Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

Hacking stories and cybersecurity insights.

Graham Cluley
Graham Cluley
@

 @grahamcluley.com
 / grahamcluley

Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras

A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand’s national parks. What could possibly have gone wrong?

Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping up on American street corners, and took a very close look inside.

All this and more in episode 486 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Dave Bittner.

0:00
0:00 0:00
0:00
Show full transcript
TranscriptThis transcript was generated automatically, probably contains mistakes, and has not been manually verified.
DAVE BITTNER
I have to say, what this reminds me of is there was a glitch on Amazon for a while.

I don't know if it's still there, where if you went to buy condoms, it would ask you, would you like to buy this item used?
GRAHAM CLULEY
Smashing Security. Smashing Security, episode 486, Vibe-Coded Shops and Hackable Flock Cameras, with Graham Cluley and special guest Dave Bittner.

Hello, hello, and welcome to Smashing Security, episode 486. My name's Graham Cluley.
DAVE BITTNER
And I'm Dave Bittner.
GRAHAM CLULEY
Dave, always lovely to have you back on the show. Star of The Cyber Wire, Hacking Humans, that other one I've forgotten the name of.
DAVE BITTNER
Caveat.
GRAHAM CLULEY
Caveat, thank you.
DAVE BITTNER
It's all good, Graham.
GRAHAM CLULEY
The good news is, Dave, actually, is I'm going to be recommending that all of our listeners go and check out your podcasts, particularly next week, because there isn't going to be an episode of Smashing Security next week.

I am grabbing a map, a compass, and a rucksack full of cheese sandwiches, and I am going to be venturing into the wilds of Britain because I'm moving house.

I'm going to a different part of the UK.
DAVE BITTNER
Wow.
GRAHAM CLULEY
And I won't have a chance to put out an episode next week.

What I will be doing is I'll be really busy contacting the CEO of Openreach and asking why it's so hard to get me a fibre internet connection to my house when there's a box just 5 feet away from me.
DAVE BITTNER
Just put a Y cable in there. What could go wrong?
GRAHAM CLULEY
Yeah, exactly. What could possibly go wrong? But never fear, folks.

If you can hold your breath until Thursday, the 8th of October, there'll be a new episode of Smashing Security then.

And in the meantime, check out Caveat and Hacking Humans and The Cyber Wire and all the other — well, thank you.

Well, before we kick off, let's thank this week's wonderful sponsors, ThreatLocker, Origin, and Vanta. We'll be hearing more about them later on in the podcast.

This week on Smashing Security, we won't be talking about how researchers managed to take over the accounts of staff at OpenAI using Anthropic's Claude.

You'll hear no discussion of how Dutch police have asked for the public's help after releasing a recording of what they believe to be the voice of a member of the Shiny Hunters hacking group.

And we won't even mention how North Korea has been posing as recruiters to infect job seekers during fake coding tests and then waiting for them to get hired somewhere real.

So Dave, what are you going to be talking about this week?
DAVE BITTNER
I'm talking about a bunch of researchers who are asking the question, what the flock?
GRAHAM CLULEY
And I'm gonna be going online to buy a laser-equipped kiwi. All this and much more coming up on this episode of Smashing Security.
GRAHAM CLULEY
This episode of Smashing Security is sponsored by Vanta.
GRAHAM CLULEY
It's 2:00 AM. Somewhere, a security team is drowning.
DAVE BITTNER
Graham!
GRAHAM CLULEY
The spreadsheets. There are so many spreadsheets. Vendor risk assessments unread. Audit evidence scattered like ash in the wind.

I've filled out the same questionnaire 4 times this week, Graham. 4 times! Some men choose to face this alone, but not tonight.
JOE
Okay, Graham, this is a bit much.
GRAHAM CLULEY
Yeah, fair point. Anyway, Vanta—
JOE
Thank God.
GRAHAM CLULEY
Vanta's a trust management platform that automates the mind-numbing stuff that makes you want to poke your eyes out with a fork.

No more manual evidence chasing, no more questionnaire hell. It continuously monitors your systems and keeps you audit ready for SOC 2, ISO 27001, HIPAA, GDPR, the works.

And it uses AI. Yes, Joe, it does.
JOE
To flag risks and streamline evidence collection so your whole security program stays in shape, not just the week before an audit.
GRAHAM CLULEY
No more 2:00 AM dread. No more spreadsheet purgatory. Just peace.
JOE
And $1,000 off if you demo it right now.
GRAHAM CLULEY
$1,000?
JOE
vanta.com/smashing. Go now before it's too late.
GRAHAM CLULEY
That's vanta.com/smashing.
JOE
And thanks to Vanta for supporting the show.
GRAHAM CLULEY
Now, chums, there are important questions to be asked of this week's guest, Mr. Dave Bittner. I won't beat around the bush, Dave. How do you feel about crusty socks?
DAVE BITTNER
How do I feel about crusty socks?
GRAHAM CLULEY
Yes, how do you feel about them?
DAVE BITTNER
I try to avoid them whenever possible.
GRAHAM CLULEY
You're not growing any in Chez Bittner right now?
DAVE BITTNER
No, no, no. But when I was a teenager, I think I had issues with crusty socks, but it's been a while.
GRAHAM CLULEY
I imagine they are pretty fresh and clean, those beautiful feet of yours these days.

