
You Are The Proxy - Hackers, Experts, and Bad Advice
About this episode
In this episode, we continue with a closer look at what cybersecurity competence actually means, and why qualifications, compliance frameworks, and public reputation are poor substitutes for understanding how real attacks work. We explore the cryptography behind Proton Mail, public and private keys, fingerprints, and what you can do with PGP word lists. We’ll also discuss passkeys, account recovery, SIM swaps, ClickFix malware, infostealers, VPN blocking, and the residential proxies that allow malicious traffic to hide behind ordinary household IP addresses.
In this week’s episode:
- Hackers, threat actors, security influencers, and the risks created by confident but inaccurate advice
- Kerckhoffs’s principle: designing security under the assumption that the enemy knows the system
- How public and private keys work, including Proton Mail encryption, digital signatures, fingerprints, and independent key verification
- Using the PsySecure Workbench and PGP word lists to make cryptographic fingerprints easier to exchange and verify
- The problem with passkeys, and why weak account recovery can undermine their security
- ClickFix attacks that imitate Cloudflare verification pages and trick users into running malicious terminal commands
- How infostealers target browser data, authenticated sessions, cookies, passwords, and other valuable information
- Why VPN traffic is increasingly blocked or challenged while attackers move toward residential proxies that resemble legitimate users
- You are the proxy: How cheap smart home devices, streaming boxes, thermostats, and cameras, can become hidden residential proxies
- The normalization of identity verification, digital ID checks, and other invasive systems
Show Links:
- The Hidden Backdoors Inside Millions of Smart Devices (WSJ): https://www.youtube.com/watch?v=apEPPKYgLL0
- keys.openpgp.org: keys.openpgp.org
- PsySecure Workbench: https://psysecure.com/workbench
- An Investigative Framework for Auditing the Security & Privacy of Mobile VPNs: https://www.ndss-symposium.org/wp-content/uploads/2026-s1573-paper.pdf
Matrix Community Rooms:
- Matrix Community Space: https://matrix.to/#/#psysecure:matrix.org
Individual Room Links:
- https://matrix.to/#/#lockdown-intro:matrix.org
- https://matrix.to/#/#lockdown-podcast:matrix.org
- https://matrix.to/#/#lockdown-general:matrix.org
How to check public key fingerprint from the command line:
gpg --show-keys --with-fingerprint public_key_file.asc
★ Support the show on Patreon ★
Get every episode summarized
Each time The Lockdown - Practical Privacy & Security publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from The Lockdown - Practical Privacy & Security

Hiding in Plain Sight, The Art of OSINT with Tony Daly
The Lockdown - Practical Privacy & Security

It's Time to Think Like A CISO
The Lockdown - Practical Privacy & Security

034 - Final Episode
The Lockdown - Practical Privacy & Security

033 - Black Mirror - Is the UK's Surveillance State Coming to America?
The Lockdown - Practical Privacy & Security