Episode notes
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong? Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping up on American street corners, and took a very close look inside. All this and more in episode 486 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Dave Bittner. EPISODE LINKS: Claude Opus…
Transcript
Read the transcript · about 6,670 words, follows along as you listen
Dave Bittner:I have to say, what this reminds me of is there was a glitch on Amazon for a while. I don't know if it's still there, where if you went to buy condoms, it would ask you, would you like to buy this item used?
Graham Cluley:Dave, always lovely to have you back on the show. Star of The Cyber Wire, Hacking Humans, that other one I've forgotten the name of.
Dave Bittner:Caveat.
Graham Cluley:Caveat, thank you. Smashing Security.
Dave Bittner:It's all good, Graham.
Graham Cluley:Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner. The good news is, Dave, actually, is I'm going to be recommending that all of our listeners go and check out your podcasts, particularly next week, because there isn't Hello, hello, and welcome to Smashing Security, episode 486. going to be an episode of Smashing Security next week. I am grabbing a map, a compass, and a rucksack full of cheese sandwiches, and I am going to My name's Graham Cluley.
Graham Cluley:be venturing into the wilds of Britain because I'm moving house. I'm going to a different part of the UK.
Dave Bittner:Just put a Y cable in I'm talking about a bunch of researchers who are asking the there. What could go wrong? question, what the flock?
Graham Cluley:And I'm gonna be going online to buy a laser-equipped kiwi. All this and much more coming up on this episode of Smashing Security. This episode of Smashing Security is sponsored by Vanta. It's 2:00 AM. Somewhere, a security team is drowning. The spreadsheets. There are so many spreadsheets. Vendor risk assessments unread. Audit evidence scattered like ash in the wind.
Dave Bittner:And I'm Dave Bittner.
Graham Cluley:I've filled out the same questionnaire 4 times this week, Graham. 4 times! Some men choose to face this alone, but not tonight.
Joe:Okay, Graham, this is a bit much.
Graham Cluley:Yeah, fair point. Anyway, Vanta—
Joe:Thank God.
Graham Cluley:Vanta's a trust management platform that automates the mind-numbing stuff that makes you want to poke your eyes out with a fork. No more manual evidence chasing, no more questionnaire hell. It continuously monitors your systems and keeps you audit ready for SOC 2, ISO 27001, HIPAA, GDPR, the works. And it uses AI. Yes, Joe, it does.
Joe:To flag risks and streamline evidence collection so your whole security program stays in shape, not just the week before an audit.
Graham Cluley:No more 2:00 AM dread. No more spreadsheet purgatory. Just peace.
Joe:And $1,000 off if you demo it right now.
Graham Cluley:$1,000?
Joe:vanta.com/smashing. Go now before it's too late.
Graham Cluley:That's vanta.com/smashing.
Joe:And thanks to Vanta for supporting the show.
Graham Cluley:Now, chums, there are important questions to be asked of this week's guest, Mr. Dave Bittner. I won't beat around the bush, Dave. How do you feel about crusty socks?
Dave Bittner:How do I feel about crusty socks?
Graham Cluley:Yes, how do you feel about them?
Dave Bittner:I try to avoid them whenever possible. Wow.
Graham Cluley:You're not growing any in Chez Bittner right now? I imagine they are pretty fresh and clean, those beautiful feet of yours these days. I'm asking because this week, somewhere in Auckland, New Zealand, there is a convenience store that briefly was selling a pair of crusty socks on its website. And that wasn't all they were selling. They were also selling a rather divine Princess Diana commemorative plate.
Unknown:Oh no.
Graham Cluley:And if you were quick, you could also have bought all of New Zealand's national parks. Now, this wasn't some marketing stunt. This wasn't a flea market with any old bric-a-brac and odds and sods and national parks and the like. Instead, this particular store had made a bit of an error when it built its website. It had used something called Base44, and Base44 is a vibe coding platform owned by Wix, one of those places where they sort of roll your own website.
Graham Cluley:They were being sold to the highest bidder as well. You can go to it and out the other end of the mixer will come a brand new website. Dave, have you ever vibe coded at all? It's very popular these days.
Dave Bittner:The closest I have come to vibe coding was I asked ChatGPT to create a version of Pong in BASIC for the TRS-80 Color Computer.
Graham Cluley:And did it work?
Dave Bittner:Yeah. I mean, it was slow, but it worked.
Graham Cluley:I rather approve of that. What do you think of the idea of vibe coding generally?