I'm asking because this week, somewhere in Auckland, New Zealand, there is a convenience store that briefly was selling a pair of crusty socks on its website.

And that wasn't all they were selling. They were also selling a rather divine Princess Diana commemorative plate.
Unknown
Oh no.
GRAHAM CLULEY
And if you were quick, you could also have bought all of New Zealand's national parks. They were being sold to the highest bidder as well.
DAVE BITTNER
Wow.
GRAHAM CLULEY
Now, this wasn't some marketing stunt. This wasn't a flea market with any old bric-a-brac and odds and sods and national parks and the like.

Instead, this particular store had made a bit of an error when it built its website.

It had used something called Base44, and Base44 is a vibe coding platform owned by Wix, one of those places where they sort of roll your own website.

You can go to it and out the other end of the mixer will come a brand new website. Dave, have you ever vibe coded at all? It's very popular these days.
DAVE BITTNER
The closest I have come to vibe coding was I asked ChatGPT to create a version of Pong in BASIC for the TRS-80 Color Computer.
GRAHAM CLULEY
And did it work?
DAVE BITTNER
Yeah. I mean, it was slow, but it worked.
GRAHAM CLULEY
I rather approve of that. What do you think of the idea of vibe coding generally?
DAVE BITTNER
I think at this point it's unavoidable. I think it's out of the box and there's no putting it back in there.

But the people I know who are professional developers, many of them say that their job has shifted from actually being a developer to being a supervisor of the AI that's actually doing the coding.

I suppose as long as there's oversight, then it's okay, but I think everybody's a little nervous about this.
GRAHAM CLULEY
I think if you've spent years and years studying how to code and now you've been replaced by a glorified speak-and-spell machine, you are going to be pretty upset about this.

I have vibe coded myself sometimes. You know how Liam Neeson in that movie says he has a very particular set of skills?
DAVE BITTNER
Yes. Yes.
GRAHAM CLULEY
Well, I have a very particular set of requirements on my computer sometimes. You just, oh, if only my computer would do this in this particular way.

And in the past, I would spend hours looking for a utility which did that particular thing.

And I do find myself now sometimes thinking, hmm, rather than spending four months coding this myself, maybe I could ask an AI to help me. And bloomin' heck, I mean, they can do it.

I wouldn't necessarily want to roll it out to the public. I wouldn't necessarily want to give it to other people and let them find the vulnerabilities in it.
DAVE BITTNER
You're okay being your own guinea pig.
GRAHAM CLULEY
Yes. You know, think, okay, I could run this on my computer. But here's the problem.

Somewhere in the process of vibe coding their own e-commerce site, these chaps who were running this store, they somehow left the entire thing open to be edited by anybody on the entire internet.
DAVE BITTNER
Oh my.
GRAHAM CLULEY
No password required.
DAVE BITTNER
Wow. How do you miss that?
GRAHAM CLULEY
Yeah. Exactly. And you also think, well, how did Base44 ever allow that to be possible?

So even if it wasn't a vulnerability in Base44, I suspect it was actually the setting up of the particular environment where there was an error.

Why did they, considering this was something which was meant to be used by non-professionals, people who weren't versed in computer security and technology — maybe, you know, I need a website.

I run a shop selling shoelaces. I know nothing about computers. Can you create me a website? Yes, I'll go and do that. How can they leave it open like that?
DAVE BITTNER
It seems like a top-tier requirement of building something like this.
GRAHAM CLULEY
You would think so.
DAVE BITTNER
Don't let the general public make changes.
GRAHAM CLULEY
And of course, inevitably, random members of the public did discover that they could just go to the website and make any changes they wanted.

They could add their own listings to the live site.
DAVE BITTNER
And they did not disappoint.
GRAHAM CLULEY
Of course, the internet never disappoints when given an opportunity like that.

So you too could buy a pair of crusty old socks, or you could purchase a single banana for $850, or a mouldy school lunch.

You too could find yourself paying off New Zealand's Deputy Prime Minister for $3,000. All kinds of things. There was even this Princess Diana commemorative dinner plate for $1.50.

Now, I've shared with you—
DAVE BITTNER
Yes.
GRAHAM CLULEY
An image, Dave, of this plate. I think it's Princess Diana.
DAVE BITTNER
Graham, never before has the beauty of the dear departed princess been on better display than it is on this, this clearly handmade and painted plate.

