Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing

Smashing Security podcast #462: LinkedIn is spying on you, and you agreed to nothing

LinkedIn has been secretly scanning your browser for over 6,000 installed extensions – on every single click you make. It can tell if you’re job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned anywhere in their privacy policy.

Meanwhile, California’s crypto millionaires are learning that no amount of encryption can protect you from someone who knocks on your door pretending to deliver a pizza.

All this and more in episode 462 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Dave Bittner.

0:00

0:00



Show full transcript


TranscriptThis transcript was generated automatically, probably contains mistakes, and has not been manually verified.

So what should I say?

Uh, let’s say, say, uh, looking forward to this week’s Smashing Security podcast.

With my co-host.

Or my special guest, Dave Bittner.

Stand down, Dave.

Thank you. Sorry. I got ahead of myself. Uh, you know.

Smashing Security, Episode 462: LinkedIn is Spying on You, and You Agreed to Nothing, with Graham Cluley and special guest Dave Bittner.

Hello, hello, and welcome to Smashing Security, Episode 462. My name is Graham Cluley.

And I’m Dave Bittner.

Dave Bittner from the CyberWire, back on the podcast again. We can’t get you away from a microphone, can we?

I know, I’m like a terrible rash and difficult to get rid of.

Do you ever feel like, you know, I’ve had enough of this, it’s time to time to hang up my spurs. Well, I suppose they’re not spurs, are they?

Time to hang up my XLR cables.

My XLR cables, yeah.

Not so much that, but I will tell you there are times when I smash my head against the desk and say, I need a vacation. I need a break. I need to get away from the bad news.

Yeah. I mean, I find it tough doing one podcast a week, but you do about 89 a week.

I do. I do. I have to learn how to navigate it so it doesn’t take too hard a toll on you emotionally, but I’m, you know, I’m mostly there, but there are days, Graham, there are days.

Well, we certainly do appreciate you coming on the Smashing Security podcast today. And before we kick off, let’s thank this week’s wonderful sponsors, Meta, ESET, and Vanta.

We’ll be hearing more about them later on in the podcast. This week on Smashing Security.

We won’t be talking about how hackers working for the Russian government broke into thousands of home routers to steal passwords.

You’ll hear no discussion of how tourists traveling to Hong Kong have been warned that it’s now a criminal offense to refuse to hand over to police the passwords for all your personal devices.

And we won’t even mention how after authorities cracked down on the use of Telegram, WhatsApp, and VPNs, Russian citizens have switched to using two other apps.

For instant message and video call, including in some cases smart cat feeders. So Dave, what are you going to be talking about this week?

I’m talking about some wealthy California crypto holders who are being targeted in wrench attacks.

And I’m going to be shining a light on how LinkedIn is shining a light on its users. All this and much more coming up on this episode of Smashing Security.

Well, before we kick off, we’ve just got a moment to thank one of this episode’s sponsors, ESET.

Now, there’s no shortage of cybersecurity vendors claiming to be the best, of course, but ESET is one of the few that’s been proven it for 30 years.

Research has always been at the core of what ESET does.

Their threat intelligence teams are actively tracking APT groups and ransomware affiliates and publishing findings that the security community actually reads and references.

That’s not a marketing line. That’s 30 years of doing the work. And here’s what makes it interesting.

3 decades of research means that ESET has built up global telemetry that most vendors simply don’t have access to.

They combine that telemetry with AI-native technology and human expertise, and that’s what powers both their products and their MDR service.

Real intelligence behind the protection, not just pattern matching. 110 million users worldwide trust ESET with their endpoints, cloud, email, and mobile devices.

That number doesn’t happen by accident. So why don’t you check them out right now? Go to smashingsecurity.com/ESET. That’s smashingsecurity.com/ESET. And thanks to ESET.

For supporting the show. Now, chums, chums, LinkedIn. Don’t you love it? Don’t you love it? I love it. Oh boy. It’s great.

If by love you mean hate and do everything in my power to avoid it, then yes, I love it.