Dave Bittner:I think at this point it's unavoidable. I think it's out of the box and there's no putting it back in there. But the people I know who are professional developers, many of them say that their job has shifted from actually being a developer to being a supervisor of the AI that's actually doing the coding. I suppose as long as there's oversight, then it's okay, but I think everybody's a little nervous about this.
Graham Cluley:And I won't have a chance to put out an episode next week. I think if you've spent years and years studying how to code and now you've been replaced by a glorified speak-and-spell machine, you are going to be pretty upset about this. I have vibe coded myself sometimes. You know how Liam Neeson in that movie says he has a very particular set of skills? What I will be doing is I'll be really busy contacting the CEO of Openreach and asking why it's so
Dave Bittner:Yes. Yes.
Graham Cluley:Well, I have a very particular set of requirements on my computer sometimes. You just, oh, if only my computer would do this in this particular way. And in the past, I would spend hours looking for a utility which did that particular thing. And I do find myself now sometimes thinking, hmm, rather than spending four months coding this myself, maybe I could ask an AI to help me. And bloomin' heck, I mean, they can do it. I wouldn't necessarily want to roll it out to the public. I wouldn't necessarily want to give it to other people and let them find the vulnerabilities in it.
Graham Cluley:hard to get me a fibre internet connection to my house when there's a box just 5 feet away from me.
Dave Bittner:You're okay being your own guinea pig.
Graham Cluley:Yes. You know, think, okay, I could run this on my computer. But here's the problem. Somewhere in the process of vibe coding their own e-commerce site, these chaps who were running this store, they somehow left the entire thing open to be edited by anybody on the entire internet. Yeah, exactly. What could possibly go wrong? But never fear, folks.
Dave Bittner:Oh my.
Graham Cluley:If you can hold your breath until Thursday, the 8th of October, there'll be a new episode of Smashing Security then. And in the meantime, check out Caveat and Hacking Humans and The Cyber Wire and all the other — well, thank you. Well, before we kick off, let's thank this week's wonderful sponsors, ThreatLocker, Origin, and Vanta. No password required. We'll be hearing more about them later on in the podcast. This week on Smashing Security, we won't be talking about how researchers managed to take over the accounts of staff at OpenAI using Anthropic's Claude. You'll hear no discussion of how Dutch police have asked for the public's help after releasing a recording of what they believe to be the voice of a member of the Shiny Hunters hacking group.
Dave Bittner:Wow.
Graham Cluley:And we won't even mention how North Korea has been posing as recruiters to infect job seekers during fake coding tests and then waiting for them to get hired somewhere real. So Dave, what are you going to be talking about this week?
Dave Bittner:How do you miss that?
Graham Cluley:Yeah. Exactly. And you also think, well, how did Base44 ever allow that to be possible? So even if it wasn't a vulnerability in Base44, I suspect it was actually the setting up of the particular environment where there was an error. Why did they, considering this was something which was meant to be used by non-professionals, people who weren't versed in computer security and technology — maybe, you know, I need a website. I run a shop selling shoelaces. I know nothing about computers. Can you create me a website? Yes, I'll go and do that. How can they leave it open like that?
Dave Bittner:It seems like a top-tier requirement of building something like this.
Graham Cluley:You would think so.
Dave Bittner:Don't let the general public make changes.
Graham Cluley:And of course, inevitably, random members of the public did discover that they could just go to the website and make any changes they wanted. They could add their own listings to the live site.
Dave Bittner:And they did not disappoint.
Graham Cluley:Of course, the internet never disappoints when given an opportunity like that. So you too could buy a pair of crusty old socks, or you could purchase a single banana for $850, or a mouldy school lunch. You too could find yourself paying off New Zealand's Deputy Prime Minister for $3,000.
Dave Bittner:Graham!
Graham Cluley:All kinds of things. There was even this Princess Diana commemorative dinner plate for $1.50. Now, I've shared with you—
Dave Bittner:Yes.
Graham Cluley:An image, Dave, of this plate. I think it's Princess Diana.
Dave Bittner:Graham, never before has the beauty of the dear departed princess been on better display than it is on this, this clearly handmade and painted plate. I would be honoured and proud to display this anywhere in my home, and I hope our listeners will take the time to check it out. It's just gorgeous.
Graham Cluley:It's a beautiful thing. And there it is alongside the Laser Kiwi, which obviously is something every person in New Zealand needs. Dave, if you had the opportunity to list something on a site like this, what sort of thing do you imagine you would want to list? What wonders would you put up on this online emporium?
Dave Bittner:Oh my goodness, I don't know. But I have to say what this reminds me of is — there was a glitch on Amazon for a while. I don't know if it's still there, where if you went to buy—
Graham Cluley:Was this the buy route?
