Skip to content
Melo Podcasts Home
CategoriesLanguagesFollowing

Episode notes

In episode 459 of Smashing Security, we dive into a chillingly clever account takeover attempt targeting WordPress co-founder Matt Mullenweg - involving MFA fatigue, real Apple alerts, a convincing support call, and a phishing page that oh-so-nearly worked. If a famous techie could have this happen to you, can you be sure you're immune? Plus: would you donate your lifetime medical history to science if you were promised anonymity? We unpack serious concerns around UK Biobank, where “de-identified” data may not be as anonymous as you think — and how surprisingly little information it takes to…

Transcript

Read the transcript · about 9,370 words, follows along as you listen

[SPEAKER_03]: a judge has sentenced a CSO to eight consecutive hours on the RSA conference floor. [SPEAKER_03]: His crime failing to disclose a breach to the Securities and Exchange Commission legal experts at the SEC are calling the penalty, Proporthenad and Corrective. [SPEAKER_03]: Former RSA attendees are calling it barbaric. [SPEAKER_00]: smashing security, episode 459. [SPEAKER_00]: This clever scam nearly hijacked a text CEO's Apple ID, with Grandcloely and Special Guest Paul Ducklin.

[SPEAKER_04]: Hello, welcome to smashing security episode 459. [SPEAKER_04]: My name's Grandcloely, and my name is Paul Ducklin. [SPEAKER_04]: Duck, great to have you back on the show once again. [SPEAKER_04]: Thank you for join us. [SPEAKER_04]: It's a great pleasure. [SPEAKER_04]: So what fun stuff have you been up too lately? [SPEAKER_03]: Well, [SPEAKER_03]: As you know, Graham, for very many years, I haven't owned a car because I kind of got into bicycling, yes.

[SPEAKER_03]: So when I need a car, which is only very occasionally, I hire one and every time, you seem to get a different model, right? [SPEAKER_03]: And the one thing you have to do at least in Britain when you hire a car, the rule is you get it full of fuel and you must return it full of fuel, or they charge you some extortionate price to fill it back up. [SPEAKER_03]: Yeah. [SPEAKER_03]: Now, and of course, because not your car, how do you know when you're pulling to the filling station, which side the filler cap is on?

[SPEAKER_03]: Oh, and although I've been doing this for years and years and years, I only very recently discovered that if you look at the field gauge, did you the law not? [SPEAKER_03]: Underneath it, there's a little petrol pump icon, says this is the fuel gas. [SPEAKER_03]: and at the bottom of the little petrol pump icon there's an arrow which is either on the left hand side or the right hand side. [SPEAKER_03]: Guess what the arrow tells you?

[SPEAKER_03]: I think bless you duck for not knowing that. [SPEAKER_04]: What? [SPEAKER_04]: Well I knew that! [SPEAKER_04]: In the cars I've driven, I've noticed that, but I didn't know all cars did that. [SPEAKER_03]: When I owned cars, I just knew which side it was on, because after the third time you've got it wrong, you kind of know. [SPEAKER_03]: The green car, it's on the left, the white car, it's on the right. [SPEAKER_04]: I have to look at the dashboard to remind myself sometimes.

[SPEAKER_03]: So you say I've given the smashing security listeners a piece of advice that only I did not know. [SPEAKER_04]: Well, let's go with the show, but before we kick off, let's thank this week's wonderful sponsors, Mita, Adaptive Security and Vanta, we'll be hearing more about them later on the podcast. [SPEAKER_04]: You'll hear no discussion of how a foreign hacker is said to have broken into the FBI in 2023 and compromised the Epstein files.

[SPEAKER_04]: And we won't even mention how a new font rendering trick can cause AI assistance to not spot malicious commands it can inseemingly harmless HTML. [SPEAKER_04]: So Dak, what are you going to be talking about this week? [SPEAKER_03]: I'm going to be asking where does nobody helping the community at large with medical data end and protecting your personal data and privacy begin? [SPEAKER_04]: And I'm going to be talking about the devious way hackers, almost stole a famous techie's Apple account, and how you could fall for the same trick.

[SPEAKER_04]: All this and much more coming up on this episode of Smash In Security. [SPEAKER_04]: Graham, who's our sponsor this week? [SPEAKER_04]: Well, adaptive security is one of them. [SPEAKER_04]: Ooh, but they do. [SPEAKER_04]: They train your stuff not to be idiots, Joe. [SPEAKER_04]: That's harsh. [SPEAKER_04]: It is a bit, but you know, when someone rings up the accounts department, pretending to be the CEO and asks to be wired $50,000.

[SPEAKER_04]: And he turned out to be a bloke and a track suit. [SPEAKER_04]: That's what we're talking about. [SPEAKER_04]: I'm familiar with the genre. [SPEAKER_04]: Yeah, so adaptive security, they stop that from happening it, proper security awareness training, not death by PowerPoint. [SPEAKER_04]: Thank goodness. [SPEAKER_04]: Yeah, real world examples tailored to your company, fishing simulations, fishing, smishing, you're just making up words now.

[SPEAKER_04]: I'm really not, Joe. [SPEAKER_04]: Voice, email, SMS, video, even AI deep fake scams and the simulations use the kind of information attackers could actually dig up about you and your staff. [SPEAKER_04]: So it's realistic. [SPEAKER_04]: Yeah, it's uncomfortably realistic and now they've got an AI content creator that lets security teams instantly spin up. [SPEAKER_04]: custom training we've got to do is paste in a news article, so could be a better breaking threat or an internal policy update.

[SPEAKER_04]: It's all done, multilingual, interactive in seconds. [SPEAKER_04]: behind all this then. [SPEAKER_04]: Well, open the AI as it happens. [SPEAKER_04]: Adaptive securities, the first cybersecurity company which is backed by open the AI. [SPEAKER_04]: That sounds like a ringing endorsement. [SPEAKER_04]: So, if you'd rather your employees weren't the weakest link, head over to smashinscurity.com slash adaptive. [SPEAKER_04]: That's smashingsecurity.com slash adaptive.

[SPEAKER_04]: And thanks to adaptive security for supporting the show. [SPEAKER_04]: Now Duck, Matt Mullenwegg, are you familiar with Matt Mullenwegg? [SPEAKER_04]: Uh, that's automatic, isn't it? [SPEAKER_04]: That's right, which is the parent company of wordpress and some other things as well. [SPEAKER_04]: And he's also the co-founder of wordpress, obviously. [SPEAKER_04]: He's a big name in tech, isn't it? [SPEAKER_04]: I mean, he did do something extraordinary of WordPress he built something which is used by son ofstonishing, statistic the number of websites out there which are powered by WordPress, either WordPress.com or the open source, a equivalent, something like 40% of the internet is using WordPress technology, I believe.

[SPEAKER_03]: Is your site on wordpress screen? [SPEAKER_03]: It is, yes. [SPEAKER_03]: Yes, so is mine. [SPEAKER_03]: So there you go. [SPEAKER_03]: Two out of two. [SPEAKER_03]: That's 100%. [SPEAKER_04]: And our survey, 100% of the internet. [SPEAKER_04]: It's been run on wordpress. [SPEAKER_04]: So he's done very well. [SPEAKER_04]: He's still managed to alienate almost everyone. [SPEAKER_04]: He's done the wordpress community over years. [SPEAKER_04]: Yes.

