Welcome to "Privacy Please," a podcast for anyone who wants to know more about data privacy and security. Join your hosts Cam and Gabe as they talk to experts, academics, authors, and activists to break down complex privacy topics in a way that's easy to understand. In today's connected world, our personal information is constantly being collected, analyzed, and sometimes exploited. We believe everyone has a right to understand how their data is being used and what they can do to protect their privacy. Please subscribe and help us reach more people! This podcast is part of The Problem Lounge network — conversations about the problems shaping our world, from digital privacy to everyday life.
Listen to episodes
60 recent
August 25, 202612 min
S7, E277 - He Used a Police Camera Network to Track His Girlfriend 180 Times
Send us Fan Mail Flock Safety's automated license plate readers are in over 5,000 communities and used by more than 40,000 cameras nationwide — sold to cities as a tool to catch car thieves and find missing people. But a Washington Post investigation found at least 50 officers accused of misusing the system, most of them to track romantic partners. This episode covers: The scale of Flock's network and how warrantless searches are legally justified Individual abuse cases in Wichita, Milwaukee, and New Bedford The Texas sheriff's office case tied to reproductive-related searches 404 Media's reporting on ICE's informal access to Flock data despite no official contract Flock's "Freeform" search feature and the race/ethnicity flagging controversy CEO Garrett Langley's August 13 apology and the new audit reforms The historical parallel: NSA's "LOVEINT" scandal from the Snowden leaks What's actually working: 39+ contracts canceled by cities in 2026 3 concrete steps if your town has these cameras flock safety, flock cameras, license plate reader, ALPR, police surveillance, data privacy, police stalking, automated license plate reader, mass surveillance, privacy please podcast, cybersecurity, ICE surveillance, police misconduct, LOVEINT Support the show
August 2, 202649 min
S7, E276 - Ransomware Doesn't Have to Hit Like a Hurricane (with Jonathan Sander)
Send us Fan Mail Jonathan Sander is back on Privacy Please — and he's brought two blog posts worth arguing about. Sander (42 Notions, now in an operational role at Myota) joins Cam and Gabe to dig into why ransomware resilience should work like New York City's storm surge infrastructure — building something that pays off before disaster strikes, not just a wall you wait behind. Then the conversation turns to AI agents: why Sander tried and failed to build a clean taxonomy for them, the six dimensions he landed on instead (authority, execution location, trigger, persistence, delegation, tool reach), and why the "hybrid agent" — switching between acting on your behalf and acting with power you never had — might be the hardest identity problem in security right now. Also covered: why "back to basics" (secrets, resilience, identity) is Sander's answer for teams panicking about AI, and a real story about an AI agent that deleted a Postgres database and just... apologized. Articles referenced: Ransomware Doesn't Have to Hit Like a Hurricane (Myota): https://www.myota.io/articles/ransomware-doesnt-have-to-hit-like-a-hurricane Why We Need an AI Agent Taxonomy Right Now But We Can't Have One (42 Notions): https://blog.42notions.com/why-we-need-an-ai-agent-taxonomy-right-now-but-we-cant-have-one/ Chapters: 00:00 – Catch-up with Sander 14:30 – The hurricane analogy: why Myota built resilience instead of a wall 20:30 – What actually makes Myota different from standard backup/cyberstorage 22:15 – Why you can't build a clean AI agent taxonomy (and the six dimensions Sander landed on instead) 28:50 – The hybrid agent problem: acting "on behalf of" vs. "for the benefit of" 45:10 – Sander's one takeaway: get the basics right before chasing the AI hype Support the show
July 18, 20269 min
S7, E275 - Choose Wisely: GigaWiper, Your New Delete Button & The Gold Bar Grift
