MARIA VARMAZIS
Oh my God. Oh my God.
CAROLE THERIAULT
Oh, for you it's uncomfortable? For you?
MARIA VARMAZIS
Y'all are fighting. I don't like it.
Unknown
Smashing Security, episode 365. Hacking hotels, Google's AI goof, and cyber flashing with Carole Theriault and Graham Cluley.
Hello, hello, and welcome to Smashing Security episode 365. My name's Graham Cluley.
CAROLE THERIAULT
Wow, the same number as the number of days in a year. And I'm Carole Theriault.
GRAHAM CLULEY
Not this year, Carole, it's a leap year. Oh. Hate to nitpick this early on in the show. And as you can hear, we are joined this week by Maria Varmazis from the T-Minus podcast.
Hello, Maria.
MARIA VARMAZIS
Pedantry from the get-go. I'm in awe. That was just amazing. Oh my gosh.
CAROLE THERIAULT
It's 366 this year, is that right?
GRAHAM CLULEY
It is 366 this year.
CAROLE THERIAULT
Well, I'll do the same joke next week. How are you, Maria?
MARIA VARMAZIS
I'm very excellent today. How are you doing? Brilliant.
CAROLE THERIAULT
Okay, I think we're all in a great mood already. So let's just kick the show off, shall we? But first, let's thank this week's wonderful sponsors, Kalyde, KiteWorks, and Vanta.
It's their support that help us give you this show for free. Now, coming up on today's show, Graham, what do you got?
GRAHAM CLULEY
I'm going to be checking into poor security.
CAROLE THERIAULT
Okay, sounds interesting. And what about you, Maria?
MARIA VARMAZIS
The enshittification of search continues.
CAROLE THERIAULT
Oh, brilliant. I do love that word. And I'm going to be talking to cyber flashers and saying beware. All this and much more coming up on this episode of Smashing Security.
GRAHAM CLULEY
Now, chums, chums, I was lucky enough last week to visit Germany. I went to the city of Magdeburg where I was hosting a little awards ceremony, introducing the Blues Brothers.
I don't know if they were the originals, giving a speech. So I showed up, right, the night before I showed up at my hotel and it was "Guten Tag, Graham Cluley. Here's your room.
Let's take you up to the 7th floor." Thank you very much. Here we are.
CAROLE THERIAULT
I can tell we're going to go down a, you're going to complain about something. So before you do, my husband was at this event and he said you were excellent on stage.
And if anyone, any listeners are out there thinking, "God, we need some talent for our stage performance, for our gig, for our corporate gig," Graham's the man.
And I'm doing this for free. Graham didn't even ask me.
GRAHAM CLULEY
But I, I think we can finish the podcast right there. I think the important things have been said. Thank you very much, Carole. Sorry, Maria, that you showed up.
MARIA VARMAZIS
No, no, I'm wiping away a tear. That was just so gorgeous. My goodness.
CAROLE THERIAULT
Well, it's true.
GRAHAM CLULEY
Very— that's very kind of you, Carole, and of your hubby.
CAROLE THERIAULT
Well, you're very welcome. Anyway, so I was taking a crack on this.
GRAHAM CLULEY
So I was taken up to the 7th floor. Your husband, by the way, was checked into the 5th floor. He checked in the same time as me. Gave him the 5th floor. I was given the 7th floor.
So I get up to my room.
CAROLE THERIAULT
He's a very important man, you know.
GRAHAM CLULEY
Well, I, I actually said the 7th floor was where the VIP club was. So I thought, as I was a bit of a minor celebrity arriving in Magdeburg, I'm hosting the awards ceremony.
I thought, okay, they've given me the best floor. Fair enough, I'm J.Lo. I'm P. Diddy. I thought, this is—
MARIA VARMAZIS
Are you sure you wanna be P. Diddy?
CAROLE THERIAULT
Do you really wanna be him?
GRAHAM CLULEY
Oh, actually, yeah.
CAROLE THERIAULT
You wanna back that up? Back it up, back it up.
MARIA VARMAZIS
Don't be like P. Diddy.
CAROLE THERIAULT
Don't be like P. Diddy.
MARIA VARMAZIS
Wow, what a name to drop today.
CAROLE THERIAULT
Choices.
GRAHAM CLULEY
There I was. I got to my hotel room and I thought, oh, I've got this work to do. Because Carole, you've just been kind to me. I'm gonna be kind to you because—
GRAHAM CLULEY
Yep, because last week, I was travelling and you said, Graham, let me edit the podcast. You said, I will do all of it.
MARIA VARMAZIS
Didn't you?
GRAHAM CLULEY
Which is very kind of you. Very excellent job, as everyone can hear, last episode. All I had to do was publish it and add a few show notes and things.
Just a little bit of wrapping around the corners. And so I thought, I have to get on the internet. Got up to my room, couldn't get on the internet. Not unusual.
You get to a hotel and you can't get on the internet. I thought, never mind.
CAROLE THERIAULT
Annoying though. Completely annoying.
GRAHAM CLULEY
It's annoying.
CAROLE THERIAULT
Especially a business hotel, because you kind of depend upon that stuff. But yeah.
GRAHAM CLULEY
You kind of do. You kind of do.
MARIA VARMAZIS
You kind of do.
GRAHAM CLULEY
But never mind, because the welcome drinks are happening at a local cinema.
And in fact, your husband and I, we walked through Magdeburg to get to the local cinema where the welcome drinks were. Lovely evening and everything.
And I thought, when I get back later, I'll get back on the internet and I'll do the work with that.
CAROLE THERIAULT
A little bit swishy.
GRAHAM CLULEY
You're on. Yeah, a little sway. I'll sway my way back to the 7th floor. So after the drinks, very nice, thank you very much.
Got back to the hotel, need to do some work, publish the podcast, blah, blah, blah, get ready for my speech first thing in the morning, right?
Maybe actually look at my slides, something like that. Oh dear, still no internet. So I traipse down to reception and I say, internet problem? I'm finding it a bit difficult.
I'm sure it's me. I'm thinking, I'm sure it's me. And they go, oh, oh, they say, are you on floor 7? Yes, I am. Oh, the internet doesn't work there.
CAROLE THERIAULT
It's a quiet floor for VIPs, so no one knows what they're doing.
MARIA VARMAZIS
It's for people who are allergic to radio signals, Graham. Radio-sensitive folks.
GRAHAM CLULEY
Perhaps, perhaps. And so I say, well, maybe you can move me to a room where there is internet. Oh no, we can't. There aren't any other rooms available.
You can hang out in the piano bar if you like.
Well, I didn't want to hang out with the piano bar for the 2.5 hours or whatever I need to do and the work I had to do and listen to podcasts and do all things like that.
So I said, well, it might be nice if you told me when I arrived, you checked me into the 7th floor, that there wasn't any internet. If you'd told me that—
CAROLE THERIAULT
So you didn't ask? 'Cause I do ask about internet every time.