[SPEAKER_04]: He's a bit like Linus Torvowd's. [SPEAKER_04]: He can be in a bit prickly, I think, sometimes. [SPEAKER_04]: So it divides opinion. [SPEAKER_04]: But he's a big cheese, isn't he? [SPEAKER_04]: And turns out he uses Apple devices. [SPEAKER_04]: So he's got an Apple watch, he's got an iPhone, and he's got an Apple Mac. [SPEAKER_04]: And he also does something which not many people do with their Apple devices, which is that he has enabled lockdown mode.

[SPEAKER_04]: That is an optional feature of Apple's operating system, which means that you shouldn't love Chrome. [SPEAKER_03]: It sounds like if you want to show your buddies how important you think I've tried it, it's very good, but you can't do an awful lot. [SPEAKER_04]: Lockdown mode for anyone who doesn't know it significantly restrict what your device can do, which is great news in terms of making it more secure, put you at less risk. [SPEAKER_04]: But it's also make sure device really bloody difficult to actually use as a computing device.

[SPEAKER_04]: So much so that Apple actually specifically does not recommend it. [SPEAKER_04]: They say this is designed for very few individuals. [SPEAKER_04]: They would hate the vast majority of people to turn this feature on. [SPEAKER_04]: I don't think they have to worry about that happening. [SPEAKER_04]: So, it is more if you're a politician or if you're a journal, I'm not if you're like a journalist right and about snuka matches or something like that, but if you are a journalist who's working on to have geopolitical or if you've got super secret sources who were in countries where there are authoritarian regime [SPEAKER_03]: Well, there have been some very, very, very deep and important gambling corruption allegations over the years in Snowden.

[SPEAKER_03]: That's true. [SPEAKER_03]: So don't not snook a journalist for the risk that they may be under. [SPEAKER_04]: All right. [SPEAKER_04]: Okay. [SPEAKER_04]: Fair enough. [SPEAKER_04]: Anyway, despite having lockdown mode enabled Matt Mullenwegg was still almost completely [SPEAKER_04]: So, if you're sitting there thinking, well, this could never happen to me, I could never fall for a trick like this. [SPEAKER_04]: Just stay listening because maybe you could hear is what happened to Matt.

[SPEAKER_04]: So, recently, in an evening there's Matt, he says that suddenly his Apple watch, his iPhone and his Mac, they all knit up with a message, prompting him to reset his Apple ID password. [SPEAKER_04]: This is the thing built into the operating system, it's popping up, so you need to reset your password. [SPEAKER_04]: And it says it came out of nowhere. [SPEAKER_04]: So he hadn't done anything to trigger it. [SPEAKER_04]: And he's thinking, well, why am I getting this notification?

[SPEAKER_04]: Tell me that there's some kind of problem with this. [SPEAKER_04]: And what was happening was that somebody was hammering Apple's own legitimate password reset process. [SPEAKER_04]: And you can do this. [SPEAKER_04]: You can go to Apple and you can save that. [SPEAKER_04]: This is my Apple ID. [SPEAKER_04]: This is effectively my email address. [SPEAKER_04]: I can no longer access my account, please reset it for me. [SPEAKER_04]: And if you do that, Apple will send this notification to your devices.

[SPEAKER_04]: Basically, he said, do you want to reset if you do? [SPEAKER_04]: This is the process which we want you to go through. [SPEAKER_04]: So he was being battered by somebody who was probably hoping that eventually he'd get frustrated by all these hundreds of messages and just tap Allow. [SPEAKER_04]: And this is a technique which is called [SPEAKER_04]: Well, some people call it MFA bombing, it relies upon MFA fatigue. [SPEAKER_04]: You must have heard about cases of this kind of thing happening, Doug.

[SPEAKER_03]: Yes, in general, notification fatigue, as I've heard it. [SPEAKER_03]: Yeah, the idea that you'll get a warning, they'll get a warning, you'll go, that's not me, that's not me, that's not me, that's not me. [SPEAKER_03]: And then eventually, you'll be at a low moment or you'll think, oh well, maybe it is me or maybe you'll go in and fiddle with something and think, well, that must be mine. [SPEAKER_03]: And you click, allow, and everything goes quiet.

[SPEAKER_04]: Yes, it's a bit like a denial of service attacking away because it stops you from doing your work or stops you from having fun with your device. [SPEAKER_03]: Once in a while, Graham, you've got to expect that these scammers who are probably doing this thousands or tens of thousands of times a day, they will coincide with a point at which someone thinks they really do or should reset their password and they'll fall in with their eyes wide shut as it were.

[SPEAKER_04]: Yeah, that's certainly possible, so eventually you can get fed up and you can do what of the messages telling you to do because you're under such a barrage. [SPEAKER_04]: Or you think, well, maybe it is legitimate. [SPEAKER_04]: I just want the problem to go away. [SPEAKER_04]: I will press every button until I find the button which makes these things bloody well stop. [SPEAKER_03]: Or you've jabber thing 50 times already and you jabber it one more time in frustration and this last time because you're so annoyed you miss.

[SPEAKER_03]: Right, and you hit the other button instead. [SPEAKER_04]: But Matt Mullenberg, he's a smart cookie, is clearly savvy to the risks. [SPEAKER_04]: But in his case, these guys didn't give up when he failed to fall for that particular trick. [SPEAKER_04]: Instead, they took things up a notch. [SPEAKER_04]: So it turns out that the people who were trying to trick him into giving them access to his account, [SPEAKER_04]: Yeah, you have to grudgingly think that's quite clever.

[SPEAKER_04]: Isn't it? [SPEAKER_04]: So they pretended to be Matt Mullenwegg, and they said I've lost my phone and need to give you a new phone number to attach to my device. [SPEAKER_04]: And because they were doing this all through Apple's actual real support channels, that interaction generated a real case ID number [SPEAKER_03]: Yes, which even if it's a fraudulent approach is quite correct. [SPEAKER_03]: It means Apple has created a record that you can then know is false if you got your wits about you.

[SPEAKER_04]: Now, Apple, of course, they're not just going to hand over the keys to someone's account just because they appear to have said, oh, I've lost my phone. [SPEAKER_04]: They're going to send notification emails to the people who's email addresses. [SPEAKER_04]: They have associated with that account, right? [SPEAKER_04]: So they're going to send notification messages. [SPEAKER_04]: And that's what happened. [SPEAKER_04]: So real Apple notification emails arrived in Matt's inbox.

[SPEAKER_04]: And all of those messages, of course, were not fishing emails. [SPEAKER_04]: They were properly signed from Apple's actual B-Mell servers with Apple's domain. [SPEAKER_04]: These weren't spoof emails. [SPEAKER_04]: They weren't blocked by spamming anything else. [SPEAKER_04]: They're completely legitimate emails to Matt about a completely fraudulent request from the hackers to gain access to his account. [SPEAKER_04]: and this has meant to be done so that you get a heads up if this kind of thing is happening.

[SPEAKER_04]: Exactly. [SPEAKER_04]: And it is at this point that Matt got a phone call. [SPEAKER_04]: Uh oh. [SPEAKER_04]: He gets a phone call from Apple Support. [SPEAKER_04]: and Alexander was a pretty good support guy. [SPEAKER_04]: He was calm, he was methodical, he was reassuring, he gave Matt some genuinely sound advice like you should check your account, make sure nothing has changed, think about updating your password, have you got two factual authentication enabled?