Send us Fan Mail Full Show Notes This week on Privacy Please, Cam breaks down four stories that all come back to one theme: choice. GigaWiper — Microsoft researchers uncovered a new backdoor malware built from pieces of older malware families, giving attackers the ability to decide after they're already inside a network how they want to cause damage — from low-level disk wipes to fake ransomware with encryption keys that are never even saved. Multiple security firms are independently tracking it, with no group attribution yet. Connecticut's new AI disclosure law — As of July 1st, companies covered by Connecticut's privacy law must clearly disclose whether their data is used to train large language models like ChatGPT, Gemini, DeepSeek, or Grok. Cam digs into why "disclosure" doesn't always mean "clarity," and what to actually look for in a privacy policy update. California's Delete Act (DROP) — A correction and a deep dive: DROP has been live since January 1st, not launching in August as previously stated. What actually changes on August 1st is enforcement — the date data brokers become legally required to act on deletion requests. Cam walks through exactly how to submit one at privacy.ca.gov. The Phantom Hacker gold bar scam — A 78-year-old Phoenix woman nearly lost $600,000 in gold bars to a scammer posing as a federal official — until she turned the tables and called the FBI herself. Cam covers the arrest, the courier-for-hire business model behind it, and the billion-dollar scale of phantom hacker scams since 2024. Tips for this episode: Back up your data offline — wipers don't negotiate, there's no ransom to pay your way out Search privacy policy updates for "train," "AI," or "language model" before skimming past them California residents: submit a DROP request now at privacy.ca.gov so it's queued before enforcement begins on August 1st No real government agency will ever tell you to convert your money to gold, crypto, or gift cards — hang up and call the agency back yourself Sources referenced: Microsoft Security research on GigaWiper Connecticut Data Privacy Act (CTDPA) amendment, effective July 1, 2026 California Delete Act / DROP platform, cppa.ca.gov FBI IC3 reporting on Phantom Hacker and gold bar scams AZFamily coverage of the Gary Christopher arrest, Phoenix Sky Harbor Airport Chapter Timestamps 00:00 – Cold Open 01:30 – GigaWiper: Choose-Your-Own-Destruction Malware 04:00 – Connecticut's LLM Data Disclosure Law 06:15 – California's Delete Act & DROP Platform 08:30 – The Phantom Hacker Gold Bar Scam 11:30 – Recap & Close Support the show
June 29, 202620 min
S7, E274 - Your Password Is Already For Sale
Send us Fan Mail Last year, every major outlet ran the same story: 16 billion passwords exposed. Apple. Google. Facebook. The largest breach in history. It was overblown. Security experts tore it apart within 48 hours. But here's the thing: the real story underneath that headline is actually scarier. And nobody covered it. It's called infostealer malware. It's been quietly running on millions of devices — stealing passwords, bypassing MFA, and feeding an underground credential economy that's behind nearly every major breach of the last two years. Ticketmaster. AT&T. Coinbase. All of it traces back here. In this episode, I dig back into that story and break down: Why the 16 billion number was a "fearset, not a dataset" What infostealer malware actually is and how it gets on your device Why MFA doesn't fully protect you from this (and what does) The underground marketplace where your stolen credentials are sold within 48 hours The stat that should genuinely keep you up at night: 67 seconds Six things you can do right now to protect yourself SHOW NOTES Episode: Your Password Is Already For Sale Last year, the 16 billion password story dominated headlines. The headline was overblown — but the real threat underneath it, infostealer malware, is what nobody talked about. It's an industrial-scale credential theft economy running quietly in the background, and it's the engine behind almost every major data breach of the last two years. We dug back into it because it's only gotten worse. Resources mentioned: Check if your email has been breached: haveibeenpwned.com Free password manager: bitwarden.com Premium password manager: 1password.com Key sources: Cybernews — original 16 billion credential report (June 2025) CyberScoop — "The 16 billion password breach story is a farce" Flashpoint / DeepStrike — 1.8 billion credentials stolen in 2025 report Microsoft Security Blog — Lumma Stealer breakdown IBM X-Force Threat Intelligence Index 2025 Verizon Data Breach Investigations Report 2025 SANS Institute commentary Connect: 🌐 theproblemlounge.com 📺 YouTube: The Problem Lounge Network Support the show
June 4, 202624 min
S7, E273 - Inside Shiny Hunters And The New Era Of SaaS Breaches
