Episode notes
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five Guys) have got together and published advice on how companies should communicate after a cyber attack. The summary? For the love of God, stop calling every breach "sophisticated." All…
Transcript
Read the transcript · about 7,840 words, follows along as you listen
Danny Palmer:As I'm sure you've seen, in many cases a company will put out a rather generic statement saying they've been hit by a sophisticated cyberattack.
Unknown:Yeah, no one wants to get hit by a dumb attack, do they? No one wants to. No. Smashing Security, episode 484: How Websites Are Tracking You with Silence with Graham Cluley and special guest Danny Palmer. Hello, hello, and welcome to Smashing Security episode 484. My name's Graham Cluley.
Danny Palmer:And I'm Danny Palmer.
Graham Cluley:Danny, thank you so much for joining us once again. Always a pleasure to see you here on the podcast.
Danny Palmer:My pleasure. Thanks for having me once more.
Graham Cluley:Terrific to have you here. Well, before we kick off, let's thank this week's wonderful sponsors, ThreatLocker, Intruder, and Vanta. We'll be hearing more about them later on in the podcast.
Danny Palmer:This week on Smashing Security.
Graham Cluley:We won't be talking about how Berlin city government's ransomware attack started with a fake Cloudflare CAPTCHA.
Danny Palmer:You'll hear no discussion of—
Graham Cluley:How France has arrested 2 suspects for hacking the country's tax agency. And we won't even mention how hackers are stealing Claude tokens from subscribers. So Danny, what are you going to be talking about this week?
Danny Palmer:I'll be talking about new advice from cyber intelligence agencies which encourages companies which fall victim to cyberattacks to avoid using PR fluff to describe what happened.
Graham Cluley:And I'll be finding out how the sound of silence could be helping to track you across the internet. All this and much more coming up on this episode of Smashing Security.
Joe:This episode of Smashing Security is supported by ThreatLocker. Agentic AI is beginning to change the tempo of cyberattacks.
Graham Cluley:Ransomware that thinks for itself, worms that rewrite their own playbook mid-attack, agents happily chaining exploits together without ever pausing to ask a human, is this alright?
Joe:Which is all very interesting, just so long as it isn't your network they're experimenting on.
Graham Cluley:And that's the problem. When a machine can scope out your network, break in, and start creeping sideways through it faster than you can finish your coffee, you can't rely on the hope that someone will notice the alert eventually. And this is where ThreatLocker earns its keep. Default deny and least privilege sit right in the agent's path, so nothing runs just because it asks nicely. Application allowlisting decides what's even allowed to execute. Ring-fencing keeps trusted apps from wandering off and touching things they shouldn't.
Joe:And privileged access management quietly confiscates the elevated access. The attacker may be moving faster, but the controls are already in place. Agentic AI doesn't make established security principles obsolete. It makes getting them right considerably more urgent.
Graham Cluley:So while the attacks are picking up speed, make sure ThreatLocker is already standing in the way. Head to threatlocker.com/smashing to find out more and grab your free demo.
Joe:That's threatlocker.com/smashing. And thanks to ThreatLocker for supporting the show.
Graham Cluley:Now, Danny, quick question for you before we get started today. How good is your hearing? Have you got quite good hearing?
Danny Palmer:I don't think I do, you know, which is not a great thing because my eyesight is terrible to begin with. So you'd hope that my ears would pick up a bit more, like Daredevil, the superhero. He's blind and he can hear and sense things really well.
Graham Cluley:Yes.
Danny Palmer:I don't have that ability. I get by in the world, but I don't think you need me for listening for something really, really far away.
Graham Cluley:Maybe you have another super sense though. Even if your eyesight isn't that great and your hearing isn't that great, maybe you got, I dunno, a fantastic sense of taste.
Danny Palmer:I can identify certain types of food. I'm not talking about, oh, that's a curry and that's spaghetti. But no, I could probably tell you what sort of beer was what, vaguely, if you gave me some blind tasting. But no, nothing useful there, I'm afraid.
Graham Cluley:Well, I'm not gonna give you a beer-related game today. Instead, what I'm gonna do is I'm gonna play you a string of short sounds. And I want you to tell me what they are. And this is a game that I like to call Name That Chime. Listeners, you can play along as well and see how you do compared to Danny. So Danny, are you ready for round 1?
Danny Palmer:I am ready.
Graham Cluley:We'll start off easy, shall we? What is this chime?
Danny Palmer:Oh, that is the — that's from opening up Windows back in the day, isn't it?
Graham Cluley:Yes. Do you know which version of Windows that might be?
Danny Palmer:Oh gosh, it's been so long now. I all kind of meld into one. I'm gonna say '98.
Graham Cluley:I think it's Windows XP. I don't know what the difference — I mean, now we get to see, I've opened a can of worms here. Someone will say it's service pack number whatever, 1.0b or something, won't they? But anyway, I think that's a win. I think that's close enough to me. All right, let's get a little bit harder.
Danny Palmer:I do know that one. Yeah, that's the Nokia 3310 ringtone.
Graham Cluley:Very good.
Danny Palmer:My first mobile phone back in the day. So yeah, very familiar with that. And we all had that as teens.
Graham Cluley:It's an absolute classic. And my wife asked me, can I program her phone to sound like an old Nokia?
Danny Palmer:Nice. Does she do that thing like, what's that show called?
Graham Cluley:Dom Joly, Trigger Happy TV.
Danny Palmer:Yeah, shouting hello. Yeah.
Graham Cluley:Okay, you're doing really good. 2 out of 2 so far.
Unknown:Ace.
