Listen early, and ad-free
by joining Smashing Security PLUS!

Smashing Security #484:

How websites are tracking you with silence

September 10, 2026
0:00
0:00 0:00
0:00
Show full transcript
TranscriptThis transcript was generated automatically, probably contains mistakes, and has not been manually verified.
DANNY PALMER
As I'm sure you've seen, in many cases a company will put out a rather generic statement saying they've been hit by a sophisticated cyberattack.
Unknown
Yeah, no one wants to get hit by a dumb attack, do they? No one wants to. No.

Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer.

Hello, hello, and welcome to Smashing Security episode 484. My name's Graham Cluley.
DANNY PALMER
And I'm Danny Palmer.
GRAHAM CLULEY
Danny, thank you so much for joining us once again. Always a pleasure to see you here on the podcast.
DANNY PALMER
My pleasure. Thanks for having me once more.
GRAHAM CLULEY
Terrific to have you here. Well, before we kick off, let's thank this week's wonderful sponsors, ThreatLocker, Intruder, and Vanta.

We'll be hearing more about them later on in the podcast.
DANNY PALMER
This week on Smashing Security.
GRAHAM CLULEY
We won't be talking about how Berlin city government's ransomware attack started with a fake Cloudflare CAPTCHA.
DANNY PALMER
You'll hear no discussion of—
GRAHAM CLULEY
How France has arrested 2 suspects for hacking the country's tax agency. And we won't even mention how hackers are stealing Claude tokens from subscribers.

So Danny, what are you going to be talking about this week?
DANNY PALMER
I'll be talking about new advice from cyber intelligence agencies which encourages companies which fall victim to cyberattacks to avoid using PR fluff to describe what happened.
GRAHAM CLULEY
And I'll be finding out how the sound of silence could be helping to track you across the internet. All this and much more coming up on this episode of Smashing Security.
JOE
This episode of Smashing Security is supported by ThreatLocker. Agentic AI is beginning to change the tempo of cyberattacks.
GRAHAM CLULEY
Ransomware that thinks for itself, worms that rewrite their own playbook mid-attack, agents happily chaining exploits together without ever pausing to ask a human, is this alright?
JOE
Which is all very interesting, just so long as it isn't your network they're experimenting on.
GRAHAM CLULEY
And that's the problem.

When a machine can scope out your network, break in, and start creeping sideways through it faster than you can finish your coffee, you can't rely on the hope that someone will notice the alert eventually.

And this is where ThreatLocker earns its keep. Default deny and least privilege sit right in the agent's path, so nothing runs just because it asks nicely.

Application allowlisting decides what's even allowed to execute. Ring-fencing keeps trusted apps from wandering off and touching things they shouldn't.
JOE
And privileged access management quietly confiscates the elevated access. The attacker may be moving faster, but the controls are already in place.

Agentic AI doesn't make established security principles obsolete. It makes getting them right considerably more urgent.
GRAHAM CLULEY
So while the attacks are picking up speed, make sure ThreatLocker is already standing in the way. Head to threatlocker.com/smashing to find out more and grab your free demo.
JOE
That's threatlocker.com/smashing. And thanks to ThreatLocker for supporting the show.
GRAHAM CLULEY
Now, Danny, quick question for you before we get started today. How good is your hearing? Have you got quite good hearing?
DANNY PALMER
I don't think I do, you know, which is not a great thing because my eyesight is terrible to begin with.

So you'd hope that my ears would pick up a bit more, like Daredevil, the superhero. He's blind and he can hear and sense things really well.
GRAHAM CLULEY
Yes.
DANNY PALMER
I don't have that ability. I get by in the world, but I don't think you need me for listening for something really, really far away.
GRAHAM CLULEY
Maybe you have another super sense though. Even if your eyesight isn't that great and your hearing isn't that great, maybe you got, I dunno, a fantastic sense of taste.
DANNY PALMER
I can identify certain types of food. I'm not talking about, oh, that's a curry and that's spaghetti.

But no, I could probably tell you what sort of beer was what, vaguely, if you gave me some blind tasting. But no, nothing useful there, I'm afraid.
GRAHAM CLULEY
Well, I'm not gonna give you a beer-related game today. Instead, what I'm gonna do is I'm gonna play you a string of short sounds. And I want you to tell me what they are.

And this is a game that I like to call Name That Chime. Listeners, you can play along as well and see how you do compared to Danny. So Danny, are you ready for round 1?
DANNY PALMER
I am ready.
GRAHAM CLULEY
We'll start off easy, shall we? What is this chime?
DANNY PALMER
Oh, that is the — that's from opening up Windows back in the day, isn't it?
GRAHAM CLULEY
Yes. Do you know which version of Windows that might be?
DANNY PALMER
Oh gosh, it's been so long now. I all kind of meld into one. I'm gonna say '98.
GRAHAM CLULEY
I think it's Windows XP. I don't know what the difference — I mean, now we get to see, I've opened a can of worms here.

Someone will say it's service pack number whatever, 1.0b or something, won't they? But anyway, I think that's a win. I think that's close enough to me.