I would be honoured and proud to display this anywhere in my home, and I hope our listeners will take the time to check it out. It's just gorgeous.
GRAHAM CLULEY
It's a beautiful thing. And there it is alongside the Laser Kiwi, which obviously is something every person in New Zealand needs.

Dave, if you had the opportunity to list something on a site like this, what sort of thing do you imagine you would want to list?

What wonders would you put up on this online emporium?
DAVE BITTNER
Oh my goodness, I don't know. But I have to say what this reminds me of is — there was a glitch on Amazon for a while. I don't know if it's still there, where if you went to buy—
GRAHAM CLULEY
Was this the buy route?
DAVE BITTNER
No, no. If you went to buy condoms, it would ask you, would you like to buy this item used?
GRAHAM CLULEY
You know what? There are probably people who pay more for that.
DAVE BITTNER
Tickles me.
GRAHAM CLULEY
Some people would.
DAVE BITTNER
Tickles me to this day. So yeah, it's not just a small little convenience store that these sort of things can happen to. Happens to the largest commerce platform in the world, right?
GRAHAM CLULEY
So at some point, the actual store owner tweaked what was going on and he tried to fight back, but he didn't know how to secure the site.

So instead what he did was he started posting other items for sale with titles like, please stop hacking us.

And within minutes, someone else added a new listing saying, well, don't use an AI site builder then, which seems like fair enough security advice coming for free from the general public.
DAVE BITTNER
Mm-hmm.
GRAHAM CLULEY
Now, this, as I said, may not have been explicitly the fault of Base44. Maybe the security settings hadn't been set properly.

But, you know, it's not as though this were the first time that Base44 has made the headlines.

Last year, security researchers at Wiz found an authentication bypass vulnerability in the platform. That allowed unauthorised access to private apps built by its users.

What that meant was if you could see the URL, which of course you could in your browser, of a particular app, you would then be able to create a verified account to access it as the owner yourself.

So the supposedly secret app ID was there for anybody to see in the URL. So security, not necessarily their strong point. Wow.
DAVE BITTNER
How is Base44 still in business, one has to ask?
GRAHAM CLULEY
And how much did Wix pay in order to acquire Base44? I hope they think this was money well spent. Or maybe they bought them and then got rid of all the security engineers.

I don't know.
DAVE BITTNER
Yeah.
GRAHAM CLULEY
So Dave, there's going to be a lot of small businesses wanting their websites to be built or refreshed.

It's like, oh, we can't really carry on with this Dreamweaver site we created in 1999 anymore, we're going to have to do a bit of a revamp of that.

And so you've got to think a lot of people will turn to simple tools that promise a lot, but that the users don't really understand.
DAVE BITTNER
No.
GRAHAM CLULEY
And that's going to be a problem.
DAVE BITTNER
Just crowdsource everything on your website, right? Open it up to the entire internet. What could go wrong?
GRAHAM CLULEY
Because these tools, they're explicitly marketed at people who have no idea, not a clue what an access control setting is.

And the AI might happily build you a gorgeous looking website, but it won't necessarily tell you if you've left all the doors and windows wide open.

So I raise a glass right now to the people of New Zealand who, with good humour, have— I mean, technically, I suppose what they did was maybe that was against the law.

I don't know whether it was or not.
DAVE BITTNER
Hmm.
GRAHAM CLULEY
If it's been left open like that. But it appears not to have been done for malicious reasons, but everyone had a good old laugh about it, which is good fun.
DAVE BITTNER
I suppose the flip side is that this convenience store operator is seeing more traffic to their website than probably ever before.
GRAHAM CLULEY
It's interesting, isn't it? Because sometimes there can be marketing stunts like this to get you some traffic. I tried going to this particular website — right now it's down.

You get a Cloudflare error.

I don't know if it's because too many people have gone there or they thought, we don't know how to stop this, we're just going to yank out some cables — they've turned it off.

But there have been cases in the past where companies — I can think of one dating site for beautiful people, for instance, where they intentionally pretended that they had been hacked in order to get lots of press coverage.

A very unusual story. I'll link to it in the show notes if anyone's interested in that.
GRAHAM CLULEY
This episode of Smashing Security is supported by Origin.
GRAHAM CLULEY
Joe, did you see that big story about AI agents running around inside OpenAI and Hugging Face's own environment?
JOE
The ones dividing up work between themselves and reviewing each other's output?
GRAHAM CLULEY
That's the one.

One of the things that really struck me was how the people who actually built those AI models had a hard time reconstructing exactly what the agents had done and said to each other.
JOE
Right, and that's really the point. Even the experts closest to the technology struggled to answer a simple question: what did our AI actually do?
GRAHAM CLULEY
Which is exactly the question this week's sponsor, Origin, wants you thinking about.

If an AI agent caused an incident at your company tomorrow, what evidence could you actually produce?
JOE
For most teams, the honest answer is not much.