Danny Palmer:I do recognise that. Yeah.
Unknown:Right.
Graham Cluley:People of a certain age will know that.
Danny Palmer:Yeah, that's a 56K modem. That was my first experience with the internet.
Graham Cluley:Okay, you've got 100% so far. Let's see how you do on this one.
Danny Palmer:Oh gosh, that does sound familiar, but I think my 100% record is gonna be going here, so I can't place that off the top of my head.
Graham Cluley:Okay, that is the startup screen of a Nintendo GameCube.
Danny Palmer:Ah, well, see, I was always on the Sega side of the fence.
Graham Cluley:Unfortunately. All right, let's see if we can get you some more points. You might be a bit too young for this.
Danny Palmer:I'm getting morning television sort of vibes. Something like Granada Television, something like that.
Graham Cluley:Oh, so close. It's Thames TV here in the UK. Let's carry on.
Danny Palmer:Uh-oh.
Graham Cluley:That's very short.
Danny Palmer:Yeah, that is AOL Messenger, I believe, or one of the messengers. MSN Messenger?
Graham Cluley:I have it down as ICQ. I don't know if AOL did it as well.
Danny Palmer:They all blended into one. There's so many of them.
Graham Cluley:ICQ was really the Tinder of its day. No one wanted to know your age, your sex, your location, wasn't it? It was ASL they'd ask.
Danny Palmer:Yes, Scott, the internet was a strange place in the '90s and early noughties, wasn't it?
Graham Cluley:All right, one more. If you get this absolutely correct, you're going to win a special prize. Oh, are you ready?
Danny Palmer:I am ready.
Graham Cluley:Again, you might be a bit too young.
Danny Palmer:To me, it just sounds like when I was down at the opticians and they gave me a hearing test.
Graham Cluley:It's pretty unpleasant to listen to.
Danny Palmer:Yes.
Graham Cluley:It's a loading screen on a ZX Spectrum.
Danny Palmer:Ah, yeah, that's a bit before my time.
Graham Cluley:The extra point was going to be if you could recognise it was Daley Thompson's Decathlon.
Danny Palmer:See, I do know that game.
Graham Cluley:Well, folks, I don't know how you compare to Danny there. Depending on how well you did, you've either just proven you're a veteran of the analog internet, or you still think punch cards are a pretty neat idea. Either way, well played, everyone. Fair play, Danny.
Danny Palmer:Yeah, I think 50%-ish there. I mean, that's a pass.
Graham Cluley:Yes, I think so. I think we'll give you that. Now, funnily enough, sound is what I'm talking about today because something rather odd happened the other day to a chap called Matt Callahan.
Danny Palmer:Hmm.
Graham Cluley:And he is a developer and he's one of those people who likes to use Bluetooth headphones. Do you have Bluetooth headphones or earphones?
Danny Palmer:Yes. I mean, what I'm speaking to you on now is my sort of gaming ones here. These aren't the ones I go out the house with. I don't buy fancy ones now, 'cause I'm just losing them all the time. They're either falling out your pocket, falling down the gap in the tube, they go through the wash. I kind of miss plugging in.
Graham Cluley:The whole problem with these wireless earphones is they don't have a bloody wire, is it? If they had a wire, you wouldn't lose them.
Danny Palmer:And I think this is part of the reason why there seems to be more people playing things loudly on their phones on public transport these days, but that's a whole other issue.
Graham Cluley:Well, some folks actually swear by them. What they like is that they can seamlessly switch from your laptop or your desktop computer to your phone. Until of course your phone suddenly rings and your headphones completely refuse to switch over. And they're utterly convinced that your laptop is playing some sound. It's playing some Finnish death metal.
Danny Palmer:Connoisseur.
Graham Cluley:And so it just carries on ringing in your pocket and you're frantically clicking around on your PC trying to stop it making a noise so you can listen to your phone call. Anyway, this is what happened to this chap, Matt, and his phone was ringing, but his earphones weren't swapping over. So he checked Spotify on his computer. And that was paused and he checked YouTube and that wasn't playing any videos. And the only thing which he actually had ultimately running on his laptop was one single browser tab sat on the AliExpress homepage.
Danny Palmer:Ah, so that's the, is it Chinese retailer?
Graham Cluley:Yeah.
Danny Palmer:Chinese Amazon.
Graham Cluley:It's an enormous site. It's not just for people in China, people all around the world use it. And this particular page, however, in his browser, it wasn't playing a video. It wasn't actually playing anything as far as he could tell. It was just sitting there, but it was preventing his earphones from switching to his phone. And he's a sort of curious chap and he wondered why might this be?
Danny Palmer:You said he's a developer, so it sounds like this is the sort of thing he might tinker about with.
Graham Cluley:Yes, exactly. And so he looked at the browser tab to work out what was going on behind the scenes. And what he found was rather surprising. Now, as we all know, websites absolutely love to recognise us when we return to them. And the traditional way to do that is with cookies, which, you know, if you're a non-nerd, cookies are like little text files that get left on your computer and they say, this is Graham coming back again, you know, make sure to show him Doctor Who-related t-shirts and things like that.
Danny Palmer:You get the exact same algorithms I get by the sound of it.
Graham Cluley:And that's one of the reasons why people love to block trackers and cookies. They use private browsing windows instead. And because of this, websites have got sneakier over time, and a lot of them now try to fingerprint you when you visit them. Now, they're not asking — it's not like going through security at an airport. They're not actually asking for your fingerprints, but what they do is they take a really good look at you and they note down all of the details that when combined make you look different from other people.
Danny Palmer:Huh. Interesting.
