits: "We Believe AI Could Kill All Humans"
Jacob Coxon spent three years doing pretraining research at OpenAI and then Anthropic. This week he resigned and posted a seven-part thread claiming neither company is acting responsibly with how fast they're racing toward self-improving AI. It hit 100 million views in a day.
This episode covers what he actually said, how Anthropic's own alignment science lead responded (and the important nuance buried in that response), the questions worth asking about Coxon's timing and incentives, a fair skeptic's rebuttal, and the AI safety legislation already moving in Congress as a result.
One thing on the title: it's a real quote, but it's Hubinger's general belief statement, not his assessment of present-day risk — he separately said present-model risk is low. Your own episode makes that distinction carefully. Worth a one-line callout in your pinned comment or community post after it's live, so the title doesn't end up being the thing people push back on in the comments before they've actually watched.
Flock Safety's automated license plate readers are in over 5,000 communities and used by more than 40,000 cameras nationwide — sold to cities as a tool to catch car thieves and find missing people. But a Washington Post investigation found at least 50 officers accused of misusing the system, most of them to track romantic partners.
This episode covers:
The scale of Flock's network and how warrantless searches are legally justified
Individual abuse cases in Wichita, Milwaukee, and New Bedford
The Texas sheriff's office case tied to reproductive-related searches
404 Media's reporting on ICE's informal access to Flock data despite no official contract
Flock's "Freeform" search feature and the race/ethnicity flagging controversy
CEO Garrett Langley's August 13 apology and the new audit reforms
The historical parallel: NSA's "LOVEINT" scandal from the Snowden leaks
What's actually working: 39+ contracts canceled by cities in 2026
Jonathan Sander is back on Privacy Please — and he's brought two blog posts worth arguing about.
Sander (42 Notions, now in an operational role at Myota) joins Cam and Gabe to dig into why ransomware resilience should work like New York City's storm surge infrastructure — building something that pays off before disaster strikes, not just a wall you wait behind. Then the conversation turns to AI agents: why Sander tried and failed to build a clean taxonomy for them, the six dimensions he landed on instead (authority, execution location, trigger, persistence, delegation, tool reach), and why the "hybrid agent" — switching between acting on your behalf and acting with power you never had — might be the hardest identity problem in security right now.
Also covered: why "back to basics" (secrets, resilience, identity) is Sander's answer for teams panicking about AI, and a real story about an AI agent that deleted a Postgres database and just... apologized.
This week on Privacy Please, Cam breaks down four stories that all come back to one theme: choice.
GigaWiper — Microsoft researchers uncovered a new backdoor malware built from pieces of older malware families, giving attackers the ability to decide after they're already inside a network how they want to cause damage — from low-level disk wipes to fake ransomware with encryption keys that are never even saved. Multiple security firms are independently tracking it, with no group attribution yet.
Connecticut's new AI disclosure law — As of July 1st, companies covered by Connecticut's privacy law must clearly disclose whether their data is used to train large language models like ChatGPT, Gemini, DeepSeek, or Grok. Cam digs into why "disclosure" doesn't always mean "clarity," and what to actually look for in a privacy policy update.
California's Delete Act (DROP) — A correction and a deep dive: DROP has been live since January 1st, not launching in August as previously stated. What actually changes on August 1st is enforcement — the date data brokers become legally required to act on deletion requests. Cam walks through exactly how to submit one at privacy.ca.gov.
The Phantom Hacker gold bar scam — A 78-year-old Phoenix woman nearly lost $600,000 in gold bars to a scammer posing as a federal official — until she turned the tables and called the FBI herself. Cam covers the arrest, the courier-for-hire business model behind it, and the billion-dollar scale of phantom hacker scams since 2024.
Tips for this episode:
Back up your data offline — wipers don't negotiate, there's no ransom to pay your way out
Search privacy policy updates for "train," "AI," or "language model" before skimming past them
California residents: submit a DROP request now at privacy.ca.gov so it's queued before enforcement begins on August 1st
No real government agency will ever tell you to convert your money to gold, crypto, or gift cards — hang up and call the agency back yourself
Sources referenced:
Microsoft Security research on GigaWiper
Connecticut Data Privacy Act (CTDPA) amendment, effective July 1, 2026
California Delete Act / DROP platform, cppa.ca.gov
FBI IC3 reporting on Phantom Hacker and gold bar scams
AZFamily coverage of the Gary Christopher arrest, Phoenix Sky Harbor Airport
Chapter Timestamps
00:00 – Cold Open 01:30 – GigaWiper: Choose-Your-Own-Destruction Malware 04:00 – Connecticut's LLM Data Disclosure Law 06:15 – California's Delete Act & DROP Platform 08:30 – The Phantom Hacker Gold Bar Scam 11:30 – Recap & Close
Last year, every major outlet ran the same story: 16 billion passwords exposed. Apple. Google. Facebook. The largest breach in history.
It was overblown. Security experts tore it apart within 48 hours.
But here's the thing: the real story underneath that headline is actually scarier. And nobody covered it.
It's called infostealer malware. It's been quietly running on millions of devices — stealing passwords, bypassing MFA, and feeding an underground credential economy that's behind nearly every major breach of the last two years. Ticketmaster. AT&T. Coinbase. All of it traces back here.
In this episode, I dig back into that story and break down:
Why the 16 billion number was a "fearset, not a dataset"
What infostealer malware actually is and how it gets on your device
Why MFA doesn't fully protect you from this (and what does)
The underground marketplace where your stolen credentials are sold within 48 hours
The stat that should genuinely keep you up at night: 67 seconds
Six things you can do right now to protect yourself
SHOW NOTES
Episode: Your Password Is Already For Sale
Last year, the 16 billion password story dominated headlines. The headline was overblown — but the real threat underneath it, infostealer malware, is what nobody talked about. It's an industrial-scale credential theft economy running quietly in the background, and it's the engine behind almost every major data breach of the last two years. We dug back into it because it's only gotten worse.