Dave Bittner:No, no, no. But when I was a No, no. If you went to buy condoms, teenager, I think I had issues with crusty it would ask you, would you like to Tickles me. socks, but it's been a while. buy this item used?
Graham Cluley:Some people would.
Dave Bittner:Tickles me to this day. So yeah, it's not just a small little convenience store that these sort of things can happen to. Happens to the largest commerce platform in the world, right?
Graham Cluley:So at some point, the actual store owner tweaked what was going on and he tried to fight back, but he didn't know how to secure the site. So instead what he did was he started posting other items for sale with titles like, please stop hacking us. And within minutes, someone else added a new listing saying, well, don't use an AI site builder then, which seems like fair enough security advice coming for free from the general public.
Dave Bittner:Mm-hmm.
Graham Cluley:Now, this, as I said, may not have been explicitly the fault of Base44. Maybe the security settings hadn't been set properly. But, you know, it's not as though this were the first time that Base44 has made the headlines. Last year, security researchers at Wiz found an authentication bypass vulnerability in the platform. That allowed unauthorised access to private apps built by its users. What that meant was if you could see the URL, which of course you could in your browser, of a particular app, you would then be able to create a verified account to access it as the owner yourself. So the supposedly secret app ID was there for anybody to see in the URL. So security, not necessarily their strong point. Wow.
Dave Bittner:How is Base44 still in business, one has to ask?
Graham Cluley:And how much did Wix pay in order to acquire Base44? I hope they think this was money well spent. Or maybe they bought them and then got rid of all the security engineers. I don't know.
Dave Bittner:Yeah. Wow.
Graham Cluley:So Dave, there's going to be a lot of small businesses wanting their websites to be built or refreshed. It's like, oh, we can't really carry on with this Dreamweaver site we created in 1999 anymore, we're going to have to do a bit of a You know what? revamp of that. And so you've got to think a lot of people will turn to simple tools that promise a lot, but that the users don't really understand. There are probably people who
Dave Bittner:No.
Graham Cluley:And that's going to be a problem.
Dave Bittner:Just crowdsource everything on your website, right? Open it up to the entire internet. What could go wrong?
Graham Cluley:pay more for that. Because these tools, they're explicitly marketed at people who have no idea, not a clue what an access control setting is. And the AI might happily build you a gorgeous looking website, but it won't necessarily tell you if you've left all the doors and windows wide open. So I raise a glass right now to the people of New Zealand who, with good humour, have— I mean, technically, I suppose what they did was maybe that was against the law.
Graham Cluley:I don't know whether it was or not.
Dave Bittner:Hmm.
Graham Cluley:If it's been left open like that. But it appears not to have been done for malicious reasons, but everyone had a good old laugh about it, which is good fun.
Dave Bittner:I suppose the flip side is that this convenience store operator is seeing more traffic to their website than probably ever before.
Graham Cluley:It's interesting, isn't it? Because sometimes there can be marketing stunts like this to get you some traffic. I tried going to this particular website — right now it's down. You get a Cloudflare error. I don't know if it's because too many people have gone there or they thought, we don't know how to stop this, we're just going to yank out some cables — they've turned it off. But there have been cases in the past where companies — I can think of one dating site for beautiful people, for instance, where they intentionally pretended that they had been hacked in order to get lots of press coverage.
Graham Cluley:A very unusual story. I'll link to it in the show notes if anyone's interested in that. This episode of Smashing Security is supported by Origin. Joe, did you see that big story about AI agents running around inside OpenAI and Hugging Face's own environment?
Joe:The ones dividing up work between themselves and reviewing each other's output?
Graham Cluley:That's the one. One of the things that really struck me was how the people who actually built those AI models had a hard time reconstructing exactly what the agents had done and said to each other.
Joe:Right, and that's really the point. Even the experts closest to the technology struggled to answer a simple question: what did our AI actually do?
Graham Cluley:Which is exactly the question this week's sponsor, Origin, wants you thinking about. If an AI agent caused an incident at your company tomorrow, what evidence could you actually produce?
Joe:For most teams, the honest answer is not much. You've got the prompt and you've got the final result, but everything in between — the commands it ran, the files it changed, the credentials it picked up along the way — that's usually gone the moment the terminal closes.
Graham Cluley:And that's the gap our sponsor, Origin, was built to close. Origin is an endpoint AI observability company. A sensor on the machine records the agent's work as it happens. Who started the session, what was asked, what the agent reached, and what it changed, all on one timeline.
