Shared Security Podcast
Shared Security Podcast
  • 550
  • 119 340
Gravy Analytics Breach & Subaru Starlink Vulnerability - Major Data Privacy Concerns!
In this episode, we discuss the recent breach involving Gravy Analytics, where 30 million location data points were leaked online, posing significant privacy concerns. We also cover a vulnerability in Subaru's Starlink system, uncovered by researcher Sam Curry, which allowed unrestricted access to vehicle controls and customer data using just a last name and license plate number. Co-host Kevin Johnson joins the conversation to share insights on these topics, addressing the lack of privacy regulations, and the implications of such security flaws. Stay tuned for an in-depth discussion on data privacy and cybersecurity in the modern world!
00:00 Introduction: Another Data Broker Breach
00:41 Subaru Starlink Vulnerability Exposed
01:12 Welcoming back Kevin Johnson
02:05 Discussing Gravy Analytics Breach
03:39 The Need for Privacy Regulation
06:07 Real-Time Bidding on Personal Data
07:10 Hacking Subaru: The Details
10:09 The Importance of Testing Admin Interfaces
15:20 Conclusion: Reflections and Sign-Off
Show notes and links mentioned during the episode:
sharedsecurity.net/2025/01/27/gravy-analytics-breach-subaru-starlink-vulnerability-exposed/
____________________________________________
Shared Security is your premier cybersecurity and privacy podcast where we explore the bonds shared between people and technology. Stay informed and take control of your online security and privacy in today's interconnected world. Hit that subscribe button for more great content each week!
ua-cam.com/users/SharedSecurityPodcast
🙏 Support and follow the podcast 🙏
Patreon: patreon.com/sharedsecurity
Web: [sharedsecurity.net](sharedsecurity.net/)
Bluesky: bsky.app/profile/sharedsecurity.bsky.social
LinkedIn: www.linkedin.com/company/shared-security-podcast/
Mastodon: infosec.exchange/@sharedsecurity
Reddit: www.reddit.com/r/SharedSecurityShow/
Subscribe on your favorite podcast app: sharedsecurity.net/subscribe
Newsletter: shared-security.beehiiv.com/subscribe
Podcast Merch: [store.sharedsecurity.net](store.sharedsecurity.net/)
🎁 Get 10% off your order of high quality faraday products built to protect your privacy from SLNT!
Visit: [slnt.com](slnt.com/) and use discount code "sharedsecurity" at checkout.
#podcast #cybersecurity #sharedsecuritypodcast #sharedsecurity #technology #privacy #cyberthreats #gravyanalyticsbreach #subarustarlinkvulnerability #databroker #locationdataleak #30milliondatapoints #dataregulation #vulnerabilityexploitation #realtimebidding #personaldataauction #smartcarssecurity #vehiclehacking #subaruvehiclecontrols #privacylegislation #subaru #gravyanalytics
Переглядів: 4