Resources mentioned:
Check if your email has been breached: haveibeenpwned.com
Free password manager: bitwarden.com
Premium password manager: 1password.com
Key sources:
Cybernews — original 16 billion credential report (June 2025)
CyberScoop — "The 16 billion password breach story is a farce"
Gabe and I dig into Shiny Hunters and why the scariest cyberattacks now look like ordinary logins instead of dramatic break-ins. We map how credential theft, social engineering, and SaaS data exports turn basic security hygiene into the difference between a close call and a headline.
• Shiny Hunters’ scale, loose structure, and why takedowns rarely stick • Why ransomware and extortion keep growing as a business model • How the tactics evolve from Microsoft 365 and developer creds to SaaS platforms like Salesforce • Credential stuffing, vishing, and smishing as “low-friction” intrusion paths • The Snowflake-style failure mode of missing MFA and weak password practices • Password reuse and how consumer breaches can cascade into enterprise access • Data retention and why old records increase privacy risk • Vendor risk and the shared responsibility model for identity and data • Practical steps that improve security without relying on perfect users
If you guys have not been to our website, theproblemlounge.com, check it out. Got some new blogs up there. Sign up for the newsletter. Support us, follow us. Let’s get this out to more people.
The Pornhub breach is being reported as a data story. It's actually a story about shame as a weapon.
In December 2025, a hacker group called ShinyHunters claimed to have stolen 200 million records from Pornhub Premium users — including email addresses, locations, and intimate watch and search history. They sent extortion demands. The data was verified as real.
In this episode of Privacy Please, Cameron Ivey breaks down:
✅ What was actually stolen — and why it's worse than most breaches ✅ The three-way blame game between Pornhub, Mixpanel, and a mysterious 2023 employee access ✅ Why ShinyHunters is one of the most dangerous and active hacker groups operating right now ✅ The bigger question nobody's asking: why does this data still exist? ✅ Five things you can do right now to protect yourself
🔗 RESOURCES MENTIONED:
Check your email in breaches: haveibeenpwned.com
Freeze your credit: annualcreditreport.com (links to all three bureaus)
Data removal: DeleteMe — joindeleteme.com
Follow the reporting: bleepingcomputer.com | malwarebytes.com/blog
In this episode of Privacy Please, Cameron Ivey investigates Palantir Technologies — a data analytics company founded in 2003 with CIA backing that has quietly become embedded across nearly every major arm of the U.S. federal government.
This week's investigation covers:
The USDA Deal On April 22nd, the Department of Agriculture signed a $300 million blanket purchase agreement with Palantir to build "One Farmer, One File" — a unified digital profile for every American farmer. The deal was awarded without competitive bidding.
The IRS Bombshell The same week, The Intercept revealed — based on documents obtained by watchdog group American Oversight — that Palantir has been running financial crime surveillance operations inside the IRS since 2018. The IRS has paid Palantir over $130 million for access to a platform that cross-references bank records, tax filings, transaction histories, and more across millions of Americans.
The Immigration Enforcement Machine Palantir's ICE contracts — now over $145 million — power the agency's case management, deportation targeting, and real-time location tracking of immigrants. A tool called ELITE creates individual dossiers on deportation targets by pulling data from the Department of Health and Human Services.
The Pushback That's Working New York City's public hospital network canceled its Palantir contract after community organizing and City Council pressure. In the UK, 229,000 people have signed petitions to remove Palantir from the National Health Service. Public pressure is moving the needle.
Five Things You Can Do Right Now Cameron closes with specific, actionable steps every listener can take — from requesting your IRS transcript to freezing your credit to contacting your representative about sole-source contracting.
Privacy Please is part of the Problem Lounge Network. New episodes weekly.theproblemlounge.com
Chapter Markers
00:00 — Cold Open
01:30 — Intro & Show Welcome
02:45 — Act One: The USDA Deal
06:00 — Act Two: Who Is Palantir?
11:30 — Act Three: The Empire Expands (ICE, Policing)
17:00 — Act Four: Your Tax Returns Are In There Too
24:00 — Act Five: The Layer Nobody's Talking About
30:00 — Act Six: The Part That Gives Me Hope
34:30 — What You Can Actually Do (5 Tips)
39:00 — Closing Reflection (Adjust timestamps after editing)
A normal data breach steals names and passwords. This one may have stolen the recipe for building the world’s most powerful AI models, and it happened through software most people will never notice until it breaks. We follow the Mercor breach from the first warning signs to the moment poisoned Python packages hit PyPI and spread in minutes across systems that were set to auto-update.
We walk through what Mercor actually does in the AI economy, especially RLHF (Reinforcement Learning from Human Feedback), and why that behind-the-scenes work shapes how tools from OpenAI, Anthropic, Meta, and Google behave. Then we unpack Lite LLM, the open source “plumbing” that connects apps to multiple AI services, and how a supply chain attack can bypass the company you’re targeting by compromising the dependencies everyone trusts.
From there, the focus shifts to the fallout: contractors whose Social Security numbers and identity documents may be exposed, companies scrambling to assess backdoors and credential theft, and the bigger fear that proprietary AI training data sets and labeling strategies are being auctioned on the dark web. We also dig into the compliance controversy around SOC2 and ISO 27001 style certifications and what happens when security audits become performance instead of protection.
If you care about cybersecurity, data privacy, AI governance, and open source risk, listen through to the end for concrete steps you can take right now. Subscribe, share this with a friend who uses AI tools, and leave a review with your take on who should be held accountable.
You already knew you were the product. But did you know you're also the teacher?
Companies are quietly feeding your emails, your work decisions, your customer interactions, and your daily patterns into AI systems — systems designed to automate exactly what you do. And most people have no idea it's happening.
In this episode of Privacy Please, we break down how it works, who's doing it, why your right to delete your own data is functionally broken in the AI era, and what you can actually do about it.
What we cover:
How "function creep" turns your data into AI training fuel without new consent
The GitHub policy change that's happening right now — and how to opt out
Why employees at Amazon, Google, and JPMorgan described training AI as "building your own coffin."
The deletion problem — why you can't remove yourself from a trained model
Practical steps to audit your tools and protect yourself today
Your anonymous account isn't anonymous anymore. Researchers just proved it costs $4 to find out who you are.