[SPEAKER_05]: There is a few things that you are able to check over. [SPEAKER_04]: This is just to ensure that the [SPEAKER_04]: Like Alexander from Apple Support is saying that someone tried to change Matt's phone number, which turned out, was what the hackers had tried to do. [SPEAKER_04]: But the Apple intercepted the attempt. [SPEAKER_04]: And who else other than Apple would know that that had happened? [SPEAKER_04]: I wonder. [SPEAKER_04]: And so you think, well, this is really helpful.

[SPEAKER_01]: And he was so convincing this support guy that Matt actually thanked him. [SPEAKER_01]: the emails are good. [SPEAKER_01]: The password is old, so maybe that was compromised, I don't know. [SPEAKER_01]: I do have to factor on. [SPEAKER_05]: Thank you, so what was your name by the way? [SPEAKER_05]: My name is Alexander. [SPEAKER_01]: Alexander, you're awesome. [SPEAKER_01]: So thank you, Reviso. [SPEAKER_05]: Thank you very much. [SPEAKER_04]: Which is kind of funny when you obviously guess the way much this is going.

[SPEAKER_03]: It also seems to be the most obvious giveaway that this is a scam. [SPEAKER_03]: Timely helpful, joyful, continuous, real, useful support. [SPEAKER_04]: Yes, Matt Mullenwek remember he's signed up for the lockdown mode. [SPEAKER_04]: He thinks he's a tech VIP maybe he thinks he's getting the gold plated support from Apple because of who he is and then Alexander says look okay so what we're going to do clearly this was a bogus support request which came in they said clearly some is trying to fish you so what we're going to do is we're going to clear this bogus support request which is coming [SPEAKER_04]: And you can then confirm your identity and we will cancel the support request.

[SPEAKER_04]: So the link arrives via SMS pointing to a URL at audit-appel.com. [SPEAKER_04]: That well-known Apple domain, exactly because it's not the real Apple.com. [SPEAKER_04]: It's got that bit on the front. [SPEAKER_04]: So Matt went to the link, it looked just like Apple's website, and he put up some screenshots of it on his blog entree as well, and it displayed the exact case ID, the number which he had had referred to in the real Apple emails, which had been sent to his inbox.

[SPEAKER_04]: There was even a fake chat transcript shown on the page a record of the scammer's own conversation with Apple, presented back to Matt as evidence that someone was attacking his account. [SPEAKER_05]: Yes, the A32 number was set as a text message. [SPEAKER_05]: This is just because we're reaching out to that mobile number as a fight now, and we can't confirm you are the as well as have access to this mobile. [SPEAKER_04]: So Matt arrives on this dodgy webpage, and at the bottom of the page, as Alexander points out, is a sign in with Apple button.

[SPEAKER_05]: I have so in relation to that request there. [SPEAKER_05]: If you should at the bottom it may stay the verification required. [SPEAKER_05]: This is just to go ahead and close it back. [SPEAKER_05]: as I stated, we've initiated the calculation request, but for it to be processed, it does require an original alcoholic or a lick. [SPEAKER_04]: Now, he's pushing for Matt to do this because this is how you will clear the support request.

[SPEAKER_04]: So we can close this whole thing down. [SPEAKER_04]: Yeah. [SPEAKER_04]: And it's at that point that thankfully Matt was feeling a little bit unsure. [SPEAKER_04]: And so we entered a completely different made-up case ID. [SPEAKER_04]: And when he did that, he got exactly the same results. [SPEAKER_04]: And nothing was being validated. [SPEAKER_04]: The whole thing was a sham. [SPEAKER_04]: He saw the same kind of page. [SPEAKER_04]: And he thought, well, hang on.

[SPEAKER_04]: You could enter anything here. [SPEAKER_04]: And so he actually called Alexander's [SPEAKER_01]: This is impressive, so this is, this is obviously fishing, like so, uh, tell me, tell me a little bit about the scam, like. [SPEAKER_04]: The whole elaborate scheme, the password reset spam, the fake Apple support call the real case ID, the authentic looking emails, all of that, was just for this one moment to steal those login details for Apple ID.

[SPEAKER_03]: I mean, this is pretty sophisticated stuff, isn't it? [SPEAKER_03]: Well, it's also very simple because the Pixel Perfect Clone website, there are any number of open source tools you can download from GitHub known as Air Quotes for Research Purpose is only that don't require any technical skill. [SPEAKER_03]: I've done it with my own site as an experiment. [SPEAKER_03]: Five minutes later, I had a pixel-perfect, java-script-perfect clone of my own site.

[SPEAKER_03]: It was exactly the same code running. [SPEAKER_03]: And the only difference was when you filled in the form and clicked Submit, it went somewhere else. [SPEAKER_03]: And you could even set a believable decoy page to land on afterwards. [SPEAKER_04]: Well, when Matt called this guy's bluff, [SPEAKER_04]: Alexander was gone. [SPEAKER_04]: It was silent. [SPEAKER_04]: Interestingly, the guys at WordPress, they think it may have been an AI voice.

[SPEAKER_04]: It may have been an AI which was clever enough to actually have the entire conversation with Matt, because there are some demos which 11 labs for instance have put out, where you can be chatting to a support chat bot, which is remarkably convincing. [SPEAKER_03]: Well, particularly if it's just talking user-escript, yeah, I don't think that particularly requires artificial intelligence. [SPEAKER_03]: It just requires a voice that sounds believable enough.

[SPEAKER_04]: Well, yeah, but in this case, it was interacting with him as well. [SPEAKER_04]: Right. [SPEAKER_04]: When Matt thanked him, Alexander said, oh, thank you very much. [SPEAKER_04]: So there was a bit of two and throw between them. [SPEAKER_04]: Yeah, and it was answered in the questions. [SPEAKER_04]: Anyway, what can we learn from this? [SPEAKER_04]: Where's the advice? [SPEAKER_04]: Well, [SPEAKER_04]: Apple is never going to call you first.

[SPEAKER_04]: Right? [SPEAKER_04]: They're not going to call you out of the blue. [SPEAKER_04]: Always check the URL. [SPEAKER_03]: And if you call them, you're not going to get through very quickly either. [SPEAKER_03]: So, both of those things should be red flags. [SPEAKER_04]: Don't click on Link's text did during a support call, be suspicious of them as well. [SPEAKER_04]: Go to whatever the business is. [SPEAKER_04]: Go there directly, if you're concerned.

[SPEAKER_04]: If you receive a password reset prompt that you didn't request. [SPEAKER_04]: then that should be a huge red flag. [SPEAKER_04]: So, approve nothing, go to your settings yourself, log in yourself, multi-factor authentication, it definitely can help. [SPEAKER_04]: But of course, they're the sort of man in the middle attacks on them, where you can actually have the multi-factor authentication token taken from you. [SPEAKER_04]: And instantly, the bad guys can use that token that you've entered to try and access your account.