GRAHAM CLULEY
Oh, it said there was free internet. It said the room came with free internet.
MARIA VARMAZIS
Doesn't mean it's gonna work. I mean, listen, they said it's free. That's all they said.
GRAHAM CLULEY
So I had the hump. I had the hump. And I thought, well, I need the internet because I've got this presentation. I've got this very important podcast to publish. What am I going to do?
So I said to him, "Tell you what," I said, "I'm going to check out. You'll give me the money back." And there was a bit of a hassle about that. Anyway, that eventually got resolved.
And then I will check into another hotel. I'll find another hotel. I will use your internet and the piano bar to find another hotel. Okay?
So I checked out of the hotel, and then I went to look for another hotel room. Unfortunately, no hotel rooms.
CAROLE THERIAULT
Yeah, it's not the biggest place in the world, is it?
GRAHAM CLULEY
Well, Carole, I always thought that about Magdeburg.
CAROLE THERIAULT
Magdeburg is bloody — oh, maybe it doesn't have a lot of tourists.
MARIA VARMAZIS
What is Magdeburg known for?
CAROLE THERIAULT
Yeah, I asked that for my husband as well. He didn't know because they're all known for something in Germany.
GRAHAM CLULEY
It's famous for its Gothic-style cathedral, the burial place of Otto the Great, the Holy Roman Emperor. I'm just coming at this randomly. It's got about 250,000 residents.
Okay, that's a decent size.
MARIA VARMAZIS
That's a decent size.
CAROLE THERIAULT
Size of Oxford, yeah.
GRAHAM CLULEY
Yeah, how many people are there in Oxford?
CAROLE THERIAULT
I don't know, but I would say about that with students. I seem to think it was 300,000 when, you know, student full capacity, which is —
GRAHAM CLULEY
2017, Oxford was 152,000. So I would say —
CAROLE THERIAULT
Without students, you know.
GRAHAM CLULEY
Well, you know, do students really exist anywhere? Yes, I mean, it's just —
CAROLE THERIAULT
They do. I live here, they do.
MARIA VARMAZIS
They're everywhere. You certainly feel them when they're there.
GRAHAM CLULEY
Right, I've just looked it up, okay. In 2021, there were 162,000 residents of Oxford, and there were 34,945 students.
Okay, so I put it to you that there are more people in Magdeburg.
CAROLE THERIAULT
I'm not going to take back my compliment that I gave earlier.
GRAHAM CLULEY
Oh, okay. Oh yes, I forgot about that. Anyway, back to the story.
So I was searching for a hotel and my, I don't know if you know about my phone, my mobile phone doesn't, its battery isn't very good. It runs out.
CAROLE THERIAULT
Oh, what do you have? Do you have the SE?
GRAHAM CLULEY
Yes, I do. So my battery isn't very good, right? It's dying.
And I'm thinking, and I can't find a taxi because although there are plenty of cyclists in Magdeburg, there aren't very many taxis.
There are trams, but no trams were — and my hotel, I eventually found one hotel, but it's an hour and a quarter walk away in the rain from where I am at 11 o'clock at night, rolling along my little bag.
CAROLE THERIAULT
Why didn't you ask my dear Yeti to use his room?
GRAHAM CLULEY
Your Yeti was still at the cinema at this point. He's not contactable. I don't know what he's doing. Anyway, I don't want to bore you with the whole story.
CAROLE THERIAULT
Oh, really?
MARIA VARMAZIS
Do you really need to?
GRAHAM CLULEY
It was okay.
CAROLE THERIAULT
Because we're going step by step here.
MARIA VARMAZIS
What did you have for breakfast that day, Graham?
GRAHAM CLULEY
It was quite stressful.
GRAHAM CLULEY
It was quite stressful. And I thought, where on earth am I going to — you know, I'm very important. I'm hosting the awards. I thought I was a celebrity. I've nowhere for me to sleep.
Anyway, eventually everything was fine, but how I wished that I would have had a key to someone else's hotel room.
And this is the link to what I'm talking about today, because if I'd had the key to someone else's room where the internet had been working, I could have gone in there.
Or maybe I should have just sat outside someone else's door. Maybe your husband on the 5th floor. I should have sat outside his door until he came back from the bloody cinema.
You should ask him questions as to how late he was out.
MARIA VARMAZIS
I feel we need a corroborating interview with him to get his side of the story.
CAROLE THERIAULT
I think my husband said that you were great on stage and I'm not going to have any go at him whatsoever.
GRAHAM CLULEY
Oh, come on. Yeah.
CAROLE THERIAULT
Oh, okay.
GRAHAM CLULEY
Come on. What is wrong with you? So a bunch of security researchers have recently revealed a vulnerability that they found in hotel key locks.
GRAHAM CLULEY
They've called this UnSAFLOCK. Oh, memorable.
Well, I think the reason is that there is a make of key locks, RFID locks, which are used in hotels by a company called Dormakaba, and they call them Safe Lock or Saf Lock.
So this is Unsaf Lock.
CAROLE THERIAULT
Okay, that makes sense. Okay. Okay.
GRAHAM CLULEY
That's why they've called it that.
GRAHAM CLULEY
Smart. Now, what they found was they found a way to unlock all rooms in a hotel using a single pair of forged key cards.
And they've discovered that over 3 million hotel locks in 131 countries are affected.
CAROLE THERIAULT
Okay, so I know, I think I know the answer to this. I think it's going to be one of those crazy questions. So when you say, it just means you bring this master key.
It's a master key that lets you get into any hotel room.
GRAHAM CLULEY
No, no, no, no, no.
GRAHAM CLULEY
No, it's not a— that would be great if that were the case. And I think there was something a bit like that before, perhaps.
And maybe there are master keys inside hotels to sort of— because it's all computerised these days, isn't it? You can use the system to get in.
CAROLE THERIAULT
Yeah, say someone committed suicide or something. You need to get in there. There's going to be a master key.
MARIA VARMAZIS
Why is that?
GRAHAM CLULEY
Why? Bring the tone down, Kroll.
MARIA VARMAZIS
You jumped right to it. My God.
CAROLE THERIAULT
It's because he got me all annoyed about my husband being out too long.
GRAHAM CLULEY
I'm annoyed about him as well.
CAROLE THERIAULT
Oh my God.
MARIA VARMAZIS
Oh my God. I am. He's a very nice guy. Oh, for you?
CAROLE THERIAULT
It's uncomfortable for you?
MARIA VARMAZIS
Y'all are fighting. I don't like it.
GRAHAM CLULEY
So all you need to break into a hotel room, they discovered, was one key card from the hotel. Now, where'd you get a key card for a hotel room from?
MARIA VARMAZIS
Literally anywhere.
CAROLE THERIAULT
In the bin.
GRAHAM CLULEY
Yeah, you get it in the bin. You get it in that little drop-off box where people dump their cards when they check out.
MARIA VARMAZIS
On a table. Yeah.
