← All Tags

#security

32 episodes

#4664: The Trapdoor in Your CPU: How Hypervisors Actually Work

Inside the silicon trapdoor that makes virtualization possible — and why it's nothing like Docker.

hardware-engineeringsecurityoperating-systems

#4626: What Israeli Law Allows in a Violent Split Second

What can you legally do when someone is attacked in front of you? We break down self-defense, citizen's arrest, and why people freeze.

israelsecurityisraeli-law

#4585: Why `export` Fails But Files Work: Linux Process Secrets

Why does `wrangler login` work across shells but `export` doesn't? The answer reveals how Linux processes really share data.

operating-systemssoftware-developmentsecurity

#4424: Inside the 3D Secure Redirect: What Happens When Your Card Gets Challenged

That split-second redirect at checkout is 3D Secure 2. Here's how the ACS, risk scoring, and SMS challenges actually work.

securityfinancial-frauddigital-identity

#4417: How to Tell Real Security Tools From Fakes

A friend's question about SSN monitoring reveals how to spot fake security tools designed to steal what you're trying to protect.

securityvpndigital-privacy

#4261: The Security You Can't See at Ofer Prison

What looks like a shabby, low-tech prison is actually a high-tech fortress. Here's what you're missing.

securitysurveillance-technologysituational-awareness

#4229: SSH Key Strategy: Compartmentalization vs. Chaos

Application-specific SSH keys vs. one key for everything — and what AI agents mean for both approaches.

securityssh-key-managementagent-based-authentication

#4161: How Your Password Manager's 6-Digit Code Actually Works

Your phone and a server generate the same code without ever talking. Here's the elegant math behind it.

cryptographysecurityauthentication

#4085: The Clinton Email Server: A Technical Autopsy

What was actually in that Chappaqua basement? A technical breakdown of the most infamous self-hosted email server in history.

hardware-engineeringsecurityprivacy

#4040: The Clipboard That Opens Any Door

Professional liars with rulebooks: inside the world of authorized break-ins, badge cloning, and jail time as a line item.

social-engineeringsecurityphysical-penetration-testing

#3999: The VLAN Blind Spot: Why Your IoT Devices Still Talk to Each Other

VLANs isolate IoT from your main network, but devices inside can still attack each other. Client isolation is the missing piece.

networkingsmart-homesecurity

#3764: Rooting's Last Stand: Play Integrity vs. Power Users

Google’s Play Integrity API is making rooted phones useless for banking. Is rooting dead?

androidsecurityhardware-reliability

#3420: How Airports Handle Planespotters: 4 Global Approaches

From designated viewing platforms to espionage charges — how airports worldwide treat people with binoculars and logbooks.

aviationsecurityisrael

#2835: Why Can't I Trust My Own Computer?

Why services keep asking you to sign in—and what it would take to fix it.

zero-trustsecurityusability

#2699: Inside Android's Binder: No HTTP Here

Android's internal APIs don't use HTTP. They use Binder — a kernel-level IPC mechanism that's faster, tighter, and completely opaque.

operating-systemsandroidsecurity

#2679: Can a VPN Protect You from SS7 Phone Spying?

SS7 is the hidden backbone of global phone networks—and it's wide open to spies. Here's what a VPN does and doesn't fix.

privacytelecommunicationssecurity

#2678: How IMSI Catchers Actually Track Your Phone

How fake cell towers intercept your phone, from GSM flaws to 5G fixes. Separating spy-thriller hype from real engineering.

surveillance-technologysecurityprivacy

#2594: The Hierarchy of Immutable Code

From mask ROM to e-fuses: how hardware enforces a hierarchy of mutability in every computing device.

hardware-engineeringhardware-reliabilitysecurity

#2508: Why CORS Doesn't Protect Your Server

Why browsers block cross-origin requests, how CORS actually works, and the common pitfalls that trip up developers.

securitycybersecuritycors

#2496: Are Hidden API Endpoints Leaks or Just Plumbing?

When LLM agents discover unauthenticated JSON endpoints in browser DevTools, is it a security breach or just reading the page?

api-integrationsecurityai-agents

#2324: The Three Layers of Filming in a Security-Conscious Country

Navigating the legal and social challenges of filming in Israel—what’s allowed, what’s not, and how creators can stay safe.

israelprivacysecurity

#2251: Agent-to-Agent Protocols: What Actually Needs Standardizing

When autonomous agents call other agents, what does a working protocol actually require? Exploring session handling, state management, security, an...

ai-agentsapi-integrationsecurity

#1797: Why the Cloud Runs on Cassette Tapes

The cloud isn't just hard drives—it's millions of robotic cassette tapes holding petabytes of data for Google and NASA.

data-storagehardware-engineeringsecurity

#1780: The Danger Zone: Your Browser Extensions

Your encrypted data is safe until it hits your browser. Here's how extensions turn your "secure" browsing into a data leak.

securitysupply-chain-securitydigital-privacy