Graham Cluley:Yeah. Well, they don't look at the size of your nose or your haircut, but what they do is they look at maybe the size of your monitor, what the resolution is. They might look at what fonts you have installed. They can look at what browser version you are using, huge amounts of information.
Danny Palmer:It's one of those things where, you know, maybe the general public, for want of a better phrase, doesn't know this is happening. But no, sounds quite invasive from what you say. If you can tell what size of monitor you are using, what your fonts are, what else can they see?
Graham Cluley:And it's actually the combination of factors, because it's all these little details. One detail, like the resolution of your screen, or the current window size or whatever it may be, or what fonts you have installed — by itself maybe doesn't narrow you down to one particular individual. But when it's hundreds of details all combined, that particular pattern, it might say, well, we've only ever seen one person with that particular mix before.
Danny Palmer:Hmm.
Graham Cluley:So they won't necessarily know who you are, but they know that you're individual number 12,038.
Danny Palmer:Yes. And you've got this size monitor, use this size font to visit these sites, et cetera, et cetera.
Graham Cluley:And you like Doctor Who t-shirts.
Danny Palmer:Yes. I think about this in another way. I use Reddit quite a lot. I mean, I've got my account there, it's anonymous. I don't post anything under my name.
Graham Cluley:Yeah.
Danny Palmer:Just for the sake of being anonymous on the internet. But I reckon if you found my profile and saw which subreddits I posted in, you'd probably easily identify it's me through sort of my interests, you know, posting about this sports team, this computer game, Doctor Who.
Graham Cluley:Yes, exactly. You're gonna be Dungeons and Dragons. You're a bit into wrestling. See, I know enough about you, Danny.
Danny Palmer:Yeah, you've identified my Reddit account there.
Graham Cluley:Yes, I think I probably could, that particular mixture.
Danny Palmer:And that's why I have my Reddit account set to private.
Graham Cluley:So all of these details which can be grabbed by a webpage can pick you out from just about everyone else. And what Matt found on AliExpress's website was that it had a piece of code which was doing just that, but it was audio fingerprinting. And so the site would ask his browser, or any person going to the site, to generate a very specific, very precise sound. Or rather, it gave the browser complicated maths to generate a sound.
Danny Palmer:Yeah.
Graham Cluley:And then it paid close attention to the final result, because it turns out no two computers calculated the audio maths in precisely the same way. So different web browsers running on different operating systems all crunch those numbers in their own slightly unique way. There's microscopic little quirks in the final calculation. It's a bit like how you can have two different pianos playing the same sheet music and they would still sound very slightly different.
Danny Palmer:Yeah, I understand what you're getting at. So is the computer actually making this noise? Can the user hear this noise, or is it so subtle the user themselves can't hear it, but the device can?
Graham Cluley:Well, this is what was really sneaky, was that AliExpress turned the volume of the noise it was generating down to zero. So you can't hear it. It's not actually generating anything which is audible. As far as your computer is concerned, there isn't any media playing at all, just some background calculations happening. Silence doesn't mean it can't be picked up by your hardware. So the calculations do actually go and grab hold of your computer's real audio system to do the computation. And on Matt's setup, that was enough to make his headphones think that audio was actually playing on his laptop, even though it'd been programmed to say absolute zero.
Unknown:Hmm.
Graham Cluley:And so his phone, when it rang, got ignored by his Bluetooth headphones. So this is really sneaky, I thought.
Danny Palmer:It's sneaky. It's very sort of — so many things these days seem to say, oh, we've seen this in a sci-fi movie.
Graham Cluley:Yeah.
Danny Palmer:Sci-fi movies go, ooh, this is a scary way how things could end up. Companies seem to go, that's a great template for how to do things.
Graham Cluley:Yes. So they have built a tracking script, which is as quiet and invisible as it is possible to be. It doesn't give itself away — well, it does give itself away, because it accidentally annoyed someone else's Bluetooth headphones. So this kind of thing isn't new. It's not unique to AliExpress. It's just one of a bunch of tricks which websites have up their metallic sleeves in order to track you. And it could be used for good. I mean, it can be done to work out if you're a genuine shopper or a bot, for instance.
Danny Palmer:Yeah. Especially these days when so many people are using AI agents and that sort of thing to spam queues and things for gig tickets and whatnot.
Graham Cluley:Do you know what had happened to me today? I was on LinkedIn. I'd written an article for a client of mine and I posted it up on LinkedIn saying, go and read this, you know, fascinating story. Go and read this.
Danny Palmer:Know the feeling.
Graham Cluley:And within about 2 minutes, this guy had replied as though he had read the article and he had this pithy little comment and hahaha. I looked at his reply, you know, sort of summing up my article, and I thought, that wasn't written by a human. And I went to look at his other comments and I saw a steady stream of every minute he's replying to someone else's article with his own 3-sentence comment on it. Clearly been written by an AI, some of them even including emojis as well. But it's just got the stench of AI about it.
Danny Palmer:Yeah. Gosh, it's so interesting and weird to me how someone whose job is writing — I mean, I take great pride in writing stuff and even for the most basic thing. Well, yeah, it seems there are people who just sort of farm out everything to AI. I actually made a LinkedIn post earlier today poking fun at this where I say, you can tell my work is not AI generated because you'll be able to see the errors in all the first drafts.
Graham Cluley:That's right. So plenty of browsers do try to stop this kind of fingerprinting, including this audio fingerprinting, for privacy reasons. So Firefox and Brave, they scramble the reading so that trackers get an unreliable answer. I think what they actually do is they make all of the calculations look a bit generic. So you can't distinguish as easily between them.