In February 2026, a team from ETH Zurich and Anthropic published a paper that quietly ended the era of practical online anonymity. Their AI pipeline, using nothing but your posts, comments, and forum activity, correctly identified 67% of pseudonymous users from a pool of 89,000 candidates. No name. No photo. No metadata. Just your words.
This episode breaks down exactly how it works, why it's different from every deanonymization scare before it, who's most at risk, and what you can actually do about it.
In this episode:
How the ESRC pipeline (Extract, Search, Reason, Calibrate) works
Why previous anonymity attacks required structured data, and this one doesn't
Why commercial AI safety guardrails didn't stop it
What "practical obscurity" meant, and why it's gone
Concrete steps to reduce your exposure today
Links:
Research paper: arxiv.org/abs/2602.16800
Delete your Reddit history: redact.dev
Tor Project: torproject.org
Signal: signal.org
Privacy Please is part of The Problem Lounge network. 🌐 theproblemlounge.com 🎙️ Subscribe on Apple Podcasts, Spotify, or wherever you listen
Cameron and Gabe sit down with Girish Redekar, co-founder and CEO of Sprinto, to pull back the curtain on one of the most misunderstood areas of security: compliance.
Girish built his first startup, RecruiterBox, to 3,500 customers before selling it, and it was the painful, expensive, duct-taped compliance process he experienced firsthand that sparked the idea for Sprinto. Today, Sprinto helps companies move beyond point-in-time audits into something far more valuable: continuous, autonomous trust.
In this episode, we dig into:
Why passing a SOC 2 or ISO 27001 audit doesn't mean you're actually secure
The three stages of compliance maturity — and how to climb them
What "compliance debt" is and why it's quietly eating your business
How smart CISOs use their security posture as a revenue driver, not a back-office cost center
The "$100/month" challenge: what actually moves the needle for startups
How AI is reshaping compliance programs — for better or worse
Why Girish spent over a year talking to customers before writing a single line of code
Plus: the "sell more jeans" framework every CISO should know, Rich Hickey, The Mom Test, and the toilet paper question.
How a Super Bowl dog commercial accidentally revealed America's surveillance infrastructure
A family loses their dog. Ring runs a Super Bowl ad. America collectively goes "wait… what?"
This week, we're digging into Ring's "Search Party" feature, the AI-powered doorbell camera tool that lit up millions of living rooms during the big game and immediately made privacy experts lose their minds. Because what looked like a heartwarming story about finding your lost lab was actually a live demonstration of a nationwide networked surveillance system most people didn't know they were part of.
We follow the trail from the commercial to the backlash, from a secret police surveillance partnership that quietly got canceled mid-chaos, to an 84-year-old woman's "deleted" doorbell footage that the FBI recovered anyway.
There's a lost dog. There's Amazon. There's a company called Flock Safety that you need to know about. And there's a question worth asking before you go home and look at your front door.
Autonomy sounds like progress until the system turns your choices against you. We dive into how AI agents change the risk equation, why “don’t trust, verify” now beats “trust but verify,” and what to do when the update button itself becomes the attack vector.
We start with the Ivy League leak tied to Harvard and UPenn, where attackers exposed admissions hold notes that map influence rather than credit cards. That context turns routine records into leverage for extortion, social pressure, and geopolitical targeting. From there, we trace the surge of agentic AI in the workplace as employees paste code, legal docs, and sensitive files into chat interfaces. The real accelerant is MCP, the model context protocol that standardizes connections across Google Drive, Slack, databases, and more. Like USB for AI, MCP makes integration simple and powerful, but a single prompt injection can pivot across everything the agent can reach.
Security gets messier with supply chain compromise. A China‑nexus campaign allegedly hijacked the Notepad++ update mechanism, handing a bespoke backdoor to developers who did the right thing. We unpack how to keep patching while reducing risk: signed updates, independent checksum checks, tight egress policies for updaters, and strong monitoring around update flows. On the policy front, Rhode Island’s vendor transparency rule forces companies to name who buys data. It is a nutrition label for privacy, and it lets users and watchdogs finally connect the dots between friendly interfaces and aggressive brokers.
We close with concrete defenses that raise the floor. Move high‑value accounts to FIDO2 hardware keys or platform passkeys to block phishing at the protocol level. Scope agent permissions narrowly, isolate MCP connectors by function, and require explicit approvals for sensitive actions. Log everything an agent touches and review those trails. Autonomy should be earned, minimal, and observable. If AI is going to act on your behalf, it must prove itself at every step.
If this conversation helps you think differently about agents, influence mapping, and how to lock down your stack, subscribe, share with a teammate, and leave a quick review telling us the one control you plan to implement this week.
We kick off season seven with a tour of the year’s early privacy & security news: neighborhood watchtowers from Ring, a rival-led hack of Breach Forums, a massive stitched leak in France, a heavy Microsoft patch drop, AI agents on the rise, and new state privacy laws. We share practical steps: self-host cameras, freeze your credit, harden identity portals, and keep humans in the loop when AI handles sensitive data.
• CES unveils Ring’s neighborhood watchtower and its surveillance tradeoffs • Why self‑hosted DVR systems beat cloud video for privacy • Breach Forums doxxed by rivals and lessons in OPSEC • France’s 45 million record “combo” leak and re‑identification risks • Credit freezes, hard vs soft inquiries, and portal security • Microsoft’s 114 patches and sane patch management • AI agents escalating breach risk and human‑in‑the‑loop controls • New privacy laws in Indiana, Kentucky, and Rhode Island and actionable rights
Please go to theproblemlounge.com and sign up for the newsletter If you have guests or topics or anything, please reach out to us!
We look back at 2025’s privacy and security reality: useful AI where data was ready, repeating breach patterns, and infrastructure limits that slowed the hype. We call out backdoors, weak 2FA, and the shift toward passkeys, decentralization, and owning more of our stack.
