Firewalls Don't Stop Dragons

@FirewallDragons
1.5K Followers
119 Following
1.4K Posts
Author and podcast host of "Firewalls Don't Stop Dragons". Electrical engineer by degree, software engineer by profession (retired). Privacy advocate, educator and speaker. Also on Bluesky.
Bloghttps://firewallsdontstopdragons.com/
Podcasthttps://podcast.firewallsdontstopdragons.com/
Bookhttps://firewallsdontstopdragons.com/buy-the-book/
Newsletterhttps://firewallsdontstopdragons.com/newsletter/

Tune in Monday when I'll be speaking with Jodi Daniels and Jan Rosenberg about surveillance on the job - how employers keeps tabs on employees.

Subscribe here:
https://firewallsdontstopdragons.com/podcast/

Podcast - Firewalls Don't Stop Dragons

I have a weekly podcast called Firewalls Don't Stop Dragons. The show is a mix of cybersecurity news and interviews of prominent people in the industry. But like the book, the shows are targeted squarely at everyday, non-technical people - covering the info that everyone needs to know in a way that's accessible and practical.

Firewalls Don't Stop Dragons

I don't blame the human here. This should not have been technically *possible*. We have to fix how we create and manage machine secrets.

https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/

CISA Admin Leaked AWS GovCloud Keys on Github – Krebs on Security

I assumed they had some level of access to this info already... so this would just be formalizing it... streamlining the process of violating the 4th Amendment...

https://www.404media.co/the-fbi-wants-to-buy-nationwide-access-to-license-plate-readers/

The FBI Wants to Buy Nationwide Access to License Plate Readers

Only a couple vendors could likely fulfill what the FBI is after, namely Flock and Motorola.

404 Media

Today we'll backup your old emails. Also: Venmo finally defaults to private; Meta workers fight back; ChatGPT ad tracking; new Canada surveillance bill; Utah targets VPNs; LLMs want your health info; Edge password fail; Chrome 4GB LLM; Canvas hack; more!

https://podcast.firewallsdontstopdragons.com/2026/05/18/download-all-your-emails/

This is going to end badly. Don't do it. Even if you have an option to set up read-only access, this is very personal information that you cannot trust to a cloud AI. (Same for health records, but more so.)

https://www.macrumors.com/2026/05/15/chatgpt-personal-finance/

ChatGPT Can Now Connect to Your Financial Accounts for Budgeting Advice

OpenAI is adding a new personal finance feature to ChatGPT, letting people connect their financial accounts to the chatbot to get budgeting advice. ...

MacRumors
Woohoo!! Just got my (signed) copy of Privacy's Defender from Cindy!! I'll treasure it! (If you missed that interview, definitely check it out.) @eff

This can't be legal. It's sure as hell not ethical. This is neither 'informed' nor 'consent'.

https://www.404media.co/mayo-clinic-is-using-ai-to-listen-to-emergency-room-visits/

Mayo Clinic is Using AI to Listen to Emergency Room Visits

Mayo Clinic's "Ambient Listening" has been around for a couple of years, but clearly not all patients know their interactions with nurses are being passively recorded and processed by AI.

404 Media
Want a preview? Cindy joined @FirewallDragons to discuss the key parts of her biggest cases, how we interpret our rights in the digital realm, and what we can do to ensure a free and open internet. https://podcast.firewallsdontstopdragons.com/2026/05/11/cindy-cohn-privacys-defender/

Today I have a delightful chat with the one-and-only Cindy Cohn, director of the @eff and longtime privacy warrior. We discuss her illustrious career, fighting on the front lines for our digital rights and a free and open internet.

https://podcast.firewallsdontstopdragons.com/2026/05/11/cindy-cohn-privacys-defender/

GAAAHH... I need some global signal that says "I don't need a business loan"!! I get so many emails, despite my best efforts at creating keyword filters...

Every damn one is the same automated 3-email formula:

1) hey, check this out
2) in case you missed it
3) one last try