GRAHAM CLULEY
Or you look through your old suit and you find it inside a pocket.
MARIA VARMAZIS
All the time.
GRAHAM CLULEY
All the time. It can be an expired key card. It can be one from your own room. It can be one taken from the express checkout box, and they can then forge other key cards from that.
And there's a little bit of jiggery-pokery. They haven't gone into all the details because, well, the reason is because the problem hasn't been fixed, Kroll.
So they found out about this problem in September 2022.
CAROLE THERIAULT
So they get the key card, an old key card. They then do some jiggery-pokery, the science.
GRAHAM CLULEY
They read the card and create a faked card.
CAROLE THERIAULT
To get into a specific room or any room?
GRAHAM CLULEY
No, once they've got this ability, they can go into any room in the house.
CAROLE THERIAULT
Right, so then they basically have a master key.
GRAHAM CLULEY
Well done, Carole.
CAROLE THERIAULT
Thank you.
MARIA VARMAZIS
Okay, that's a good summary. Good, good, good. Okay, now I understand what the heck's going on.
CAROLE THERIAULT
All right.
GRAHAM CLULEY
And you, by the way, you can also do this with a Flipper Zero, which is a favorite hacking gadget that loads of people are talking about at the moment, or you can use an NFC-capable Android phone as well.
MARIA VARMAZIS
Are they banned in Canada yet?
GRAHAM CLULEY
What, Android?
MARIA VARMAZIS
No, no, no, the Flipper Zero that Canada's trying to ban them.
GRAHAM CLULEY
Oh, are they trying to ban them? Yeah. Good luck with that.
GRAHAM CLULEY
Yeah. Great publicity for them, I suppose. Anyway, September 2022, these researchers, they found the problem. They thought, crikey, this is bad.
And they contacted Dormakaba, who make these safe locks, SAF locks. That's smart.
GRAHAM CLULEY
Smart, smart, smart.
GRAHAM CLULEY
And they had a meeting with Dormakaba the following month in October 2022.
CAROLE THERIAULT
Oh, they weren't ignored. Fantastic.
GRAHAM CLULEY
No. And over the following 18 months, they've had at least, they say, 13 meetings with Dormakaba to discuss the vulnerability.
MARIA VARMAZIS
Death by meetings. 13. 13.
GRAHAM CLULEY
At least. At least, they say.
CAROLE THERIAULT
Oh my God. Can you imagine the Zoom meetings? And there's probably 30 people on it.
MARIA VARMAZIS
Yeah. God.
GRAHAM CLULEY
In November 2023, the first hotels began to upgrade their locks to resolve the vulnerability. But as of today, so what is it, March 2024 now?
CAROLE THERIAULT
Yeah, that's correct.
GRAHAM CLULEY
They say that only around 36% of the impacted locks have been updated or replaced. Remember, there are millions around the world.
CAROLE THERIAULT
Right, so they got through a third so far, yeah. Yeah.
MARIA VARMAZIS
Imagine that's gonna be a process. Yeah.
GRAHAM CLULEY
So it, well, it is, isn't it? Because you have to do a software update or you have to replace the actual lock.
And they say all key cards have to be reissued, front desk software to be changed, card encoders need to be upgraded. All kinds of upgrades are required.
Some physical, some a bit of a handful.
CAROLE THERIAULT
You know what's really upsetting? You have to tell people if you've got a flaw on your website that has leaked data, for example. Right?
CAROLE THERIAULT
You've got to announce that. But hotels apparently who claim to provide security with a locked door.
CAROLE THERIAULT
It can be bypassed. They've known about it since when? 2022?
CAROLE THERIAULT
And this is the first instance I've heard of it. What about you? Because you actually read tech news.
GRAHAM CLULEY
It's the first that this particular vulnerability has been spoken about. There have been vulnerabilities with key cards in the past.
CAROLE THERIAULT
As you said. Yeah.
GRAHAM CLULEY
I think F-Secure did some research a few years ago. We may have even spoken about it on the podcast.
CAROLE THERIAULT
But the fact that they can stay quiet. I'm going to be staying in a hotel at some point. That's kind of annoying. Anyway.
GRAHAM CLULEY
And you don't know when you book into a hotel whether it has one of these locks. In fact, if you look at the lock, you can't tell—
CAROLE THERIAULT
That's great.
GRAHAM CLULEY
If it's been fiddled with or not.
MARIA VARMAZIS
What a nightmare for the hotels too. I bet they have to pay for all this, and I'm sure they don't have the money for it.
I can't imagine safe locks coming in going, "Here, have a bunch of free upgraded locks." Oh.
GRAHAM CLULEY
So, if you are staying in a hotel, lucky you, by the way, if you're staying in a hotel, particularly if it has Wi-Fi.
MARIA VARMAZIS
That works. That works.
GRAHAM CLULEY
One that works. It has Wi-Fi.
MARIA VARMAZIS
Doesn't work, but it exists. Yeah.
GRAHAM CLULEY
Only on the 7th floor does it not work. But I don't understand that. I don't understand that.
MARIA VARMAZIS
How is that even physically possible?
GRAHAM CLULEY
I don't— I don't know, Maria. I don't know.
MARIA VARMAZIS
Someone explain the physics of this one to me, 'cause I don't get it. Alright.
GRAHAM CLULEY
So if you're in a hotel room, how do you protect yourself? Well, of course you could have a deadlock, couldn't you? Yeah, right, because you get these other things.
Turns out these hacked keycards turn the deadlock. How? Right?
CAROLE THERIAULT
Wait, okay, I'm thinking old-school hotels with an actual deadlock.
MARIA VARMAZIS
Yeah, I was gonna say, usually there's a separate one that's completely just physical.
GRAHAM CLULEY
Yeah, if you've got something on a chain, then obviously it can't undo that, right? So if you've got a little chug-chug.
But in these modern locks, these RFID locks, the actual deadbolt, the thing which you go chug-chug, you turn, apparently that actually gets unlocked, which is probably for the reason which Carole told us about earlier, the scenario she painted of when the hotel staff really kind of need to get into the room.
MARIA VARMAZIS
Yeah, I was thinking if a bathtub is overflowing or a toilet won't stop flushing, not someone unaliving themselves. Thanks, girl.
CAROLE THERIAULT
I had guys come into our room because we were having a big party, and the way they got in was by offering champagne. But actually, they had no champagne.
They just had champagne glasses, and then they all came in and closed the whole party down. They tricked us.
MARIA VARMAZIS
Oh, that's a clever, clever trick.
CAROLE THERIAULT
Yeah, thank you, Vancouver.
GRAHAM CLULEY
So another good question is, has anyone actually exploited this yet?
CAROLE THERIAULT
Oh, it's not even in the wild.
MARIA VARMAZIS
You don't even know who knows.
GRAHAM CLULEY
No, no, no, it is in the wild. Millions of locks affected, but nobody knows if it's been exploited.