• AI succeeds when data, process and governance are mature • Power, chips and cost constraints limit AI growth • SALT Typhoon shows backdoor risk and patching failures • SMS 2FA remains weak while passkeys gain ground • Data hoarding expands breach blast radius • Streaming consolidation drives algorithm control and piracy’s return • Decentralization and self‑hosting rebuild trust with users • 2026 outlook: AI contraction, ML pragmatism, fewer but stronger tools
Check out our website: the problemlounge.com If you have episode guest ideas or topics you want us to talk about, please send them our way Go check out YouTube channel, Privacy Please Podcast
In 2026, would you like to see us do live streams?
It is Monday, December 15th, and the battle for Hollywood has officially gone nuclear.
What started as an $82 billion acquisition by Netflix has morphed into a $108 billion hostile takeover battle with Paramount Skydance. As of this morning, stocks are volatile, the government has frozen the deal, and a massive Class Action Lawsuit has just been filed to burn it all down.
In this Special Report from Privacy Please, we break down the chaos of the last 72 hours. We uncover the "National Security" weapon Netflix is using to kill the deal, the foreign money backing Paramount, and the leaked memos that reveal why executives are selling you out.
No matter who wins—the Algorithm or the Oligarchs—your privacy is the casualty.
A week where the lawful intercept backdoor became the front door, a supply chain hop hit 200+ companies, a bargain app faced a malware lawsuit, and a university breach turned into a donor-targeting roadmap. We share simple moves to lower risk fast and set guardrails that actually hold.
• Salt Typhoon abusing CALEA at major US telecoms • Negligence, unpatched routers and weak passwords • Why SMS is transparent and how to switch to Signal • Kill SMS 2FA and use authenticators or YubiKey • Gainsight-to-Salesforce island hopping at scale • Audit connected apps and revoke stale API keys • Arizona AG lawsuit calling Timu malware • Shop via browser sandbox and use masked payments • UPenn donor data leak and Oracle exploit • Whaling protections with voice verification and data scrubbing • Practical recap: trust nothing, verify everything
Please follow us or subscribe on your podcast app, and watch the video on our YouTube or at theproblemlounge.com. If you have topics or guest ideas, we would love to hear from you
A sleepless night, a soft prompt, and a flood of relief—the rise of AI therapy and companion apps is rewriting how we seek comfort when it matters most. We explore why these tools feel so human and so helpful, and what actually happens to the raw, intimate data shared in moments of vulnerability. From CBT-style exercises to memory-rich chat histories, the promise is powerful: instant support, lower cost, and zero visible judgment. The tradeoff is less visible but just as real—monetization models that thrive on sensitive inputs, “anonymized” data that can often be re-identified, and breach risks that turn private confessions into attack surfaces.
We dig into the ethical edge: can a language model provide mental health care, or does it simulate empathy without the duty of care? We look at misinformation, hallucinated advice, and the way overreliance on AI can delay genuine human connection and professional help. The legal landscape lags behind the technology, with HIPAA often out of scope and accountability unclear when harm occurs. Still, there are practical ways to reduce exposure without forfeiting every benefit. We walk through privacy policies worth reading, data controls worth using, and signs that an app takes security seriously, from encryption to third‑party audits.
Most of all, we focus on agency. Use AI for structure, journaling, and small reframes; lean on people for crisis, nuance, and real relationship. Create boundaries for what you share, separate identities when possible, and revisit whether a tool is helping you act or just keeping you company. If you’ve ever confided in a bot at 2 a.m., this conversation gives you the context and steps to stay safer while still finding support. If it resonates, subscribe, share with a friend who might need it, and leave a review to help others find the show.
In this episode of Privacy Please, host Cameron Ivey discusses significant security threats, including a critical vulnerability in Microsoft's WSUS, a major data breach at the University of Pennsylvania, and the emergence of sophisticated malware known as Glassworm. The conversation highlights the importance of cybersecurity measures and the potential consequences of negligence in IT security.
She has millions of followers, lands six-figure brand deals, and lives a life of curated perfection. The only catch? She isn't real. She was entirely created by artificial intelligence.
Welcome to the unsettling world of synthetic influencers.
In this compelling episode of Privacy Please, we dive deep into the booming industry of AI-generated online personalities. Discover:
The Technology: How advanced AI image generators, 3D modeling, and Large Language Models combine to create hyper-realistic avatars and their compelling "personalities."
The Business Case: Why major brands and marketing agencies are investing millions in digital beings that offer total control, scalability, and no risk of scandal.
The Privacy & Ethical Dilemmas: We explore the "uncanny valley" of trust, the impact of deception by design, the new extremes of unrealistic beauty standards, and the potential for these AI personas to be used for sophisticated scams or propaganda.
The Future of Authenticity: What does the rise of the synthetic star mean for human creativity, genuine connection, and the very definition of "real" in our digital world?
It's a future that's already here, shaping what we see, what we buy, and even what we believe.
Key Topics Covered:
What are virtual/synthetic influencers?
Examples: Lil Miquela, Aitana Lopez, Shudu Gram
AI technologies used: image generation, 3D modeling, LLMs
Reasons for their rise: control, cost, scalability, data collection
Ethical concerns: deception, parasocial relationships with AI
Impacts: unrealistic standards, displacement of human creators, potential for malicious use (scams, propaganda)
Debate around regulation and disclosure for AI-generated content
We unpack how Apple’s Memory Integrity Enforcement changes the rules of mobile security by rebuilding memory architecture, not just adding guardrails. We weigh who should upgrade now, what this means for Android, and why people remain the biggest risk.
• memory corruption explained with apartment analogy • why NOP sleds and heap sprays fail under MIE • tags, type segregation, and synchronous checks at runtime • market-share vs design: Apple, Windows, Android trade-offs • Pegasus, zero-click exploits, and threat profiles • game hacking parallels: reading vs corrupting memory • should you upgrade: high-risk users vs everyday users • why architecture-level security beats bolt-on tools
You click "agree," you swipe a loyalty card, you browse online – every digital breadcrumb you leave is being collected, but not just by the apps and websites you use. Welcome to the world of data brokers, a multi-billion-dollar, hidden industry that aggregates, analyzes, and profits from your most intimate personal information.