Joe:So if something unexpected happens, you're not piecing it together from scattered logs. You open the trace and read the session in order from the original prompt through to the outcome.
Graham Cluley:It works wherever agents actually operate too. Coding agents in a terminal, local agents, anything calling an MCP server on a laptop. None of that needs to pass through a cloud gateway for Origin to see it.
Joe:So if you want to see what a trace actually looks like, head to originhq.com/smashing.
Graham Cluley:That's originhq.com/smashing. And thanks to Origin for sponsoring the podcast.
Dave Bittner:Well, Graham, do you have Flock Safety cameras over on your side of the pond yet?
Graham Cluley:Flock surveillance cameras? Yes, we do. Britain is supposed to be the country with more CCTV cameras than practically anywhere else. I think we've only got more than North Korea. But these Flock ones, they're making lots of headlines over in the States, aren't they? They seem to be quite invasive.
Dave Bittner:They are. And we're doing our best to catch up with you all. These Flock Safety cameras are popping up like dandelions all over the place. In fact, there are open-source projects to track their locations. People have put together Google Maps where you can look at your community and see where the Flock Safety cameras are around you.
Graham Cluley:Right.
Dave Bittner:There are several around where I live, and they're easy to spot. They have a particular look to them, and I find it disturbing as they're popping up all over the place. These are licence plate reading cameras. So the idea is you drive by with your car, it takes a picture of your car, it logs your licence plate, it logs the type of car, what direction you were going, the time of day, all that sort of thing. And of course, you get enough of these little bits of data, and you can put together a picture of where someone's going and when they're going and what they may be up to. So hackers have gotten their hands on one of these cameras.
Dave Bittner:And by getting their hands on one, I think they backed a truck into it and ran off with it. I think that's sort of the subtext of what's going on here. But there are hundreds of thousands of them all over our great nation, so I don't think they'll miss the one. But they got a good look inside the cameras, and from a security point of view, it's not good. There's a hacker collective called Stegonogram.
Unknown:Okay.
Dave Bittner:Of course, there's a jaunty zero in the middle of the word Stegonogram instead of an O, because hackers.
Graham Cluley:Yes.
Dave Bittner:So they got their hands on this Flock camera. They took it apart, and they extracted its storage. And the group Distributed Denial of Secrets has published images of those file systems, which has enabled lots of researchers to take a look under the hood at what exactly is going on here. So security researcher Mika Lee, who you've interviewed before, haven't you, Graham?
Graham Cluley:I mean, have you?
Dave Bittner:Mika's been a guest on Smashing.
Graham Cluley:I don't think — no, Mika hasn't been on Smashing Security, but I certainly know their work.
Dave Bittner:Yeah. So well-known researcher, well-respected.
Unknown:Yeah.
Dave Bittner:He took a look and published a blog post about this. He found that this camera was running a modified version of Android 8.1, which is an OS that was released in 2017 and no longer supported by Google. Its patching was dated to June of 2018, and its underlying Linux kernel was also, in his words, ancient. So in other words, this camera was watching modern traffic with software security that was from the 2010s. Lee identified several publicly known vulnerabilities that are applicable to components of the device. He saw flaws that could allow malicious software already running on the camera to gain deeper control.
Dave Bittner:But then, sort of the chef's kiss of all this, are the credentials.
Graham Cluley:Right.
Dave Bittner:He found an API key hardcoded into a software library that's shared by 19 Flock applications that run on the camera. So based on his analysis, that key is used during the process by which the cameras obtain their credentials for accessing Flock's backend infrastructure. So the—
Graham Cluley:Is it possible the person who created these cameras then got a job at Base44 creating a website building tool?
Dave Bittner:Yes, yes.
Graham Cluley:Right.
Dave Bittner:Because they had excellent credentials. And the people looked at their past work and said, well, this looks good to us. Yeah.
Graham Cluley:Good enough.
Dave Bittner:The device also stored authentication credentials in plaintext—
Graham Cluley:Of course.
Dave Bittner:On an unencrypted partition. Now I will say, as you and I are recording this, this API key has been making the rounds on social media. It is everywhere. If you want to look for it, people are just posting and reposting, having the time of their lives posting this hardcoded key for Flock. Not going to Obviously it's illegal to use this key to do what you want with Flock's API server, but do we know what you could do with this? recognise it as
Graham Cluley:Is it a case of taking data off the cameras or maybe putting data on the cameras?