You've got the prompt and you've got the final result, but everything in between — the commands it ran, the files it changed, the credentials it picked up along the way — that's usually gone the moment the terminal closes.
GRAHAM CLULEY
And that's the gap our sponsor, Origin, was built to close. Origin is an endpoint AI observability company. A sensor on the machine records the agent's work as it happens.

Who started the session, what was asked, what the agent reached, and what it changed, all on one timeline.
JOE
So if something unexpected happens, you're not piecing it together from scattered logs.

You open the trace and read the session in order from the original prompt through to the outcome.
GRAHAM CLULEY
It works wherever agents actually operate too. Coding agents in a terminal, local agents, anything calling an MCP server on a laptop.

None of that needs to pass through a cloud gateway for Origin to see it.
JOE
So if you want to see what a trace actually looks like, head to originhq.com/smashing.
GRAHAM CLULEY
That's originhq.com/smashing. And thanks to Origin for sponsoring the podcast.
DAVE BITTNER
Well, Graham, do you have Flock Safety cameras over on your side of the pond yet?
GRAHAM CLULEY
Flock surveillance cameras? Yes, we do. Britain is supposed to be the country with more CCTV cameras than practically anywhere else. I think we've only got more than North Korea.

But these Flock ones, they're making lots of headlines over in the States, aren't they? They seem to be quite invasive.
DAVE BITTNER
They are. And we're doing our best to catch up with you all. These Flock Safety cameras are popping up like dandelions all over the place.

In fact, there are open-source projects to track their locations.

People have put together Google Maps where you can look at your community and see where the Flock Safety cameras are around you.
GRAHAM CLULEY
Right.
DAVE BITTNER
There are several around where I live, and they're easy to spot. They have a particular look to them, and I find it disturbing as they're popping up all over the place.

These are licence plate reading cameras.

So the idea is you drive by with your car, it takes a picture of your car, it logs your licence plate, it logs the type of car, what direction you were going, the time of day, all that sort of thing.

And of course, you get enough of these little bits of data, and you can put together a picture of where someone's going and when they're going and what they may be up to.

So hackers have gotten their hands on one of these cameras. And by getting their hands on one, I think they backed a truck into it and ran off with it.

I think that's sort of the subtext of what's going on here. But there are hundreds of thousands of them all over our great nation, so I don't think they'll miss the one.

But they got a good look inside the cameras, and from a security point of view, it's not good. There's a hacker collective called Stegonogram.
Unknown
Okay.
DAVE BITTNER
Of course, there's a jaunty zero in the middle of the word Stegonogram instead of an O, because hackers.
GRAHAM CLULEY
Yes.
DAVE BITTNER
So they got their hands on this Flock camera. They took it apart, and they extracted its storage.

And the group Distributed Denial of Secrets has published images of those file systems, which has enabled lots of researchers to take a look under the hood at what exactly is going on here.

So security researcher Mika Lee, who you've interviewed before, haven't you, Graham?
GRAHAM CLULEY
I mean, have you?
DAVE BITTNER
Mika's been a guest on Smashing.
GRAHAM CLULEY
I don't think — no, Mika hasn't been on Smashing Security, but I certainly know their work.
DAVE BITTNER
Yeah. So well-known researcher, well-respected. He took a look and published a blog post about this.

He found that this camera was running a modified version of Android 8.1, which is an OS that was released in 2017 and no longer supported by Google.

Its patching was dated to June of 2018, and its underlying Linux kernel was also, in his words, ancient.

So in other words, this camera was watching modern traffic with software security that was from the 2010s.
Unknown
Yeah.
DAVE BITTNER
Lee identified several publicly known vulnerabilities that are applicable to components of the device.

He saw flaws that could allow malicious software already running on the camera to gain deeper control. But then, sort of the chef's kiss of all this, are the credentials.
GRAHAM CLULEY
Right.
DAVE BITTNER
He found an API key hardcoded into a software library that's shared by 19 Flock applications that run on the camera.

So based on his analysis, that key is used during the process by which the cameras obtain their credentials for accessing Flock's backend infrastructure. So the—
GRAHAM CLULEY
Is it possible the person who created these cameras then got a job at Base44 creating a website building tool?
DAVE BITTNER
Yes, yes.
GRAHAM CLULEY
Right.
DAVE BITTNER
Because they had excellent credentials. And the people looked at their past work and said, well, this looks good to us. Yeah.
GRAHAM CLULEY
Good enough.
DAVE BITTNER
The device also stored authentication credentials in plaintext—
GRAHAM CLULEY
Of course.
DAVE BITTNER
On an unencrypted partition. Now I will say, as you and I are recording this, this API key has been making the rounds on social media. It is everywhere.

If you want to look for it, people are just posting and reposting, having the time of their lives posting this hardcoded key for Flock.