So anytime you've been accused of taking the slippers or the towels or there've been some unexpected minibar charges.
CAROLE THERIAULT
You know what? Come on.
GRAHAM CLULEY
Or someone's been watching adult movies on the TV you can justifiably say, well, it could have been someone who got in.
CAROLE THERIAULT
No, no, no. We need a few detectives on this, right? There's someone that has to monitor the camera, right, on the hallway.
And then you check the log in for when the keycard was in use and you go, oh yeah, that was Bob. There's Bob's wife. There's Bob's kids. Who's that guy?
GRAHAM CLULEY
Who's that guy wheeling off the contents of the minibar?
MARIA VARMAZIS
Who's that guy in the black hoodie looking all sketchy? He's a bit of a— stock photography of a hacker. He's doing something he shouldn't.
GRAHAM CLULEY
So one thing that these researchers say that you can do is you can look at the keycard. So if you've got a Mifare Classic keycard, apparently they are marked in that way.
Those are vulnerable, but a Mifare Ultralight C keycard—
MARIA VARMAZIS
What? Oh, I'm definitely gonna remember this.
CAROLE THERIAULT
How do I know?
GRAHAM CLULEY
'Cause it will say it. You should be looking at the keycard and be able to identify the make of keycard.
CAROLE THERIAULT
Okay, no, but you've said the same make, so they're both Mifare, but—
GRAHAM CLULEY
A different type. The Ultralight C card is the safe one, apparently, but the Mifare Classic, no good.
CAROLE THERIAULT
No good. Classic is not good. Right.
GRAHAM CLULEY
There you go. There you go. So I hope that's useful to everyone.
CAROLE THERIAULT
Thank you very much.
GRAHAM CLULEY
We'll put some links in the show notes where you can read more about this research, but not too much.
'Cause they haven't released too much because they are terrified people will exploit it.
MARIA VARMAZIS
I mean, it could— this could get very serious and very dark very quickly. I mean, I'm sure everyone's heard stories of people following you back to your hotel room.
You're a celebrity, Graham. I'm sure you've experienced fans who just stalk you in the elevator and then in the hallway trying to be like, "Is that Graham?
Hmm, let's see what room he's in." I'm sure it's happened many times, right?
GRAHAM CLULEY
It's happened. And that sometimes is why I want to go to a floor where there's no internet so they can't— They can't livestream what happens next. Oh no, I didn't mean that. Oh no.
Moving on. Maria, what have you got for us this week? Oh my God.
MARIA VARMAZIS
I need a second. That's so dark.
GRAHAM CLULEY
I don't know what you're thinking.
MARIA VARMAZIS
I went a little American Psycho in my head. I was like, that's where my brain went.
GRAHAM CLULEY
What is going on with you two tonight?
MARIA VARMAZIS
Anyway. Okay. Whew.
MARIA VARMAZIS
Collecting myself. All right. So I teased this at the top of the show about the enshittification of search. It's truly enshittification all the way down.
I'm sure I can go out on a limb here and say we've all noticed that search has gotten really crap lately, has it not?
CAROLE THERIAULT
How do you mean?
MARIA VARMAZIS
When you search for something, I don't know, on Google, which is the one that a lot of us use, do you have an easy time of finding what the hell you're trying to find?
CAROLE THERIAULT
Or are you finding yourself having to comb through reams of garbage?
I find that I always will go down to about the 10th entry and start looking there because there's so many sponsored ads. I think I use Startpage.
GRAHAM CLULEY
That's what I use.
MARIA VARMAZIS
Wasn't that a pick of the week forever ago?
GRAHAM CLULEY
Yeah, yeah, yeah. Startpage was. But the thing I find is if I use Google quite often, it will be links to Reddit. There'll be lots and lots of links to Reddit before anything else.
Reddit must be getting a hell of a lot of traffic.
MARIA VARMAZIS
Yeah, well, that's because a lot of people— that is the remedy to the enshittification of search. That's hilarious.
Because if you can't find what you're looking for, usually people— I do this now too. I enter the term I'm looking for and then add Reddit to the end.
And now Google's indexing that. That's hilarious. Oh my God.
GRAHAM CLULEY
It's all you, Maria.
MARIA VARMAZIS
Oh, no, no, no, no, no, not me. I mean, everybody's doing this, obviously. That's so funny. Okay, so I'm looking for a review on this product.
And if you just Google that, everything you find is suspect. It's all fake blogs, fake AI-generated, all nonsense.
So one of the only places you think, and I don't even know if this is even true, but one of the few places that seems to have the whiff of reality is Reddit, because in theory it's real people commenting.
If that's actually true, who knows.
CAROLE THERIAULT
Anyway, yeah, there's no bots there, don't worry.
MARIA VARMAZIS
Yeah, there's definitely no bots on Reddit and nothing, no shenanigans going on there. So Google has decided to improve search because it knows that people are complaining.
So I don't know if you've heard of this thing that's very popular right now. It's called artificial intelligence.
CAROLE THERIAULT
No, tell me about it.
MARIA VARMAZIS
Sometimes it's shortened to AI.
CAROLE THERIAULT
Yeah. Okay.
MARIA VARMAZIS
So Google last year introduced this AI chatbot. They called it the Google Search Generative Experience, or SGE, and it was opt-in.
And the idea was for a search query, where Google deemed a chatbot might be especially helpful, it would generate an AI-based response to your query.
Somewhere in there, there might be actual links to websites, but for the most part, it would be like, this is the information we think you're looking for. Here's a summary.
And then here's a whole bunch of other information that might be good.
Like if you search for a product, it'll tell you most of the time this product will cost between this and this. In theory, sounds like it might be maybe helpful. Maybe. Yeah, maybe.
CAROLE THERIAULT
Yeah, maybe. Maybe my experience with AI is not always correct. Yeah, but yeah, maybe.
MARIA VARMAZIS
Maybe. Because I'm sure you also know the acronym GIGO.
MARIA VARMAZIS
Garbage in, garbage out. Yeah. So your AI is really only as good as your dataset.
And if you have an SEO-ified search situation, what is AI really going through and aggregating to offer as a suggestion? You've got SEO-ified AI search. It's a mess anyway.
So not a big surprise.
People who have been poking around this, what was up until recently experimental AI-augmented search, have found that attackers and bad dudes have been taking advantage of AI, just sort of trawling the internet and finding all sorts of search results.
And they've been figuring out how to SEO poison AI chatbot results. So—
CAROLE THERIAULT
Of course they have.
MARIA VARMAZIS
Of course they have. Of course they have.
So one SEO consultant, her name is Lily Ray, found that for many queries that Google found to be helpful to have a chatbot, the top results and the information that AI was serving up was directly from not just spammy but also malicious websites.
Yeah. So none of us are surprised. It's not just a cynical thing. It's like, of course someone has figured out how to do this.
So one of the common— the ways that these websites are compromised is essentially there's SEO poisoning going on.