Dave Bittner:being human. No. It seems as though this key is how the camera authenticates itself with Flock's mothership, if you will. So it says, this is who I am, this is where I am, which is another thing. The camera sends its GPS coordinates to identify where it is. And so with this information, you could basically authenticate yourself on Flock's API on their home base servers and pretend to be one of the remote cameras.
Graham Cluley:We could pretend to be
Dave Bittner:We could, we could.
Graham Cluley:And muddy their database.
Dave Bittner:Imagine the fun we could have. We could post pictures of that Princess Di plate. Just—
Graham Cluley:a Flock camera if we I don't think facial recognition is going to work on that plate.
Dave Bittner:No, no.
Graham Cluley:I don't think you'd even— Even if they had wanted to, maybe. No. a modern Flock camera rather than one built in
Dave Bittner:So the logs recovered from the camera contained GPS coordinates. This particular camera seemed to have come from somewhere in Wisconsin, and researchers were able to use Google Street View to find the particular camera, I suppose, when it was still there.
Graham Cluley:2017, 2018, I don't think it was— Yes.
Dave Bittner:Flock, of course, in response to the stories that have been written about this in places like 404 Media and Wired, they have said, and I quote, they take security seriously and they maintain a vulnerabilities disclosure programme. Yeah.
Graham Cluley:Is it possible that their statement was also written in 2017 or 2018? They had that in their back pocket because—
Dave Bittner:It's possible.
Graham Cluley:I think we've heard that one before a few times, haven't we?
Dave Bittner:So related to all of this, I think it's worth mentioning that there is a huge amount of pushback against these Flock cameras here in the States right now. There are municipalities who have had contracts with them and are cancelling the contracts.
Unknown:Yeah.
Dave Bittner:There is a story from a police organisation in Illinois where the former police chief and two of the other high-level police people in this police force were using the town's Flock licence plate cameras to monitor the police chief's ex-wife. He had instructed other officers to track her, allegedly. The state police confirmed there's an active investigation into the matter. Again, obviously all alleged, but these three police officers resigned from the force when this information came out. So again, there's a lot of pushback. People feel as though this has gone a little too far, that our locations are being tracked.
Dave Bittner:That the information is accessible without a warrant by police officers. So I think the folks who make the Flock cameras have been set back on their heels a little bit at the amount of pushback there is. And now to add on to that, these reports of how insecure and easy to hack both their cameras are and their central servers.
Graham Cluley:It's what we like to call an omni-shambles, isn't it? I like that. I like that.
Dave Bittner:I'm going to steal that, Graham. Omni-shambles. I like that. That has a nice ring to it.
Graham Cluley:Yeah. These are devices which, sometimes it is argued, they are being introduced into society in order to protect us, to make us feel more secure. But in fact, they're either being abused or they are themselves insecure in their very nature in the first place.
Dave Bittner:And to be fair, law enforcement will say this is a powerful tool for them to be able to solve crimes. And there's no question that that's true. It's just a matter of how much are we all willing to give up in order to do that? And that's the unresolved question so far, but it's moving rapidly.
Graham Cluley:This episode of Smashing Security is brought to you by ThreatLocker.
Joe:Agentic AI is changing the speed of cyberattacks, Graham.
Graham Cluley:Yes, I read about that too. Self-directing ransomware, AI worms that adapt as they go, agents chaining tools together with no human anywhere near the controls.
Joe:So basically, the attackers have automated their way to a 4-day workweek and the rest of us haven't.
Graham Cluley:When enumeration, exploitation, and lateral movement happen at machine speed, plans like, oh, we'll catch it when someone checks their alerts, they begin to fall apart.
Joe:Like most incident response plans, then. Great in the slide deck, less great at 3 AM.
Graham Cluley:ThreatLocker puts default deny and least privilege between the agent and its next move. Application allowlisting decides what's allowed to run at all. Ringfencing limits what trusted applications can reach or launch, and privileged access management takes away elevation the agent never needed in the first place.
Joe:So speed's not the problem anymore. Getting through the door is.
Graham Cluley:So get ahead of machine speed attacks with ThreatLocker. Head to threatlocker.com/smashing to find out more and book your free demo.
Joe:That's threatlocker.com/smashing. Thanks to ThreatLocker for supporting the show and for doing the fast bit so we don't have to.
Graham Cluley:And welcome back. Can you join us at our favourite part of the show? The part of the show that we like to call Pick of the Week. Pick of the Week.
Dave Bittner:Pick of the Week.
Graham Cluley:Pick of the Week is the part of the show where everyone chooses something they like. It could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish. It doesn't have to be security-related necessarily. Better not be. Now, Dave, I wonder if, like me, you are a fan of the movie La La Land.
