599 episodes
- Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
Age verification is spreading across the internet. It promises to protect children, but what happens when accessing a website or using your own device requires facial recognition, identity documents or third-party verification?
David speaks with Alexis Hancock from the Electronic Frontier Foundation about the growing privacy risks surrounding age verification and digital ID systems. They examine how these technologies could threaten online anonymity, create new surveillance infrastructure and expose sensitive personal information.
Alexis explains why age verification alone does not teach children how to stay safe online, how data brokers and behavioral advertising contribute to the problem, and why banning VPNs or weakening encryption would make everyone less secure.
They also discuss zero-knowledge proofs, facial recognition, encryption backdoors, government surveillance and the danger of building a digital identity system that could be abused by future governments.
Finally, Alexis shares practical ways to protect your privacy, including using encrypted communication, learning from EFF’s Surveillance Self-Defense guides and contacting elected representatives when harmful legislation is proposed.
// Alexis Hancock’ SOCIAL //
LinkedIn: / alexishancock
// EFF Website REFERENCE //
https://www.eff.org/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Intro
0:41 - Alexis Hancock background // Who are the EFF
01:48 - Eroding privacy & age verification
08:48 - Online safety for children
12:25 - Online monitoring
14:20 - ThreatLocker sponsor segment
15:27 - Big tech vs government
17:49 - How to fight for privacy
20:19 - Online censorship & privacy
26:17 - The push for age verification
29:29 - Age verification "whack-a-mole"
33:03 - Parental control vs age verification
36:24 - What about non-tech savvy people?
41:02 - Zero-knowledge proof
44:48 - Is it too late? // Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#ageverification #privacy #bhusa2026 - Big thanks to @ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
You can write secure C code, follow accepted best practices and still end up with a vulnerable binary. The reason is simple: the CPU does not run your source code. It runs whatever the compiler produces.
David sits down with security researcher Chris Domas at Black Hat to examine how legal compiler optimizations can remove security protections, delete memory-clearing operations and introduce time-of-check to time-of-use vulnerabilities into code that appeared secure.
Chris explains the C abstract machine, why compilers are allowed to transform code so dramatically and how register pressure, structure layout and even data size can affect whether a binary is vulnerable. In one striking example, 17 or 33 bytes can be safe while nearby sizes produce vulnerable code. They also discuss whether Rust solves the problem, why switching between GCC and Clang is not the answer and how AI helped analyse 500 million lines of open-source code to identify 300 potentially dangerous patterns.
Most importantly, Chris explains what developers can do now, including enabling compiler warnings, using sanitizers, analysing optimized builds and testing the exact binary that will be shipped.
// Christopher Domas’ SOCIAL //
LinkedIn: / christopher-domas
GitHub: https://github.com/xoreaxeaxeax
X: https://x.com/xoreaxeaxeax
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:48 - Intro
02:05 - Different Ways of Exploiting CPU’s
04:10 - The C Specifications
06:17 - The Compiler Deleting Nemsec
08:40 - Do we need to use a new Compiler ?
10:09 - Compiler Inventing Vulnerabilities
12:13 - Don't Give up Writing Secure Code
12:44 - Sponsored Section
14:25 - Any Easy Options To Create A New Compiler ?
15:09 - Chris’s Presentation at Black Hat
20:00 - Weird Situations with Size of Data
21:22 - What Can Developers Do ?
23:32 - Who Can Leverage this Vulnerability ?
25:02 - Could AI Make it Easy For Attackers To Leverage This?
28:27 - Recommendations For Developers
29:48 - Advice To Be Like Chris
30:36 - Conclusion & Outro
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#bhusa2026 #securecoding #compiler - Big thanks to ThreatLocker for sponsoring my trip to Black Hat USA 2026 and also for sponsoring this video. To start your free trial with ThreatLocker please use the following link: https://www.threatlocker.com/davidbombal
A zero-click attack can compromise your phone without you opening a link, installing an application or even touching the device.
David sits down with Natalie Silvanovich and Seth Jenkins from Google Project Zero to examine how specially crafted audio messages were used to remotely compromise the Pixel 9 and Pixel 10.