Obviously it's illegal to use this key to do what you want with Flock's API server, but do we know what you could do with this?
GRAHAM CLULEY
Is it a case of taking data off the cameras or maybe putting data on the cameras?
DAVE BITTNER
It seems as though this key is how the camera authenticates itself with Flock's mothership, if you will. So it says, this is who I am, this is where I am, which is another thing.

The camera sends its GPS coordinates to identify where it is.

And so with this information, you could basically authenticate yourself on Flock's API on their home base servers and pretend to be one of the remote cameras.
GRAHAM CLULEY
We could pretend to be a Flock camera if we wanted to, maybe.
DAVE BITTNER
We could, we could.
GRAHAM CLULEY
And muddy their database.
DAVE BITTNER
Imagine the fun we could have. We could post pictures of that Princess Di plate. Just—
GRAHAM CLULEY
I don't think facial recognition is going to work on that plate.
DAVE BITTNER
No, no.
GRAHAM CLULEY
I don't think you'd even— Even if they had a modern Flock camera rather than one built in 2017, 2018, I don't think it was—
DAVE BITTNER
Not going to recognise it as being human. No.
GRAHAM CLULEY
No.
DAVE BITTNER
So the logs recovered from the camera contained GPS coordinates.

This particular camera seemed to have come from somewhere in Wisconsin, and researchers were able to use Google Street View to find the particular camera, I suppose, when it was still there.
GRAHAM CLULEY
Yes.
DAVE BITTNER
Flock, of course, in response to the stories that have been written about this in places like 404 Media and Wired, they have said, and I quote, they take security seriously and they maintain a vulnerabilities disclosure programme.

Yeah.
GRAHAM CLULEY
Is it possible that their statement was also written in 2017 or 2018? They had that in their back pocket because—
DAVE BITTNER
It's possible.
GRAHAM CLULEY
I think we've heard that one before a few times, haven't we?
DAVE BITTNER
So related to all of this, I think it's worth mentioning that there is a huge amount of pushback against these Flock cameras here in the States right now.

There are municipalities who have had contracts with them and are cancelling the contracts.
Unknown
Yeah.
DAVE BITTNER
There is a story from a police organisation in Illinois where the former police chief and two of the other high-level police people in this police force were using the town's Flock licence plate cameras to monitor the police chief's ex-wife.

He had instructed other officers to track her, allegedly. The state police confirmed there's an active investigation into the matter.

Again, obviously all alleged, but these three police officers resigned from the force when this information came out. So again, there's a lot of pushback.

People feel as though this has gone a little too far, that our locations are being tracked. That the information is accessible without a warrant by police officers.

So I think the folks who make the Flock cameras have been set back on their heels a little bit at the amount of pushback there is.

And now to add on to that, these reports of how insecure and easy to hack both their cameras are and their central servers.
GRAHAM CLULEY
It's what we like to call an omni-shambles, isn't it? I like that. I like that.
DAVE BITTNER
I'm going to steal that, Graham. Omni-shambles. I like that. That has a nice ring to it.
GRAHAM CLULEY
Yeah. These are devices which, sometimes it is argued, they are being introduced into society in order to protect us, to make us feel more secure.

But in fact, they're either being abused or they are themselves insecure in their very nature in the first place.
DAVE BITTNER
And to be fair, law enforcement will say this is a powerful tool for them to be able to solve crimes. And there's no question that that's true.

It's just a matter of how much are we all willing to give up in order to do that? And that's the unresolved question so far, but it's moving rapidly.
GRAHAM CLULEY
This episode of Smashing Security is brought to you by ThreatLocker.
JOE
Agentic AI is changing the speed of cyberattacks, Graham.
GRAHAM CLULEY
Yes, I read about that too. Self-directing ransomware, AI worms that adapt as they go, agents chaining tools together with no human anywhere near the controls.
JOE
So basically, the attackers have automated their way to a 4-day workweek and the rest of us haven't.
GRAHAM CLULEY
When enumeration, exploitation, and lateral movement happen at machine speed, plans like, oh, we'll catch it when someone checks their alerts, they begin to fall apart.
JOE
Like most incident response plans, then. Great in the slide deck, less great at 3 AM.
GRAHAM CLULEY
ThreatLocker puts default deny and least privilege between the agent and its next move. Application allowlisting decides what's allowed to run at all.

Ringfencing limits what trusted applications can reach or launch, and privileged access management takes away elevation the agent never needed in the first place.
JOE
So speed's not the problem anymore. Getting through the door is.
GRAHAM CLULEY
So get ahead of machine speed attacks with ThreatLocker. Head to threatlocker.com/smashing to find out more and book your free demo.
JOE
That's threatlocker.com/smashing. Thanks to ThreatLocker for supporting the show and for doing the fast bit so we don't have to.
GRAHAM CLULEY
And welcome back. Can you join us at our favourite part of the show? The part of the show that we like to call Pick of the Week. Pick of the Week.
DAVE BITTNER
Pick of the Week.
GRAHAM CLULEY
Pick of the Week is the part of the show where everyone chooses something they like.