[SPEAKER_04]: Absolutely. [SPEAKER_04]: A lot better to have that kind of protection in place. [SPEAKER_04]: It is not a 100% guarantee that your account's going to be safe. [SPEAKER_03]: And never, ever, read out that 2FA code to anyone else. [SPEAKER_03]: No. [SPEAKER_03]: Like a pin, personal identification number, it's for you only. [SPEAKER_04]: Yeah. [SPEAKER_04]: That's actually right, just in the last week or so, the guys at Signal, which is the encrypted messaging app, they've put out a warning that there are messages going around, claiming to come from the Signal Security Support Chatbot, and it says we've noticed suspicious activity on your device.

[SPEAKER_03]: Oh boy, they've even justified the fact that you're going to have a chat with an AI up front. [SPEAKER_04]: Yes, these messages say to prevent you losing access to your account, you have to pass verification. [SPEAKER_04]: We are about to send you a verification code. [SPEAKER_04]: Don't tell it to anyone. [SPEAKER_04]: It says not even signal employees just send it to this number when you receive it. [SPEAKER_04]: Don't tell it to anyone except this person.

[SPEAKER_03]: Right, if in doubt Graham don't give it out, simple as that. [SPEAKER_04]: That's a good little motto, you should stick with it on the front of your t-shirt. [SPEAKER_04]: Maybe I'll do that. [SPEAKER_04]: Ok dokie, a little bit of time now to talk about me to her one of our sponsors this week. [SPEAKER_04]: What does this one do? [SPEAKER_04]: They set up your office networks so you don't have to. [SPEAKER_04]: That's it? [SPEAKER_04]: Yeah, well pretty much, yeah, that's it.

[SPEAKER_04]: You know when you move into a new office and suddenly you're juggling ice peas and flow plant and hardware and configuration, it basically becomes a second job, doesn't it? [SPEAKER_02]: Yes, I know this one. [SPEAKER_02]: It's when the contract turns up on the wrong day or the wrong address and tries to install the wrong thing. [SPEAKER_04]: That's the one, yeah. [SPEAKER_04]: Well, meet us in Thai pitches. [SPEAKER_04]: What if that just wasn't your problem?

[SPEAKER_04]: I'm listening. [SPEAKER_04]: So you hand them a physical address and a floor plan, and they sought out the ISP, they designed the network, they shop on site, they racked their own hardware, their own hardware, not reselling someone else's kit. [SPEAKER_02]: Yep, their own hardware, and they get the whole thing up and running. [SPEAKER_04]: But what if I like being put on hold for 45 minutes to listen to pamphlet music? [SPEAKER_04]: so full visibility with none of their legwork.

[SPEAKER_04]: Yep, that's exactly it. [SPEAKER_04]: And it's sold through a subscription model, so it's no nasty surprises. [SPEAKER_04]: There's even a hardware buy-back program if you've already got kit from another vendor. [SPEAKER_04]: Ah, that's rather civilised. [SPEAKER_04]: Isn't it just? [SPEAKER_04]: So head over to meta.com slash smashing to find out more that's methr.com slash smashing. [SPEAKER_04]: And thanks to meter for supporting the show.

[SPEAKER_03]: What's your story for us this week? [SPEAKER_03]: Well, my story goes around an exclusive story that was published on British news site, The Guardian, over the weekend. [SPEAKER_03]: And it has to do with a UK biomedical research enabling organisation called UK Biobank. [SPEAKER_03]: Right, now I've heard of UK Biobank. [SPEAKER_03]: There a charity which for our North American listeners that would be not for profit, although they have a CEO, and that is Professor Sir Rory Collins will come back to him in a moment.

[SPEAKER_03]: They're associated with the academic medical research ecosystem. [SPEAKER_03]: And to be quite fair, the idea is that this is not something that you just get forced into, you volunteer to hand over via this group, all your medical data throughout your life, as much as you choose, up to an including everything. [SPEAKER_03]: So that they can anonymise it or de-identify it as they call it, and collect it together and make it available under apparently controlled circumstances to medical researchers who want to do long-term research.

[SPEAKER_04]: and my understanding is quite a lot of people have volunteered to participate in this I mean because people think that doing this will help medical research they think well there's no privacy problem as far as I'm concerned because you're going to be careful it's de-identified yeah because people won't be able to identify who I am but if this helps [SPEAKER_04]: medical science. [SPEAKER_04]: Something like half a million people have volunteered to help this study of diseases and things.

[SPEAKER_03]: And this is UK-only, so that's right for million people out of what is our population around 70 million. [SPEAKER_03]: So it's a very significant number of people who genuinely think they're doing the right thing, or maybe some of them are young enough. [SPEAKER_03]: that they haven't thought about how specific some of the conditions they might have in the future will be to them, right? [SPEAKER_03]: You know, maybe they've just had things that tend to happen to everybody so far.

[SPEAKER_03]: So they don't think that re-identifying them afterwards would be terribly hard. [SPEAKER_03]: Yep. [SPEAKER_03]: And you can also imagine why people would think, you know what, I was in a desperate situation, the National Health Service intervened and they basically saved my life. [SPEAKER_03]: You kind of feel maybe I should give something back. [SPEAKER_03]: I absolutely understand that. [SPEAKER_03]: and you'll remember that time I had that automotive accident horrendous and I wound up in hospital and then for four months I couldn't work but after four months I could walk again unadid and to this day all I have to show for it is some scars where the operations were done.

[SPEAKER_04]: Yeah, it was pretty bad, and as I recalled, as long as you remember now what side the filling cap is on your car, you should be safe going forward. [SPEAKER_04]: Well, it was a motorcycle filling cap. [SPEAKER_03]: It was a motorcycle. [SPEAKER_03]: Yes. [SPEAKER_03]: I could imagine, given the fact that I was in dire straits in the middle of nowhere and a helicopter descended from the sky and whisked him off to one of the premier teaching hospitals in the country.

[SPEAKER_03]: If somebody said you know what, in your operation we use stainless steel screws to fit all the broken bits back together. [SPEAKER_03]: Sometimes we use titanium screws, but they're much more expensive. [SPEAKER_03]: What we want to do is see what is the sort of risk real world of that. [SPEAKER_03]: would probably go, you know what, that would be really helpful. [SPEAKER_03]: I wouldn't want to begrudge the person. [SPEAKER_03]: But I like to think that I would think twice thrice or even four times about saying, okay, I'll sign up for this thing so that you can use what happened to me way back then when I had the crash.

[SPEAKER_03]: But also, [SPEAKER_03]: all the other medical data that applies to me for every doctor surgery, there's it every hospital, there's it every surgery, every bit of medical treatment, possibly even including mental health treatment that I have for the rest of my natural life. [SPEAKER_03]: That to me would feel like I was probably letting myself in for something for which nobody had really thought through the possible consequences for me.

[SPEAKER_03]: And that sadly is what seems to have happened in this case. [SPEAKER_04]: Right. [SPEAKER_04]: So we've got all these volunteers. [SPEAKER_04]: This data has been given to UK by a bank. [SPEAKER_04]: So what has happened? [SPEAKER_04]: What's gone wrong? [SPEAKER_03]: Well, [SPEAKER_03]: they require researchers to sign up and they've been in some way and I don't think they vet that they're great programmers or that they have experience in software engineering or that they have experience in cyber security or how to use GitHub properly etc etc and also people have signed up for this some of them might be surprised to know that these elite special group of [SPEAKER_03]: already apparently, number 20,000 people all around the globe, who right, get access to some much or all of this data for whatever research it is they want to do.