Dave Bittner:Uh, I—
Graham Cluley:Oh, hang on. There was a pause.
Dave Bittner:I have watched La La Land twice, I believe.
Unknown:Oh.
Dave Bittner:I enjoyed watching La La Land. I will say I did not go gaga for La La the way many other people did. And this is surprising for me because I love a musical.
Graham Cluley:Yes. Love a musical.
Dave Bittner:For whatever reason, it just didn't resonate with me the way it did with other people, but that's okay. That's just me. I have no doubt this is a wonderful movie, and clearly people love it, so good on them.
Graham Cluley:I think you're a bit more of a Seven Brides for Seven Brothers kind of thigh-slapping style musical fan, right?
Dave Bittner:That's true. Yes. Give me The Music Man or Singin' in the Rain, and I'm happy as a clam. Okay. All right.
Graham Cluley:Well, I love La La Land. If you haven't seen it, of course, it was the movie which had the Best Picture Oscar cruelly ripped from its paws back in 2017. If you haven't seen it, unlike Dave, who I'm beginning to question his judgement, I think you should go and watch it. Tell me if you like it, and if you didn't like it, unsubscribe from Smashing Security immediately. Go on, clear off, clear off the lot of you. Well, no, no, no, no, no, no, no, no, no, no, come.
Graham Cluley:Come back. Didn't mean it.
Dave Bittner:Oh my! I think what am I not going to be invited back anymore?
Graham Cluley:Labours of love. Dave, don't leave just yet. You've got a few more minutes to go. All right. Anyway, if any of you are still listening, I love La La Land. I could watch it on a loop, and my pick of the week this week is a website that is La La Land related. So I've stumbled across a website called seeing-stars.com, and it's done something brilliant. They have tracked down literally every single filming location used in the movie. So there's a real spot in Boulder City, Nevada, where Ryan Gosling goes to pick up Emma Stone when he visits her in her hometown. There's a pier where he sings City of Stars to an old married couple and dances with the wife.
Graham Cluley:There's the famous observatory. I think it's in Rebel Without a Cause as well, or some James Dean movie.
Unknown:Yeah.
Graham Cluley:Where they have their dreamy planetarium dance scene. There's even tiny little throwaway moments, which may just be on the screen for a second, like a parking lot that Emma Stone walks through for an audition. So this isn't a brief list. This is every single location throughout the movie. This La La Land lunatic has watched the movie with his pause button. He's worked out where everything was taken.
Dave Bittner:Right.
Graham Cluley:It's extraordinary. And he's posted alongside the screencaps, real photos, map links, Street View. He's given a narrative as well. There are so many pages of this, and I found myself trawling through this and I thought, you know what? This is the kind of obsessiveness I want to see on the internet. This is like the old days. There used to be lots of bonkers sites like this.
Dave Bittner:Yes. Yes, I agree.
Graham Cluley:And I don't think anyone's got enough time really these days. It doesn't feel like anyone's actually putting the effort into building something. This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake. But also, after watching it, you might want to go and check out this website. The other thing is, if La La Land isn't your thing, the same guy has documented all of the locations used in the Dexter TV series. You must know that one.
Graham Cluley:That's that family show about what a police blood spatter expert gets up to in his free time.
Dave Bittner:Lovely little lighthearted jaunt. Yes.
Graham Cluley:Yes, exactly. So La La Land on one side, Dexter on the other. You can take your pick and go and check out the locations.
Dave Bittner:I love this kind of thing. Yeah, this is great fun.
Graham Cluley:That is my pick of the week. Dave, what's your pick of the week?
Dave Bittner:Well, Graham, how do I say this?
Graham Cluley:Goodbye. That's right.
Dave Bittner:I grew up in a household that did not have a lot of musical sophistication. Let's put it that way. My parents, who were children of the '50s, not the '60s, which meant they were more Frank Sinatra than the Beatles.
Unknown:Okay.
Dave Bittner:Yeah. When I was a young lad, my father would be down in his workshop doing little projects, and I would be down in the basement playing with my Matchbox cars or my Legos.
Graham Cluley:Can I just check? He wasn't a blood splatter expert working for the police, was he?
Dave Bittner:He was not. No, no, no, no, no. Okay.
Graham Cluley:Just clearing that up.
Dave Bittner:No, no, no. On the 8-track tape player —
Unknown:Ooh-hoo!
Dave Bittner:Yeah. I can still hear the clunk-clunk sound when it would switch tracks. On the 8-track tape player, he would often have an 8-track of the Ray Conniff Singers.