In this special episode from Privacy Please, we pull back the curtain on this shadowy ecosystem. Discover:
What a data broker is and how they differ from typical tech companies.
Where they get your data – from public records and online activity to your shopping habits and app usage.
Who they sell your data to – marketers, financial institutions, insurers, political campaigns, and even law enforcement.
The alarming real-world impacts, from hyper-targeted ads and scams to potential discrimination and exploitation.
This industry operates with minimal regulation in the United States, leaving most consumers vulnerable.
Actionable steps you can take right now to reclaim some control over your personal information, including data removal requests and essential digital hygiene.
It's an invisible trade happening without your consent, and you are the product. Listen now to understand the true price of your digital life.
Key Topics Covered:
What are data brokers?
Sources of personal data collection
Types of data collected (demographics, health, financial, behavioral)
Who buys data broker profiles?
Impacts: targeted ads, scams, discrimination, political targeting
Privacy and cybersecurity leader Sonia Siddiqui joins us to explore the collision between emerging technologies and privacy regulations, offering insights on how companies can navigate this complex landscape while building trust.
• Sonia's journey from aspiring architect to privacy expert, motivated by the intersection of civil rights and privacy • The growing gap between rapid technological innovation and slower-moving regulatory frameworks • Examining real-world tensions like WorldCoin's iris scanning under GDPR's biometric data provisions • Why privacy should be a core business enabler rather than just a compliance checkbox • The importance of implementing privacy by design as a living process that evolves with technology • Why principles-based regulation allows for better adaptation to new technologies than prescriptive rules • The inseparable relationship between privacy and security in building customer trust • How privacy professionals can stay current through professional networks, podcasts, and continuous learning • Essential privacy resources including "The Unwanted Gaze" and "Dieterman's Field Guide to Privacy"
Find Sonia and her privacy consulting practice at tamarack.solutions or connect with her at the upcoming AI conference in Boston.
The digital world can be treacherous, especially when you're looking for a safe space to share your most vulnerable thoughts. Today's story about the Tea app breach will make you rethink every "anonymous" platform you've ever trusted.
Tea promised women complete anonymity, a digital sanctuary where they could share dating horror stories, relationship struggles, and deeply personal confessions too raw for other platforms. Thousands believed this promise, uploading personal photos and sharing intimate details of their lives. Then security researchers made a chilling discovery: Tea's entire database sat completely unprotected on the internet. No password required.
The numbers are staggering: 72,000 private images including selfies and IDs, plus 1.1 million direct messages containing confessions about abortion, sexual assault, infidelity, and more, all exposed. But the story takes an even darker turn when someone created "T-Spill," weaponizing this stolen data by turning private photos into ranking games and mapping personal information to real locations. This wasn't just a technical failure; it was a profound betrayal that turned a supposed sanctuary into what can only be described as a predator's playground.
As the FBI investigates and lawsuits mount, we're left with uncomfortable questions about digital trust. How do we balance our need for connection with the reality that our most vulnerable moments are only as protected as the people building these platforms? The next time an app promises total privacy, remember Tea and maybe wait to see how they handle their first crisis before sharing your deepest secrets. Subscribe to Privacy Plays for more deep dives into breaches that expose the very human cost of our connected world, and check out our expanded content on the Problem Lounge Network.
For decades, Chris Hansen’s iconic catchphrase, "Why don't you have a seat?" was the prelude to exposing predators in the real world.
Now, his hunt has moved into the metaverse. His target is Roblox, the global gaming platform used by over 70 million people daily, most of whom are children. Hansen and his team allege the platform is a "cesspool" and a "hunting ground" for criminals, while Roblox maintains its safety systems are robust.
In this special report, "Privacy Please" goes beyond the headlines to investigate the clash. We explore the platform's design, from the "Avatar Loophole" that allows bad actors to bypass chat filters to the recommendation algorithm that can lead young users down dangerous paths.
Is this a simple case of a company needing to moderate more, or is the very business model that made Roblox a multi-billion dollar success also its greatest safety vulnerability?
Credited Resources & Further Reading
Primary Sources & Reporting:
Takedown Across America with Chris Hansen: Official platform for Hansen's ongoing investigations and reporting.
Roblox Corporate Statements & Community Standards: Official statements and policies from Roblox regarding their safety and moderation efforts.
WIRED/Bloomberg Reporting: Recent articles from major tech publications that have investigated platform safety issues on Roblox and similar metaverse platforms.
Common Sense Media: A non-profit organization that provides independent reviews and ratings for media and technology, often analyzing the safety features of platforms like Roblox.
(Note: As this is an ongoing investigation, it's recommended to reference the most current news articles and official press releases from the time of recording for the most up-to-date information.)
Digital privacy is under siege from all sides, and we're bringing you the latest developments along with a major announcement about our growing privacy-focused network.
This week has seen a flood of significant data breaches across critical sectors. Air France-KLM and Workday experienced major incidents, with the latter connected to a broader campaign targeting Salesforce CRM systems. These breaches highlight the vulnerability of systems storing vast amounts of customer data and raise serious questions about the security of our critical infrastructure. As we discuss these events, we examine the ripple effects they create and what organizations should be doing differently.
The question of who truly owns your digital identity emerges as a central theme in our conversation. Most people don't realize that when using third-party authentication providers like Google or Facebook, they're surrendering control of their identity. Every "Login with Facebook" click allows these companies to track when and where that identity is used across the digital landscape. We explore self-sovereign identity as an alternative approach, where individuals control their own verification infrastructure rather than relying on tech giants.
We also tackle the paradox at the heart of data minimization efforts. For years, companies have been told that "data is the new oil" or "currency," yet are now expected to minimize collection. This contradiction makes implementing privacy principles challenging. As we put it: "You told me I'm sitting on gold, and now you want me to minimize it?"
Beyond these discussions, we share exciting news about our expansion into a network featuring three distinct shows. In addition to Privacy Please, we're launching "Problem Lounge," exploring the messiness of being human in our technology-driven world, and "Decoded," a technical deep-dive with privacy engineer Jake that will explore privacy-enhancing technologies, cookie audits, and the intersection of privacy and AI.