[SPEAKER_03]: Right. [SPEAKER_03]: And of course, as you and I know all too well, it's not enough just to trust those people. [SPEAKER_03]: You have to trust their computers as well, that they haven't got data scraping malware on them. [SPEAKER_03]: You have to trust the network there on. [SPEAKER_03]: You have to trust the employer or the owner or the influencer of the institution where they study, which might be quite hard to determine. [SPEAKER_03]: So what happened is that for good academic reasons.

[SPEAKER_03]: it was decided that anyone who's using this data and who's done their research, obviously they'll write software code which will process it and manipulate it. [SPEAKER_03]: And it's very important in the scientific research of this sort, medical or otherwise, that other people can repeat your experiments if they're given access to the data. [SPEAKER_03]: to see whether you cheated or made a mistake with the results. [SPEAKER_03]: Okay, so they're required to publish their code.

[SPEAKER_03]: Yeah, but of course they can't publish the data because anyone who wants to check the results has to go and persuade UK buyer bank the staff. [SPEAKER_03]: Yes, they're cool as well. [SPEAKER_03]: Well, that seems sensible to me. [SPEAKER_03]: Now I suspect that at least some of this code that was written would have been done, A by people who weren't skilled software engineers to start with, or perhaps B by some kind of vibe coding AI.

[SPEAKER_03]: Yes, very much so. [SPEAKER_03]: Yes. [SPEAKER_03]: How can I put it? [SPEAKER_03]: And you can imagine what happened when they went to publish because you imagine you're such a so excited. [SPEAKER_03]: Oh, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, yes, [SPEAKER_04]: Oh, okay, well, obviously that's an oversight, but duck, don't worry, because that code has been de-identified, hasn't it?

[SPEAKER_04]: There's no way of working out its Mrs. Miggins, you know, from 13 Trellis Avenue. [SPEAKER_04]: That's not gonna happen, is it? [SPEAKER_04]: So that's all right. [SPEAKER_03]: Yes, that sort of where the aforementioned Professor Sirore Collins chief executive and principal investigator of UK Biobank started his… I have to say sort of semi-rebuttal of what the Guardian had done. [SPEAKER_03]: What did the Guardian do? [SPEAKER_03]: So the Guardian found someone who had volunteered with UK by a bank, and went to her and said, look, we'd like to see just how well this is de-identified.

[SPEAKER_03]: Will you give us some of your medical data? [SPEAKER_03]: just some snippets of your history, just in another critical information, and we all see how little of it we need until we do a search and bang we get one record. [SPEAKER_03]: And as soon as you get down to one record, then you know that magic anonymized ID that ties that record to the others. [SPEAKER_03]: which is the whole purpose of this project, right, that you can tie this surgery to that treatment, this counselling to that behavioral change, etc.

[SPEAKER_03]: But without knowing who it is, and with this particular volunteer, they have the month and year in which she was born, which I think for most people in the UK given the number of breaches so far, we should consider a matter of public record. [SPEAKER_03]: Yes, yes, and they had the fact that she had a specific type of operation, I believe it was a Historectomy in a particular month of year and I think she was 71 years old, so she had a lot of medical history in there Oh, we just had information.

[SPEAKER_03]: Let's say the date of birth. [SPEAKER_03]: Let's consider that free of charge Let's just assume to a first approximation everyone the UK has a public date of birth [SPEAKER_04]: So let's call her Alice, and now, just with those two pieces of information, one operation, in one month that they knew, yeah, bingo, deanonymized. [SPEAKER_04]: That's just one person done. [SPEAKER_04]: And now, whoever it was, is able to find out everything else about all the other treatments that they've had.

[SPEAKER_03]: Yes, because you find that one record and it says, we're not telling you this is Alice from [SPEAKER_03]: Yeah. [SPEAKER_03]: And so you're just going to, well, what other things as 1053 had? [SPEAKER_03]: Well, three years ago, this five years ago, that seven years ago, the other, in other words, you've deanonymized that person. [SPEAKER_03]: You've re-identified them. [SPEAKER_03]: You can then go through the database and replace their magic number 1053 to whatever it is with the text Alice of Trellis Avenue.

[SPEAKER_04]: Done. [SPEAKER_04]: Right. [SPEAKER_04]: Thank goodness this person agreed to be a guinea pig for the Guardian, [SPEAKER_04]: so that both of you came by a bank that CEO, what's he had to say about this? [SPEAKER_03]: Well, he has reacted in a way that I think is very old-fashioned and suggest that he's not familiar with where we are in you might call deanonymization skills and abilities, right? [SPEAKER_03]: He just said, we take your privacy extremely seriously.

[SPEAKER_03]: Oh, red flat and novel one. [SPEAKER_03]: That's a novel life. [SPEAKER_03]: Yes, not her that one before. [SPEAKER_03]: I am also a UK biobank participant, so I know how much this matters. [SPEAKER_04]: Oh, how do we know his month and year of birth? [SPEAKER_04]: I bet we could find that out probably from company's house. [SPEAKER_04]: Yes! [SPEAKER_03]: or you could just kind of look at a photo of him roughly guesses age. [SPEAKER_03]: That gives you the year, and then you've got 12 months to play with, so it's not that hard.

[SPEAKER_03]: Right, right. [SPEAKER_03]: Okay, okay. [SPEAKER_03]: He said, we know that the possibility of your data being identified can never be completely removed, but it would require someone to have specific matching information from another source. [SPEAKER_03]: That is what the Guardian has done, the participant featured chose to give specific personal health information the Guardian then crossed referenced this. [SPEAKER_03]: This is not a failure of our approach to data confidentiality because the participant shared the information to identify themselves.

[SPEAKER_04]: Right, so we've already agreed that data birth is basically public knowledge now, right? [SPEAKER_04]: Yes, because we've all had so many breaches. [SPEAKER_04]: Correct. [SPEAKER_04]: Okay, so yes, they would have had to have known when should had a historic me operation, for instance. [SPEAKER_04]: I mean, it would be difficult. [SPEAKER_04]: Wouldn't it find an out when someone else has had an operation? [SPEAKER_04]: I mean, unless you handed it over.

[SPEAKER_03]: Unless you happened to be able to reconstruct that data as an attacker, maybe a cyber criminal, who's made millions off of ransomware and has got plenty of money in time to burn or a state sponsor attacker who's funded to do this as a job. [SPEAKER_03]: I would imagine that there are very, very, very many people in every country of the world, including the UK, who, when they have been in hospital for some serious, specific operation, have received get well soon messages on social media from their chimps.

[SPEAKER_03]: Wouldn't you think that? [SPEAKER_03]: Yes, so that gives you the month and year of the operation, and even if it doesn't actually say what they're in for many people give it away, or you might notice if there's a picture in the ward, you might be able to reconstruct what it is. [SPEAKER_03]: But here's an even easier way to do it, right? [SPEAKER_03]: Apparently, and this doesn't just disperse the effect women, this only affects women, right?

[SPEAKER_03]: our biases are in section, which requires an operation surgery. [SPEAKER_03]: The date of the operation earn avoidably coincides with the date of the child born during that operation doesn't it? [SPEAKER_03]: It kind of does, doesn't it? [SPEAKER_03]: You can imagine if it's one minute to midnight, then depending on when the midwife writes down, you might get it wrong by one day, but you only need a month and a year. [SPEAKER_03]: So if you start by going, let's focus on month, year, C-section.