Danny Palmer:It's like it says, oh, John Smith is using this site. And there's like a million other John Smiths out there in the world.
Graham Cluley:Yes. A bit. It's a bit like the Matrix. The Matrix when — is it Agent Smith or something?
Danny Palmer:Smith, yeah.
Graham Cluley:Agent Smith gets replicated millions of times. Safari does something similar as well when you're private browsing, because it injects random noise into the Web Audio API's output. So you wouldn't be able to tell with the human ear, but if anything is coming along and trying to work out any difference from the audio, even if it's silent audio, as in this case, it wouldn't be able to. So you might not be going mad if your headphones start behaving strangely when you're visiting a shopping website. And if you would rather your browser didn't do this kind of thing, what you can do is you can run a browser extension. uBlock Origin is a good one, which can block this kind of behaviour for you and give you that extra little bit of privacy if you don't want to be tracked online.
Danny Palmer:It's really interesting how there's some tech firms which are actively doing these things to try and build up people's privacy, to protect against the stuff that other tech firms are doing.
Graham Cluley:Yes.
Danny Palmer:And a lot of it is behind the scenes. I mean, your average user will have no idea what is going on in this fight in the background while they're just browsing the internet.
Graham Cluley:There is this incredible arms race between different technology companies going on all the time. The irony is, of course, some of the tech companies which are building these browsers are themselves advertising companies. Let's not beat around the bush, right?
Danny Palmer:Yes. The internet is a very interesting and often flawed place, it turns out.
Graham Cluley:And on that note— I love it. Actually, maybe I'll make that my ringtone.
Unknown:This week's episode is supported by Vanta.
Graham Cluley:Joe, what's the thing that keeps you up at 2 o'clock in the morning, security-wise?
Joe:Honestly, whether I remembered to hit the record button.
Graham Cluley:No, no, no. I mean a real worry. No, like, have I got the right controls in place? Can I actually trust my vendors?
Joe:Nope. I'm still worried we might not actually be recording.
Graham Cluley:Okay, try this one for size. How do I ever climb out from under all these clunky old tools and manual processes?
Joe:Okay, fair enough. That does sound scary.
Graham Cluley:Well, that's where Vanta comes in. It takes the manual misery off your plate. So no more wrestling spreadsheets, hunting down audit evidence, or slogging through endless questionnaires.
Joe:That's right. Their trust management platform continuously monitors your systems, centralises your data, and uses AI to flag risks and keep you audit-ready all the time.
Graham Cluley:Going for SOC 2, ISO 27001, GDPR, HIPAA, whatever it is, Vanta gets you there faster and lets you scale with confidence.
Joe:And actually get back to sleep.
Graham Cluley:Head to vanta.com/smashing to get started. That's V-A-N-T-A.com/smashing, and our listeners get $1,000 off.
Joe:And thanks to Vanta for supporting the show.
Graham Cluley:Joe, the record button, you definitely pressed it this time, right?
Danny Palmer:Me?
Joe:I thought it was you.
Graham Cluley:Danny, what's your story for us this week?
Danny Palmer:Now, Graham, I've been a technology journalist for over 15 years now, and I've focused on cybersecurity reporting for I'd say at least 10 of those. That means I have seen and reported on hundreds of cyberattacks, data breaches, and other, let's call them incidents.
Graham Cluley:Yes.
Danny Palmer:Over the years.
Graham Cluley:Yes.
Danny Palmer:As I'm sure you know, so much of this stuff happens. I mean, retailers, utility providers, government agencies, banks and financial services companies, charities, sports teams, even postal services. You name the industry, I've likely written about a cyberattack, a hack, a data breach, a ransomware attack.
Graham Cluley:Yeah.
Danny Palmer:Or a DDoS attack, which has affected the organisation in some way. And there's new stuff keeps appearing, as we've seen in recent times with AI and whatnot. But it is also a bit weird to think about how long I have been doing this. When I first started at ZDNet back in 2016, one of my first stories was about a ransomware attack against a local council. And the council didn't pay because the ransom demand was a whopping £500, which is just amazing to think about in terms of how much ransom demands and things have gone up.
Graham Cluley:You would be thanking your lucky stars these days, wouldn't you? 500 quid?
Danny Palmer:Yeah.
Graham Cluley:Brilliant.
Danny Palmer:You'd think the cybercriminal in question might be a bit slow on the uptake. It's like that bit in Austin Powers where Dr. Evil's going, $1 million, and just like, yeah, whatever. So anyway, loads of these attacks in many, many cases, especially when the entity affected by the cyberattack is here in the UK. As a cybersecurity reporter, it has been my job to find out exactly what is going on, which sometimes can be harder than other times. I've made phone calls or sent emails to PR communication teams to verify they've been hit by a cyberattack. More often than not, the organisations in question don't want to speak widely about it because they often cite ongoing issues, which is understandable. I see their perspective from that. You know, my job is to try and get information about what's going on, but then organisations, if they've got an ongoing thing, they don't want to jeopardise that. I suppose you can think of it like when a court case is ongoing, the news publications can't really say much about it just because it might impact what is going on.
Graham Cluley:Sure.
Danny Palmer:As I'm sure you've seen in many cases, a company will put out a rather generic statement saying they've been hit by a sophisticated cyberattack.
Unknown:Yeah.
Graham Cluley:No one wants to get hit by a dumb attack, do they?
Unknown:No. No.
Danny Palmer:Sometimes it turned out to be a teenager that guessed the internet-facing admin password was 1234. Not that sophisticated, but I suppose they don't want to seem like they've been foolish, but these things eventually sometimes come out. Anyway, why am I talking about this? I assure you, Graham, it's not just ranting.