Visit our new website at theproblemlounge.com to learn more about our expanding network and how you can become part of the conversation around privacy in the digital age.
It starts with a strange letter in the mail. A car loan you never applied for. A credit card you don't own. A digital ghost is quietly living your life, and you have no idea how it got the keys. When you turn to one of the silent guardians of your financial identity for help, you find only chaos, confusion, and a company that seems to be a danger to itself.
This week on Digital Fallout, we tell the true story of one of history's most catastrophic data breaches. It's a tale of staggering corporate negligence, a botched public response that became a dark comedy, and a 76-day silent heist where the identities of 147 million people were stolen.
What happens when the keepers of our most valuable secrets simply forget to lock the door?
Show Notes: Sources
This story was pieced together from numerous public records, government reports, and in-depth investigative journalism. For those who want to learn more about the 2017 Equifax breach, these are the key sources we consulted:
The official report from the U.S. Government Accountability Office (GAO) titled "Data Protection: Actions Taken by Equifax and Federal Agencies in Response to the 2017 Breach," which provides a definitive timeline and analysis of the failures.
Federal Trade Commission (FTC) public statements and court filings related to the landmark global settlement with Equifax.
In-depth reporting from security journalist Brian Krebs (KrebsOnSecurity), who meticulously covered the botched response, including the fake phishing sites promoted by Equifax's own Twitter account.
Technical explainers from outlets like WIRED magazine that broke down the Apache Struts vulnerability and how it was exploited.
Ongoing coverage of the corporate and financial fallout from The New York Times and The Wall Street Journal during September and October 2017.
The public testimony of former Equifax CEO Richard Smith before the U.S. House Committee on Energy and Commerce, where many of the internal failures were brought to light.
It started with a few flickering screens in a Danish office. Within minutes, a digital plague had paralyzed global trade, leaving the world's largest shipping company powerless and its massive vessels adrift. But this attack wasn't for ransom—it was for pure destruction. In the premiere of Digital Fallout, we uncover the story of a geopolitical cyber weapon that escaped its cage and the unbelievable, accidental miracle that saved a global empire from permanent deletion. This is the story of how our physical world hangs by a fragile digital thread.
Show Notes: Sources
Our story today was built on the foundation of incredible investigative journalism from reporters who covered this event extensively. For listeners who want to dive deeper into the story of the NotPetya attack, these are the primary sources we recommend:
"The Untold Story of NotPetya, the Most Devastating Cyberattack in History," an article by Andy Greenberg for WIRED magazine, forms the core of the public narrative regarding Maersk's experience.
The book "Sandworm: A New Era of Cyberwar and the Hunt for the Kremlin's Most Dangerous Hackers" by Andy Greenberg provides deep context on the attackers and the geopolitical landscape.
Financial and logistical impact reporting from The New York Times, The Wall Street Journal, and Reuters was published in the weeks and months following the June 2017 attack.
Public statements and quarterly financial reports from A.P. Møller-Maersk detailing the incident's operational and financial costs.
We explore how cybercriminals fell victim to their own security mistakes and examine major attacks targeting corporate SharePoint environments. Privacy legislation advances with new protections for children and groundbreaking AI accountability measures in Minnesota.
• Cybercrime forum exposes member data through database misconfiguration • SharePoint under active attack with remote code execution vulnerabilities • California passes enhanced children's privacy legislation requiring stricter parental consent • Minnesota Consumer Privacy Act launches July 31st with human review rights for AI decisions • Problem Lounge studio expansion announcement with new podcast launches • Trust and anonymity requirements in criminal digital ecosystems • Corporate IT challenges with ubiquitous software vulnerabilities • Growing complexity of state-by-state privacy compliance requirements
The US military has issued a stark warning to all forces to operate under the assumption that their networks have been compromised by Salt Typhoon, a sophisticated threat actor with ties to the Chinese government. This breach highlights the urgency for organizations to adopt Zero Trust principles as cyber warfare becomes the new battlefield.
• Zero Trust is a framework, not a single product or technology • The first tenant of Zero Trust is treating networks as already compromised • Salt Typhoon remained undetected in networks for almost a year • The threat actor targeted telecommunications, energy, and transportation infrastructure • Critical national infrastructure remains at high risk from similar focused attacks • Traditional security approaches focusing solely on perimeter defense are inadequate • Once compromised, networks may never be fully trusted again • Verification must occur upon every access request, not just initially
The European Parliament has released a groundbreaking 175-page study concluding that AI companies' practice of training on copyrighted material without permission constitutes mass reproduction not covered by current laws. This study recommends transforming the landscape through an opt-in system, radical transparency requirements, and fair compensation models for creators whose work trains AI systems.
• EU study reveals AI companies are treating the internet like a free "all-you-can-eat buffet" of creative content • Recommendation to shift from opt-out to opt-in system requiring AI companies to request permission • Call for mandatory transparency about what data AI models are trained on • Proposal for fair licensing models similar to Spotify where creators get paid when their work trains AI • New EU AI Act regulations taking effect in August will incorporate some of these protections
Stay safe, stay informed, and always question the code.
Cameron and Gabe dive into Healthline Media's record-breaking $1.55 million settlement for CCPA violations, examining whether such penalties are sufficient deterrents against improper sharing of sensitive health data.
• Healthline violated CCPA by sharing sensitive user health data with advertisers without proper consent • First U.S. regulatory action against a company for disclosing "inferred sensitive data" • Violation included failing to provide mechanisms to opt out of sensitive data sharing • Discussion of whether fines proportional to company revenue would be more effective • Comparison of data brokers to other harmful entities in society • Brief preview of upcoming episode about a major data breach potentially larger than Equifax
Stay safe this holiday weekend and don't put fireworks where they don't belong! Tune in next time for our breakdown of a massive data breach of "epic proportions."
