1
00:00:00,999 --> 00:00:08,920
This week, Surveillance Support covers the most severe Linux threat in years that has sent researchers and distributions scrambling.

2
00:00:09,480 --> 00:00:14,300
Apple is patching that weird bug that police were using to extract deleted signal messages from iPhones.

3
00:00:14,940 --> 00:00:20,020
Utah has this new weird law regulating VPNs and trying to make those much harder to access.

4
00:00:20,540 --> 00:00:24,360
And Microsoft Edge just wants to store all your passwords in plain text memory.

5
00:00:24,670 --> 00:00:26,580
Just typical Microsoft shenanigans.

6
00:00:26,980 --> 00:00:31,080
Welcome to the Techlore Surveillance Report, your essential weekly tech news where I deliver

7
00:00:31,230 --> 00:00:35,900
deep analysis on the latest threats to security, privacy, and digital freedom, empowering you

8
00:00:35,930 --> 00:00:40,900
to reclaim control and defend your rights. My name is Henry. And a quick note before we get

9
00:00:41,010 --> 00:00:45,180
into the news, just have a quick announcement. I owe you all a pretty big apology here as this

10
00:00:45,410 --> 00:00:49,140
episode is landing way later than it should have. We've been working on some big projects back here.

11
00:00:49,210 --> 00:00:53,180
We are a two-person team. And a lot of times when we put more emphasis on those, it's really hard

12
00:00:53,200 --> 00:00:57,720
to keep up with this, the anchors that we have. Now we've done some restructuring back here to

13
00:00:57,740 --> 00:01:01,320
make this a little bit better. So going forward, I want to really emphasize that consistency a bit

14
00:01:01,460 --> 00:01:04,739
more. And I just wanted to get something out this week. And so today's episode is a little bit

15
00:01:05,040 --> 00:01:09,400
lighter. I'm just going to cover the most major stories. That way we can at least get this news

16
00:01:09,500 --> 00:01:14,740
out and get back on track. Let's start with two really crazy Linux stories. The first one being

17
00:01:14,880 --> 00:01:20,140
the most severe Linux threat to surface in years. Now, if you're reading news or you keep up with

18
00:01:20,100 --> 00:01:24,360
this kind of stuff, the way that this attack is overall referred to is called copy fail,

19
00:01:24,530 --> 00:01:31,100
which is one word. Now, the overall idea of this is that it gives an attacker root access to Linux

20
00:01:31,360 --> 00:01:36,740
machines quite without many restrictions. It's quite interesting. Now, what copy fail does,

21
00:01:36,980 --> 00:01:41,260
it's described as a critical flaw. It's a local privilege escalation, which is a vulnerability

22
00:01:41,660 --> 00:01:45,980
class that allows unprivileged users to elevate themselves to administrators. The example they use

23
00:01:45,980 --> 00:01:50,060
here is that an attacker exploits a known WordPress plugin vulnerability, which we cover

24
00:01:50,080 --> 00:01:54,760
on a weekly basis at this point, and then it gets shell access. They run this copy-fail proof of

25
00:01:55,100 --> 00:01:59,100
concept, and they are now root on the host. The way the researchers described this is the

26
00:01:59,340 --> 00:02:03,960
vulnerability does not get the attacker onto the box. It changes what happens in the next 10 seconds

27
00:02:04,260 --> 00:02:09,100
after they land there. So if this was combined with another vulnerability, it can just take over

28
00:02:09,240 --> 00:02:13,660
your machine, which is quite scary. I really want to outline a little bit of the drama around how

29
00:02:13,840 --> 00:02:16,980
this came to light because it's quite relevant to the story. Because normally the way that

30
00:02:17,000 --> 00:02:21,940
disclosure works. If I am a security researcher and I'm investigating a piece of software and

31
00:02:22,150 --> 00:02:27,260
I find something critically wrong with it, what is typically considered reasonable slash proper

32
00:02:27,420 --> 00:02:32,180
disclosure is I reach out to the affected software vendor, I work with them directly,

33
00:02:32,680 --> 00:02:39,460
and then they ideally issue a patch before the public finds out. So that way it's kept low-key

34
00:02:39,910 --> 00:02:44,200
and attackers can't exploit whatever that security researcher found, assuming they didn't already

35
00:02:44,220 --> 00:02:49,220
find it. Now, this didn't quite work that way. A vulnerability analyst here that I'm showing on

36
00:02:49,220 --> 00:02:53,540
the article on screen if you're on video, but their name is Will Dorman, said that this org

37
00:02:53,740 --> 00:02:59,320
doing the disclosure did an absolutely terrible job of vulnerability coordination because at the time

38
00:02:59,380 --> 00:03:05,120
of making this video, not every Linux distribution is actually patched. Now, they did disclose this

39
00:03:05,360 --> 00:03:09,819
weeks before to the Linux kernel security team, and they actually patched that vulnerability in

40
00:03:09,840 --> 00:03:14,620
the Linux kernel itself. The problem is that few of the Linux distributions, which are downstream

41
00:03:14,980 --> 00:03:18,660
of the Linux kernel and need to actually integrate the Linux kernel into their operating systems,

42
00:03:18,820 --> 00:03:23,100
actually incorporated those fixes. Now, this Ars Technica coverage happened last week,

43
00:03:23,500 --> 00:03:28,940
and at that time, the only people who actually patched this were Arch Linux, Red Hat, Fedora,

44
00:03:29,500 --> 00:03:34,500
SUSE, and Ubuntu. That was kind of it. And so if you had any other distro, it wasn't really known

45
00:03:34,540 --> 00:03:37,379
if you were patched. Now, if you're using a different distro from one of those, it's really

46
00:03:37,400 --> 00:03:42,300
important to check your distro and see if they have patched this issue. Now, before I share a few

47
00:03:42,420 --> 00:03:47,140
more of my takeaways, I wanted to also share this story as well, which came out a few days before

48
00:03:47,310 --> 00:03:51,440
that last one, which is there was an open source package with 1 million monthly downloads that stole

49
00:03:51,610 --> 00:03:56,760
user credentials. This is a command line interface for a piece of software called Element Data. And

50
00:03:56,880 --> 00:04:00,900
what this tool does is it helps users monitor performance anomalies in machine learning systems.

51
00:04:01,060 --> 00:04:05,719
It's a very niche tool, but it clearly has a lot of downloads. The developer account was taken over

52
00:04:05,720 --> 00:04:09,080
and they published a compromised version of the piece of software.

53
00:04:09,370 --> 00:04:11,020
You might be wondering, Henry, what's my takeaway?