Graham Cluley:Clearly it is.
Danny Palmer:It is, it is sort of me just ranting. This week, cyber intelligence agencies from the United States, Canada, the United Kingdom, Australia, and New Zealand, collaboratively known as Five Eyes, they've got together and they've published advice to organisations on what they should do when they get hacked.
Graham Cluley:Sorry, I may have misheard you. This is Five Eyes. This isn't Five Guys, correct?
Danny Palmer:It's not the burger chain. No, Five Eyes. And the advice that Five Eyes have given organisations is that if you get hacked or face a cyber incident, please be a bit clearer in your communications about what has happened.
Graham Cluley:Right.
Danny Palmer:So they put out this document. It's titled Communicating Under Pressure: Best Practices for Service Providers. And that guidance has been published by CISA, which is the agency responsible for securing critical infrastructure in the United States. But it's also been written with input from other Five Eyes agencies, including the FBI, the UK's National Cyber Security Centre, and the Australian Signals Directorate. The aim of the 9-page document is to provide guidance to organisations on how they can plan and execute what they say is clear, timely, accurate, and audience-appropriate communications during IT and OT outages as a result of cyberattacks and other issues. As we've just discussed, these cyberattack things appear to be quite common these days.
Graham Cluley:This sounds like a real novelty, Danny. So it's going to be clear and timely and accurate and appropriate.
Danny Palmer:Yes.
Graham Cluley:For the audience. This sounds like genius, whoever came up with this idea, rather than obfuscated and complicated and difficult for people to peruse and unscramble.
Danny Palmer:Yeah. Yeah.
Graham Cluley:I'm glad we've got these intelligence agencies to tell us maybe this would be a good idea.
Danny Palmer:Yeah, they're really earning their coin here.
Graham Cluley:Yeah.
Danny Palmer:Well, unfortunately, it seems for many organisations, especially around the corporate communications areas, this is brand new information to them. But the advice is based on a handful of key ideas. And the first around these is to ensure your organisation already has a plan around communications should it be hit by an incident. Businesses are told to have contingency plans in place for their cybersecurity and other teams on how they should react if they get hacked or breached. So it only makes sense that the communications team should be a part of that. I mean, there should be some sort of standard document.
Graham Cluley:Yeah.
Danny Palmer:It might not be as simple as it sounds because of course every cyberattack is different and they can cause different types of disruption to an organisation, which means statements and communications might need some tailoring depending on what's going on. Something I've just thought of as well is we might have to factor into this: if you're hit by a certain type of cyberattack, can you even get that information out there into the world?
Graham Cluley:Oh, absolutely.
Unknown:Yeah.
Graham Cluley:Because if you've been hit by ransomware and your email server is down, you haven't maybe got your address book. It's tricky. Often when we've seen a company which has been hit by something like ransomware, what you find is they've actually been communicating with each other via WhatsApp.
Danny Palmer:Yes.
Graham Cluley:Or using some other system because none of our IT systems work anymore.
Danny Palmer:Yeah, I've heard various cases where organisations which have been hit have discussed how they set up things like Google email addresses or WhatsApp, that sort of thing, just to communicate. Anyway, so the plan is to have a plan. So if the worst happens, someone in an organisation knows how to react — stakeholders, partners, customers, and yes, nosy gits like me in the press. If we have questions, they can actually answer those questions. So that's tick one. So that leads to the second piece of advice, which is that those who have been hit with a cyber incident should, quote, practice transparency and avoid PR and marketing language. Yes.
Graham Cluley:Maybe don't use any people in the PR and marketing department. Maybe if you want, get a developer to write your statement. Get someone in the IT department to describe what's happened to the company. Now, there may be drawbacks in that approach as well. You could have an impact on your stock price, could have an impact on your brand reputation, but it'll be clinically honest. That's the thing you can guarantee. There will be absolutely probably far more transparency than you could ever have wanted.
Danny Palmer:It is this advice around the PR marketing language which has really sparked my interest. There's a lot of fluffy marketing language which doesn't really tell you anything. Now, as a reporter, this is frustrating. You know, it just basically sort of barricades me from doing my job in terms of trying to actually find out what has happened. But it's even more worrying for customers if they feel like they've been left in the dark by vague statements. In the long run, it doesn't help anyone.
Graham Cluley:Can I play devil's advocate here for a second?
Danny Palmer:Please do.
Graham Cluley:Because obviously I have complained before about the press releases from organisations who've been hit by sophisticated cyberattacks and all the rest of it. But if you put yourself in the position of a company which has suffered an attack and you are saying, Danny, you need to be transparent and you need to explain what's happened, it's not always obvious what has happened.
Danny Palmer:That is true. That is true.
Graham Cluley:And it's not always obvious what the scale of it is. So it's like, well, we know this has happened, but we don't know yet whether our customers are really impacted, or whether it's 3 of our customers or 3 million of our customers. And it's going to take time for us to ascertain that. So much as I would love companies to be more upfront about these things, there are sometimes quite legitimate reasons why they may find it impossible to confirm everything all at once.
Danny Palmer:That is very true.
Graham Cluley:What would you as a journalist like them to say to you? At that early initial point?
Danny Palmer:Me using my miserable journalist hack brain. Well, there have actually been some high-profile cyberattacks over the years where the organisation affected has been pretty transparent about what has happened during the incident and its resolution. I think one of the best examples of this, NotPetya, remember that?
Graham Cluley:Yes.