So these bad dudes are creating tons and tons of websites with information that might sound plausible around a search-related term.
And then if you click on that website that again looks like it might be a real helpful website, you're gonna get redirected a gajillion times and eventually you'll end up on a website that prompts you to enable notifications.
And those of us who are savvy, we know now, no, don't enable notifications.
But many people go, all right, well, this website says it's gonna help me, so maybe I will enable desktop notifications.
And then that's when you start getting the popups and all sorts of— that's just a very common way that people get in and start just harassing people on their computers and getting them to try and click something.
CAROLE THERIAULT
Yeah. And call marketing.
MARIA VARMAZIS
Yeah. Yes. Some might call it that too. Sometimes there's even unwanted browser extensions. This feels very '90s sometimes when I'm reading about this, unwanted browser extensions.
It's going to hijack search. What is going on? What's the name of that gorilla? We're in a loop. Bondi gorilla or whatever. What's the name of that? Anyway, sorry.
Don't know if anyone remembers that but me.
GRAHAM CLULEY
What are you talking about? A Bondi gorilla?
MARIA VARMAZIS
Wasn't there a gorilla in the '90s that was a search hijacked thing? Someone's gonna know what I'm talking about.
CAROLE THERIAULT
Okay. Email the show.
MARIA VARMAZIS
Ignore that. Ignore that. Anyway, so yeah, it's a lot of fake results and the SEO poisoning the well for AI.
And Google says that they have fixed this issue, that they will no longer surface SEO-poisoned websites through the AI chatbot.
And they're continuously updating their systems to make sure this won't continue to happen.
But ultimately, the weight is on the user that you have to— don't click spammy links because obviously you'll be able to tell which ones are legit and which ones aren't, right?
GRAHAM CLULEY
So, Maria, are you suggesting that sellotaping AI onto every single technology on the internet may not necessarily be a great idea?
MARIA VARMAZIS
Gee, it might. It might be. That is the angle here. It's just amazing that search has gotten so bad and then we put AI on top of it and it's wow, and it's even worse now. Fantastic.
And I should also mention that this experimental feature is no longer experimental or opt-in. It is now being rolled out to all users. I don't have it yet. I tried.
I wanted to see if I could replicate this, but it is not available for me right now. I've heard also if you use Firefox that it won't work for you yet.
I guess Chrome browsers are getting prioritized. But yeah, really interesting.
I imagine people who put dodgy things on the internet are really enjoying the fact that AI can make their jobs easier.
CAROLE THERIAULT
Of course they are. And I think this is probably just the tip of the iceberg.
MARIA VARMAZIS
Yeah, it's great.
GRAHAM CLULEY
It's great.
MARIA VARMAZIS
And shitification all the way down. Yuck.
GRAHAM CLULEY
Carole, what have you got for us this week?
CAROLE THERIAULT
So when I was a kid, imagine all the family piled up in the car for a regular trip to the big city of Montreal. And you know, you're on the highway bored, right?
Because it's about an hour long. You didn't have devices as a kid.
So you're kind of just sitting there lazily watching traffic go past, you know, some cars passing you, you passing cars, la la la. And this car goes past.
And I noticed because the driver, this young guy, this man was laughing hysterically. And then, you know, the car moves beyond us.
And then there were in the back window, there were two hairy sacks beneath two hairy cracks, smushed against the backside window.
And my brothers and I died of laughter because, you know.
But later, when I was in university, I met this guy and he told me that he and his mates would get all drunk and then would run around flashing their bits as they shouted, "Last chicken in Sainsbury's." to people, and he thought this was so funny.
Can you imagine, Maria, we're walking home at night and a bunch of guys ensnare us with their junk in hand shouting about chickens? We'd be scarred for life.
GRAHAM CLULEY
I'm scarred for life just hearing about this, let alone seeing it.
CAROLE THERIAULT
I don't want to tell you I dated him, but I dated him.
GRAHAM CLULEY
Let's go, Carole!
CAROLE THERIAULT
Before I knew this, before.
GRAHAM CLULEY
Yeah, but here you are years later happily married to him.
MARIA VARMAZIS
Oh God, how dare you.
CAROLE THERIAULT
These situations were all in real life. But what about cyber flashing? Has that ever happened to you? Have you ever got a dick pic or?
MARIA VARMAZIS
Oh my goodness. Even more than in real life. Yes. My goodness. Yes.
GRAHAM CLULEY
I've got a story about that. I was giving a talk at the Excel Center in London for Microsoft. Thousands of people in the audience, right?
It was, it's probably the biggest gig I've ever done. It was huge. And I was doing this talk in this amazing area and blah, blah, blah, blah, blah.
And while I was on stage, so you get off the stage and you think, I wonder how that went. I'll see if anyone tweeted me.
CAROLE THERIAULT
Of course, that would be the first thing you'd do.
GRAHAM CLULEY
Yeah. Yes. You know, to see if it had gone all right. And, you know, and someone had sent me a picture and said, you know, row J, seat 234 or whatever it was.
And it sent me a picture of his knob.
CAROLE THERIAULT
Was it standing to attention?
GRAHAM CLULEY
I didn't look at it that closely, Carole, but you know, oh, it was— I didn't save it or bookmark it or anything like that. But yeah, so, so it has happened to me as well.
CAROLE THERIAULT
When was this? Like a long time ago?
GRAHAM CLULEY
Oh, about, probably about 2015 would be my guess.
CAROLE THERIAULT
So, so this is cyber flashing.
That's a perfect example of what cyber flashing is, and it's a form of sexual harassment where someone sends unsolicited sexual or nude images on social media, dating sites or directly through tools such as Bluetooth or AirDrop.
And instances of cyberflashing are on the up. In 2020, data revealed that reports of cyberflashing to the British Transport Police had almost doubled in 12 months.
And other sobering stats include 48% of women aged 18 to 24 say they've received a sexual photo without consent.
And the issue is worse for teens, with one study saying that 76, so 3/4 of girls aged 12 to 18, had been sent unwanted nudes of boys and men.
MARIA VARMAZIS
Yeah, that does not surprise me. I mean, that's the age also at which many people that age are receiving their first smartphones.
CAROLE THERIAULT
They're curious.
MARIA VARMAZIS
Yeah, they're curious. They're also enjoying a new freedom that they were not allowed to have.
Flip side, people who are the victims of this kind of thing, they may not know, hey, don't leave AirDrop wide open.
MARIA VARMAZIS
Not that— I mean, again, doesn't— that's not their fault.
But it's one of those things, if you leave AirDrop wide open and you're sitting— oh, I don't know— in a subway car, you're going to get stuff AirDropped to you that you do not want to see.
GRAHAM CLULEY
So it does seem to happen on public transport. It does.
MARIA VARMAZIS
Yeah. Because you're anonymous and it's— and you can just leave immediately. It's— and people think it's funny.
CAROLE THERIAULT
And you can also watch the reaction. And no one knows where you are.