Graham Cluley:Right.
Dave Bittner:Now, Graham, I don't know if you are lucky enough to know who the Ray Conniff Singers are.
Graham Cluley:I'm not.
Dave Bittner:I put a link in here just for you of them doing their rendition —
Graham Cluley:Hey Jude, don't make it bad. Okay, that's horrible. Yes, it is.
Dave Bittner:Yes, it is. So for those who aren't familiar, the Ray Conniff Singers was just a group of vocalists, and they would take popular songs of the day, and they would get together as a choir, and they would sing the songs with an orchestral accompaniment. And it was just completely benign, right?
Graham Cluley:It was awful. It was, it was.
Dave Bittner:But this was the soundtrack of my childhood, right?
Graham Cluley:Oh, bless.
Dave Bittner:So I heard this kind of thing over and over again. So this was my introduction to a lot of popular songs, was the Ray Conniff Singers cover version of it.
Unknown:Oh.
Dave Bittner:Yeah. We didn't have any Yeah. So I say that as introduction to why I have great affection for a documentary that I came across recently. It's called Let's Have a Party: The Piano Genius of Mrs. Mills. Beatles albums growing up. Graham, are you familiar with Mrs. Mills?
Graham Cluley:I am familiar with Mrs. Mills, yes.
Dave Bittner:Not a one. She is from your neck of the woods.
Graham Cluley:Yeah, she was a British lady who could sort of stomp things out on the old piano, on the old Joanna.
Dave Bittner:That's right. That's right.
Graham Cluley:She was very talented. She wasn't your typical sort of celebrity starlet. She wasn't what I would call glamorous.
Dave Bittner:No, no, no.
Graham Cluley:She was one of us.
Dave Bittner:She was a mom, yeah.
Graham Cluley:Yes.
Dave Bittner:But she could play. She had her own distinct style.
Unknown:Yeah.
Dave Bittner:I would categorize it as being kind of sing-along music, right?
Graham Cluley:Yes.
Dave Bittner:This comes from the era before recorded music, when everyone could play piano, and the way people would entertain themselves at a party or in a pub was that someone would sit down and play a few tunes, and everyone would have a few drinks and sing along.
Graham Cluley:Which sounds bloody marvellous to me. And I think that's exactly the way I think about her as well. It's the kind of roll-out-the-barrel music you can imagine in the corner of the pub.
Dave Bittner:Exactly.
Graham Cluley:Stomping out a song, people holding their glasses of beer, enjoying the evening, singing along.
Dave Bittner:Exactly. And so, for me, discovering Mrs. Mills has been opening up an entire new category of musical comfort food.
Graham Cluley:Right.
Dave Bittner:Because of the hardwiring of the awful Ray Conniff Singers in my brain when I was a child, Mrs. Mills just slots right in there and I love it to death.
Graham Cluley:And she didn't sing, did she? Unlike the Ray Conniff Singers who shouldn't have sung.
Dave Bittner:She did not sing, but there were singers on her albums and sometimes on her albums it would be the entire bar who would be singing along.
Graham Cluley:Right. The algorithm has learned about you, Dave.
Dave Bittner:There's no getting rid of me. So I've left a link to Let's Have a Party: The Piano Genius of Mrs. Mills, which is a BBC documentary. But Graham, there's a particular thing in here that made me realise that this was the perfect thing to have as my pick of the week just for you, because Mrs. Mills' piano is at Abbey Road Studios. To this day, her piano is there, and her piano was used by the Beatles.
Graham Cluley:It was. And Dave, hold on to your seat. I have actually seen Mrs. Mills's piano.
Dave Bittner:Get out!
Graham Cluley:I really have, because I was very lucky a few years ago to actually go into Abbey Road and into Studio 2, which is the famous studio where the Beatles recorded a lot of their songs, the one with the stairs going down the side.
Unknown:Yeah.
Dave Bittner:So I made the mistake of tracking down
Graham Cluley:And that piano is still there. They didn't let us play it.
Dave Bittner:some of her things in my iTunes app,
Unknown:Okay.
Dave Bittner:which means now she's in the rotation.
Graham Cluley:But yeah, so many amazing songs. I think maybe With a Little Help from My Friends and Ob-La-Di, Ob-La-Da with that digga digga ding ding ding at the beginning — that's all on the Mrs. Mills piano.
Dave Bittner:Yes. So I've included a link here from Abbey Road that has a picture of, I think, Paul and John seated at Mrs. Mills' piano. The legend goes on beyond Mrs. Mills herself.