Відео

Meta Ditches Fact-Checking for Community Notes: Is This the Right Move?
Переглядів 7016 годин тому
In this episode, we explore Meta's recent decision to replace traditional fact-checking with community notes and its potential impact on misinformation. We also discuss the implications of a TikTok ban in the U.S., with users migrating to similar apps like RedNote. The conversation covers the challenges of maintaining reliable information in social media and the shifting landscape of news consu...
AI Privacy Policies: ChatGPT, Gemini, and Claude Compared - What You Need to Know!
Переглядів 19614 днів тому
Do you ever read the privacy policy of your favorite AI tools like ChatGPT, Gemini, or Claude? In this episode, Scott Wright and Tom discuss the critical aspects of these policies, comparing how each AI engine handles your personal data. They explore the implications of data usage, security, and privacy in AI, with insights from industry giants like Anthropic's CEO, Dario Amodai. Are these AI t...
Y2K Anniversary: Lessons for Future Tech and AI Safety
Переглядів 3821 день тому
Join us as we reminisce about Y2K, the panic, the preparations, and the lessons learned 25 years later. We also discuss the implications for future technology like AI and potential cybersecurity crises. Plus, in our 'Aware Much' segment, Scott shares tips on protecting your data if your phone is stolen. Happy New Year and welcome to our first episode of 2025! 00:00 Introduction and Y2K Reminisc...
Reflecting on Our 2024 Predictions: What We Got Right and Wrong | Shared Security Podcast
Переглядів 4328 днів тому
In the final episode of the Shared Security Podcast for 2024, join us as we recap our predictions for the year, discuss what we got right and wrong, and highlight our top episodes on UA-cam. We also extend a heartfelt thank you to our Patreon supporters and special guests. Plus, stay tuned for our predictions for 2025 and some fun discussions on AI's impact, phishing attacks, and more. Happy Ne...
Digital License Plate Vulnerabilities and How to Avoid New Text Message Scams
Переглядів 401Місяць тому
In this episode, the hosts discuss the vulnerabilities of digital license plates and the potential for hackers to exploit them. They explain what digital license plates are and how they work. The 'Aware Much?' segment covers the topic of suspicious text messages and why you should avoid responding to unknown senders. The team also shares personal project frustrations and emphasizes the importan...
Encryption: The Government’s Double Standard
Переглядів 58Місяць тому
In Episode 359, the team examines a shocking hack-for-hire operation alleged to target over 500 climate activists and journalists, potentially involving corporate sponsorship by ExxonMobil. They explore the intricate layers of this multifaceted campaign and the broader implications on security risk assessments. Additionally, Scott discusses the massive Salt Typhoon hacking campaign attributed t...
Tanya Janca on Secure Coding, AI in Security, and Her New Book!
Переглядів 110Місяць тому
Join us for an insightful episode of the Shared Security Podcast as Tanya Janca returns for her fifth appearance. Discover the latest on her new book about secure coding, exciting updates in Application Security, and the use of AI in security. Learn how her new book goes deeper into secure coding practices, backed by her practical experiences and detailed research, aimed at empowering developer...
Australia Bans Social Media for Kids: Controversial Move Explained
Переглядів 483Місяць тому
Australia Bans Social Media for Kids: Controversial Move Explained
Digital Privateers: How Deepfakes and Data Brokers Threaten Privacy
Переглядів 622 місяці тому
Digital Privateers: How Deepfakes and Data Brokers Threaten Privacy
Is It Time to Delete Your Twitter Account? Here's What You Need to Know
Переглядів 7322 місяці тому
Is It Time to Delete Your Twitter Account? Here's What You Need to Know
The Advanced Persistent Teenager: New Cybersecurity Threat?
Переглядів 1172 місяці тому
The Advanced Persistent Teenager: New Cybersecurity Threat?
Massive Change Healthcare Data Breach: Ransomware Fallout & Mortgage Wire Fraud Prevention
Переглядів 4622 місяці тому
Massive Change Healthcare Data Breach: Ransomware Fallout & Mortgage Wire Fraud Prevention
AI Toilet Cameras & Major Internet Archive Breach - When Innovation Meets Privacy Risks
Переглядів 2,5 тис.2 місяці тому
AI Toilet Cameras & Major Internet Archive Breach - When Innovation Meets Privacy Risks
Hacked Robot Vacuums Shouting Slurs & Secret Printer Tracking Dots!
Переглядів 6143 місяці тому
Hacked Robot Vacuums Shouting Slurs & Secret Printer Tracking Dots!
Celebrating 350 Episodes: Podcast Milestones and Emergency Preparedness
Переглядів 843 місяці тому
Celebrating 350 Episodes: Podcast Milestones and Emergency Preparedness
Hacking Kia: Shocking Web Portal Vulnerability Discovered! Plus, NIST Password Updates!
Переглядів 1933 місяці тому
Hacking Kia: Shocking Web Portal Vulnerability Discovered! Plus, NIST Password Updates!
Discord's End-to-End Encryption: What You Need to Know!
Переглядів 2943 місяці тому
Discord's End-to-End Encryption: What You Need to Know!
Why You Don't Need to Worry About Your Phone Exploding: Debunking The Exploding Pager Incident
Переглядів 2034 місяці тому
Why You Don't Need to Worry About Your Phone Exploding: Debunking The Exploding Pager Incident
AI-Driven Voicemail Scams & Political Donation Data Mining
Переглядів 1204 місяці тому
AI-Driven Voicemail Scams & Political Donation Data Mining
Shocking SQL Injection in TSA App & Bitcoin ATM Scams Targeting Seniors
Переглядів 5834 місяці тому
Shocking SQL Injection in TSA App & Bitcoin ATM Scams Targeting Seniors
Telegram's Encryption Controversy Explained | Must Watch!
Переглядів 2814 місяці тому
Telegram's Encryption Controversy Explained | Must Watch!
Is Google a Monopoly? Breaking Down the Latest Accusations
Переглядів 435 місяців тому
Is Google a Monopoly? Breaking Down the Latest Accusations
🤔Are People-Search Removal Tools Effective?
Переглядів 1285 місяців тому
🤔Are People-Search Removal Tools Effective?
Exclusive Insights on Cybersecurity: Black Hat & DEF CON Highlights with Shourya Pratap Singh
Переглядів 1185 місяців тому
Exclusive Insights on Cybersecurity: Black Hat & DEF CON Highlights with Shourya Pratap Singh
The Great CrowdStrike Crash: Discussing the Largest IT Outage in History
Переглядів 905 місяців тому
The Great CrowdStrike Crash: Discussing the Largest IT Outage in History
Revolutionizing Cyber Defense: An In-Depth Look at SquareX with Jeswin Mathai
Переглядів 825 місяців тому
Revolutionizing Cyber Defense: An In-Depth Look at SquareX with Jeswin Mathai
Cybersecurity Trends 2024: AI, Deepfakes & More | Dan DeCloss from PlexTrac
Переглядів 995 місяців тому
Cybersecurity Trends 2024: AI, Deepfakes & More | Dan DeCloss from PlexTrac
AT&T Data Breach Hits 110 Million Customers: What You Need to Know
Переглядів 2626 місяців тому
AT&T Data Breach Hits 110 Million Customers: What You Need to Know
Authy Breach Impact & RockYou 2024 Password Leak
Переглядів 5076 місяців тому
Authy Breach Impact & RockYou 2024 Password Leak