Several popular Chrome extensions, including privacy and security tools, have been found leaking sensitive data through unencrypted HTTP and hard-coded credentials in their code. Security is both hard and easy - hard because of existing unencrypted protocols and trust placed in developers, but easy because fundamental security practices should be common knowledge in 2025.
• Chrome extensions including DualSafe Password Manager and Avast Online Security are leaking sensitive user data • HTTP vs HTTPS - the 'S' stands for security and encrypts data transmission over the internet • HTTPS Only extension from EFF forces secure connections when browsing • Hard-coded credentials in extensions create permanent security vulnerabilities • Developers sometimes collect excessive data "just in case" rather than minimizing collection • OWASP (Open Web Application Security Project) provides essential resources for developers • Technology abstraction makes users less aware of security fundamentals • The newly restarted OWASP Nomad chapter offers virtual community for application security
Check out our GitHub repository of privacy resources at "Awesome Privacy Engineering Tools" for more information on implementing better privacy practices in development.
We explore the recent LexisNexus data breach that exposed sensitive personal information of over 364,000 individuals through a third-party platform accessing their GitHub account. This incident highlights critical vulnerabilities in how data brokers handle our most sensitive information and raises questions about regulatory oversight.
• Data exposed included names, date of birth, phone numbers, social security numbers, and driver's license numbers • The breach occurred when someone accessed the company's GitHub account through a third-party platform • Attackers likely found hard-coded credentials that allowed them to move laterally through systems
• Data brokers operate with minimal regulation despite handling massive amounts of sensitive information • Better governance policies and automated privacy operations could significantly reduce these risks • Both technical solutions and regulatory approaches are needed to protect consumer data
Breach Occurred: December 25, 2024.
Discovery: April 1, 2025.
Public Notification: May 27, 2025.
Notice Letters Sent: May 24, 2025.
Shameless plus: Check out tools like Transcend's autonomous privacy operations to help prevent similar incidents and continue to monitor your privacy activities.
Gabe and Cameron dive into the unseen dangers of AI systems, exploring how inherent biases shape our perception and how prompt injection attacks pose serious security threats.
• Generative AI models contain built-in biases based on their training data, favoring Western and particularly North American perspectives • A recent study shows ChatGPT-4 with personalization is more persuasive than humans 64.4% of the time • Most users accept AI outputs without questioning the underlying biases • Prompt injection allows hackers to insert malicious instructions into AI systems that can lead to data leaks and security breaches • Security professionals don't yet understand the full scope of AI vulnerabilities • Google's new video generation technology makes it impossible to distinguish between real and AI-created content • Despite digital concerns, it's important to appreciate real-world experiences like enjoying ice cream on a hot summer day
ProPublica's investigation reveals the National Shooting Sports Foundation has been secretly sharing gun buyers' personal information, including underwear sizes, for political purposes. This privacy breach raises serious concerns about data exploitation even in industries that publicly position themselves as defenders of individual rights.
• Gun owners group demands federal investigation into firearms industry data sharing • Personal data shared included underwear sizes and was allegedly used for political targeting • NSSF collaborated with Cambridge Analytica to enhance voter data • Privacy concerns should transcend political divides - "Privacy is an everybody problem" • The gun industry publicly defends rights while quietly engaging in data exploitation • Senator Richard Blumenthal supports investigation into these practices
If you're a privacy professional or legal expert with insights on this issue, we'd love to have you on the show to discuss this further and answer some of the questions we've raised today.
Privacy Please News, for hitting big topics quickly with a hint of sarcasm to bring some joy and knowledge.
This week, we hit on the latest privacy events in tech with a satirical perspective on how your data is being shared, sold, and exploited. From Google's dramatic stance on sharing search data to state-sponsored hackers dominating zero-day exploits, this episode highlights the absurdity of our current digital privacy landscape.
• Google CEO Sundar Pichai compares sharing search data to "ripping out the company's brain" • WhatsApp's new AI feature sends "private" messages to cloud servers despite Meta's safety claims • Gun rights group outraged after gun industry shared customer data, including underwear sizes, for political campaigns • OpenAI's Sam Altman promotes eyeball scanning for WorldC, dismissing privacy concerns as regulatory lag • State-sponsored hackers from China and North Korea are leading the zero-day vulnerability exploitation game
Cameron and Gabe return after a brief hiatus to explore major developments in security, privacy, and resilience. They dive into insights from the IAPP conference and VeeamOn, examining how AI governance and outdated privacy tools are reshaping the industry landscape.
• AI governance frameworks dominated IAPP discussions with companies "building the plane as they're flying" • Verizon's Data Breach Report debunks overblown AI security fears, showing real risks are data leakage and poor access controls • Growing frustration with outdated privacy management tools is driving demand for better solutions • Security posture isn't about using recognized brands but about architecture without dangerous gaps • Sam Altman's virtual appearance at IAPP disappointed attendees expecting an in-person keynote
Stay tuned for our bonus episode covering even more developments from this busy week in privacy and security!
Privacy threats continue to escalate as human error undermines even the most secure systems, from military officials accidentally exposing classified information to Russian hackers targeting encrypted messaging apps.
• Signal security breach occurred when defense officials accidentally added a reporter to their encrypted group chat discussing sensitive military operations • Russian-linked attackers targeting Signal users through QR code vulnerabilities, tricking users into linking their secure accounts to attacker-controlled instances • QR codes present broader security concerns as users can't verify where they lead before scanning them • Attackers can place malicious QR codes over legitimate ones in public spaces like restaurants and airports • 23andMe's bankruptcy raises critical questions about the fate of genetic data from 15 million users • When companies holding sensitive personal information go bankrupt, data ownership and protection becomes uncertain • Human error remains the primary vulnerability in most privacy and security systems • Always consider the long-term implications when sharing personal information with any service
Remember to think beyond the present when sharing your data – consider what might happen to that information in 10, 20, or even 30 years from now.
Privacy threats are intensifying across multiple fronts, from genetic data vulnerabilities at 23andMe to corporate violations and messaging app security concerns. Cameron Ivey breaks down three urgent privacy issues and provides practical guidance on protecting your digital footprint in an increasingly vulnerable online landscape.