CAROLE THERIAULT
Oh, I see.
GRAHAM CLULEY
But do you know when you send the picture? So if you AirDrop it to someone on a tube, do you know who you're sending it to?
MARIA VARMAZIS
No, it's just broadcast.
MARIA VARMAZIS
You just see a bunch of names, and those names may not be real. And, you know, there's a user icon. It doesn't always say your actual real name.
It depends on what the person has set up.
GRAHAM CLULEY
So if I were to send my dick pic to everybody in the train carriage or something.
MARIA VARMAZIS
Please don't.
GRAHAM CLULEY
No, obviously I won't. No. But not that I have that in my photo reel or anything like that.
CAROLE THERIAULT
They're trapped, Graham. They can't even get away.
GRAHAM CLULEY
I imagine if I were a perpetrator, maybe the thing to do is look equally shocked and disgustedly at my phone to rule myself out. Go, oh, God, who's the to do that?
Because if you're the one person who's sat there sniggering or looking around at everybody else. That would look more suspicious, wouldn't it?
CAROLE THERIAULT
It's pretty manipulative, you know.
GRAHAM CLULEY
I don't know, that's my department, you know.
CAROLE THERIAULT
There's this UK personality known as Jess Davies. She told the BBC in 2021 that she'd had enough.
She had received hundreds of unsolicited images, explicit images and videos of men since she started being active on social media, and she was now campaigning for it to stop.
Her Instagram at the time was in the six figures. She said she'd become almost numb to the images she received.
She's quoted as saying, "If it's illegal offline, it should be illegal online." Well, her and many other campaigners' voices did not go unheard.
As of January 31st, 2024, cyber flashing is a jailable offense in the UK with a maximum sentence of 2 years.
CAROLE THERIAULT
So people who send or provide unwanted images or films of genitals may also be fined and added to the Sex Offenders Register.
Plus, victims of the offense and other image-based abuses receive lifelong anonymity under the Sexual Offense Act from the point they report it.
So just this week, the UK has sentenced its very first offender under this new cyber flashing law.
GRAHAM CLULEY
Oh, marvelous.
CAROLE THERIAULT
Nicholas Hawkes, he was 39, from Basildon, UK, was arrested by Essex Police. Now, this guy already had a rap sheet, having interfered with a 15-year-old girl the previous year.
So at the time of his arrest, he was already on the sex offenders list.
So Hawkes gets nabbed by the police, and he ends up telling the Southend Crown Court that he had sent images from his father's phone.
So basically, he was living with his dad at the time and apparently borrowed the phone to call the probation officer, but then decided to sneak the phone into a private area so that he could send a pic of his taut ding dong to a teenager via iMessage and one to a 60-year-old woman via WhatsApp.
GRAHAM CLULEY
So he wasn't sending this via AirDrop. He actually sending it from his dad's phone, so it would have had his number or his user ID on it.
MARIA VARMAZIS
Oh my God.
GRAHAM CLULEY
Well, he's — look, I'd be so proud of that son.
CAROLE THERIAULT
The teenage girl was said to be left overwhelmed and crying by the image. Of course.
The 60-year-old woman took screenshots of the photograph — very smart — and reported it to Essex Police the same day, which led to his arrest.
CAROLE THERIAULT
Hawkes admitted to two counts of sending photographs of his junk to cause alarm, distress, or humiliation.
And on 19th of March, he was sentenced to 62 weeks in prison for these two offenses.
GRAHAM CLULEY
I've just noticed my email has a junk folder, and I don't often go in there, and I'm wondering now what I might find.
CAROLE THERIAULT
Don't do it. Never go into the junk folder. So I think the upshot here is never assume someone wants to see your meat and two veg. Never assume that.
MARIA VARMAZIS
Don't do it. Don't do it. Don't do it.
CAROLE THERIAULT
And in the UK, you now face jail time if you get caught doing that. So really big bravo to the UK for that.
But of course, Maria, as you alluded to already, prevention is better than conviction.
So one of the simplest ways is to protect yourself from cyber flashing from a stranger is to review your phone settings.
So turn off Apple AirDrop features on iPhone by turning off Wi-Fi and Bluetooth, or you know, you can ping it on and off depending on where you are.
And don't pair your Bluetooth with unidentified sources. Do you guys have anything else that might be a sage piece of advice here?
GRAHAM CLULEY
I think that Apple, I don't know about Android, but I think Apple have recently introduced a feature whereby it analyzes videos and photos that you are sent and it can display a sensitive content warning.
This is a setting you can have and it blurs out the image so it warns you before you view it. So that's something that people might want to turn on.
I think it's under privacy and security in your settings.
CAROLE THERIAULT
That's mad because as my sign-off for this piece, I was going to say, hey, maybe we should lobby phone providers to put a fig leaf on by default when they detect suspicious fleshy things on screen.
A bit late on that one, Cluley.
GRAHAM CLULEY
Yeah. So I'm just reading about this now. They say it's on-device machine learning. So I guess they taught it with thousands of images of people's penises.
CAROLE THERIAULT
Wonderful.
MARIA VARMAZIS
Oh my God.
GRAHAM CLULEY
How great it is to be an Apple employee. But apparently, yeah, so this is a feature which now exists in iOS, which you can turn on.
And it sounds like it's— oh, and you can do it on your Apple Mac as well, I'm reading. So a good idea probably to turn on something like that if it's available to you.
CAROLE THERIAULT
And the thing to remember is if you receive an unwanted sexual image in the UK, screenshot the evidence and report it to your local coppers, citing the new cyber flashing law.
And if it happens while you're traveling on public transport, please contact British Transport Police.
Interestingly, seems that in the US there are only two states, Texas and California, that have cyber flashing laws. There is no federal law prohibiting cyber flashing.
I read today that New York is looking at it, but I think the penalty will be 15 days in prison, which is a lot less than what we're seeing in the UK with two years.
MARIA VARMAZIS
That's if you can get a conviction, which would be hard as hell.
Yeah, I live in one of the only two states in the country that still does not have a revenge porn law, if you can believe it. Massachusetts still doesn't have one.
Yeah, it's been in the works for years and they still won't pass it.
So I mean, if you can't get legislation to move on revenge porn, I'm just kind of like, I would be surprised if there's anything about this because it's super common, you know, to the point where in my mental model I think of it as a nuisance.
But of course, you know, I'm much older. But, you know, I'm not happy about the state of things here about this topic area. So, yeah.
CAROLE THERIAULT
Well, there have been a lot of cyber laws that have been passed recently, so let's just hope we see some action in this space pretty damn pronto.
GRAHAM CLULEY
Legacy managed file transfer tools are dated. They lack the security that today's remote workforce demands.
Companies that continue relying on outdated technology put their sensitive data at risk.
Well, this podcast is sponsored by KiteWorks, who enable organizations to effectively manage risk in every send, share, receive, and save of sensitive content.