Oh, Dave, Dave, it’s a wonderful service. It’s a fantastic place. It’s a platform where people I’ve never met can endorse me for skills that I don’t have.

Right? Have you ever been told you are excellent at being an astronaut? You know, brain surgeon? Absolutely. Yes, he’s fully qualified. Qualified for that.

Good news, we got the perfect job for you.

Belly dancer. Oh yes, sirree.

But you know what I love the most about LinkedIn is the humility. The humility that everyone shows up there.

You know, because no one’s afraid to be a little bit vulnerable on LinkedIn these days, are they?

They’re all sharing the lessons they’ve learned on life’s journey, often from their failures.

Maybe they’ve been made redundant and they started up a company and now they’ve succeeded and they’re encouraging others.

They’re saying, look, I was a failure too, just like you, but now I am magnificent. Or they’ll give you a humble brag about stepping on an orange.

There’ll be some lesson they’ve learned in life and they’ll post about it and link to it. I find those heartwarming. Don’t you? Don’t you love those?

Oh, for sure. I can’t get enough of them. It’s a highlight of my day. Go on.

You know what? I think it’s great because there’s not a site out there that is more unintentionally entertaining than LinkedIn.

Seeing what people are posting, it’s a good old guffaw. So I go there every day.

Well, I, you know, I was recently turned on to a Reddit group.

Actually, uh, Maria Varmazis told me about— there’s a Reddit group called LinkedIn Lunatics.

I’ve been there. In fact, I think I’ve been, I’ve been included in on it before.

Okay, well, it’s just, it’s very entertaining, very entertaining.

Yes, I did make an appearance up there and I got a certain amount of abuse about a humble brag.

Didn’t involve stepping on an orange, but clearly I’d showed a little bit too much humility or been self-promoting too much.

Now, of course, I don’t go on LinkedIn looking for a job. What fool would go on LinkedIn to look for a job? That’s not what it’s there for.

You know, it’s not to say though that I don’t love the feeling of a recruiter sliding into my DMs, which they do occasionally, saying, oh, we’ve got the perfect job for you.

We can tell that you’re a cybersecurity and AI whatchamacallit. And sometimes they offer me jobs which are entirely inappropriate.

I think there was once a touring group that they asked me to join, a chorus line for HMS Pinafore or something going around Bulgaria.

Well, see, that would grab my attention, actually.

You would be tempted by that, wouldn’t you?

Yes, I would. That fish would work on me.

Now, one thing is clear, LinkedIn is a deeply strange corner of the internet.

And this week, it got that little bit stranger because a German privacy group— and you always have to worry when a privacy group is German, they’re serious about their privacy.

They are called Fairlinked, and they’ve published what they’re calling the Browsergate Report. And you always know you’re in trouble, don’t you, when there’s a gate involved?

Oh, absolutely.

You know, ever since 1972, 2, I think it was.

I often wondered, no, what if there was a scandal involving something like the Brandenburg Gate? Would you then have Brandenburg Gate Gate?

Or perhaps a scandal involving Bill Gates.

Bill Gates Gate. You know, yes. Maybe that’s the defence to prevent there being a scandal about you is to change your surname to Gate beforehand.

Anyway, Browsergate reveals that every single time you open LinkedIn in a Chrome-based browser, the LinkedIn platform will quietly inject a little bit of JavaScript into your session.

And that little bit of JavaScript, well, I say it’s little, is 2.7 megabytes, David, 2.7 megabytes of JavaScript.

Well, by today’s standards, that’s nothing.

That’s barely anything, is it? And that, that what it does is starts scanning your browser for over 6,000 specific installed extensions. Hmm.

So it’s looking for all kinds of information about what you are running on your computer within your browser while you’re on LinkedIn.

It also harvests your CPU core count, your available memory, your screen resolution, your battery status, your time zone, your language settings.

And this isn’t once per visit to LinkedIn. This is every single click that you make. Hmm.

So you click on someone’s profile and it’s going to send a fingerprint, a unique, pretty much unique fingerprint with all these different indicators regarding your computer.

