Firewalls Don't Stop Dragons Podcast

How to Choose a PIN

·1 hr 11 min·5 clips
Gary Parker warns you to update Chrome immediately due to actively exploited bugs, then defends his controversial Firefox stance.
The episode opens with host Gary Parker urging listeners to update Apple devices and Chrome due to security fixes, while defending his recommendation to use Firefox over Chrome despite criticism of Mozilla's financial management. He then runs through a news roundup: a ransomware attack on Australian prescription provider MetaSecure impacting personal health data; CISA warnings about D-Link router vulnerabilities; a story from Ars Technica about a tankless water heater controller with an unauthenticated API allowing remote control; a bleepingcomputer report on a hacker scraping 49 million Dell customer records via a partner portal API with fake company registrations; Nissan's disclosure of a breach exposing 53,000 employee social security numbers; a Tom's Guide article on the Cuckoo Mac malware that steals data and avoids infecting devices in certain countries; a cyber attack on healthcare provider Ascension; ProtonMail's compliance with a Swiss court order leading to the identification of an activist, highlighting OPSEC failures; an Ars Technica article on the Tunnel Vision VPN attack exploiting DHCP option 121, with responses from Mullvad and Proton; new data privacy laws passed in Vermont and Maryland; and a collaboration between Apple and Google on cross-platform anti-stalking detection for Bluetooth trackers. The tip of the week is inspired by analysis of 3.4 million breached PIN codes, revealing that 10.7% are '1234' and many are based on dates like birth years, advising listeners to avoid guessable patterns and consider using six-digit codes or obscure numbers. The episode concludes with previews of upcoming interviews.

As heard by us

A practical security tour that ties Apple updates, Chrome hygiene, and Mac malware risks together.

Gary Parker opens episode 377 with a timely reminder to update Apple devices and keep Chrome current, then moves into Cuckoo, a Mac malware campaign tied to piracy sites and fake converter apps.

Read the full review in PlayNext →

Why you'd press play

A brisk security checkup with Apple updates, a Chrome exploit warning, and a Mac malware detour.

Read the full recommendation in PlayNext →
Listen to the show on