Graham Cluley:Her piano will live forever through the music of the Beatles, because she was signed by Parlophone. She was on the same record label as the Beatles.
Dave Bittner:This woman made a solid living playing piano. Her albums were hits just by going right down the centre. That is my pick of the week.
Graham Cluley:This is fantastic. I'm definitely going to check out that documentary. I love that. Well, that just about wraps up the show for this week. Thank you so much, Dave, for joining us. Maybe you can tell our listeners where they can follow you online and find out what you're up to. What's the best way for them to do that?
Dave Bittner:Just go to our website, thecyberwire.com, and you'll find all of my shows there.
Graham Cluley:Terrific stuff. And of course, you can find me, Graham Cluley, on LinkedIn, Bluesky, Mastodon, Instagram, and even the Tok of Tik. The list goes on. And you can also follow Smashing Security on Bluesky, Mastodon, and Reddit. Don't forget to ensure you never miss another episode. Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts. And you can look for our show notes, sponsorship info, guest list, and the entire back catalogue of 486 episodes at smashingsecurity.com. Until a couple of weeks, not next week, the week after. Cheerio. Bye-bye.
Graham Cluley:You've been listening to Smashing Security with me, Graham Cluley, and a huge thank you to Dave Bittner for joining me this week and this week's sponsors ThreatLocker, Origin, and Vanta. Do make sure to go and check out their offerings because they help keep the show afloat. Now, chums, according to the limited stats I get to see as to our listenership, the vast majority of you appear to be male. However, we do have a marvellous cohort of female listeners too, and some of them have been kind enough to become members of Smashing Security Plus. So I thought, you know what? Let's give some of them a nice shout out today. So kicking us off are Jessica Orth, Lisa, and Sharon — three fine chums, not putting up with any nonsense. A big huzzah to Sharon, a name which resembles that satisfying crisp click that you might get when closing the lid of a brand new laptop. The legendary Maya MacDonald, the beautifully double-barrelled Adena Bogut O'Brien, and Jane with a Y, because why not? Big love as well to The Green Girl, our most colour-coordinated patron, and to the delightfully whimsical Butterfly Skies. Thank you. And finally for this week, Frankie Guzikowski. Frankly, Frankie can be a boy's name or a girl's name. I'm not sure which way our Frankie leans. But anyway, these fine, upstanding, generous individuals are all members of Smashing Security Plus, which means they get their episodes ad-free earlier than the general public, and perhaps most importantly, have the opportunity to have their names pulled out of the hat at the end of the show and read out for mild ridicule. Curated by myself. If you would like to join them in this exclusive club of the wonderful and slightly foolish, just head over to smashingsecurity.com/plus, where for a modest fee, you too can support the podcast. You can support us in other ways as well. You can write a review; those are always lovely. You can like, you can subscribe, and you can tell your friends about us. Go on, go and find a chum. Collar them and say, you know what? You really should listen to Smashing Security. Well, thanks to all of you who support the show, and I'll be back for another episode on October the 8th. So make sure to tune in then. Until then, cheerio. Bye-bye.
Unknown:Bye-bye.
Transcript supplied by the publisher with the episode.
Smashing Security
by Graham Cluley · English · Tech & Science
Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all…
More from Smashing Security
-
E485 · 1 hr 3 min
These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured…
-
E484 · 46 min
How websites are tracking you with silence
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated." All…
-
E483 · 44 min
This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just…
-
E482 · 50 min
This hacker leaked GTA 6 - and launched their own cryptocurrency
A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of "residential proxies" - how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet…
-
E481 · 46 min
Never say this to a robot dog
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts - and some parallels for the world of…
-
E480 · 46 min
This is the AI service you should never sign up to
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off with full access to your emails, your files, and your entire organisation. All this and more in…
-
E479 · 1 hr
How a fake police officer nearly stole Graham's cryptocurrency
Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education - sending an…
-
E478 · 59 min
This job interview could destroy your company
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly…
-
E477 · 51 min
How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball. EPISODE LINKS: Bengaluru triple murder: Accused allegedly used…
-
E476 · 38 min
Remote-control rickshaws and rogue book marketers
An app has appeared in India that lets anyone with a smartphone stop a passing e-rickshaw dead in its tracks - no login, no passwords, no permissions needed. Meanwhile, Geoff - swimming in money and Lamborghinis, as all published authors are - has been on the receiving end of a slew of AI-generated scam pitches from fake book marketing experts. Rather than ignore them, he's been playing them at their own game... All this and more in episode 476 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White. EPISODE LINKS: The…