54
00:04:11,050 --> 00:04:15,320
Well, first off, I just want to zoom out and say that vulnerabilities happen on every operating system,

55
00:04:15,430 --> 00:04:18,420
so this isn't a Linux-inherent issue, and it goes all directions.

56
00:04:18,920 --> 00:04:25,320
And I think that it's also important to debunk the myth that just being on Linux is inherently crazy secure.

57
00:04:25,820 --> 00:04:29,060
Now, I do think Linux has a ton of benefits from an open-source perspective,

58
00:04:29,280 --> 00:04:32,280
from a transparency perspective, from a philosophy perspective,

59
00:04:32,700 --> 00:04:34,780
from also sometimes just a usability perspective.

60
00:04:34,800 --> 00:04:41,360
I understand why someone would want to use Linux over Windows or macOS, especially Windows with how that whole world is going right now.

61
00:04:41,360 --> 00:04:43,440
I don't need to expand further than that.

62
00:04:44,280 --> 00:04:50,920
But I think it's really important to challenge this overall conception that if you're on Linux, you're resistant to every attack out there.

63
00:04:51,000 --> 00:04:51,580
That's just not true.

64
00:04:51,620 --> 00:04:54,160
We've seen really severe exploits in the Linux world.

65
00:04:54,200 --> 00:05:03,480
And because Linux is just overall this ecosystem of hundreds of different distributions, and it requires more to fix these kind of issues.

66
00:05:03,660 --> 00:05:09,340
If Apple catches something like this, they just roll out an update to all their devices and everybody has the update.

67
00:05:09,510 --> 00:05:14,660
But with this, it's a little bit harder to do that because it reflects the openness that is the Linux ecosystem.

68
00:05:14,770 --> 00:05:22,640
And so whatever distro you're on, it's really important to just do a quick web search and just type in copy fail and then your distro name.

69
00:05:23,140 --> 00:05:28,780
And you should get some kind of coverage or some kind of community response to whether or not they have patched this.

70
00:05:29,080 --> 00:05:41,820
And I have no issue saying if your Linux distro of choice hasn't made any kind of public statement and isn't communicating this issue to their users, I would genuinely flag that as a real concern and reconsider your Linux distribution of choice.

71
00:05:42,040 --> 00:05:43,880
This might sound harsh, but it's for two reasons.

72
00:05:44,070 --> 00:05:48,800
One, these are the developers pushing code to your machines, and it's partly their responsibility to keep you safe.

73
00:05:48,890 --> 00:05:56,140
And so if your safety isn't a number one concern to them, I would argue that's already sacrificing a major value that a Linux distro is supposed to provide.

74
00:05:56,660 --> 00:06:25,480
The other thing is that I think that reflects an overall communication pattern of a project. And so if this project that you're using day to day, if they're not responding to an issue this massive, are they going to respond to an even larger issue? Are they going to respond to their accounts getting compromised? So these are things that I would be thinking about personally. I know the Linux world has everything from Hannah Montana OS to Red Star OS to actually really legitimate operating systems used day to day to the servers that you connect to.

75
00:06:25,720 --> 00:06:30,500
So there is literally the craziest stuff out there to the most legit stuff out there.

76
00:06:30,570 --> 00:06:34,960
And so I just want to make sure people are aware of that spectrum when they're moving over to a Linux distro.

77
00:06:35,290 --> 00:06:40,020
And to also make sure that you're updating your software and actually getting the latest security updates along the way.

78
00:06:40,220 --> 00:06:43,600
It was also quite disappointing for me to read the way that this was disclosed

79
00:06:43,980 --> 00:06:47,920
and how there wasn't enough time given to some of these Linux distributions to actually patch the issue.

80
00:06:48,300 --> 00:06:54,180
But I was still happy to see some of these major distros, a lot of which we recommend back here, did patch this quite quickly.

81
00:06:54,360 --> 00:06:56,080
So those are kind of my initial thoughts there.

82
00:07:02,160 --> 00:07:06,860
All right, coming soon, we have Utah's new law regulating VPNs, which is crazy.

83
00:07:07,020 --> 00:07:08,420
And we'll talk about what to do there.

84
00:07:08,580 --> 00:07:12,120
We also have Microsoft Edge literally saving your passwords in plain text on your computer.

85
00:07:12,540 --> 00:07:14,520
Just typical Microsoft stuff lately.

86
00:07:15,060 --> 00:07:17,220
But before we get there, very quick signal boost.

87
00:07:17,400 --> 00:07:25,980
We talked recently, I think on the last surveillance report, about how there was essentially this bug slash issue, whatever you want to call it, this problem.

88
00:07:26,610 --> 00:07:36,320
I don't know how you want to describe this issue, but pretty much there was a court case that came out that revealed that there was a user that was being investigated using the Signal Messenger, the end-to-end encrypted messenger.

89
00:07:36,640 --> 00:07:45,700
And pretty much they already deleted the whole Signal app before the law enforcement agents started trying to break into the phone and trying to get access to those messages.

90
00:07:46,140 --> 00:07:54,840
Pretty much, they were actually able to intercept messages retroactively, even though the Signal app was completely deleted, because of notifications on iOS.

91
00:07:55,280 --> 00:08:03,360
Essentially, the operating system, only on iOS, was caching all the notification content locally, even for apps that were already deleted.

92
00:08:03,940 --> 00:08:05,760
So that was a pretty serious problem.

93
00:08:06,060 --> 00:08:06,940
A lot of people were concerned.

94
00:08:07,070 --> 00:08:09,040
We got a huge amount of questions about this.

95
00:08:09,110 --> 00:08:11,200
And so I did do coverage for that back then.

96
00:08:11,480 --> 00:08:15,620
But the real update here is that you can just update your iPhone to the newest version.

97
00:08:15,900 --> 00:08:18,320
and that will even retroactively fix the problem.

98
00:08:18,740 --> 00:08:20,880
And so even if your iPhone has been collecting

99
00:08:21,160 --> 00:08:23,180
all of your notification content the last 10 years,

100
00:08:23,620 --> 00:08:25,700
the moment you update to the latest version of iOS

101
00:08:25,860 --> 00:08:26,700
from a couple weeks ago,

102
00:08:26,860 --> 00:08:27,960
I know we're a little late on this,

103
00:08:28,080 --> 00:08:29,120
this is resolved now.

104
00:08:29,540 --> 00:08:31,620
And I think they also pushed out this update

105
00:08:31,900 --> 00:08:33,620
to iOS 18 as well.

106
00:08:33,680 --> 00:08:35,460
So you didn't even have to go to iOS 26

107
00:08:35,700 --> 00:08:37,599
to still get that update on some older devices

108
00:08:37,900 --> 00:08:40,780
or if for whatever reason you don't want to go to iOS 26.