All right, let's get a little bit harder.
DANNY PALMER
I do know that one. Yeah, that's the Nokia 3310 ringtone.
GRAHAM CLULEY
Very good.
DANNY PALMER
My first mobile phone back in the day. So yeah, very familiar with that. And we all had that as teens.
GRAHAM CLULEY
It's an absolute classic. And my wife asked me, can I program her phone to sound like an old Nokia?
DANNY PALMER
Nice. Does she do that thing like, what's that show called?
GRAHAM CLULEY
Dom Joly, Trigger Happy TV.
DANNY PALMER
Yeah, shouting hello. Yeah.
GRAHAM CLULEY
Okay, you're doing really good. 2 out of 2 so far.
Unknown
Ace.
DANNY PALMER
I do recognise that. Yeah.
Unknown
Right.
GRAHAM CLULEY
People of a certain age will know that.
DANNY PALMER
Yeah, that's a 56K modem. That was my first experience with the internet.
GRAHAM CLULEY
Okay, you've got 100% so far. Let's see how you do on this one.
DANNY PALMER
Oh gosh, that does sound familiar, but I think my 100% record is gonna be going here, so I can't place that off the top of my head.
GRAHAM CLULEY
Okay, that is the startup screen of a Nintendo GameCube.
DANNY PALMER
Ah, well, see, I was always on the Sega side of the fence.
GRAHAM CLULEY
Unfortunately. All right, let's see if we can get you some more points. You might be a bit too young for this.
DANNY PALMER
I'm getting morning television sort of vibes. Something like Granada Television, something like that.
GRAHAM CLULEY
Oh, so close. It's Thames TV here in the UK. Let's carry on.
DANNY PALMER
Uh-oh.
GRAHAM CLULEY
That's very short.
DANNY PALMER
Yeah, that is AOL Messenger, I believe, or one of the messengers. MSN Messenger?
GRAHAM CLULEY
I have it down as ICQ. I don't know if AOL did it as well.
DANNY PALMER
They all blended into one. There's so many of them.
GRAHAM CLULEY
ICQ was really the Tinder of its day. No one wanted to know your age, your sex, your location, wasn't it? It was ASL they'd ask.
DANNY PALMER
Yes, Scott, the internet was a strange place in the '90s and early noughties, wasn't it?
GRAHAM CLULEY
All right, one more. If you get this absolutely correct, you're going to win a special prize. Oh, are you ready?
DANNY PALMER
I am ready.
GRAHAM CLULEY
Again, you might be a bit too young.
DANNY PALMER
To me, it just sounds like when I was down at the opticians and they gave me a hearing test.
GRAHAM CLULEY
It's pretty unpleasant to listen to.
DANNY PALMER
Yes.
GRAHAM CLULEY
It's a loading screen on a ZX Spectrum.
DANNY PALMER
Ah, yeah, that's a bit before my time.
GRAHAM CLULEY
The extra point was going to be if you could recognise it was Daley Thompson's Decathlon.
DANNY PALMER
See, I do know that game.
GRAHAM CLULEY
Well, folks, I don't know how you compare to Danny there.

Depending on how well you did, you've either just proven you're a veteran of the analog internet, or you still think punch cards are a pretty neat idea.

Either way, well played, everyone. Fair play, Danny.
DANNY PALMER
Yeah, I think 50%-ish there. I mean, that's a pass.
GRAHAM CLULEY
Yes, I think so. I think we'll give you that.

Now, funnily enough, sound is what I'm talking about today because something rather odd happened the other day to a chap called Matt Callahan.
DANNY PALMER
Hmm.
GRAHAM CLULEY
And he is a developer and he's one of those people who likes to use Bluetooth headphones. Do you have Bluetooth headphones or earphones?
DANNY PALMER
Yes. I mean, what I'm speaking to you on now is my sort of gaming ones here. These aren't the ones I go out the house with.

I don't buy fancy ones now, 'cause I'm just losing them all the time. They're either falling out your pocket, falling down the gap in the tube, they go through the wash.

I kind of miss plugging in.
GRAHAM CLULEY
The whole problem with these wireless earphones is they don't have a bloody wire, is it? If they had a wire, you wouldn't lose them.
DANNY PALMER
And I think this is part of the reason why there seems to be more people playing things loudly on their phones on public transport these days, but that's a whole other issue.
GRAHAM CLULEY
Well, some folks actually swear by them. What they like is that they can seamlessly switch from your laptop or your desktop computer to your phone.

Until of course your phone suddenly rings and your headphones completely refuse to switch over. And they're utterly convinced that your laptop is playing some sound.

It's playing some Finnish death metal.
DANNY PALMER
Connoisseur.
GRAHAM CLULEY
And so it just carries on ringing in your pocket and you're frantically clicking around on your PC trying to stop it making a noise so you can listen to your phone call.

Anyway, this is what happened to this chap, Matt, and his phone was ringing, but his earphones weren't swapping over. So he checked Spotify on his computer.

And that was paused and he checked YouTube and that wasn't playing any videos.

And the only thing which he actually had ultimately running on his laptop was one single browser tab sat on the AliExpress homepage.
DANNY PALMER
Ah, so that's the, is it Chinese retailer?
GRAHAM CLULEY
Yeah.
DANNY PALMER
Chinese Amazon.
GRAHAM CLULEY
It's an enormous site. It's not just for people in China, people all around the world use it. And this particular page, however, in his browser, it wasn't playing a video.

It wasn't actually playing anything as far as he could tell. It was just sitting there, but it was preventing his earphones from switching to his phone.

And he's a sort of curious chap and he wondered why might this be?
DANNY PALMER
You said he's a developer, so it sounds like this is the sort of thing he might tinker about with.
GRAHAM CLULEY
Yes, exactly. And so he looked at the browser tab to work out what was going on behind the scenes. And what he found was rather surprising.