Danny Palmer:So that hit organisations around the globe in 2017. One of the organisations hit by this was the shipping giant Maersk. And if I recall correctly, the company's security and leadership teams were rather transparent. This instance hit us, here's how we're dealing with it. And, you know, they completely gave updates on how they're trying to fix it. I mean, this was a major shipping company where a lot of stuff that goes around the world was reliant on it.
Graham Cluley:Absolutely. I mean, if you think about all the problems which are being caused right now by the Straits of Hormuz being closed. Maersk, this huge shipping organisation, their ships weren't moving.
Danny Palmer:Yeah.
Graham Cluley:Because their IT systems were down. And I think you're right, they demonstrated real fantastic leadership. I mean, they came out looking like rock stars after this. They were hit by a cybersecurity breach, but they actually turned it in some ways into a great piece of branding for them because they came out looking like heroes.
Danny Palmer:Yeah.
Graham Cluley:Not only did they not pay, but they were so open about what had happened. And what you find is that when you are open, when you do speak to your clients, and your customers and your partners and explain to them what's happening, you actually get a lot of sympathy.
Danny Palmer:Yeah. These organisations that should have been doing as much as they can to prevent a cyberattack. It's the cliché, isn't it? You only need one hole in the armour to get in.
Graham Cluley:So this guide, which has come out from Five Eyes, is there one sort of final piece of advice from them which companies should take on board?
Danny Palmer:They just want organisations to be very, very clear about what happened. In my experience, this transparency helps reassure the public. It can help reassure the companies around it. Other cybersecurity leaders like to hear about these things. They can learn lessons. I mean, I've got an interview that'll be coming up that we publish shortly for Inverness Security Magazine, where I spoke to a CISO about a ransomware attack that hit them and how he recovered without paying the ransom, which is, yeah, you don't really get from PR speak. So, yeah, to answer your questions, what's the final piece of advice?
Danny Palmer:It recommends once an incident has been dealt with, organisations should detail the technical information about what happened, what the cause was of the incident. That sort of thing can help other organisations from falling victim to attacks. So maybe it is those IT workers and those devs that need to write those documents. Maybe not the ones doing the first PR, but at the end of the cycle, real-world lessons can be really helpful to organisations. And I'm not just saying that as a reporter with a vested interest in digging out information. I promise.
Graham Cluley:This episode is sponsored by Intruder. Now, Joe, quick quiz. How often does your team ship code?
Joe:Multiple times a week, maybe more if someone's had too much coffee.
Graham Cluley:And how often do you get a proper pen test?
Joe:Oof, once a year if we remember.
Graham Cluley:Well, that's the problem right there. Software moves weekly. Pen testing moves yearly. So most of what you ship never actually gets tested properly.
Joe:Which is exactly the gap Intruder's AI pen testing closes. You get the depth of a real manual pen test, but on demand, whenever you need it. No scoping calls, no 6-week wait, and it costs a fraction of the traditional price.
Graham Cluley:It's built by Intruder's own certified pen testers, so the agents catch the complex stuff human testers can miss. And every finding is validated against your actual app. Real issues, not noise. You get an audit-ready report within hours.
Joe:And it plugs straight into Intruder's full platform. Attack surface monitoring, cloud security, vulnerability management, all watching around the clock. It flags what's exploitable, what to fix first, and how, so your team can act without waiting around for the security team.
Graham Cluley:Over 3,000 companies already trust Intruder with their attack surface.
Joe:You can kick off a pen test in minutes, and as a Smashing Security listener, get 25% off your first.
Graham Cluley:So just head to intruder.io/smashing. That's intruder.io/smashing.
Joe:And thanks to Intruder for supporting the show.
Graham Cluley:And welcome back, and you join us at our favourite part of the show, the part of the show that we like to call Pick of the Week. Pick of the Week.
Danny Palmer:Pick of the Week.
Graham Cluley:Pick of the Week is the part of the show where everyone chooses something they like. It could be a funny story, a book that they've read, a TV show, a movie, a record, a podcast, a website, or an app, whatever they wish. It doesn't have to be security-related necessarily. Well, my pick of the week this week is not security-related. Danny, I don't know if you consider me a bit of a sportsman.
Danny Palmer:Oh, definitely.
Unknown:Yeah.
Graham Cluley:Do you really?
Danny Palmer:Oh, excellent. No, not really. No, I don't think sports is, a forte. I mean, you're like me — I enjoy watching sports, playing it not so much. I once took a shot on goal and it went out for a throw-in. I'll leave it there.
Graham Cluley:Dear me. Anyway, last weekend, hundreds of people from around the world congregated on the tiny island of Easdale in the Inner Hebrides off the shores of Scotland.
Danny Palmer:Sounds remote.
Graham Cluley:Normal population of about 60, but they had about 350 people descend on them. Why were they there? I will tell you why they were there. Because, as I'm sure you're aware, Danny, it was the World Stone Skimming Championships. So for anyone who's ever skimmed a stone, I wouldn't say I've ever successfully skimmed a stone.
Danny Palmer:No, it's gone in the water.
Graham Cluley:Yes, it goes in the water and makes a bit of a bloop sort of sound.
Danny Palmer:Sinks.
Graham Cluley:Yeah, it's not that great. It's more sort of a sort of uh-oh kind of noise, really. When you skim a stone, the idea is that it bounces along the water a bit like a Barnes Wallis bomb going up against a Nazi dam sort of bouncing along and how far can you get it? Well, they have this competition in Scotland. People come from all around the world. They were coming from Africa. They were coming from the Antipodes.
Danny Palmer:It's a world championship.
