Skip to content
PodcastsTechnologyDavid Bombal

David Bombal

David Bombal
David Bombal
Latest episode

601 episodes

  • David Bombal

    #605: Flock Cameras: What They Can Reveal About Your Life

    12/09/2026 | 22 mins.
    Big thank you to DeleteMe for sponsoring this video. Use my link join https://joindeleteme.com/Bombal or use the QR code in the video to get 20% off.

    Your license plate could reveal more than you think. Flock cameras, vehicle tracking and OSINT can turn information about your car into clues about where you live and your daily routines.

    I’m joined by an OSINT expert to discuss how vehicle information can be connected with public records, why surveillance raises privacy concerns and what happens when people trust an incorrect license plate match.

    He shares his experiences of locating a missing car after a police search came up short and investigating a hit-and-run using a partial plate and publicly available
    information.

    We discuss:
    • Flock cameras and vehicle identification beyond license plates
    • How vehicle data can expose patterns in your movements
    • License plate recognition errors and the importance of verification
    • How public records can connect a vehicle to a person
    • The risks of surveillance access being abused
    • Privacy measures, their limitations and the need for accountability
    • DeFlock and community scrutiny of surveillance cameras

    How much can someone discover about you from the information you leave exposed?

    // Mishaal Kahn’s SOCIALS //
    LinkedIn: / mish-aal
    Website: https://www.mishaalkhan.com/
    Tool created: https://www.operationprivacy.com/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:47 - The Growing Flock Camera Controversy
    01:28 - What Are Flock Cameras Actually Collecting?
    02:33 - Police Misuse and Abuse of Surveillance Data
    03:45 - Mapping and Avoiding Flock Cameras
    04:57 - How Personal Data Fuels Scams
    06:54 - What Can Police Actually Do With Flock Data?
    07:12 - Testing Flock: A Real Missing Vehicle Case
    09:09 - How Mishaal Found the Vehicle Himself
    10:20 - Drones: The Next Level of Surveillance
    11:11 - How Can You Protect Your Privacy?
    13:07 - Facial Recognition Is Expanding Everywhere
    14:13 - AI Can Rebuild Your Entire Pattern of Life
    15:51 - What Can Someone Find From Your License Plate?
    17:16 - Solving a Hit-and-Run With a Partial Plate
    19:08 - What Could a Rogue Police Officer Do?
    20:28 - Is There Any Hope for Privacy?
    21:53 - Where to Learn More About Privacy and OSINT

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #flockcameras #defcon #privacy
  • David Bombal

    #604: How He Infiltrated LockBit and Helped Get Them Indicted

    12/09/2026 | 24 mins.
    Big thanks to Proton Drive for sponsoring this video. You can use my link http://proton.me/drive/davidbombal to sign up for Proton Drive and get 40% discount.

    John DiMaggio created fake identities, profiled ransomware operators and spent approximately 18 months earning the trust of LockBit.

    In this interview, John explains how his investigation led to work with the FBI and the UK’s National Crime Agency, contributed to indictments and resulted in death threats against him. He also reveals how the work affected his mental health, relationships and everyday life.

    John shares the remarkable story of a young REvil hacker connected to the Kaseya ransomware attack and its $70 million ransom demand. He explains how ransomware operators are recruited, manipulated and sometimes controlled by intelligence agencies.

    You will also learn why stolen cryptocurrency is difficult to spend, how Bitcoin tracing and money-laundering mistakes expose cybercriminals and why technical hacking skills do not make someone good at hiding money. Finally, John warns aspiring researchers not to approach ransomware gangs without professional training and support. He discusses his new book, Owned, and how he plans to use his experience to help cybersecurity teams and business leaders prepare for ransomware attacks.

    // Link to No Starch Website for Jon DiMaggio’s Book //
    Order Owned on No Starch: https://nostarch.com/owned
    Use Coupon Code OWNED30 for 30% off Owned at NoStarch.com

    // Jon DiMaggio’s SOCIALS //
    Website: https://arkemcyber.com/
    X: https://x.com/Jon__DiMaggio
    LinkedIn: / jondimaggio

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:36 - Introduction
    01:28 - Infiltrating the LockBit Ransomware Gang
    03:45 - Working With the FBI & NCA
    04:55 - Sponsor – Proton Drive
    06:54 - Stories From the Ransomware Gang
    07:35 - Befriending a Hacker
    10:21 - The Kaseya Ransomware Attack
    12:10 - Arrest, Extradition & a 14-Year Sentence
    13:12 - An Unexpected Message From Prison
    14:57 - The LockBit Story & the Mental Health Toll
    16:30 - Advice for Young People Drawn to Cybercrime
    18:09 - Why Hackers Can’t Easily Spend Their Money
    19:12 - How to Become a Jon DiMaggio
    21:58 - What’s Next for Jon DiMaggio
    23:08 - Preparing Companies for Ransomware Attacks
    23:52 - Final Thoughts

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #lockbit #ransomware #revil
  • David Bombal

    #603: How Age Verification Threatens Your Online Privacy

    08/09/2026 | 47 mins.
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    Age verification is spreading across the internet. It promises to protect children, but what happens when accessing a website or using your own device requires facial recognition, identity documents or third-party verification?