Now, as we all know, websites absolutely love to recognise us when we return to them.

And the traditional way to do that is with cookies, which, you know, if you're a non-nerd, cookies are like little text files that get left on your computer and they say, this is Graham coming back again, you know, make sure to show him Doctor Who-related t-shirts and things like that.
DANNY PALMER
You get the exact same algorithms I get by the sound of it.
GRAHAM CLULEY
And that's one of the reasons why people love to block trackers and cookies. They use private browsing windows instead.

And because of this, websites have got sneakier over time, and a lot of them now try to fingerprint you when you visit them.

Now, they're not asking — it's not like going through security at an airport.

They're not actually asking for your fingerprints, but what they do is they take a really good look at you and they note down all of the details that when combined make you look different from other people.
DANNY PALMER
Huh. Interesting.
GRAHAM CLULEY
Yeah. Well, they don't look at the size of your nose or your haircut, but what they do is they look at maybe the size of your monitor, what the resolution is.

They might look at what fonts you have installed. They can look at what browser version you are using, huge amounts of information.
DANNY PALMER
It's one of those things where, you know, maybe the general public, for want of a better phrase, doesn't know this is happening. But no, sounds quite invasive from what you say.

If you can tell what size of monitor you are using, what your fonts are, what else can they see?
GRAHAM CLULEY
And it's actually the combination of factors, because it's all these little details.

One detail, like the resolution of your screen, or the current window size or whatever it may be, or what fonts you have installed — by itself maybe doesn't narrow you down to one particular individual.

But when it's hundreds of details all combined, that particular pattern, it might say, well, we've only ever seen one person with that particular mix before.
DANNY PALMER
Hmm.
GRAHAM CLULEY
So they won't necessarily know who you are, but they know that you're individual number 12,038.
DANNY PALMER
Yes. And you've got this size monitor, use this size font to visit these sites, et cetera, et cetera.
GRAHAM CLULEY
And you like Doctor Who t-shirts.
DANNY PALMER
Yes. I think about this in another way. I use Reddit quite a lot. I mean, I've got my account there, it's anonymous. I don't post anything under my name.
GRAHAM CLULEY
Yeah.
DANNY PALMER
Just for the sake of being anonymous on the internet.

But I reckon if you found my profile and saw which subreddits I posted in, you'd probably easily identify it's me through sort of my interests, you know, posting about this sports team, this computer game, Doctor Who.
GRAHAM CLULEY
Yes, exactly. You're gonna be Dungeons and Dragons. You're a bit into wrestling. See, I know enough about you, Danny.
DANNY PALMER
Yeah, you've identified my Reddit account there.
GRAHAM CLULEY
Yes, I think I probably could, that particular mixture.
DANNY PALMER
And that's why I have my Reddit account set to private.
GRAHAM CLULEY
So all of these details which can be grabbed by a webpage can pick you out from just about everyone else.

And what Matt found on AliExpress's website was that it had a piece of code which was doing just that, but it was audio fingerprinting.

And so the site would ask his browser, or any person going to the site, to generate a very specific, very precise sound.

Or rather, it gave the browser complicated maths to generate a sound.
DANNY PALMER
Yeah.
GRAHAM CLULEY
And then it paid close attention to the final result, because it turns out no two computers calculated the audio maths in precisely the same way.

So different web browsers running on different operating systems all crunch those numbers in their own slightly unique way.

There's microscopic little quirks in the final calculation.

It's a bit like how you can have two different pianos playing the same sheet music and they would still sound very slightly different.
DANNY PALMER
Yeah, I understand what you're getting at. So is the computer actually making this noise?

Can the user hear this noise, or is it so subtle the user themselves can't hear it, but the device can?
GRAHAM CLULEY
Well, this is what was really sneaky, was that AliExpress turned the volume of the noise it was generating down to zero. So you can't hear it.

It's not actually generating anything which is audible. As far as your computer is concerned, there isn't any media playing at all, just some background calculations happening.

Silence doesn't mean it can't be picked up by your hardware. So the calculations do actually go and grab hold of your computer's real audio system to do the computation.

And on Matt's setup, that was enough to make his headphones think that audio was actually playing on his laptop, even though it'd been programmed to say absolute zero.
Unknown
Hmm.
GRAHAM CLULEY
And so his phone, when it rang, got ignored by his Bluetooth headphones. So this is really sneaky, I thought.
DANNY PALMER
It's sneaky. It's very sort of — so many things these days seem to say, oh, we've seen this in a sci-fi movie.
GRAHAM CLULEY
Yeah.
DANNY PALMER
Sci-fi movies go, ooh, this is a scary way how things could end up. Companies seem to go, that's a great template for how to do things.
GRAHAM CLULEY
Yes. So they have built a tracking script, which is as quiet and invisible as it is possible to be.

It doesn't give itself away — well, it does give itself away, because it accidentally annoyed someone else's Bluetooth headphones. So this kind of thing isn't new.

It's not unique to AliExpress. It's just one of a bunch of tricks which websites have up their metallic sleeves in order to track you. And it could be used for good.

I mean, it can be done to work out if you're a genuine shopper or a bot, for instance.
DANNY PALMER
Yeah. Especially these days when so many people are using AI agents and that sort of thing to spam queues and things for gig tickets and whatnot.
GRAHAM CLULEY
Do you know what had happened to me today? I was on LinkedIn.