The attack begins inside the Dolby Unified Decoder, where Android automatically processes incoming audio for transcription. The researchers explain how they exploited the decoder, escaped the media codec sandbox and targeted vulnerable Pixel hardware drivers to achieve kernel code execution and root access.
They also discuss ASLR, SELinux, memory corruption, the eight-week exploit development process, how AI helped automate repetitive tasks and why Apple’s compiler protections prevented the same Dolby bug from affecting iPhones.
Most importantly, they explain what manufacturers can do to reduce their attack surface and make commercial zero-click exploits significantly more expensive.
These vulnerabilities were responsibly disclosed and patched. Pixel users running the latest security updates are protected.
// Seth Jenkins SOCIAL //
LinkedIn: https://www.linkedin.com/in/seth-jenkins-a20b914b/
X: https://x.com/__sethJenkins
// Natalie Silvanovich SOCIAL //
X: https://x.com/natashenka?lang=en
Website: https://natashenka.ca/
// Website REFERENCE //
Google Project Zero website: https://projectzero.google/
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU//
0:00 - Intro
01:00 - ThreatLocker sponsor segment
02:10 - Natalie Silvanovich background
04:00 - Seth Jenkins background
04:49 - Zero click audio codec vulnerability
05:41 - Disclaimer
06:07 - Hacking using audio files // How it works
10:23 - What happens in the sandbox
13:27 - The next step
15:15 - Running into issues
22:55 - Would someone notice the hack?
26:20 - Not secure by default
27:44 - Using AI assistance
29:44 - How to reduce attack surface
34:57 - How to get into cybersecurity
39:05 - Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#google #bhusa2026 #pixel10 - Can you recover working software from a photograph of a microchip?
Embedded systems reverse engineer Travis Goodspeed demonstrates how to extract the original Game Boy’s 256-byte boot ROM from a microscopic photograph of the mask ROM inside its CPU.
The source image was created by combining 22 microscope photographs captured at 50x magnification. Using his free, open-source Mask ROM Tool, Travis marks 2,048 ROM bit locations, separates the ones from the zeros and checks for possible recognition errors. He then determines the logical order of the bits, disassembles the program and shows how it can be exported as a ROM file for use in an emulator.
Travis also explains the Game Boy’s unusual copy-protection system. During startup, its boot ROM displays logo data supplied by the cartridge and compares it with Nintendo’s internal copy. If the logos do not match, the game does not boot. Requiring cartridges to contain Nintendo’s trademark gave the company legal leverage against unlicensed publishers.
The video also explores techniques from Travis’s book, Microcontroller Exploits. These include extracting protected firmware from an access-control reader, chemically decapsulating chips while preserving their operation and using ultraviolet light with a nail-polish mask to remove memory protection without erasing the program.
The Mask ROM Tool, Game Boy chip photograph and step-by-step tutorial are publicly available, allowing you to reproduce the ROM-decoding demonstration without owning a microscope or chemistry lab.
// Sponsored SEGMENT //
Big thank you to Proton Pass for sponsoring this video. Take your security to the next level by getting Proton Pass using the following be www.proton.me/davidbombal
// Link to No Starch Website for Travis’ Book //
Order Microcontroller Exploits and get the eBook free.
https://nostarch.com/microcontroller-...
Use Coupon Code GOODSPEED25 for 25% off Microcontroller Exploits at NoStarch.com
// Travis Goodspeed SOCIAL //
GitHub: https://github.com/travisgoodspeed
// GitHub link to GameBoy ROM Tutorial //
https://github.com/travisgoodspeed/gb...
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU//
0:00 - Coming Up
0:40 - Intro
03:28 - Book Overview
05:27 - Proton Pass Ad
07:29 - Demonstration Context
09:56 - Demo Begins
12:48 - Marking the Chip Rows
18:27 - How Travis Wrote his Book
19:55 - Design Rule Check
23:11 - How to Decode the Binary
28:36 - Can the Binary Numbers Change?
30:30 - Why is this Method Useful?