109
00:08:41,320 --> 00:08:42,380
So this is a quick signal boost

110
00:08:42,560 --> 00:08:44,159
and it's good to see Apple address this

111
00:08:44,180 --> 00:08:45,960
because they don't always address things like this.

112
00:08:52,120 --> 00:08:57,940
All right, so we are now going to talk about this new law that came out of Utah, the land of freedom.

113
00:08:58,860 --> 00:09:03,740
It is called SB 73. You can read this yourself. I am showing it here on screen and what it looks

114
00:09:03,920 --> 00:09:07,560
like. But of course, you can always find this in the show notes down in the description if you want

115
00:09:07,560 --> 00:09:12,420
to actually read the bill for yourself. I will be doing a dedicated video on this to dive into it a

116
00:09:12,420 --> 00:09:15,880
little bit more. So stay subscribed if you want to see that. It should go live in the next day or so.

117
00:09:16,400 --> 00:09:22,520
So pretty much this law builds off of the 2023 law that was their adult content kind of law.

118
00:09:22,860 --> 00:09:26,240
Now, this has been happening all around the world for a little bit of context. We see all these

119
00:09:26,430 --> 00:09:31,700
countries and states that are trying to target age verification slash adult content websites in the

120
00:09:31,800 --> 00:09:38,799
name of keeping children safe, adults safe. It's a bit unclear. And I still haven't really gotten a

121
00:09:38,820 --> 00:09:45,200
really good answer as to what the real intention and the real proven benefits are to these kind of

122
00:09:45,760 --> 00:09:52,360
things. And it's hard to see this in any kind of optimistic way for me. Now, a big problem for this

123
00:09:52,440 --> 00:09:57,080
is that even if we could get a good answer out of these politicians and the people really promoting

124
00:09:57,280 --> 00:10:01,820
this stuff, implementing this is very hard and it's quite challenging because of the way the

125
00:10:01,960 --> 00:10:07,579
internet works, right? If Utah's blocking something, but California isn't, someone could just use a

126
00:10:07,540 --> 00:10:13,240
California-based VPN or even just a VPN based out of Utah, but that has servers in California

127
00:10:13,760 --> 00:10:18,020
and just access the site anyway, right? Like the internet is really hard to censor in the way that

128
00:10:18,020 --> 00:10:24,700
they're trying to do. So this already happened yesterday, May 6th. This law was passed that now

129
00:10:25,100 --> 00:10:31,360
puts VPNs in the crosshairs of Utah. And the craziest thing is this doesn't just impact you

130
00:10:31,480 --> 00:10:37,500
people in Utah because the law puts the liability on the adult content websites to age check Utah

131
00:10:37,500 --> 00:10:43,340
users to fully comply. This means that a website has to verify the ages of every visitor regardless

132
00:10:43,420 --> 00:10:48,520
of where their IP address says they're located. So theoretically, if any of you are using a

133
00:10:48,760 --> 00:10:53,940
California-based IP regardless of where you come from, NSFW website doesn't know if you're a Utah

134
00:10:54,220 --> 00:10:58,220
resident or not. So they still have to figure out where you're actually residing somehow.

135
00:10:59,100 --> 00:11:04,040
Somehow, I don't know. The same law also prohibits adult content websites from sharing instructions

136
00:11:04,040 --> 00:11:09,980
on how to use a VPN, and it creates a 2% tax for transactions on online pornography websites.

137
00:11:10,560 --> 00:11:15,060
It's actually quite interesting because here is a direct quote from a Republican sponsor of the

138
00:11:15,140 --> 00:11:19,580
law, which is Senator Calvin Musselman, I believe is how you say his last name. He said, quote,

139
00:11:19,780 --> 00:11:25,200
protecting kids while preserving freedom is not a new concept. SB 73 is about accountability,

140
00:11:25,580 --> 00:11:30,120
requiring companies that profit from material harmful to minors to take reasonable steps to

141
00:11:30,080 --> 00:11:34,600
help prevent access by children. Now, before I continue on what he said next, which I think is

142
00:11:34,800 --> 00:11:38,200
actually the crazier part, I think it's really important to clear something up, and at least my

143
00:11:38,310 --> 00:11:43,680
stance on this, which is I would argue this is not preserving freedom. This isn't preserving freedom

144
00:11:44,280 --> 00:11:50,320
for even people outside of Utah. Someone should have the freedom to access content and be able

145
00:11:50,420 --> 00:11:56,180
to do it in a privacy-respecting way, and there is no privacy-respecting way to do this. This isn't

146
00:11:56,200 --> 00:12:01,360
preventing access to just children is preventing access to adults as well. So this is inherently

147
00:12:01,800 --> 00:12:07,040
not preserving freedom for everybody along the way. This is kind of the difficulty with trying

148
00:12:07,040 --> 00:12:11,560
to navigate this really touchy subject. Now, here's where I think it gets crazy. And this is

149
00:12:11,660 --> 00:12:16,580
where I think there's a technical gap or a intentional or unintentional understanding of

150
00:12:16,660 --> 00:12:23,839
what this technology looks like. He says websites could, with a C, could, not should, could have a

151
00:12:23,860 --> 00:12:28,800
process for users to verify their age or confirm which state they're in, quote, while still

152
00:12:29,220 --> 00:12:33,840
preserving the encryption options for users. Now, I've been doing this for over 10 years.

153
00:12:33,860 --> 00:12:40,260
I've gone through all these marketing slogans like military-grade encryption and anonymous data,

154
00:12:40,540 --> 00:12:44,820
like anonymizing data sets and this kind of nonsense that is really hard to actually prove.

155
00:12:45,120 --> 00:12:48,680
There's all these marketing phrases that are used. And this man just goes out and throws out

156
00:12:48,860 --> 00:12:53,260
preserving the encryption options for users. This is the kind of person who's going to say,

157
00:12:53,440 --> 00:12:57,620
Well, they used HTTPS on the website when you uploaded your ID, so it's encrypted.

158
00:12:57,780 --> 00:13:02,340
And it's like, well, that's just the data in transit to make sure there's no middleman

159
00:13:03,200 --> 00:13:05,940
that's actually intercepting that ID that you're uploading.

160
00:13:06,140 --> 00:13:08,600
What are those encryption options that you're talking about?

161
00:13:08,860 --> 00:13:12,660
There is absolutely no discussion right now about even zero-knowledge proofs really in

162
00:13:12,660 --> 00:13:12,960
the US.

163
00:13:13,540 --> 00:13:14,640
That's kind of happening in Europe.