I'd written an article for a client of mine and I posted it up on LinkedIn saying, go and read this, you know, fascinating story. Go and read this.
DANNY PALMER
Know the feeling.
GRAHAM CLULEY
And within about 2 minutes, this guy had replied as though he had read the article and he had this pithy little comment and hahaha.

I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human.

And I went to look at his other comments and I saw a steady stream of every minute he's replying to someone else's article with his own 3-sentence comment on it.

Clearly been written by an AI, some of them even including emojis as well. But it's just got the stench of AI about it.
DANNY PALMER
Yeah. Gosh, it's so interesting and weird to me how someone whose job is writing — I mean, I take great pride in writing stuff and even for the most basic thing.

Well, yeah, it seems there are people who just sort of farm out everything to AI.

I actually made a LinkedIn post earlier today poking fun at this where I say, you can tell my work is not AI generated because you'll be able to see the errors in all the first drafts.
GRAHAM CLULEY
That's right. So plenty of browsers do try to stop this kind of fingerprinting, including this audio fingerprinting, for privacy reasons.

So Firefox and Brave, they scramble the reading so that trackers get an unreliable answer. I think what they actually do is they make all of the calculations look a bit generic.

So you can't distinguish as easily between them.
DANNY PALMER
It's like it says, oh, John Smith is using this site. And there's like a million other John Smiths out there in the world.
GRAHAM CLULEY
Yes. A bit. It's a bit like the Matrix. The Matrix when — is it Agent Smith or something?
DANNY PALMER
Smith, yeah.
GRAHAM CLULEY
Agent Smith gets replicated millions of times. Safari does something similar as well when you're private browsing, because it injects random noise into the Web Audio API's output.

So you wouldn't be able to tell with the human ear, but if anything is coming along and trying to work out any difference from the audio, even if it's silent audio, as in this case, it wouldn't be able to.

So you might not be going mad if your headphones start behaving strangely when you're visiting a shopping website.

And if you would rather your browser didn't do this kind of thing, what you can do is you can run a browser extension.

uBlock Origin is a good one, which can block this kind of behaviour for you and give you that extra little bit of privacy if you don't want to be tracked online.
DANNY PALMER
It's really interesting how there's some tech firms which are actively doing these things to try and build up people's privacy, to protect against the stuff that other tech firms are doing.
GRAHAM CLULEY
Yes.
DANNY PALMER
And a lot of it is behind the scenes. I mean, your average user will have no idea what is going on in this fight in the background while they're just browsing the internet.
GRAHAM CLULEY
There is this incredible arms race between different technology companies going on all the time.

The irony is, of course, some of the tech companies which are building these browsers are themselves advertising companies. Let's not beat around the bush, right?
DANNY PALMER
Yes. The internet is a very interesting and often flawed place, it turns out.
GRAHAM CLULEY
And on that note— I love it. Actually, maybe I'll make that my ringtone.
Unknown
This week's episode is supported by Vanta.
GRAHAM CLULEY
Joe, what's the thing that keeps you up at 2 o'clock in the morning, security-wise?
JOE
Honestly, whether I remembered to hit the record button.
GRAHAM CLULEY
No, no, no. I mean a real worry. No, like, have I got the right controls in place? Can I actually trust my vendors?
JOE
Nope. I'm still worried we might not actually be recording.
GRAHAM CLULEY
Okay, try this one for size. How do I ever climb out from under all these clunky old tools and manual processes?
JOE
Okay, fair enough. That does sound scary.
GRAHAM CLULEY
Well, that's where Vanta comes in. It takes the manual misery off your plate.

So no more wrestling spreadsheets, hunting down audit evidence, or slogging through endless questionnaires.
JOE
That's right. Their trust management platform continuously monitors your systems, centralises your data, and uses AI to flag risks and keep you audit-ready all the time.
GRAHAM CLULEY
Going for SOC 2, ISO 27001, GDPR, HIPAA, whatever it is, Vanta gets you there faster and lets you scale with confidence.
JOE
And actually get back to sleep.
GRAHAM CLULEY
Head to vanta.com/smashing to get started. That's V-A-N-T-A.com/smashing, and our listeners get $1,000 off.
JOE
And thanks to Vanta for supporting the show.
GRAHAM CLULEY
Joe, the record button, you definitely pressed it this time, right?
DANNY PALMER
Me?
JOE
I thought it was you.
GRAHAM CLULEY
Danny, what's your story for us this week?
DANNY PALMER
Now, Graham, I've been a technology journalist for over 15 years now, and I've focused on cybersecurity reporting for I'd say at least 10 of those.

That means I have seen and reported on hundreds of cyberattacks, data breaches, and other, let's call them incidents.
GRAHAM CLULEY
Yes.
DANNY PALMER
Over the years.
GRAHAM CLULEY
Yes.
DANNY PALMER
As I'm sure you know, so much of this stuff happens.

I mean, retailers, utility providers, government agencies, banks and financial services companies, charities, sports teams, even postal services.

You name the industry, I've likely written about a cyberattack, a hack, a data breach, a ransomware attack.
GRAHAM CLULEY
Yeah.
DANNY PALMER
Or a DDoS attack, which has affected the organisation in some way. And there's new stuff keeps appearing, as we've seen in recent times with AI and whatnot.

But it is also a bit weird to think about how long I have been doing this.

When I first started at ZDNet back in 2016, one of my first stories was about a ransomware attack against a local council.