Graham Cluley:Yeah, it's the world champ— it's not the World Series in America, which doesn't involve 99% of the world. This was the entire world, practically, were involved in stone skimming. Now, sometimes it's quite controversial, it turns out. Last year, there was some controversy. Officials caught some competitors meddling with the stones. They were sanding their stones into suspiciously perfect discs.
Danny Palmer:Ooh.
Graham Cluley:In order to cheat.
Danny Palmer:Sounds a bit like tampering of cricket balls.
Graham Cluley:Yeah, exactly. And so they've now hired an actual geologist to police the integrity of the stones.
Unknown:Now—
Danny Palmer:You're always better off with a geologist around.
Graham Cluley:Very wise. Very wise. Well, I know lots of people are excited to hear about the World Stone Skimming Championship, but of course you're thinking that was last weekend and I wasn't on the island of Easdale last weekend or in the Outer Hebrides. What can I do? Have I missed it for another year? Well, fear not, fear not, because I have researched this and I've found a YouTube video which is 4 and a half hours long.
Danny Palmer:Nice.
Graham Cluley:Live coverage of the World Stone Skimming Championships. No spoilers. I'm not gonna reveal who wins, but if you want to go and check it out, links in the show notes. Danny, I know you love your sport. Will you be checking out?
Danny Palmer:I honestly think I will, 'cause this sounds fascinating. And I also wanna see what the commentators speak about for 4 and a half hours.
Graham Cluley:Yeah, well, I wouldn't get too carried away imagining there's actually gonna be commentary. There may be people introducing each skimmer, but there's not a lot of, you know, you don't sort of get Sue Barker or her — do the competitors get big entrances like World Championship boxers? That'd be fantastic, wouldn't it? Anyway, the World Stone Skimming Championship is, of course, my pick of the week. Danny, what's your pick of the week?
Danny Palmer:Well, by complete coincidence, Graham, my pick of the week is also water-based.
Graham Cluley:Okay.
Danny Palmer:You may remember that from one of my previous appearances on Smashing Security that this year, I finally started playing Dungeons & Dragons at a venue which runs games you can drop in and out of.
Unknown:Yes.
Danny Palmer:And they're very fun, very convenient. People like me with busy lifestyles, he tries to convince himself. But no, I've attended a few sessions and—
Graham Cluley:Right.
Danny Palmer:Now, outside of journalism and editorial writing, I worry that I'm not the most creative person in the world. So I — it's taken me a bit of time to sort of come up with my character backstory and lore.
Graham Cluley:Okay.
Danny Palmer:But it finally seems to be coming together. He's evolved into something of a nautical explorer, someone who is an expert in sailing on the high seas, and searching for long-lost islands for treasures. Some people might say this sounds a bit like a pirate. Keen to do my research, I've been reading a book called The Pirate's Code: Laws and Life Aboard Ship.
Unknown:Oh yes.
Danny Palmer:It's by Dr. Rebecca Simon, a historian who specialises in the Golden Age of Piracy. So think late 1600s into the early 1700s. And Graham, I have learned a lot about pirates by reading this book.
Graham Cluley:Okay.
Danny Palmer:Turns out, while popular pirate tales get a lot right, they also get quite a bit wrong.
Graham Cluley:Right.
Danny Palmer:For a start, as far as I can tell, there were actually no wisecracking talking parrots.
Graham Cluley:What's the point of that? Why have a parrot?
Danny Palmer:Company, I suppose. I think they used to sort of help with getting rid of vermin, apparently.
Unknown:Oh, okay.
Danny Palmer:We apparently have Robert Louis Stevenson's 1883 novel Treasure Island to thank for the pirates and for walking the plank as well. That wasn't actually really a thing — it just became a thing in fiction. I think one pirate maybe tried to do it, but he wasn't very successful at it. But something I found interesting while reading this is there's arguably some similarities between pirates of the 17th and 18th centuries and cybercriminals today. And no, I don't mean the software pirates who download movies, music, and games for free from nefarious sources.
Danny Palmer:You see, something I learned from this book was that one of the reasons that men — and it was for the most part men — signed up for life on a pirate ship was because the paying conditions were much better than working on a legitimate vessel, be it a trading ship or in the Royal Navy or something like that. And this had me thinking about how a lot of malware developers and BEC scammers try to justify doing this work, saying, oh yeah, we're doing crimes, but it pays more. They also see themselves as taking from the rich — they often mean people in Europe and the United States. If they stole my savings, I don't think I'd be seeing it as some sort of romantic ideal about stealing from the better off.
Graham Cluley:Well, yeah, I think this is a completely spurious argument if they are seriously using this. But I mean, if you think of how many people are romance scammers or defrauding the elderly out of their savings.
Danny Palmer:No, they see themselves sometimes just as, yeah, oh, making the money or living outside of the rules of the norm, as it were. Like cybercrime, piracy — yes, it has potential vast riches, but do it for too long or push things too far and you can get caught, which if anything this book has taught me is that didn't go very well for pirates if they were caught.
Graham Cluley:So you are enjoying this book. What's the name of the book again?
Danny Palmer:It is called The Pirate's Code: Laws and Life Aboard Ship by Dr. Rebecca Simon. I definitely recommend this book because it ties some real history to think about in a fun way — pirates are very much in the public consciousness, but you think about how much we actually know about them. So I recommend that book 100%.
Graham Cluley:Well, that just about wraps up the show for this week. Thank you so much, Danny, for joining us on Smashing Security.
Danny Palmer:Thank you. Pleasure as always.
Graham Cluley:I'm sure lots of our listeners would love to find out what you're up to and follow you online. What's the best way to do that?