164
00:13:14,780 --> 00:13:16,180
I did some coverage for that recently.

165
00:13:16,920 --> 00:13:20,640
That is at least a step in the right direction, but that still calls into question the freedom

166
00:13:20,640 --> 00:13:25,260
of information, even when it's done properly in a privacy and security respecting way that's open

167
00:13:25,500 --> 00:13:29,380
source. None of these US politicians that I've seen are actually proposing this. They're just saying,

168
00:13:29,740 --> 00:13:34,440
yeah, you know, these websites got to figure out it's their problem. But them trying to offload

169
00:13:34,900 --> 00:13:40,660
all of that responsibility onto a provider is also jeopardizing all users and their data along the

170
00:13:40,780 --> 00:13:44,700
way. And it's very reckless. If they are going to pass this, which I don't agree with, by the way,

171
00:13:44,740 --> 00:13:49,000
I don't agree with age verification in the first place. But even if I was in support of age

172
00:13:49,020 --> 00:13:54,340
verification, I would still be a big proponent of finding out a way to do it safely so that it's not

173
00:13:54,400 --> 00:13:59,080
just going to chuck a ton of users' data out into the ether with no regulation and no thought behind

174
00:13:59,240 --> 00:14:03,160
it, which is what this guy is saying when he's saying, oh, yeah, people could preserve the

175
00:14:03,320 --> 00:14:07,940
encryption options for users. Like, yeah, I really hope that websites asking for my ID are actually

176
00:14:08,080 --> 00:14:12,420
using a proper SSL certificate. That's a good starting point. Thank you, Mr. Musselman. I'm

177
00:14:12,480 --> 00:14:16,020
getting really angry talking about this. Stay subscribed if you want to see more coverage for it.

178
00:14:16,420 --> 00:14:18,380
I'm sure I'll make a dedicated video on it coming soon.

179
00:14:24,580 --> 00:14:27,540
Okay, this is a pretty wild ride from Microsoft.

180
00:14:27,800 --> 00:14:29,940
I swear, every week that we do this podcast,

181
00:14:30,340 --> 00:14:31,600
Microsoft does something else that just,

182
00:14:31,800 --> 00:14:33,880
it just makes me question what they're thinking back there.

183
00:14:34,020 --> 00:14:36,100
And every time I'm like, well, this can't get worse,

184
00:14:36,240 --> 00:14:37,180
it somehow gets worse.

185
00:14:37,420 --> 00:14:39,500
So Microsoft Edge, which is the default browser

186
00:14:39,640 --> 00:14:41,640
that Microsoft tries to shove down everybody's throat,

187
00:14:41,820 --> 00:14:43,620
that's not even an opinion, that is a fact.

188
00:14:43,760 --> 00:14:46,120
Every update, there has been reports from the Mozilla team,

189
00:14:46,180 --> 00:14:51,640
They've done studies now that show all the dark patterns that Microsoft does on Windows to try to get you to use Edge.

190
00:14:52,060 --> 00:14:55,420
It can even undo your default browser during some updates.

191
00:14:55,640 --> 00:14:56,360
It's crazy.

192
00:14:56,620 --> 00:15:07,200
But yes, that browser they're trying to shove down your throat apparently has been saving all of your passwords in the password to your device's memory and doing it in plain text.

193
00:15:07,580 --> 00:15:11,060
Now, I'm going to say Tom because I don't know how to pronounce the letter O with a line through it.

194
00:15:11,180 --> 00:15:12,620
That is a new concept to me.

195
00:15:13,260 --> 00:15:15,040
So I'm going to call him Tom, which I think is accurate.

196
00:15:15,220 --> 00:15:16,480
And there's no line through that O.

197
00:15:16,780 --> 00:15:19,040
So that's good for me in my pronunciation.

198
00:15:19,660 --> 00:15:20,540
But he actually went public.

199
00:15:20,640 --> 00:15:24,240
We talked earlier about kind of what a typical vulnerability disclosure looks like.

200
00:15:24,280 --> 00:15:28,260
And so this researcher went public, but because Microsoft wrote him off,

201
00:15:28,400 --> 00:15:30,540
which is typically the next best thing.

202
00:15:30,740 --> 00:15:34,060
So if somebody goes to a company with a real problem and the company doesn't respond

203
00:15:34,300 --> 00:15:36,880
or they ignore them and that researcher tries their best,

204
00:15:37,000 --> 00:15:38,980
it's a little bit more acceptable for them to then go public

205
00:15:39,560 --> 00:15:42,040
because then at least there will be public pressure to fix the issue.

206
00:15:42,500 --> 00:15:51,100
Now, Microsoft looked at this problem and responded to him saying, quote, Microsoft Edge loads all of your saved passwords into memory in clear text, even when you're not using them.

207
00:15:51,960 --> 00:15:59,380
What's so fascinating is that even though Edge is based on Chromium, which is what Chrome is based on, this isn't even a behavior in Google Chrome.

208
00:15:59,650 --> 00:16:01,380
This is an Edge-specific behavior.

209
00:16:01,840 --> 00:16:07,560
To be clear here, what this means is that if somebody has administrative access to your machine, they can exploit this vulnerability.

210
00:16:07,900 --> 00:16:14,060
And what they can do is they just access the memory of all logged in user processes, and then your passwords would just be in there.

211
00:16:14,280 --> 00:16:18,100
I'll touch on my thoughts on this in a second, but the Microsoft response to this is, quote,

212
00:16:18,240 --> 00:16:20,740
Safety and security are foundational to Microsoft Edge.

213
00:16:20,920 --> 00:16:25,440
Access to browser data as described in a reported scenario would require the device to already be compromised.

214
00:16:25,920 --> 00:16:31,020
Design choices in this area involve balancing performance, usability, and security, and we continue to review it against evolving threats.

215
00:16:31,440 --> 00:16:34,580
Browsers access password data and memory to help users sign in quickly and securely.

216
00:16:34,900 --> 00:16:36,660
This is an expected feature of the application.

217
00:16:36,700 --> 00:16:42,160
We recommend users install the latest security updates and antivirus software to help protect against security threats.

218
00:16:42,680 --> 00:16:48,580
Now, my initial gut reaction to reading this, again, this is more of an emotional reaction, is that this is quite lazy, right?

219
00:16:48,640 --> 00:16:54,820
I think there is always some kind of thing that you can say is someone else's problem or that's intended by design.

220
00:16:55,020 --> 00:17:06,400
If I build a website and it has some kind of vulnerability in it, but the website's vulnerability can only be exploited if something else down the chain gets exploited, then I can just say, well, that's out of scope.