It could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.

It doesn't have to be security-related necessarily. Better not be. Now, Dave, I wonder if, like me, you are a fan of the movie La La Land.
DAVE BITTNER
Uh, I—
GRAHAM CLULEY
Oh, hang on. There was a pause.
DAVE BITTNER
I have watched La La Land twice, I believe.
Unknown
Oh.
DAVE BITTNER
I enjoyed watching La La Land. I will say I did not go gaga for La La the way many other people did. And this is surprising for me because I love a musical.
GRAHAM CLULEY
Yes. Love a musical.
DAVE BITTNER
For whatever reason, it just didn't resonate with me the way it did with other people, but that's okay. That's just me.

I have no doubt this is a wonderful movie, and clearly people love it, so good on them.
GRAHAM CLULEY
I think you're a bit more of a Seven Brides for Seven Brothers kind of thigh-slapping style musical fan, right?
DAVE BITTNER
That's true. Yes. Give me The Music Man or Singin' in the Rain, and I'm happy as a clam.
DAVE BITTNER
Okay.
DAVE BITTNER
All right.
GRAHAM CLULEY
Well, I love La La Land. If you haven't seen it, of course, it was the movie which had the Best Picture Oscar cruelly ripped from its paws back in 2017.

If you haven't seen it, unlike Dave, who I'm beginning to question his judgement, I think you should go and watch it.

Tell me if you like it, and if you didn't like it, unsubscribe from Smashing Security immediately. Go on, clear off, clear off the lot of you.

Well, no, no, no, no, no, no, no, no, no, no, come. Come back. Didn't mean it.
DAVE BITTNER
Oh my! I think what am I not going to be invited back anymore?
GRAHAM CLULEY
Dave, don't leave just yet. You've got a few more minutes to go. All right. Anyway, if any of you are still listening, I love La La Land.

I could watch it on a loop, and my pick of the week this week is a website that is La La Land related.

So I've stumbled across a website called seeing-stars.com, and it's done something brilliant. They have tracked down literally every single filming location used in the movie.

So there's a real spot in Boulder City, Nevada, where Ryan Gosling goes to pick up Emma Stone when he visits her in her hometown.

There's a pier where he sings City of Stars to an old married couple and dances with the wife. There's the famous observatory.

I think it's in Rebel Without a Cause as well, or some James Dean movie.
Unknown
Yeah.
GRAHAM CLULEY
Where they have their dreamy planetarium dance scene.

There's even tiny little throwaway moments, which may just be on the screen for a second, like a parking lot that Emma Stone walks through for an audition.

So this isn't a brief list. This is every single location throughout the movie. This La La Land lunatic has watched the movie with his pause button.

He's worked out where everything was taken.
DAVE BITTNER
Right.
GRAHAM CLULEY
It's extraordinary. And he's posted alongside the screencaps, real photos, map links, Street View. He's given a narrative as well.

There are so many pages of this, and I found myself trawling through this and I thought, you know what? This is the kind of obsessiveness I want to see on the internet.

This is like the old days. There used to be lots of bonkers sites like this.
DAVE BITTNER
Yes.
GRAHAM CLULEY
Labours of love.
DAVE BITTNER
Yes, I agree.
GRAHAM CLULEY
And I don't think anyone's got enough time really these days. It doesn't feel like anyone's actually putting the effort into building something.

This was definitely not created — if you haven't seen La La Land, go watch La La Land for goodness' sake.

But also, after watching it, you might want to go and check out this website.

The other thing is, if La La Land isn't your thing, the same guy has documented all of the locations used in the Dexter TV series. You must know that one.

That's that family show about what a police blood spatter expert gets up to in his free time.
DAVE BITTNER
Lovely little lighthearted jaunt. Yes.
GRAHAM CLULEY
Yes, exactly. So La La Land on one side, Dexter on the other. You can take your pick and go and check out the locations.
DAVE BITTNER
I love this kind of thing. Yeah, this is great fun.
GRAHAM CLULEY
That is my pick of the week. Dave, what's your pick of the week?
DAVE BITTNER
Well, Graham, how do I say this?
GRAHAM CLULEY
Goodbye. That's right.
DAVE BITTNER
I grew up in a household that did not have a lot of musical sophistication. Let's put it that way.