[SPEAKER_03]: Right. [SPEAKER_03]: You also have the issue that I believe there are something like 100,000 operations in the UK each year for hernia. [SPEAKER_03]: That's the most common operation, apparently. [SPEAKER_03]: So, suddenly, the fact that this sounds like a very unlikely coincidence that an attacker could ever guess is not true, but imagine if they actually had data that they had bought off the dark web from an earlier breach from a health care institution that had been hit by ransomware data had been stolen, the ransom wasn't paid and the crux decided to sell it on.

[SPEAKER_03]: On its own, you would think that's quite annoying for those individuals, whoever I'm now knows, they had trouble with their throat in such a month year. [SPEAKER_03]: That would be bad enough, but that alone could now be enough to deanonymise all of those people. [SPEAKER_03]: And that's something like up to 50,000 people a year in the UK. [SPEAKER_03]: So Professor Sorori's disclaimer, I don't think he's being disingenuous. [SPEAKER_03]: I think he may just genuinely not realize how easy it is to stick together little bits of data from lots of sources.

[SPEAKER_04]: That's probably not the kind of stitching which he was done which earned him his professorship and knighthood, I suspect. [SPEAKER_03]: Yes. [SPEAKER_03]: I mean, Graham, if you think that we now have enough processing power around the world and enough data storage to build statistical inferencing models, some people call them LMS or AR's, such that you can essentially reconstruct [SPEAKER_03]: the full text of all the Harry Potter novels by steering this thing in the right way to guess what comes next.

[SPEAKER_03]: If that's possible, then piecing together this guy had a ton select to be in March 1985 and also had a hernia operation in July 2006 and was born in March 1963. [SPEAKER_03]: The idea that you can't use that with this data to deenonymise the person seems to be a bit of a fall-or-one hope. [SPEAKER_04]: Okay, now just to be devil's advocate for a moment, couldn't you argue that the Guardian has been a bit sensationalist here, because nobody's actually been identified against their will so far, have they?

[SPEAKER_03]: No, I don't know that they're being two senses. [SPEAKER_03]: I think that the article they published, which we'll put in the show notes, does give a reasonably balanced view. [SPEAKER_03]: They were saying, well, we went to a volunteer and we happened to have one piece of information that they've volunteered. [SPEAKER_03]: Because obviously, they didn't want to go on the dark web and say, hey, let's see if we can buy illegal data. [SPEAKER_03]: Yeah, do it that way.

[SPEAKER_03]: which I kind of suspect they could have done and I kind of suspect they wouldn't have got Alice from Trellis Avenue's data. [SPEAKER_03]: They might have got 10, 20, 50, 100 people's data. [SPEAKER_03]: So I think the problem here is not that people were forced to hand over data that then got abused by cyber criminals. [SPEAKER_03]: I just think that Professor Sorori may have underestimated the extent to which the de-identification of the data is reversible.

[SPEAKER_04]: Yeah, it sounds like he's made an assumption about probability that probably doesn't actually hold very much water. [SPEAKER_04]: The fact that nobody's been caught doing this yet, it is not the same as it can't be done. [SPEAKER_04]: And we have to worry about this because of course, the health service more and more wants to use our data. [SPEAKER_04]: And it wants to give it to some companies who are promising to do remarkable things, which they say will help make our health service more efficient.

[SPEAKER_04]: And I think they're understandable concerns about how well that data's going to be [SPEAKER_03]: Yes, particularly if one of those companies is an American startup that claims by taking a tiny drop of blood from your thumb, it can diagnose 7 trillion diseases and save the planet. [SPEAKER_03]: Yeah. [SPEAKER_03]: See, former CEO now serving 11 years in a federal prison. [SPEAKER_04]: Yes, yes. [SPEAKER_03]: So, there isn't clear and obvious advice for this.

[SPEAKER_03]: So, I don't want to say to people, do not sign up for these programs, because you may feel so strongly about the value that you got from something like the National Health Service. [SPEAKER_03]: then you feel it is actually worth cyber criminals getting at your stuff potentially in the future that you're prepared to take that risk because the benefits to other people from learning from what went right and wrong in your treatment that it just could all work out.

[SPEAKER_03]: But don't be seduced by the fact that hey this is absolutely fantastic. [SPEAKER_03]: the de-identification or the anonymisation of the data is bound to be enough and don't forget the data breaches are very sadly in the healthcare industry much more common than you might like. [SPEAKER_04]: Well, we've got time right now to chat about one of our sponsors this week, Vanta. [SPEAKER_04]: Oh, yes, my favourites, what do they do again? [SPEAKER_04]: They stop you running your entire security program out of a spreadsheet, Joe.

[SPEAKER_04]: That seems aimed at me personally, Graham. [SPEAKER_04]: Well, it is a little bit, yes, but you know how most companies have to prove their secure to customers or auditors or regulators and the whole thing involves chasing down evidence, filling in questionnaires and forms, updating the same spreadsheet sales over and over again. [SPEAKER_02]: over and over again, it sounds utterly soul-destroying. [SPEAKER_04]: Yeah, well, Vanta automates all of that.

[SPEAKER_04]: Automates it. [SPEAKER_04]: How? [SPEAKER_04]: Well, their trust management platform keeps a continuous eye on your systems. [SPEAKER_04]: It pulls everything into one place, and keeps you audit ready around the clock. [SPEAKER_04]: So no more staring at the ceiling at 2AM, wondering whether you've got the right controls in place or whether one of your supplies has been breached. [SPEAKER_04]: The stuff of nightmares. [SPEAKER_04]: Yeah, it would be wouldn't it, but this Banta solution uses AI as well, and it's the useful kind, flagging risks, collecting evidence, slotting into the tools your team already uses.

[SPEAKER_04]: So you move faster, scale without the headaches, and perhaps actually get some sleep. [SPEAKER_02]: Go to vanta.com slash smashing to find out more. [SPEAKER_02]: That's B-A-N-T-A dot com slash smashing, and thanks to Vanta for supporting the show. [SPEAKER_04]: And welcome back and enjoy our favourite part of the show, the part of the show that we like to call, Pick of the Week! [SPEAKER_03]: Pick, other week! [SPEAKER_04]: Pick of the Week is the part of the show where everyone chooses to send the like, could be a funny story a book that they've read a TV show, movie a record of podcast or website, or an app.

[SPEAKER_04]: Whatever they wish it doesn't have to be, security-related necessarily. [SPEAKER_04]: Well, my pick the week this week is not security related. [SPEAKER_04]: My pick the week this week is a website, which tickled me. [SPEAKER_04]: Everyone's gone mad about AI. [SPEAKER_04]: Everyone's using AI, left, right, and center. [SPEAKER_04]: Are you bored with AI or are you horrified with AI duck? [SPEAKER_03]: Uh, sorry. [SPEAKER_03]: What was that, Grin?

[SPEAKER_03]: I don't know. [SPEAKER_03]: When I heard that, when I heard AI, I thought, I'm gully more slop. [SPEAKER_04]: Well, this is a bit of fun. [SPEAKER_04]: This is a website called your AI SlopBores.me link in the show notes. [SPEAKER_04]: I'm going there. [SPEAKER_04]: I want you to go there. [SPEAKER_04]: So this presents itself as being a bit like an AI chatbot where you can type in a question. [SPEAKER_04]: And as is the case often with these AI chatbot, it's not going to give itself away for free, right?