Send us Fan Mail Gabe and I dig into Shiny Hunters and why the scariest cyberattacks now look like ordinary logins instead of dramatic break-ins. We map how credential theft, social engineering, and SaaS data exports turn basic security hygiene into the difference between a close call and a headline. • Shiny Hunters’ scale, loose structure, and why takedowns rarely stick • Why ransomware and extortion keep growing as a business model • How the tactics evolve from Microsoft 365 and developer creds to SaaS platforms like Salesforce • Credential stuffing, vishing, and smishing as “low-friction” intrusion paths • The Snowflake-style failure mode of missing MFA and weak password practices • Password reuse and how consumer breaches can cascade into enterprise access • Data retention and why old records increase privacy risk • Vendor risk and the shared responsibility model for identity and data • Practical steps that improve security without relying on perfect users If you guys have not been to our website, theproblemlounge.com, check it out. Got some new blogs up there. Sign up for the newsletter. Support us, follow us. Let’s get this out to more people. Support the show
May 23, 202616 min
S7, E272 - They Know What You Watched
Send us Fan Mail SHOW NOTES The Pornhub breach is being reported as a data story. It's actually a story about shame as a weapon. In December 2025, a hacker group called ShinyHunters claimed to have stolen 200 million records from Pornhub Premium users — including email addresses, locations, and intimate watch and search history. They sent extortion demands. The data was verified as real. In this episode of Privacy Please, Cameron Ivey breaks down: ✅ What was actually stolen — and why it's worse than most breaches ✅ The three-way blame game between Pornhub, Mixpanel, and a mysterious 2023 employee access ✅ Why ShinyHunters is one of the most dangerous and active hacker groups operating right now ✅ The bigger question nobody's asking: why does this data still exist? ✅ Five things you can do right now to protect yourself 🔗 RESOURCES MENTIONED: Check your email in breaches: haveibeenpwned.com Freeze your credit: annualcreditreport.com (links to all three bureaus) Data removal: DeleteMe — joindeleteme.com Follow the reporting: bleepingcomputer.com | malwarebytes.com/blog 📰 SOURCE REPORTING: BleepingComputer — ShinyHunters extortion demand (December 2025) Malwarebytes — Pornhub/Mixpanel/SoundCloud breach roundup Euronews — Pornhub investigation coverage Reuters — user data verification Panda Security — breach overview 🎙️ Privacy Please is part of the Problem Lounge Network 🌐 theproblemlounge.com 📺 YouTube: The Problem Lounge Network If this one hit different — share it. Support the show
May 5, 202622 min
S7, E271 - One File to Rule Them All
Send us Fan Mail In this episode of Privacy Please, Cameron Ivey investigates Palantir Technologies — a data analytics company founded in 2003 with CIA backing that has quietly become embedded across nearly every major arm of the U.S. federal government. This week's investigation covers: The USDA Deal On April 22nd, the Department of Agriculture signed a $300 million blanket purchase agreement with Palantir to build "One Farmer, One File" — a unified digital profile for every American farmer. The deal was awarded without competitive bidding. The IRS Bombshell The same week, The Intercept revealed — based on documents obtained by watchdog group American Oversight — that Palantir has been running financial crime surveillance operations inside the IRS since 2018. The IRS has paid Palantir over $130 million for access to a platform that cross-references bank records, tax filings, transaction histories, and more across millions of Americans. The Immigration Enforcement Machine Palantir's ICE contracts — now over $145 million — power the agency's case management, deportation targeting, and real-time location tracking of immigrants. A tool called ELITE creates individual dossiers on deportation targets by pulling data from the Department of Health and Human Services. The Pushback That's Working New York City's public hospital network canceled its Palantir contract after community organizing and City Council pressure. In the UK, 229,000 people have signed petitions to remove Palantir from the National Health Service. Public pressure is moving the needle. Five Things You Can Do Right Now Cameron closes with specific, actionable steps every listener can take — from requesting your IRS transcript to freezing your credit to contacting your representative about sole-source contracting. Privacy Please is part of the Problem Lounge Network. New episodes weekly. theproblemlounge.com Chapter Markers 00:00 — Cold Open 01:30 — Intro & Show Welcome 02:45 — Act One: The USDA Deal 06:00 — Act Two: Who Is Palantir? 11:30 — Act Three: The Empire Expands (ICE, Policing) 17:00 — Act Four: Your Tax Returns Are In There Too 24:00 — Act Five: The Layer Nobody's Talking About 30:00 — Act Six: The Part That Gives Me Hope 34:30 — What You Can Actually Do (5 Tips) 39:00 — Closing Reflection (Adjust timestamps after editing) Support the show