Or if you ignore a connection request from someone you met at a conference a few years ago, again, it will send a fingerprint or If you spend 4 minutes reading a post about 3 things the Navy SEALs taught me about inbox zero, it’s going to— it’s going to send your fingerprint.

And none of this, none of this is mentioned anywhere in LinkedIn’s privacy policy, which is absolutely fine.

No, absolutely fine and dandy, isn’t it? It’s brilliant.

No worries. No worries.

No worries at all. So 6,000 extensions is looking nice. I think I’ve got 6,000. And what are these extensions? Well, it turns out they’re like language and grammar extensions.

So if you have a tool which helps you translate LinkedIn posts, for instance, hmm, it will pick that up or a grammar extension, something to make you look more eloquent on LinkedIn.

If you’re using a tax tool, If you— oh, also extensions designed for people with ADHD or dyslexic users, because there are dyslexic extensions you can put on your browser which change the font to make it easier to read, for instance.

There are tools that notify users— oh, this was an odd one— tools that notify users of Islamic prayer times.

Oh, that’s not at all problematic.

Who would be interested in that, I wonder?

No, no. What could possibly— history has told us what could possibly go wrong with tracking people based on their religion.

And there are also extensions that could indicate your politics. I don’t know quite what they do.

Maybe they change your wallpaper to a particular flag or put a color scheme on your laptop. I’m not sure. But anyway, many of these aren’t scraping tools. These are personal tools.

They could reveal deeply private information about you and your health and your faith or your neurology.

And that’s not really what you want LinkedIn to be secretly cataloging, is it?

No, I would not expect this of them, although I have to say these days nothing surprises me anymore.

Right. And it’s dangerous information because that is linked to your real name, right? No one calls themselves Fruitbat79 on LinkedIn.

That’s right.

You’ve got your real name and your employer and your job title, etc. So this isn’t by any means anonymous browsing data. You are logged in LinkedIn.

LinkedIn knows exactly who you are.

And it’s also going to know if, for instance, you’re secretly looking for work and it will be logging that against your profile on the very website that your boss uses, because this list includes over 500 job search tools.

So if you have those tools installed, when you go on LinkedIn, it knows about it. It knows you’re looking for a job. Well, your current employer has an account as well.

So LinkedIn internally apparently calls this a spectroscopy. Spectroscopy? Is that it? It sounds like a colonoscopy.

I think that’s right. That’s the tool that chemists use to tell the elements, right?

Yeah. Isn’t it shining a light or a very bright light and determining something? Yeah.

Didn’t you have some sort of high-profile figure who strongly believed in shining a bright light inside your body in order to kill COVID? Oh, that’s not Stalin. All that. Yeah.

Anyways, apparently back in 2017, which is around about the time LinkedIn introduced this feature, so it’s only really been uncovered now.

Back then, LinkedIn was scanning for 38 extensions, which feels like, well, maybe that’s all right.

Because maybe these were extensions which were scraping information, maybe people’s personal information off LinkedIn. They may want to stop that from happening.

By 2024, it had gone from 38 extensions to 461, which is still a lot, but you could perhaps argue there are 461 ways to scrape LinkedIn.

I’ll be honest with you, I actually have an extension in my browser which does take information from LinkedIn, right?

So I have a CRM for customers and things and people who contact me asking me to do work for them and things.

And it’s useful sometimes just to collect information about, you know, who are they, what’s their job title, what’s their contact details if we connected and things.

And so I’ve got this little button which I can press which does take it from their profile and add it to my CRM and it saves me some time. So, you know, I do kind of do this now.

I don’t know if LinkedIn don’t like that I’ve got this little tool.

You’re not doing it at scale.

No, no, no. I’m doing it maybe once or twice a week. Right. Anyway, they’ve now gone from 38 to 461 banned extensions, or rather logged extensions. Now it’s 6,000.

I looked this morning, it’s 6,222.

But who’s counting?

Well, it’s the German privacy guys who are counting. So LinkedIn have been asked about this. And what they’ve said is the claims made are plainly wrong.