КОМЕНТАРІ

  • @jimcabezola3051
    @jimcabezola3051 2 години тому

    I wonder when these data vampires will mandate that my silly mountain bike needs to be connected to their networks. It's gotten to where I don't even drag a mobile phone with me on my bike anymore. Sure...all the spy cameras on the roads can see me, but they can't call me...can they? 🤣 Aloha and take care.

  • @oldspammer
    @oldspammer 5 днів тому

    Reference videos 1. The New York Times And Wikipedia EXPOSED Like Never Before 2. Wikipedia Exposed Unmasking the Biased Disinformation Machine - UA-cam 3. EXPOSED: Wikipedia’s Bias Tested and PROVEN! - UA-cam

  • @helenwalker2986
    @helenwalker2986 5 днів тому

    Its like when Diana said .. "There were... 3 people within the relationship.." No one needs that shit... its like having a stalker and it encourages busy bodies and third party interloper presumption of being welcome.... People learn that everyones elses busiess is their business... and this impacts social enagement... gossip... reporting your neighbour... prettiness... its a deathly thing to encourage... Its all the same... Have it as an option for people but its just all very imposing.

  • @jimcabezola3051
    @jimcabezola3051 7 днів тому

    I don't use TikTok, but I would be very put out if UA-cam were banned. Banning this... Banning that... Is this digital book burning?

  • @truthiz102
    @truthiz102 9 днів тому

    degoogle your life. time to go back to linux and learn how to remain Anonymous

  • @brendanmcdowell4335
    @brendanmcdowell4335 13 днів тому

    I worry that AI from Canada will do a reverse-takeover of the United States. Or maybe I should be hoping for it. 😅

  • @jimcabezola3051
    @jimcabezola3051 14 днів тому

    Stay safe, stay secure, stay private...and despite all the rubbish and guff from Yankee media...stay Canadian! You folks MAKE my Sunday nights! Aloha!