[SPEAKER_04]: Bring it to this particular site. [SPEAKER_04]: You earn some credits before you can ask questions. [SPEAKER_04]: And the way in which you earn credits on your AI SlopBores.me is you can answer questions. [SPEAKER_04]: Other people have posted to the AI. [SPEAKER_03]: Oh, it's an MITM attack. [SPEAKER_04]: So you can effectively become the machine. [SPEAKER_04]: I've been playing with this deck, so I've actually had great fun pretending to be an AI.

[SPEAKER_04]: Answering other people's questions that they've been putting to what they may assume is an AI. [SPEAKER_04]: So for instance, someone asked me, can you draw a strawberry? [SPEAKER_04]: And I thought, well, yes, I can draw a strawberry, so I did a sort of rough sort of Microsoft paid style picture of a strawberry. [SPEAKER_04]: And then I wrote the word strawberry, or be it I put about 15 hours in it [SPEAKER_04]: They were happy, it's not 15, it's 12, I always get set wrong.

[SPEAKER_04]: Someone else said, can you draw some fried chicken? [SPEAKER_04]: So I drew a little cartoon chicken and put it in a fried pan. [SPEAKER_04]: Someone else said, oh, I'm thinking of going to Japan this year before World War 3 ruins everything. [SPEAKER_04]: am I safe to go? [SPEAKER_04]: And I said, well, you don't say where you're going to Japan from, that would be a useful relevant detail. [SPEAKER_04]: So I was able to answer these questions, and I was earning credit, so that I could then myself ask questions of the AI.

[SPEAKER_04]: I have to say. [SPEAKER_04]: I find it really addictive, pretending to be an AI, answering questions. [SPEAKER_03]: Now, I'm actually on that site right now, Graham, so help me along here, right? [SPEAKER_03]: It says I've got one token, and I asked a question, I said, how long is a yard, right? [SPEAKER_03]: And hasn't used up my token, so I hadn't been asked to solve anything yet. [SPEAKER_04]: Oh, go and click on the tab which says, LARP as AI.

[SPEAKER_04]: Oh, and if you go there, [SPEAKER_04]: and you click on start larping, you should receive a question. [SPEAKER_03]: Oh, it says someone has asked, stop looking at me. [SPEAKER_03]: Not a real question. [SPEAKER_03]: Submit an end token. [SPEAKER_03]: There you are. [SPEAKER_03]: Oh, that's it. [SPEAKER_03]: That's all you gotta do. [SPEAKER_03]: You say? [SPEAKER_03]: Am I even real? [SPEAKER_03]: No, that's not. [SPEAKER_03]: Break up text, blaming alignment of stars, and high credit score.

[SPEAKER_03]: Oh, that's good. [SPEAKER_03]: So I have to tell you something they can tell to their SO. [SPEAKER_03]: I'm going to put PIC's $$$$$ excess error 404. [SPEAKER_03]: I see what you mean. [SPEAKER_03]: It's quite addictive. [SPEAKER_04]: So you can literally put anything and you earn the tokens. [SPEAKER_04]: Now, it's possible for the person receiving your answer to say that it was spam or, you know, offensive or something like that, then maybe you won't get a token.

[SPEAKER_04]: But I imagine you're as bashing the keyboard. [SPEAKER_03]: Oh, now I've asked the question that I actually don't know the answer to. [SPEAKER_03]: Can I skip? [SPEAKER_03]: You can skip. [SPEAKER_03]: I'm just going to put Dino. [SPEAKER_03]: That'll do. [SPEAKER_03]: I've got six tokens already. [SPEAKER_03]: Explain to Catwise legally obligated to cuddle right now. [SPEAKER_03]: Let's put me out. [SPEAKER_03]: Exclamation point. [SPEAKER_03]: That's important.

[SPEAKER_03]: I've got eight tokens already. [SPEAKER_03]: Why do eyes exist? [SPEAKER_03]: Ah, can't hear you. [SPEAKER_03]: Motivational quote for people who's only gold today is not crying. [SPEAKER_03]: This is getting a bit weird. [SPEAKER_04]: There are some which are a bit weird, but you've now earned to see some credits, so you can ask questions. [SPEAKER_04]: I've got non-intoken snowgroom. [SPEAKER_03]: You're doing very well, Doug. [SPEAKER_03]: Well done.

[SPEAKER_03]: Is that good? [SPEAKER_03]: Well, I think so. [SPEAKER_03]: So now I can go back and spend those. [SPEAKER_03]: Can I, I won't do it now. [SPEAKER_03]: I'm going to save it up for later. [SPEAKER_04]: I think this is the future of AI. [SPEAKER_04]: If we had human powered AI, I personally find this quite a big, I particularly enjoyed the drawing tasks. [SPEAKER_04]: I think this is quite a good answer to things. [SPEAKER_04]: use AI rather than all these computers to do things.

[SPEAKER_04]: Well, we seem to have fallen into Edlong. [SPEAKER_04]: Folks, you can try this out for yourself. [SPEAKER_04]: Go to your AI slot balls.me and who knows, you could be answering a question from Duck when he uses up some of his credits. [SPEAKER_03]: What's your pick of the week? [SPEAKER_03]: When my pick of the week is something that I read on LinkedIn, which delighted me because as far as I can see, it's a real post, replying to an article where the post is not AI, which is surprisingly rare on LinkedIn these days.

[SPEAKER_03]: It's a chat by the name of Vaughan Shanks, okay, who is responding to a satirical news story on a website called The Excloit, right? [SPEAKER_03]: I think it tries to be a little bit serious, but this is more of an onion thing. [SPEAKER_03]: The headline on the site is [SPEAKER_03]: A judge has sentenced a CSO to 8 consecutive hours on the RSA conference Expo Fluor. [SPEAKER_03]: His crime failing to disclose a breach to the Securities and Exchange Commission of the USA within the mandated 4-day window.

[SPEAKER_03]: Legal experts, the SEC, are calling the penalty, Proportionate and Corrective. [SPEAKER_03]: Former RSA attendees are calling it barbaric. [SPEAKER_04]: It is barbaric. [SPEAKER_04]: I've been there. [SPEAKER_04]: I had a duck of you beat the harrots say expo floor. [SPEAKER_03]: Yes, working on a booth. [SPEAKER_03]: I have. [SPEAKER_03]: Oh, yeah. [SPEAKER_03]: And I think that was back in the days when it was, it wasn't quite as pay-to-play as it's become.

[SPEAKER_03]: Anyway, that the bit that Vaughan Shanks added is an exploration of what the RSA conference expo floor is because people may not know. [SPEAKER_03]: And his death and the issue on it is fantastic. [SPEAKER_03]: This is the Expo Floor for the uninitiated is 50,000 square meters of vendors who all do the same thing. [SPEAKER_03]: None of whom can quite explain what that thing is, and every single one of whom has, as of 18 months ago, always been an AI company.

[SPEAKER_03]: The defendant is said to be in good spirits. [SPEAKER_04]: Well, it's good timing because I think RSA is on next week, isn't it? [SPEAKER_04]: Yeah, something like that. [SPEAKER_03]: It's fun to go, but eight consecutive hours. [SPEAKER_03]: Oh, it's roughly hard. [SPEAKER_03]: As Vaughan Shanks point out, he says, as his joke is, the defendant has said to be in good spirits, but sources close to the case, warn that we'll change about 40 minutes in.