    David speaks with Alexis Hancock from the Electronic Frontier Foundation about the growing privacy risks surrounding age verification and digital ID systems. They examine how these technologies could threaten online anonymity, create new surveillance infrastructure and expose sensitive personal information.

    Alexis explains why age verification alone does not teach children how to stay safe online, how data brokers and behavioral advertising contribute to the problem, and why banning VPNs or weakening encryption would make everyone less secure.

    They also discuss zero-knowledge proofs, facial recognition, encryption backdoors, government surveillance and the danger of building a digital identity system that could be abused by future governments.

    Finally, Alexis shares practical ways to protect your privacy, including using encrypted communication, learning from EFF’s Surveillance Self-Defense guides and contacting elected representatives when harmful legislation is proposed.

    // Alexis Hancock’ SOCIAL //
    LinkedIn: / alexishancock

    // EFF Website REFERENCE //
    https://www.eff.org/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Intro
    0:41 - Alexis Hancock background // Who are the EFF
    01:48 - Eroding privacy & age verification
    08:48 - Online safety for children
    12:25 - Online monitoring
    14:20 - ThreatLocker sponsor segment
    15:27 - Big tech vs government
    17:49 - How to fight for privacy
    20:19 - Online censorship & privacy
    26:17 - The push for age verification
    29:29 - Age verification "whack-a-mole"
    33:03 - Parental control vs age verification
    36:24 - What about non-tech savvy people?
    41:02 - Zero-knowledge proof
    44:48 - Is it too late? // Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #ageverification #privacy #bhusa2026
  • David Bombal

    #602: How Compilers Turn Secure C Code Into Vulnerable Binaries

    08/09/2026 | 30 mins.
    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces.

    David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure.

    Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns.

    Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped.

    // Christopher Domas’ SOCIAL //
    LinkedIn: / christopher-domas
    GitHub: https://github.com/xoreaxeaxeax
    X: https://x.com/xoreaxeaxeax

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:48 - Intro
    02:05 - Different Ways of Exploiting CPU’s
    04:10 - The C Specifications
    06:17 - The Compiler Deleting Nemsec
    08:40 - Do we need to use a new Compiler ?
    10:09 - Compiler Inventing Vulnerabilities
    12:13 - Don't Give up Writing Secure Code
    12:44 - Sponsored Section
    14:25 - Any Easy Options To Create A New Compiler ?
    15:09 - Chris’s Presentation at Black Hat
    20:00 - Weird Situations with Size of Data
    21:22 - What Can Developers Do ?
    23:32 - Who Can Leverage this Vulnerability ?
    25:02 - Could AI Make it Easy For Attackers To Leverage This?
    28:27 - Recommendations For Developers
    29:48 - Advice To Be Like Chris
    30:36 - Conclusion & Outro

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #bhusa2026 #securecoding #compiler
  • David Bombal

    #601: Google Researchers Hacked the Pixel Phone using Audio Messages

    08/09/2026 | 39 mins.
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device.

    David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10.

    The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access.

    They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones.

    Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive.

    These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected.

    // Seth Jenkins SOCIAL //
    LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/
    X: https://x.com/__sethJenkins

    // Natalie Silvanovich SOCIAL //
    X: https://x.com/natashenka?lang=en
    Website: https://natashenka.ca/

    // Website REFERENCE //
    Google Project Zero website: https://projectzero.google/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU//
    0:00 - Intro
    01:00 - ThreatLocker sponsor segment
    02:10 - Natalie Silvanovich background
    04:00 - Seth Jenkins background
    04:49 - Zero click audio codec vulnerability
    05:41 - Disclaimer
    06:07 - Hacking using audio files // How it works
    10:23 - What happens in the sandbox
    13:27 - The next step
    15:15 - Running into issues
    22:55 - Would someone notice the hack?
    26:20 - Not secure by default
    27:44 - Using AI assistance
    29:44 - How to reduce attack surface
    34:57 - How to get into cybersecurity
    39:05 - Conclusion


    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!


    Disclaimer: This video is for educational purposes only.

    #google #bhusa2026 #pixel10
More Technology podcasts
About David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content. David’s details: Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co Website: http://www.davidbombal.com YouTube: https://www.youtube.com/davidbombal All the best! David
Podcast website

Listen to David Bombal, The Big Tech Show and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features