  • @lynnmaholias2879
    @lynnmaholias2879 14 днів тому

    My face ID is not recognized. I can not re-set face ID because Stolen Protection is on. I can not disable because it requires face ID. Apple tech support could not help me. What do I do ? Will not let me get into any of my accounts or apps that require a password because I need a Face ID and mine will not work. How is it possible for somebody to change my Face ID? It works for only two sites and it stopped working for no reason whatsoever all of a sudden

  • @alyssiaalexandria3553
    @alyssiaalexandria3553 21 день тому

    YES there are other platforms to hang out on if one has t time to do this and to find community. Elon Musk stinks as a brand and a person and as a businessman. Stop supporting him infact do not support any Aholes in 2025 YOU are worth more than that:) Namaste - Good People find each other on or off social media be well!

  • @t1nk3r_n_r3v3rs
    @t1nk3r_n_r3v3rs 23 дні тому

    This is the third video I have watched on application encryption and I hear about pushing the button and the other person needing to be online to ensure it is secure. However, has anyone actually looked a the wire to verify encryption? I feel we just trust if it has an encrypt button it's encrypted. I don't understand why either outside of, at times, being lazy. Thank u for this video. God bless.

  • @pagetvido1850
    @pagetvido1850 27 днів тому

    I presume the Microsoft programmers realized button bloated software does not play well with LLM's. This screenshot based vector base is the only plan Microsoft has got. I don't see it beating the ancient python + llm combo.

  • @LatashaSharp-j8o
    @LatashaSharp-j8o 27 днів тому

    😂😂

  • @jimcabezola3051
    @jimcabezola3051 27 днів тому

    Happy New Year!

  • @johnnycaps1
    @johnnycaps1 Місяць тому

    Perhaps the leader of N. Korea wasn't all that crazy when he had all his poop collected when and wherever he traveled (by trusted employees, of course).

  • @johnnycaps1
    @johnnycaps1 Місяць тому

    Too funny! Subscribed - not for any kind of "security" since that's IMPOSSIBLE but for the humor which is grate!

  • @Godneverfails-s3d
    @Godneverfails-s3d Місяць тому

    يا صديقي @Fleeptool، أنت بطل العصر الحديث. أنا سعيد جدًا برجال إنفاذ القانون على متن الطائرة;

  • @ClinttheGreat
    @ClinttheGreat Місяць тому

    Great info. Subbed.

  • @g3r1-hp18
    @g3r1-hp18 Місяць тому

    10 min explanation for 1 f tag.

    • @acmhfmggru
      @acmhfmggru Місяць тому

      Yeah, this was insufferable. A bunch of old boring men with zero communication skills decided to make a podcast. What a joke!

  • @jimcabezola3051
    @jimcabezola3051 Місяць тому

    I predict I'll enjoy your prediction show next week. Mele Kalikimaka, folks!

  • @GTSongwriter
    @GTSongwriter Місяць тому

    There's going to be so many work arounds after this.. LoL. Social Media will change it's name and meaning to re-open doors.

  • @seancollins9745
    @seancollins9745 Місяць тому

    I think social media should be off limit for minors like alcohol and drugs etc 18 minimum, tired of having to cater to fucking children on the internet

  • @gslim7337
    @gslim7337 Місяць тому

    Our major party politicians are clueless. They acknowledged that they hadn't decided how verification would take place. In the end, it means everyone has to provide user ID every time they sign onto social media. Just to add to the farce, Facebook is banned for 16 y.o. but Pornhub is not.

  • @anthonyroberts7641
    @anthonyroberts7641 Місяць тому

    I despise our Nanny State, uniparty! The absolute arrogance they have is sickening. Last day, last bill before their 9.5 week break.