221
00:17:06,660 --> 00:17:11,740
that assumes too many things. So this is actually working as designed. But I would argue that's not

222
00:17:11,959 --> 00:17:16,780
best practice. Best practice is to assume and try to protect your users at every step of the process.

223
00:17:17,360 --> 00:17:23,060
And we know that Microsoft kind of has that same carelessness to Windows as an operating system,

224
00:17:23,189 --> 00:17:27,579
and what they're actually depending on here is themselves. So imagine I was like, oh, hey, yeah,

225
00:17:29,140 --> 00:17:32,140
there is this exploit. Yeah, I know you guys are reporting this exploit on my website,

226
00:17:32,220 --> 00:17:34,960
but it's okay because the downstream or upstream person

227
00:17:35,820 --> 00:17:37,020
would also need to be exploited.

228
00:17:37,200 --> 00:17:38,580
Oh, but that person's also me.

229
00:17:39,200 --> 00:17:40,820
So that's what Microsoft's doing here.

230
00:17:40,900 --> 00:17:41,600
They're pretty much saying,

231
00:17:41,820 --> 00:17:43,740
hey, yeah, Microsoft Edge has this problem,

232
00:17:44,080 --> 00:17:45,900
but it's okay because it would require

233
00:17:46,060 --> 00:17:47,480
some of the compromised Microsoft Windows.

234
00:17:47,980 --> 00:17:48,920
But what do we see?

235
00:17:49,040 --> 00:17:52,640
We see Microsoft do a lot of really lazy things as well

236
00:17:52,780 --> 00:17:54,140
on the Microsoft Windows side of things,

237
00:17:54,240 --> 00:17:56,180
also sometimes from a security perspective.

238
00:17:56,280 --> 00:17:58,360
And so I think that this is just lazy.

239
00:17:58,520 --> 00:17:58,900
It's careless.

240
00:17:59,020 --> 00:18:01,180
It's not thinking about, well, what if something goes wrong?

241
00:18:01,420 --> 00:18:09,440
It's also maybe too much confidence in their own product in some ways that I don't know where that's coming from the last year or two as Microsoft has not had a strong couple years.

242
00:18:09,880 --> 00:18:13,420
I really struggle to follow Microsoft's reasoning and their explanation for this.

243
00:18:13,540 --> 00:18:15,980
I'm not saying there isn't any layer of legitimacy to it.

244
00:18:16,010 --> 00:18:28,420
I just think that especially coming from them as a company and their history and their lack of explanation on what it's actually providing, I'm inclined to say that this is something that should be fixed, especially when every other browser doesn't have this problem.

245
00:18:28,760 --> 00:18:31,120
So I think no matter what, try to avoid Microsoft Edge.

246
00:18:31,340 --> 00:18:35,740
There are many reasons to do this as well from a privacy perspective and also just a transparency perspective.

247
00:18:36,140 --> 00:18:38,120
I think that the Brave browser is a really good alternative.

248
00:18:38,360 --> 00:18:39,880
The Firefox browser is a great alternative.

249
00:18:40,240 --> 00:18:41,720
Firefox forks are great as well.

250
00:18:42,000 --> 00:18:46,560
Whatever you want to use, if it's open source, it's probably going to be a bit better than something like this.

251
00:18:46,940 --> 00:18:53,140
On top of that, if you want to do things a little bit more best practice, you can always use a desktop-based password manager instead.

252
00:18:53,680 --> 00:18:57,940
Those typically have dedicated security teams to make sure they're pretty much locked vaults on your system.

253
00:18:58,240 --> 00:19:02,340
I can highly recommend something like Bitwarden or 1Password or ProtonPass.

254
00:19:02,500 --> 00:19:05,160
These are good starting points that are quite easy for a lot of people.

255
00:19:05,940 --> 00:19:09,400
And then you have more advanced things like KeePass as well if you want something a little bit more advanced.

256
00:19:09,560 --> 00:19:11,360
So this is something I wanted to put in your guys' radar.

257
00:19:11,570 --> 00:19:20,560
I think it's just another kind of flag to plant inside of the drowning Microsoft ship of all of their problems they've been going through the last couple years.

258
00:19:20,640 --> 00:19:27,060
I talked about earlier when you look at these Linux distributions, and there's one of the most critical vulnerabilities that we've seen in the last few years.

259
00:19:27,560 --> 00:19:33,640
And some Linux distros may or may not even be taking it seriously or communicating properly to their users or patching it as quickly as they can.

260
00:19:33,940 --> 00:19:39,000
Something that should be something that a developer stays up overnight to fix to help keep their users safe.

261
00:19:39,090 --> 00:19:42,020
I know I would if I ran a Linux distribution and there was a critical vulnerability.

262
00:19:42,560 --> 00:19:44,720
I'd be up all night to make sure my users were kept safer.

263
00:19:45,240 --> 00:19:46,780
So that is an important thing to flag.

264
00:19:46,830 --> 00:19:48,100
Two should be the same for Microsoft.

265
00:19:48,270 --> 00:19:51,880
So if Microsoft is getting these exploits and they're like, well, that's just intentional.

266
00:19:52,100 --> 00:19:54,460
Yeah, you know, we trust that Microsoft's safe, blah, blah, blah.

267
00:19:55,880 --> 00:19:57,120
That's a big red flag.

268
00:19:57,380 --> 00:20:08,180
So I do just challenge you all, if you are using some kind of vendor or piece of software that has someone who communicates like this about real security problems, flag that, right?

269
00:20:08,420 --> 00:20:11,300
Doesn't mean you need to move away from it day one, but I think that's something worth considering.

270
00:20:17,440 --> 00:20:20,140
All right, everybody, and now we're going to get into the defense bulletin.

271
00:20:20,240 --> 00:20:24,440
Now, again, this was a shorter week, so I'm keeping a defense bulletin a lot shorter than we normally do.

272
00:20:24,580 --> 00:20:29,780
And I'm just going to cover what I felt were kind of the most interesting or most important stories of the last couple weeks.

273
00:20:30,700 --> 00:20:33,520
So next week, we'll go back to a normal episode, but let's just get through these.

274
00:20:33,800 --> 00:20:35,940
First one is that there was an issue in cPanel.

275
00:20:35,960 --> 00:20:39,100
If you've ever hosted a website, you might have experienced with cPanel.

276
00:20:39,820 --> 00:20:43,920
But there is a very massive vulnerability here that was used on millions of websites,

277
00:20:44,220 --> 00:20:48,340
which allowed attackers to hijack and take full control of the servers running the affected software.

278
00:20:49,300 --> 00:20:50,320
This is patched.