34:24 - More book Overviews
40:48 - Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#gameboy #reverseengineering #rom - Your internet speed can look fine while your Wi-Fi is still failing. Packet loss, latency, congested channels, interference and poor configuration can all damage performance, but a normal speed test will not show you the full picture.
In this video, I test the Ookla Speedtest Pulse, a pocket-sized Wi-Fi 7 diagnostic tool that measures more than 25 network metrics in around 45 seconds. We test Wi-Fi at the Natural History Museum in London and examine results from an Airbnb to identify whether the problem comes from the Wi-Fi network, wired connection or internet service provider.
Matt explains how the device tests 2.4, 5 and 6 GHz Wi-Fi, detects channel problems, measures signal quality and gives you practical recommendations in plain English.
We also compare Speedtest Pulse with the normal Speedtest application, laptopbased tools and the Ekahau Sidekick 2. You will see its current limitations, upcoming continuous monitoring features and how it could help technicians finally capture intermittent Wi-Fi problems.
Big thanks to OOKLA for sponsoring this video. To get your own Speedtest Pulse please use the following link: https://wifi.ekahau.com/david-bombal-...
// Matt Starling’s SOCIAL //
LinkedIn: / matt-starling-03913633
X: https://x.com/mattstarling?s=21
// Ookla’s SOCIAL //
LinkedIn: / ookla
// David's SOCIAL //
Discord: discord.com/invite/usKSyzb
Twitter: www.twitter.com/davidbombal
Instagram: www.instagram.com/davidbombal
LinkedIn: www.linkedin.com/in/davidbombal
Facebook: www.facebook.com/davidbombal.co
TikTok: tiktok.com/@davidbombal
YouTube: / @davidbombal
Spotify: open.spotify.com/show/3f6k6gE...
SoundCloud: / davidbombal
Apple Podcast: podcasts.apple.com/us/podcast...
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Coming Up
0:58 - Testing Public Wi-Fi in London
01:40 - What Is the Speedtest Pulse?
03:40 - Pulse vs Speedtest vs Sidekick 2
06:19 - Making Wi-Fi Troubleshooting Easy
07:44 - Running a Wi-Fi Test
09:22 - Understanding Wi-Fi Performance Scores
11:16 - Reports and Cloud Results
13:00 - Active vs Continuous Pulse
15:14 - Wired and Wireless Network Testing
18:05 - Why Not Just Use a Laptop?
21:02 - Mobile Support and Wi-Fi 7 Hardware
23:17 - Understanding Your Wi-Fi Score
26:54 - Wi-Fi Security and PMF
29:03 - Signal Strength and Transmit Power
30:19 - Wi-Fi Channels and Interference
31:58 - How to Improve Your Wi-Fi
33:12 - WPA3 Best Practices
34:16 - Price and Coverage Mapping
35:59 - Pulse vs Sidekick 2 for Interference
38:36 - Solving Intermittent Wi-Fi Problems
40:32 - Cloud Monitoring and Multi-Site Management
42:12 - Final Thoughts
Please note that links listed may be affiliate links and provide me with a small
percentage/kickback should you use them to purchase any of the items listed or recommended.
Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#ookla #speedtest #wifi
More Technology podcasts
Trending Technology podcasts
About David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place!
On this channel, I discuss Python, Ethical Hacking, Networking, Network Automation, CCNA, Virtualization and other IT related topics.
This YouTube channel has new videos every week! Subscribe for technical, detailed, no fluff content.
David’s details:
Discord: https://discord.com/invite/usKSyzb
Twitter: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
Website: http://www.davidbombal.com
YouTube: https://www.youtube.com/davidbombal
All the best!
David
Podcast websiteListen to David Bombal, Lex Fridman Podcast and many other podcasts from around the world with the radio.net app

Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features
Get the free radio.net app
- Stations and podcasts to bookmark
- Stream via Wi-Fi or Bluetooth
- Supports Carplay & Android Auto
- Many other app features


David Bombal
Scan code,
download the app,
start listening.
download the app,
start listening.





