And the council didn't pay because the ransom demand was a whopping £500, which is just amazing to think about in terms of how much ransom demands and things have gone up.
GRAHAM CLULEY
You would be thanking your lucky stars these days, wouldn't you? 500 quid?
DANNY PALMER
Yeah.
GRAHAM CLULEY
Brilliant.
DANNY PALMER
You'd think the cybercriminal in question might be a bit slow on the uptake. It's like that bit in Austin Powers where Dr. Evil's going, $1 million, and just like, yeah, whatever.

So anyway, loads of these attacks in many, many cases, especially when the entity affected by the cyberattack is here in the UK.

As a cybersecurity reporter, it has been my job to find out exactly what is going on, which sometimes can be harder than other times.

I've made phone calls or sent emails to PR communication teams to verify they've been hit by a cyberattack.

More often than not, the organisations in question don't want to speak widely about it because they often cite ongoing issues, which is understandable.

I see their perspective from that.

You know, my job is to try and get information about what's going on, but then organisations, if they've got an ongoing thing, they don't want to jeopardise that.

I suppose you can think of it like when a court case is ongoing, the news publications can't really say much about it just because it might impact what is going on.
GRAHAM CLULEY
Sure.
DANNY PALMER
As I'm sure you've seen in many cases, a company will put out a rather generic statement saying they've been hit by a sophisticated cyberattack.
Unknown
Yeah.
GRAHAM CLULEY
No one wants to get hit by a dumb attack, do they?
Unknown
No. No.
DANNY PALMER
Sometimes it turned out to be a teenager that guessed the internet-facing admin password was 1234.

Not that sophisticated, but I suppose they don't want to seem like they've been foolish, but these things eventually sometimes come out. Anyway, why am I talking about this?

I assure you, Graham, it's not just ranting.
GRAHAM CLULEY
Clearly it is.
DANNY PALMER
It is, it is sort of me just ranting.

This week, cyber intelligence agencies from the United States, Canada, the United Kingdom, Australia, and New Zealand, collaboratively known as Five Eyes, they've got together and they've published advice to organisations on what they should do when they get hacked.
GRAHAM CLULEY
Sorry, I may have misheard you. This is Five Eyes. This isn't Five Guys, correct?
DANNY PALMER
It's not the burger chain. No, Five Eyes.

And the advice that Five Eyes have given organisations is that if you get hacked or face a cyber incident, please be a bit clearer in your communications about what has happened.
GRAHAM CLULEY
Right.
DANNY PALMER
So they put out this document. It's titled Communicating Under Pressure: Best Practices for Service Providers.

And that guidance has been published by CISA, which is the agency responsible for securing critical infrastructure in the United States.

But it's also been written with input from other Five Eyes agencies, including the FBI, the UK's National Cyber Security Centre, and the Australian Signals Directorate.

The aim of the 9-page document is to provide guidance to organisations on how they can plan and execute what they say is clear, timely, accurate, and audience-appropriate communications during IT and OT outages as a result of cyberattacks and other issues.

As we've just discussed, these cyberattack things appear to be quite common these days.
GRAHAM CLULEY
This sounds like a real novelty, Danny. So it's going to be clear and timely and accurate and appropriate.
DANNY PALMER
Yes.
GRAHAM CLULEY
For the audience. This sounds like genius, whoever came up with this idea, rather than obfuscated and complicated and difficult for people to peruse and unscramble.
DANNY PALMER
Yeah. Yeah.
GRAHAM CLULEY
I'm glad we've got these intelligence agencies to tell us maybe this would be a good idea.
DANNY PALMER
Yeah, they're really earning their coin here.
GRAHAM CLULEY
Yeah.
DANNY PALMER
Well, unfortunately, it seems for many organisations, especially around the corporate communications areas, this is brand new information to them.

But the advice is based on a handful of key ideas.

And the first around these is to ensure your organisation already has a plan around communications should it be hit by an incident.

Businesses are told to have contingency plans in place for their cybersecurity and other teams on how they should react if they get hacked or breached.

So it only makes sense that the communications team should be a part of that. I mean, there should be some sort of standard document.
GRAHAM CLULEY
Yeah.
DANNY PALMER
It might not be as simple as it sounds because of course every cyberattack is different and they can cause different types of disruption to an organisation, which means statements and communications might need some tailoring depending on what's going on.

Something I've just thought of as well is we might have to factor into this: if you're hit by a certain type of cyberattack, can you even get that information out there into the world?
GRAHAM CLULEY
Oh, absolutely.
Unknown
Yeah.
GRAHAM CLULEY
Because if you've been hit by ransomware and your email server is down, you haven't maybe got your address book. It's tricky.

Often when we've seen a company which has been hit by something like ransomware, what you find is they've actually been communicating with each other via WhatsApp.
DANNY PALMER
Yes.
GRAHAM CLULEY
Or using some other system because none of our IT systems work anymore.
DANNY PALMER
Yeah, I've heard various cases where organisations which have been hit have discussed how they set up things like Google email addresses or WhatsApp, that sort of thing, just to communicate.

Anyway, so the plan is to have a plan.

So if the worst happens, someone in an organisation knows how to react — stakeholders, partners, customers, and yes, nosy gits like me in the press.

If we have questions, they can actually answer those questions. So that's tick one.

So that leads to the second piece of advice, which is that those who have been hit with a cyber incident should, quote, practice transparency and avoid PR and marketing language.

Yes.
GRAHAM CLULEY
Maybe don't use any people in the PR and marketing department. Maybe if you want, get a developer to write your statement.

