So last Tuesday I'm sitting in the Caltrain quiet car at 6:14 AM, half-dead after a midnight pager storm where three microservices decided to have a disagreement about certificate rotation. My phone's connected to the train WiFi โ the same public WiFi that Kevin Mitnick would absolutely roast me for using without a VPN. And I'm listening to Kevin Mitnick tell me exactly why that's a terrible idea. The irony was not lost on me.
Ray Porter narrates this. Need I say more?
Fine, I'll say more.
Your Threat Model Is Probably Wrong
TL;DR: Worth your commute, but with caveats.
Mitnick structures this as a series of real-world privacy horror stories โ someone's email gets intercepted because they used hotel WiFi, a journalist's source gets burned because of metadata in a phone call, that kind of thing โ followed by practical countermeasures. The format is basically "here's how you're screwed, here's how to be less screwed." It's organized by attack surface: email, browsing, mobile devices, social media, physical surveillance.
The good: Mitnick's hacker cred is real, and he doesn't waste time proving it. He drops into specific techniques โ how Stingrays (cell-site simulators) intercept your calls by pretending to be legitimate towers, how even Tor can be deanonymized if you're sloppy about browser fingerprinting, how a single metadata leak from an encrypted email can expose your entire contact graph. The man literally evaded the FBI for three years, and that authority comes through even in Porter's gruff, matter-of-fact delivery. That kind of earned credibility โ someone telling you hard truths because they've actually lived them โ reminded me of what made My Confession stick with me too, that same unsettling sensation of a narrator who has no reason to lie to you.
The less good: this is from 2017, and security moves fast. Some of the specific tool recommendations are outdated โ certain VPN providers he mentions have changed ownership or policies, and the privacy landscape around things like Signal has evolved significantly. The core concepts hold up (defense in depth, minimizing your attack surface, assuming the network is hostile), but if you're following his step-by-step instructions verbatim, you'll want to cross-reference with current best practices.
Could've Been a Blog Post (But It's the Right Blog Post)
Okay, not literally a blog post. But this is one of those books where you feel the padding. Mitnick will make a solid point about, say, how your ISP logs every DNS query you make, and then spend another twenty minutes on variations of the same theme with different anecdotes. At 9 hours 19 minutes, there's probably a killer 5-hour book hiding inside.
I bumped it to 1.75x for the sections that repeated concepts I already knew from work โ TLS handshakes, man-in-the-middle attacks, basic OpSec hygiene. If you're already in tech, you can safely speed through probably 40% of this. If you're NOT in tech โ if you're, say, Kevin (my boyfriend, not Mitnick), who still uses the same password for everything despite living with a security-adjacent engineer โ then 1.25x to 1.5x and actually absorb it.
The ROI on this audiobook is highest for people who know they should care about privacy but haven't operationalized it. It's the gap between "I should use a password manager" and actually understanding why your threat model requires one.
Porter Makes the Man Pages Sound Good
Ray Porter reading technical content is โ and I will die on this hill โ one of the best pairings in audiobooks. His gruff, no-nonsense delivery is perfect for Mitnick's tone, which is basically "I'm telling you this because I used to be the guy doing it to you." There's a dry authority to it. Porter doesn't try to make the technical sections exciting. He trusts the material to be inherently alarming, which it is.
No sound effects, no music, no full-cast gimmicks. Just Porter and the text. Clean production. Exactly what you want for a book like this.
My one gripe: the anecdotal sections where Mitnick describes social engineering attacks โ like impersonating IT support to get someone's credentials โ would've benefited from slightly more vocal differentiation between the attacker and victim in the story. Porter keeps it pretty flat, which works for the technical instruction but makes the narrative portions blur together a bit, especially at speed.
Who Gets Root Access
Perfect for: your commute, gym, housework โ anywhere you can give it about 70% attention. The story-then-lesson structure means you can zone out on a anecdote and snap back for the takeaway without losing much.
Skip if: you're a practicing security engineer. You know this stuff. Or if you need something published post-2020 with current tool recommendations.
Best audience: the technically curious non-expert. Your parents. Your friends who think incognito mode means they're invisible. Kevin.
Ship It, But Pin the Version
This is basically a pentest report but for your personal life โ here are the vulnerabilities, here's the remediation. The core security thinking is solid and mostly timeless. The specific tooling recommendations have bit-rotted. I'd love a second edition (sadly, Mitnick passed in 2023, so that won't happen, which makes this feel like a more important artifact of his thinking).
I finished it in 4 commutes at 1.75x. Immediately changed two passwords and finally set up a hardware security key I'd been procrastinating on for months. If a book makes you actually do something, that's worth something.
Just... don't listen to it on public WiFi without your VPN running. Mitnick would haunt you.







![Steve Jobs [unabridged audiobook] audiobook cover](/_next/image?url=https%3A%2F%2Fcovers.audiobooks.com%2Fimages%2Fcovers%2Ffull%2F9788499923406.jpg&w=1920&q=75)








