#cybersecurity
51 episodes
#3804: Stateful Firewalls vs. Modern Threats
Is a basic firewall still enough in 2026? We break down what each security layer actually catches—and misses.
#3644: What Criminologists Actually Do (It's Not CSI)
Criminology isn't detective training. It's a social science that studies why crime happens—and whether the system works.
#3216: EFF's 36-Year Fight for Digital Rights
How the Electronic Frontier Foundation has fought for internet freedom since 1990 — from the Crypto Wars to border phone searches.
#2834: The Deep Ocean Trench of Authentication
PIN + smart card + biometric + behavioral checks. The real security stack behind federal authentication.
#2827: Why People Still Pay for SSL Certificates
Free DV certificates are everywhere, yet paid SSL still thrives. Here’s what commercial CAs actually provide that free ones don’t.
#2698: How Hackers Hide C2 Servers in Plain Sight
Bulletproof hosts, hijacked routers, and Discord channels — how command and control infrastructure stays up despite takedown attempts.
#2696: How Pegasus Silently Hijacks Your Phone's Microphone
How NSO's Pegasus achieves silent mic access on Android through zero-click exploits, kernel privilege escalation, and DMA buffer reading.
#2508: Why CORS Doesn't Protect Your Server
Why browsers block cross-origin requests, how CORS actually works, and the common pitfalls that trip up developers.
#2500: What Actually Counts as Hacking?
The CFAA, web scraping, and the messy line between curious URL-poking and federal crime.
#2481: How to Ask Cloud Vendors About Security (Without Sounding Clueless)
What to ask cloud vendors about security practices — and the technical red flags that actually matter.
#2391: When Anti-Bot Defenses Break Accessibility
How browser automation hits a wall with Israel's strict geo-restrictions and anti-bot measures—and what practical workarounds exist.
#2383: The Blame Gap: Public Anger vs. Breach Reality
How much blame do companies deserve for data breaches? The answer isn't as simple as you think.
#2382: How Five Eyes Intel Sharing Really Works
Behind the headlines of global cyber takedowns—how Five Eyes allies share signals intelligence in practice, from WWII roots to modern ops.
#2372: Choosing the Right Sandbox for Your Threat Model
Explore the tools and methods for creating secure, isolated environments to test malware, browse privately, and protect sensitive systems.
#2371: The Graph That Thinks: From Data Dots to Human Judgment
Discover how tools like Maltego and Spiderfoot transform single data points into intricate webs of connections, bridging digital and physical inves...
#2226: When Quantum Breaks Everything
Quantum computers will shatter RSA and elliptic-curve encryption—but the real danger is data being stolen and stored right now, waiting to be decry...
#2104: The Envelope Problem: Why Your VPN Isn't Enough
A VPN isn't magic. Learn how DNS and SNI leaks expose your browsing, and what encrypted DNS and ECH actually do to fix it.
#2103: AI Firewalls: Spotting Bombs on an Encrypted Conveyor Belt
With 95% of web traffic encrypted, firewalls can't read packets. Here's how AI analyzes metadata to detect threats without decryption.
#2102: Why Don't You Notice AI Security Delays?
Multi-layer security checks add latency, but modern CLIs hide it under 100ms using parallelization and speculation.
#2098: The Invisible War for the Radio Spectrum
Modern wars are won by controlling invisible waves, not just physical ground. Discover how electronic and cyber warfare merge to rewrite reality.
#2078: SITREP Flash; 7 Apr 02:50 (23:50 UTC)
U.S. sets a midnight deadline for Iran to leave the Strait of Hormuz as B-21 bombers and carriers move into position.
#2059: When Your AI Agent Runs Stale Code
npx is silently running old versions of your AI tools. Here's why your updates vanish into a cache black hole.
#1908: The Web's New Bouncer: When to Block AI Bots
AI bots are crawling the web like a bank heist. Are Cloudflare's new controls protecting your content, or just helping Google?
#1905: How VCs Verify AI Startups Without Stealing Code
From the "No-NDA Paradox" to AWS bill forensics, here’s how investors separate real AI from Raspberry Pis in fancy cases.