• 23andMe users should consider deleting their genetic data immediately due to bankruptcy proceedings that could compromise privacy protections • Law professor Craig Conneth warns that terms of service could change during bankruptcy, with inadequate federal regulations to protect consumers • Honda fined $632,500 by California Privacy Protection Agency for creating unnecessarily complicated opt-out processes • Companies must reform data request procedures and stop creating "mazes of chaos" that trick consumers • Signal messaging app, despite its encryption features, has raised NSA security concerns after being used by senior US officials • No messaging platform is completely secure for highly sensitive information • Stay informed about your rights under privacy legislation like the CCPA • Be mindful about what personal information you share digitally, even on supposedly secure platforms
If you have expertise in these privacy issues and would like to join a deeper discussion on the show, contact Cameron for a potential guest appearance.
We explore how uncertainty and chaos create both vulnerabilities and opportunities in privacy and security. Amid global turmoil, cybersecurity professionals must adopt a bias toward action to counter increased threats that thrive in chaotic environments.
• Chaos serves as a smoke screen for malicious actors, just as DOS attacks once distracted from network intrusions • Recent Ghost ransomware attack affected 70 countries but received less attention due to global uncertainty • Security resource contraction combined with increased noise creates fertile ground for more breaches • AI may cause job losses primarily in roles created to support the initial AI boom • States are tightening data breach reporting requirements with class action lawsuits doubling or tripling since 2022 • Some states introducing "safe harbor" laws to shield businesses that implement strict cybersecurity standards • Elon's Department of Government Efficiency (DOGE) faces 11 lawsuits for allegedly violating Privacy Act of 1974
Today's episode dives into the intersection of AI behavior and digital security concerns. We discuss a startling incident involving a malfunctioning AI robot and explore a new ransomware threat known as Ghost.
• Overview of an AI robot incident that raised ethical concerns • Examination of Asimov's Laws of Robotics and their relevance • Introduction to Ghost ransomware and its impact on multiple industries • Discussion on backup security strategies and resilience against ransomware • Insights into the evolving tactics of ransomware attacks, including Ghost's methods • Encouragement for businesses to prioritize future-proofing their data security
We encourage listeners to reach out with questions or further discussion on data backups and data security measures.
The emergence of quantum computing presents a unique set of challenges and opportunities for data security and privacy. As Microsoft reveals its new quantum chip, the industry must prepare for the significant threats that stable quantum computing poses to existing encryption methods.
• Microsoft announces a new quantum processing chip • Potential risks to encryption and data security • Industry skepticism toward claims of rapid advancements • Understanding the mechanics of quantum computing • Implications of quantum technology for various sectors • The need for proactive planning and strategy for security professionals
The episode delves into the ongoing lawsuits challenging the sharing of personal data by federal agencies with Doge, the Department of Government Efficiency. The hosts discuss the implications of these lawsuits, particularly regarding the lack of clarity surrounding Doge's operations and the dismantling of the CFPB, raising concerns about privacy and data protection.
• Overview of Doge data lawsuits and their significance • Concerns about data sharing by federal agencies • The troubling lack of transparency surrounding Doge • The impact of CFPB restructuring on privacy oversight • Risks of diminished regulatory powers over personal data • Importance of citizen engagement in privacy advocacy • Calls for transparency and accountability in data handling • The evolving narrative of privacy in the digital age • Encouragement for listeners to stay informed and proactive
The episode examines the implications of a recent hacking incident involving the Chinese AI company DeepSeek, which claims to outperform competitors on cost and performance. We discuss the risks associated with AI tools, the necessity for better governance, and the broader impacts of AI on cybersecurity and data privacy.
• DeepSeek's emergence as a significant player in AI • Performance claims that challenge established tech firms • Consequences of the recent hack on industry perceptions • The dangers of unregulated AI usage in corporations • Governance challenges surrounding AI adoption • Personal experiences using AI-driven coding tools • Future predictions on AI's role in security and privacy
The conversation centers on the evolving regulatory landscape amid a new administration, discussing the implications for data privacy and AI legislation. The episode emphasizes state-level movements and the potential for Congress to enact a cohesive national law while addressing emerging concerns around social media and technology.
• Overview of the new administration's regulatory potential • Recent state-level data privacy laws and their implications • Importance of legislative committees in shaping policy • Future prospects for national data privacy legislation • National security concerns related to technology, especially TikTok • Discussion on transparency in AI data usage • Evolving roles of states versus federal government in tech policy • Anticipation of 2025's regulatory challenges and opportunities
Apple’s recent iOS update has raised serious privacy concerns by enabling AI tools that monitor user behavior without consent. The episode emphasizes the urgent need for users to disable invasive settings while questioning Apple's commitment to privacy amidst its marketing claims.
• Examination of the AI features in the latest iOS update • Default settings that allow data collection on app usage • Discussion on Apple's reputation versus actual practices • Potential consequences for users who are unaware of these changes • Speculation on how this may affect Apple's market share • Exploration of the need for privacy-focused technology alternatives • Encouragement to take action by adjusting privacy settings
Go turn off all those privacy-invasive settings on your device.
As 2025 kicks off, we explore the irony of the EU Commission fining itself for breaching its own data privacy regulations. The episode delves into the absurdity of minor fines, enforcement challenges, and the need for accountability in privacy governance.
• Introduction to the state of the world in 2025 • Discussion of California’s wildfires and broader global issues • Examination of the EU’s self-imposed fine for data privacy violations • Analysis of the significance of a $412 fine • Importance of enforcement over mere fines • Teaser for upcoming discussions on legislation and privacy in 2025
The episode reflects on the intertwined impacts of AI, privacy, and cybersecurity throughout 2024. We explore trends around ransomware, consumer trust in data privacy, and what to expect in 2025 as technologies evolve and regulations advance.
• Discussion of AI's ambiguous role in cybersecurity • Rise of ransomware incidents and implications for critical sectors • Notable trends in consumer preferences regarding data privacy • Legislative developments in data protection regulations • Predictions for 2025 focused on quantum computing and cybersecurity strategies