S6, E245 - Hard-coded Secrets and Unencrypted Data: A Digital Security Nightmare episode artwork

EPISODE · Jun 16, 2025 · 15 MIN

S6, E245 - Hard-coded Secrets and Unencrypted Data: A Digital Security Nightmare

from Privacy Please · host Cameron Ivey

Send us Fan MailSeveral popular Chrome extensions, including privacy and security tools, have been found leaking sensitive data through unencrypted HTTP and hard-coded credentials in their code. Security is both hard and easy - hard because of existing unencrypted protocols and trust placed in developers, but easy because fundamental security practices should be common knowledge in 2025.• Chrome extensions including DualSafe Password Manager and Avast Online Security are leaking sensitive user data• HTTP vs HTTPS - the 'S' stands for security and encrypts data transmission over the internet• HTTPS Only extension from EFF forces secure connections when browsing• Hard-coded credentials in extensions create permanent security vulnerabilities• Developers sometimes collect excessive data "just in case" rather than minimizing collection• OWASP (Open Web Application Security Project) provides essential resources for developers• Technology abstraction makes users less aware of security fundamentals• The newly restarted OWASP Nomad chapter offers virtual community for application securityCheck out our GitHub repository of privacy resources at "Awesome Privacy Engineering Tools" for more information on implementing better privacy practices in development.Support the show

Send us Fan Mail Several popular Chrome extensions, including privacy and security tools, have been found leaking sensitive data through unencrypted HTTP and hard-coded credentials in their code. Security is both hard and easy - hard because of existing unencrypted protocols and trust placed in developers, but easy because fundamental security practices should be common knowledge in 2025. • Chrome extensions including DualSafe Password Manager and Avast Online Security are leaking sensitive ...

NOW PLAYING

S6, E245 - Hard-coded Secrets and Unencrypted Data: A Digital Security Nightmare

0:00 15:15

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Never Time to Give Up Shadoe Lass A nod to the classics with a note from the future. A project meant to encompass every call I wanted to make but never went through. Seriously, it's just me, calling you. Pick up the phone? :) Hosted on Acast. See acast.com/privacy for more information. Explicit Unfiltered Casefile Presents Unfiltered invites guests from all walks of life to share real stories about justice and transformation. Join host Raquel O'Brien for a series of raw and honest conversations from a range of perspectives in an invitation for you to make up your own mind. No topic is off-limits. Hosted on Acast. See acast.com/privacy for more information. Explicit I am Consciously Curious Victor Chan I am Consciously Curious is a Chicago based podcast that dissects passionate individuals in various industries. The goal is to share their stories to inspire you to cultivate meaning within your own space. If you are interested in coming on or know someone that would be great for the podcast, please message us on fb/ig: @iamconsciouslycurious Explicit TCAST: The Future of Data & AI TARTLE The Data Intelligence Podcast (TCAST) explores the intersection of AI, data privacy, and ethical technology. Join Alexander McCaig and Jason Rigby as they decode the future of data ownership, artificial intelligence, and digital privacy with industry leaders, researchers, and innovators.Each episode delivers actionable insights on:AI and machine learning developmentsData privacy and ownership strategiesEthical technology implementationReal-world applications of data intelligenceFuture trends in digital identity and data marketplacesPerfect for tech leaders, data scientists, privacy advocates, and forward-thinking professionals looking to understand and shape the future of data and AI.Presented by TARTLE, pioneers in ethical data exchange and AI enhancement. New episodes every week.The show is hosted by Co-Founder and Source Data Pioneer Alexander McCaig and Head of Conscious Marketing Jason Rigby.What's your data worth? Find out at (https://tartle.co/)Watch the podcast on Yo Explicit

Frequently Asked Questions

How long is this episode of Privacy Please?

This episode is 15 minutes long.

When was this Privacy Please episode published?

This episode was published on June 16, 2025.

What is this episode about?

Send us Fan MailSeveral popular Chrome extensions, including privacy and security tools, have been found leaking sensitive data through unencrypted HTTP and hard-coded credentials in their code. Security is both hard and easy - hard because of...

Is there a transcript available for this episode?

Yes, a full transcript is available for this episode. You can read the complete transcript on the episode page.

Can I download this Privacy Please episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!