Skip to content
PodcastsTechnologyDavid Bombal

David Bombal

David Bombal
David Bombal
Latest episode

599 episodes

  • David Bombal

    #603: How Age Verification Threatens Your Online Privacy

    2026/09/08 | 47 mins.
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    Age verification is spreading across the internet. It promises to protect children, but what happens when accessing a website or using your own device requires facial recognition, identity documents or third-party verification?

    David speaks with Alexis Hancock from the Electronic Frontier Foundation about the growing privacy risks surrounding age verification and digital ID systems. They examine how these technologies could threaten online anonymity, create new surveillance infrastructure and expose sensitive personal information.

    Alexis explains why age verification alone does not teach children how to stay safe online, how data brokers and behavioral advertising contribute to the problem, and why banning VPNs or weakening encryption would make everyone less secure.

    They also discuss zero-knowledge proofs, facial recognition, encryption backdoors, government surveillance and the danger of building a digital identity system that could be abused by future governments.

    Finally, Alexis shares practical ways to protect your privacy, including using encrypted communication, learning from EFF’s Surveillance Self-Defense guides and contacting elected representatives when harmful legislation is proposed.

    // Alexis Hancock’ SOCIAL //
    LinkedIn: / alexishancock

    // EFF Website REFERENCE //
    https://www.eff.org/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Intro
    0:41 - Alexis Hancock background // Who are the EFF
    01:48 - Eroding privacy & age verification
    08:48 - Online safety for children
    12:25 - Online monitoring
    14:20 - ThreatLocker sponsor segment
    15:27 - Big tech vs government
    17:49 - How to fight for privacy
    20:19 - Online censorship & privacy
    26:17 - The push for age verification
    29:29 - Age verification "whack-a-mole"
    33:03 - Parental control vs age verification
    36:24 - What about non-tech savvy people?
    41:02 - Zero-knowledge proof
    44:48 - Is it too late? // Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #ageverification #privacy #bhusa2026
  • David Bombal

    #602: How Compilers Turn Secure C Code Into Vulnerable Binaries

    2026/09/08 | 30 mins.
    Big thanks to ‪@ThreatLocker‬ for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces.

    David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure.

    Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns.

    Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped.

    // Christopher Domas’ SOCIAL //
    LinkedIn: / christopher-domas
    GitHub: https://github.com/xoreaxeaxeax
    X: https://x.com/xoreaxeaxeax

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:48 - Intro
    02:05 - Different Ways of Exploiting CPU’s
    04:10 - The C Specifications
    06:17 - The Compiler Deleting Nemsec
    08:40 - Do we need to use a new Compiler ?
    10:09 - Compiler Inventing Vulnerabilities
    12:13 - Don't Give up Writing Secure Code
    12:44 - Sponsored Section
    14:25 - Any Easy Options To Create A New Compiler ?
    15:09 - Chris’s Presentation at Black Hat
    20:00 - Weird Situations with Size of Data
    21:22 - What Can Developers Do ?
    23:32 - Who Can Leverage this Vulnerability ?
    25:02 - Could AI Make it Easy For Attackers To Leverage This?
    28:27 - Recommendations For Developers
    29:48 - Advice To Be Like Chris
    30:36 - Conclusion & Outro

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #bhusa2026 #securecoding #compiler
  • David Bombal

    #601: Google Researchers Hacked the Pixel Phone using Audio Messages

    2026/09/08 | 39 mins.
    Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal

    A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device.

    David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10.

    The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access.

    They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones.

    Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive.

    These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected.

    // Seth Jenkins SOCIAL //
    LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/
    X: https://x.com/__sethJenkins

    // Natalie Silvanovich SOCIAL //
    X: https://x.com/natashenka?lang=en
    Website: https://natashenka.ca/

    // Website REFERENCE //
    Google Project Zero website: https://projectzero.google/

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU//
    0:00 - Intro
    01:00 - ThreatLocker sponsor segment
    02:10 - Natalie Silvanovich background
    04:00 - Seth Jenkins background
    04:49 - Zero click audio codec vulnerability
    05:41 - Disclaimer
    06:07 - Hacking using audio files // How it works
    10:23 - What happens in the sandbox
    13:27 - The next step
    15:15 - Running into issues
    22:55 - Would someone notice the hack?
    26:20 - Not secure by default
    27:44 - Using AI assistance
    29:44 - How to reduce attack surface
    34:57 - How to get into cybersecurity
    39:05 - Conclusion


    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!


    Disclaimer: This video is for educational purposes only.

    #google #bhusa2026 #pixel10
  • David Bombal

    #600: This Free Tool Decodes Game Boy ROM From a Photograph

    2026/09/02 | 41 mins.
    Can you recover working software from a photograph of a microchip?

    Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy’s 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU.

    The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator.

    Travis also explains the Game Boy’s unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo’s internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo’s trademark gave the company legal leverage against unlicensed publishers.

    The video also explores techniques from Travis’s book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program.

    The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab.

    // Sponsored SEGMENT //
    Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal

    // Link to No Starch Website for Travis’ Book //
    Order Microcontroller Exploits and get the eBook free.
    https://nostarch.com/microcontroller-...

    Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com

    // Travis Goodspeed SOCIAL //
    GitHub: https://github.com/travisgoodspeed

    // GitHub link to GameBoy ROM Tutorial //
    https://github.com/travisgoodspeed/gb...

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU//
    0:00 - Coming Up
    0:40 - Intro
    03:28 - Book Overview
    05:27 - Proton Pass Ad
    07:29 - Demonstration Context
    09:56 - Demo Begins
    12:48 - Marking the Chip Rows
    18:27 - How Travis Wrote his Book
    19:55 - Design Rule Check
    23:11 - How to Decode the Binary
    28:36 - Can the Binary Numbers Change?
    30:30 - Why is this Method Useful?
    34:24 - More book Overviews
    40:48 - Conclusion

    Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #gameboy #reverseengineering #rom
  • David Bombal

    #599: This Pocket Tool Diagnoses Wi-Fi in 45 Seconds

    2026/09/02 | 42 mins.
    Your internet speed can look fine while your Wi-Fi is still failing. Packet loss, latency, congested channels, interference and poor configuration can all damage performance, but a normal speed test will not show you the full picture.

    In this video, I test the Ookla Speedtest Pulse, a pocket-sized Wi-Fi 7 diagnostic tool that measures more than 25 network metrics in around 45 seconds. We test Wi-Fi at the Natural History Museum in London and examine results from an Airbnb to identify whether the problem comes from the Wi-Fi network, wired connection or internet service provider.

    Matt explains how the device tests 2.4, 5 and 6 GHz Wi-Fi, detects channel problems, measures signal quality and gives you practical recommendations in plain English.

    We also compare Speedtest Pulse with the normal Speedtest application, laptopbased tools and the Ekahau Sidekick 2. You will see its current limitations, upcoming continuous monitoring features and how it could help technicians finally capture intermittent Wi-Fi problems.

    Big thanks to OOKLA for sponsoring this video. To get your own Speedtest Pulse please use the following link: https://wifi.ekahau.com/david-bombal-...

    // Matt Starling’s SOCIAL //
    LinkedIn: / matt-starling-03913633
    X: https://x.com/mattstarling?s=21

    // Ookla’s SOCIAL //
    LinkedIn: / ookla

    // David's SOCIAL //
    Discord: discord.com/invite/usKSyzb
    Twitter: www.twitter.com/davidbombal
    Instagram: www.instagram.com/davidbombal
    LinkedIn: www.linkedin.com/in/davidbombal
    Facebook: www.facebook.com/davidbombal.co
    TikTok: tiktok.com/@davidbombal
    YouTube: / @davidbombal
    Spotify: open.spotify.com/show/3f6k6gE...
    SoundCloud: / davidbombal
    Apple Podcast: podcasts.apple.com/us/podcast...

    // MY STUFF //
    https://www.amazon.com/shop/davidbombal

    // SPONSORS //
    Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com

    // MENU //
    0:00 - Coming Up
    0:58 - Testing Public Wi-Fi in London
    01:40 - What Is the Speedtest Pulse?
    03:40 - Pulse vs Speedtest vs Sidekick 2
    06:19 - Making Wi-Fi Troubleshooting Easy
    07:44 - Running a Wi-Fi Test
    09:22 - Understanding Wi-Fi Performance Scores
    11:16 - Reports and Cloud Results
    13:00 - Active vs Continuous Pulse
    15:14 - Wired and Wireless Network Testing
    18:05 - Why Not Just Use a Laptop?
    21:02 - Mobile Support and Wi-Fi 7 Hardware
    23:17 - Understanding Your Wi-Fi Score
    26:54 - Wi-Fi Security and PMF
    29:03 - Signal Strength and Transmit Power
    30:19 - Wi-Fi Channels and Interference
    31:58 - How to Improve Your Wi-Fi
    33:12 - WPA3 Best Practices
    34:16 - Price and Coverage Mapping
    35:59 - Pulse vs Sidekick 2 for Interference
    38:36 - Solving Intermittent Wi-Fi Problems
    40:32 - Cloud Monitoring and Multi-Site Management
    42:12 - Final Thoughts

    Please note that links listed may be affiliate links and provide me with a small
    percentage/kickback should you use them to purchase any of the items listed or recommended.
    Thank you for supporting me and this channel!

    Disclaimer: This video is for educational purposes only.
    #ookla #speedtest #wifi
More Technology podcasts
About David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content. David’s details: Discord: https://discord.com/invite/usKSyzb Twitter: https://www.twitter.com/davidbombal Instagram: https://www.instagram.com/davidbombal LinkedIn: https://www.linkedin.com/in/davidbombal Facebook: https://www.facebook.com/davidbombal.co Website: http://www.davidbombal.com YouTube: https://www.youtube.com/davidbombal All the best! David
Podcast website

Listen to David Bombal, Lex Fridman Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app

  • Stations and podcasts to bookmark
  • Stream via Wi-Fi or Bluetooth
  • Supports Carplay & Android Auto
  • Many other app features