Danny Palmer:Best ways at the moment, probably on LinkedIn, where I try to regularly post, and Bluesky as well. That's just more my general ramblings rather than cybersecurity things. They're very interesting, I promise you.
Graham Cluley:And of course, you can find me, Graham Cluley, on LinkedIn and Bluesky and Mastodon and Instagram and TikTok. The list goes on. Or you can follow Smashing Security on Reddit and Bluesky and Mastodon as well. And don't forget to ensure you never miss another episode. Follow Smashing Security in your favourite podcast app, such as Apple Podcasts, Spotify, and Pocket Casts for episode show notes, sponsorship info, guest lists, and the entire back catalogue of more than 480 episodes. Check out smashingsecurity.com. Until next time, cheerio. Bye-bye.
Danny Palmer:Bye-bye.
Graham Cluley:You've been listening to Smashing Security with me, Graham Cluley. And a huge thank you to Danny Palmer for joining me this week and to this week's sponsors, ThreatLocker, Intruder, and Vanta, whose money we've accepted with enormous enthusiasm and only a small amount of shame. And a very special thank you to the following fine chums. Travis West, who's riding in, sorting out his security posture, and riding off again. We've got Richard Anand. Cheers to Panda Bear, whose true identity remains one of the great unsolved mysteries of the world. And also to Panos. Sounds like a Greek loaf of bread if you ask me. Big love to Billy, a man unbothered by surnames. And to Robert Martin and Govind Acharya, a name that sounds like it belongs to someone who knows something we don't. And finally for this week, Jamie Forster, Scotia, and JBSK. Four letters there with zero explanation and maximum intrigue. Those fine, upstanding, and clearly slightly reckless individuals are members of Smashing Security Plus, which means they get their episodes ad-free earlier than the general public, and perhaps most importantly, they get their names read out at the end of the show in a tone that, well, sort of hovers somewhere between sincere gratitude and mild ridicule. If you would like to join them in this exclusive club of the wonderful and slightly foolish, head over to smashingsecurity.com/plus where for a modest fee, you too can be publicly mocked by a middle-aged British cybersecurity podcaster. So yes, you can become a patron, or if you'd rather keep your money, there are plenty of ways to support the show that don't cost a penny. You can like, you can subscribe, you can leave a 5-star review wherever you listen, you can tell your friends about us, or you just shout about the podcast in the pub until people politely ask you to leave. Every little bit helps, and frankly, it really makes all the effort worthwhile. So until next time, cheerio. Bye-bye.
Transcript supplied by the publisher with the episode.
Smashing Security
by Graham Cluley · English · Tech & Science
Stories from the world of hacking, cybersecurity, and rogue AI. Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all…
More from Smashing Security
-
E487 · 58 min
Clippy's crypto comeback
Microsoft's Twitter account, with its 13 million followers, was hijacked by a paperclip. There was no ransomware or data theft, just Clippy, a dodgy crypto coin, and a corporate apology that wasn't from Microsoft either. Meanwhile, UK losses from hacked email and social media accounts have rocketed by 417%, as scammers pose as your friends to flog you tickets to gigs that don't exist. Plus, Hack The Box's Christine Bartlett joins us for a featured interview to ask what happens when AI agents join your security team, and whether anyone has thought to give them a performance review. All this…
-
E486 · 41 min
Vibe-coded shops, and hackable Flock cameras
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong? Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping up on American street corners, and took a very close look inside. All this and more in episode 486 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Dave Bittner. EPISODE LINKS: Claude Opus…
-
E485 · 1 hr 3 min
These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name "Awesome" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a "jump scare"... Plus, in our featured…
-
E483 · 44 min
This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just…
-
E482 · 50 min
This hacker leaked GTA 6 - and launched their own cryptocurrency
A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more than binge-watching Netflix while you sleep. We explore the shadowy world of "residential proxies" - how they end up inside home routers, smart TVs, and IoT devices, and why an entire criminal economy is quietly running through your internet…
-
E481 · 46 min
Never say this to a robot dog
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall, a blue ice chest, and anyone in the room wearing white shoes. Oh, and did we mention you can buy a flamethrower attachment? Meanwhile, in Salzburg, 280 gold statuettes of Mozart have vanished from the streets. This has happened to the same artist before. Organised crime, or a publicity stunt? Jenny has thoughts - and some parallels for the world of…
-
E480 · 46 min
This is the AI service you should never sign up to
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a phishing-as-a-service platform called "Greatness" has come up with something rather nasty: a phishing attack that doesn't need a fake website, a suspicious URL, or your password. Just a real Microsoft login page and a moment of misplaced trust - and the attackers walk off with full access to your emails, your files, and your entire organisation. All this and more in…
-
E479 · 1 hr
How a fake police officer nearly stole Graham's cryptocurrency
Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education - sending an…
-
E478 · 59 min
This job interview could destroy your company
You've been headhunted for a great job in cryptocurrency. All you have to do is complete a short online assessment - with your webcam on, of course, so they can verify who you really are. Which is ironic, because the person recruiting you doesn't exist. And North Korean hackers using this trick have already made off with $643 million in crypto this year alone. Meanwhile, researchers at UC San Diego have discovered that 2.2 million cars across the United States can be unlocked or immobilised by anyone with a bit of Bluetooth kit - thanks to one aftermarket car alarm that made a truly…
-
E477 · 51 min
How 14 orders of chicken McNuggets helped nail a suspected Russian hacker
A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball. EPISODE LINKS: Bengaluru triple murder: Accused allegedly used…