  • @stevemartin4249
    @stevemartin4249 Місяць тому

    New subscriber from Japan (an American expat here for 42 years). That Australian law analysis was to the point and scary. Some brush it off by comparing it to a minimum drinking or driving age. But a better analogy I've seen is banning all kids from swimming in the ocean or pool because it is dangerous. My greatest fear is that it is one of many potential back doors to eventually requiring digital proof of identity. Cold Fusion's recent podcast, "Australia's Social Media Ban" is especially good. Regarding my passion for fishing ... oh, 'phishing'? Darnn it. Although Japan now has a relatively clean image as a cheap, safe, exotic destination for tourists, for residents, Japanese or foreign, it is a different story. There is a slow but steady push to incentivize and then require a single digital identity number with China's police state as the model, and as the economy for the working class further erodes, there is a palpable uptick in all crime, including burglaries and violence, but especially a variant of phishing called "ore-ore sagei' ... originally, a telephone call from a fake relative to a well off retiree saying they need money for an emergency. But between the dire economic situation and clever use of A.I. these scams have become sophisticated enough so that for a few years now, the evening news always includes a brief segment warning the residents of how the latest scams work with an example for the day. Daily. Lots of other big news in the Far East, Korea under martial law, the coming clamp down on live streaming thanks to the Johnny Somali case, etc. But there are only so many minutes in a day, and life is growing shorter. Enjoyed the banter. Cheers from Japan

    • @ShtNotworking
      @ShtNotworking Місяць тому

      social media is like alcohol... not everyone use it, and these before 16 shouldn't use it

    • @SharedSecurityPodcast
      @SharedSecurityPodcast Місяць тому

      Thank you for the insightful comment!

  • @InvisiblePinkSoylent
    @InvisiblePinkSoylent Місяць тому

    Are your 16yo kids allowed to drink alcohol? My kids would be fine. We've discussed it. It's a matter of trust.

    • @JoseMartinez-ll7vo
      @JoseMartinez-ll7vo Місяць тому

      Hahahaha!! You’re kids are the last ones that should be trusted!! You’re an idiot!! The biggest one here. You had to say it so it must not be true!!

  • @davidgrim5990
    @davidgrim5990 Місяць тому

    The point wasn't to ban it for kids it was to make it remove anonymity for adults to craxkvdown on "undesirable" speech.

  • @chuckken3438
    @chuckken3438 Місяць тому

    GOOD FOR THEM!...ITS GREAT

  • @TT3TT3
    @TT3TT3 Місяць тому

    He's been doxxing government employees- I've heard . He's such a disappointment.

  • @JohnLopez-j5j
    @JohnLopez-j5j Місяць тому

    X is dead. Its full of haters, porn stars, white supremacist and Musk propaganda. Bsky is the new FREEDOM OF SPEECH app.

  • @jimcabezola3051
    @jimcabezola3051 2 місяці тому

    Yes! All hail the Great Pirate...Kevin! I LIKE the idea of letters of mark for data destroyers! Arrr, matey, sign me up!

  • @soonheaven
    @soonheaven 2 місяці тому

    Dr. Shiva sued and beat Eelon. His suit exposed the gov'ts 'backdoor portal' to Twitter. Shiva is on social media but arguably the most censored guy on the internet. The people can't let billionaires continue to censor and ruin their lives. Shiva says alot that the govt disagrees with. Shiva is the voice of the people. Support him and join the push for him to be president of the US.

  • @drieman
    @drieman 2 місяці тому

    I dumped you

  • @hebozhe
    @hebozhe 2 місяці тому

    Gab is the best option. Mastodon and Bluesky are for grown men who upspeak half of their sentences and dye their hair... oh, never mind.

  • @Jim_the_Hermit
    @Jim_the_Hermit 2 місяці тому

    I don't know why everybody didn't leave twitter after the first guy got fired for a tweet.

  • @Rich32262
    @Rich32262 2 місяці тому

    You had me until I heard Trump propaganda which I thought might end up being part of this. Yeah there sure isn't any propaganda on the left on MSNBC CNN ABC CBS and on and on. The BS that Facebook pulled in the 2020 election the Twitter files exposed by Matt taibbi, the FBI suppressing the hunter Biden laptop I could spend a half a day with all the crap the left is done. See ya dude, yeah this isn't political.

  • @roblotomy
    @roblotomy 2 місяці тому

    Sounds like a Facebook move. Why would anyone switch to threads

  • @Jon-to6969
    @Jon-to6969 2 місяці тому

    Move over to Bluesky 🤣🤣🤣 nothing like having an echo chamber of group think.