And they say that while at the same time not denying that they do have a list of 6,000 extensions. They haven’t denied any of that.

They’ve only tried to discount the intention behind it. So they say the scanning is purely to identify extensions that scrape data. In violation of their terms of service.

Again, I don’t know what that has to do with Muslim prayer times.

They say they don’t use the data to infer anything sensitive about their users. And they say that this report from these German guys should be taken with, you know, a pinch of salt.

In fact, they say that the person behind the report had their account banned by LinkedIn for scraping in the past. And apparently a German court denied their injunction request.

Against the platform. So there is some beef between the researchers and LinkedIn.

So this is all sour grapes according to LinkedIn?

Well, that’s what they’re kind of claiming. But I think it’s possible that the person who discovered this, maybe they were behaving badly at some point, right?

But it’s also entirely possible that the thing they discovered is still a problem. And those two things are not mutually exclusive.

So if someone with a speeding ticket tells you that your house is on fire, you should probably still check. Is it a bit warm in here?

Right, right.

Rather than just say, no, no, no, you’ve got a speeding ticket. I don’t know. Anyway, what can you do about this problem?

Well, the obvious thing to do is either not go to LinkedIn or use a different browser. So if you use Firefox, you’re largely protected.

The way its extensions work don’t expose the same identifiers that Chrome does. Similarly, Brave, that blocks tracking endpoints by default.

Safari users largely in the clear as well.

But if you’re on Chrome or Edge, Edge of course is a Chrome-based browser, you are being scanned every time you visit and there’s no setting to stop them from doing it.

And LinkedIn is not being upfront about what it is doing. So regulators have been informed. We’ll have to see if anything comes from this, but it’s not great, is it?

It’s not great. And I wonder, how does this come up against GDPR over, over in your neck of the woods?

Yes, well, I think this German privacy guy has lodged a GDPR complaint with the regulators, so we’ll have to see.

It does sound like the guys at LinkedIn are rather scooping up a bit too much information.

What do you make of this, though? Do you think it’s just browser fingerprinting that’s kind of spun out of control, or do you think there’s more to it than that?

I don’t think it’s necessarily being done with malicious intent.

How can I be in this industry so long and be so naive to think that it It won’t be used for advertising purposes or surveillance.

What even counts as malicious intent anymore, right?

What even counts? That’s true. That is very true. Now, you mentioned to me about LinkedIn earlier because I’m a user of this very cool browser. I don’t use Google. I use Kagi. Okay.

And they introduced this new feature and you reminded me earlier about this. They’ve got this translator thing, haven’t they?

Where, you know, like you have Google Translate, you can translate between languages, but now with Kagi, you can translate something into LinkedIn speak.

Have you had a go at this?

Oh, I have. Why don’t you type something in here and we’ll see how it translates. This is great fun.

Okay, okay. So what should I say?

Let’s say, looking forward to this week’s Smashing Security podcast with my co-host, my co-host or my special guest, Dave Bittner.

Stand down, Dave.

Thank you.

I got ahead of myself, you know.

Okay. It’s done a little translation into LinkedIn. So it starts off, of course, with an emoji. So I’ve got a rocket emoji.

Thrilled to announce— come on, British, I’m never thrilled— that I’ll be joined by the one and only Dave Bittner on this week’s episode of the Smashing Security podcast.

Microphone emoji. Can’t wait to dive deep into the latest in cybersecurity. You won’t want to miss this conversation.

#cybersecurity, #infosec, #postcast, #networking, #thoughtleadership. Oh, I can change my excitement level. I can go for high energy with more emojis and hype.

That’s right. And you can puke hashtags as well.

Well, we’ve got time right now to chat about one of our sponsors this week, Vanta. SPEAKER_02. Oh yes, my favorites. What do they do again?

They stop you running your entire security program out of a spreadsheet, Joe. SPEAKER_02. That seems aimed at me personally, Graham.

Well, it is a little bit, yes.

But you know how most companies have to prove they’re secure to customers or auditors and regulators, and the whole thing involves chasing down evidence, filling in questionnaires and forms, updating the same spreadsheet cells over and over again.