My parents, who were children of the '50s, not the '60s, which meant they were more Frank Sinatra than the Beatles.
Unknown
Okay.
Unknown
Okay.
DAVE BITTNER
Yeah.
DAVE BITTNER
When I was a young lad, my father would be down in his workshop doing little projects, and I would be down in the basement playing with my Matchbox cars or my Legos.
GRAHAM CLULEY
Can I just check? He wasn't a blood splatter expert working for the police, was he?
DAVE BITTNER
He was not. No, no, no, no, no.
DAVE BITTNER
Okay.
GRAHAM CLULEY
Just clearing that up.
DAVE BITTNER
No, no, no. On the 8-track tape player —
Unknown
Ooh-hoo!
DAVE BITTNER
Yeah. I can still hear the clunk-clunk sound when it would switch tracks. On the 8-track tape player, he would often have an 8-track of the Ray Conniff Singers.
GRAHAM CLULEY
Right.
DAVE BITTNER
Now, Graham, I don't know if you are lucky enough to know who the Ray Conniff Singers are.
GRAHAM CLULEY
I'm not.
DAVE BITTNER
I put a link in here just for you of them doing their rendition —
GRAHAM CLULEY
Hey Jude, don't make it bad. Okay, that's horrible. Yes, it is.
DAVE BITTNER
Yes, it is.

So for those who aren't familiar, the Ray Conniff Singers was just a group of vocalists, and they would take popular songs of the day, and they would get together as a choir, and they would sing the songs with an orchestral accompaniment.

And it was just completely benign, right?
GRAHAM CLULEY
It was awful. It was, it was.
DAVE BITTNER
But this was the soundtrack of my childhood, right?
GRAHAM CLULEY
Oh, bless.
DAVE BITTNER
So I heard this kind of thing over and over again. So this was my introduction to a lot of popular songs, was the Ray Conniff Singers cover version of it.
Unknown
Oh.
DAVE BITTNER
Yeah. We didn't have any Beatles albums growing up. Not a one.
DAVE BITTNER
Yeah.
DAVE BITTNER
So I say that as introduction to why I have great affection for a documentary that I came across recently. It's called Let's Have a Party: The Piano Genius of Mrs. Mills.

Graham, are you familiar with Mrs. Mills?
GRAHAM CLULEY
I am familiar with Mrs. Mills, yes.
DAVE BITTNER
She is from your neck of the woods.
GRAHAM CLULEY
Yeah, she was a British lady who could sort of stomp things out on the old piano, on the old Joanna.
DAVE BITTNER
That's right. That's right.
GRAHAM CLULEY
She was very talented. She wasn't your typical sort of celebrity starlet. She wasn't what I would call glamorous.
DAVE BITTNER
No, no, no.
GRAHAM CLULEY
She was one of us.
DAVE BITTNER
She was a mom, yeah.
GRAHAM CLULEY
Yes.
DAVE BITTNER
But she could play. She had her own distinct style.
Unknown
Yeah.
DAVE BITTNER
I would categorize it as being kind of sing-along music, right?
GRAHAM CLULEY
Yes.
DAVE BITTNER
This comes from the era before recorded music, when everyone could play piano, and the way people would entertain themselves at a party or in a pub was that someone would sit down and play a few tunes, and everyone would have a few drinks and sing along.
GRAHAM CLULEY
Which sounds bloody marvellous to me. And I think that's exactly the way I think about her as well.

It's the kind of roll-out-the-barrel music you can imagine in the corner of the pub.
DAVE BITTNER
Exactly.
GRAHAM CLULEY
Stomping out a song, people holding their glasses of beer, enjoying the evening, singing along.
DAVE BITTNER
Exactly. And so, for me, discovering Mrs. Mills has been opening up an entire new category of musical comfort food.
GRAHAM CLULEY
Right.
DAVE BITTNER
Because of the hardwiring of the awful Ray Conniff Singers in my brain when I was a child, Mrs. Mills just slots right in there and I love it to death.
GRAHAM CLULEY
And she didn't sing, did she? Unlike the Ray Conniff Singers who shouldn't have sung.
DAVE BITTNER
She did not sing, but there were singers on her albums and sometimes on her albums it would be the entire bar who would be singing along.
GRAHAM CLULEY
Right.
DAVE BITTNER
So I made the mistake of tracking down some of her things in my iTunes app, which means now she's in the rotation.
GRAHAM CLULEY
The algorithm has learned about you, Dave.
DAVE BITTNER
There's no getting rid of me. So I've left a link to Let's Have a Party: The Piano Genius of Mrs. Mills, which is a BBC documentary.

But Graham, there's a particular thing in here that made me realise that this was the perfect thing to have as my pick of the week just for you, because Mrs.

Mills' piano is at Abbey Road Studios. To this day, her piano is there, and her piano was used by the Beatles.
GRAHAM CLULEY
It was. And Dave, hold on to your seat. I have actually seen Mrs. Mills's piano.
DAVE BITTNER
Get out!
GRAHAM CLULEY
I really have, because I was very lucky a few years ago to actually go into Abbey Road and into Studio 2, which is the famous studio where the Beatles recorded a lot of their songs, the one with the stairs going down the side.
Unknown
Yeah.
GRAHAM CLULEY
And that piano is still there. They didn't let us play it.
Unknown
Okay.
GRAHAM CLULEY
But yeah, so many amazing songs.