Get someone in the IT department to describe what's happened to the company. Now, there may be drawbacks in that approach as well.

You could have an impact on your stock price, could have an impact on your brand reputation, but it'll be clinically honest. That's the thing you can guarantee.

There will be absolutely probably far more transparency than you could ever have wanted.
DANNY PALMER
It is this advice around the PR marketing language which has really sparked my interest. There's a lot of fluffy marketing language which doesn't really tell you anything.

Now, as a reporter, this is frustrating. You know, it just basically sort of barricades me from doing my job in terms of trying to actually find out what has happened.

But it's even more worrying for customers if they feel like they've been left in the dark by vague statements. In the long run, it doesn't help anyone.
GRAHAM CLULEY
Can I play devil's advocate here for a second?
DANNY PALMER
Please do.
GRAHAM CLULEY
Because obviously I have complained before about the press releases from organisations who've been hit by sophisticated cyberattacks and all the rest of it.

But if you put yourself in the position of a company which has suffered an attack and you are saying, Danny, you need to be transparent and you need to explain what's happened, it's not always obvious what has happened.
DANNY PALMER
That is true. That is true.
GRAHAM CLULEY
And it's not always obvious what the scale of it is.

So it's like, well, we know this has happened, but we don't know yet whether our customers are really impacted, or whether it's 3 of our customers or 3 million of our customers.

And it's going to take time for us to ascertain that.

So much as I would love companies to be more upfront about these things, there are sometimes quite legitimate reasons why they may find it impossible to confirm everything all at once.
DANNY PALMER
That is very true.
GRAHAM CLULEY
What would you as a journalist like them to say to you? At that early initial point?
DANNY PALMER
Me using my miserable journalist hack brain.

Well, there have actually been some high-profile cyberattacks over the years where the organisation affected has been pretty transparent about what has happened during the incident and its resolution.

I think one of the best examples of this, NotPetya, remember that?
GRAHAM CLULEY
Yes.
DANNY PALMER
So that hit organisations around the globe in 2017. One of the organisations hit by this was the shipping giant Maersk.

And if I recall correctly, the company's security and leadership teams were rather transparent. This instance hit us, here's how we're dealing with it.

And, you know, they completely gave updates on how they're trying to fix it.

I mean, this was a major shipping company where a lot of stuff that goes around the world was reliant on it.
GRAHAM CLULEY
Absolutely. I mean, if you think about all the problems which are being caused right now by the Straits of Hormuz being closed.

Maersk, this huge shipping organisation, their ships weren't moving.
DANNY PALMER
Yeah.
GRAHAM CLULEY
Because their IT systems were down. And I think you're right, they demonstrated real fantastic leadership. I mean, they came out looking like rock stars after this.

They were hit by a cybersecurity breach, but they actually turned it in some ways into a great piece of branding for them because they came out looking like heroes.
DANNY PALMER
Yeah.
GRAHAM CLULEY
Not only did they not pay, but they were so open about what had happened.

And what you find is that when you are open, when you do speak to your clients, and your customers and your partners and explain to them what's happening, you actually get a lot of sympathy.
DANNY PALMER
Yeah. These organisations that should have been doing as much as they can to prevent a cyberattack. It's the cliché, isn't it? You only need one hole in the armour to get in.
GRAHAM CLULEY
So this guide, which has come out from Five Eyes, is there one sort of final piece of advice from them which companies should take on board?
DANNY PALMER
They just want organisations to be very, very clear about what happened. In my experience, this transparency helps reassure the public. It can help reassure the companies around it.

Other cybersecurity leaders like to hear about these things. They can learn lessons.

I mean, I've got an interview that'll be coming up that we publish shortly for Inverness Security Magazine, where I spoke to a CISO about a ransomware attack that hit them and how he recovered without paying the ransom, which is, yeah, you don't really get from PR speak.

So, yeah, to answer your questions, what's the final piece of advice?

It recommends once an incident has been dealt with, organisations should detail the technical information about what happened, what the cause was of the incident.

That sort of thing can help other organisations from falling victim to attacks. So maybe it is those IT workers and those devs that need to write those documents.

Maybe not the ones doing the first PR, but at the end of the cycle, real-world lessons can be really helpful to organisations.

And I'm not just saying that as a reporter with a vested interest in digging out information. I promise.
GRAHAM CLULEY
This episode is sponsored by Intruder. Now, Joe, quick quiz. How often does your team ship code?
JOE
Multiple times a week, maybe more if someone's had too much coffee.
GRAHAM CLULEY
And how often do you get a proper pen test?
JOE
Oof, once a year if we remember.
GRAHAM CLULEY
Well, that's the problem right there. Software moves weekly. Pen testing moves yearly. So most of what you ship never actually gets tested properly.
JOE
Which is exactly the gap Intruder's AI pen testing closes. You get the depth of a real manual pen test, but on demand, whenever you need it.

No scoping calls, no 6-week wait, and it costs a fraction of the traditional price.
GRAHAM CLULEY
It's built by Intruder's own certified pen testers, so the agents catch the complex stuff human testers can miss. And every finding is validated against your actual app.

Real issues, not noise. You get an audit-ready report within hours.
JOE
And it plugs straight into Intruder's full platform. Attack surface monitoring, cloud security, vulnerability management, all watching around the clock.