SPEAKER_02. Over and over again. It sounds utterly soul-destroying.

Well, Vanta automates all of that. SPEAKER_02. Automates it?

Well, their trust management platform keeps a continuous eye on your systems. It pulls everything into one place. And keeps you audit-ready around the clock.

So no more staring at the ceiling at 2 AM wondering whether you’ve got the right controls in place or whether one of your suppliers has been breached. SPEAKER_02.

The stuff of nightmares.

Yeah, it would be, wouldn’t it?

But this Banta solution uses AI as well, and it’s the useful kind— flagging risks, collecting evidence, slotting into the tools your team already uses so you move faster, scale without the headaches, and perhaps actually get some sleep.

Go to vanta.com/smashing to find out more. SPEAKER_02. That’s vanta.com/smashing. And thanks to Vanta for supporting the show.

Dave, what’s your story for us this week?

Well, Graham, uh, I am talking about life imitating art. And by art, I mean the classic XKCD comic, which I’m sure you are familiar with.

This is the comic with the little stickmen, isn’t it?

It is, yeah. The comic with the little stickmen generally talking about tech and occasionally cybersecurity.

And I have to say, the first time I saw this particular comic, it had indeed been printed out and stuck to a bulletin board in a break room.

That was the first time I saw it, but I’ve seen it dozens of times afterwards. I thought perhaps the two of us could reenact this for our listeners before I dig into the story here.

So I will narrate and also I will be one of the characters and you can be the other characters.

–spp-font-ui: -apple-system, BlinkMacSystemFont, ‘Segoe UI’, sans-serif;

background: var(–spp-bg);
border-top: 6px solid var(–spp-accent);
border-bottom: 6px solid #E76E4E;
border-left: 1px solid var(–spp-border);
border-right: 1px solid var(–spp-border);
border-radius: 8px;
overflow: hidden;
font-family: var(–spp-font-ui);
color: var(–spp-text);
max-width: 820px;
margin: 1.5rem auto;
box-shadow: 0 4px 24px rgba(0,0,0,.4);
}

.spp-header {
display: flex; gap: 18px; align-items: flex-start;
padding: 16px 18px;
background: var(–spp-header-bg);
border-bottom: 1px solid var(–spp-border);
}
.spp-artwork-link { flex-shrink: 0; }
.spp-artwork { width: 100px; height: 100px; object-fit: cover; border-radius: 6px; display: block; }
.spp-wrap .spp-meta { flex: 1; display: flex; flex-direction: column; gap: 4px; justify-content: flex-start; padding-top: 4px; }
.spp-wrap .spp-episode-num { font-size: .9rem; font-weight: 600; letter-spacing: .08em; text-transform: uppercase; color: var(–spp-accent); margin: 0 !important; padding: 0 !important; }
.spp-wrap .spp-title { font-size: 1.5rem; font-weight: 600; line-height: 1.4; color: var(–spp-text); margin: 0 !important; padding: 0 !important; }
.spp-title a { color: inherit; }
.spp-title a:hover { text-decoration: underline; }

.spp-audio-simple { width: 100%; margin-top: 8px; }

.spp-caption-text {
flex: 1; min-width: 0; font-size: .85rem; color: var(–spp-muted);
overflow: hidden; display: -webkit-box; -webkit-line-clamp: 3;
-webkit-box-orient: vertical; line-height: 1.4; visibility: hidden;
height: calc(1.4em * 3); align-self: center; font-style: italic;
opacity: 0.4;
}
.spp-caption-text:not(:empty) { visibility: visible; }
.spp-caption-text.spp-playing { opacity: 1; }
@media (max-width: 650px) { .spp-caption-text { display: none; } }
.spp-has-precise-captions .spp-caption-text {
font-size: 1rem; font-weight: 500; color: var(–spp-text);
text-align: center; -webkit-line-clamp: 1; height: 1.5em;
letter-spacing: .01em; font-style: italic;
}