[SPEAKER_03]: somewhere between the third autonomous threat detection platform and the man offering to scan his badge just to send some resources over. [SPEAKER_03]: The sentence is believed to be the hardest and it down to a security executive since the solar wind's incident. [SPEAKER_03]: It's brilliant. [SPEAKER_03]: I love it. [SPEAKER_04]: Very funny. [SPEAKER_04]: Thank you so much Duck for joining us this week. [SPEAKER_04]: I'm sure lots of our listeners would love to find out what you're up to and follow you online.

[SPEAKER_04]: What's the best way to do that? [SPEAKER_03]: You can just visit my website. [SPEAKER_03]: It is pducklin.com slash about and find out about me. [SPEAKER_03]: And if you think I can create some fantastic content for you whether it's written, spoken, or visual, please get in touch. [SPEAKER_04]: fantastic, and of course, I'm on social media as well, you can find me on LinkedIn or you can follow smashing security on Reddit, BlueSky, and MasterDone, and don't forget to ensure you never miss an episode follow smashing security in your favourite podcast app, such as Apple Podcasts, Spotify, and Pocketcasts for episode show notes, Spongebob, and the entire back catalogue of RedVat459 episodes.

[SPEAKER_04]: Check out smashingsecurity.com until next time! [SPEAKER_04]: Cheer up, bye bye! [SPEAKER_04]: Bye! [SPEAKER_04]: You've been listening to Smashing Security with me, Graham Kluley, and I'm grateful to Doug for joining us this week, as well as this episode's sponsors, Adaptive Security, Vanta, and Meta, and all those chums who've signed up for Smashing Security Plus by a Patreon. [SPEAKER_04]: As members of Smashing Security Plus, they not only get episodes that pod earlier than the great Amosh public, and had free episodes at that, but they also get the chance to be pulled out of the hat.

[SPEAKER_04]: and be thanked here at the tail end of the show. [SPEAKER_04]: So let's pick some of them out of the metaphorical hat right now. [SPEAKER_04]: First up, Marvin 71, which is just the at least 70 other marvins, that they feel they need to distinguish themselves from, frankly I respect that. [SPEAKER_04]: A big hello to Elbow, which could be a name, could be a joint, a big Margie shout at someone who's hogging their arm [SPEAKER_04]: who's decided one name is quite enough.

[SPEAKER_04]: Thank you. [SPEAKER_04]: Cheers to Travis West. [SPEAKER_04]: Enter Heisenberg, who we are legally required to say we don't know and have never met. [SPEAKER_04]: A special welcome to one patron who's entered their name, entirely in Kenji characters. [SPEAKER_04]: And thus, unpronounceable by this ignorant Englishman, but thank you anyway. [SPEAKER_04]: And finally, thank you to Karen Reynolds, as well as Alex Tarsca and Richard Mortner.

[SPEAKER_04]: two names that sound like they belong, and they're very good detective novel. [SPEAKER_04]: If you'd like to join Smash and Security Plus and support the show, as well as get all of those benefits just head over to smashandsecurity.com slash plus for all of the details. [SPEAKER_04]: And I understand that not everyone can support the podcast in that way, and if that is true for you, do not be, you can still leave us a review or like the podcast or best of all, tell your friends that you enjoy smashing security, go on, encourage them to subscribe as well.

[SPEAKER_04]: Well, that just about rounds off the show for this week. [SPEAKER_04]: I hope you've enjoyed it. [SPEAKER_04]: See ya, bye-bye!

Transcript supplied by the publisher with the episode.

Smashing Security

by Graham Cluley · English · Tech & Science

Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all…

More from Smashing Security

  1. E462 · 42 min

    LinkedIn is spying on you, and you agreed to nothing

    LinkedIn has been secretly scanning your browser for over 6,000 installed extensions — on every single click you make. It can tell if you're job hunting, what religion you are, and whether you have ADHD. And none of this is mentioned anywhere in their privacy policy. Meanwhile, California's crypto millionaires are learning that no amount of encryption can protect you from someone who knocks on your door pretending to deliver a pizza. All this and more in episode 462 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special…

  2. E461 · 46 min

    This man hid $400 million in a fishing rod. Then it vanished

    A cannabis-growing, beekeeping, gyrocopter-flying Irishman invested his drug money in Bitcoin back in 2011 - and now sits on a fortune worth $400 million. There's just one small problem: the access codes were tucked inside his fishing rod case, which has mysteriously vanished. Or has it? Because this week, one of his frozen wallets suddenly woke up and moved $35 million - and someone had to identify themselves to do it. Meanwhile, Ajax Football Club scores a spectacular cyber own-goal, as a data breach that the club claimed affected "a few hundred" fans turns out to may have exposed the…

  3. E460 · 41 min

    Never knock on the door of a nuclear submarine base and ask for a selfie

    A disgruntled data analyst decides that the best response to losing his contract is to steal the entire company payroll database and demand $2.5 million in Bitcoin - signing his extortion emails from a company called "Loot." Meanwhile, two people drive up to the entrance of the UK's nuclear submarine base at Faslane and politely ask if they can have a look around. Tourists? Spies? Something in between? Plus: Female Muslim punk rock group, and a little red book that might save your sanity in a post-truth world. All this and more in episode 460 of the "Smashing Security" podcast with…

  4. E458 · 41 min

    How not to steal $46 million from the US government

    A Wikipedia security engineer accidentally wakes a dormant JavaScript worm that hadn't stirred since 2024 - and within minutes, giant woodpecker images are plastered across the internet's favourite encyclopaedia. Meanwhile, a crypto contractor hired to help the US Marshals manage seized digital assets allegedly decides to help himself to $46 million of it - and then brags about it on a recorded Telegram call. Plus: Graham champions Asterix, Trisha discovers the fantasy novels of Robin Hobb, and someone called "Lick" ends up in the nick. All this, and much more, in episode 458 of the…

  5. E487 · 58 min

    Clippy's crypto comeback

    Microsoft's Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn't from Microsoft either. Meanwhile, UK losses from hacked email and social media accounts have rocketed by 417%, as scammers pose as your friends to flog you tickets to gigs that don't exist. Plus, Hack The Box's Christine Bartlett joins us for a featured interview to ask what happens when AI agents join your security team, and whether anyone has thought to give them a performance review. All this…

  6. E486 · 41 min

    Vibe-coded shops, and hackable Flock cameras

    A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong? Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping up on American street corners, and took a very close look inside. All this and more in episode 486 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Dave Bittner. EPISODE LINKS: Claude Opus…

  7. E485 · 1 hr 3 min

    These researchers got drunk to hack an LG TV

    Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured…

  8. E484 · 46 min

    How websites are tracking you with silence

    When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated." All…

  9. E483 · 44 min

    This AI helps thieves steal your iPhone

    You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just…

  10. E482 · 50 min

    This hacker leaked GTA 6 - and launched their own cryptocurrency

    A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of "residential proxies" - how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet…

Every episode of Smashing Security →

Take it with you

The Melo app keeps playing with the screen off, works in the car and on your watch, wakes you to your station, and browses the whole catalogue offline. Free, no ads, no account.

Get it on Google Play