To do that, they've created a platform that delivers content governance, compliance, and protection to customers, tracking, controlling, and securing sensitive content as it moves within, into, and out of organizations, all while ensuring regulatory compliance on all sensitive content communications.
KiteWorks provides the industry's first private content network for protecting risky third-party communications with secure email, secure file sharing, secure mobile, secure web forms, managed file transfer, and governed SFTP servers.
Visit kiteworks.com to get started today. That's kiteworks.com, and thanks to them for supporting the show.
CAROLE THERIAULT
Smashing Security is also sponsored by Vanta. Managing the requirements for modern security programs is increasingly challenging and time-consuming. Enter Vanta.
Vanta gives you one place to centralize and scale your security program. Quickly access risk, streamline security reviews, and automate compliance for ISO 27001, SOC 2, and more.
You can leverage Vanta's market-leading trust management platform to unify risk management and secure the trust of your customers.
Plus, use Vanta AI to save time when completing security questionnaires. Smashing Security listeners, you get 20% off Vanta.
All you lucky sausages have to do is visit vanta.com/smashing to claim your discount. That's V as in Victor, A-N-T-A.com/smashing. And thanks to Vanta for sponsoring the show.
GRAHAM CLULEY
You've probably heard us talk about Kolide before, but did you know Kolide was just acquired by 1Password?
Well, that's pretty big news since these two companies are leading the industry in creating security solutions that put users first.
For over a year, Kolide Device Trust has helped companies with Okta ensure that only known and secure devices can access their data.
And that's what they're still doing, but now as part of 1Password. So if you've got Okta and you've been meaning to check out Kolide, now's a great time.
Kolide comes with a library of pre-built device posture checks, and you can write your own custom checks for just about anything you can think of.
Plus, you can use Kolide on devices without MDM, your Linux fleet, contractor devices, and every BYOD phone and laptop in your company.
Now that Kolide is part of 1Password, it's only going to get better. Check it out at kolide.com/smashing to learn more and watch the demo today.
That's k-o-l-i-d-e.com/smashing, and thanks to them for supporting the show.
And welcome back, and you join us at our favorite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.
CAROLE THERIAULT
Pick of the Week.
GRAHAM CLULEY
Pick of the Week is the part of the show where everyone chooses something they like.
Could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app. Whatever they wish.
It doesn't have to be security-related necessarily.
CAROLE THERIAULT
Better not be.
GRAHAM CLULEY
Well, my Pick of the Week this week is not security-related.
CAROLE THERIAULT
Very good.
GRAHAM CLULEY
My Pick of the Week this week is an article I was reading about some of the weirdest secret agent gadgets.
I don't know if either of you think of yourselves as a secret agent, James Bond type.
You think that'd be glamorous, but you may want to check out the link, which I'm going to share on the Stay Weird website, because I'll tell you about some of the things which I found out about.
We've some pictures as well, which I'll share with you too, but other people can check out in the images. We've got exploding rats.
So the British during World War II stuffed rats with explosives. And they sort of sent them in. They said, "This way, little Timmy. This way, little Timmy.
Go and go into that munitions dump, and then we can blow up and cause damage and confusion." And apparently the Germans, they intercepted a shipment of exploding rats before the plan could come into effect.
And so the Germans were on top of it. You may have heard the phrase, "You dirty rat." This is where it comes from.
CAROLE THERIAULT
Oh, my God.
GRAHAM CLULEY
No, it's not true.
MARIA VARMAZIS
Okay. You convinced us. It was a very— Yeah, good lie. I like it. All right.
GRAHAM CLULEY
Intercepted it. And so the Brits thought, well, we won't do that anymore.
The Germans apparently wasted loads of time and resources looking out for exploding rats as a consequence, thinking any moment we might get attacked by an exploding rat.
There were also pigeon cameras in the early 1900s, because obviously drones didn't exist.
CAROLE THERIAULT
Pigeon cameras?
GRAHAM CLULEY
Yeah, they would strap a Polaroid camera to a pigeon.
CAROLE THERIAULT
No, they didn't.
GRAHAM CLULEY
Well, there's a picture, Carole. I've got a picture. Go and check it out.
CAROLE THERIAULT
Okay, just because it's a picture, I don't know if you've heard of DALL·E and AI.
GRAHAM CLULEY
There is a picture of a pigeon sat on a little wooden plinth.
MARIA VARMAZIS
I feel like we talked about this earlier, maybe.
GRAHAM CLULEY
Yeah. With a camera around its neck.
CAROLE THERIAULT
Looks pretty heavy, that camera.
MARIA VARMAZIS
How the hell is that thing gonna fly with that on its neck? I mean, that's glass and metal. How is that gonna fly?
CAROLE THERIAULT
Tell you what, my pigeons could. Mine are really big. I've been feeding them.
GRAHAM CLULEY
They're pretty tough. If you think of how a pigeon walks and what it does with its neck, it's got really strong neck muscles, a pigeon. So it can be used.
We've got a glove with a gun hidden inside the glove, which apparently is if you had a meeting with someone who you thought was a bit— Well, maybe you hold that further up to speak.
CAROLE THERIAULT
Extra white glove. No one's going to notice.
GRAHAM CLULEY
No one's going to notice.
MARIA VARMAZIS
Fake hand. Yeah.
GRAHAM CLULEY
Okay. And we've got a dog poop transmitter used by the CIA.
MARIA VARMAZIS
Of course, of course.
CAROLE THERIAULT
It's the size of France, that dog shit. As if what you see, what that would just be on the sidewalk and I'm supposed to go, oh yeah, that's real.
GRAHAM CLULEY
That's right.
CAROLE THERIAULT
Where's the monster that gave, that put this one out?
MARIA VARMAZIS
That's a Great Dane size too, easily.
GRAHAM CLULEY
Look, let me explain how it works, Carole. If you're having a secret meeting that you want to record, right? You might go to the lavatory.
You might deposit the transmitting device, as we'll call it, in the lavatory. Don't flush! You probably couldn't flush this. It's so big. It just floats there.
And when other people go in there to have their secret conversations, it is recording it and sending the information back to—
CAROLE THERIAULT
Yes, we were going to hear them go, "Jesus Christ, look at that thing! Who fucking put that in the loo and didn't flush?
GRAHAM CLULEY
Jesus!" Go and get the coat hanger. Urgent.
GRAHAM CLULEY
Too much. Anyway, this article, I found it very illuminating and very interesting. And that is why it is my pick of the week. Maria, what's your pick of the week?
MARIA VARMAZIS
Follow that. Yeah, we're talking about pigeons and dog shit. Great. My pick of the week is the video game that I've been playing nonstop since— when did I get it? December?
It's been out longer than that. Oh, you may have heard of it, so this is not an obscure pick by any stretch of the imagination. It's called Baldur's Gate 3. Have you heard of this?
GRAHAM CLULEY
Oh yes, yes, I've heard of it, but I've never played it.