.spp-mobile-caption-strip { display: none; }
@media (max-width: 650px) {
.spp-mobile-caption-strip {
display: flex; align-items: center; justify-content: center;
padding: 8px 16px; min-height: 2.8em;
border-bottom: 1px solid var(–spp-border); background: var(–spp-bg);
}
.spp-mobile-caption-text {
font-size: 1rem; font-weight: 500; color: var(–spp-text);
text-align: center; white-space: nowrap; overflow: hidden;
text-overflow: ellipsis; width: 100%; font-style: italic;
opacity: 0.4;
}
.spp-mobile-caption-text.spp-playing { opacity: 1; }
.spp-has-precise-captions .spp-mobile-caption-text { font-size: 1.1rem; font-style: italic; }
}

.spp-controls {
display: flex; align-items: center; gap: 10px;
padding: 0 18px 12px; flex-wrap: wrap;
background: var(–spp-bg); border-bottom: 1px solid var(–spp-border);
}
.spp-controls button { -webkit-appearance: none; appearance: none; }
.spp-controls button:hover, .spp-controls button:focus, .spp-controls button:active { outline: none; box-shadow: none; background-color: transparent; }
.spp-play-btn:hover, .spp-play-btn:focus, .spp-play-btn:active { background-color: var(–spp-accent) !important; }

.spp-progress-wrap { order: -1; width: 100%; padding: 10px 0 4px; border-bottom: 1px solid var(–spp-border); margin: 0 0 8px; }
.spp-progress-bar { position: relative; height: 54px; cursor: pointer; display: flex; align-items: center; }
.spp-waveform { position: absolute; top: 0; left: 0; width: 100%; height: 100%; display: block; }
.spp-wave-times { display: flex; justify-content: space-between; padding: 3px 0 0; }
.spp-wave-current, .spp-wave-total { font-family: var(–spp-font-mono); font-size: .72rem; color: var(–spp-muted); pointer-events: none; }
.spp-time-current, .spp-time-total { display: none; }

@media (max-width: 650px) {
.spp-wave-times { display: none; }
.spp-time-current, .spp-time-total { display: inline; }
.spp-wrap .spp-title { font-size: 1.1rem; }
}

.spp-skip-btn {
background: none; border: none; color: var(–spp-muted); cursor: pointer;
display: flex; flex-direction: column; align-items: center; justify-content: center;
gap: 1px; padding: 0; line-height: 1; transition: color .15s;
}
.spp-skip-btn:hover { color: var(–spp-text); }
.spp-skip-arrow { font-size: 20px; line-height: 1; }
.spp-skip-num { font-size: 10px; font-family: var(–spp-font-mono); line-height: 1; }

.spp-play-btn {
background: var(–spp-accent); border: none; border-radius: 50%;
width: 40px; height: 40px; min-width: 40px;
display: flex; align-items: center; justify-content: center;
cursor: pointer; color: #3a2000; transition: opacity .15s, transform .1s;
}
.spp-play-btn .spp-icon-play, .spp-play-btn .spp-icon-pause { width: 22px; height: 22px; }
.spp-play-btn:hover { opacity: .85; transform: scale(1.05); }
.spp-play-btn svg { width: 16px; height: 16px; }

.spp-time-current, .spp-time-total { font-family: var(–spp-font-mono); font-size: .92rem; color: var(–spp-muted); white-space: nowrap; min-width: 44px; }

.spp-speed-btn {
background: var(–spp-surface); border: 1px solid var(–spp-border);
border-radius: 4px; color: var(–spp-muted); font-size: .72rem;
font-family: var(–spp-font-mono); padding: 3px 7px; cursor: pointer;
white-space: nowrap; transition: color .15s, border-color .15s;
}
.spp-speed-btn:hover { color: var(–spp-text); border-color: var(–spp-accent); }