    • @brianh9358
      @brianh9358 2 місяці тому

      Social Media is for social interaction. It turned into a political cesspit over time. Why should I spend my day dealing with trolls - I already get enough of that on UA-cam.

    • @mcdiesel7505
      @mcdiesel7505 2 місяці тому

      😂😂 You mean like X and truth social! Can't trust Elon, guys a scumbag!

    • @JohnLopez-j5j
      @JohnLopez-j5j Місяць тому

      MAGAs are jealous and need liberals to exist. Bsky doesn't control the algorithms like Musk does. Its called FREEDOM OF SPEECH!!!!!

  • @ThatYoutubeBro
    @ThatYoutubeBro 2 місяці тому

    You want a tissue for those tears 😂 Who else is happy this clown won’t be on x lol

    • @mcdiesel7505
      @mcdiesel7505 2 місяці тому

      😂😂X is for clowns! Blue sky will probably buy X in a few years for 100 million! Lmao

  • @notlessgrossman163
    @notlessgrossman163 2 місяці тому

    X has algorithms that limit views to posts while boosting views on others based on arbitrary opaque parameters., so in effect, X sensors messages

  • @jimc9516
    @jimc9516 2 місяці тому

    whatever platform you move to will add those same policies in the near future

    • @brianh9358
      @brianh9358 2 місяці тому

      Well one thing is for sure, it won't have Elon using the platform as his personal bullhorn.

    • @monsirto
      @monsirto 13 днів тому

      LOL, even Facebook is better managed. So many deleting on the 20th.

  • @soap5393
    @soap5393 2 місяці тому

    I dumped FB instead - before joining X, for reason it is much in more for free speech, without FB| censorship. .

    • @mcdiesel7505
      @mcdiesel7505 2 місяці тому

      😂😂😂😂 Free speech my ass! Only if you say right wing ignorant shit! Twitter becoming another Truth Social, complete bullshit platform! Blue sky baby!!

    • @JohnLopez-j5j
      @JohnLopez-j5j Місяць тому

      well, you got duped big time. LOL!

    • @soap5393
      @soap5393 Місяць тому

      @@JohnLopez-j5j No, X has a 50-50 split of libs and conservatives. FB is 72% woke Marxist deep state, and 28% simpletons who tolerate forever being censored via FB jail and "fact checking."

    • @mcdiesel7505
      @mcdiesel7505 Місяць тому

      @@soap5393 😂😂😂😂😂 X the opposite of free speech! Companies can do what they want! X is not free speech tho!

    • @soap5393
      @soap5393 Місяць тому

      @@mcdiesel7505 Among X users half report being lib / half conservative. You won't find anything close to that ratio any other format. It happened after Musk bought it and cleaned out the government monitoring / censoring agents.

  • @brendanmcdowell4335
    @brendanmcdowell4335 2 місяці тому

    I am a lemming… I’m following Tom’s advice. By Elon.

  • @ac0pt
    @ac0pt 2 місяці тому

    lol

  • @laurabramblett5337
    @laurabramblett5337 2 місяці тому

    I have just dumped Google.

    • @DarrenSaw
      @DarrenSaw 2 місяці тому

      How did you reply on UA-cam? Lol

  • @y.gorman6572
    @y.gorman6572 2 місяці тому

    Thank you

  • @adamisherwood6708
    @adamisherwood6708 2 місяці тому

    Yep my next move from win10 will be to freebsd desktop !!!!

  • @katiedid1851
    @katiedid1851 2 місяці тому

    And AI will fuck us forever.

  • @v2kguy
    @v2kguy 2 місяці тому

    I downloaded it on my server. I had to split the file in thousands of little files. It's mostly machine generated passwords. I use it with metaexploit. I got it on a remote drive. My own little remote 10 billion password database.

  • @tjmarx
    @tjmarx 2 місяці тому

    There was a joke about a decade ago about Google bringing out a toilet just like this... In clown world it seems all past jokes are the future.

  • @bruceg1845
    @bruceg1845 2 місяці тому

    reminds me of "The Light of other days" sci fi...