279
00:20:50,320 --> 00:20:54,320
And so if you run anything that has cPanel on it, please make sure you would have updated by now.

280
00:20:54,460 --> 00:20:56,920
I really hope you would have updated by now because it's been like a week.

281
00:20:57,100 --> 00:20:58,280
So definitely get on that.

282
00:20:58,620 --> 00:20:59,360
Now, this one's pretty crazy.

283
00:20:59,400 --> 00:21:01,380
It happened a couple weeks ago, but it's from Bitwarden.

284
00:21:01,580 --> 00:21:04,720
The Bitwarden, which is the password manager's command line interface,

285
00:21:04,980 --> 00:21:07,980
was compromised as part of an ongoing supply chain attack.

286
00:21:08,240 --> 00:21:11,200
Now, supply chain attacks are really hard to pull off, generally speaking.

287
00:21:11,580 --> 00:21:12,220
They're quite rare.

288
00:21:12,580 --> 00:21:16,080
And so this is something that is very hard to protect against as a software vendor.

289
00:21:16,140 --> 00:21:19,100
I think that kind of context is important when discussing this kind of thing.

290
00:21:19,500 --> 00:21:23,400
With that said, Bitwarden's security team identified and contained that malicious package,

291
00:21:23,680 --> 00:21:28,680
provoked compromised access, and deprecated the affected release pretty much as soon as they could.

292
00:21:28,940 --> 00:21:30,180
So this is what I'm talking about, guys.

293
00:21:30,230 --> 00:21:37,140
So this was deployed at 5.57 Eastern time, and they patched it and removed it by 7.30 Eastern time,

294
00:21:37,500 --> 00:21:41,500
which means that users would have had like an hour and a half to download this.

295
00:21:41,640 --> 00:21:45,320
Now, if you were in that hour and a half window, A, really bad luck.

296
00:21:45,560 --> 00:21:45,860
I'm sorry.

297
00:21:45,950 --> 00:21:49,960
But B, they do have instructions that they posted formally, and they send out really proper announcements.

298
00:21:50,500 --> 00:21:55,220
Now, I think that a lot of people might come down on Bitwarden here, and I don't even use Bitwarden personally.

299
00:21:55,220 --> 00:21:57,640
I have no reason to say this, but I have a lot of respect for their team.

300
00:21:57,750 --> 00:22:00,080
I know that they have a really good security team.

301
00:22:00,310 --> 00:22:02,220
And this can in some ways happen to anybody.

302
00:22:02,430 --> 00:22:06,680
And so this is the kind of thing that I personally look more for the response times, right?

303
00:22:07,040 --> 00:22:11,680
If they were purposely leaving the password saved in memory, and then there was some vulnerability that exploited that,

304
00:22:11,960 --> 00:22:14,040
and then I would be like, that's a little bit different.

305
00:22:14,300 --> 00:22:17,340
But supply chain incidents like this are really hard to protect against.

306
00:22:17,620 --> 00:22:27,280
So typically, in these situations, I'm looking for the response, how quickly they dealt with it, how they communicated it to their users, and also just the kind of approach that they're taking to this problem.

307
00:22:27,540 --> 00:22:29,380
And for me, I'm quite happy with this.

308
00:22:29,760 --> 00:22:38,460
If you are a Bitwarden user, I recommend actually reading in the show notes the responses that Bitwarden wrote and see how comfortable you are with them and if there's something that you feel like is lacking.

309
00:22:38,920 --> 00:22:41,700
And if there is, then maybe you can reconsider your password manager.

310
00:22:41,980 --> 00:22:46,360
But I think what I want people to kind of take away from this week's episode is to really

311
00:22:46,770 --> 00:22:50,380
look at the software you're using, look at the communication behind the developers and

312
00:22:50,440 --> 00:22:54,100
who's running it as they're pushing software to your device, and just see if it's something

313
00:22:54,150 --> 00:22:56,140
that you align with and that you're comfortable with.

314
00:22:56,440 --> 00:23:00,220
And if you're looking at this Bitwarden story and it makes you feel weird, that's something

315
00:23:00,270 --> 00:23:01,000
you can listen to.

316
00:23:01,050 --> 00:23:04,420
Just make sure to act appropriately and also try to find an alternative that you think

317
00:23:04,520 --> 00:23:08,340
is actually fixing whatever communication problem that you feel like you've isolated out.

318
00:23:08,640 --> 00:23:09,880
It's kind of the theme of the week.

319
00:23:10,280 --> 00:23:15,580
WordPress. I think I mentioned earlier, every week we have WordPress stuff. So yeah, there was people

320
00:23:15,590 --> 00:23:20,220
who planted backdoors in dozens of WordPress plugins used in thousands of websites. So as we,

321
00:23:21,080 --> 00:23:25,600
tale as old as time, guys. It's called the Essential Plugin that says on its website that

322
00:23:25,640 --> 00:23:32,340
has over 400,000 plugin installs and more than 15,000 customers. And yeah, it's been hijacked.

323
00:23:32,560 --> 00:23:36,000
So if you use any kind of WordPress plugins, definitely check this one out. All right,

324
00:23:36,000 --> 00:23:39,600
I did want to just highlight a couple data breaches here that were kind of the larger ones.

325
00:23:39,700 --> 00:23:43,400
And so France confirmed a data breach at a government agency that manages citizens' IDs.

326
00:23:43,820 --> 00:23:48,500
I wish that they used encryption, as our U.S. senators would say.

327
00:23:48,800 --> 00:23:52,000
But I'm sure they did use encryption when it came to collecting this information.

328
00:23:52,100 --> 00:24:01,100
But I think this exposes the problem, which is just because you used encryption while data was in transit doesn't mean that it was actually properly secured at its location and it can't keep out malicious actors.

329
00:24:02,059 --> 00:24:04,960
So they didn't specify how many people were affected by this breach.

330
00:24:05,060 --> 00:24:09,100
But if you are a French citizen, please keep up with the story because it could impact you.

331
00:24:09,300 --> 00:24:12,360
This next story has a really important lesson that I want to clear up as well.

332
00:24:12,470 --> 00:24:17,400
So there's a home security company out there called ADT, and they had a data breach.

333
00:24:17,600 --> 00:24:19,460
So this is a company that's like, we're going to keep you safe.

334
00:24:19,650 --> 00:24:23,760
We have security cameras, window sensors, door locks, whatever.

335
00:24:24,110 --> 00:24:25,720
You come in, you type in a passcode.

336
00:24:26,300 --> 00:24:28,140
One of those security companies, right?

337
00:24:28,190 --> 00:24:32,520
But they had a data breach, and they confirmed that it was limited to names, phone numbers, and addresses.