I think maybe With a Little Help from My Friends and Ob-La-Di, Ob-La-Da with that digga digga ding ding ding at the beginning — that's all on the Mrs. Mills piano.
DAVE BITTNER
Yes. So I've included a link here from Abbey Road that has a picture of, I think, Paul and John seated at Mrs. Mills' piano. The legend goes on beyond Mrs. Mills herself.
GRAHAM CLULEY
Her piano will live forever through the music of the Beatles, because she was signed by Parlophone. She was on the same record label as the Beatles.
DAVE BITTNER
This woman made a solid living playing piano. Her albums were hits just by going right down the centre. That is my pick of the week.
GRAHAM CLULEY
This is fantastic. I'm definitely going to check out that documentary. I love that. Well, that just about wraps up the show for this week. Thank you so much, Dave, for joining us.

Maybe you can tell our listeners where they can follow you online and find out what you're up to. What's the best way for them to do that?
DAVE BITTNER
Just go to our website, thecyberwire.com, and you'll find all of my shows there.
GRAHAM CLULEY
Terrific stuff. And of course, you can find me, Graham Cluley, on LinkedIn, Bluesky, Mastodon, Instagram, and even the Tok of Tik. The list goes on.

And you can also follow Smashing Security on Bluesky, Mastodon, and Reddit. Don't forget to ensure you never miss another episode.

Follow Smashing Security in your favourite podcast apps such as Apple Podcasts, Spotify, and Pocket Casts.

And you can look for our show notes, sponsorship info, guest list, and the entire back catalogue of 486 episodes at smashingsecurity.com.

Until a couple of weeks, not next week, the week after. Cheerio. Bye-bye.
Unknown
Bye-bye.
GRAHAM CLULEY
You've been listening to Smashing Security with me, Graham Cluley, and a huge thank you to Dave Bittner for joining me this week and this week's sponsors ThreatLocker, Origin, and Vanta.

Do make sure to go and check out their offerings because they help keep the show afloat.

Now, chums, according to the limited stats I get to see as to our listenership, the vast majority of you appear to be male.

However, we do have a marvellous cohort of female listeners too, and some of them have been kind enough to become members of Smashing Security Plus. So I thought, you know what?

Let's give some of them a nice shout out today. So kicking us off are Jessica Orth, Lisa, and Sharon — three fine chums, not putting up with any nonsense.

A big huzzah to Sharon, a name which resembles that satisfying crisp click that you might get when closing the lid of a brand new laptop.

The legendary Maya MacDonald, the beautifully double-barrelled Adena Bogut O'Brien, and Jane with a Y, because why not?

Big love as well to The Green Girl, our most colour-coordinated patron, and to the delightfully whimsical Butterfly Skies. Thank you. And finally for this week, Frankie Guzikowski.

Frankly, Frankie can be a boy's name or a girl's name. I'm not sure which way our Frankie leans.

But anyway, these fine, upstanding, generous individuals are all members of Smashing Security Plus, which means they get their episodes ad-free earlier than the general public, and perhaps most importantly, have the opportunity to have their names pulled out of the hat at the end of the show and read out for mild ridicule.

Curated by myself.

If you would like to join them in this exclusive club of the wonderful and slightly foolish, just head over to smashingsecurity.com/plus, where for a modest fee, you too can support the podcast.

You can support us in other ways as well. You can write a review; those are always lovely. You can like, you can subscribe, and you can tell your friends about us.

Go on, go and find a chum. Collar them and say, you know what? You really should listen to Smashing Security.

Well, thanks to all of you who support the show, and I'll be back for another episode on October the 8th. So make sure to tune in then. Until then, cheerio. Bye-bye.
DAVE BITTNER
Bye-bye.

Host:

Graham Cluley:

Guest:

Dave Bittner:

Episode links:

Sponsored by:

  • Vanta – Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
  • Origin – Endpoint AI observability. Put your AI agent on the record, and request a demo.
  • ThreatLocker – Book a demo today and start securing your organisation.

Support the show:

You can help the podcast by telling your friends and colleagues about “Smashing Security”, and leaving us a review on Apple Podcasts or Podchaser.

Join Smashing Security PLUS for ad-free episodes and our early-release feed!

Follow us:

Follow the show on Bluesky, or join us on the Smashing Security subreddit, or visit our website for more episodes.

Thanks:

Theme tune: “Vinyl Memories” by Mikael Manvelyan.
Assorted sound effects: AudioBlocks.


Graham Cluley is an award-winning keynote speaker who has given presentations around the world about cybersecurity, hackers, and online privacy. A veteran of the computer security industry since the early 1990s, he wrote the first ever version of Dr Solomon's Anti-Virus Toolkit for Windows, makes regular media appearances, and hosts the popular "Smashing Security" podcast. Follow him on TikTok, LinkedIn, Bluesky and Mastodon, or drop him an email.

What do you think? Leave a comment

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.