.spp-controls-spacer { flex: 1; }
.spp-has-captions .spp-controls-spacer { flex: 0; min-width: 0; }
.spp-has-captions .spp-caption-text { flex: 1; min-width: 0; }
.spp-volume-wrap { display: flex; align-items: center; gap: 6px; }
.spp-mute-btn { background: none; border: none; color: var(–spp-muted); cursor: pointer; display: flex; align-items: center; padding: 0; transition: color .15s; }
.spp-mute-btn:hover { color: var(–spp-text); }
.spp-mute-btn svg { width: 18px; height: 18px; }
.spp-volume-slider { -webkit-appearance: none; appearance: none; width: 70px; height: 7px; background: var(–spp-border); border-radius: 4px; outline: none; cursor: pointer; }
.spp-volume-slider::-webkit-slider-thumb { -webkit-appearance: none; width: 14px; height: 14px; background: var(–spp-accent); border-radius: 50%; }
.spp-volume-slider::-moz-range-thumb { width: 14px; height: 14px; background: var(–spp-accent); border: none; border-radius: 50%; }

.spp-ft-su-transcript { padding: 14px 18px; border-bottom: 1px solid var(–spp-border); margin-bottom: 4px; }

.spp-full-transcript { border-top: 1px solid var(–spp-border); background: var(–spp-surface); }
.spp-full-transcript-toggle {
display: flex; justify-content: space-between; align-items: center;
padding: 12px 18px; cursor: pointer; list-style: none;
color: var(–spp-muted); font-size: .9rem; font-weight: 600;
letter-spacing: .04em; text-transform: uppercase;
transition: color .15s, background .15s; user-select: none;
}
.spp-full-transcript-toggle::-webkit-details-marker { display: none; }
.spp-full-transcript-toggle:hover { color: var(–spp-text); background: #2a2a2a; }
.spp-full-transcript[open] .spp-full-transcript-toggle { color: var(–spp-text); }
.spp-full-transcript-arrow { transition: transform .2s; display: inline-block; }
.spp-full-transcript[open] .spp-full-transcript-arrow { transform: rotate(180deg); }

.spp-full-transcript-body { padding: 8px 0 16px; }

.spp-ft-block { padding: 10px 18px; border-left: 4px solid transparent; }
.spp-ft-meta { display: flex; align-items: baseline; gap: 10px; margin-bottom: 4px; }
.spp-ft-speaker { font-size: .8rem; font-weight: 700; text-transform: uppercase; letter-spacing: .06em; color: var(–spp-accent); }
.spp-ft-time { background: none; border: none; padding: 0; font-family: var(–spp-font-mono); font-size: .78rem; color: var(–spp-muted); cursor: pointer; transition: color .15s; }
.spp-ft-time:hover { color: var(–spp-accent); text-decoration: underline; }
.spp-ft-text { font-size: .95rem; line-height: 1.7; color: var(–spp-muted); margin: 0; }

.spp-subscribe { padding: 10px 18px; border-top: 1px solid #3A3A3A; background: var(–spp-bg); }
.spp-subscribe #podcast-listen-on,
.spp-subscribe #podcast-listen-on p,
.spp-subscribe #podcast-listen-on strong,
.spp-subscribe #podcast-listen-on a { font-size: 1.2rem !important; margin: 0 !important; }

.spp-with-transcript .plyr { display: none !important; }
.spp-with-transcript .spp-audio { display: none !important; }

@media (max-width: 650px) {
.spp-progress-wrap { order: 0; width: auto; flex: 1; min-width: 0; padding: 0; border-bottom: none; margin: 0; }
.spp-progress-bar { height: 36px; }
.spp-controls { padding: 8px 12px 10px; gap: 8px; }
.spp-volume-wrap { display: none; }
.spp-speed-btn { display: none; }
.spp-controls-spacer { display: none; }
.spp-artwork { width: 70px; height: 70px; }
}
]]>

Host:

Graham Cluley:






Guest:

Dave Bittner:



Episode links:

SPONSORS:

  • ESET – 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.
  • Meter – Network infrastructure for the enterprise. Get a free personalised demo.
  • Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!

Support the show:

You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.

Join Smashing Security PLUS for ad-free episodes and our early-release feed!

Follow us:

Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.

Thanks:

Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.












About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.