338
00:24:33,100 --> 00:24:42,140
The real concern I have about this is that for some people, this is actually a very serious thing because ADT has such sensitive information like where you live.

339
00:24:42,180 --> 00:24:51,400
And now if an attacker has a list of all their customers and where they're located, etc., that's actually pretty sensitive private information that could make them a larger target.

340
00:24:51,460 --> 00:24:57,900
So this is an ironic story for me because this is a company that's literally his entire business model is to keep you safer.

341
00:24:58,520 --> 00:25:00,180
And they are caught in this breach.

342
00:25:00,440 --> 00:25:17,520
So for me, the lesson and kind of why I wanted to outline this story is that I think the companies that genuinely, and I mean genuinely care about keeping you safer, even if they do provide you some benefits like ADT, they're also going to provide ways to restrict the kind of information they can access as well.

343
00:25:18,140 --> 00:25:36,380
What I mean by this is even a company like Amazon with their Amazon Rings, I am not an Amazon fan. I don't like Amazon Rings very much, but they baked in a feature that allows end-to-end encryption with Amazon Rings. And so if you are an Amazon Ring customer, you just enable end-to-end encryption and that prevents Ring themselves from accessing your camera footage.

344
00:25:36,660 --> 00:25:46,940
I think this is a really good example of how this is still providing you security without that inherent downside of them getting to see your data, which comes with so many other side effects.

345
00:25:47,140 --> 00:25:50,440
You're not trusting every employee as part of the company to not spy on you.

346
00:25:50,780 --> 00:25:56,240
You also are trusting that they don't get hacked and some random person tries to leak it, which could put you in the crosshairs of something else.

347
00:25:56,720 --> 00:26:05,340
And so again, I think the right companies to put your trust in are the ones that genuinely try to collect as little as possible about you to still offer you a good service.

348
00:26:05,560 --> 00:26:08,640
So within reason, but this is a good reminder.

349
00:26:09,460 --> 00:26:16,020
There was another data breach from Vimeo, the video service, that did expose user data, email addresses for some of its customers.

350
00:26:16,560 --> 00:26:20,160
But most of the exposed information was technical data like video titles and metadata.

351
00:26:20,400 --> 00:26:23,200
So if you want to learn more about this, there's always the show notes in the description.

352
00:26:23,660 --> 00:26:24,720
This one I thought was pretty cool.

353
00:26:24,780 --> 00:26:30,320
So Proton, the people behind ProtonMail, ProtonVPN, etc., are now doing post-quantum.

354
00:26:30,480 --> 00:26:35,200
They have a whole help article that I'll leave in the show notes as well that teaches you how to enable it.

355
00:26:35,240 --> 00:27:01,360
This is being gradually rolled out. And so if you don't see it in your account yet, there's nothing you need to do. Just keep checking. And as they're gradually rolling this out to do this, you just sign into your account, you go into settings, you go to encryption and keys from the sidebar, and then there's a enable post quantum protection button. And then if you're watching this video, you can see that there is an enable and generate keys, and then you can manage your account keys, etc. It's cool. This is really awesome stuff.

356
00:27:01,500 --> 00:27:05,740
I believe Tuda, kind of the main competitor to Proton, has already rolled out post-Quantum.

357
00:27:05,770 --> 00:27:08,580
And so this is a good way and we see some healthy competition here.

358
00:27:08,920 --> 00:27:11,540
And I think it's cool that Proton's really pushing the envelope there on that.

359
00:27:11,810 --> 00:27:17,180
We also, a couple weeks ago, had Tails, the anonymous operating system, release version 7.7.

360
00:27:17,580 --> 00:27:20,940
It comes with some extra security notifications when it comes to Secure Boot.

361
00:27:21,240 --> 00:27:25,660
And it comes with other updates like updating Tor Browser and Thunderbird and some bug fixes as well.

362
00:27:25,880 --> 00:27:28,180
This next story is a very interesting one.

363
00:27:28,260 --> 00:27:31,800
And if you haven't heard of this before, it's an interesting thing, I think.

364
00:27:31,890 --> 00:27:37,000
So pretty much Apple does a really bad job of handling VPNs on iOS because Apple just

365
00:27:37,200 --> 00:27:38,000
has random exceptions.

366
00:27:38,550 --> 00:27:41,440
Apple doesn't force everything to go through the VPN tunnel.

367
00:27:41,530 --> 00:27:45,560
So even if you're connected to a really nice VPN provider, like in this case, Mullvad, they

368
00:27:45,700 --> 00:27:49,400
can't really guarantee that all of your web traffic always goes through the VPN on iOS.

369
00:27:49,680 --> 00:27:52,920
And this is just kind of like the Microsoft thing of like, yep, that's just how it works.

370
00:27:53,040 --> 00:27:53,800
That's by design.

371
00:27:54,310 --> 00:27:58,220
Though at least in Apple's case, they kind of try to justify it by saying, well, we don't

372
00:27:58,220 --> 00:28:02,840
want everything to go through a VPN tunnel because then you can't reliably connect to

373
00:28:02,900 --> 00:28:08,180
Apple services required to offer you a clean experience, whatever. But I think that reasoning

374
00:28:08,400 --> 00:28:11,900
falls apart when they also release features like lockdown mode, which is geared towards activists

375
00:28:12,100 --> 00:28:17,260
and people in higher risk situations, public figures. And those people probably want to know

376
00:28:17,280 --> 00:28:21,460
for a fact that all of their traffic is going through something like a VPN. And so I think at

377
00:28:21,720 --> 00:28:26,000
minimum, something like lockdown mode should make it so a VPN on iOS actually works system-wide

378
00:28:26,020 --> 00:28:32,040
reliably. Anyway, I offered the context before Mullvad described it here in the article, but they

379
00:28:32,220 --> 00:28:36,300
say here they have been stuck with a VPN app that they knew would leak some traffic in some

380
00:28:36,620 --> 00:28:40,740
circumstances, and they explained kind of the technical bits for it. They did implement a

381
00:28:41,040 --> 00:28:44,360
workaround, though. We've decided we're not going to wait anymore, and we would like to offer our

382
00:28:44,480 --> 00:28:48,580
users the best possible privacy and security, even if it comes with a major UX limitations.

383
00:28:49,360 --> 00:28:53,540
So pretty much they are releasing a new version of the iOS app that will contain a new feature.

384
00:28:53,780 --> 00:28:56,280
This is from Lovat VPN called Force All Apps.

385
00:28:56,800 --> 00:29:01,100
Under the hood, enabling this feature sets the Include All Networks configuration option to true,

386
00:29:01,580 --> 00:29:04,360
and they have tried to make sure that users who enable the feature do so deliberately

387
00:29:04,620 --> 00:29:06,280
without making them jump through too many hoops.