It flags what's exploitable, what to fix first, and how, so your team can act without waiting around for the security team.
GRAHAM CLULEY
Over 3,000 companies already trust Intruder with their attack surface.
JOE
You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first.
GRAHAM CLULEY
So just head to intruder.io/smashing. That's intruder.io/smashing.
JOE
And thanks to Intruder for supporting the show.
GRAHAM CLULEY
And welcome back, and you join us at our favourite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.
DANNY PALMER
Pick of the Week.
GRAHAM CLULEY
Pick of the Week is the part of the show where everyone chooses something they like.

It could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish.

It doesn't have to be security-related necessarily. Well, my pick of the week this week is not security-related. Danny, I don't know if you consider me a bit of a sportsman.
DANNY PALMER
Oh, definitely.
Unknown
Yeah.
GRAHAM CLULEY
Do you really?
DANNY PALMER
Oh, excellent. No, not really. No, I don't think sports is, a forte. I mean, you're like me — I enjoy watching sports, playing it not so much.

I once took a shot on goal and it went out for a throw-in. I'll leave it there.
GRAHAM CLULEY
Dear me. Anyway, last weekend, hundreds of people from around the world congregated on the tiny island of Easdale in the Inner Hebrides off the shores of Scotland.
DANNY PALMER
Sounds remote.
GRAHAM CLULEY
Normal population of about 60, but they had about 350 people descend on them. Why were they there? I will tell you why they were there.

Because, as I'm sure you're aware, Danny, it was the World Stone Skimming Championships.

So for anyone who's ever skimmed a stone, I wouldn't say I've ever successfully skimmed a stone.
DANNY PALMER
No, it's gone in the water.
GRAHAM CLULEY
Yes, it goes in the water and makes a bit of a bloop sort of sound.
DANNY PALMER
Sinks.
GRAHAM CLULEY
Yeah, it's not that great. It's more sort of a sort of uh-oh kind of noise, really.

When you skim a stone, the idea is that it bounces along the water a bit like a Barnes Wallis bomb going up against a Nazi dam sort of bouncing along and how far can you get it?

Well, they have this competition in Scotland. People come from all around the world. They were coming from Africa. They were coming from the Antipodes.
DANNY PALMER
It's a world championship.
GRAHAM CLULEY
Yeah, it's the world champ— it's not the World Series in America, which doesn't involve 99% of the world. This was the entire world, practically, were involved in stone skimming.

Now, sometimes it's quite controversial, it turns out. Last year, there was some controversy. Officials caught some competitors meddling with the stones.

They were sanding their stones into suspiciously perfect discs.
DANNY PALMER
Ooh.
GRAHAM CLULEY
In order to cheat.
DANNY PALMER
Sounds a bit like tampering of cricket balls.
GRAHAM CLULEY
Yeah, exactly. And so they've now hired an actual geologist to police the integrity of the stones.
Unknown
Now—
DANNY PALMER
You're always better off with a geologist around.
GRAHAM CLULEY
Very wise. Very wise.

Well, I know lots of people are excited to hear about the World Stone Skimming Championship, but of course you're thinking that was last weekend and I wasn't on the island of Easdale last weekend or in the Outer Hebrides.

What can I do? Have I missed it for another year? Well, fear not, fear not, because I have researched this and I've found a YouTube video which is 4 and a half hours long.
DANNY PALMER
Nice.
GRAHAM CLULEY
Live coverage of the World Stone Skimming Championships. No spoilers. I'm not gonna reveal who wins, but if you want to go and check it out, links in the show notes.

Danny, I know you love your sport. Will you be checking out?
DANNY PALMER
I honestly think I will, 'cause this sounds fascinating. And I also wanna see what the commentators speak about for 4 and a half hours.
GRAHAM CLULEY
Yeah, well, I wouldn't get too carried away imagining there's actually gonna be commentary.

There may be people introducing each skimmer, but there's not a lot of, you know, you don't sort of get Sue Barker or her — do the competitors get big entrances like World Championship boxers?

That'd be fantastic, wouldn't it? Anyway, the World Stone Skimming Championship is, of course, my pick of the week. Danny, what's your pick of the week?
DANNY PALMER
Well, by complete coincidence, Graham, my pick of the week is also water-based.
GRAHAM CLULEY
Okay.
DANNY PALMER
You may remember that from one of my previous appearances on Smashing Security that this year, I finally started playing Dungeons & Dragons at a venue which runs games you can drop in and out of.
Unknown
Yes.
DANNY PALMER
And they're very fun, very convenient. People like me with busy lifestyles, he tries to convince himself. But no, I've attended a few sessions and—
GRAHAM CLULEY
Right.
DANNY PALMER
Now, outside of journalism and editorial writing, I worry that I'm not the most creative person in the world.

So I — it's taken me a bit of time to sort of come up with my character backstory and lore.
GRAHAM CLULEY
Okay.
DANNY PALMER
But it finally seems to be coming together.

He's evolved into something of a nautical explorer, someone who is an expert in sailing on the high seas, and searching for long-lost islands for treasures.

Some people might say this sounds a bit like a pirate. Keen to do my research, I've been reading a book called The Pirate's Code: Laws and Life Aboard Ship.
Unknown
Oh yes.
DANNY PALMER
It's by Dr. Rebecca Simon, a historian who specialises in the Golden Age of Piracy. So think late 1600s into the early 1700s.