MARIA VARMAZIS
Yeah, it's won every conceivable award in the game industry that exists. It's made literal billions of dollars. Yeah, so this is not some unknown thing.
I'm just adding my voice to the many. I don't play Dungeons and Dragons. This is not me trying to be a hipster. I just don't play it, but it is a Dungeons and Dragons-based game.
It's got a lot of D&D lore. I knew none of it going into this game, and the game did a brilliant job of sort of walking me through it. And more importantly—
GRAHAM CLULEY
Have you never played Dungeons and Dragons, Maria?
MARIA VARMAZIS
I have never, and that always shocks people.
GRAHAM CLULEY
It does shock, 'cause you're such a nerd.
MARIA VARMAZIS
I know, I know. And my husband is a diehard D&D fan, diehard. But I have never played it. I've tried many times.
I don't know if it's because of when I grew up and it was very much a teenage boy thing and being the only girl surrounded by gross teenage boys was just really not appealing.
It's changed a lot since then. It's changed a lot.
But yeah, my husband was watching me play and he was, "you're learning about this thing." I'm, "I have no idea what you're talking about, but I'm enjoying this game a great deal." Super fun.
The story is fantastic. I joke that it's kind of a dating sim disguised as a Dungeons and Dragons game.
You can romance different people throughout the game and the relationships are surprisingly complex for a video game.
GRAHAM CLULEY
Dungeons and Dragons Eagles fans probably need a dating sim, don't they? They probably need a little bit. They're not going to get it in real life, so it's a good idea.
MARIA VARMAZIS
Yeah, honestly. And because they're nerds, you can have a polycule, and it's very nerdy.
CAROLE THERIAULT
Polycules. Where do you play this? Is this on a computer?
MARIA VARMAZIS
You can play it through Steam. I have it on the Xbox. I think there's a PS5 version. It's just everywhere. This, as I said, won every Gaming Award. It's a massive, massive success.
CAROLE THERIAULT
But now we have your stamp of approval.
MARIA VARMAZIS
Yeah, I'm just adding—if someone wants to message me about Baldur's Gate 3, I'm all about it. I already beat the game. I'm happy to chat about it. I really, really enjoyed it.
I put easily 150 hours into my first playthrough, and I'm playing it now again. So yeah, Baldur's Gate 3, highly recommend.
CAROLE THERIAULT
Whoa. Now I know why you don't answer my phone call. Yeah, I'm playing Baldur's Gate 3.
GRAHAM CLULEY
Carole, what's your pick of the week?
CAROLE THERIAULT
So my pick of the week—I should first explain that I kind of got into birds during the pando.
I'm no birder or anything, or twitcher, I don't know what they're called, but I can kind of identify all the birds in my yard and I even know the families, which ones get on with others, who's trying to woohoo.
GRAHAM CLULEY
Woohoo? Is that the noise they make?
CAROLE THERIAULT
I know who's wooing who. Yeah, I know who the enemies are and all that jazz. Okay, crazy bird lady, that's me. So in honor of this and of spring, I have chosen an app.
I can't believe I've never made this my pick of the week before, but it's called Merlin Bird ID by Cornell Lab. Have you guys heard of it?
MARIA VARMAZIS
I have. I think I have that on my phone.
CAROLE THERIAULT
Yes. It's a really cool app. It's free.
MARIA VARMAZIS
Yeah, I do. Yep. Yeah.
CAROLE THERIAULT
Yep. So do I. I've had it on for months and months. So it's a free global bird guide with photos, sounds, and maps.
Okay, so there's three different main things I see that I use it for. So you can listen. There's a listen sound ID component which listens to—
GRAHAM CLULEY
Oh, it's Shazam.
MARIA VARMAZIS
Shazam for birds. Yes, that is exactly what it's like.
GRAHAM CLULEY
That's so clever. That's so clever.
CAROLE THERIAULT
Listens to birds around you and then shows you real-time suggestions who's singing. And it works completely offline.
So you can identify birds that you hear no matter where you are, even if you have no—see, you could have done this, Graham.
You could have done this instead of working on the podcast because you don't need to. You can do this all completely offline.
You can obviously send them a snap of a picture or one from your camera roll, and Photo ID will provide you with a short list of possible matches.
And you can build a digital scrapbook of your birding memories. I haven't done that. But you just kind of like, this is my bird.
And each time you identify a bird, it will add it to your growing list. So it's very, very cool.
GRAHAM CLULEY
Can you make the sound of a particular bird for us, Crooks? You must be learned. Could you make one?
CAROLE THERIAULT
No, no, no. I'm going to—
GRAHAM CLULEY
No, not the phone. I want to hear you.
CAROLE THERIAULT
Yeah, this will be me. This is me. This is me.
GRAHAM CLULEY
Oh, this is you. Let's hear it.
CAROLE THERIAULT
This is the Eurasian blackbird, right? So this is its song. Okay. And then this is one of their calls.
MARIA VARMAZIS
Cool, right? Oh, I feel more relaxed having heard that. It's so nice.
CAROLE THERIAULT
It's a very nice app. It's very cute. You can just kind of even also go Oxford or wherever you live just to see what birds are around that you can try and ID.
So it's free, it's great, and you help the world by mapping all these wonderful birds. So Merlin Bird ID, and that's my pick of the week.
GRAHAM CLULEY
Well, haven't we done well? Three excellent picks of the week this week. I'm including mine, obviously. And that just about wraps up the show for this week.
CAROLE THERIAULT
Spy turds.
GRAHAM CLULEY
Maria, what's the best way for folks to find out what you're up to?
MARIA VARMAZIS
If you want to hear my damn voice in your ear holes every day, I'm the host of T-Minus Space Daily. You can get it on your favorite podcast app.
I did a really good job of selling it right now. Please don't fire me. And the website is based on n2k.com and I'm also on the Fediverse at Varmazis. So find me there.
GRAHAM CLULEY
Super stuff. And you can follow us on Twitter at Smashing Security, no G. Twitter allows to have a G. And don't forget to ensure you never miss another episode.
Follow Smashing Security in your favorite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.
CAROLE THERIAULT
And huge shout out to our episode sponsors, Fanta, Kolide, and KiteWorks, and of course to our wonderful Patreon community. It's thanks to them all this show is free.
For episode show notes, sponsorship info, guest lists, and the entire back catalog of more than 364 episodes, check out smashingsecurity.com.
GRAHAM CLULEY
Until next time, cheerio, bye-bye. Bye.
CAROLE THERIAULT
I think you'll find it wasn't this year. It wasn't this year. It took you five days.
MARIA VARMAZIS
Well, actually. Well, actually. Oh, that was brilliant. That was still my favorite moment for the whole episode, was right at the top. It was all downhill.
GRAHAM CLULEY
It's all downhill. Yeah.
MARIA VARMAZIS
Oh my God.
GRAHAM CLULEY
Slippery slope.
There is currently a ban on Flipper Zero devices in Canada.