April 20, 202613 min
S7, E270 - The 40-Minute Hack That Stole the Blueprint for AI | The Mercor Breach
Send us Fan Mail A normal data breach steals names and passwords. This one may have stolen the recipe for building the world’s most powerful AI models, and it happened through software most people will never notice until it breaks. We follow the Mercor breach from the first warning signs to the moment poisoned Python packages hit PyPI and spread in minutes across systems that were set to auto-update. We walk through what Mercor actually does in the AI economy, especially RLHF (Reinforcement Learning from Human Feedback), and why that behind-the-scenes work shapes how tools from OpenAI, Anthropic, Meta, and Google behave. Then we unpack Lite LLM, the open source “plumbing” that connects apps to multiple AI services, and how a supply chain attack can bypass the company you’re targeting by compromising the dependencies everyone trusts. From there, the focus shifts to the fallout: contractors whose Social Security numbers and identity documents may be exposed, companies scrambling to assess backdoors and credential theft, and the bigger fear that proprietary AI training data sets and labeling strategies are being auctioned on the dark web. We also dig into the compliance controversy around SOC2 and ISO 27001 style certifications and what happens when security audits become performance instead of protection. If you care about cybersecurity, data privacy, AI governance, and open source risk, listen through to the end for concrete steps you can take right now. Subscribe, share this with a friend who uses AI tools, and leave a review with your take on who should be held accountable. Support the show
April 1, 202612 min
S7, E269 - You're the Teacher Now: How Companies Are Using Your Data to Build AI That Replaces You
Send us Fan Mail You already knew you were the product. But did you know you're also the teacher? Companies are quietly feeding your emails, your work decisions, your customer interactions, and your daily patterns into AI systems — systems designed to automate exactly what you do. And most people have no idea it's happening. In this episode of Privacy Please, we break down how it works, who's doing it, why your right to delete your own data is functionally broken in the AI era, and what you can actually do about it. What we cover: How "function creep" turns your data into AI training fuel without new consent The GitHub policy change that's happening right now — and how to opt out Why employees at Amazon, Google, and JPMorgan described training AI as "building your own coffin." The deletion problem — why you can't remove yourself from a trained model Practical steps to audit your tools and protect yourself today Links: GitHub opt-out: github.com/settings/copilot/features Khan v. Figma lawsuit: rainintelligence.com FTC on AI data practices: ftc.gov Check your state privacy rights: iapp.org/resources/article/us-state-privacy-legislation-tracker Delete old posts: redact.dev Privacy Please is part of The Problem Lounge network. 🌐 theproblemlounge.com 🎙️ Subscribe on Apple Podcasts, Spotify, or wherever you listen Support the show
March 13, 202610 min
S7, E268 - AI Can Unmask Your Anonymous Account for $4 | Here's How
Send us Fan Mail Your anonymous account isn't anonymous anymore. Researchers just proved it costs $4 to find out who you are. In February 2026, a team from ETH Zurich and Anthropic published a paper that quietly ended the era of practical online anonymity. Their AI pipeline, using nothing but your posts, comments, and forum activity, correctly identified 67% of pseudonymous users from a pool of 89,000 candidates. No name. No photo. No metadata. Just your words. This episode breaks down exactly how it works, why it's different from every deanonymization scare before it, who's most at risk, and what you can actually do about it. In this episode: How the ESRC pipeline (Extract, Search, Reason, Calibrate) works Why previous anonymity attacks required structured data, and this one doesn't Why commercial AI safety guardrails didn't stop it What "practical obscurity" meant, and why it's gone Concrete steps to reduce your exposure today Links: Research paper: arxiv.org/abs/2602.16800 Delete your Reddit history: redact.dev Tor Project: torproject.org Signal: signal.org Privacy Please is part of The Problem Lounge network. 🌐 theproblemlounge.com 🎙️ Subscribe on Apple Podcasts, Spotify, or wherever you listen Support the show
Is this your show?
Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.