And Graham, I have learned a lot about pirates by reading this book.
GRAHAM CLULEY
Okay.
DANNY PALMER
Turns out, while popular pirate tales get a lot right, they also get quite a bit wrong.
GRAHAM CLULEY
Right.
DANNY PALMER
For a start, as far as I can tell, there were actually no wisecracking talking parrots.
GRAHAM CLULEY
What's the point of that? Why have a parrot?
DANNY PALMER
Company, I suppose. I think they used to sort of help with getting rid of vermin, apparently.
Unknown
Oh, okay.
DANNY PALMER
We apparently have Robert Louis Stevenson's 1883 novel Treasure Island to thank for the pirates and for walking the plank as well.

That wasn't actually really a thing — it just became a thing in fiction. I think one pirate maybe tried to do it, but he wasn't very successful at it.

But something I found interesting while reading this is there's arguably some similarities between pirates of the 17th and 18th centuries and cybercriminals today.

And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.

You see, something I learned from this book was that one of the reasons that men — and it was for the most part men — signed up for life on a pirate ship was because the paying conditions were much better than working on a legitimate vessel, be it a trading ship or in the Royal Navy or something like that.

And this had me thinking about how a lot of malware developers and BEC scammers try to justify doing this work, saying, oh yeah, we're doing crimes, but it pays more.

They also see themselves as taking from the rich — they often mean people in Europe and the United States.

If they stole my savings, I don't think I'd be seeing it as some sort of romantic ideal about stealing from the better off.
GRAHAM CLULEY
Well, yeah, I think this is a completely spurious argument if they are seriously using this.

But I mean, if you think of how many people are romance scammers or defrauding the elderly out of their savings.
DANNY PALMER
No, they see themselves sometimes just as, yeah, oh, making the money or living outside of the rules of the norm, as it were.

Like cybercrime, piracy — yes, it has potential vast riches, but do it for too long or push things too far and you can get caught, which if anything this book has taught me is that didn't go very well for pirates if they were caught.
GRAHAM CLULEY
So you are enjoying this book. What's the name of the book again?
DANNY PALMER
It is called The Pirate's Code: Laws and Life Aboard Ship by Dr. Rebecca Simon.

I definitely recommend this book because it ties some real history to think about in a fun way — pirates are very much in the public consciousness, but you think about how much we actually know about them.

So I recommend that book 100%.
GRAHAM CLULEY
Well, that just about wraps up the show for this week. Thank you so much, Danny, for joining us on Smashing Security.
DANNY PALMER
Thank you. Pleasure as always.
GRAHAM CLULEY
I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way to do that?
DANNY PALMER
Best ways at the moment, probably on LinkedIn, where I try to regularly post, and Bluesky as well. That's just more my general ramblings rather than cybersecurity things.

They're very interesting, I promise you.
GRAHAM CLULEY
And of course, you can find me, Graham Cluley, on LinkedIn and Bluesky and Mastodon and Instagram and TikTok. The list goes on.

Or you can follow Smashing Security on Reddit and Bluesky and Mastodon as well. And don't forget to ensure you never miss another episode.

Follow Smashing Security in your favourite podcast app, such as Apple Podcasts, Spotify, and Pocket Casts for episode show notes, sponsorship info, guest lists, and the entire back catalogue of more than 480 episodes.

Check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
DANNY PALMER
Bye-bye.
GRAHAM CLULEY
You've been listening to Smashing Security with me, Graham Cluley.

And a huge thank you to Danny Palmer for joining me this week and to this week's sponsors, ThreatLocker, Intruder, and Vanta, whose money we've accepted with enormous enthusiasm and only a small amount of shame.

And a very special thank you to the following fine chums. Travis West, who's riding in, sorting out his security posture, and riding off again. We've got Richard Anand.

Cheers to Panda Bear, whose true identity remains one of the great unsolved mysteries of the world. And also to Panos. Sounds like a Greek loaf of bread if you ask me.

Big love to Billy, a man unbothered by surnames. And to Robert Martin and Govind Acharya, a name that sounds like it belongs to someone who knows something we don't.

And finally for this week, Jamie Forster, Scotia, and JBSK. Four letters there with zero explanation and maximum intrigue.

Those fine, upstanding, and clearly slightly reckless individuals are members of Smashing Security Plus, which means they get their episodes ad-free earlier than the general public, and perhaps most importantly, they get their names read out at the end of the show in a tone that, well, sort of hovers somewhere between sincere gratitude and mild ridicule.

If you would like to join them in this exclusive club of the wonderful and slightly foolish, head over to smashingsecurity.com/plus where for a modest fee, you too can be publicly mocked by a middle-aged British cybersecurity podcaster.

So yes, you can become a patron, or if you'd rather keep your money, there are plenty of ways to support the show that don't cost a penny.

You can like, you can subscribe, you can leave a 5-star review wherever you listen, you can tell your friends about us, or you just shout about the podcast in the pub until people politely ask you to leave.

Every little bit helps, and frankly, it really makes all the effort worthwhile. So until next time, cheerio. Bye-bye.

EPISODE DESCRIPTION:

When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web.

Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated."

All this and more in episode 484 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

EPISODE LINKS:

SPONSORS:

  • ThreatLocker - Book a demo today and start securing your organisation.
  • Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
  • Intruder - The depth of a manual pentest, on-demand. Start an AI pentest in minutes - 25% off your first pentest for Smashing Security listeners.

SUPPORT THE SHOW:

Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.

Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

FOLLOW THE SHOW:

Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

THANKS:

Theme tune: "Vinyl Memories" by Mikael Manvelyan.

Assorted sound effects: AudioBlocks.

Privacy & Opt-Out: https://redcircle.com/privacy