388
00:29:06,640 --> 00:29:08,880
The phone will still enter the broken update loop,

389
00:29:08,920 --> 00:29:11,760
but now users should receive a notification about a new version being available

390
00:29:11,920 --> 00:29:13,300
before the app gets auto-updated.

391
00:29:13,580 --> 00:29:17,940
We expect a minority of our users using this feature will end up with a broken networking stack,

392
00:29:18,220 --> 00:29:20,020
and unfortunately, there is not much we can do.

393
00:29:20,460 --> 00:29:23,740
If you've been affected by this, we can only encourage you to capture the anguish

394
00:29:23,740 --> 00:29:28,180
express it as feedback to Apple. If you're a more technical person, they have a few more technical

395
00:29:28,360 --> 00:29:32,360
details there in the blog article as well. But the idea here is that Mullvad has looked at this

396
00:29:32,550 --> 00:29:36,420
problem on iOS and said, you know what, we can roll out a fix for this, but it's actually quite

397
00:29:36,430 --> 00:29:41,080
a risky fix that might actually cause a little bit of breakage for some users. But yeah, this is,

398
00:29:41,240 --> 00:29:44,860
I think, a cool thing. I think Mullvad's trying to put themselves out there. I think what I'm

399
00:29:45,260 --> 00:29:49,020
personally excited about for this is that now there's a real bug there. And Apple might look

400
00:29:49,100 --> 00:29:52,900
at this and go, oh my God, people are using VPNs and it's causing their devices to break,

401
00:29:53,020 --> 00:29:55,380
but the VPNs are doing this because we haven't fixed this other problem.

402
00:29:55,640 --> 00:30:00,080
So it might create and force a better discussion that Apple might take more seriously.

403
00:30:00,180 --> 00:30:02,380
And so that's kind of what I'm hoping is going to happen.

404
00:30:02,800 --> 00:30:06,640
I can't say I'm going to recommend this to really anybody unless you're in a super high-risk scenario.

405
00:30:07,220 --> 00:30:10,680
But in that situation, I'd say you probably shouldn't be doing whatever you're about to do on your phone

406
00:30:10,720 --> 00:30:14,720
and maybe migrate to a proper Tor browser or even something like Tails OS or Hoonix

407
00:30:14,780 --> 00:30:17,380
or just something a little bit more established for that kind of use case.

408
00:30:17,620 --> 00:30:21,760
But in the meantime, I think this is a really good form of leadership from Bolvan.

409
00:30:22,460 --> 00:30:24,800
This is a really quick update for Brave users.

410
00:30:25,280 --> 00:30:27,080
Brave has a feature called the Shred button,

411
00:30:27,500 --> 00:30:31,860
which pretty much lets you just delete data on a per-site basis when you leave it,

412
00:30:31,980 --> 00:30:34,600
or if you just want to just delete data right away at the click of a button.

413
00:30:35,080 --> 00:30:36,580
They're now moving that over to Android.

414
00:30:37,000 --> 00:30:37,740
So it's been on iOS.

415
00:30:38,100 --> 00:30:40,820
I don't know what the delay was or why it took so long to bring us to Android,

416
00:30:41,080 --> 00:30:42,340
but it is now on Android.

417
00:30:42,640 --> 00:30:46,500
Maryland has become the first state to pass a bill banning surveillance pricing.

418
00:30:47,580 --> 00:30:48,800
If you don't know what this is,

419
00:30:48,820 --> 00:30:53,120
essentially there are websites that try to take your personal data, like your location,

420
00:30:53,230 --> 00:30:57,380
your browsing history, your purchasing behavior, and try to actually change pricing online

421
00:30:58,020 --> 00:31:01,820
based on how much they think you'll actually pay. And so Maryland has banned this practice.

422
00:31:01,980 --> 00:31:06,120
This is really cool. I think it's really frustrating if this is in any way a normalized

423
00:31:06,290 --> 00:31:10,220
thing nowadays. And I think it's another selling point for privacy. If you're using privacy tools,

424
00:31:10,340 --> 00:31:14,820
even free ones, you might actually be spending less money on websites that aren't profiling you

425
00:31:14,820 --> 00:31:18,400
to see that you'll actually pay more money for something. And so it's cool that this is happening.

426
00:31:18,500 --> 00:31:21,320
I'd love to see kind of more initiatives like this out there.

427
00:31:21,700 --> 00:31:24,020
With all of that said, I want to thank you all for listening.

428
00:31:24,180 --> 00:31:27,600
I know it's been a while, so I especially also want to thank you for your patience.

429
00:31:28,160 --> 00:31:30,220
That is going to conclude this week's surveillance report.

430
00:31:30,580 --> 00:31:31,680
We're hoping to get back on track.

431
00:31:31,980 --> 00:31:35,660
And maybe I didn't want to announce this at the front, but the idea is that this is actually

432
00:31:35,700 --> 00:31:36,520
a video podcast.

433
00:31:36,920 --> 00:31:41,660
So if you are watching this on Apple and it's a video podcast, then this worked.

434
00:31:42,080 --> 00:31:43,380
Let me know how the experience was.

435
00:31:43,480 --> 00:31:46,040
I'd love to hear from you all if this worked cleanly.

436
00:31:46,340 --> 00:31:52,560
And then if it did work cleanly and everything worked appropriately, then next week I'll actually make that a formal announcement at the beginning.

437
00:31:53,140 --> 00:32:01,320
Now, if you like this podcast and you got value from it and it helped you reclaim control for you or the people around you, you can become a Techlorian and support us down in the show notes.

438
00:32:01,540 --> 00:32:03,840
You'll get access to our exclusive communities on Signal.

439
00:32:04,140 --> 00:32:06,700
You'll get key perks along the way in our community as well.

440
00:32:07,100 --> 00:32:08,680
And you'll also help the podcast keep growing.

441
00:32:09,180 --> 00:32:13,440
I also want to ask all of you if you can definitely try to leave a rating, share this episode with friends and family.

442
00:32:13,640 --> 00:32:15,220
and you can also help spread digital freedom

443
00:32:15,310 --> 00:32:17,780
by just talking to them for things like Mother's Day

444
00:32:17,790 --> 00:32:18,500
or anything like that.

445
00:32:19,090 --> 00:32:19,760
Thank you all for listening.

446
00:32:20,300 --> 00:32:21,200
Thank you all for your patience again

447
00:32:21,540 --> 00:32:23,660
and I'll see you in the next episode of Surveillance Report.